Cyber Security
Case Study

Adopting Secure by Design in live delivery

A delivery programme told that Secure by Design was mandatory, with the self-assessment treated as a document to complete near go-live.

Secure by DesignDeliveryAssurance

The challenge

The team understood Secure by Design as a form to fill in. Security decisions were still being raised late, and the self-assessment was being completed retrospectively to describe choices that had already been made.

That inverts the intent. Completed late, the assessment records history rather than influencing design — and a high confidence score produced that way is misleading to everyone who relies on it.

Our approach

  1. Create real ownershipEstablish who owns cyber risk for the service, so decisions have an accountable owner instead of falling between delivery and security.
  2. Move decisions earlierBring threat modelling and risk-driven design into the points where architecture and procurement choices are actually made.
  3. Evidence as you goCapture decisions, risk acceptances and supporting evidence while the work happens, rather than reconstructing them later from memory.
  4. Make assurance continuousUse the self-assessment as a live conversation about confidence through delivery, not a document produced once before a gate.

What changed

Security decisions started landing early enough to change the design rather than to document it, and the confidence profile began reflecting the service as built.

The team could explain not just what its score was, but why — which is the question an assurance reviewer actually asks.

This is an anonymised, representative engagement. We do not publish client names, or figures we cannot substantiate, without explicit permission — in government and critical infrastructure, naming a client can itself be a security concern.

Other case studies

Recognise this situation?

If yours looks similar, the useful first step is usually a conversation about what is actually driving the requirement.