Skip to main content

Technology considerations

Under this heading, the NCSC publishes short statements on selected topics that are related to IT security and are of general interest.

Fundamentals of Cybersecurity

Technology consideration: Cybersecurity management

In today's information society, information is vital to the operations of organisations and com panies. It is usually stored, processed and transmitted electronically in the form of data. Be cause of its importance, this data must be protected to meet specific security objectives – such as confidentiality, integrity (or authenticity), and availability. Ensuring this protection is a de manding (management) task, often referred to as information security management or cyber security management, and is ideally supported by an information security management sys tem (ISMS).

Technology consideration: Cybersecurity and resilience

This technology brief highlights the differences between security and resilience, why resilience is more suitable as an overarching goal, and why this is particularly important in cyberspace. Ultimately, the general aim will be to increasingly align today’s cybersecurity efforts with cyber resilience requirements.

Measurability and testability of IT security

If IT security is to be made measurable and testable in this context, various approaches must be considered. This paper outlines a few examples: reducing complexity (thesis 1), measures based on facts (thesis 2), combining verifying and falsifying approaches (thesis 3) and creating security through trust and transparency (thesis 4).

Recommendations

Technology consideration: Cloud computing and cybersecurity

‘The cloud’ or ‘cloud computing’ is often described as a paradigm shift, i.e. something new that operates according to a different set of rules. As a result, discussing cybersecurity in the context of cloud solutions can be challenging. This is evident in many projects, such as deciding whether to use cloud services or enhancing the security of existing cloud-based solutions.

Technology consideration: Requirements and recommendations for the secure distributed processing of information requiring protection

In any organisational environment, there is information that requires protection for a variety of reasons (for example because it is classified). The need for protection may relate to different security objectives, such as confidentiality, authenticity or availability. This technology brief sets out the requirements for the secure distributed processing of infor mation requiring protection, proposes a suitable target architecture, and provides recommen dations for related development and procurement projects. Given that technological solutions for the secure storage and transmission of such information are already available, these as pects are not addressed in detail and are only discussed where relevant.

Further Information:
28 May 2026: echnology brief on the secure distributed processing of information requiring protection

Assessments

NCSC assessment: Action required in relation to post-quantum cryptography (PQC)

In light of ongoing efforts to build sufficiently large quantum computers and the impact this may have on current cryptographic procedures and algorithms, the NCSC has produced a technology brief on quantum computers and post-quantum cryptography (PQC).

Technologies and techniques

Technology consideration: Quantum computers and post-quantum cryptography

This document outlines what a quantum computer is and why it poses challenges to the security of certain cryptographic methods. It also explains what is meant by post-quantum cryptography (PQC), what progress has been made in this field, and where further action is needed.

Technology consideration: SCION

SCION is a technology that promises greater security, reliability and control over routing and, consequently, data transmission on the internet. As part of this examination of the technology, the NCSC briefly outline the problem with current architecture and the extent to which SCION can offer a solution.

Technology consideration: Passkeys

Passwords remain the most widely used form of authentication, despite their many well known and well-documented security flaws. None of the alternative authentication methods proposed in the past have gained broad acceptance. By contrast, the FIDO2 standard and its passkey implementation are seeing growing support. This document provides an overview of the FIDO2 standard and passkeys, and discusses their security properties and practical implications.

Technology consideration: Confidential Computing

Ensuring the security of information processing operations in IT systems is a major challenge, particularly given the increasing use of cloud computing and related services. While data stor age and transmission can be effectively secured using cryptographic methods, processing data securely remains a core challenge – particularly when the software (code) controlling the process and the execution environment are managed by a cloud provider and lie outside the user’s control.1 Various approaches to address this issue have been developed – and, in some cases, implemented. This technology brief introduces and discusses one such approach: confidential computing. It describes how it works, outlines its advantages and disadvantages, presents current market solutions, and explores future prospects.

Technology consideration: The ‘Zero Trust’ principle

The document is avalable in:

German
French

Further Information:

Cyber-Defence Campus: Technologie Review