NCSC urges better forensic visibility in network devices

The UK National Cyber Security Centre (NCSC) is calling on manufacturers and customers to make forensic observability a standard feature of firewalls, VPN gateways and other network appliances.These d...

The UK National Cyber Security Centre (NCSC) is calling on manufacturers and customers to make forensic observability a standard feature of firewalls, VPN gateways and other network appliances.

These devices often sit at the edge of an organisation’s network and are increasingly targeted by capable threat actors. When one is compromised, defenders need to establish what occurred, determine the extent of the intrusion and decide whether the system can still be trusted. In many cases, however, the information available from the device is insufficient.

What forensic observability involves

Forensic observability is the ability to examine a device’s current and historical activity through dependable, supported functions. Relevant capabilities include detailed telemetry and logs, configuration history, and the collection of forensic evidence from memory and storage.

Transparency about the software running on an appliance is also important. Clear version data and a software bill of materials can help investigators identify affected components and reduce the time needed to assess an incident. Evidence should be trustworthy and designed to resist tampering by an attacker.

Reducing reliance on workarounds

The NCSC says incident response should not depend on reverse engineering, improvised methods or exploiting vulnerabilities in the product being investigated. Such approaches can leave defenders with fewer practical tools than the attacker and may delay containment and recovery.

In 2025, the agency published guidance covering digital-forensics and protective-monitoring specifications for producers of network devices and appliances. It is also working with international partners on a reference architecture intended to help manufacturers provide secure, reliable forensic access without weakening core security controls.

Shared responsibility

Some vendors are already improving logging, evidence collection and system transparency. Sophos, reflecting on its Pacific Rim campaign, said extending detection and response beyond endpoints to firewall devices helped reduce customer harm. The company said the experience reinforced the need to plan for the failure of perimeter systems, rather than assuming they can always be protected.

For buyers, forensic capabilities should form part of procurement and security evaluations. Vendors, meanwhile, should treat observability as a product requirement. Wider adoption would help organisations investigate more quickly, give manufacturers clearer incident insight and make recovery less dependent on scarce specialist expertise.