Published date:
Firewalls, VPNs and other network security devices are often the first line of defence against cyber attacks. However, if one of these devices is compromised, organisations need a way to understand what happened and whether the device can still be trusted.
The National Cyber Security Centre (NCSC) calls this forensic observability. In simple terms, it means security devices should provide clear logs, activity records and other useful information that helps organisations investigate a cyber incident quickly and accurately.
Without this visibility, security teams may struggle to determine how an attacker gained access, what actions they carried out, or whether any data was affected. Investigations can take longer and become more costly.
When choosing firewalls, VPNs or other network equipment, small businesses and charities should look for products that offer:
- Detailed security logging
- Easy access to incident data
- Clear information about software versions and updates
- Built-in tools that support investigations
The NCSC encourages organisations to consider these features when purchasing network devices, helping them respond more quickly and confidently if an incident occurs.
Key takeaway: Cyber security isn't just about preventing attacks. It's also about having the information you need to understand, investigate and recover from an incident when one happens.
To find more information on Forensic Observability please visit NCSC: The National Cyber Security Centre | National Cyber Security Centre
The National Cyber Security Centre
The National Cyber Security Centre, a part of GCHQ, helps businesses, the public sector and individuals protect the online services and devices that we all depend on.