Skip to main content
Annual Review

NCSC Annual Review 2024

Looking back at the National Cyber Security Centre's eighth year and its key developments and highlights, between 1 September 2023 and 31 August 2024.

Page 15 of 16

Chapter 04: Keeping pace with evolving technology

The NCSC's expertise across the technology stack helps the UK respond to emerging threats and opportunities.

As the national technical authority for cyber security, it’s vital that the NCSC keeps pace with evolving technology, particularly where significant changes affect our critical technologies, systems and sectors.

Some of these changes directly impact end users, such as understanding how we can reduce our reliance on passwords for authentication and move to passkeys. Other changes impact developers, for example improving software development practices to reduce vulnerabilities in the apps and devices embedded throughout our connected society. The NCSC requires expertise throughout this technology stack to help the UK prepare and respond to emerging opportunities, risks and threats. 

The NCSC invests in extensive internal research into emerging technologies to explore new ways to reduce harm at scale. Some new technologies – such as AI – are potentially disruptive, and their development cannot be ignored. Many others evolve more slowly, but continue to have a huge effect on how resilient our systems are. For example, cloud and the ‘internet of things’ (IoT) can no longer be described as new, but they’re so ubiquitous that small changes to the standards or technologies they incorporate can have far reaching impact. 

Research is long-term work that doesn’t always result in short-term benefits. However, the expertise we gain informs everything we do and allows us to provide expert authoritative input to drive our strategic aims which manifest elsewhere in government, such as our work supporting research into semiconductors led by the Department for Science, Innovation and Technology (DSIT). Similarly, our expertise in IoT platform security informed the development of the PSTI (Product Security and Telecommunications Infrastructure) Act, which came into force in April 2024. The act requires manufacturers of UK consumer connectable products (or ‘smart’ products) to meet minimum security requirements. 

The global technology landscape is vast. The NCSC’s technical teams are small by comparison, so we work closely with national and international partners in industry, government and academia to meet the challenge and maximise our impact. The NCSC’s research institutes (based at the University of Bristol, University of Surrey, Imperial College London and Queen’s University Belfast) provide focal points for foundational research into critical aspects of cyber security. The communities they generate span all of our technical partnerships, and allow us to collaborate on a larger scale. 








Other major guidance published this year included:

Vulnerability management
Principles to help organisations establish an effective vulnerability management process.

Principles for ransomware-resistant cloud backups
Helping to make cloud backups resistant to the effects of destructive ransomware.

Private Branch Exchange (PBX) best practice
Guidance helping organisations to protect their telephony systems from cyber attacks and telecoms fraud.

Website statistics

1.5m

user visits to ncsc.gov.uk

Top searched terms

Cyber aware1,441
Password(s)1,376
Phishing858

Most accessed topics

Phishing397k
Education200k
Passwords167k
CNI102k
AI60k

 

Reviewed

Version

1.0

Written for