NCSC Annual Review 2023
Pages
Page 14 of 16
Technology

Introduction
As technology develops, the cyber security threat we face is evolving too. Since the launch of ChatGPT, the interest in artificial intelligence (AI) has taken off dramatically. There is rarely a day when AI does not feature in national news. The NCSC has been researching AI security for several years and has been working with our international counterparts, as well as the public and private sector in the UK, to realise the benefits and protect against the risks associated with AI.
But there are other critical areas of technology which don’t make the headlines as often, which the NCSC considers just as important in the future. These include semiconductors (as core components of all electronic devices), cryptography (that will keep our data safe from the threat from future large-scale quantum computers) as well as telecoms security, socio-technical research, and assessing risks from radio frequency transmissions. The NCSC has contributed to two national technical strategies led by the Department for Science, Innovation and Technology (DSIT), providing expert cyber security advice on building resilience to protect our national security.
The importance of secure and resilient critical technology is never far from the NCSC’s mind. In the past year, we have published 15 pieces of guidance, 53 blogs and set out the five most significant ‘cross-cutting’ problems which the NCSC believes need concerted and significant collaborative effort over the next decade in our research problem book (which we discuss in further detail below).
Artificial intelligence (AI)
The whole field of artificial intelligence is developing at a phenomenal pace. In this rapidly evolving arena, we must ensure that cyber security is both a core requirement of AI technology throughout its life cycle and integral to its development from the outset.
Our primary objective is to ensure that cyber security does not become a secondary consideration but is recognised as an essential precondition for the safety, reliability, predictability, and ethics of AI systems.
Taking a ‘secure by design’ approach to development will help society and organisations realise the benefits of advances in AI, but also help to build wider trust that AI is safe and secure to use.
In the last year, we have published three blogs about the risks associated with AI and large language models (LLMs), spoken at conferences globally to emphasise the importance of building AI technologies on secure foundations, and have shaped the government’s AI agenda.
Quantum computing and semiconductors
DSIT has published two national technical strategies in the past year covering emerging technologies that have critical implications for cyber security, and experts in the NCSC have advised on the technical positions in those strategies.
The National Quantum Strategy focuses on investment in and development of quantum technologies. Quantum computing has substantial economic potential, but also provides a threat to cryptography. The NCSC’s role is clearly defined within the strategy as the lead organisation in government on advising on mitigations to this threat. The strategy also sets out our key technical messages, focussing on the need to prepare for a future transition to post-quantum cryptography. Additionally, through discussions as part of the strategy development, and with the UK Quantum Communications Hub, we have helped set a government vision for future quantum networking to share information between quantum devices.
Building on the UK’s specific semiconductor strengths, DSIT’s National Semiconductor Strategy focuses on the resilience of systems on which we rely to combat cyber attacks. The UK’s leadership on chip design positions us well to take a leading global role in this area, supporting initiatives such as the ‘Digital Security by Design’ programme led by UK Research and Innovation, which offers a potential step change in attack mitigation.
The NCSC research problem book
In August, we published the latest iteration of the NCSC research problem book with the aim to guide cyber security research towards the most critical security challenges that we have identified as significant barriers to improving cyber security.
Two problems worth specific mention are:
-
Problem 1 - How can we build systems we can trust when we can’t trust any of the individual components within them?
Hardware is becoming more complex all the time and it’s difficult to gain confidence in long global supply chains. This in turn means diminished confidence in individual computers, circuit boards and microchips. But to protect our critical national infrastructure, defence and intelligence systems and more besides, we need to build computer systems we can rely on.
-
Problem 5 - How can we accelerate the adoption of modern security mitigations into OT?
Operational technology (OT), such as the industrial control systems (ICS) that operate factories, smart cities and our energy infrastructure, often lack many of the security controls and mitigations that we take for granted in Information Technology (IT). This means that if threat actors manage to reach OT systems, they may then be able to use relatively simple techniques to have a physical real-world impact. Research in the areas below could contribute to significantly improving the security of OT systems.
Technology assurance
As technology, and the way it’s used, continues to evolve at a rapid pace, the need to update the way we gain confidence in its cyber resilience came into sharper focus this year. Any new approach must raise the bar across a broad landscape and also enable new technology solutions to be imagined, creating a thriving ecosystem underpinned by cyber-resilient technology. This year, in collaboration with Adelard, we’ve formalised the method that underpins our new approach to technology assurance: Principles Based Assurance (PBA). Key to the success of making PBA a reality is the ability to leverage industry partners, and so the NCSC has also begun the first steps towards standing up our national network of Cyber Resilience Test Facilities (CRTFs) which will independently assess a range of technologies at scale, that has a national impact in uplifting cyber resilience.
Technology crosses many international boundaries, both in terms of sales and interoperability, and the NCSC recognises the importance of mutual recognition between PBA and other assurance schemes. To this end we’ve continued our international dialogue, as well as across the different parts of UK government, to ensure that this new assurance regime can have the greatest impact possible.
UK Telecoms Lab (UKTL)
Telecoms networks are fundamental to the security of the UK’s digital infrastructure and digital economy. To help test, research and improve the security of telecoms equipment, DSIT have established a new state-of-the-art UK Telecommunications Lab in Solihull, operated by the National Physical Laboratory (NPL). Advice from the NCSC’s world-leading telecoms security experts has been central to the success of the programme. The need for the facility was first recognised by DCMS and the NCSC in 2019, and the creation of this facility in 2023 is a key milestone after years of effort, and testament to a successful partnership between DSIT, NCSC and NPL.
Vulnerabilities
The number of Common Vulnerabilities and Exposures (CVEs) in commodity technology continues to rise, a trend we expect to continue. There are many factors that contribute to an over 50% growth in reported vulnerabilities over the past five years, which include for example, a greater motivation to discover and report vulnerabilities. The rise does not necessarily imply a worsening security posture, but rather a greater level of discovery capacity and capability within government, industry, and academia to find latent issues. More indicative of the security posture, is to assess reported vulnerabilities against a measure of ‘forgivability'. Vulnerabilities that come about because of development constructs that are known to carry greater degrees of risk and that are so trivial to find they are almost immediately apparent by inspection are examples of ‘unforgivable’ vulnerabilities. No technology will ever be devoid of bugs, and some of these bugs will turn out to be exploitable security vulnerabilities. But even though the concept of unforgivable vulnerabilities was introduced over 15 years ago, such vulnerabilities are still being found – sometimes in major products produced by companies. It is this situation which needs to change both for current and future technologies if we are to achieve our objective of a safer and more resilient society.
Security-conscious developers will not only seek to avoid the unforgivable vulnerabilities, but to put a process in place to receive and mitigate more complex vulnerabilities that are more subtle and can be forgiven for their presence. Some vendors choose to operate a bug bounty programme, which pays researchers for vulnerabilities they submit. When the NCSC receives a bug bounty payment for vulnerabilities that we have disclosed, we donate the money to charity. Earlier this year we disclosed a vulnerability in Chrome that was fixed and assigned CVE-2023-1530. The disclosure was also awarded a $7,000 USD bug bounty that Google doubled to $14,000 when it was donated to charity.
Vulnerability Reporting Service
Over the past five years the NCSC’s Vulnerability Reporting Service (VRS) has helped secure government systems and services from a wide range of security issues, such as cross-site scripting vulnerabilities and dangling domains, preventing the reported vulnerabilities from turning into incidents.
The VRS has provided the people reporting vulnerabilities - the finders - with a route to report these vulnerabilities and a way to directly communicate and include the system owner. The VRS has also raised awareness of vulnerability disclosure with system owners and demonstrates how it can help secure the systems, products, and services they manage.
It has been hugely successful. So much so that the VRS, as described in the Government Cyber Security Strategy , will move into the developing Government Cyber Coordination Centre (GC3), a joint venture with the Cabinet Office. This move will help the VRS deliver more effective coordination and further improve the resilience of the UK government.
Earlier this year, the finder community were key to reporting cross-site scripting vulnerabilities affecting Citrix ADC and Citrix Gateway instances across UK government. In 2021, finders reported and helped UK government rapidly remediate vulnerabilities affecting Microsoft Exchange servers.
We would like to thank our partners in helping us create the VRS and we will be showing our thanks to our finder community by awarding NCSC Challenge Coins to those finders who have shown themselves to be exemplars of the vulnerability disclosure community.
Researchers (the finders)
Annual breakdown of researchers
| Year | Number |
|---|---|
| 2018 | 13 |
| 2019 | 71 |
| 2020 | 109 |
| 2021 | 173 |
| 2022 | 194 |
| 2023 | 163 |
We are proud of the fact that finders from across the world have taken an interest in the security and resilience of the UK government and submitted vulnerability reports. Working with our platform provider (HackerOne) we have seen the majority of finders who submit reports originate from outside of the UK.
The vulnerabilities
| Breakdown of top 10 vulnerabilities | |
|---|---|
| Cross-site scripting (reflected) | 42% |
| Information disclosure | 18% |
| Open redirect | 10% |
| Path traversal | 8% |
| Code injection | 5% |
| Privilege escalation | 4% |
| Improper access control | 4% |
| Information exposure through directory listing | 3% |
| Cross-site scripting (generic) | 3% |
| SQL injection | 3% |
The Vulnerability Reporting Service data shows that the majority of the vulnerabilities reported are cross-site scripting. The second most common relate to information disclosure, which is largely caused by content management system (CMS) plug-ins. However, a consistent mitigation of a large percentage of vulnerabilities is to ensure system owners are running the latest version of the software and any installed plug-ins.
The system owners
| Reports by department type | |
|---|---|
| Local | 73% |
| Central | 21% |
| Other | 6% |
System owners broadly fall into three categories:
- Local – Local government; providing services at local level from county level, down to town or parish councils. It can also include local public services such as GP surgeries, and fire and police services.
- Central – Central government departments with overall governance and decision-making at a national level, such as national regulatory bodies. Some central government departments have their own vulnerability disclosure programme (VDP) through the Disclosure for Government Scheme.
- Other – Exceptions for significant but out-of-scope cases, such as CNI. ‘Other’ will also include any spam reports.
Guidance
This year, our best-practice guidance on cloud computing has scored well with NCSC stakeholders, aligning with an ever-increasing number of businesses adopting cloud computing. Since ChatGPT secured global coverage earlier this year and excitement around the capabilities of AI has grown, the NCSC has leveraged its technical knowledge into practical guidance, to concentrate on the real opportunities and potential risks for the UK.
As a reminder that some cyber threats are evergreen, our phishing guidance remains among our most popular content. We’re committed to keeping our content current, reflecting changes in threat and how to counter it.
15
new or revamped pieces of guidance were published in 2023.
1.7m
user visits.
53
blogs on a range of topics.
| The most searched terms were | |
|---|---|
| ‘password(s)’ | 2,490 searches |
| ‘phishing’ | 2,004 searches |
| ‘Cyber Aware’ | 871 searches |
Capability
- The NCSC and DCMS published the Code of Practice for app store operators and developers. It will encourage them to meet a minimum bar for security and privacy.
- The NCSC hosted an international workshop virtually and in Manchester, focusing on the security of compressed machine learning models, particularly in the context of embedded or edge devices.
- The NCSC provided support to AUKUS in establishing best-practice security culture.
- The NCSC vulnerability management team responded to significant vulnerabilities including those affecting the MOVEit managed file transfer software and a critical vulnerability affecting Fortinet devices.