The NCSC research problem book
Pages
Page 1 of 21
Introducing the problem book
Cyber security is hard and it’s unlikely to get easier over the next decade. The NCSC views research as the way we can meet our greatest cyber security challenges in the long term. The UK National Cyber Strategy 2022 asks the NCSC to provide leadership to find the solutions to these challenges. To this end, we have built a research ‘problem book’.
Our aim is to guide cyber security research towards the most critical security challenges that we have identified as significant barriers to improving cyber security. The problem book starts by setting out the most significant ‘cross-cutting’ problems, where multiple and diverse disciplines need to collaborate to tackle the overarching problem. The newest problem book chapter covers hardware security. In future, we will add further chapters to the book which will cover other specific cyber disciplines, such as socio-technical or cyber physical.
The research book is intentionally not an exhaustive list of problems, but instead a set of focus points that we judge require coordinated and significant efforts over the next decade.
Who is it for?
The problem book is primarily intended for academia, but it may also be useful to private sector companies carrying out research or identifying innovation gaps.
How should it be used?
As outlined, the book describes the problems we believe need significant research activity over the next five to ten years. We have suggested some research strands of our own under the ‘sub-problems’ but also hope they will inspire you to think of your own research projects to help solve the overarching problems described.
For each problem, you will find:
- a description of the problem
- the NCSC’s view on some of the sub-problems within it, for specialist disciplines to work through
- a statement from an NCSC expert explaining why this problem is a priority
The chapters
The cross-cutting problems
The six cross-cutting problems span different disciplines and areas, looking at big questions like: how can we make phishing a thing of the past? How can we speed up the take-up of better security measures in OT? And the really hard question of how can we build systems we trust when there is a complex chain of individual components within them? Visit the cross-cutting problems chapter
The hardware security problems
Processors and microelectronics are now such a common feature of everyday devices that how they behave is foundational to every aspect of our digital lives. This makes it crucial to understand the impact they have on the security of a wider system. This chapter sets out four problem areas that we think will benefit from increased focus. They build up from the physical properties of an electronic device, through designing devices with security in mind, up to integrating these devices into wider systems. Visit the hardware security chapter
The cyber-physical problems
The cyber-physical chapter of the NCSC problem book brings together the high-level questions we think are important to secure the systems that bridge the gap between the physical and digital worlds. The problems here reflect only some of the challenges facing critical national infrastructure (CNI), operational technology (OT) and operators of cyber-physical equipment. It isn’t an exhaustive list, but instead provides a guide to the types of problems we collectively need to solve. Visit the cyber-physical problems chapter


