NCSC Urges Network Device Vendors to Build In Forensic Observability
The UK's National Cyber Security Centre (NCSC) is calling on network device manufacturers to embed forensic observability features directly into their products to aid incident response.
The UK's National Cyber Security Centre (NCSC) is urging manufacturers of critical network infrastructure, such as firewalls and VPN gateways, to proactively integrate enhanced forensic observability capabilities into their devices. This initiative aims to empower security teams with the tools needed to conduct more efficient and effective investigations following a cyber incident.
According to Chris A, technical director for networking and infrastructure at the NCSC, network devices are increasingly becoming prime targets for attackers. When compromises occur, organizations require reliable methods to understand the scope of the breach, determine the trustworthiness of affected devices, and facilitate rapid remediation. Forensic observability, as defined by the NCSC, encompasses the provision of detailed telemetry, robust logging, configuration state information, and the ability to extract forensic data from both device memory and stored data.
Furthermore, the NCSC emphasizes the importance of transparency regarding the software running on these devices. This includes providing clear version information or, ideally, a comprehensive Software Bill of Materials (SBOM). The agency notes that many manufacturers currently fall short of these expectations, despite the fact that even minor design choices can significantly reduce the time and effort required for incident triage and investigation.
The NCSC seeks to dispel common misconceptions that might hinder manufacturers from adopting these security enhancements. One such myth is that exposing telemetry data would provide attackers with additional opportunities for exploitation. The NCSC counters that well-designed features, such as structured logging and authenticated data collection mechanisms, actually strengthen security rather than undermine it. Another misconception is that customers would react negatively to increased visibility; instead, the agency posits that clear forensic capabilities can build customer trust.
Finally, the NCSC addresses the concern that implementing forensic observability is too technically challenging. While acknowledging that it requires careful engineering, the agency asserts that these capabilities are entirely achievable, particularly when prioritized early in the product design lifecycle. The NCSC encourages vendors to consult its guidance on building forensic observability, released in February 2025, and also urges IT buyers to advocate for these features from their suppliers.
In parallel with its call to industry, the NCSC is collaborating with international partners to develop a reference architecture for forensic observability in network appliances and similar devices. This framework is intended to guide manufacturers in providing secure and reliable forensic access mechanisms that do not compromise the overall security posture of their products. The goal is to standardize and simplify the process, making it easier for defenders to investigate and respond to threats effectively.