Software Engineering Institute (SEI) Podcast Series · Members of Technical Staff at the Software Engineering Institute

Mitigating Cyber Risk with Secure by Design

·32 min·2 clips
Greg says secure by design has a one-to-many relationship with national security and prosperity.
1. Software Engineering Institute (SEI) Podcast Series episode "Mitigating Cyber Risk with Secure by Design" centers on secure by design as a response to ransomware and systemic cyber risk. 2. Matthew Pekovic, technical director of Cyber Risk and Resilience in the CERT Division, interviews Greg Tuhill, who is a co-author of the AFSEA International Cyber Committee paper and a former Air Force captain. 3. The episode asks why the paper was written now, and Tuhill ties that answer to ransomware, national security, and economic prosperity. 4. Tuhill says John Gilligan, CEO of the Center for Internet Security and chair of the SEI Board of Visitors, served as lead author of the paper. 5. Tuhill argues that ransomware attacks point to systemic vulnerabilities in the cyber ecosystem rather than isolated incidents. 6. He says secure by design matters because hardware, software, and the human element all shape that ecosystem. 7. Tuhill describes national security and national prosperity as depending on a safe, secure, and trusted cyber ecosystem. 8. He says secure by design can "buy down that risk" by producing secure code and secure systems from the start. 9. He distinguishes design-phase security from post-deployment work, saying operational issues such as zero days still require management after release. 10. Tuhill says the SEI has been a pioneer in secure by design, citing birthright documents from 1988 and secure design principles published in 2009. 11. He recalls using SEI products in 1988 while serving as a captain in the Air Force on national security capabilities. 12. Tuhill says CISA amplified earlier SEI work and cites the February 2023 secure by design campaign launched by Jen Easterly at Carnegie Mellon and the SEI. 13. He lists the campaign’s three principles: take ownership of customer security outcomes, embrace radical transparency and accountability, and build organizational structures and leadership for the goal. 14. Tuhill says the AFSEA report adds six common solution-set attributes because the campaign still lacked discrete measures, prioritization of best practices, and appropriate motivation. 15. He names organizational culture, a formal process for identifying and prioritizing risk, and a standardized software development environment as key attributes. 16. Tuhill also emphasizes robust automated tools, metrics and measures of merit, and mitigation of external software dependencies through software bill of materials practices. 17. The conversation is interview-based and technical, with Matthew Pekovic pressing for practical implications and Tuhill answering in long, structured explanations. 18. The tone stays policy-oriented and implementation-focused, especially when Tuhill shifts from software to systems, supply chains, leadership, and measurement. 19. People working on cybersecurity policy, secure software, and AI-enabled systems would likely get the most from this episode. 20. Listeners wanting a light or entertainment-first show will probably skip this one.

As heard by us

A sober, practical episode on turning secure-by-design principles into organizational and software-development habits.

The episode takes a broad warning about cyber risk and brings it down to the level of everyday software practice: how organizations can make security part of the work before anything reaches a customer.

Read the full review in PlayNext →

Why you'd press play

You want to know whether building in security from the start can hold up against ransomware pressure, critical infrastructure risk, and the messy handoff from development to delivery.

Read the full recommendation in PlayNext →
Listen to the show on