NCSC Annual Review 2024
Pages
Page 15 of 16
Chapter 04: Keeping pace with evolving technology
The NCSC's expertise across the technology stack helps the UK respond to emerging threats and opportunities.
As the national technical authority for cyber security, it’s vital that the NCSC keeps pace with evolving technology, particularly where significant changes affect our critical technologies, systems and sectors.
Some of these changes directly impact end users, such as understanding how we can reduce our reliance on passwords for authentication and move to passkeys. Other changes impact developers, for example improving software development practices to reduce vulnerabilities in the apps and devices embedded throughout our connected society. The NCSC requires expertise throughout this technology stack to help the UK prepare and respond to emerging opportunities, risks and threats.
The NCSC invests in extensive internal research into emerging technologies to explore new ways to reduce harm at scale. Some new technologies – such as AI – are potentially disruptive, and their development cannot be ignored. Many others evolve more slowly, but continue to have a huge effect on how resilient our systems are. For example, cloud and the ‘internet of things’ (IoT) can no longer be described as new, but they’re so ubiquitous that small changes to the standards or technologies they incorporate can have far reaching impact.
Research is long-term work that doesn’t always result in short-term benefits. However, the expertise we gain informs everything we do and allows us to provide expert authoritative input to drive our strategic aims which manifest elsewhere in government, such as our work supporting research into semiconductors led by the Department for Science, Innovation and Technology (DSIT). Similarly, our expertise in IoT platform security informed the development of the PSTI (Product Security and Telecommunications Infrastructure) Act, which came into force in April 2024. The act requires manufacturers of UK consumer connectable products (or ‘smart’ products) to meet minimum security requirements.
The global technology landscape is vast. The NCSC’s technical teams are small by comparison, so we work closely with national and international partners in industry, government and academia to meet the challenge and maximise our impact. The NCSC’s research institutes (based at the University of Bristol, University of Surrey, Imperial College London and Queen’s University Belfast) provide focal points for foundational research into critical aspects of cyber security. The communities they generate span all of our technical partnerships, and allow us to collaborate on a larger scale.
Artificial intelligence (AI)
The NCSC is pioneering research in the secure development of AI technologies, both through our own insights and through engaging with industry and academia.
In February 2024, the NCSC hosted the fourth iteration of WAIST (the Workshop on AI Security Technologies). This is an annual event delivered by the NCSC’s data science research team, and aims to build understanding of AI security vulnerabilities and strengthen the community working to mitigate them. This year's delegates included partners from across the Five Eyes and UK intelligence community, as well as industry, academia and other international agencies. By working together in this way, we can drive global security improvements in a critical technology whilst supporting UK entrepreneurship.
At the same time, the NCSC has deepened its cooperation with US counterparts, including the Cybersecurity and Infrastructure Security Agency (CISA), the AI Security Center (AISC), and the US AI Safety Institute. In November 2023, the NCSC published the Guidelines for Secure AI System Development in cooperation with industry experts and 21 other international agencies and ministries from across the world, including those from all members of the G7 group. The UK-led guidelines, the first of their kind to be agreed globally, aim to raise the cyber security levels of AI and help ensure that it is designed, developed, and deployed securely.
The NCSC are now working closely with DSIT to deliver the next stages of this work, developing the guidelines into a voluntary Code of Practice and global standard.
In the past year, the NCSC has also advanced its collaboration with the UK AI Safety Institute (AISI), which was set up by DSIT in November 2023. This partnership has focused on developing robust AI safety protocols. These efforts aim to ensure that AI technologies are deployed responsibly, reducing the risk of cyber harm due to AI models.
Post-quantum cryptography
In August 2024, a major milestone in post-quantum cryptography (PQC) was reached when NIST, the US national standards organisation, published three PQC algorithm standards. The same month, the NCSC published a paper describing what this means for UK organisations planning their migration to PQC. This is covered in more detail in the thought leadership paper: Post-quantum cryptography in this review.
In addition to hosting an event on PQC with UK regulators, on the international front we have ensured that the NCSC’s technical positions are prominent in work that the Central Digital & Data Office (part of DSIT) have led in the multi-national Digital Government Exchange, and offered a well-received thought leadership paper on the likely computational cost of quantum attacks on cryptography within standards bodies.
Crypt-Key
The NCSC collaborates with UK and international partners to protect our most sensitive information and enable our most important capabilities using our cryptographic expertise, known as ‘Crypt-Key'. Crypt-Key ensures the UK has high confidence in critical systems against the most advanced cyber threats. The NCSC’s National Crypt-Key Centre (NCKC) remains central to developing and maintaining secure communications for government, military, industry and national security partners within the UK, and to ensure interoperability with key allies as technology and threats evolve.
Throughout 2024, the NCSC produced and distributed thousands of highly secure cryptographic keys to protect the UK’s most sensitive data whilst continuing to build capabilities to support and key the next generation of cryptographic devices. This is only achieved in concert with the UK’s sovereign Crypt-Key industry, a national asset that as well as supporting NCSC directly has collaborated with us throughout 2024 to deliver world-leading encryption products to protect the UK’s most sensitive data, and that of our partners.
Working with the MOD the NCSC is also leading major transformation in Crypt-Key that will benefit the UK’s defence capabilities for many years to come. The Joint Crypt-Key Programme (JCKP) is a £2.6 billion initiative that protects the MOD's people, platforms, networks and information and provides high-grade cryptography for mission-critical services, enhancing cyber security and trust among allies. 2024 has seen JCKP gain ministerial approval of the next major phase of Crypt-Key transformation. This phase will deliver an adaptable and innovative architecture, ready to face the threats to defence over the coming decades, through collaboration between government and the UK sovereign Crypt-Key industry.
Principles Based Assurance
Principles Based Assurance (PBA) is the NCSC's approach to determining if a technology product is ‘secure enough’ for its intended use. This approach is a quite radical departure from traditional methods of technology assurance, in that the principles describe ‘what’ needs to be achieved, rather than ‘how’ this is carried out. For us, PBA describes the overarching aim, as opposed to providing specific granular instructions for users to follow.
The flexibility of PBA means it can be used to assure a wide range of different technology products. This year we've developed a range of new assurance services that use PBA for specific technology classes or customer needs, including those facing elevated threats. The first of these at-scale services will be Cyber Resilience Testing (CRT), which is designed to assess how resilient any connected technology is to attack from a connection to a less-trusted environment, such as the internet. PBA is applied to consider the engineering processes used to develop and support the technology throughout its life cycle, limiting vulnerabilities at every stage.
The CRT service (and associated services for cyber resilience when facing elevated threats) has been successfully piloted, laying the ground for formal launch. These services will be closely aligned with initiatives from international partners, and will prove a valuable tool in uplifting the cyber resilience of technology across all sectors.
Individual Cyber Defence
In response to the UK general election, we accelerated our development of the Individual Cyber Defence (ICD) service to provide practical support for high-risk individuals for UK officials and election candidates, as part of our Defending Democracy initiative, see Chapter 02 - Building the UK's cyber resilience. This followed the government’s announcements of attempts by the Russian Intelligence Services and China state-affiliated actors to carry out malicious activity targeting UK institutions and individuals, including parliamentarians.
The two new opt-in ICD services comprise:
- the Personal Internet Protection service, which adds an extra layer of security against spear-phishing by blocking access to known malicious domains on individual’s personal devices
- the Account Registration service, which alerts individuals if the NCSC becomes aware of a cyber incident impacting a personal account
The Personal Internet Protection service builds on the NCSC’s Protective DNS service which was developed principally for use by organisations. Since 2017, PDNS has provided protection at scale for millions of public sector users, handling more than 2.5 trillion site requests and preventing access to 1.5 million malicious domains.
Vulnerability Reporting Service
Since 2018, the NCSC Vulnerability Reporting Service (VRS) has allowed individuals to report vulnerabilities in government online services to the NCSC. As a thank you to those who submit vulnerabilities, finders are awarded HackerOne reputation points. In select cases we have also presented them with an NCSC challenge coin.
In addition, the NCSC also runs the Disclosure for Government Scheme, which enables government departments to manage their own vulnerability disclosure process while making use of the shared platform and triage service the VRS offers. We now have over 40 government organisations running their own disclosure programme through the scheme with a further 30 more currently being onboarded.
The VRS and the Disclosure for Government Scheme have both successfully been transitioned to the Government Cyber Coordination Centre (GC3). The NCSC, as part of GC3, will continue to support and encourage vulnerability disclosure across government. Of course, this wouldn’t be possible without the continued support of the finder community and the value they bring to government.
In the last 12 months we have seen the number of finders who have submitted vulnerabilities continue to grow to the highest numbers we have had so far. The table below shows the trend continuing, and it is predicted by the end of 2024 we will see an even higher number of individual finders participating in the VRS. We are working as part of GC3 to take feedback from the finder community and working with our platform and triage partners to continue to improve this engagement and encourage best practice amongst the vulnerability disclosure community.
Annual breakdown of researchers (vulnerability finders) | |
|---|---|
| Year | Count |
| 2018 | 12 |
| 2019 | 71 |
| 2020 | 109 |
| 2021 | 173 |
| 2022 | 194 |
| 2023 | 201 |
| 2024 | 188 |
Number of finders submitting vulnerabilities to the VRS, by year
Finders can report a vulnerability they find in any UK government online service. The table below shows a breakdown of submitted reports by department type. Three quarters of all reports submitted to the VRS are related to services run by local authorities. However, this is to be expected as the UK is split into over 10,000 local councils, each with an online presence and any number of digital service offerings.
Reports by department type | ||
|---|---|---|
| 2023 | 2024 | |
| Local government | 79.4% | 74.6% |
| Central government | 14.2% | 19.4% |
| Other departments | 6.4% | 6.0% |
The system owners using the Disclosure for Government scheme are from the following departments:
Local government providing services at local level from county level, down to town or parish councils. It can also include local public services such as GP surgeries, and fire and police services.
Central government departments with overall governance at a national level, such as national regulatory bodies. Some central government departments have their own vulnerability disclosure programme (VDP) through the Disclosure for Government scheme.
Other departments that comprise significant but out-of-scope cases, such as critical national infrastructure. ‘Other’ will also include any spam reports.
Cross-site scripting continues to be the most reported vulnerability, although the total is down from last year. Vulnerabilities that result in information disclosure have also decreased. We have also seen insecure direct object reference (IDOR) vulnerabilities break into the top 10. Of course, the most encouraging aspect is that these vulnerabilities are being reported and remediated as soon as possible.
Breakdown of top 10 (2023/24) | |||
|---|---|---|---|
| 2023 | Vulnerability type | 2024 | |
| 49.61% | Cross-site Scripting (XSS) - Reflected | 33.99% | |
| 14.27% | Information Disclosure | 18.50% | |
| 11.52% | Open Redirect | 11.55% | |
| 4.45% | Path Traversal | 6.69% | |
| 4.32% | Code Injection | 6.56% | |
| 3.80% | Improper Access Control - Generic | 5.64% | |
| 3.27% | Privilege Escalation | 4.59% | |
| 3.27% | Information Exposure Through Directory Listing | 4.59% | |
| 3.01% | SQL Injection | 4.20% | |
| 2.49% | Cross-site Scripting (XSS) - Generic | 3.67% | |
NCSC guidance
The NCSC produced a suite of ‘Defending Democracy’ guidance in advance of the general election, which included:
- new guidance for high-risk individuals (such as parliamentarians and election candidates) to help them improve the security of their personal devices and accounts
- guidance for political organisations offering advice to help IT practitioners implement security measures that will help prevent common cyber attacks
- guidance for organisations involved in coordinating elections, such as local authorities on steps to take to protect electoral management systems
In addition to the Guidelines for Secure AI System Development (which was jointly published by the NCSC, CISA, and 20 other partner agencies from around the world) the NCSC also updated the principles for the security of Machine Learning to reflect recent developments in the rapidly advancing world of AI. This included new sections on risks to large language model (LLM) systems, the importance of supply chain security and lifecycle management.
77
new or revamped guidance and blog publications
Other major guidance published this year included:
Vulnerability management
Principles to help organisations establish an effective vulnerability management process.
Principles for ransomware-resistant cloud backups
Helping to make cloud backups resistant to the effects of destructive ransomware.
Private Branch Exchange (PBX) best practice
Guidance helping organisations to protect their telephony systems from cyber attacks and telecoms fraud.
Website statistics
1.5m
user visits to ncsc.gov.uk
Top searched terms | |
|---|---|
| Cyber aware | 1,441 |
| Password(s) | 1,376 |
| Phishing | 858 |
Most accessed topics | |
| Phishing | 397k |
| Education | 200k |
| Passwords | 167k |
| CNI | 102k |
| AI | 60k |