The NCSC research problem book
Pages
Page 16 of 21
CP2 - How do we incentivise better security for cyber-physical systems?
How do we incentivise better security for cyber-physical systems?
In an ideal scenario, every cyber-physical system would be safe and secure. But in reality there are numerous competing objectives that mean security isn’t always the top priority. For example, operational requirements in the areas of safety concerns or regulations may sometimes be at odds with security goals.
Trying to bridge these perceived trade-offs is a challenge, and there are often barriers. Fundamentally we need to identify how and where the barriers are, so we can develop ways to support the organisations that most need to improve their security practices.
In cyber-physical systems, the requirements may differ depending on the sector and industry, especially if it’s regulated. Creating ‘better’ means incentivising more proactive security, and pushing up critical sectors above the baseline to support a more resilient UK.
Addressing this problem also brings together skills from the engineering disciplines and social sciences to generate practical solutions.
| See also Cross-cutting problem 6. How do we incentivise secure by design technology? which provides the overall context. |
Strands or sub-problems
-
Economics
In any organisation, security is subject to many of the same drivers and must compete with other areas for attention and funding. There are often additional security overheads in cyber-physical systems, which can have an economic impact on uptake. This is about investigating the economic factors that may limit progress and working out how to address these challenges.
-
Policy
When considering the incentives for cyber-physical security, we need to look at all aspects of how to encourage change, including regulatory or policy considerations. Identifying how and where these decisions can benefit or hinder better security can improve how we talk about the security of cyber-physical systems.
-
Culture
Overcoming the barriers in cyber-physical security requires more than financial and policy drivers – it also needs us to think about how we develop cultural change and acceptance. This can help to support new working practices.