patch&proof.
← The dispatch

standards / Archive analysis

Secure by Design shifted attention from users to product makers

CISA's 2023 principles asked suppliers to take ownership of customer security outcomes.

Historical backfill · prepared 16 September 2026. Dates below describe the source or event; this is a local review edition.

Development brief

In November 2023, CISA discussed the revised international Secure by Design principles released the previous month. The agency summarized three themes: take ownership of customer security outcomes, embrace transparency and accountability, and lead from the top. The earlier principles had already challenged a familiar pattern in which customers receive a long list of settings while insecure defaults and avoidable product weaknesses remain the supplier's problem only in name. The November article documents the revised paper's direction; it is not the original launch date for the entire initiative.

The change in responsibility

Secure by Design does not mean a customer has no configuration duties. It asks whether the product arrives with a safer baseline and whether the maker can show how its design reduces foreseeable classes of harm. A buyer with limited security staff may be unable to compensate for an unsafe default spread across thousands of deployments. Transparency also means explaining product risks and remediation in terms customers can act on, not simply shifting liability through documentation. The principle is most useful when procurement, engineering and support all see the same measurable customer outcome.

Defensive reading

A supplier can test new installations for safe defaults, reduce unnecessary privileges, and make strong authentication and useful logs available without obscure paid tiers or fragile manual steps. A customer can ask what works securely out of the box, what remains its responsibility, and how the supplier communicates incidents and fixes. Record those answers in onboarding and revisit them after product changes. Measure whether users can safely operate the product in practice, not whether a security option technically exists in a manual.

What remains bounded

The CISA principles are guidance, not a certificate that signatories or vendors have achieved them. A marketing pledge should be checked against product behavior. This article does not offer legal advice about obligations in any jurisdiction. Its historical significance is a change in the location of the question: from why every customer failed to configure a control to why a product required so many customers to repair its baseline.

Evidence & dates

Follow the source.

CISA article dates the revised principles to October 2023; cited November commentary is not the original initiative date. Full page fetch returned 403.

Source published
2023-11-16
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Applying Secure By Design Thinking to Events in the News
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval