Skip to main content
CybersecurityNetwork Security

NCSC Urges Vendors to Embed Forensic Observability in Network Devices

Technicians work on networking equipment in a well-lit network operations center with rows of servers and IT infrastructure.

"When incidents occur, organizations need reliable ways to understand what happened and assess whether a device can still be trusted. This is why forensic observability matters," Chris A, technical director networking and infrastructure at the National Cyber Security Centre (NCSC), wrote in a blog post on July 29.

Why the NCSC is targeting firewalls, VPN gateways and network devices

The NCSC's appeal is prompted by a trend the agency describes plainly: firewalls, VPN gateways and other network devices are increasingly targeted by attackers. In that context the agency argues defenders require built-in capabilities to investigate compromises without having to reverse engineer products or rely on specialist vulnerability research.

Chris A warned that “investigating a compromised device should not require discovering or exploiting vulnerabilities in the product itself.” Instead, he said, manufacturers should provide “supported mechanisms for gathering the evidence needed to investigate incidents, assess impact and restore trust in affected systems.”

What the NCSC means by “forensic observability”

The NCSC defines forensic observability as a combination of capabilities and transparency: telemetry, logging, configuration state, and the ability to collect forensic data from memory and data at rest. It also includes transparency about the software running on a device, either via version information or a software bill of materials (SBOM).

Those elements are presented as practical building blocks: structured logs and authenticated collection mechanisms enable defenders to investigate a compromise using “supported capabilities built into the product,” rather than ad hoc techniques that can prolong investigations and increase risk.

Manufacturers are falling short — and small design choices matter

According to the NCSC, many device manufacturers are not yet providing the capabilities described above. Chris A argued that this is not an insoluble engineering problem: “small design decisions can significantly reduce the time needed to triage and investigate incidents,” and forensic observability is achievable, “especially when prioritized early in the design process.”

The agency frames supported forensic access as a risk-reduction measure: by enabling the collection of reliable evidence, manufacturers can help incident response teams determine impact and restore trust in affected systems without forcing investigators to probe the product itself for vulnerabilities.

Dispelling three myths about observability

  • Observability helps attackers: The NCSC rejects this claim, saying that exposing telemetry will not provide more opportunities for exploitation. “Well-designed features like structured logging, authenticated collection mechanisms, and clearly defined forensic interfaces will strengthen rather than undermine security,” the agency wrote.
  • Customers will react negatively: The NCSC contends the opposite — clear telemetry and forensic capabilities can build trust through improved visibility.
  • It’s too difficult: While forensic observability requires “careful engineering,” the agency says it is absolutely achievable when prioritized early in design.

What this means for manufacturers, IT buyers, and incident responders

  • Manufacturers: The NCSC urges vendors to adopt its guidance on building forensic observability, first released in February 2025, and to provide supported mechanisms for evidence collection rather than leaving investigators to reverse-engineer devices.
  • IT buyers and procurement leaders: Chris A encouraged buyers to push vendors to provide telemetry, logging, configuration state information, forensic collection abilities and software transparency such as version information or SBOMs.
  • Incident response teams and security operators: If vendors follow the NCSC’s recommendations, responders should be able to investigate compromises faster and with more reliable evidence, reducing the need for specialist vulnerability research or reverse engineering.

The next step: a reference architecture with global partners

The NCSC said it is working with global partners to develop a reference architecture for forensic observability in network appliances and similar devices. Once finalised, the reference architecture should help manufacturers provide “safe, reliable forensic access” that does not diminish product security.

Until that architecture is complete, the NCSC’s February 2025 guidance and the July 29 blog post are the agency’s active instructions to vendors and buyers: prioritize observability early in design, provide supported collection mechanisms, and treat transparency as a component of trust.

Original story