Landing at the NCSC (glad I brought my towel)
Ollie Whitehouse, the NCSC’s new Chief Technology Officer, outlines the cyber security challenges he’ll be prioritising.

gremlin via Getty Images
It is with a tremendous sense of pride that after 27 years in the private sector, I joined the NCSC as the CTO in October 2023. Reflecting on what Ian Levy wrote in his final post 'So long and thanks for all the bits', I wanted to continue the discussion and – 2 months into my post – outline what my immediate priorities are.
It is fair to say the calibre of technical workforce I have inherited at the UK’s authority for cyber security, is striking and deeply impressive. At its core, the NCSC is a technical agency with a critical role in preparing the UK for tomorrow whilst supporting a path to a whole-of-society cyber resilience today.
The external priorities I outline below are informed by an understanding of the threat the UK faces (including our adversaries' objectives), clear evidence-based understanding of our collective weaknesses, and an objective analysis of the efficacy of how to build resilience across products, services and systems.
Through this increased understanding, we can be clear on our own objectives which are needed to direct the necessary research and innovation that will drive generational advances in technology.
Cyber as a science, data as an enabler
Across many of the cyber security challenges we face, there’s a lack of evidence supporting the efficacy of mitigations and defences in real-world situations.
On one hand, we have exemplars such as seL4 (a formally verified microkernel with 1 million lines of proofs), CHERI/Morello and Rust. These all mitigate memory safety vulnerabilities. Similarly, Trusted Types have been shown to be effective at mitigating DOM cross-site scripting, as they also have underlying evidence bases as to their efficacy in reaching their aims.
However, these examples are in the minority. On the flipside, we have claims being made on the efficacy (or the level of cyber security present) across a range of commercial cyber security solutions and technologies supported with little (or dubious) evidence. Sometimes we encounter vendor hostility towards independent analysis and assessment.
This disconnect between assertion and evidence-backed efficacy is a key priority of mine for several reasons:
- lack of primary evidence means we do not know what works in the real world
- we would not tolerate this lack of evidence in other safety-critical domains
- information asymmetry is a disadvantage for defenders (see The Market for Lemons)
A relentless pursuit of achieving this evidenced understanding is going to be crucial for the next phase of our collective resilience. Today there is, at best, very patchy systems-scale evidence of efficacy of what is built (or is being built) regarding its real-world cyber resilience. Where we do have evidence, it is often limited to isolated aspects/components/patterns, and as mentioned even that is lacking (or not present) in many cases.
To achieve our outcomes, we need to understand those aspects that, when combined, work most effectively to address threat and risk, along with human factors and operational dimensions. These solutions then need to be coupled with a compelling narrative that explains the improved outcomes in order to drive adoption. This understanding needs to include how effective they are, against which threats and risks, and what caveats are applicable.
It is fair to say we have a long journey ahead of us to reach this outcome. How we will build this understanding of real-world resilience of systems will vary, but there are some good examples:
- Science of Cyber Virtual Organisation driven by our colleagues at the National Security Agency
- regulatory ‘red teaming’ as evidenced most recently by the CBEST 2023 thematic findings
- chaos engineering when manifested as chaos security engineering to provide continuous evidence and assurance of resilience
- near-miss analysis to understand why an event was averted
How we then share these evidence bases to the benefit of all is the next challenge.
Imposing cost on our adversaries
It is still far too easy for our adversaries to operate in an ephemeral or enduring fashion at little cost against a majority of organisations, as articulated in David Bianco’s Pyramid of Pain.

How we change this imbalance to impose cost on and for our adversaries would benefit from debate, but there are different points where it could be imposed across operational phases:
- research & development
- commercial supply of capabilities
- initial access
- persistence
There are also wider aspects to consider:
- detection, containment and resolution speed and efficacy
- adversary tradecraft disruption
- personal cost (with respect to the operators and their leaders)
Where the best return and enduring effect can be found is not clear yet in all cases. However, I think the role of Active Cyber Defence 2.0 will be crucial, which is why it is another one of my priorities.
Addressing levels of technical security debt
We are formed by our lived experiences. In 2012 I co-authored a paper titled Software Security Austerity - Software security debt in modern software development. Sadly, nothing has materially moved in the last decade or so with respect to this area. The paper explored high-level concepts for dealing with technical security debt when organisations are shipping features at pace in a highly competitive market, and the adverse cyber security outcomes from an ever-growing mountain of technical security debt.
The challenge is twofold. Firstly, we struggle to quantify the levels of technical debt beyond unfixed-but-known vulnerabilities in bug tracking systems, delayed feature work or fixed-yet-unpatched vulnerabilities.
The second challenge is that everywhere we care to look, there is technical security debt – often in large volumes – across architecture, technology, code, dependencies, systems and operations.
Put simply, how we go about addressing technical security debt in practice is going to be critical. However –in reality – it is hard to incentivise due to cost, or it puts a business at a competitive disadvantage. Unless we address this, the benefits from initiatives like Secure by Design/Default or Market Incentives for Securing Technology will be harder to realise in our lifetime.
In terms of technical security debt, my priorities are:
- raising the level of literacy and discussion on the topic
- having academia and industry develop methods of measurement
- evidencing paydown benefits to encourage and stimulate action
- evolving corporate incentives (not just penalties)
An end to cyber security as a ‘premium feature’
In my first few weeks as CTO I gave keynote speeches at SANS CyberThreat 2023 and BlackHat Europe 2023. During both I laboured the point that seatbelts are not a premium feature, and we should not accept the same in the world of technology.
We live in a free market society where digital services can be given away or sold, yet in some instances cyber security features are deemed premium add-ons. These premium features can include multi-factor authentication or even access to certain levels of logging.
Volvo didn’t compete on safety in the first instance and gave away the seat-belt patents for the betterment of all. Sadly, outside of the issue of patents in cyber security, many vendors either compete on price (having a lower price point of entry) or upsell security features. For SMEs, charities, education and the public sector, cost consideration is a very real thing, which is often coupled with a lack of cyber security resources. Consequently, it is these organisations (which need the most cyber security assistance) that are most impacted by ‘security as a premium’.
So another one of my priorities is driving market forces so that an acceptable continually evolving ‘base level’ of cyber security in products and services is no longer a premium feature.
Market signalling and convening
Government is not going to solve tomorrow's challenges on its own, due to the level of investment required to be coupled with the pace and scale of technological evolution. This is where capital, investors, entrepreneurs , established companies and academia come in.
There exist today many gaps both of terms of cyber capability (that is, what we can do) and capacity (how we can deliver against objectives). We often know what we need now and/or will need in the future, as well as which scarcities exist domestically in the UK, as well internationally.
As the NCSC we are uniquely placed to provide an unbiased set of market signals around cyber based on threat, vulnerability, technology understanding and size of potential market. Taking this approach we can have a greater impact by shaping future capacity and capability whilst helping to ensure availability when it is required, rather than lagged. It is similar to the approach that has helped shape scores of organisations which have completed the NCSC for Startups programme.
As an example, some initial signalling I have recently provided has been around the lack of capacity and capability in the UK’s operational technology (OT) and industrial control system (ICS) supply base around threat intelligence and incident response. As a country, we have lots of OT/ICS, and it is often highly fragmented and hard to replace. We also know that the number of threat actors with demonstrated capability to disrupt OT and ICS continues to grow. Yet the capability and capacity to deal with operational environments at time of crisis across the UK simply is not where it needs to be, in terms of both depth and scale.
Thus, another priority is to give greater signalling to supply bases, entrepreneurs, investors and different forms of capital to build the things that the UK needs, on a five-year plus horizon.
Preparing for ‘when’, not 'if'
Finally, we must ensure that the UK, our international partners and supply chains are prepared for material cyber events. This will be achieved in part through the culmination of the priority areas discussed above.
We continue to operate in a world of greater competition, instability and contention than we have in over 30 years; a time before which cyber was material. As such we need to go beyond the excellent work already in place (in the guise of national exercises and Exercise in a Box, et al) and prepare for when the big cyber event hits organisations, the UK, and the globe. Our adversaries, criminal and otherwise, are more aggressive and technically able than ever before, and show no sign of slowing down. So, we need to prepare for ‘when’ and not 'if'.
Closing thoughts
So in summary, it is great to be here. As an organisation, the NCSC has made great strides in the pursuit of national cyber resilience. But as I have explained, it is clear that we need:
- even better understanding of threat actor objectives
- clearer evidence-based understanding of our collective weaknesses
- more objective understanding of the efficacy of resilience-building efforts across technology, products, services, people, process and systems
Invariably one must prioritise, and the priorities I have discussed are enablers for various outcomes across the whole of society. But it is also important to note that the NCSC is doing a lot more besides. For example, we have important work ongoing in artificial intelligence, post-quantum cryptography transition (please start cataloguing now), Cyber Aware, future technologies, counter proliferation, our Research Problem Book and initiatives around passkeys, zero-trust, memory safety and CNI resilience.
In conclusion: I am glad I brought my towel as I go swimming in the sea of national and international cyber resilience.