Skip to main content
Annual Review

NCSC Annual Review 2024

Looking back at the National Cyber Security Centre's eighth year and its key developments and highlights, between 1 September 2023 and 31 August 2024.

Page 14 of 16

Market incentives and the future of technology security

Technology markets do not incentivise the investments required to secure the foundations of cyberspace.

The modern three-point seat belt, designed by a Volvo engineer over 60 years ago, has doubtless saved millions of lives. Yet the patent for it was given away for free for the betterment of all, because Volvo chose not to compete on safety.

Just as seat belts are not a premium feature that users pay extra for, we should not have to pay for ‘safety features’ across the software and hardware sectors. Unfortunately, many cyber security features (such as multi-factor authentication, single sign-on or even access to certain logging) are deemed ‘premium add-ons'; functionality that involves additional cost for organisations (or users), rather than being a fundamental component of the offering.

Products and services are produced by commercial enterprises operating in mature markets which – understandably – prioritise growth and profit rather than the security and resilience of their solutions. Inevitably, it’s small and medium sized enterprises (SMEs), charities, education establishments and the wider public sector that are most impacted because for most organisations, cost consideration is the primary driver.   

Put simply, if the majority of customers prioritise price and features over ‘security’, then vendors will concentrate on reducing time to market at the expense of designing products that improve the security and resilience of our digital world. 

The NCSC want to build a future where products are secure, private, resilient, and accessible to all. The technology to achieve this exists, but the business and commercial incentives to encourage adoption are not present. So how can we ensure there are market incentives to make this happen?



A series of discussion groups, expert panels and academic research led the NCSC to develop an understanding of four key drivers that we believe could shift the incentive structures that underpin technology markets and their attitude to security. These drivers are: liability, financial reward, transparency, and consensus.

Drivers that underpin technology markets (liability, financial reward, transparency, and consensus)

Leveraging these drivers to develop policy options would use network effects, the drive for profit and the desire to maintain reputation to incentivise enterprises to prioritise security. We believe that a range of incentives are required to encourage commercial enterprises to focus on security for their own benefit, which will mean better security outcomes for everyone.

The NCSC wants to build an alliance of stakeholders across HMG, industry, academia and with our international partners. Creating the desired market incentives will require further research into the dynamics of our most important technology sectors and markets. Strategic policy will need to be developed across government. We must:


Published

Reviewed

Version

1.0

Written for