A problem shared is . . . in the research problem book
Introducing the new NCSC research problem book and find out how you can get involved.

Sesame via Getty Images
Background to the book
If you take the long view of cyber security, you’ll know something of the complex challenges ahead in our field. We’re talking here about the really knotty questions which, unless we get ahead of them, will be real barriers to improving cyber security. In the NCSC, we’ve been thinking about this too and what we can do to help move our field forwards. Out of this, we’ve developed the NCSC problem book.
Most major leaps forward in cyber security have their origins in research. There are active cyber security research communities in academia, private sector, public sector, and also personal research by individuals. Different organisations and individuals will have different drivers and criteria for choosing where they put research effort, but one great source is from ‘problem books’.
A book full of problems?
Well, yes, but in a constructive way.
Our newly revamped problem book is a set of really tricky problems where we think considerable research is needed to find new thinking and solutions. You could also describe it as a set of research focus points that require a huge collective effort over the next five to ten years.
Context is everything, so for each ‘problem’, we include a full description of the issue, a set of questions – or sub-problems – that could be used as starting point for research, and then a short insight from someone in the NCSC working in a relevant area explaining why it matters.
Breaking it down
There is a lot we could cover, so to make it manageable, we are breaking down the book into chunks, based on different areas of research. We’re launching it with five cross-cutting problems, or put another way, problems that span different disciplines and areas, looking at big questions like: how can we make phishing a thing of the past? How can we speed up the take-up of better security measures in OT? And the really hard question of how can we build systems we trust when there is a complex chain of individual components within them?
In future, other section themes will be added on topics like cyber physical security, or sociotechnical problems.
Who is this for and how can I get involved?
The problem book is for anyone with research interests in cyber security topics. We expect this will mostly be from the academic world, but hope it will appeal to others too – industry partners thinking about research and innovation, for example.
This is a long game, and publishing the problems is the first step. By setting out the problems for this first chapter, we hope it will encourage those already thinking about – or actively working on – research in these fields to build on that, knowing that their work will be part of something bigger. For others, this may be an encouragement to start.
Whichever it is, we’re interested to hear about work that’s happening that contributes to solving these problems and have set up a form for you to tell us more, including the institution you’re linked with and whether you’ve worked with us before.
And in the longer term, look out for more chapters in the research problem book that we hope will inspire more research to move our field forward.