Site navigation

NCSC Sets New Edge Device Security Standards

Graham Turner

,

Edge device security
New guidelines from GCHQ’s National Cyber Security Centre (NCSC) and international partners outline security and forensic standards for edge device manufacturers.

A new set of guidlines for the manufacturers of Edge devices to make their offerings more secure and easier to invesigate if an incident occurs has been released by the GCHQ’s National Cyber Security Centre (NCSC).

Edge devices, such as routers, IoT devices, smart appliances, sensors, and cameras, serve as critical entry points between local networks and the internet. These devices often handle sensitive data, making them prime targets for hackers.

The new recommendations urge manufacturers to implement standardised logging and forensic features by default, enabling more effective detection and investigation of malicious activity. They also establish minimum forensic visibility standards to bolster both proactive security measures and post-compromise responses for organisations.

In a comment given on the organisation’s news page, NCSC technical director Ollie Whitehouse said: “In the face of a relentless wave of intrusions involving network devices globally our new guidance sets what we collectively see as the standard required to meet the contemporary threat.

“In doing so we are giving manufacturers and their customers the tools to ensure products not only defend against cyber attacks but also provide investigative capabilities require post intrusion.”

“Alongside our international partners, we are focused on nurturing a tech culture that bakes security and accountability into every device, while enabling manufacturers and their customers to detect and investigate sophisticated intrusions”

Last month, the organisation issued guidance for critical infrastructure organisations in a bid to help them secure their operational technology (OT) systems from growing cyber-threats.


Recommended reading


The advice set out key security considerations for firms when purchasing OT products, aiming to help OT owners and operators find those that follow secure-by-design principles, ensuring systems have a cyber-resilient foundation and minimise the risks posed by cyber-attacks. 

On issuing the advice, the NCSC warned that threat actors often target OT products, rather than specific organisations, because they can easily replicate attacks across multiple victims and sectors.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data