Jonathan Leach, Deputy Head Cyber Security Assessment and Advisory Services (part of the Cyber Defence and Risk Directorate), tells us about the new Secure by Design (SbD) Guidance.
For the past three years, Secure by Design has been the main focus of my work, looking to improve cyber security in defence by changing the culture to ensure that security is considered from the start of any capability. The aim of SbD is to reduce the cyber risks across MOD as well as promoting a ‘one team’ approach to cyber-security. This enables and empowers everyone to deliver and maintain capabilities that are resilient from cyber-attacks. To achieve this, we have introduced new policies, a new tool and guidance on how to apply the new approach.

While SbD was mandated in MOD policy, the policy didn’t completely answer the users’ questions when they were looking to actively implement SbD for themselves. As a result, we recently wrote new user-centred guidance for SbD on Digital MOD.UK. This is now the go-to place for all Secure by Design guidance material, and replaces the previous guidance hosted on Defence Gateway.
Why the change?
While the Defence Gateway guidance was comprehensive, it became increasingly technical and inaccessible to those who could not access Defence Gateway. The move to the Digital MOD.UK platform allows us to:
- Improve Accessibility: We noticed that a lot of our target users work outside of the MOD and in the wider defence industry. So, we decided to put the guidance on Digital MOD.UK because it is available online to everyone.
- Enhance Clarity: By adhering to Government Design Standards and identifying the essential information for users, the new guidance is more concise and easier to understand for all audiences.
What’s next?
As we deliver Secure by Design, we understand that users may need additional support beyond the guidance. Other areas of support we will provide include:
- Outreach and Engagement: Look out for our Focus Sessions, Lunch and Learn events, and industry events on Defnet.
- Feedback: The Secure by Design guidance is a work in progress that we're continuously improving, with resources coming soon. Help us tailor the content by sharing your feedback directly via the Give Feedback link.
Leave a comment