Why the NCSC Is Turning Up the Heat on Device Vendors
When a firewall gets compromised, the clock starts ticking. Incident responders need to know exactly what happened, how deep the intrusion goes, and whether the device can ever be trusted again. But too often, that evidence is locked away inside proprietary hardware and software.
The UK’s National Cyber Security Centre (NCSC) has had enough. In a blog post on July 29, Chris A, the agency’s technical director for networking and infrastructure, laid out a clear demand: device manufacturers must embed forensic observability into their products from the ground up.
Firewalls, VPN gateways, and other network appliances are prime targets for attackers. When they fall, organizations are left scrambling. “When incidents occur, organizations need reliable ways to understand what happened and assess whether a device can still be trusted,” Chris A wrote. “This is why forensic observability matters.”
The concept is straightforward: give defenders supported, built-in capabilities to investigate a compromise, rather than forcing them to reverse-engineer the device or hunt for vulnerabilities just to collect basic forensic data. That’s still the norm in many shops, and it’s a costly, time-consuming nightmare.
What Forensic Observability Actually Means
According to the NCSC, forensic observability isn’t a single feature. It’s a bundle of capabilities that should be baked into every network device:
- Comprehensive telemetry and structured logging
- Access to configuration state
- Ability to collect forensic data from memory and data at rest
- Transparency about the software running on the device, either via version info or a software bill of materials (SBOM)
That last point matters more than most people realize. If you don’t know exactly what software is on a device, you can’t assess its exposure to known vulnerabilities. An SBOM changes that equation entirely.
Chris A emphasized that investigating a compromised device “should not require discovering or exploiting vulnerabilities in the product itself.” Instead, manufacturers should provide supported mechanisms for gathering evidence, assessing impact, and restoring trust in affected systems.
The NCSC isn’t asking for the moon here. “Small design decisions can significantly reduce the time needed to triage and investigate incidents,” he noted.
Three Myths That Hold Vendors Back
The NCSC’s technical director also took aim at misconceptions that keep manufacturers from making these design improvements. These myths, he argued, are preventing progress in network device security.
Myth 1: Observability Helps Attackers
Some vendors worry that exposing telemetry gives attackers a roadmap. The NCSC disagrees. Well-designed features like structured logging, authenticated collection mechanisms, and clearly defined forensic interfaces strengthen security rather than undermine it. Attackers don’t need your logs to exploit your device; they need your vulnerabilities.
Myth 2: Customers Will React Negatively
The fear here is that customers will see forensic features as complexity or backdoors. The reality, per the NCSC, is the opposite. Clear telemetry and forensic capabilities build trust through improved visibility. Buyers want to know what their devices are doing, especially after an incident.
Myth 3: It’s Too Difficult to Build
Yes, forensic observability requires careful engineering. But it’s absolutely achievable, especially when prioritized early in the design process. Waiting until after a product ships makes it exponentially harder — and far more expensive.
What Vendors and Buyers Should Do Now
The NCSC isn’t just publishing blog posts and walking away. The agency released formal guidance on building forensic observability into products back in February 2025. Now it’s pushing vendors to follow it.
Chris A also had a message for IT buyers: push your vendors. If you’re procuring firewalls, VPN gateways, or any other network appliance, ask what forensic capabilities are built in. Demand SBOMs. Make forensic observability a checkbox in your procurement process.
In parallel, the NCSC is working with global partners to develop a reference architecture for forensic observability in network appliances. Once finalized, this should give manufacturers a blueprint for providing “safe, reliable forensic access” without weakening the security of their products.
For incident response teams, this shift can’t come soon enough. The gap between what attackers exploit and what defenders can investigate is a serious problem. Forensic observability closes that gap — but only if vendors actually build it.
Want to dig deeper into related topics? Check out our coverage of Android spyware forensics tools and the broader push for software bill of materials adoption in enterprise security.