No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Embedding Security by Design: A Shared Responsibility

May 18, 2023
in Protection
0
Embedding Security by Design: A Shared Responsibility



Amid a feverish cybersecurity environment, there is a growing chorus for software to be secure by design. In April, the US Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), aligned with the cybersecurity authorities of Australia, Canada, the United Kingdom, Germany, the Netherlands, and New Zealand to create guidelines aimed at supporting software manufacturers to “embed security-by-design and by-default.”

In this new paper, the agencies call on software makers to deploy threat modeling at the design stage. These guidelines follow fast on the news that the US government will legislate to introduce liability for software makers to secure the products they manufacture.

All software developers want to build secure software, so why is it so difficult to do, what does effective security by design look like, and what needs to change to embed it in the software development process?

The Challenge

The sheer prevalence of cybersecurity breaches is evidence of the huge challenge faced by developers trying to build secure software. Striving to get their products to market quickly, software manufacturers are incentivized to take shortcuts on security. And the challenge of designing secure software is becoming more difficult as software architecture grows in complexity, with every sector of the economy being transformed by software. The recent intention of the White House to hold vendors accountable for poor software security could be seen as an attempt to correct the current market incentives.

This is especially the case with supply chains, which are getting ever more complex, making it difficult to predict how different pieces of software will interact. We’ve seen this challenge in the growing trend of supply chain attacks that have affected businesses, including Air France, KLM, and Nissan in the past year.

Security by Design and Threat Modeling

It is still the case that most software security activities are focused at the end of the development process, but this creates some problems. First, scanning software through application security testing tools can miss more complex flaws in the design of an application. In addition, when you do identify a bug once you have completed development, remediation can be costly and time consuming.

It is much better to identify and address security flaws before code is written, through the process of threat modeling. There are a number of different approaches to threat modeling, but fundamental to them all is analyzing the design of the system as a cross-functional team — development and security teams coming together to identify potential security and privacy issues and developing a plan to solve or mitigate them.

So far, so straightforward. So why isn’t this happening? There seem to be three main barriers: skills, responsibility, and practicality.

Embedding Security by Design

A fundamental challenge is that many developers enter the workplace without the technical knowledge to build secure software and with little or no experience of threat modeling. It is a software skill that you have to invest in and it takes time to learn. The focus of the developer is, understandably, on the functionality that they are developing, not on how a threat actor might find a vulnerability in that new functionality.

This leads us to the second barrier, which is a lack of clarity over where responsibility for security at the design stage lies, which means in many businesses threat modeling can fall through the cracks. Despite their fundamental role, the development team often views security as the responsibility of the security team. This is also entirely understandable, given that in most businesses the knowledge about the process of threat modeling and of the security risks is held by the security team. Just as you can’t design secure software without the engineers, you can’t build secure software without the security team’s insight into the evolving attack vectors used by threat actors.

Until these two teams are working together at the very start of the software development process and threat modeling is embedded as a community practice with shared responsibility, this problem won’t be solved.

The third barrier is that until fairly recently, traditional approaches to threat modeling have been impractical when developing software on a large scale. For an organization that is building many thousands of applications, the traditional approach to threat modeling, as a group in a meeting room with a whiteboard, isn’t possible. However, automation of this process is now a reality. As a developer, you can now use automation to generate a threat model that contains relevant threats and countermeasures for you.

This latest guidance from the world’s leading cybersecurity agencies should leave us in no doubt that security by design is no longer just best practice — it has to become a fundamental part of software development. The tools exist now to make it possible to achieve, but it must be a shared endeavor, with development and security teams working closely together before a line of code is written.

Editorial Team

Editorial Team

Related Posts

The Best Prime Deals on Fitness Equipment Up to 50% Off
Protection

The Best Prime Deals on Fitness Equipment Up to 50% Off

June 22, 2026
These Independent Apps Let You Use Your Whoop Without a Subscription (For Now)
Protection

These Independent Apps Let You Use Your Whoop Without a Subscription (For Now)

June 22, 2026
10 Shows Like 'Succession' You Should Watch Next
Protection

10 Shows Like ‘Succession’ You Should Watch Next

June 22, 2026
These Prime Day–Discounted Monitor Arms Might Be the Cheapest Desk Upgrades You'll Make This Year
Protection

These Prime Day–Discounted Monitor Arms Might Be the Cheapest Desk Upgrades You’ll Make This Year

June 22, 2026
NotebookLM's Latest Update Makes It an Even Better Research Tool
Protection

NotebookLM’s Latest Update Makes It an Even Better Research Tool

June 22, 2026
This Woot Deal Is the Cheapest Way to Get the Nintendo Switch 2 Before Prices Go Up
Protection

This Woot Deal Is the Cheapest Way to Get the Nintendo Switch 2 Before Prices Go Up

June 22, 2026
Load More
Next Post
Carl Icahn admits mistake with bearish bet that cost $9bn

Carl Icahn admits mistake with bearish bet that cost $9bn

Popular News

  • The 10 best banks for college students in 2025

    The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • The First Four Settings to Change on Any Boox E-Ink Tablet

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • The Best (and Worst) Ways to Organize Your To-Do List

    0 shares
    Share 0 Tweet 0
  • I Used Monarch Money for 30 Days: Here’s What Happened

    0 shares
    Share 0 Tweet 0

Latest News

How Montreal’s Once-Buzzy Mile End Has Remade Itself Once Again

How Montreal’s Once-Buzzy Mile End Has Remade Itself Once Again

June 22, 2026
0

Where to eat in Mile EndMontreal’s signature meals blend border-hopping haute-gastronomic precision with the unfussy feel of a wine-fueled dinner-party—and...

Strategy CEO backs troubled STRC with $1M bet on recovery - 1

Strategy CEO backs troubled STRC with $1M bet on recovery

June 22, 2026
0

Strategy President and CEO Phong Le has invested $1 million in the company’s STRC preferred stock as shares continue trading...

A flood of oil is set to hit energy markets. Here’s how much crude may be unleashed.

A flood of oil is set to hit energy markets. Here’s how much crude may be unleashed.

June 22, 2026
0

Despite a fragile U.S.-Iran cease-fire and fears of an uneven recovery, millions of barrels of crude oil are already lined...

The Best Prime Deals on Fitness Equipment Up to 50% Off

The Best Prime Deals on Fitness Equipment Up to 50% Off

June 22, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.