- What: UK NCSC urges manufacturers to improve device forensic observability
- Impact: Aims to help incident response teams collect evidence after breaches
Incident Response UK cybersecurity agency urges manufacturers to improve device forensic observability July 30, 2026 Share By SC Staff Examiner pressing DIGITAL FORENSIC INVESTIGATION on a touch screen interface. Business metaphor and technology concept. Magnifying glass icons represent analytical tools for investigative techniques. Based on information from Infosecurity Magazine, the UK's National Cyber Security Centre (NCSC) is calling on device manufacturers to enhance forensic observability in their products to aid incident response teams in evidence collection following a compromise. The NCSC highlights that network devices like firewalls and VPN gateways are increasingly targeted by attackers. Chris A, technical director at NCSC, stated that when incidents occur, organizations need reliable methods to understand what happened and assess device trustworthiness. Forensic observability, defined by the NCSC as providing telemetry, logging, configuration state, and the ability to collect forensic data from memory and at rest, is crucial for this. Manufacturers are urged to build supported mechanisms for gathering evidence, rather than defenders relying on reverse engineering or vulnerability research. The NCSC aims to dispel myths that observability aids attackers, deters customers, or is too difficult to implement, asserting that well-designed features enhance security and build trust. The agency is also collaborating with global partners to develop a reference architecture for forensic observability in network appliances. Source: Infosecurity Magazine SC Staff Related Incident Response Effective incident response plans elusive for most cybersecurity teams Steve Zurier July 29, 2026 Experts say untested incident response plans leave firms unprepared. Event logging Beyond 24/7 Monitoring: What CISOs Should Ask Before Choosing an MSSP SC Media Editorial Intelligence, reviewed by Dustin Sachs July 17, 2026 Evaluation should start with the operating problem your organization needs solved Incident Response Progress Software warns ShareFile users of external security threat SC Staff July 10, 2026 Progress Software has alerted ShareFile customers who utilize Storage Zone Controllers, which allow for on-premises file hosting while using ShareFile's cloud platform for management, to immediately shut down their servers. Related Events Cybercast Inside 1,500+ incidents: When trusted tools become attack vectors Mon Aug 10 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Boot Record Infector Computer Emergency Response Team (CERT) Stimulus You can skip this ad in 5 seconds