
The UK government’s Secure by Design is meant to shape decisions, not be a form completed near go-live. Here is what doing it properly looks like.
Secure by Design is the UK government’s approach to building cyber security into digital services from the outset, rather than assessing it near the end. It is mandatory for government departments, and it comes with a self-assessment and a confidence profile. The most common failure is not technical: it is treating the self-assessment as a document to complete just before go-live.
The intent is simple and sound. Security decisions are cheapest and most effective when they are made early, while the architecture, suppliers and operating model are still choices rather than commitments. Secure by Design asks teams to identify risk continuously through delivery and to be able to show, with evidence, how confident they are in the service they are building.
When Secure by Design is understood as a form, it gets filled in when a form is due - near a gate, near go-live. By then the significant decisions have already been made, so the assessment records history instead of shaping the design. Worse, a high confidence score produced retrospectively is actively misleading to everyone who relies on it.
A confidence profile completed after the decisions are made does not measure the service. It measures how good the team is at describing decisions it can no longer change.
Doing Secure by Design properly starts with ownership: someone accountable for cyber risk for the service, so decisions do not fall between the delivery team and central security. From there, threat modelling and risk-driven design belong at the points where architecture and procurement choices are actually made, not in a review afterwards.
Capture decisions, risk acceptances and supporting evidence while the work is happening. Reconstructing them later from memory is slow, unreliable, and exactly the pattern that produces a misleading score. Evidence gathered in the moment is both more accurate and far cheaper to produce.
Use the self-assessment as a live conversation about confidence through delivery, not a one-off document produced before a gate. When the confidence profile reflects the service as it is actually being built, it becomes genuinely useful - to the team, to the senior owner, and to the assurance reviewer who will ask not just what your score is, but why.
That shift, from a form completed late to a set of decisions made early with the evidence to back them, is the whole point of Secure by Design. It is also the difference between a confidence score you can defend and one you simply hope nobody examines.
Written by the E2E Security Consulting team. This article is general guidance, not formal advice on your specific circumstances - for that, the useful first step is a short conversation.