NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 32 of 32
'Radical transparency' - the key to enabling better cyber security outcomes

Technology is currently opaque, and that leads to adverse cyber security outcomes which favour malfeasant threat actors.
Understanding in detail the cyber security of a modern technology product or system requires expert knowledge, time and skill. Security professionals must patiently conduct deep analysis, identify weaknesses, and then work with vendors and systems integrators on a resolution.
This approach obviously does not scale, leading to the worrying observation that it is easier for an attacker to get useful data – either through reverse engineering or internet scanning – than it is for a defender. The former only needs to dive deep on one part of a system in order to identify any weakness, and exploit it. In contrast, defenders require a complete understanding in order to the protect the entire system (or system of systems).
The NCSC believes we have to address this imbalance in cost and complexity that at the moment favours malfeasant threat actors.
Previous initiatives have encouraged the adoption of Software Bills of Materials (SBOMs). And whilst SBOMs (and HBOMs) can provide organisations with better insight into their supply chains, they are not enough on their own. We need to be much clearer about which cyber security decisions are important, and work hard to make better supporting evidence available. A lot of those decisions do not concern technology; they involve management of business/legal risk or organisational governance. Our job is to translate technical insights to justify investment, to support a different direction or to defend a course of action, potentially in court.
Sausages and incentives
For some time now, the NCSC has been calling for more effort to improve transparency in technology to enable better cyber security outcomes. This is across hardware, software and services.
At this year’s CYBERUK technology plenary, the NCSC’s Ollie Whitehouse quipped that “we know more about what’s in our sausages than our software, and that's probably not right for 2025”. The serious point here, is that making it easier to identify the technology products in the supply chain (and what those products comprise) would enable developers to compete on security, and support better-informed decision making by customers.
Clearly there are limits; details of vulnerabilities can accelerate exploitation, and commercial sensitivities need to be respected. Nonetheless, there must be more we can do to expose information needed in the appropriate way to provide evidence and insights for impactful cyber security decision making.
Here are some of the ‘important questions’ which the NCSC – and other cyber defenders – would like to be able to answer in a timely, consistent, and accurate manner.
Prior to purchase:
-
Do you have evidence that this product is secure by design and secure by default?
-
How long will the product be supported for?
-
Will it be updated automatically?
-
Will all the components also be updated automatically?
-
More generally, what is the burden of secure operation, and who has to shoulder that burden?
-
Does it need to be rebooted/reflashed to install updates?
-
What information (telemetry) could be collected by the manufacturer? What level of security monitoring is provided in return?
-
How easily can a device recover from a given exploit? Can recovery be completed remotely?
-
How are vulnerabilities in the product managed? Is there an audited record of decisions made on how/if to fix particular issues?
-
Is there a product/support roadmap?
During operation:
-
What is the most recent version available?
-
How will I know a new update/version is available? How will I know it has been successfully installed?
-
How can I easily and remotely get the version information / asset management information?
-
Is the product exposed to vulnerability XYZ, and if so what should I do about it?
-
How can I check the integrity of the product?
-
Do I need to replace the product?
-
Is the product internet-facing? Does it need to be?
-
How is the product configured and is this as expected?
-
What software version is loaded?
Organisations that make it simple to answer these questions could be described as being ‘radically transparent.’ Most of these questions should not be difficult to answer, in theory. In practice, however, they may involve manual processes and spreadsheets, or tracing queries through a product's supply chain. All of which are likely to be time consuming. A complex system comprising many products, services and third parties adds further layers of complexity.
Improving and automating the process of asking these questions (and getting answers to them) has many benefits. Data collected becomes more accurate and up to date (potentially even near real time). Suppliers have clarity in terms of what information they have to provide and when. Information can be shared appropriately (for example, one can confidently ask if a given product is up to date without having to personally check each sub-component, or revealing potentially sensitive product details).
In the longer term, radical transparency allows vendors with sound practices to demonstrate their commitment to cyber security more convincingly.
This information is not just of value to individual customers, but could also inform longer term decisions by potential investors.
Transparency is also required in hardware, which is increasingly complex and comes with many of the same considerations that apply to software. In contemporary semiconductors there may be intellectual property from many organisations present in a single chip, each with distinct security considerations.
Creating standards to formalise the above would ensure clarity on vendor responsibilities at each stage of the supply chain. System owners could more rapidly aggregate consistent data and use it to inform operational decisions.
Our approach should be to keep initial queries relatively simple, and concentrate on aggregating accurate and useful information at scale and at speed. It is important to be clear about vendor responsibility to provide this information; it will need to be propagated via the contractual relationships that underpin all stages of the supply chain.
Getting this right will mean that information will be available when needed, but not aggregated unnecessarily. It will be important for vendors to demonstrate ability (and commitment) to providing timely information. We will then be taking steps towards greater confidence in the ability of our digital ecosystem to provide the resilience society requires.