General Atomics

Cyber agencies unveil new guidelines to secure edge devices

Cyber security chiefs in the UK and their international allies have issued a new set of guidelines to help manufacturers of edge devices make their products more secure and easier to investigate if a compromise occurs.



Image by Doucefleur / copyright Shutterstock

Published by GCHQ’s National Cyber Security Centre (NCSC) and cyber security agencies in Australia, Canada, New Zealand and the US, the new guidance highlights an increasing number of sophisticated malicious actors targeting vulnerabilities in edge devices.

Edge devices are internet-connected devices that sit at the ‘edge’ of a network, acting as entry points for data between local networks and the wider internet. Examples include routers, smart appliances, IoT devices, sensors and cameras, which can be particularly vulnerable to hackers as they often handle important data and connect directly to external networks.

The new guidelines encourage device manufacturers to include and enable standard logging and forensic features that are robust and secure by default, so that network defenders can more easily detect malicious activity and investigate following an intrusion.

They also set out the minimum standards for forensic visibility to help network defenders in securing organisational networks, both proactively and in response to a compromise.

NCSC Technical Director Ollie Whitehouse said: “In the face of a relentless wave of intrusions involving network devices globally our new guidance sets what we collectively see as the standard required to meet the contemporary threat.
    
“In doing so we are giving manufacturers and their customers the tools to ensure products not only defend against cyber attacks but also provide investigative capabilities require post intrusion.
    
“Alongside our international partners, we are focused on nurturing a tech culture that bakes security and accountability into every device, while enabling manufacturers and their customers to detect and investigate sophisticated intrusions.”

The guidance is part of a coordinated series of complementary publications on edge device security, released today in collaboration with agencies in Australia, New Zealand, Canada and the US, with input from the NCSC.

Earlier this year, the NCSC highlighted an Ivanti advisory about a critical security vulnerability in their remote access product, which enables employees to work from home and acts as an edge device to protect against external threats.

Related

Manufacturers warn Government over UK steel import tariffs
UK steel manufacturing
Manufacturers warn Government over UK steel import tariffs
As a petition highlighting the negative impact of Government-imposed steel import tariffs on UK manufacturing surpasses 10,000 signatures, industry calls for an urgent review.
UK airport reliability ranked: Heathrow leads globally while Manchester is near the bottom
Heathrow Airport, British Airways Airbus A380 engine, Feb 2015
UK airport reliability ranked: Heathrow leads globally while Manchester is near the bottom
A new study ranks Heathrow as the UK's most reliable airport, with Edinburgh ahead of Gatwick and Stansted, and Manchester near the bottom globally.
Aerospace

5 Aug 2026

Gatwick Northern Runway expansion clears Court of Appeal challenge
Gatwick Airport
Gatwick Northern Runway expansion clears Court of Appeal challenge
London Gatwick’s plans to bring its existing Northern Runway into routine…
Aerospace Most Read

5 Aug 2026

Manufacturers warn Government over UK steel import tariffs
UK steel manufacturing
Manufacturers warn Government over UK steel import tariffs
As a petition highlighting the negative impact of Government-imposed steel import tariffs on UK manufacturing surpasses 10,000 signatures, industry calls for an urgent review.
BAE Systems to maintain Royal Navy torpedoes
Spearfish
BAE Systems to maintain Royal Navy torpedoes
A new £135 million contract to has been awarded to BAE Systems to maintain and repair Royal Navy torpedo weapons.
Defence Member News

5 Aug 2026

Tempest demonstrator in final assembly ahead of planned first flight in 2027
The bulbous central fuselage section of BAE Systems' CAFD demonstrator is seen underway at the firm's facility in Samlesbury, Lancashire, in July 2026. Image: BAE Systems
Tempest demonstrator in final assembly ahead of planned first flight in 2027
BAE Systems' new Tempest prototype, otherwise known as the Combat Air Flying Demonstrator (CAFD), has passed the halfway point in final assembly, with its rollout and first flight remaining on track for 2027.
SSTL racks up smart storage solution
SSTL racks up smart storage solution
A smart racking solution from Altus has helped Surrey Satellite Technology Limited (SSTL) integrate its materials management processes.
Member News Space

5 Aug 2026

Seraphim Space deploys first capital from £137m C share raise
Seraphim Space deploys first capital from £137m C share raise
The investments have been made in businesses involved in key areas that are driving the next phase of growth within the space sector.
Member News Space

4 Aug 2026

AccelerComm underpins Eclipse Space’s 5G physical layer for satellite constellations
UK From Space-Telecom
AccelerComm underpins Eclipse Space’s 5G physical layer for satellite constellations
Flight-proven 5G non-terrestrial network (NTN) tech from Southampton based AccelerComm, is supporting a scalable direct-to-device and broadband architecture from Starlink veterans behind Eclipse Space.
Member News Space

31 Jul 2026

Manufacturers warn Government over UK steel import tariffs
UK steel manufacturing
Manufacturers warn Government over UK steel import tariffs
As a petition highlighting the negative impact of Government-imposed steel import tariffs on UK manufacturing surpasses 10,000 signatures, industry calls for an urgent review.
UK AISI test exposes AI agent’s attempt to plant malicious code
Lockheed martin cybersecurity
UK AISI test exposes AI agent’s attempt to plant malicious code
The UK’s AI Security Institute uncovered unexpectedly autonomous and deceptive behaviour during a cyber evaluation, including an attempted attack on open-source software.
Most Read Security

5 Aug 2026

CAA explores future for BVLOS drone ops
Amazon PrimeAir MK30 drone
CAA explores future for BVLOS drone ops
A new report from the UK Civil Aviation Authority (CAA) outlines a vision for enabling routine Beyond Visual Line of Sight (BVLOS) commercial drone operations alongside existing UK airspace users.
Aerospace Security

3 Aug 2026