Secure by design
19
MENTIONS
7
EPISODES
7
PODCASTS
Search complete. 19 mentions across 7 episodes found for "Secure by design".
Sep 8, 2026
Why Identity — Not the Network — Is Your First Line of Defense Against Tomorrow's AI Agents
K
30:44Kimberly J. LewisHOST
to take, Dennis, we're going to take a short break.
K
30:46Kimberly J. LewisHOST
And when we come back, I want to talk a little bit about Secure by Design and then kind of talk about, you know, we're three quarters of the way through 2026 now.
K
30:58Kimberly J. LewisHOST
And kind of talk about what you think is coming up in 2027.
K
31:02Kimberly J. LewisHOST
Right.
Episode 98: Rethinking ERP Security in a 24/7 AI Driven World
J
15:10Jan StoeltingGUEST
And this is a challenge we see.
J
15:11Jan StoeltingGUEST
So the goal should not be to slow innovation, but rather to adapt security by design approaches.
J
15:17Jan StoeltingGUEST
So to build security directly into innovation.
J
15:21Jan StoeltingGUEST
such as security, governance, compliance, and AI.
Risky Bulletin: Two TeamPCP members arrested in Australia
C
7:47Claire AirdHOST
Most of the attacks targeted a small number of vulnerabilities.
C
7:51Claire AirdHOST
CISA says continuing its Secure by Design initiative should help secure against easy targeting and insecure software in the long run.
C
8:00Claire AirdHOST
Researchers from VulnCheck have discovered two more backdoors in ZBT home routers' firmware.
C
8:06Claire AirdHOST
One, named DarkLantern, listens to incoming network packets for commands, while the other, SpeakingStone, phones home to a preset domain at regular intervals.
CI Fortify: Isolation, Recovery and a Minimum Viable America with CISA's Matt Rogers
F
30:32Frank CilluffoHOST
Awesome.
F
30:32Frank CilluffoHOST
Two, two more questions and then I wanna pivot, but how does CI Fortify fit into the broader secure by design thinking? And if you could wave a magic wand and ask, uh, an OT, a- a- any new OT product, now the challenge is many are legacy products that have been around forever, what's the one thing you'd like to see them fix? So two, two, two biggies there.
M
30:56Matthew RogersGUEST
Okay.
M
30:56Matthew RogersGUEST
So I, I will say I, I started the secure by design specifically for OT work at CISA.
F
31:00Frank CilluffoHOST
For OT.
F
31:00Frank CilluffoHOST
Yeah, you led that effort, right?
M
31:02Matthew RogersGUEST
I did, and I, I still do.
M
31:04Matthew RogersGUEST
And so there is a lot of secure by design that kind, kind of gets snuck under the coat of, uh, CI Fortify sometimes.
#596: This is the Real Cybersecurity Problem
J
21:35Jen EasterlyGUEST
Yeah, no, absolutely.
J
21:36Jen EasterlyGUEST
I mean, look, hopefully folks are somewhat familiar with the whole secure by design movement, but we really leaned into this.
J
21:44Jen EasterlyGUEST
And so- I would highly recommend that your listeners just check out the website on CISA.gov. There's a whole bunch of really interesting technical information around the Secure by Design campaign.
J
21:59Jen EasterlyGUEST
What does it actually mean? How do you build secure products from a supplier-vendor perspective? We actually did this whole pledge.
J
22:07Jen EasterlyGUEST
And we started out, we did it at RSA in 2024.
J
23:19Jen EasterlyGUEST
It led to compliance box checking, not actually operational risk reduction.
J
23:24Jen EasterlyGUEST
So I'm not a huge fan of regulation.
J
23:27Jen EasterlyGUEST
But I think that the EU Cyber Resilience Act is actually pretty interesting because much of what it asks vendors to do aligns with the secure by design principles that we've been putting out for a while now we've been talking about.
When AI Generated Patches Become the New Vulnerability
K
37:54Keith HoodletGUEST
So
P
37:55Phyllis LeeHOST
I have a question like, you know, maybe because we just, you know, thinking about secure by design, but, you know, you also have to run your patches regardless of who writes it.
P
38:06Phyllis LeeHOST
AI, human, combo of both.
P
38:08Phyllis LeeHOST
You have to run it through your secure by design best practices, right? right? You have to go, you have to look, you know, you have to check the, whatever, you know, your normal code checking, and maybe it's enhanced by AI.
P
38:21Phyllis LeeHOST
You should still be doing that.
P
38:22Phyllis LeeHOST
Did you take that into consideration for your scenarios?
K
38:50Keith HoodletGUEST
And I think to the point that you're driving toward, that I think is a really strong example of what good, secure design outcomes can produce, is you go back to, I think it was maybe March or April, when Firefox released a pretty big patch set, something like 200 plus patches.
K
39:09Keith HoodletGUEST
But they talked about in that same release, how there were a very large hundreds of vulnerabilities that did not need to be patched because of the design and architecture of the software that prevented those from ever becoming exploitable.
DEF CON 34
K
14:32Kerry ParkerHOST
He also worked at CISA and was the head of security, the CISO or CISO at Yahoo at one point.
K
14:39Kerry ParkerHOST
And he's also led a lot of great work around this notion of secure by design.
K
14:42Kerry ParkerHOST
That initiative is something that he has been one of the kind of founders of.
K
14:47Kerry ParkerHOST
And he's just a great guy.
6 MINS LATER
B
20:56Bob LordGUEST
I'll probably do another newsletter.
B
20:58Bob LordGUEST
coming up soon, so go check that out.
B
21:01Bob LordGUEST
And then, you know, my main passion is around Secure by Design.
B
21:04Bob LordGUEST
I've been doing a bunch of consulting for organizations to help them think through their security of their systems.