Security by Design

Security begins with the design of the foundation.

Why is Security by Design important?

Security by Design originally comes from software development, but must be understood holistically: Both the processes and the infrastructure and software of an organization must meet an individual IT security level, which must be taken into account during the planning phase.

In addition to more efficient work processes, Security by Design prevents high follow-up costs; studies show that the costs for correcting security flaws during the implementation phase are 6.5 times, during the testing phase 15 times, and after release 60 times higher than if security had been planned during the design phase.

From an economic point of view, security cannot mean "as secure as possible". Together with you, we determine how secure your processes and applications need to be and ensure that instead of fear of threats, you have confidence in the architecture of your processes and applications.

  • Demand-oriented IT security
  • Avoidance of expensive error corrections
  • Protection against financial and reputational damage
  • Confidence in your own processes and applications

What modules are available for Security by Design?

Concept Creation

For the design of a secure architecture that considers the four levels of information security (protection, deterrence, detection, and response), we first identify risks and threats. Only through risk analysis and threat modelling can strategies and countermeasures for a secure architecture be developed. We support you in the conceptualization of processes and applications and take over the design review so that security aspects can be taken into account at an early stage.

Information Security Management

According to ISO/IEC 27001, information security management is understood as measures and regulations that are intended to guarantee the security of information and systems permanently and to improve them constantly. Together with you, we define the required security level for your organization and develop an IT security concept for this. Through these technical and organizational measures and regulations, the desired goal of IT security is achieved in an economically efficient manner. We also support you in drawing up crisis operation plans so that you are prepared for disaster recovery in case of an emergency.

Security in the Development Process

The specifications of a secure architecture are implemented in the development process. We support you in defining a robust development process that detects errors during implementation and delivers secure software. Best practices such as peer reviews, automation, and testing, paradigms, and checklists help to avoid errors.

Training

Technical measures to protect infrastructure and data are relatively easy to implement. These are supported by organizational measures intended to influence human behavior. This complex task can be supported by training to create awareness of security and data protection. We demonstrate unconscious dangers in live hacking presentations, create this awareness in special awareness training, and support the development team with our secure coding training.

Defects in planning lead to high follow-up costs and loss of image. Ensure Security by Design.