Site navigation

UK Joins International Partners to Make ‘Secure-by-Design’ Default

Elizabeth Greenberg

,

secure by design
The new guide is a joint effort to hold more manufacturers accountable for cyber-secure technology products.

The UK has joined international partners in sharing new advice to help technology manufacturers make secure-by-design and by-default the global standard for technology manufacturing.

In a new joint guide by the National Cyber Security Centre (NCSC) a part of GCHQ and agencies from the US, Australia, Canada, Germany, the Netherlands, and New Zealand, software manufacturers are encouraged to embed secure-by-design and by-default principles into their products to help keep customers safe.

The NCSC has stipulated that treating security as an ‘additional technical feature’ or an option where users need to make configuration changes to stay secure can leave consumers open to malicious cyber intrusions and safety risks.

NCSC CEO Lindy Cameron said: “As our lives become increasingly digital, it is vital technology products are being designed and developed in a way that holds security as a core requirement.”

Indeed, the risks appear to have increased. Cyber-attacks are a huge liability for UK consumers and organisations – in 2022 they increased by 77% in the UK. Organisations which outsource their technology and cybersecurity measures, however, can be left in the lurch if cybersecurity is left as a second thought.

As cybersecurity is still hampered by a major talent shortage, the new guide is attempting to shift cyber responsibilities to technology manufacturers rather than consumers.

The ‘Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and Default’ guide represents a shared, international effort to lesson the burden of risk on customers by providing manufacturers with a roadmap of actionable steps they can take to prioritise security and reduce vulnerabilities.

Manufacturers are advices to follow the guide’s recommendations, which include strategies for engaging senior leaders with these security principles and more tactical steps such as eliminating default passwords and implementing single sign-on technology.

Further, the guide includes advice aimed at organisations to help them hold their technology suppliers accountable for cyber security outcomes and encourage collaboration with industry partners to incentivise secure-by-design and by-default practices.


Recommended


“Our new joint guide aims to drive the conversation around security standards and help turn the dial so that the burden of cyber risk is no longer carried largely by the consumer,” Cameron continued.

“We call on technology manufacturers to familiarise themselves with the advice in this guide and implement secure-by design and by-default practices into their products to help ensure our society is secure and resilient online.”

The NCSC has issued this guide with the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), National Security Agency (NSA), the Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), Germany’s Federal Office for Information Security (BSI), the Netherlands’ National Cyber Security Centre (NCSC-NL), New Zealand’s National Cyber Security Centre (NCSC-NZ) and New Zealand Computer Emergency Response Team (CERT-NZ).

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data