The UK has joined international partners in sharing new advice to help technology manufacturers make secure-by-design and by-default the global standard for technology manufacturing.
In a new joint guide by the National Cyber Security Centre (NCSC) – a part of GCHQ – and agencies from the US, Australia, Canada, Germany, the Netherlands, and New Zealand, software manufacturers are encouraged to embed secure-by-design and by-default principles into their products to help keep customers safe.
The NCSC has stipulated that treating security as an ‘additional technical feature’ or an option where users need to make configuration changes to stay secure can leave consumers open to malicious cyber intrusions and safety risks.
NCSC CEO Lindy Cameron said: “As our lives become increasingly digital, it is vital technology products are being designed and developed in a way that holds security as a core requirement.”
Indeed, the risks appear to have increased. Cyber-attacks are a huge liability for UK consumers and organisations – in 2022 they increased by 77% in the UK. Organisations which outsource their technology and cybersecurity measures, however, can be left in the lurch if cybersecurity is left as a second thought.
As cybersecurity is still hampered by a major talent shortage, the new guide is attempting to shift cyber responsibilities to technology manufacturers rather than consumers.
The ‘Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and Default’ guide represents a shared, international effort to lesson the burden of risk on customers by providing manufacturers with a roadmap of actionable steps they can take to prioritise security and reduce vulnerabilities.
Manufacturers are advices to follow the guide’s recommendations, which include strategies for engaging senior leaders with these security principles and more tactical steps such as eliminating default passwords and implementing single sign-on technology.
Further, the guide includes advice aimed at organisations to help them hold their technology suppliers accountable for cyber security outcomes and encourage collaboration with industry partners to incentivise secure-by-design and by-default practices.
Recommended
- Critical Vulnerabilities Found in Microsoft Message Queuing
- Scots Rural Small Businesses Struggling Due to Poor Broadband
- Scottish Games Week to Return Later This Year
“Our new joint guide aims to drive the conversation around security standards and help turn the dial so that the burden of cyber risk is no longer carried largely by the consumer,” Cameron continued.
“We call on technology manufacturers to familiarise themselves with the advice in this guide and implement secure-by design and by-default practices into their products to help ensure our society is secure and resilient online.”
The NCSC has issued this guide with the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), National Security Agency (NSA), the Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), Germany’s Federal Office for Information Security (BSI), the Netherlands’ National Cyber Security Centre (NCSC-NL), New Zealand’s National Cyber Security Centre (NCSC-NZ) and New Zealand Computer Emergency Response Team (CERT-NZ).





