CYBERUK 2026 - Technology Track

Unknown

CYBERUK 2026 · Day 1 · Technology Track

Overview

This talk, delivered as a panel discussion at CYBERUK 2026, delves into the critical need for radical transparency in securing our increasingly complex technology landscape. Moderated by an unnamed NCSC representative, the panel features industry and government experts who explore how greater openness about product status and vendor processes can transform cyber defense. The core premise is that current approaches to security, often hampered by a "security through obscurity" mindset and fragmented supply chains, are failing to keep pace with evolving threats. By exposing more detail to customers and operators, the aim is to incentivize better security practices, enable more informed decision-making, and ultimately foster a more resilient cyber ecosystem.

Watch on YouTube

Visual summary for CYBERUK 2026 - Technology Track by Unknown
Visual summary for CYBERUK 2026 - Technology Track by Unknown

Key moments

  1. 5:30 Introduction to radical transparency for better security
  2. 6:15 Defining transparent products and vendors
  3. 7:00 NCSC's principal-based assurance model for transparency
  4. 8:00 Panelists introduce their diverse cybersecurity backgrounds
  5. 9:30 Exploitation scaling faster than cyber defenses
  6. 10:00 Edge devices remain primary target for exploitation
  7. 11:00 Zero-day exploitation vs. slow patching: A critical gap
  8. 12:00 The growing and critical information gap in cybersecurity

Radical Transparency: Shaping the Next Decade of Cyber Defense

Speakers: Glenn Thorp, Lead Researcher, Grey Noise Intelligence; Ross McCombie, CISO, Sophos; Carla Baker, Head of Strategy and Cyber Policy

Conference: CYBERUK

YouTube: https://www.youtube.com/watch?v=eai-mmjuB3E

Overview

This talk, delivered as a panel discussion at CYBERUK 2026, delves into the critical need for radical transparency in securing our increasingly complex technology landscape. Moderated by an unnamed NCSC representative, the panel features industry and government experts who explore how greater openness about product status and vendor processes can transform cyber defense. The core premise is that current approaches to security, often hampered by a "security through obscurity" mindset and fragmented supply chains, are failing to keep pace with evolving threats. By exposing more detail to customers and operators, the aim is to incentivize better security practices, enable more informed decision-making, and ultimately foster a more resilient cyber ecosystem.

The discussion highlights that good security is difficult to buy, hard to sell, and challenging to verify. The panel argues that a shift towards proactive transparency—from visible version numbers to comprehensive Software Bill of Materials (SBOMs)—is essential to give credit for diligent security efforts and empower defenders. This transformation requires overcoming significant cultural, technical, and market-based hurdles, necessitating a collaborative approach between industry, government, and the procurement community to redefine incentives and foster a shared understanding of what constitutes true security maturity.

Background

▶ Watch: Introduction to radical transparency for better security (5:30)

The foundational problem addressed in this talk is the inherent complexity of modern technology stacks. As the moderator aptly puts it, what we once conceived as an "orderly stack" is now a "tangle" of diverse hardware, software configurations, assembled and evolved at different times by various parts of the supply chain. This fragmentation makes it incredibly difficult for customers to compare product offerings, understand their network's current state, or verify the resilience designed into products. Consequently, the incentive for vendors to invest in robust security practices is often limited because the returns are hard to quantify and sell.

Glenn Thorp from Grey Noise Intelligence underscores the urgency of this problem by presenting stark statistics on the current threat landscape. Exploitation is scaling significantly faster than defenses. Attackers, particularly since the COVID-19 pandemic, remain heavily focused on the edge, with a shocking concentration of attacks. The Verizon Data Breach Investigations Report (DBIR) noted an 8x increase in edge exploitation last year, and Mandiant observed that the top four vulnerabilities exploited were all related to edge devices. A six-month post-Salt Typhoon campaign analysis by Census revealed that edge device exposures only decreased by 25%, while Cisco IOS device exposure actually increased. This data is corroborated by Grey Noise's firsthand observations, confirming the edge as a primary target.

The speed of exploitation further exacerbates the issue. The DBIR indicates an average exploitation time of zero days for many edge vulnerabilities, while the average time to patch them is over 30 days. This "patch diffing" problem, though not new, is intensified by the deluge of vulnerabilities discovered with the aid of AI. Compounding this, Thorp notes that half of the IPs observed by Grey Noise attempting Remote Code Execution (RCE) have no prior history on blocklists, appearing suddenly and immediately engaging in exploitation, making defense exceptionally challenging.

Finally, an information gap pervades the field. Thorp provides a compelling example: CISA's Known Exploited Vulnerabilities (KEV) catalog includes a field for "known ransomware usage campaign" which was updated silently 59 times last year. Such silent updates significantly alter the threat characterization without the fanfare or alerts associated with initial catalog additions, leaving defenders at a disadvantage.

To counter these challenges, the NCSC has begun embracing a more transparent approach. They are establishing a national ecosystem of cyber resilience test facilities that leverage NCSC's principal-based assurance model. This model, inspired by the claims, arguments, and evidence (CAE) approach from the safety community, requires vendors to demonstrate and document how their products meet security principles. Test facilities then publish reports assessing these claims, providing customers with significantly more information than traditional pass/fail certifications. Additionally, the NCSC has advocated for visible version numbers on the wire, even acknowledging the risk that this information could also aid attackers, demonstrating a radical commitment to transparency.

Key Findings

▶ Watch: NCSC's principal-based assurance model for transparency (7:00)

The central finding of the panel discussion is a strong consensus that radical transparency is strategically essential for improving cyber defense, despite acknowledged tactical dilemmas and perverse incentives. The panel advocates for a shift away from security through obscurity, arguing that while it might offer temporary tactical advantages, it is ultimately unsustainable and detrimental in the long term, especially with the rise of AI-driven attacks.

Key findings and arguments for transparency include:

  1. Enabling Defenders: More information (e.g., version numbers, SBOMs, introspection tools) directly empowers administrators and defenders to understand their assets, identify risks, and prioritize patching effectively. Glenn Thorp emphasizes that attackers often don't need this information as they can brute-force or broadly exploit vulnerabilities due to the low cost of doing so.
  2. Driving Market Differentiation and Incentives: Transparency allows vendors who invest in robust security to differentiate themselves. The NCSC's principal-based assurance model aims to provide customers with detailed, verifiable evidence, rewarding vendors for their efforts.
  3. Shifting Focus to Response and Maturity: The panel argues that the focus should move from merely counting CVEs (which can penalize transparent vendors) to assessing a vendor's response capabilities, such as root cause analysis, median patch time, and mature disclosure programs. This emphasizes how a vendor handles vulnerabilities rather than just what vulnerabilities exist.
  4. Overcoming Perverse Incentives: Ross McCombie highlights the "first-mover disadvantage" where a single transparent vendor might face scrutiny while others remain opaque. This suggests a need for collective action, potentially through policy or industry-wide initiatives, to create a level playing field.
  5. The Diminishing Value of Obscurity: AI significantly shifts the balance, making obscurity less effective as AI agents can quickly discover vulnerabilities. Ross McCombie even suggests that the value of source code alone has dropped, and sharing more, potentially even under escrow, could allow for AI-driven hunting to stay ahead of attackers.
  6. The Need for Procurement Evolution: A critical finding is the disconnect between current procurement processes and desired security outcomes. Procurement questionnaires often focus on superficial "green tick" compliance (e.g., "Do you have MFA enabled?") rather than deeper indicators of product security maturity (e.g., bug bounty programs, SBOM provision, CNA status). A "radical evolution of procurement processes" is deemed necessary.

Challenges and blockers identified include:

  • Tactical vs. Strategic Transparency: Vendors may tactically choose obscurity (e.g., reducing device discoverability during active campaigns) to disrupt immediate threats, even if it contradicts a long-term strategic goal of transparency.
  • Information Overload and Fatigue: Carla Baker raises concerns about "SBOM fatigue" if customers receive too much undigestible information from multiple vendors, leading to a loss of signal in the noise.
  • Cultural and Legacy Barriers: The historical view of information disclosure as a vulnerability (e.g., version numbers leading to CVEs) creates cultural inertia against transparency.
  • Technical Barriers for Edge Devices: Many edge devices are "black boxes" running specialized software, making it hard to implement deep introspection or transparency controls common in typical endpoints.
  • Lack of Standardization and Context: The crowded landscape of different security schemes (Cyber Essentials, DCC, Telecom Vendor Assessment, CRA, DORA, US Software Pledge) creates confusion. There's a need for mapping or translation services to provide context and reduce the burden on industry.

Ultimately, the panel converges on the idea that while the journey to radical transparency is complex and fraught with challenges, it is an imperative for building a more resilient and defensible cyber future.

Technical Deep Dive

▶ Watch: Exploitation scaling faster than cyber defenses (9:30)

The discussion touched upon several key technical concepts and practices relevant to achieving transparency and improving security:

  1. Visible Version Numbers on the Wire: A core tenet of radical transparency, championed by NCSC, is for products to openly share their update status and version numbers directly on the network. The argument is that while this information could be used by attackers, it is far more valuable to defenders for inventory management, patch prioritization, and understanding their attack surface. Glenn Thorp points out that many attackers don't perform version checks anyway, opting for broad, cheap exploitation attempts, meaning defenders benefit more from this visibility. Ross McCombie acknowledges the tactical tension but leans towards this as a long-term strategic goal, especially as AI makes fingerprinting and version discovery easier for attackers, rendering obscurity less effective.
  1. Software Bill of Materials (SBOMs): SBOMs are detailed inventories of all the software components, libraries, and dependencies used in a product. The panel discusses their immense potential for transparency, allowing customers to understand the composition of what they are deploying. However, Ross McCombie and Carla Baker highlight challenges:
  • Contextualization: An SBOM alone might show vulnerable libraries, but without contextualized information (e.g., whether the vulnerability is actually reachable or exploitable in the specific product configuration), it can create "friction" and drive "wrong behaviors" (like blindly updating all libraries, which can introduce new risks).
  • Information Overload: The sheer volume of SBOMs from multiple vendors could lead to "SBOM fatigue" for customers.
  • Ecosystem Maturity: For SBOMs to be truly actionable, the ecosystem needs to develop tools and skillsets for at-scale analysis and understanding.
  1. Deep Introspection Tools: These tools would allow customers and administrators to gain deeper insights into the operational status and internal workings of products. This aligns with the desire for more insight into the "status of a product in operation." The implication is going beyond surface-level checks to understand configuration, internal component health, and potential vulnerabilities.
  1. Edge Device Specifics: Glenn Thorp notes that edge devices often present unique technical barriers to transparency. They are frequently "black boxes" running highly specialized and tuned software, lacking the typical controls available on standard endpoints. This makes it challenging to implement the kind of deep introspection or expose the granular information desired for transparency.
  1. Attacker Fingerprinting Techniques: Ross McCombie shares a specific tactical example from Sophos where adversaries were fingerprinting their devices using techniques like hashing the favicon. This intel, obtained from C2 servers through law enforcement collaboration, allowed Sophos to make tactical decisions to reduce the discoverability of their devices in the short term, disrupting mass exploitation campaigns. This illustrates the cat-and-mouse game where attackers leverage seemingly innocuous information for targeting.
  1. OAUTH Scopes and Cloud Identity: A significant emerging threat vector discussed is identity across cloud services, particularly issues related to OAUTH scopes. Ross McCombie points out that customers often struggle to understand "how much access does that app... require to do its job?" or "how is this vendor storing the keys?" He notes that questions about OAUTH scopes often lead to "crickets" from vendors, indicating a lack of transparency and understanding in this critical area. Breaches like the recent Salesloft incident are cited as examples of "crazy OAUTH scope problems." This highlights a technical blind spot where the complexity of modern cloud identity management makes transparency both difficult and urgently needed.

Demo / Proof of Concept

▶ Watch: Edge devices remain primary target for exploitation (10:00)

This session was structured as a panel discussion rather than a presentation featuring a live demonstration or proof of concept. The speakers engaged in a debate about the theoretical and practical aspects of radical transparency in cybersecurity. Therefore, no specific technical demo or proof of concept was showcased during the talk. Instead, the discussion focused on the concepts of what should be transparent (e.g., visible version numbers, SBOMs, deep introspection tools) and the implications of implementing such transparency for both defenders and attackers. The Sophos example of tactically disrupting an attacker's fingerprinting techniques, while a real-world scenario, was recounted as an anecdote rather than a live demonstration.

Defensive Implications

▶ Watch: The growing and critical information gap in cybersecurity (12:00)

The insights from this panel discussion offer several critical implications for defenders seeking to enhance their organization's cybersecurity posture:

  1. Demand Proactive Transparency from Vendors: Defenders should actively push their vendors for greater transparency regarding product status and development processes. This includes requesting visible version numbers on the wire, comprehensive SBOMs, and details about support lifetimes. The NCSC's advocacy for visible version numbers and its principal-based assurance model provide a framework for such demands.
  2. Shift Procurement Focus: The current procurement model is often misaligned with true security maturity. Defenders, particularly those involved in vendor selection, must advocate for a "radical evolution of procurement processes." Instead of generic "green tick" compliance questions (e.g., "Do you have MFA enabled?"), procurement should ask more pointed questions about:
  • Vendor's security development lifecycle: Does the vendor demonstrate secure design practices?
  • Vulnerability management: What is the vendor's median patch time? Do they perform robust root cause analysis?
  • Disclosure programs: Does the vendor operate a bug bounty program or embrace responsible disclosure? Is the vendor a CVE Numbering Authority (CNA)?
  • Contextualized SBOMs: While raw SBOMs can be overwhelming, defenders should work with vendors to understand the context of identified vulnerabilities within their specific product.
  1. Prioritize Vendor Response Over CVE Count: A high CVE count might indicate a mature disclosure program rather than an inherently insecure product. Defenders should instead assess a vendor's ability to respond to vulnerabilities—their speed, thoroughness, and willingness to share insights into fixes and root causes.
  2. Address Emerging Threat Vectors: Be vigilant about new attack surfaces. Glenn Thorp's mention of residential proxies highlights the need to consider threats originating from compromised SOHO or consumer devices. Ross McCombie's emphasis on OAUTH scopes and cloud identity issues is crucial for organizations heavily invested in cloud services. Defenders must scrutinize the permissions requested by third-party SaaS applications and demand greater transparency from cloud service providers about their key storage and access management practices.
  3. Leverage Government Initiatives (and push for more): Keep abreast of government policies and initiatives aimed at improving software security, such as the UK's DEIT Software Security Code of Practice, the EU's Cyber Resilience Act (CRA) and DORA, and the US Software Pledge. While these can be complex, they provide frameworks and incentives for vendors to improve. Defenders should use these as leverage in their conversations with vendors and advocate for better international alignment and "translation services" between different regulatory frameworks.
  4. Educate and Adapt: The shift to radical transparency requires an educated defense community. Defenders need to develop the skills to interpret and act upon the increased data provided by transparent vendors (e.g., understanding SBOMs, OAUTH scopes). They must also be agile enough to adapt their defensive strategies as the threat landscape and best practices evolve rapidly. The NCSC's role in providing "top cover" with practical advice (like on password expiry) can help defenders navigate conflicting compliance requirements.
  5. Champion Responsible Practices: Where possible, defenders should proactively build trust by demonstrating their own commitment to transparent and mature security practices internally, mirroring the expectations they place on their vendors.

Key Takeaways

  • Radical transparency is a strategic imperative: Moving beyond "security through obscurity" is essential for modern cyber defense, empowering defenders and incentivizing better vendor practices.
  • Edge devices are critical targets: Exploitation of edge vulnerabilities is scaling rapidly, with slow patching times and a high volume of previously unknown attacker IPs.
  • Procurement processes need fundamental reform: Current vendor questionnaires often miss crucial indicators of product security maturity, focusing instead on superficial compliance.
  • Vendor response and maturity are paramount: Assess vendors not just by CVE counts, but by their ability to respond to vulnerabilities, their patch times, and their engagement in responsible disclosure.
  • Cloud identity (OAUTH scopes) is an emerging blind spot: Lack of transparency around SaaS app permissions and key storage presents significant risks that defenders must actively address.
  • Government and industry collaboration is key: Policy interventions, standardized approaches (not necessarily new standards), and NCSC's "soft power" can help overcome market failures and drive collective action towards transparency.

About the Speaker(s)

  • Glenn Thorp is the Lead Researcher at Grey Noise Intelligence, a company focused on identifying and classifying internet background noise to help security teams prioritize threats. With over 20 years of experience, Glenn has a diverse background spanning practitioner and leadership roles across vendors, government, private industry, and the intelligence community. His work now increasingly involves the application of AI in intelligence.
  • Ross McCombie serves as the CISO at Sophos, a cybersecurity software and hardware company. His responsibilities cover both product and corporate security, with a significant focus (approximately 80% of his time) on product security, which he views as central to building customer trust. He advocates for secure design and strong products, emphasizing strategic transparency.
  • Carla Baker is the Head of Strategy and Cyber Policy. With 15 years of experience in cyber policy, she has witnessed the evolution of government approaches to cybersecurity strategy and industry collaboration. Her expertise lies in developing policies that build resilience, demonstrate conformance, and understand the impact of government interventions on market incentives. Her role likely involves shaping UK government cyber policy, potentially within an organization like the NCSC or a related department.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent panel discussion at a government-adjacent conference on a real and underserved problem — the market failure that keeps security transparency unprofitable for vendors. The three panelists bring legitimate credentials and the threat data Thorp cites (DBIR edge exploitation stats, Grey Noise RCE IP observations, the silent KEV updates) grounds the conversation in something real. But this is ultimately a 'we should do better' panel that circles the problem more than it solves it. The tactical tension between obscurity and transparency gets surfaced honestly — the Sophos favicon-hashing anecdote is the sharpest moment — but the panel never resolves it. SBOM fatigue, procurement…

Heather Calloway (CISO) — SOLID

A competent and credible panel that names the right problems — procurement failure, vendor opacity, edge exploitation velocity, SBOM limitations — but never quite gets to the accountability structure or decision framework that would make it actionable at the institutional level. Strong on diagnosis, weak on prescription. Useful for a practitioner audience thinking about vendor management or procurement reform, but it will not move a board or drive a governance decision.

→ Top-rated talks at CYBERUK 2026

All talks from CYBERUK 2026