Summary
Organisations must act now to prepare for a wave of patches that will address decades of technical debt. Whether they are technology producers and vendors, or consumers and operators, all organisations have ‘technical debt’; a backlog of technical issues – that is both expensive and time-consuming – as a result of prioritising short-term gains over building resilient products. Artificial Intelligence, when used by sufficiently-skilled and knowledgeable individuals, is showing the ability to exploit this technical debt at scale and at pace across the technology ecosystem. As a result, the NCSC expects there will be a ‘forced correction’ to address this technical debt across all types of software, including open source, commercial, proprietary and This is why we are encouraging all organisations to prepare now for when a ‘patch wave’ arrives; a rush of software updates that will need to be applied across the technology stack to address the disclosure of new vulnerabilities. Prioritise external attack surfaces All organisations must take steps to identify and minimise their internet-facing (and other externally-exposed) attack surfaces as soon as is possible. As we’ve argued for some time, you should prioritise technologies on your perimeter and then work inwards covering cloud instances and on-premises environments.