Skip to main content
Annual Review

NCSC Annual Review 2025

Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.

Page 32 of 32

'Radical transparency' - the key to enabling better cyber security outcomes

Technology is currently opaque, and that leads to adverse cyber security outcomes which favour malfeasant threat actors.

Understanding in detail the cyber security of a modern technology product or system requires expert knowledge, time and skill. Security professionals must patiently conduct deep analysis, identify weaknesses, and then work with vendors and systems integrators on a resolution. 

This approach obviously does not scale, leading to the worrying observation that it is easier for an attacker to get useful data – either through reverse engineering or internet scanning – than it is for a defender. The former only needs to dive deep on one part of a system in order to identify any weakness, and exploit it. In contrast, defenders require a complete understanding in order to the protect the entire system (or system of systems). 

The NCSC believes we have to address this imbalance in cost and complexity that at the moment favours malfeasant threat actors.

Previous initiatives have encouraged the adoption of Software Bills of Materials (SBOMs). And whilst SBOMs (and HBOMs) can provide organisations with better insight into their supply chains, they are not enough on their own. We need to be much clearer about which cyber security decisions are important, and work hard to make better supporting evidence available. A lot of those decisions do not concern technology; they involve management of business/legal risk or organisational governance. Our job is to translate technical insights to justify investment, to support a different direction or to defend a course of action, potentially in court.


During operation:

  • What is the most recent version available?

  • How will I know a new update/version is available? How will I know it has been successfully installed?  

  • How can I easily and remotely get the version information / asset management information?

  • Is the product exposed to vulnerability XYZ, and if so what should I do about it?

  • How can I check the integrity of the product?

  • Do I need to replace the product?

  • Is the product internet-facing? Does it need to be?

  • How is the product configured and is this as expected?

  • What software version is loaded?

Organisations that make it simple to answer these questions could be described as being ‘radically transparent.’ Most of these questions should not be difficult to answer, in theory. In practice, however, they may involve manual processes and spreadsheets, or tracing queries through a product's supply chain. All of which are likely to be time consuming. A complex system comprising many products, services and third parties adds further layers of complexity.

Improving and automating the process of asking these questions (and getting answers to them) has many benefits. Data collected becomes more accurate and up to date (potentially even near real time). Suppliers have clarity in terms of what information they have to provide and when. Information can be shared appropriately (for example, one can confidently ask if a given product is up to date without having to personally check each sub-component, or revealing potentially sensitive product details).

In the longer term, radical transparency allows vendors with sound practices to demonstrate their commitment to cyber security more convincingly.

This information is not just of value to individual customers, but could also inform longer term decisions by potential investors.

Transparency is also required in hardware, which is increasingly complex and comes with many of the same considerations that apply to software. In contemporary semiconductors there may be intellectual property from many organisations present in a single chip, each with distinct security considerations.

Creating standards to formalise the above would ensure clarity on vendor responsibilities at each stage of the supply chain. System owners could more rapidly aggregate consistent data and use it to inform operational decisions.

Our approach should be to keep initial queries relatively simple, and concentrate on aggregating accurate and useful information at scale and at speed. It is important to be clear about vendor responsibility to provide this information; it will need to be propagated via the contractual relationships that underpin all stages of the supply chain. 

Getting this right will mean that information will be available when needed, but not aggregated unnecessarily. It will be important for vendors to demonstrate ability (and commitment) to providing timely information. We will then be taking steps towards greater confidence in the ability of our digital ecosystem to provide the resilience society requires.

Published

Reviewed

Version

1.0