Skip to main content

Raising the cyber resilience of software 'at scale'

New ‘Code of Practice for Software Vendors’ will ensure that security is fundamental to developing and distributing products and services.

iStock.com/ArtemisDiana

Software is the lifeblood of our digital economy. But alongside the benefits it provides, it introduces risks that need to be managed across our software supply chains, to ensure our systems remain resilient against cyber attacks.

In a recent blog, Ollie Whitehouse explained that cyber security shouldn’t be a premium feature, just as seatbelts have never been a price differential in the car industry. The voluntary Code of Practice for Software Vendors is a systemic intervention by the UK government, designed to ensure that security is ‘baked into' software, rather than a costed extra.

The Code is aimed at software vendors*, setting out the minimum set of actions that should be in place to ensure their products and services are resilient to a cyber attack from a commodity threat. It will begin as voluntary code, but further policy interventions to support its uptake and impact are currently being explored. You can respond to the call for views by visiting the Code of Practice for Software Vendors page on the gov.uk website.


There are many things that a vendor can do to make their product more secure, but in reality, we know cyber security is just one of many risks an organisation is juggling. Organisations ultimately have a ‘compliance budget’; a limit to the number of things they can afford to do well whilst also making a profit. The Code therefore defines a modest set of provisions, and working collaboratively with industry we have tested the efficacy of each control, ensuring they are proportionate to both the vulnerabilities they remove and the likely budget available, given that the 98% of the UK’s private-sector comprises small businesses (ie with less than 49 employees).  For this reason, we particularly welcome any thoughts on the proportionality and impact the code would have on vendors of all sizes and sectors, through the call for views.

Build environment security is included in the Code, since this is critical to the cyber resilience of the software product or service. It is drawn out as a separate principle as we recognise its importance as a distinct area of focus with its own complexities. We would expect any software vendor in the critical supply chain market (that is, facing an elevated threat) to have taken significant steps to improve the cyber resilience of their organisational, development and build environments, as directed by their customers. However, for vendors whose products and services require basic cyber resilience (that is, against a commodity threat), the cost of this exceeds the benefit to the consumer.

For this reason, the provisions under Principle 2 focus on the interactions between the developers and the build environment, and we will pursue other interventions that will support software vendors to build trust in their development and build environments.
 



Written by

Helen L CTO Cyber Growth, NCSC