Skip to main content

Sausages and incentives: rewarding a resilient technology future

Why ‘thinking big’ is required to shift the dynamics of the technology market.
,

At this year’s CYBERUK’s Technology Plenary, the NCSC’s CTO Ollie Whitehouse sparked a debate when he proposed that the technology market does not currently reward those technology companies that invest in cyber security.

In the lively discussion that followed, the panel of industry experts – perhaps predictably – took issue with Ollie’s claim that “we have a non-functional market”. By contrast, subsequent coverage from the technology press (including this detailed analysis from The Register and an editorial from Infosecurity Magazine) was broadly supportive, and acknowledged that the current technology marketplace fails to properly reward secure development practices.

In this blog, we'll re-iterate why the NCSC believe that the market does not always reward investment in cyber resilience, particularly within the supply chain where component choices can be invisible to end users. We'll also highlight the many initiatives, designed to incentivise the development of resilient software, that the NCSC contribute to.

The reality is that in 2025, we know how to build secure products and services.

The technology to raise resilience at scale exists, from memory safe hardware and programming languages to anti-fragile architectures to formal methods. Unfortunately, the business and commercial incentives to encourage adoption and sustainment of secure solutions are not sufficient. A number of standard economic theories can be used to explain, to an extent, why this is the case:

  • Rational inattention theory proposes that individuals cannot process all available information, and must therefore choose which issues to consider, and which to ignore. A person or organisation may prioritise short-term issues over long-term risks (which are harder to quantify). A person procuring – for example – technology services and products, may overlook cyber security among all the risks they have to consider, particularly as cyber risk is difficult to quantify and is often perceived as technically challenging.

  • An externality is a cost or benefit that is caused by one party, but financially incurred or received by another. For example, if a factory emits pollutants, the harm is a negative externality because the factory doesn't bear the full cost of its actions, which is instead borne by nearby residents. Cyber security can be seen as a positive externality (or public good) because the benefits are felt beyond the organisation providing the security.

  • Information asymmetry is when one party in a transaction has 'better’ information than the other. The classic example is the used car market, where it is very hard for buyers to know if a potential vehicle will be reliable. The result is a 'market for lemons'. Information asymmetry is highly relevant within supply chains where an organisation’s ability to understand its cyber risk is exacerbated by limited security information on products or services they procure.

However, these economic theories do not tell us the entire story. In the NCSC’s 2024 Annual Review, we introduced four key drivers we believe can shift the incentives that underpin the technology market’s approach to security. These drivers are liability, financial reward, transparency, and consensus.

Liability, financial rewards, transparency and consensus drive the market approach

Drivers that underpin technology markets (liability, financial reward, transparency, and consensus)





Written by

Paul W Principal Technical Director, NCSC Capability
Ollie Whitehouse Chief Technology Officer (CTO), NCSC

Published