Secure by Design (SbD) shifts the responsibility of cybersecurity from the end-user to the product developer, embedding protection into the entire development lifecycle rather than patching flaws after release.
The framework is defined by two key perspectives: the core executive principles established globally by CISA and the UK’s NCSC, alongside the foundational engineering principles used by system architects.
Core Principles (CISA & NCSC Joint Guidance)

- Take Ownership of Customer Outcomes: Security must not be an upcharge, premium feature, or burden left to the user. Essential protections (such as single sign-on, logging, and multi-factor authentication) must be included out-of-the-box at no additional cost.
- Embrace Radical Transparency and Accountability: Organizations must openly publish security data, share accurate vulnerability data (CVEs/CWEs), disclose root causes, and publish memory-safety roadmaps to help the wider ecosystem learn.
- Lead from the Top: Security is treated as a core product quality metric and business priority managed directly by executive leadership and board members—not treated as an isolated IT task.
Core Engineering & Architectural Principles
When building software, systems, or infrastructure, engineering teams apply these specific functional design patterns:
- Secure Defaults: Products ship pre-configured in the most secure state possible—requiring no complex configuration or hardening guides for basic protection.
- Least Privilege: Access rights for users, applications, and processes are restricted to only the absolute minimum necessary to perform their immediate functions.
- Defense in Depth: Multiple layered security controls are implemented so that if one mechanism fails, secondary controls prevent a full breach.
- Fail Securely: When a process or system encounters an error or crashes, it defaults to a closed, safe state rather than exposing access or sensitive data.
- Complete Mediation: Every access attempt to every resource must be validated for authority every single time—a foundational concept of Zero Trust.
- Keep Security Simple (KISS): Systems and architectures are kept as simple and lightweight as possible to minimize attack vectors and simplify auditing.
- Reduce Attack Surface: Unnecessary code, unused features, exposed open ports, and obsolete protocols are eliminated to limit exploitation points.
- Memory Safety: Legacy languages subject to buffer overflows are phased out in favor of memory-safe programming languages (e.g., Rust, Go, Swift).
