
A delivery programme told that Secure by Design was mandatory, with the self-assessment treated as a document to complete near go-live.
The team understood Secure by Design as a form to fill in. Security decisions were still being raised late, and the self-assessment was being completed retrospectively to describe choices that had already been made.
That inverts the intent. Completed late, the assessment records history rather than influencing design — and a high confidence score produced that way is misleading to everyone who relies on it.
Security decisions started landing early enough to change the design rather than to document it, and the confidence profile began reflecting the service as built.
The team could explain not just what its score was, but why — which is the question an assurance reviewer actually asks.
This is an anonymised, representative engagement. We do not publish client names, or figures we cannot substantiate, without explicit permission — in government and critical infrastructure, naming a client can itself be a security concern.