Market incentives in the pursuit of resilient software and hardware
A new paper from the ONCD explores how metrics can influence markets to improve the cyber security ecosystem.

For the past year, President Biden’s National Cybersecurity Strategy has acknowledged that mitigating known software vulnerabilities is a complex problem, and that the current ecosystem does not properly incentivise the investments required to secure the foundations of cyberspace.
‘Back To The Building Blocks: A Path Toward Secure and Measurable Software’ is a new paper from the White House’s Office of the National Cyber Director (ONCD), which argues that in order to establish accurate cyber security quality metrics, the research community can address the hard and complex research problem of 'software measurability’.
The NCSC fully support the ONCD’s endeavours, and in this post, we share our thinking on a number of key themes in the report, including:
- the market incentives and behaviours for secure software and hardware
- where the research, capability and understanding gaps exist
and
- how the NCSC is taking steps to address these
Market behaviours and incentives
In a recent blog, the NCSC’s CTO Ollie Whitehouse argued that – where there is an absence of regulation, legislation or procurement requirement – market incentives do not currently exist to produce or sustain secure software/hardware that is sufficient to meet the modern threat.
The reasons for this are due to a wide set of market behaviours and incentives, including:
- information asymmetry between vendors and customers (see The Market for Lemons)
- vendors will prioritise reducing time to market over designing products that are ‘secure by design’ (which takes longer and requires increased engineering costs)
- customers will usually prioritise price and features over security
- the adverse cyber security outcomes from an ever-growing mountain of technical security debt, exacerbated by mergers and acquisitions which inherit legacy technologies (burdened with years of historic underinvestment)
We’d also argue that there’s a belief by some that the risks of insecure technology and digital infrastructure should be borne by wider society, rather than by those making investment decisions.
All of these contribute to the current dynamics and patterns we see playing out in a society that’s increasingly reliant on digital technology, at work and at home. Organisations like the NCSC have the technical knowledge required to design, build and sustain technology in a cyber resilient manner. So how do we ensure there are market incentives to make this happen?
The power of collaboration
Governments are not going to solve tomorrow's challenges on their own, due to the level of investment required, coupled with the pace and scale of technological evolution. If we want whole life ‘Security by Design’ in software and hardware, governments need to collaborate with each other, along with academia, industry and investors.
As part of this shared goal, the NCSC wholeheartedly agree with the underlying theme of ‘Back To The Building Blocks: A Path Toward Secure and Measurable Software’; the need to solve security problems at root cause, and to explore the incentives required to re-align the market. As the paper explains, ‘measurability’ is a building block and enabler in increasing transparency. By addressing information asymmetry in the market, we will improve incentives to invest appropriately in the cyber resilience of our technology foundations.
Cyber as a science, data as an enabler
For cyber security to continue to evolve as a discipline, we need both quantitative and qualitative insights to understand those aspects that, when combined, work most effectively to address threat and risk, along with human factors and operational dimensions. These solutions then need to be coupled with a compelling narrative to explain our conclusions and objectives to a range of audiences.
For the quantitative aspects, access to underlying data types and sources is critical. When we think about software and hardware specifically, there are many possible points of measurement which can contribute to our understanding of its intrinsic security and support assurance. As the White House paper states:
“Software measurability is one of the hardest open research problems to solve; in fact, cybersecurity experts have grappled with this problem for decades. It is not just about refining existing metrics or tools; it is also about pioneering a new frontier in software engineering and cybersecurity research.“
We have techniques that can help to solve some aspects of this problem. For example, formal verification of code, attestation, and software bill of materials (SBOM). There is clearly more research to do both in identifying new techniques and understanding how to use them in real-world situations to improve decision making.
In short, we need richer data sets, analytic tools and surfacing of this knowledge to help address the information asymmetry which exists in the market today. This is because information asymmetry negates informed buying and risk management decisions, for all but the most sophisticated organisations.
A challenge we cannot shy away from
Improving the resilience of our software and hardware technology stacks in ways that can scale globally is a multi-faceted, sociotechnical challenge. Creating the right market incentives is our priority. Without these in place, we cannot begin to make progress at the pace or scale we need.
Our collective interventions to improve engineering best practices and more transparent behaviours must be driven by data, and targeted by research and innovation. All of this requires better access to skills and cyber education, improved tools, and accessible infrastructure. To that end, our governments, industries and academic partners must collaborate to curate a portfolio of short, medium and long-term initiatives, underpinned by evidence to address this hard cyber problem. The ONCD paper calls out software measurability as an example of a longer-term problem we cannot shy away from.
Reasons to be cheerful…
We should have optimism that the market can and will pay for cyber resilient solutions. What are the grounds for this optimism? Well, research undertaken by University College London published in 2020 on the subject of ‘internet of things’ (IoT) device security found:
“Consumers would be willing to pay more for added security, but the amount depends on the type of device ... However, willingness to pay is not dependent on the level of risk reduction offered, suggesting that consumers would not pay more for a higher reduction in risk”.
So, what does the future hold? As far as the NCSC is concerned, we have a range of activities planned that address the challenges outlined in the ONCD paper, which include:
- engaging with academia and industry through our Research Institutes to define research questions
- in April 2024, the NCSC and the Department of Science, Technology & Innovation (DSIT) will release public consultations on the UK’s Software Vendor and AI Codes of Practice and their policy intentions
- in May 2024, CYBERUK (the UK government's flagship cyber security conference) will include a panel titled How Do We Incentivise the Market To Invest in Secure-by-Design?
- by March 2025, the UK government will establish the first of its Cyber Resilience Testing Facilities (CRTFs) to enable the NCSC’s Principles Based Assurance ambitions for technology
- and of course, continued engagement and collaboration with international partners such as the ONCD and CISA


