NCSC Annual Review 2024
Pages
Page 14 of 16
Market incentives and the future of technology security
The modern three-point seat belt, designed by a Volvo engineer over 60 years ago, has doubtless saved millions of lives. Yet the patent for it was given away for free for the betterment of all, because Volvo chose not to compete on safety.
Just as seat belts are not a premium feature that users pay extra for, we should not have to pay for ‘safety features’ across the software and hardware sectors. Unfortunately, many cyber security features (such as multi-factor authentication, single sign-on or even access to certain logging) are deemed ‘premium add-ons'; functionality that involves additional cost for organisations (or users), rather than being a fundamental component of the offering.
Products and services are produced by commercial enterprises operating in mature markets which – understandably – prioritise growth and profit rather than the security and resilience of their solutions. Inevitably, it’s small and medium sized enterprises (SMEs), charities, education establishments and the wider public sector that are most impacted because for most organisations, cost consideration is the primary driver.
Put simply, if the majority of customers prioritise price and features over ‘security’, then vendors will concentrate on reducing time to market at the expense of designing products that improve the security and resilience of our digital world.
The NCSC want to build a future where products are secure, private, resilient, and accessible to all. The technology to achieve this exists, but the business and commercial incentives to encourage adoption are not present. So how can we ensure there are market incentives to make this happen?
The roots of digital architecture
For some time now, the NCSC has used the term ‘secure by design’ to describe an approach that encourages organisations to ‘bake’ cyber security into all stages of the development life cycle, rather than adding it as an afterthought. Doing this addresses cyber security problems at root cause and prevents costly redesigns later on. We can improve the overall resilience of systems by encouraging investment in ‘secure by design’ practices. This is particularly true at the ‘foundational layer’ of our digital architecture, as any software or systems built on those foundations will benefit.
When we follow a ‘secure by design’ approach, we fix classes of vulnerability, rather than having to address the symptoms of a particular issue (typically through software patching). Memory safety vulnerabilities, for example, are one of the most prevalent types of disclosed software vulnerabilities, and investing in ‘secure by design’ development could drastically reduce onerous patch management and incident response activities. But with few incentives in current market structures for organisations to fix the root cause, memory safety vulnerabilities will continue to proliferate.
The NCSC believe that fixing these foundational insecurities will improve digital resilience across the globe, which is why we fully support a paper by the White House’s Office of the National Cyber Director, ‘Back To The Building Blocks: A Path Toward Secure and Measurable Software’. Like the NCSC’s Principles Based Assurance (PBA) initiative, this paper stresses the need to solve security problems at root cause, and to explore the incentives required to re-align the market.
The backdrop to this is a threat landscape that reveals increased intent from nation-state actors and cyber criminals, both with access to enhanced capabilities such as AI-enhanced vulnerability scanning. The increased appetite and ability to rapidly scan for and exploit these foundational vulnerabilities means we are presenting adversaries with an increasingly exploitable attack surface. One which we could harden by fixing vulnerabilities at root cause.
Creating the right market incentives
As mentioned earlier, the software and hardware market does not incentivise investment in security. The reasons for this are due to a wide set of market behaviours and incentives, including:
-
‘information asymmetry’ between vendors and customers (a situation where sellers are better informed than buyers about the quality of the goods or services)
-
vendors will prioritise reducing time to market over designing products that are ‘secure by design’ (which takes longer and requires increased engineering costs)
-
customers will usually prioritise price and features over security
-
the adverse cyber security outcomes from an ever-growing mountain of technical security debt, exacerbated by mergers and acquisitions which inherit legacy technologies
-
a belief by some that the risks of insecure technology and digital infrastructure should be borne by wider society, rather than by those making investment decisions
A series of discussion groups, expert panels and academic research led the NCSC to develop an understanding of four key drivers that we believe could shift the incentive structures that underpin technology markets and their attitude to security. These drivers are: liability, financial reward, transparency, and consensus.

Drivers that underpin technology markets (liability, financial reward, transparency, and consensus)
Leveraging these drivers to develop policy options would use network effects, the drive for profit and the desire to maintain reputation to incentivise enterprises to prioritise security. We believe that a range of incentives are required to encourage commercial enterprises to focus on security for their own benefit, which will mean better security outcomes for everyone.
The NCSC wants to build an alliance of stakeholders across HMG, industry, academia and with our international partners. Creating the desired market incentives will require further research into the dynamics of our most important technology sectors and markets. Strategic policy will need to be developed across government. We must:
-
work with DSIT to develop the underpinning strategic policy
-
signal to markets that nations are fully committed to increasing the transparency and visibility of poor cyber security standards that organisations have grown used to accepting
-
make those responsible for those decisions accountable for investing in ‘defective products’
CISA chief Easterly calls software vulnerabilities a 'product defect,' urges liability regime
Two visions of the future of security…
The future of technology security will evolve somewhere along a spectrum. At one end, the market continues as it is now, where security remains an afterthought and consumers and wider civil society bear the brunt. In this scenario, consumers will find their data compromised, their systems held at ransom, and their privacy invaded. They will have no means of holding to account those responsible for the defects that failed to prevent such attacks.
Furthermore, it will be increasingly difficult to know where defective products have allowed vulnerabilities to be exploited, such is the increasing complexity of interconnected digital systems. Entire swathes of our critical infrastructure could be severely impacted by exploitation of simple vulnerabilities, affecting the UK’s ability to have consistent flows of electricity, clean water and a functioning transport system. The UK won’t be economically prosperous if we can’t trust the integrity of our critical sectors.
At the other end, entire classes of exploitable bugs could be mitigated by organisations investing in basic digital resilience through foundational security and ‘secure by design’ technology.
Improving the resilience of our software and hardware technology stacks in ways that can scale globally is a multi-faceted challenge. The technology to raise resilience at scale exists, but it will require – amongst other things – a strategic policy agenda that fundamentally alters the dynamics of the existing market.