Category: Secure by Design

  • Secure by Design vs. Security Control Sets

    Secure by Design vs. Security Control Sets

    A Comparison through Simon Sinek’s ‘Start with Why’ Philosophy In cyber security, the concept of Secure by Design is often seen to clash with the traditional security approach of applying security control sets, such as NIST SP 800-53. Here we compare these two approaches using Simon Sinek’s influential idea of “Start with Why.” Sinek’s philosophy…

  • Rethinking Secure by Design: Key Questions to Enhance Cyber Security

    Rethinking Secure by Design: Key Questions to Enhance Cyber Security

    A recent letter sent to all defence industry CEOs focused on driving cyber resilience in supply chains, is a stark reminder that in challenging times it is of upmost importance that the systems we rely on remain safe and secure. Within the letter, Ministry of Defence officials—the Second Permanent Secretary, DG Chief Information Officer and…

  • Understanding the Secure by Design Principles

    Understanding the Secure by Design Principles

    Traditionally, “successful” cyber security approaches and implementation have been evidenced by attaining accreditation. This method, however, enables cyber security to be viewed as a bolt-on aspect or an afterthought in system design. Secure by Design, the MOD’s new approach to cyber risk management, advocates for a more holistic approach, integrating cyber security risk management into…

  • Getting Started with Secure by Design

    Getting Started with Secure by Design

    Secure by Design has been launched by the UK Government and is already creating a lot of noise by challenging existing security norms, especially in the Ministry of Defence (MOD) and more recently, the Central Digital and Data Office (CDDO).    Previously, we have explored what Secure by Design is and why it’s important to…

  • Secure by Design – Continual Risk Management

    Secure by Design – Continual Risk Management

    Secure by Design is changing the way the Ministry of Defence (MOD), UK Government and its departments implement cyber security, in a move away from traditional accreditation-based compliance. This new approach aims to deliver better systems that are more secure, trustworthy, and resilient to cyber-attack. Here, we look why organisations should seek to go beyond…

  • MOD Secure by Design – Cyber Risk Management

    MOD Secure by Design – Cyber Risk Management

    The launch of the Ministry of Defence’s (MOD) Secure by Design initiative, and the soon to be launched Cabinet Office initiative of the same name, should give rise to significant discussion, and pause for thought for everyone who works in these areas. This is not yet another new approach to security accreditation; it is a fundamental…

  • What is Secure by Design?

    What is Secure by Design?

    Secure by Design – Managing Cyber Risk Secure by Design (SbD) is the UK Government approach to Cyber Security. Led by the Cabinet Office along with the Ministry of Defence (MOD), Secure by Design fundamentally changes the traditional accreditation model to one based on continual risk management and security design principles. Not just for security…