Skip to main content
Secure by design

Secure by design

Search complete. 19 mentions across 7 episodes found for "Secure by design".

Sep 8, 2026

Kimberly J. LewisHOST
30:44
to take, Dennis, we're going to take a short break.
Kimberly J. LewisHOST
30:46
And when we come back, I want to talk a little bit about Secure by Design and then kind of talk about, you know, we're three quarters of the way through 2026 now.
Kimberly J. LewisHOST
30:58
And kind of talk about what you think is coming up in 2027.
Kimberly J. LewisHOST
31:02
Right.
Jan StoeltingGUEST
15:10
And this is a challenge we see.
Jan StoeltingGUEST
15:11
So the goal should not be to slow innovation, but rather to adapt security by design approaches.
Jan StoeltingGUEST
15:17
So to build security directly into innovation.
Jan StoeltingGUEST
15:21
such as security, governance, compliance, and AI.
Claire AirdHOST
7:47
Most of the attacks targeted a small number of vulnerabilities.
Claire AirdHOST
7:51
CISA says continuing its Secure by Design initiative should help secure against easy targeting and insecure software in the long run.
Claire AirdHOST
8:00
Researchers from VulnCheck have discovered two more backdoors in ZBT home routers' firmware.
Claire AirdHOST
8:06
One, named DarkLantern, listens to incoming network packets for commands, while the other, SpeakingStone, phones home to a preset domain at regular intervals.
Frank CilluffoHOST
30:32
Awesome.
Frank CilluffoHOST
30:32
Two, two more questions and then I wanna pivot, but how does CI Fortify fit into the broader secure by design thinking? And if you could wave a magic wand and ask, uh, an OT, a- a- any new OT product, now the challenge is many are legacy products that have been around forever, what's the one thing you'd like to see them fix? So two, two, two biggies there.
Matthew RogersGUEST
30:56
Okay.
Matthew RogersGUEST
30:56
So I, I will say I, I started the secure by design specifically for OT work at CISA.
Frank CilluffoHOST
31:00
For OT.
Frank CilluffoHOST
31:00
Yeah, you led that effort, right?
Matthew RogersGUEST
31:02
I did, and I, I still do.
Matthew RogersGUEST
31:04
And so there is a lot of secure by design that kind, kind of gets snuck under the coat of, uh, CI Fortify sometimes.
Jen EasterlyGUEST
21:35
Yeah, no, absolutely.
Jen EasterlyGUEST
21:36
I mean, look, hopefully folks are somewhat familiar with the whole secure by design movement, but we really leaned into this.
Jen EasterlyGUEST
21:44
And so- I would highly recommend that your listeners just check out the website on CISA.gov. There's a whole bunch of really interesting technical information around the Secure by Design campaign.
Jen EasterlyGUEST
21:59
What does it actually mean? How do you build secure products from a supplier-vendor perspective? We actually did this whole pledge.
Jen EasterlyGUEST
22:07
And we started out, we did it at RSA in 2024.
Jen EasterlyGUEST
23:19
It led to compliance box checking, not actually operational risk reduction.
Jen EasterlyGUEST
23:24
So I'm not a huge fan of regulation.
Jen EasterlyGUEST
23:27
But I think that the EU Cyber Resilience Act is actually pretty interesting because much of what it asks vendors to do aligns with the secure by design principles that we've been putting out for a while now we've been talking about.
Keith HoodletGUEST
37:54
So
Phyllis LeeHOST
37:55
I have a question like, you know, maybe because we just, you know, thinking about secure by design, but, you know, you also have to run your patches regardless of who writes it.
Phyllis LeeHOST
38:06
AI, human, combo of both.
Phyllis LeeHOST
38:08
You have to run it through your secure by design best practices, right? right? You have to go, you have to look, you know, you have to check the, whatever, you know, your normal code checking, and maybe it's enhanced by AI.
Phyllis LeeHOST
38:21
You should still be doing that.
Phyllis LeeHOST
38:22
Did you take that into consideration for your scenarios?
Keith HoodletGUEST
38:50
And I think to the point that you're driving toward, that I think is a really strong example of what good, secure design outcomes can produce, is you go back to, I think it was maybe March or April, when Firefox released a pretty big patch set, something like 200 plus patches.
Keith HoodletGUEST
39:09
But they talked about in that same release, how there were a very large hundreds of vulnerabilities that did not need to be patched because of the design and architecture of the software that prevented those from ever becoming exploitable.
Kerry ParkerHOST
14:32
He also worked at CISA and was the head of security, the CISO or CISO at Yahoo at one point.
Kerry ParkerHOST
14:39
And he's also led a lot of great work around this notion of secure by design.
Kerry ParkerHOST
14:42
That initiative is something that he has been one of the kind of founders of.
Kerry ParkerHOST
14:47
And he's just a great guy.

6 MINS LATER

Bob LordGUEST
20:56
I'll probably do another newsletter.
Bob LordGUEST
20:58
coming up soon, so go check that out.
Bob LordGUEST
21:01
And then, you know, my main passion is around Secure by Design.
Bob LordGUEST
21:04
I've been doing a bunch of consulting for organizations to help them think through their security of their systems.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.