I’ve been thinking about a surprisingly intricate question:




Where does Secure by Design actually end?


The term now covers everything from threat modelling and architecture reviews to secure development, vulnerability scanning and assurance.

All of these are important, but I think there is value in separating designing a system to be...