Studies in secure system design
Worked examples for Operational Technology and Virtualised systems, using the NCSC’s secure design principles
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Worked examples for Operational Technology and Virtualised systems, using the NCSC’s secure design principles

Our Secure design principles carefully divide up the work of creating and evaluating secure systems of all kinds.
To be widely applicable like this, the principles themselves remain at a fairly high level. This leaves you to fill in the blanks for your particular scenario.
This process may not come naturally to everyone, so to help you make the most of the principles, we’ve released a pair of fictionalised ‘case studies.’ Each working through the system design process, guided by the principles and the practical demands of a real-world project. These principles and associated case studies have been developed from NCSC’s experience supporting customers across the UK.
This blog post introduces those case studies and signposts some related work on securing Critical National Infrastructure (CNI), developed by our partners at CISA, in the US. Alongside NCSC’s guidance presented here, CISA have developed a handy and concise summary of cyber security best practices for Industrial Control Systems (ICS). More on this below.
Our first case study follows the design of the kind of cyber physical system used by CNI projects, like power stations and water treatment plants. In this fictionalised study, Adminox is a highly volatile, but universally essential, form of administrative paperwork. We join the story as its main producer, Admin Corp, sit down to assess the design of their end-to-end production, storage and distribution system.
The second study looks at the peculiarities of virtualised systems. Here, we follow another fictitious manufacturing company, this time, looking to consolidate their infrastructure using virtualisation. Crucially, they want to do this without impacting the integrity or availability of their systems.
As a system progresses through the design phase of the life-cycle into production, it is essential that the right cyber security practices are established. CISA’s infographic will be an invaluable guiding reference during this step of the process:
This CISA resource sets out the most prevalent vulnerabilities that CISA has discovered from their assessments in 2019, the potential consequences if a threat actor is able to exploit them and the practices that should be employed in order to pro-actively protect critical infrastructure.
Those with a keen eye will probably spot that the second NCSC case study here isn’t new. This example does in fact date back to the release of our virtualisation security design principles.
The release of our latest walk through provided a good opportunity to bring all the related guidance together in one spot. So now you can read the principles, check their application with the case studies and ensure you’re not falling into the trap of implementing a security architecture 'anti-pattern'.


