Secure by Design, Secure by Default, Secure by Demand: The Signs of a Secure Software Supply Chain

Secure by Design, Secure by Default, Secure by Demand: The Signs of a Secure Software Supply Chain

Welcome to Data Security Decoded. Join host Caleb Tolin in conversation with Lauren Zabierek, Senior Vice President for the Future of Digital Security at the Institute for Security and Technology. A former CISA leader and long-time national security professional, Lauren unpacks the principles of Secure by Design, Secure by Default, and Secure by Demand and how these frameworks are reshaping the software supply chain.

What You’ll Learn:
Why security must be a business decision led by executives rather than a technical afterthought
How Secure by Design principles inspired more than 300 companies to eliminate entire classes of vulnerabilities
The economic incentives that drive insecure software and what must change to realign the market
How customers can evaluate vendors and ask the right questions to ensure secure authentication and transparent practices
The role of Secure by Demand in helping buyers assess software safety before and after adoption
Why initiatives like #ShareTheMicInCyber are essential for expanding diversity and innovation across cybersecurity policy

The conversation offers a practical roadmap for executives, CISOs, and technology leaders to integrate secure development practices into business strategy, turning software security from a compliance checkbox into a competitive advantage.

Chapters:
[00:00] Intro
[00:26] Fall vibes and theatre talk
[02:05] Drumming, dance, and creativity beyond cybersecurity
[04:04] From aviation safety to software safety
[08:46] How the Secure by Design pledge was born
[09:41] The three pillars of Secure by Design
[11:59] Rethinking security as a business and economics issue
[15:41] Secure by Demand: What customers should ask vendors
[18:23] The story and impact of #ShareTheMicInCyber
[23:35] Where to learn more and what’s next for software security

Episode Resources:
Caleb Tolin on LinkedIn: https://www.linkedin.com/in/calebtolin
Lauren Zabierek on LinkedIn: https://www.linkedin.com/in/laurenz1010
Institute for Security and Technology (IST): https://securityandtechnology.org
Secure by Demand Guide from CISA: https://www.cisa.gov/resources-tools/resources/secure-demand-guide
Secure by Design Pledge from CISA: https://www.cisa.gov/securebydesign

👉 Subscribe here: https://rbrk.co/4cVWzno

#Cybersecurity #Leadership #SoftwareSecurity