UK Cybersecurity Agency Calls for Enhanced Forensic Support from Device Manufacturers
In a significant call to action, the United Kingdom’s foremost cybersecurity agency has urged manufacturers of network devices to play a pivotal role in supporting incident response teams. This initiative aims to facilitate the collection of evidence following security breaches, thereby enhancing the overall cybersecurity landscape.
In a blog post dated July 29, Chris A, who serves as the technical director for networking and infrastructure at the National Cyber Security Centre (NCSC), articulated the growing menace posed by attackers targeting devices such as firewalls and VPN gateways. As incidents of cyber compromise rise, the need for organizations to reliably understand what transpires during a security breach is becoming increasingly critical. Chris A emphasized that "forensic observability" plays a crucial role in this context.
Forensic observability is defined by the NCSC as the capability to provide essential telemetry, detailed logging, configuration states, and the ability to source forensic data from both memory and data at rest. This framework also necessitates transparency about the software operating on a device, which can be facilitated through mechanisms such as version information or a comprehensive software bill of materials (SBOM). The lack of these features often hampers the ability of organizations to assess whether a compromised device can still be trusted.
Chris A acknowledged that many manufacturers are currently falling short of these expectations. He noted that even minor design adjustments could significantly reduce the time required for the triage and investigation of incidents. "Investigating a compromised device should not necessitate discovering or exploiting vulnerabilities in the product itself," Chris A remarked. He highlighted that manufacturers have a responsibility to provide robust, supported mechanisms for gathering the evidence needed to evaluate the consequences of incidents and ultimately restore trust in affected systems.
Addressing Misconceptions in Observability
Chris A further addressed several prevalent misconceptions surrounding observability that may hinder manufacturers from implementing the necessary design improvements. He outlined three key myths:
-
Observability Aids Attackers: It is a common misconception that exposing telemetry to defenders could also provide attackers with more exploitation opportunities. However, the NCSC argues otherwise, asserting that well-designed features such as structured logging, authenticated collection mechanisms, and clearly defined forensic interfaces can strengthen security rather than compromise it.
-
Negative Customer Reactions: Some manufacturers fear that customers will react negatively to increased transparency regarding telemetry and forensic capabilities. On the contrary, the NCSC claims that clear telemetry can actually foster trust among customers through enhanced visibility of the products they are utilizing.
- Complexity of Implementation: Another myth asserts that creating forensic observability is overly challenging. While it does necessitate "careful engineering," the NCSC posits that it is entirely feasible, especially when prioritized early in the product development lifecycle.
In light of these insights, Chris A has encouraged vendors to adopt the guidance provided by the NCSC on the creation of forensic observability in their products. This guidance, which highlights best practices and necessary features, was initially published in February 2025.
Furthermore, Chris A has urged IT buyers to actively advocate for these essential features from their vendors. As organizations continue to grapple with the complexities of cyber threat landscapes, the demand for robust forensic capabilities is only expected to grow.
Collaborative Efforts for Future Solutions
Meanwhile, the NCSC is engaged in collaborative efforts with global partners to develop a standardized reference architecture for forensic observability specifically designed for network appliances and similar devices. This reference architecture aims to guide manufacturers in constructing "safe, reliable forensic access" without compromising the security integrity of their products.
In conclusion, as cyber threats become increasingly sophisticated and pervasive, the call from the NCSC for manufacturers to enhance their forensic capabilities underscores the importance of creating a safer digital environment. By addressing misconceptions, facilitating active dialogue between vendors and IT buyers, and developing comprehensive standards, the industry can move towards greater accountability and resilience in the face of malicious cyber activity. The recommendations put forth by the NCSC mark an essential step forward in establishing a more secure technological infrastructure, ultimately benefiting organizations and consumers alike.
