Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Dev

July 30, 2026

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

July 30, 2026

Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

July 30, 2026
Facebook X (Twitter) Instagram
Thursday, July 30
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Dev
News

NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Dev

Team-CWDBy Team-CWDJuly 30, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The UK’s leading cybersecurity agency has urged device manufacturers to help incident response teams by making it easier for them to collect evidence after a compromise.

Chris A, technical director networking and infrastructure at the National Cyber Security Centre (NCSC), explained in a blog post on July 29 that firewalls, VPN gateways and other network devices are increasingly targeted by attackers. 

“When incidents occur, organizations need reliable ways to understand what happened and assess whether a device can still be trusted. This is why forensic observability matters,” he said.

“It enables defenders to investigate compromise using supported capabilities built into the product, rather than relying on reverse engineering, or specialist vulnerability research – as is still often the case.”

Read more on forensics: Google Launches Android Spyware Forensics Tool for High-Risk Users

As defined by the NCSC, forensic observability means providing telemetry, logging, configuration state, and the ability to collect forensic data from memory and data at rest. It also demands transparency about the software running on a device, either via version information or a software bill of materials (SBOM).

However, many device manufacturers are falling short, even though “small design decisions can significantly reduce the time needed to triage and investigate incidents,” Chris A continued.

“Investigating a compromised device should not require discovering or exploiting vulnerabilities in the product itself. Instead, manufacturers should provide supported mechanisms for gathering the evidence needed to investigate incidents, assess impact and restore trust in affected systems.”

Dispelling Three Observability Myths

Chris A explained that observability means empowering defenders to do their job properly post incident. However, there are still misconceptions about the topic which may be holding manufacturers back from making the required design improvements, he added.

These are:

  • Observability helps attackers: In fact, exposing telemetry will not provide more opportunities for exploitation. Well-designed features like structured logging, authenticated collection mechanisms, and clearly defined forensic interfaces will strengthen rather than undermine security, the NCSC said
  • Customers will react negatively: Clear telemetry and forensic capabilities can actually build trust through improved visibility, the agency claimed
  • It’s too difficult: Although it requires “careful engineering,” forensic observability is absolutely achievable, especially when prioritized early in the design process, the NCSC said

Chris A encouraged vendors to follow the NCSC’s guidance on building forensic observability in products, which was released in February 2025. He also urged IT buyers to push their vendors to provide such features.

In the meantime, the NCSC is working with global partners to develop a reference architecture for forensic observability in network appliances and similar devices.

Once finalized, this should help manufacturers provide “safe, reliable forensic access” which doesn’t diminish the security of their products.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
Team-CWD
  • Website

Related Posts

News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

July 30, 2026
News

Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

July 30, 2026
News

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

July 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

Beware of Winter Olympics scams and other cyberthreats

February 2, 2026

Is Poshmark safe? How to buy and sell without getting scammed

February 19, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.