Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Cyber agencies unveil new guidelines to secure edge devices

Security

Cyber agencies unveil new guidelines to secure edge devices

Cyber security chiefs in the UK and their international allies have issued a new set of guidelines to help manufacturers of edge devices make their products more secure and easier to investigate if a compromise occurs.

Image by Doucefleur / copyright Shutterstock

Published by GCHQ’s National Cyber Security Centre (NCSC) and cyber security agencies in Australia, Canada, New Zealand and the US, the new guidance highlights an increasing number of sophisticated malicious actors targeting vulnerabilities in edge devices.

Advertisement
ODU RT

Edge devices are internet-connected devices that sit at the ‘edge’ of a network, acting as entry points for data between local networks and the wider internet. Examples include routers, smart appliances, IoT devices, sensors and cameras, which can be particularly vulnerable to hackers as they often handle important data and connect directly to external networks.

The new guidelines encourage device manufacturers to include and enable standard logging and forensic features that are robust and secure by default, so that network defenders can more easily detect malicious activity and investigate following an intrusion.

They also set out the minimum standards for forensic visibility to help network defenders in securing organisational networks, both proactively and in response to a compromise.

Advertisement
ODU RT

NCSC Technical Director Ollie Whitehouse said: “In the face of a relentless wave of intrusions involving network devices globally our new guidance sets what we collectively see as the standard required to meet the contemporary threat.
    
“In doing so we are giving manufacturers and their customers the tools to ensure products not only defend against cyber attacks but also provide investigative capabilities require post intrusion.
    
“Alongside our international partners, we are focused on nurturing a tech culture that bakes security and accountability into every device, while enabling manufacturers and their customers to detect and investigate sophisticated intrusions.”

The guidance is part of a coordinated series of complementary publications on edge device security, released today in collaboration with agencies in Australia, New Zealand, Canada and the US, with input from the NCSC.

Earlier this year, the NCSC highlighted an Ivanti advisory about a critical security vulnerability in their remote access product, which enables employees to work from home and acts as an edge device to protect against external threats.

Advertisement
General Atomics LB
Axon introduces new products and partnerships

Security

Axon introduces new products and partnerships

24 April 2025

Axon has introduced a number of new products and partnerships, expanding its real-time network and public safety ecosystem.

Heathrow Airport extends partnership with Safe365

Aerospace Security

Heathrow Airport extends partnership with Safe365

23 April 2025

Heathrow Airport has renewed its commitment to workplace and passenger safety by extending its partnership with Safe365 - a New Zealand-based safety technology company - for a further three years, which was witnessed in a ceremony attended by New Zealand Prime Minister Christopher Luxon.

Independent review turns to tackling Britain’s biggest crime

Security

Independent review turns to tackling Britain’s biggest crime

23 April 2025

Better protections for the British public against fraud, and tougher enforcement against the perpetrators, will be the goals of the first independent review carried out in 40 years into the UK’s fraud laws.

Unifi secures Oxford Airport ground handling and security contracts

Aerospace Security

Unifi secures Oxford Airport ground handling and security contracts

17 April 2025

Unifi has secured its first business aviation ground handling contract and its third Fixed Base Operation/FBO security contract in the UK at London Oxford Airport, marking a major expansion of its services and a new milestone in its global growth.

Advertisement
DSEI 2025
M Group acquires Telent

Defence Security

M Group acquires Telent

16 April 2025

M Group has aquired Telent, a provider of operational technology and digital solutions for Critical National Infrastructure (CNI) across the UK and Ireland.

Met brings leader of fraud platform to justice 

Security

Met brings leader of fraud platform to justice 

15 April 2025

A massive worldwide operation led by the Met has seen a prolific cyber-criminal sent to prison for eight-and-a-half years.

Advertisement
ODU RT