Eradicating trivial vulnerabilities, at scale
A new NCSC research paper aims to reduce the presence of ‘unforgivable’ vulnerabilities.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

In the NCSC’s 2024 Annual Review, we described how fixing ‘foundational vulnerabilities’ in software code is required to improve digital resilience across the globe. 'Market incentives and the future of technology security' stressed the need to address decades of misaligned incentives that prioritised ‘features’ and ‘speed to market’ at the expense of fixing vulnerabilities that can improve security, at scale.
All systems contain vulnerabilities. And we know many vulnerabilities are complex and hard to avoid.
However, the vulnerabilities referred to in the Annual Review (that is, those vulnerabilities that are trivial to find and that occur time and time again) are ones that the NCSC are aiming to drive down at scale. These ‘unforgivable vulnerabilities', a phrase coined by Steve Christie in his 2007 MITRE paper, are ‘beacons of a systematic disregard for secure development practices. They simply should not appear in software that has been designed, developed, and tested with security in mind’.
A new paper by the NCSC ('A method to assess ‘forgivable' vs ‘unforgivable' vulnerabilities’) extends the ideas introduced in the MITRE paper, and proposes a method that allows security researchers to assess if a vulnerability is ‘forgivable’ or ‘unforgivable’. The method outlined in the paper effectively quantifies how easily the mitigations required to manage the vulnerability could be applied. Vulnerabilities with ‘easy’ mitigations can subjectively be declared as ‘unforgivable', or not.
More importantly, the paper intends to generate discussion with vendors, and is a call on them to work to eradicate vulnerability classes and make the top-level mitigations discussed in the paper easier to implement.
Most of the 13 ‘unforgivable vulnerabilities’ mentioned in the original MITRE 2007 paper still exist in one form or another. At the core of this research is the desire to eradicate vulnerability classes and make the top-level mitigations easier to implement. The NCSC believe this can be best done by making operating systems more secure, by improving development frameworks, and by encouraging developers and vendors to adopt secure programming concepts.
Whilst vulnerabilities are hard to avoid, we can eradicate many using the right tools and approaches, such as those outlined by CISA Secure by Design and the voluntary Code of Practice for Software Vendors, a systemic intervention by the UK government aimed at software vendors, and designed to ensure that security is ‘baked into' software. It will begin as voluntary code, but further policy interventions to support its uptake and impact are currently being explored.
The Code of Practice will be published later in the year, and we’ll be publishing guidance to help you implement the technical controls that will ensure your organisation complies with the code.
Head of Vulnerability Management Team


