Skip to main content

Making forensic observability the norm for network devices

Progress is being made, but too many network devices still remain difficult to investigate after compromise

a close up of a computer circuit board with a central microchip surrounded by electrical components

Westend61 via Getty Images

Organisations' firewalls, VPN gateways and other network devices are increasingly targeted by attackers. This creates a shared challenge for both the vendors that build these products and the organisations that buy and operate them.

When incidents occur, organisations need reliable ways to understand what happened and assess whether a device can still be trusted. This is why forensic observability matters. It enables defenders to investigate compromise using supported capabilities built into the product, rather than relying on reverse engineering, or specialist vulnerability research –  as is still often the case. 

We are seeing encouraging progress across industry, but there is still some way to go before forensic observability capabilities become standard. Both vendors and buyers have a role to play in making this happen.


What is forensic observability?

Forensic observability means giving defenders reliable ways to understand what a device is doing, what it has done and whether it can still be trusted after an incident. This includes telemetry, logging, configuration state, and the ability to collect forensic data from both memory and data at rest.

It also depends on transparency. When vendors make it easy to understand what software is running on a device – for example through version information or a software bill of materials – defenders can investigate incidents more quickly and confidently.   

As highlighted at the CYBERUK 2026 Technology Track panel on radical transparency, the NCSC is encouraging vendors to provide greater transparency because small design decisions can significantly reduce the time needed to triage and investigate incidents.

The goal is simple: defenders should be able to investigate compromise using trustworthy information provided by the system in a way that makes it difficult for attackers to tamper with it.


Why forensic observability matters for network devices

But many network devices still provide only limited support for incident investigation. 

Forensic observability is particularly important for edge devices such as firewalls, VPN gateways and other network appliances. These systems often sit at trust boundaries and are increasingly targeted by sophisticated threat actors. 

To help address this challenge, in 2025 the NCSC published guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances describing the capabilities that manufacturers should build into network devices and appliances.


Incident response should not depend on workarounds

Despite this growing focus, incident response on many network devices remains unnecessarily difficult. Too often, defenders must rely on improvised techniques, reverse engineering, or even zero-day vulnerabilities to understand what happened on a compromised device. In effect, they can have fewer tools available to them than the attacker. 

That should not be normal. Investigating a compromised device should not require discovering or exploiting vulnerabilities in the product itself. Instead, manufacturers should provide supported mechanisms for gathering the evidence needed to investigate incidents, assess impact and restore trust in affected systems.  

This benefits everyone involved in incident response:

  • Defenders have access to the information they need to determine scope and impact
  • Vendors reduce the need for unsupported investigative techniques
  • Organisations can respond more quickly and confidently without relying on specialist domain knowledge

Progress towards forensic observability

Encouragingly, we are seeing meaningful progress from parts of the technology industry. Several vendors have begun investing in better logging, forensic data collection capabilities, and greater system transparency. 

To support this shift, the NCSC has been working with international partners to develop a reference architecture for forensic observability in network appliances and similar devices. The goal is to describe a practical approach that vendors can adopt to provide safe, reliable forensic access while maintaining strong security boundaries.


A view from industry

Vendors that have invested in forensic observability are already seeing its value in practice. Reflecting on its Pacific Rim campaign, Sophos said: 

we proved the value of extending detection and response techniques beyond corporate endpoints to firewall devices, and it materially reduced harm to our customers. The experience reinforced a simple principle: you can't just try to protect firewalls, you have to plan for when they fail. The NCSC's forensic guidance builds on that same thinking, giving manufacturers and buyers a blueprint for making network devices easier to analyse when they're compromised. We're using it to guide our own firewall roadmap, and we'd encourage anyone buying a firewall to make it part of their evaluation criteria.

 

Three common misconceptions

Despite the progress being made, there are still misconceptions about observability. 

Doesn’t this help attackers?

No. One common concern is that exposing additional telemetry or forensic interfaces will provide attackers with more opportunities to exploit a system. But well designed observability features improve security rather than weaken it. Structured logging, authenticated collection mechanisms, and clearly defined forensic interfaces are safer than forcing investigators to rely on undocumented behaviour, or vulnerability research. Security engineering should assume that defenders will need to investigate systems under pressure and design for that reality from the outset.  

Won’t customers hate it?

No. Another frequently cited concern is that customers may react negatively to increased transparency. But experience suggests the opposite. Organisations responsible for operating critical infrastructure consistently ask vendors for better visibility into the systems they deploy. Clear telemetry and forensic capabilities build trust because they allow operators to verify what their systems are doing and respond effectively when something goes wrong. 

 Isn’t it too difficult? 

No.  There is a belief that implementing forensic observability is too difficult. Although it does require careful engineering, the examples emerging from industry demonstrate that it is achievable. Vendors that prioritise observability early in the design process find that it becomes a natural part of their platform rather than an afterthought bolted on in response to incidents. 

Observability is ultimately about enabling defenders to do their jobs properly. When systems provide the information needed to understand their behaviour, organisations can investigate incidents quickly, confidently and safely. That is better for vendors, better for operators, and better for the security of the wider ecosystem. 


What next?

Vendors: Following the NCSC’s guidance, build forensic observability into your products early in the design process.

Buyers: If your edge devices don’t have this feature, push for it. The fastest route to widespread adoption may be for customers to ask for these capabilities as standard.

By making forensic observability the norm, we can help organisations respond more effectively to cyber incidents – strengthening the resilience that underpins the UK’s security and economic growth.

Chris A 
Technical Director Networking and Infrastructure 

Written by

Chris A Technical Director Networking and Infrastructure