Unpacking secure by design

Unpacking secure by design

Over the past few years we’ve seen organizations forced to take their security more seriously, moving from something of a grudge purchase to one of the key discussion points at the start of any project.  

As a company, this approach is something that we’ve always embraced. The idea of ‘secure by design’ is a manifestation of our core belief that we shouldn’t even start before we’ve considered the security implications of the solution. 

What we’ve seen is that in the past 12 months is that this idea has become a fundamental issue in all technology decision making processes. With an understanding that it’s much harder to implement security once technology is up and running, our clients are asking ‘how is this going to be secured?’ before they make any decisions.  

Aligning security and business 

This means that today, more than ever, there’s a close alignment between security teams and business objectives. 

To help our clients achieve this, we’ve created a set of reference architectures that provide a starting point for our interactions with our clients. Every IT environment is different, but by leveraging this strategy we’re able to work from a core design that is proven and then adapt that to meet the specific needs of the client. 

This means that our interactions with our clients now start as a consulting engagement as opposed being product focused. We’re asking our clients ‘What outcomes are you looking to achieve?’ and ‘What’s an acceptable level of risk for your environment?’ before we start. This allows us to align the security solution very closely to the business outcome, something that would’ve been a pipe dream a few years ago.  

Approaching all technology with a secure by design approach means that security has stopped being done once and then forgotten about. Just as applications are constantly evolving so the security also constantly evolves, not just to the threat landscape but also to the needs of the organization. If an organization needs to cater for remote access to a greater degree, the focus of the security component would need to shift at the same time.  

Taking the pressure off internal teams 

This constant evolution puts pressure on IT teams, and as a result we’re seeing increased demand for our managed security services to support and manage the security requirements of our clients. It’s not just finding the right level of expertise that organizations battle with, it’s the requirement for continued vigilance across their entire IT environment. Security today is more about taking the information that you gather and using it to create actionable insights and doing this in real time. This isn’t something most organizations can do, and they need partners to provide them with this capability.

 It’s at this point that the concept of secure by design really comes to life. It’s not simply about delivering a service, but rather creating a relationship between the two organizations. When we speak to a client it’s not just a once off, we engage with all aspects of the company. From making sure that the right discussions are happening around the boardroom table, all the way to development teams and end-users who need to be educated around the risks that exist out there and how to identify them.

 By building these relationships and leveraging our strength as a global security organization we’re able to constantly innovate and find new ways to ensure that our clients stay ahead of the evolving threat landscape.

To find out more about our security services, click here



Mike Quinn

Chief Executive Officer at Active Cypher?

4 年

Matt and Tony Jarvis both hit the points and then the work begins. You can design but the easy of deployment, reduction of human interaction in the process and getting the politics away from the facts. Very often a design is not totally aligned to the business(revenue) but in response to a cost center within a cost center. Stay true to the goals...

回复
Amit Nath

Co-Founder & Global CEO of SecurityGen, a Telecom Cybersecurity Company

4 年

Nice article - we agree 100 % Matt

Tony Jarvis

CISO advisor | Cybersecurity strategy | Cloud and Zero Trust | Keynote speaker

4 年

I think there are two ways to look at security by design - doing it because you know you should, and doing it because you are compelled to. For the latter, mandatory disclosure laws, regulations governing privacy of data and cybersecurity labels for consumer devices have moved things forward. Open dialogue is helping with recognising the need and voluntary adoption of security by design principles which is fantastic to see.

回复

要查看或添加评论,请登录

Matt Gyde的更多文章

  • Learning from a momentous year

    Learning from a momentous year

    A lot’s been written about how 2020’s been an extraordinary year but looking back I’m not sure we can truly comprehend…

    7 条评论
  • 2021: Now’s our time to get a step ahead of the scourge of cybercrime

    2021: Now’s our time to get a step ahead of the scourge of cybercrime

    2020 ? a year of unprecedented disruption, fear and uncertainty ? is rapidly drawing to its close. I’d like to take…

    3 条评论
  • Creating the team of the future

    Creating the team of the future

    The story of any successful organization is a story about teams. For any complex task to be performed people need to…

  • Creating a culture of innovation

    Creating a culture of innovation

    Innovation is a word that gets bandied about a lot these days. Every organization is looking to innovate in one way or…

    3 条评论
  • A Transformational journey

    A Transformational journey

    The past year has been one of the most exciting and challenging of my entire career. Not only did we have to manage the…

    6 条评论
  • Making security the Yes team

    Making security the Yes team

    Most organizations have had to accelerate their digital transformation strategies in the wake of COVID-19. Some in…

    2 条评论
  • Are you ready for the new view?

    Are you ready for the new view?

    There’s been a lot of talk about the new normal or the next normal, but it’s time to accept that whatever the world…

    6 条评论
  • Security policies need to evolve quickly to remain relevant post-COVID

    Security policies need to evolve quickly to remain relevant post-COVID

    There’s a lot of talk about the ‘new normal’, or the ‘next normal’ - the way business is going to be conducted in the…

    3 条评论
  • World Health Day 2020

    World Health Day 2020

    We at NTT Ltd. believe all hospitals should be secure.

  • Intelligent Cybersecurity

    Intelligent Cybersecurity

    The ever-evolving world of cybersecurity ? five trends to watch in 2020 that will drive a Secure by Design methodology…

    2 条评论

社区洞察

其他会员也浏览了