Skip to main content

Studies in secure system design

Worked examples for Operational Technology and Virtualised systems, using the NCSC’s secure design principles

Case studies in secure architecture design

Our Secure design principles carefully divide up the work of creating and evaluating secure systems of all kinds.

To be widely applicable like this, the principles themselves remain at a fairly high level. This leaves you to fill in the blanks for your particular scenario.

This process may not come naturally to everyone, so to help you make the most of the principles, we’ve released a pair of fictionalised ‘case studies.’ Each working through the system design process, guided by the principles and the practical demands of a real-world project. These principles and associated case studies have been developed from NCSC’s experience supporting customers across the UK.

This blog post introduces those case studies and signposts some related work on securing Critical National Infrastructure (CNI), developed by our partners at CISA, in the US. Alongside NCSC’s guidance presented here, CISA have developed a handy and concise summary of cyber security best practices for Industrial Control Systems (ICS). More on this below.




Written by

Tony B