The NCSC research problem book
Pages
Page 19 of 21
CP5 - How can we make use of emerging technologies in a secure way within cyber-physical systems?

How can we make use of emerging technologies in a secure way within cyber-physical systems?
Technology is always developing and we need to better understand how new and potentially disruptive technology could impact operations. This could cover a range of things: from materials, devices and mechanisms to algorithmic approaches, development strategies and design methodologies.
Cyber-physical systems often bring together technological developments that support real-world functions. But this could also result in unseen operational risks to address, especially if they are for use in an environment where safety is critical. Understanding the implications of new technology is critical if we are to introduce it into cyber-physical systems.
As sectors look to future systems to provide better insights into operations or higher levels of performance, it’s important to take stock of where these technologies connect with wider systems, and what we need to do to ensure secure integration.
This problem is about trying to understand a technology that might still be at an early stage, and to build a range of expertise to support how it develops, with security principles in mind.
Strands or sub-problems
-
Engineering
As we develop new technologies, it’s important to consider security early on to lower the risk of fundamental vulnerabilities in it. But creating secure engineering processes for unknown technologies is a challenge.
-
Policy
The impact of new technologies isn’t restricted to designing secure measures – it also needs oversight. We need to consider the policy requirements for these technologies when they are still in development, not once they’re operational.
-
Threat modelling
As new technology is developed, we need to consider the risk of it being used maliciously. This includes understanding the threats a new technology might pose, as well as identifying mitigations.
-
Risk
There is a need to create a clear and robust way to describe the security risk for technologies whose operational use is currently uncertain. This is such that as new technology begins to come through into operational use the risk assessment processes are adequately capable of representing new and evolving risks.