Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » UK NCSC Urges Firewall and VPN Vendors to Build Better Forensic Tools

UK NCSC Urges Firewall and VPN Vendors to Build Better Forensic Tools

Last updated:July 31, 2026
Human Written
  • The NCSC in the UK wants device makers to build better forensic tools into firewalls and VPN gateways to help investigators collect evidence after attacks.

  • Forensic observability means providing logging, telemetry, configuration state, and the ability to collect data from memory and storage.

  • The NCSC is cooperating with international allies to establish a reference framework for forensic surveillance in network appliances.

UK NCSC Urges Firewall and VPN Vendors to Build Better Forensic Tools

Recently, the National Cyber Security Centre (NCSC) in the UK made a call for manufacturers to develop the forensic capabilities of their devices. The agency requested that companies implement tools that aid in gathering evidence following a security violation. Notably, routers, firewalls, and other network devices are becoming major targets for attackers.

The technical director for Networking of NCSC, Chris A, announced the suggestion through a column published on July 29, stating that organizations need efficient means to analyze events occurring after a cyber incident.

They also need to assess whether a compromised device can still be trusted. The agency defined forensic observability as providing telemetry, logging, configuration state, and the ability to collect forensic data from memory and stored data.

What Forensic Observability Means

The NCSC wants manufacturers to include supported mechanisms for gathering evidence. Defenders should not have to rely on reverse engineering or vulnerability research.

The agency provided specific instructions on this matter in February 2025. Some of the major international agencies that participated in this project include those located in Australia, Canada, New Zealand, and the US.

Forensic observability has two main parts. First, it requires proper logging and telemetry. Devices should record events like authentication attempts, configuration changes, and system updates. Second, it needs the ability to collect forensic data. This includes both volatile data from running memory and non-volatile data from storage.

The guidance recommends that logs follow standard formats. All timestamps should use UTC time and include milliseconds. Devices should also support remote logging with encryption. This helps investigators gather evidence without physically accessing the device.

Volatile data collection is particularly important. This category of information includes vital pieces of information like process details, network connections, and memory files among others. Criminals are clever and attempt to erase the evidence of their attacks. Therefore, capturing the described type of data is very relevant.

Why this Matters Now

Monitoring devices like VPN gateways and firewalls are situated on the border of networks and handle information exchange between the systems of an organization and the public network. This makes them prime targets for attackers. Sophisticated threat actors increasingly target these devices; they exploit vulnerabilities and insecure design features to gain access.

Once compromised, these devices can give attackers a foothold in the network, and such a breach can remain hidden for long periods. The ability to detect and investigate breaches is critical, as seen in the Origin Energy data breach, where experts warn of follow-on scams. Many devices provide limited logging. This makes it hard to detect suspicious activity.

The NCSC aims to dispel several myths about forensic observability. Some manufacturers worry that such features could help attackers. The agency says well-designed features actually strengthen security. Others fear customers might react negatively. But clear telemetry can actually build trust through improved visibility.

Some believe implementing these features is too difficult. The NCSC says careful engineering makes it achievable. The key is to prioritize these capabilities early in the design process as waiting to add them later creates more challenges.

Global Cooperation and Next Steps

The NCSC is working with international partners on this issue. They are developing a reference framework for forensic surveillance. This will help manufacturers provide safe and reliable forensic access. The architecture will maintain strong security boundaries while enabling investigations.

Several vendors have already started investing in better logging and forensic capabilities. Sophos mentioned that they proved the value of prolonging the detection and response methods to firewall devices. They used the guidance of the NCSC to inform their own product roadmap.

The NCSC encourages buyers to push for these features. Organizations should include forensic observability in their evaluation criteria. The fastest way to drive adoption is for customers to demand these capabilities as standard.

Security experts note that this guidance reflects a broader shift in thinking. Cybersecurity is about more than just prevention; it also requires enabling rapid investigation and recovery when prevention fails.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.