The NCSC research problem book
Pages
Page 8 of 21
CC6 - How do we incentivise secure by design technology?
Cyber resilience cannot be achieved without investing to fix the weaknesses in foundational technology at root.
How do we incentivise investment in - and markets for - foundational technology that is secure by design?
To achieve the necessary level of cyber resilience requires strengthening the security of our foundational technology. Solving security problems at root cause – and in technology that forms the foundations of technology stacks – will make it easier to produce, deploy and operate secure products and solutions using those foundations.
This requires a fundamental shift in approach across international technology markets: in production, consumption and operation. We can no longer accept the continued presence of well-known and avoidable classes of insecurities and vulnerability within our digital infrastructure.
Secure by Design principles provide a framework for technology producers to improve the resilience of their products and reduce the burden on consumers by fixing problems at root cause. But actors across the digital technology ecosystem currently lack incentives to develop, deploy, demand and operate products or solutions that embody the Secure by Design principles, particularly at the foundational level.
Addressing the fundamentals of supply and demand will require the application of economic, social, legal and organisational governance as well as commercial insight to implement the most appropriate technical engineering solutions within our digital infrastructure.
| See also Cyber-physical problem 2. How do we incentivise better security for cyber-physical systems? which more specifically focuses on incentivisation for cyber-physical systems and operational technology. |
Strands or sub problems
-
Transparency
An information asymmetry exists whereby purchasers of technology products often lack the means to judge the relative security of them. This information asymmetry may manifest differently for different products, solutions or services.
What are the common or repeated information asymmetries?
What steps can be taken to reduce information asymmetry?
What steps can be taken to increase the transparency of technology constitution by producers?
What steps can be taken to better understand whether – and how effectively – producers are building in security at a foundational level?
-
Consensus
Addressing the information asymmetry alone is not enough: market participants should also be motivated to seek more secure products.
Can we identify novel ways to drive narrative change so that foundational security is universally valued across digital technology markets?
How can the digital technology ecosystem be encouraged to take concerted action so that security is demanded at all levels of technology stacks?
-
Financial incentives
For there to exist a market incentive recognised as a strategic issue with industry decision makers, we need to show a clear return on investment in foundational security.
Does Secure by Design scale for everyone, or are there hidden costs for certain organisations or projects?
How can we help organisations to understand and potentially measure the level and implications of the technical debt they carry?
And how can we help organisations measure and compare the costs incurred by vulnerabilities – either through patching, suffering incidents, or some other cost – with long-term investment in more resilient technologies?
-
Liability
There is often a misalignment between those who bear the costs of insecurities – often end users and wider society – and those most able to build in better security.
How can we shift liability for technology and operational security failures to those able to address them at root cause?
What are the risks of doing so?
And how can manufacturers be held accountable for delivering on their claims for product security?
-
Complexity
Interventions in complex systems risk causing unintended, perverse outcomes. Better understanding how this happens will help policymakers anticipate and avoid these outcomes becoming entrenched.
How might interventions in the areas outlined above result in negative outcomes for cyber security?
What will be the impact of these interventions on other priority areas, such as growth, innovation and the move to net zero?
Why this is important
“Today, the investment levels from vendors do not adequately address modern cyber threats, especially given the chronic underinvestment in the past. This issue is further compounded by the lack of incentives and the generally low maturity levels among most customers. As a result, progress towards achieving cyber resilience is not happening at the necessary pace.
Most importantly, the cost of this underinvestment is ultimately borne not by the vendors, but downstream by customers, insurers, the government and society. This is partly because companies can contract away their liabilities related to software and hardware vulnerabilities, which may later be discovered and exploited by threat actors at great cost to customers and the government.
It is these market fundamentals that need to be addressed if we are to achieve our national aims for cyber resilience.”
Ollie Whitehouse, NCSC Chief Technology Officer