General Atomics

Cyber agencies unveil new guidelines to secure edge devices

Cyber security chiefs in the UK and their international allies have issued a new set of guidelines to help manufacturers of edge devices make their products more secure and easier to investigate if a compromise occurs.



Image by Doucefleur / copyright Shutterstock

Published by GCHQ’s National Cyber Security Centre (NCSC) and cyber security agencies in Australia, Canada, New Zealand and the US, the new guidance highlights an increasing number of sophisticated malicious actors targeting vulnerabilities in edge devices.

Edge devices are internet-connected devices that sit at the ‘edge’ of a network, acting as entry points for data between local networks and the wider internet. Examples include routers, smart appliances, IoT devices, sensors and cameras, which can be particularly vulnerable to hackers as they often handle important data and connect directly to external networks.

The new guidelines encourage device manufacturers to include and enable standard logging and forensic features that are robust and secure by default, so that network defenders can more easily detect malicious activity and investigate following an intrusion.

They also set out the minimum standards for forensic visibility to help network defenders in securing organisational networks, both proactively and in response to a compromise.

NCSC Technical Director Ollie Whitehouse said: “In the face of a relentless wave of intrusions involving network devices globally our new guidance sets what we collectively see as the standard required to meet the contemporary threat.
    
“In doing so we are giving manufacturers and their customers the tools to ensure products not only defend against cyber attacks but also provide investigative capabilities require post intrusion.
    
“Alongside our international partners, we are focused on nurturing a tech culture that bakes security and accountability into every device, while enabling manufacturers and their customers to detect and investigate sophisticated intrusions.”

The guidance is part of a coordinated series of complementary publications on edge device security, released today in collaboration with agencies in Australia, New Zealand, Canada and the US, with input from the NCSC.

Earlier this year, the NCSC highlighted an Ivanti advisory about a critical security vulnerability in their remote access product, which enables employees to work from home and acts as an edge device to protect against external threats.

Related

Regional airports come top in best and worst UK airport rankings
Aircraft landing at Heathrow Airport
Regional airports come top in best and worst UK airport rankings
New Which? rankings reveal regional airports are delivering the best passenger experience while some of the UK's largest aviation gateways lost marks due to queues and customer satisfaction.
Aerospace

13 Sep 2026

Velocity Composites appoints Matthew Fowler as CFO
Matthew Fowler, New CFO of Velocity Composites plc
Velocity Composites appoints Matthew Fowler as CFO
As international aerospace and defence market opportunities increase, Matthew Fowler will support Velocity Composites' drive to assist aerospace manufacturers in improving efficiencies and optimising the supply of advanced composite materials across the production process.
‘The economic case stacks up’: UK chancellor renews government backing for Heathrow expansion
Heathrow Airport
‘The economic case stacks up’: UK chancellor renews government backing for Heathrow expansion
Former Chancellor Rachel Reeves decided in January 2025 to back a third runway as part of Labour's plans to boost economic growth.
Aerospace

11 Sep 2026

Velocity Composites appoints Matthew Fowler as CFO
Matthew Fowler, New CFO of Velocity Composites plc
Velocity Composites appoints Matthew Fowler as CFO
As international aerospace and defence market opportunities increase, Matthew Fowler will support Velocity Composites' drive to assist aerospace manufacturers in improving efficiencies and optimising the supply of advanced composite materials across the production process.
Royal Navy spends more than £123,000 on content creators
XC Excalibur uncrewed submarine for the Royal Navy
Royal Navy spends more than £123,000 on content creators
The Ministry of Defence confirmed the spend as it looks to reach new audiences and support recruitment.
Defence

11 Sep 2026

US private equity group agrees £1.1bn takeover of key UK defence supplier
Self sheilded storage box for contaminated nuclear waste
US private equity group agrees £1.1bn takeover of key UK defence supplier
Cerberus Capital Management has agreed a £1.1bn acquisition of Goodwin engineering businesses tied to sensitive UK defence, nuclear and naval supply chains.
Defence

11 Sep 2026

Skyrora completes hot-fire testing of advanced LEO engine
Skyrora engine test
Skyrora completes hot-fire testing of advanced LEO engine
Skyrora has conducted hot fire testing of its LEO engine at its Midlothian facility in Loanhead, demonstrating the potential of stronger, lightweight parts for future propulsion systems.
Member News Space

11 Sep 2026

UK spends nearly £30m on SpaceX satellite services as military shifts to Starshield
Starlink already offers unparalleled end-to-end user data encryption. Starshield uses additional high-assurance cryptographic capability to host classified payloads and process data securely, meeting the most demanding government requirements.
UK spends nearly £30m on SpaceX satellite services as military shifts to Starshield
The UK military operates around 1,000 SpaceX Starshield terminals after spending nearly £30m on Starshield and Starlink satellite communications.
Defence Space

11 Sep 2026

NewOrbit gains launch slot for first VLEO commercial mission
NEO1
NewOrbit gains launch slot for first VLEO commercial mission
Reading-based NewOrbit will conduct the first commercial mission on which any payload developer can fly, test and validate technology in Very Low Earth Orbit (VLEO), approximately 200-300km above the Earth.
Space

10 Sep 2026

Three government hacks in one week: Has Whitehall learnt its lesson?
Headshot for Trevor Dearing Director of Critical Infrastructure at Illumio
Three government hacks in one week: Has Whitehall learnt its lesson?
Trevor Dearing, Director of Critical Infrastructure at Illumio, argues that three government breaches in one week show why Whitehall must focus less on keeping attackers out and more on limiting the damage once they are inside.
Insights Security

12 Sep 2026

Lindy Cameron appointed as first female FCDO Permanent Under-Secretary
Lindy Cameron appointed as first female FCDO Permanent Under-Secretary
With vast experience across national security, diplomacy and development, Lindy Cameron has become the first female Permanent Under Secretary at the Foreign, Commonwealth and Development Office (FCDO).
Security

12 Sep 2026

MI5 chief warns next major threat may come from where the UK is not looking
MI5 Director General Ken McCallum
MI5 chief warns next major threat may come from where the UK is not looking
MI5 chief Sir Ken McCallum says the next major security shock may already be developing where intelligence agencies are not looking, 25 years after 9/11.
Security

11 Sep 2026