Skip to main content

How the NCSC thinks about security architecture

Richard C explains how an understanding of vulnerabilities - and their exploitation - informs how the NCSC assesses the security of computer systems.
Nitat Termmee via Getty Images

The NCSC has a security architecture team who consult on the design and operation of some of the most important computer systems in the UK; systems that handle the UK's most sensitive information and provide some of the most critical functions.

The current team has an impeccable pedigree and continues to build on thought-leading knowledge and techniques developed over more than a decade.

Although we're very clear what we mean by the term 'security architecture', we find there are differing views within the industry. And this can lead to a mismatch in expectations when we - to give one example - interview candidates for a security architecture role.

This blog defines what the NCSC mean by 'security architecture'. If you subscribe to a different school of thought, that’s fine, but we're passionate about what we believe is a practical approach, particularly when we need to get the most out of a brief engagement with a system owner.





Written by

Richard Crowther NCSC Deputy CTO