By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: NCSC sets up Vulnerability Research Initiative | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > NCSC sets up Vulnerability Research Initiative | Computer Weekly
News

NCSC sets up Vulnerability Research Initiative | Computer Weekly

News Room
Last updated: 2025/07/15 at 10:58 AM
News Room Published 15 July 2025
Share
SHARE

The UK’s National Cyber Security Centre (NCSC) has lifted the lid on a Vulnerability Research Initiative (VRI) programme designed to engage the private sector on vulnerability research and discovery for the benefit of wider society.

The NCSC already runs a team of internal research experts who spend their days probing a wide range of technologies and products – anything from ubiquitous commodity tech used by consumers, to specialised operational devices used in only a few places.

This in-house capability has made the cyber agency much better informed about the security of commonly deployed technology – and how hard it can be to find vulnerabilities in software products – and helps inform down-the-line advice, guidance and risk mitigations, as well as responses to major disclosure incidents such as Citrix Bleed or Log4Shell.

However, this is a lengthy and involved process, and as the pace of technology development continues to ramp up both in complexity and volume, demand for vulnerability research is soaring.

Enter the VRI, a scheme through which the NCSC will work with external cyber  researchers and ethical hackers to expand access to the tools and tradecraft available for vulnerability discovery, and enhance understanding of the security of the technology that daily life in the UK depends on.

Among other things, the VRI aims to try to better understand the vulnerabilities present in a technology or product, what mitigations might be needed to fix them, how researchers go about conducting their research, and the tooling they use to enable it. The NCSC said this would increase its own vulnerability research capacity and share expertise across the wider ecosystem.

Ultimately, the programme’s output will be used to inform future advice and guidance delivered by the NCSC as the UK’s national technical authority on cyber security, to better engage with the supplier community to encourage them to build more secure products in the first place and to fix bugs in existing ones.

Immersive senior director of cyber threat research, Kev Breen, welcomed the NCSC’s decision to try to extend its vulnerability research capabilities: “There is a great deal of capability in the public domain, especially in more niche areas of research. It is not practical for the NCSC to maintain the necessary skills, time and resources to effectively hunt for bugs across all of these domains. Extending the VRI to include the wider community, via invitation or application, is an excellent way to broaden that knowledge base.”

Incentivising researchers

Breen noted, however, that the lack of any associated bug bounties may limit the number of individuals willing to participate in the programme when they could be compensated for conducting similar work through existing schemes.

Kevin Robertson, chief technology officer at Acumen Cyber, agreed: “Cyber is often described as a community sport. However, independent researchers typically have little incentive to collaborate with bodies like the NCSC, as they stand to gain far more recognition and impact by publishing their findings themselves, rather than handing them over to a government agency. It is essential that this does not become yet another example of wasted potential in a field where independent action often proves more meaningful.”

The NCSC said that it was keen to hear from experts in several topics – particularly the potential application of artificial intelligence (AI) to vulnerability research – and is encouraging them to get in touch. More details of the programme, including information on the overarching equities process that governs how newly found vulnerabilities are handled and disclosed, and by whom, are available here.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Apple Reportedly Taps Samsung Display for First Foldable iPhone Screens
Next Article How AI and Machine Learning Are Driving the Future of Formula 1 | HackerNoon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Never buy $1.25 common item at Dollar Tree – as there’s a better $3 alternative
News
Microsoft 365 also has an expiration date in Windows 10
Mobile
Imposter signs fake agreement on behalf of Li Auto with Uzbekistan dealership · TechNode
Computing
Nasa trials TINY supersonic ‘Son of Concorde’ for racy 925mph flight in tunnel
News

You Might also Like

News

Never buy $1.25 common item at Dollar Tree – as there’s a better $3 alternative

4 Min Read
News

Nasa trials TINY supersonic ‘Son of Concorde’ for racy 925mph flight in tunnel

6 Min Read
News

My 2025 Forecasts Still Have Time to Pay Off — Act Before Year-End

10 Min Read
News

Before iOS 26, Apple Will Release at Least One More iOS 18 Update Soon

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?