Secure-By-Design Is Your New Friend
This is so good that it deserves amplification.
Since 2023, CISA -- the US Cybersecurity and Infrastructure Security Agency -- has pushed software manufacturers toward three secure-by-design commitments: take ownership of customer security outcomes, embrace radical transparency and accountability, and lead from the top. That last one matters more than its plain wording suggests. It puts security accountability on senior leadership, not just the engineers writing the code.
More recently, CISA extended the same thinking to the 'buy side': a guide for software purchasers, with questions to ask vendors before you sign. That's the piece CISOs should actually be pinning up: security starting at procurement, not bolted on after deployment.
How realistic is any of this? Jen Easterly, former Director of CISA, posted an announcement on LinkedIn that as of late September 2026 the State of Oregon is applying these principles in its own procurement practice. If a state government can do it, you can, too. Can't you?
We routinely note in the Litany of the Hacked that creating community and shared resources is paramount to effective cyber-defense. CISA's work here is what's needed to begin a virtuous cycle of pooled resources and creating a security culture mindset.
Thank you, CISA!
Ask us how you can create a secure-by-design virtuous cycle.
Comments
Post a Comment