Breaking
April 28, 2025

Secure by design: what we can learn from the financial services sector | usagoldmines.com

More than 250 companies have signed the “Secure-by-Design” (SBD) pledge from the Cybersecurity and Infrastructure Security Agency (CISA). By committing to the voluntary pledge, software manufacturers are promising to increase multi-factor authentication (MFA) for products; better enable customers to do their own patching; reduce default passwords; and decrease vulnerabilities, among additional proactive, protective practices.

By embedding cyber defense from the outset of product development and system architecture, SBD is intended to transform cybersecurity from an afterthought to an essential, core element of design. Companies that fail to adopt this approach run the risk of falling behind in their security and compliance maturity, while losing consumer trust. They also could run into some very expensive problems, as the average cost of a data breach has increased to $4.88 million – up from $4.45 million in 2023.

Implementing an SBD strategy

So how do organizations effectively implement an SBD strategy? They can start by looking at the financial services sector, which is often more willing to invest in innovative approaches to security upskilling and additional preventative measures than other industries. These institutions are taking such steps because, frankly, they have to, given the immense challenges they face:

Increasing – and more costly – threats

If history has taught us anything, it’s that cyber criminals always follow the money. Financial organizations are experiencing 1,115 breaches a year, which ranks #4 among all verticals.

Regulatory pressures

The Payment Card Industry Data Security Standard (PCI DSS) and the European Union’s General Data Protection Regulation (GDPR) require financial organizations to achieve higher levels of governance and security. As part of the ongoing compliance process, the industry’s developers must bring verified skills to properly configure sensitive databases, payment gateways and portals.

The critical – and fragile – state of consumer trust

Financial service firms’ customers expect no less than the absolute fortification of their personal data and transactions. If an institution suffers an attack that compromises any of this, it runs the risk of losing consumer trust with potentially devastating market/revenue consequences – if not extinction.

SBD developer readiness

Fortunately in our research, we have found that the financial industry is doing an exceptional job of positioning for SBD developer readiness. There is no quality that is more “make or break” in significance than the upgrading of the skills and tools of the people who innovate, develop and disseminate code at the heart of our digital systems.

Indeed, in taking a closer look at what these companies are doing, we get a better sense of the level of developer risk management this industry is pursuing– and can help lift other industries as they “shift left” in seeking to make good on the CISA pledge.

Investments in upskilling

On average, in organizations, there are less than four software security group (SSG) specialists for every 100 developers. Given how few of these specialists are on board, it’s no wonder that code-level vulnerabilities continue to plague most verticals.

This speaks to the urgency of developer upskilling, with a focus on flexible, dynamic training programs that align learning within the context of “real life” threats – a “learning by doing” approach. The financial sector is considered an early adopter of these and other initiatives aimed at building security into the software development life cycle (SDLC), and has achieved high maturity rates here as a result.

Benchmarking

To ensure upskilling initiatives are working, organizations must establish baselines and benchmarks to assess whether SBD is recognized as an indispensable part of their DNA. Such benchmarking should cover the state of developers’ security skills, awareness and the measurement of their success profile against that of other industry members. With this, these leaders will truly know if their teams have earned a “license to code,” and that the inherent risk of developers with low security skills is being managed and effectively improved.

Proactive threat modeling and testing

Financial services providers are quite good at regularly conducting threat modeling to address risks sooner rather than later – preferably before an attack ever has a chance to strike. The industry also relies upon strict code reviews, testing and audits to reveal vulnerabilities and additional areas of concern.

By following financial institutions’ lead in establishing a baseline for developer risk management activities and implementing the described best practices, organizations across the board will cultivate a winning developer-driven security culture. This environment will prepare developers to implement robust, secure code from start to finish, to the point in which this emerges as a habit they can perform at speed.

That’s when companies of all kinds will demonstrate they’re doing far more than simply signing CISA’s pledge – they’re delivering on its promise to make SBD a universal norm by acting now to defend the future.

We rate the best school coding platform.

This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

The iPhone 17 Pro looks chunky in the latest leak, but it could still sell better than the sleek iPh...

Simplify your business accounting needs with Intuit QuickBooks, now 64% off | usagoldmines.com

Gartner: enabling cybersecurity amid geopolitical rifts | usagoldmines.com

The government’s ransomware payment ban: what are the wider implications? | usagoldmines.com

What Makes Shopify Delivery Flexibility the Future of Online Shopping? Anuradha Sinha | usagoldmines...

Nothing makes sense: why the company's new (3a) Pro is my favorite affordable premium smartphone ove...

In HBO’s The Last of Us, revenge is a dish best served democratically Andrew Cunningham | usagoldmin...

Best PC computer deals: Top picks from desktops to all-in-ones | usagoldmines.com

Revisiting iZombie, 10 years later Jennifer Ouellette | usagoldmines.com

Largest DDoS attack of 2025 hit an online betting organization with 1Tbps brute force: here's what w...

Amazon Introduces $50 Discounts on Nearly Every 11th Gen iPad, Now Starting at $299 Mitchel Broussar...

Google teases a key upgrade for Android Find My Device coming "very soon", and touts 4x speed improv...

DEAL: You Can Get a Pixel Watch 2 for $149 Kellen | usagoldmines.com

AirPods 4 Hit $99.99 on Amazon, Plus Big Discounts on ANC Model and AirPods Pro 2 Mitchel Broussard ...

Apple Watch Series 10 Hits Lowest-Ever Price of $299 on Amazon, Plus Big Discounts on SE Models Mitc...

DEAL: Google’s Pixel 9 Series Gets $250 Off Discount Kellen | usagoldmines.com

I saw Anker’s new 4K projector, and it really could be the ideal summer party projector james.davids...

Two-thirds of managers think employees are fearful of the impact of AI tools: here's what this surve...

NYT Connections hints and answers for Monday, April 28 (game #687) | usagoldmines.com

NYT Strands hints and answers for Monday, April 28 (game #421) | usagoldmines.com

Quordle hints and answers for Monday, April 28 (game #1190) | usagoldmines.com

Newly leaked DJI Mavic 4 Pro images may have revealed the premium drone's design in full | usagoldm...

“You wouldn’t steal a car” anti-piracy campaign may have used pirated fonts Kevin Purdy | usagoldmin...

I bought a cheap refurbished Steam Deck, and it’s convinced me to skip the Nintendo Switch 2 james.p...

Kill ads on every website and device with AdGuard’s lifetime plan | usagoldmines.com

Adata unleashes the fastest memory card ever - but you will need a special card reader to make the m...

AMD set to launch new Radeon Pro W9000 workstation GPU to take on Nvidia's formidable RTX Pro 6000 B...

Faster than SRAM! New flash memory tech from China is millions of times faster than NAND rivals from...

Anker Offers MacRumors Readers 20% Off Collection of Chargers, Hubs, Batteries, and More Mitchel Bro...

Google ends support for older Nest thermostats – and will stop selling new models in Europe complete...

Windows 10 goes dark in 6 months, yet shockingly, many businesses haven't even got a plan to upgrade...

Netflix's sound-effect-free subtitles will transform how I watch – and GenZ will be over the moon la...

‘It's like magic and everything just works’: We spoke to Adobe’s AI maestro to find out what’s new w...

NYT Strands hints and answers for Sunday, April 27 (game #420) | usagoldmines.com

NYT Connections hints and answers for Sunday, April 27 (game #686) | usagoldmines.com

Quordle hints and answers for Sunday, April 27 (game #1189) | usagoldmines.com

I wish phone makers would stop calling budget phone features 'flagship' jamie.richards@futurenet.com...

Top Stories: iPhone 17 Air Rumors, Apple Watch Turns 10, and More MacRumors Staff | usagoldmines.com

300 billion and counting: most popular chip designer in the world turns 40, and it all started in a ...

New Samsung tri-fold leak gives us another hint about how big the 'G Fold' phone might be | usagold...

Is The Elder Scrolls IV: Oblivion still fun for a first-time player in 2025? Kyle Orland | usagoldmi...

YouTube’s new TV app redesign looks promising, but I hope it fixes this annoying subscriptions probl...

This new app turns your phone into a high quality scanner | usagoldmines.com

ICYMI: the week's 7 biggest tech stories from your LG becoming an Xbox to the new Insta360 X5 camera...

I tried using ChatGPT to restore old photos, here’s how to really do it erichs211@gmail.com (Eric Ha...

Weapons of war are launching from Cape Canaveral for the first time since 1988 Stephen Clark | usago...

Here's How the Switch 2 Specs Compare to the Original Jake Peterson | usagoldmines.com

Reverse Searing Is Faster in the Air Fryer Allie Chanthorn Reinmann | usagoldmines.com

What's Next for the Apple Watch Ultra 3 and Apple Watch SE 3 Juli Clover | usagoldmines.com

HostGator vs Hostinger: finding the better choice in reasonably-priced web hosting providers | usag...

The AI That Cried AAAAAAHHH! erichs211@gmail.com (Eric Hal Schwartz) | usagoldmines.com

Looming tariffs are making it extra hard to be a tech geek Scharon Harding | usagoldmines.com

New study shows why simulated reasoning AI models don’t yet live up to their billing Benj Edwards | ...

Mike Lindell’s lawyers used AI to write brief—judge finds nearly 30 mistakes Jon Brodkin | usagoldmi...

With over 900 US measles cases so far this year, things are looking bleak Beth Mole | usagoldmines.c...

Samsung Galaxy S23, Fold 5, and Flip 5 Get One UI 7 Update in US Kellen | usagoldmines.com

This Cyber Attack Targets Microsoft 365 Accounts Emily Long | usagoldmines.com

How to Get Minesweeper and Seven Other Classic Games Back in Windows 11 Justin Pot | usagoldmines.co...

FBI offers $10 million for information about Salt Typhoon members Dan Goodin | usagoldmines.com

Netflix introduces a new kind of subtitles for the non-hearing impaired Samuel Axon | usagoldmines.c...

New study: There are lots of icy super-Earths John Timmer | usagoldmines.com

Windows is testing a better profanity filter, **** yeah | usagoldmines.com

The Original Google Pixel Watch Is on Sale for $80 Daniel Oropeza | usagoldmines.com

Oura’s AI Chatbot Really Makes You Think—About Yourself Beth Skwarecki | usagoldmines.com

I went hands-on with Eufy’s elusive E10 smart display | usagoldmines.com

Tested! The best Chromebooks you can buy in 2025 — from budget to premium | usagoldmines.com

Slate is the perfect EV pickup truck for PC builders like me | usagoldmines.com

Best VPN for streaming Netflix 2025: Watch from wherever you are | usagoldmines.com

Chrome on Android Lets You Open PDFs in Chrome After All These Years Kellen | usagoldmines.com

How to Track When Nintendo Switch 2 Preorders Are Back in Stock Jake Peterson | usagoldmines.com

This SSD just smashed the 15 GBps speed barrier to become the fastest ever tested, but you won't be ...

Silicon Valley billionaires literally want the impossible Jennifer Ouellette | usagoldmines.com

Google announces 1st and 2nd gen Nest Thermostats will lose support in October 2025 Ryan Whitwam | u...

Thermal imaging shows xAI lied about supercomputer pollution, group says Ashley Belanger | usagoldmi...

Google is dropping support for its oldest Nest Learning Thermostats | usagoldmines.com

My Favorite Amazon Deal of the Day: The Latest M4 MacBook Air Daniel Oropeza | usagoldmines.com

MacRumors Giveaway: Win a 13-Inch iPad Air and Mount From Lululook Juli Clover | usagoldmines.com

WhatsApp says forcing blue Meta AI circle on everyone is a ‘good thing’ despite fierce backlash mark...

North Korean hackers are using advanced AI tools to help them get hired at Western firms | usagoldm...

Ecobee Smart Doorbell Camera (wired) review: A premium porch watcher | usagoldmines.com

Windows Recall is too risky for your Copilot+ PC. Turn it off, now | usagoldmines.com

Blame your phone for killing off this traditional Windows app | usagoldmines.com

This mini PC has 16GB of RAM for just $158 | usagoldmines.com

Zodiac Labs is Bringing Pro-Level Esports PCs to the People | usagoldmines.com

Google Sets End Date for Nest Thermostat 1st Gen and 2nd Gen Kellen | usagoldmines.com

Threads Is Going All In on Ads Pranay Parab | usagoldmines.com

Netflix Finally Adds Dialogue-Only Subtitles Khamosh Pathak | usagoldmines.com

Motorola's Moto Watch Fit might look like an Apple Watch, but it reportedly packs more than 20 times...

Nvidia's RTX 5060 8GB GPU is rumored to launch at $299 - but history suggests it will cost more at r...

Got Philips Hue lights? This new customizable button could make them even smarter | usagoldmines.co...

A worrying stealthy Linux security bug could put your systems at risk - here's what we know | usago...

Almost a million patients hit by Frederick Health data breach | usagoldmines.com

Report: TP-Link’s low router prices probed in criminal antitrust investigation Jon Brodkin | usagold...

Microsoft rolls Windows Recall out to the public nearly a year after announcing it Andrew Cunningham...

Best laptops for college students 2025: Top picks and expert advice | usagoldmines.com

Intel’s older CPUs are being snapped up. Well, duh | usagoldmines.com

I've Been Using This Sizzling Oil Sauce, and It Transforms Any Main Course Allie Chanthorn Reinmann ...

The MacRumors Show: Latest iPadOS 19 and iPhone 17 Air Rumors Hartley Charlton | usagoldmines.com

A grim signal: Atmospheric CO2 soared in 2024 Bob Berwyn, Inside Climate News | usagoldmines.com

Why I never use a bottleneck calculator to decide my PC gaming hardware | usagoldmines.com

Leave a Reply