Sausages and incentives: rewarding a resilient technology future

At this year’s CYBERUK’s Technology Plenary, the NCSC’s CTO Ollie Whitehouse sparked a debate when he proposed that the technology market does not currently reward those technology companies that invest in cyber security.
In the lively discussion that followed, the panel of industry experts – perhaps predictably – took issue with Ollie’s claim that “we have a non-functional market”. By contrast, subsequent coverage from the technology press (including this detailed analysis from The Register and an editorial from Infosecurity Magazine) was broadly supportive, and acknowledged that the current technology marketplace fails to properly reward secure development practices.
In this blog, we'll re-iterate why the NCSC believe that the market does not always reward investment in cyber resilience, particularly within the supply chain where component choices can be invisible to end users. We'll also highlight the many initiatives, designed to incentivise the development of resilient software, that the NCSC contribute to.
The reality is that in 2025, we know how to build secure products and services.
The technology to raise resilience at scale exists, from memory safe hardware and programming languages to anti-fragile architectures to formal methods. Unfortunately, the business and commercial incentives to encourage adoption and sustainment of secure solutions are not sufficient. A number of standard economic theories can be used to explain, to an extent, why this is the case:
-
Rational inattention theory proposes that individuals cannot process all available information, and must therefore choose which issues to consider, and which to ignore. A person or organisation may prioritise short-term issues over long-term risks (which are harder to quantify). A person procuring – for example – technology services and products, may overlook cyber security among all the risks they have to consider, particularly as cyber risk is difficult to quantify and is often perceived as technically challenging.
-
An externality is a cost or benefit that is caused by one party, but financially incurred or received by another. For example, if a factory emits pollutants, the harm is a negative externality because the factory doesn't bear the full cost of its actions, which is instead borne by nearby residents. Cyber security can be seen as a positive externality (or public good) because the benefits are felt beyond the organisation providing the security.
-
Information asymmetry is when one party in a transaction has 'better’ information than the other. The classic example is the used car market, where it is very hard for buyers to know if a potential vehicle will be reliable. The result is a 'market for lemons'. Information asymmetry is highly relevant within supply chains where an organisation’s ability to understand its cyber risk is exacerbated by limited security information on products or services they procure.
However, these economic theories do not tell us the entire story. In the NCSC’s 2024 Annual Review, we introduced four key drivers we believe can shift the incentives that underpin the technology market’s approach to security. These drivers are liability, financial reward, transparency, and consensus.

Drivers that underpin technology markets (liability, financial reward, transparency, and consensus)
Liability framework
There is often a misalignment between those who bear the costs of insecurities (that is, end users and wider society) and the technology providers who are best positioned to ‘bake in’ security.
Can legislation be used to ensure that producers and providers are held accountable for delivering on their claims for product security? Our hypothesis is that it would force a market correction.
The NCSC have argued that this would require collaboration across international boundaries to have alignment and real, global, impact, which is why the UK actively supports other international secure by design initiatives, and recently worked with the European Telecommunications Standards Institute (ETSI) to create an international standard and set a benchmark for securing AI which creates a bedrock.
Ecosystem consensus
By this, we mean how can the wider technology ecosystem be encouraged to take concerted action, so that security is demanded by all parties. This would include encouraging consumers to seek out more secure products so that security is universally valued across digital technology markets. Doing so collectively could help to overcome the power imbalance felt by smaller businesses when dealing with larger suppliers.
The Software Security Code of Practice, launched at CYBERUK, is an example of government establishing clear expectations for a market baseline with regards to cyber security. The Code provides a framework to help providers measure their progress, identify improvements, and provide tangible evidence of their commitment to security. For consumers, knowing their provider has followed the Code provides confidence that the software has been created using reasonable security measures and good practices.
Transparency
During the CYBERUK technology plenary, Ollie Whitehouse quipped that “we know more about what’s in our sausages than our software, and that's probably not right for 2025”. The serious point is that making it easier to identify the technology products in the supply chain (and what those products comprise) would enable developers to compete on security, and support better-informed decision making by customers. Ollie closed the plenary by inviting the conference to “judge us how quickly we define – with international partners – what minimum transparency looks like.”
There are techniques that can help, such as formal verification of code, attestation, and software bill of materials (SBOM). But we need richer data sets and analytic tools to help address the information asymmetry, because information asymmetry negates informed buying and risk management decisions for all but the most sophisticated organisations.
Financial rewards
Finally, we need to show a clear return on investment in those organisations that invest in foundational security. How can we help organisations measure and compare the costs incurred by vulnerabilities (either through patching, suffering incidents, or some other whole of life cost) with long-term investment in more resilient technologies?
How do we incentivise addressing technical debt when organisations are shipping features at pace? How can we help vendors compete on cyber security?
Thinking big
The cost of underinvestment in cyber security is ultimately borne not by the vendors, but downstream by customers, insurers, the government and wider society. It is these market fundamentals that need to be addressed if we are to prevent software and hardware vulnerabilities being exploited.
Raising the bar is therefore critical. However, to go further, faster, we need to harness the power of competitive innovation to improve resilience. Our future digital infrastructure must be built on secure foundations in order to deliver the digital resilience we know that the next generation will require. We believe that the need to incentivise ‘secure by design’ technology will require significant efforts over the next decade, and it’s the latest cross-cutting problem to be added to the NCSC’s research problem book.
The technology to raise cyber resilience at scale exists, but it will require us – amongst other things – to 'think big' and drive a strategic policy agenda that fundamentally alters the dynamics of the existing market in technology and services.


