
Embed the ten Secure by Design principles throughout governance, digital delivery, architecture, risk management and continuous assurance. We help government organisations and delivery teams implement the UK Government Secure by Design approach across individual services and wider portfolios.
Secure by Design is not a final-stage security review. It integrates cyber security into the delivery of digital services and technical infrastructure from the outset and throughout the service life cycle — so security is designed in, owned, and evidenced as the service evolves.
It changes where and how cyber security decisions are made: instead of relying on a security check shortly before go-live, it asks delivery teams to weigh cyber risk when shaping the business case, selecting technology, designing the service, procuring suppliers, building controls and managing operational change.
The approach is collaborative rather than security-owned. Senior responsible owners, service owners, product and delivery managers, architects, engineers, commercial teams and security professionals all contribute to the security position of the service. The objective is to ensure decisions are proportionate to risk, supported by evidence, and revisited as the service and threat landscape evolve.
The policy applies at both organisational and service-delivery levels. Departments and arm’s-length bodies need an organisational approach that establishes accountability, governance and supporting processes, while individual delivery teams apply the principles and relevant activities to their services.
Suppliers are not automatically subject to the policy in the same way as departments, but they are often central to implementation. Contracting authorities may require suppliers to provide security evidence, participate in threat and risk activities, implement agreed controls, and support the maintenance of the service’s confidence profile.
The ten principles are mandatory when delivering new or significantly changed digital services and technical infrastructure.
Product, delivery, architecture, engineering, commercial and security teams share responsibility for implementation.
Suppliers support the contracting authority's implementation through evidence, controls, risk information and technical activities.
The principles define the outcomes delivery teams must achieve. The supporting activities can be tailored to the organisation, service and risk profile.
Organisations should align Secure by Design activities to their own delivery methodology and the phases used by the official self-assessment (discovery, alpha, private beta and public beta or live). The illustrative lifecycle below shows how ownership, risk, controls, evidence and assurance continue from the business case into live operation.
Good implementation is continuous, proportionate and evidence-based — activities are tailored to the service’s risk and delivery stage, not applied as a fixed checklist.
Organisational adoption is more than asking individual projects to complete the self-assessment. Departments need to define how Secure by Design fits within existing governance, digital delivery, architecture, commercial, risk-management and assurance processes.
We help organisations determine which services are in scope, define decision rights and escalation routes, assign accountable roles, establish proportionate evidence expectations, and create a consistent route from identified gaps to owned remediation or risk decisions.
Where Secure by Design is being introduced across a portfolio, we also support transition planning, pilot projects, champion networks, reporting arrangements and the development of reusable guidance and templates — building a sustainable capability delivery teams can operate without permanent dependence on external consultants.
A Secure by Design operating model and decision rights that fit your existing delivery and assurance governance.
Clear ownership across senior risk, service, delivery and security roles, so implementation is explicitly assigned.
Secure by Design embedded into business cases, governance gates, procurement, architecture review and definitions of done.
A champion network and capability development so teams can sustain the approach themselves.
A portfolio view of confidence profiles and gaps, surfacing systemic issues rather than dozens of separate trackers.
A phased plan to meet the required timescales, with preparation, adoption and operation support.
The result is a consistent organisational approach — rather than every project interpreting the policy independently.
At service level, we work alongside product, delivery, architecture, engineering, commercial and security teams to apply the principles in a way that matches the service’s criticality and risk profile.
Support can begin during discovery or the development of the business case, or it can be introduced later where a project needs to recover from gaps in ownership, risk analysis, architecture, supplier assurance or evidence. We help teams understand what activities are proportionate, produce or review the necessary artefacts, and turn findings into clear decisions and actions.
Our role is not to introduce a parallel security process. We integrate Secure by Design into the team’s existing delivery cadence, governance and tooling — so security work happens alongside service development, rather than immediately before an approval point.
Establish the threats, legal and policy obligations, and risk appetite that shape proportionate decisions.
Practical threat modelling (STRIDE, attack trees) and security risk assessment grounded in real impact.
Proportionate controls connected to the architecture, from identity to data protection and defence in depth.
Assess third-party product and supplier risk, and set the security requirements that carry into contracts.
Capture evidence, risk acceptances and decisions in place as the work happens, mapped to the principles.
Re-assess as the service changes so the confidence profile reflects reality, not just launch day.
The official self-assessment should be maintained as part of normal delivery rather than completed retrospectively. Responses should reflect the current state of the service and be supported by evidence that is relevant, current and proportionate to the question being answered.
We help teams interpret the assessment questions, identify suitable evidence, and distinguish between an activity being started, completed or demonstrated effectively. Where responses produce low or medium confidence, we help translate the underlying gaps into actions with named owners, target dates and appropriate governance oversight.
The confidence profile is a useful indicator of delivery maturity, but it must remain connected to the risks, controls, decisions and evidence behind the answers — and be reviewed whenever the service architecture, supplier arrangements, threat landscape, operating model or risk position changes.
Complete the official questions for the relevant delivery phase.
Link responses to risks, decisions, threat models, controls, tests and supplier evidence.
Turn low and medium confidence into owned actions, and review the assessment when the service changes.
A high confidence profile demonstrates that the approach is being followed. It does not, by itself, prove that the service is secure — and it is not a risk register or a risk treatment plan.
E2ERisk provides an optional workflow and evidence layer around the official Secure by Design approach. It lets organisations assign questions and actions to named owners, link supporting evidence directly to assessment responses, record decisions and approvals, and maintain a history of changes as the service evolves.
At portfolio level, it provides visibility of confidence profiles, overdue activities, recurring gaps and dependencies across multiple services — helping you tell where an issue is isolated to one project, and where it points to a broader capability, supplier or governance weakness.
The platform does not introduce a replacement set of principles or an alternative confidence calculation. It helps you operate the official approach more consistently, with stronger traceability.
The goal is not to replace the tracker — it is to make it meaningful. Explore the E2ERisk Secure by Design module →
Related, but distinct. Evidence developed through Secure by Design may support GovAssure and relevant CAF outcomes — the processes are separate.
Secure by Design helps delivery teams incorporate effective security practices while a service is being designed, built and operated. GovAssure is a separate assurance process for assessing in-scope critical government systems against the NCSC Cyber Assessment Framework, and the CAF defines the security and resilience outcomes and indicators of good practice.
Secure by Design provides an example controls taxonomy based on CAF 4.0, which can help teams align service controls and evidence with relevant CAF outcomes. That alignment reduces duplication and improves evidence reuse — but it does not make the processes interchangeable. A high Secure by Design confidence profile is not a GovAssure result, and completing the self-assessment does not constitute a complete CAF assessment.
Three primary ways to start, plus flexible options where you need them.
For organisations establishing Secure by Design across a portfolio.
For delivery teams applying the principles to a live service.
For projects needing a review before internal assurance.
Ongoing architecture, risk and delivery-team support through the service life cycle.
Focused advisory support shaped around a specific decision, gap or assurance milestone.
Secure by Design requires more than familiarity with a checklist. It requires practitioners who understand government delivery, security architecture, cyber-risk ownership, organisational assurance and the practical constraints faced by multidisciplinary teams.
Our consultants bring experience from UK government and regulated environments, where security decisions must be technically sound, proportionate and defensible to senior risk owners and independent assurance. We support both sides of the problem — establishing the organisational model, and working directly with delivery teams to apply it to real services.
Read the source. We help you apply it.
Whether you are standing up organisational adoption across a portfolio or supporting a single delivery team, we help you meet the ten principles, evidence the official self-assessment, and build continuous assurance into how you already govern and manage risk.