Where are the biggest risks from - developers, vendors, customers? Where could government intervention help to improve the cyber resilience of software supply chains? Explore case studies of different contexts, for example: (i) most recent significant attacks, incidents and exploited vulnerabilities and their causes and (ii) statistics on attacks, breaches and prevalence of software vulnerabilities. What are the biggest/most urgent software supply chain risks to the UK economy (that companies face)?

Background

In order to ensure the UK is well protected now and in the future we need to build upon our existing knowledge of cyber security risks and the resilience of software supply chains and are working to identify which mitigations the government can leverage to ensure the UK is well protected now and in the future.

We’re also assessing the impact of these mitigations in driving enhanced security measures. A key area of research interest therefore is understanding the consequences of requiring higher levels of cybersecurity for products and digital services sold in the UK. Strengthening this evidence base will help shape and inform future policy work around the regulation of products and business requirements for cyber security.
Some technologies are critical to cyberspace. To build and sustain competitive edge in cyber-related technologies we need a coordinated, rigorous and consistent approach to identify and analyse critical areas of science and technology and prioritise national effort. CSDI is interested inbeing able to better anticipate the science and technology developments most vital to UK cyber power and in analysing thebe opportunities and risks related to those developments.

It is crucial to ensure that digital identity solutions are both secure and inclusive. The directorate seeks to gather further evidence on how best to enable more inclusive digital identity services whilst maintaining robust security measures. Digital identity solutions enable a person to prove something about themselves for the purposes of a transaction, an eligibility check or accessing services. This includes verifying a person’s age when purchasing age regulated products, when undertaking pre-employment checks or opening a bank account. The government is not mandating specific approach, but instead has committed to setting outcomes-based standards in the form of the UK digital identity & attributes trust framework. (https://www.gov.uk/government/publications/uk-digital-identity-and-attributes-trust-frameworkbeta-version/uk-digital-identity-and-attributes-trust-framework-beta-version)
Organisations that adhere to these standards and agree to oversight from the Office for Digital Identities and Attributes (OfDIA) will receive a trust mark, so that businesses and individuals can be confident that their digital identity solution is safe and secure.

Next steps

If you are keen to register your interest in working and connecting with DSIT Digital Technology and Telecoms Group and/or submitting evidence, then please complete the DSIT-ARI Evidence survey - https://dsit.qualtrics.com/jfe/form/SV_cDfmK2OukVAnirs.
Please view full details: https://www.gov.uk/government/publications/department-for-science-innovation-and-technology-areas-of-research-interest/dsit-areas-of-research-interest-2024

Source

This question was published as part of the set of ARIs in this document:

DSIT Areas of Research Interest 2024 GOV UK

Related UKRI funded projects


  • Research Institute in Science of Cyber Security (RISCS) Phase 2

    The Digital Economy is a key part of the strategy for UK economic growth. But as more businesses move into the digital space, they need to be able to protect their assets (such as their Intellectual Property) and process...

    Funded by: EPSRC

    Why might this be relevant?

    The project focuses on developing security solutions for modern organizations and measuring the impact of security measures, aligning with the question's emphasis on cyber resilience and software supply chain risks.

  • TrueDeploy

    Cybercrime is estimated to cost the world economy $10 trillion annually by 2025, up from $3 trillion in 2015\. We have transitioned to a world where every business is underpinned by technology. Software remains the weake...

    Funded by: ISCF

    Why might this be relevant?

    The project addresses the risks in software supply chains and provides a solution to improve cyber resilience.

  • Cyber Local Meet The Buyer

    UMi and Innovation SuperNetwork (ISN) in partnership with CyberNorth, is excited to announce the upcoming Cyber Local Supplier Village at Venturefest North East 2025. This addition to the established event will connect t...

    Funded by: Innovate UK

    Why might this be relevant?

    The project focuses on connecting cyber security suppliers with businesses, which is relevant to improving cyber resilience.

  • Cyber-R: Securing Businesses through Generative AI-based Adaptive Cyber Resilience Service

    According to the UK Cyber Security Breaches Survey 2024, UK businesses faced approximately 7.78 million cybercrimes over the past year, with phishing attacks accounting for 84% of these incidents. Additionally, 50% of bu...

    Funded by: Innovate UK

    Lead research organisation: UNIVERSITY OF WOLVERHAMPTON

  • Enhancing Cyber Resilience of Small and Medium-sized Enterprises through Cyber Security Communities of Support

    Small and Medium-sized Enterprises (SMEs) are a vital element of the economy, accounting for 99.9% of UK businesses, generating three fifths of employment and turnover of £2.3 trillion. They are a crucial asset req...

    Funded by: EPSRC

    Why might this be relevant?

    The project specifically targets enhancing cyber resilience of Small and Medium-sized Enterprises (SMEs) through support communities, aligning with the question's exploration of cyber resilience and software supply chain risks in different contexts.

  • Centre for Secure Information Technologies (CSIT) - Phase 3

    Cyber-attacks such as those recently perpetrated on Solarwinds, Colonial Pipeline and Viasat are scaling at an alarming rate. Resilient cyber security technologies are vital to ensure that society can safely and confiden...

    Funded by: EPSRC

  • Cyber Security Cartographies: CySeCa

    "The growth of the internet has been the biggest social and technological change of my lifetime [...] It will have a huge role to play in supporting sustainable development in poorer countries. At the same time our ...

    Funded by: EPSRC

  • Strengthening the Local Business Community Resilience to Cyber Incidents and Reducing the Regional Cyber Skills Gap.

    The [NEBRC][0] is a not for profit private company limited by guarantee. We are a unique partnership between police, academia and corporate business that exists to help businesses mitigate business cyber risks. Our miss...

    Funded by: Innovate UK

  • An innovative cyber compliance platform using AI, live monitoring data and machine learning to automate compliance and due diligence completion.

    Naq is a UK-based cyber compliance SME with a core project team of Chris Harden (Project Lead and Serial CTO), Chris Clinton (Product Manager, exNATO), Svenja Perkins (Policy Lead) and Nadia Kadhim (CEO and Financial Man...

    Funded by: Innovate UK

  • CyberSecurityAId: Empowering Small Businesses with Cyber Hygiene

    CyberSecurityAId is a pioneering project looking to revolutionise the cybersecurity landscape for small businesses in the United Kingdom. This transformative initiative is driven by a clear and compelling motivation: to ...

    Funded by: ISCF