NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 30 of 32
NCSC Engineering: practicing what we preach

The NCSC doesn’t just advise others on how to build secure systems. We design, develop and support our own systems too.
In line with the NCSC’s own guidance, we continuously evolve our business-critical and research platforms to ensure they remain secure, resilient, and fit for purpose. We apply the same principles we advocate to others, leading by example and embedding security into every stage of our engineering life cycle.
For example, for our highly sensitive Crypt-Key mission, we adopt the NCSC’s Design guidelines for high assurance products.
For our ‘internet-facing’ research and business projects, we put theory into practice using the principles found across the 10 Steps to Cyber Security and use the Cyber Assessment Framework.
Compliance through continuous assurance
We strive to continuously review and amend our policies and compliance stance. The devices that NCSC staff use must meet strict criteria to access environments, and non-compliant ones are automatically restricted from accessing key environments. Criteria includes:
- patch management (devices must be up-to-date with the latest cumulative updates; falling behind triggers access restrictions)
- endpoint protection (all devices are enrolled in endpoint protection systems)
- encryption and access control (on-device encryption, secure boot, and code integrity are enforced, and MFA is mandatory)
NCSC Engineering exemplifies the principles we advocate. For us, security is not just a checklist, it’s a mindset, and we foster a culture of secure engineering through exercising. By embedding security into every layer of our platforms, we strive to ensure that our systems are not only compliant but also robust, agile, and secure. Platform security is a never-ending challenge, and we face it head on. As threats evolve, so do we. Our roadmap for the next year includes; expanding zero-trust architecture, enhancing automation, and adopting a posture of ‘Verify explicitly, least privilege, and assume breach’
We’re not just advising the UK on cyber security - we’re living it!