Sharpen CISO Logo

Secure by Design: What ENISA’s New Playbook Means for Small Teams

Most small software and hardware teams agree that security matters. But agreeing isn’t the hard part. The hard part is knowing exactly what to build. Do it with almost no spare budget or dedicated security staff, and the gap between intention and execution grows fast.

That’s the gap ENISA just tried to close. In July 2026, the EU Agency for Cybersecurity published the Secure by Design and Default Playbook. It’s a practical guide built specifically for small and medium-sized enterprises. The document doesn’t just repeat the usual “shift security left” advice. Instead, it breaks secure by design into 22 concrete playbooks. Each one comes with a checklist, a minimum-evidence list, and a release gate your team can copy straight into a pull request template.

This post walks through what the playbook actually says. It covers why the guidance exists now, and how a lean team can start using it without hiring a security department first.

The guidance targets a specific audience: software developers, technical product managers, SME security leads, and system architects working with limited resources. If that sounds like your team, the playbook was written with you in mind, not with a Fortune 500 security org.

Why Secure by Design Needed Its Own Playbook

Secure by design sounds simple: build protection in from the start instead of bolting it on later. However, simple ideas don’t always translate into simple action.

ENISA points to a familiar pattern. SME manufacturers face budget constraints, limited security expertise, and constant time pressure from the business. As a result, principles that sound obvious in a conference talk often stay unimplemented in the actual codebase.

The Cyber Resilience Act (CRA) raises the stakes further. Products with digital elements sold in the EU must now demonstrate an appropriate level of cybersecurity. They must also ship with secure default configurations and support timely security updates. So secure by design isn’t just good practice anymore. For many manufacturers, it’s becoming a market-access requirement.

The playbook doesn’t offer legal advice. Instead, it gives engineering teams something more useful day to day: a repeatable way to translate CRA-relevant principles into ordinary sprint work.

Two Ideas, Four Categories

ENISA organizes its guidance around two related but distinct concepts.

Secure by design covers how a system is built. It means embedding threat modeling, secure architecture patterns, and vulnerability management into development from day one. That’s very different from retrofitting them after launch.

Secure by default covers what happens when a user first turns the product on. A secure-by-default product ships with the most protective configuration reasonably possible. Users shouldn’t need expert knowledge just to stay safe out of the box.

Within secure by design, ENISA groups principles into architectural foundations and operational integrity. Architectural foundations cover how the system is structured. Operational integrity, meanwhile, covers how it’s managed and maintained after launch. Within secure by default, principles split into default hardening and guided protection. Default hardening describes the factory-shipped state. Guided protection, in turn, describes how the system helps users stay secure over time.

Together, these four categories organize all 22 playbooks. They range from trust boundaries and least privilege through to secure recovery and ownership transfer.

Inside a Playbook: How the Checklists Actually Work

Each of the 22 playbooks follows the same five-part structure. That consistency is part of what makes the guide so usable for small teams.

First comes the principle itself, stated in one sentence. Next comes the objective: what failure mode this principle is meant to prevent. Then a checklist lists the highest-impact actions. These are written to be achievable by lean teams, not large dedicated security functions.

After that, a minimum evidence section names the smallest set of artifacts that prove the checklist was actually implemented. Finally, a release gate offers pass/fail criteria you can paste directly into a CI pipeline or release review.

For example, take attack surface minimization. The checklist asks teams to list every exposed interface and enforce default-deny network rules. It also asks them to strip development and diagnostic tooling from production builds, and to minimize the data they collect in the first place. The release gate then confirms, before each release, that no new port or admin endpoint slipped through unreviewed.

This format matters because it turns “be more secure” into something a developer can actually check off during a pull request review.

The Principles Cover the Whole Product Life Cycle

The 22 playbooks map onto every stage of a product’s life, not just the coding phase.

Trust boundaries and threat modeling come first. Teams need to know what they’re protecting before they can protect it. Least privilege, strong identity architecture, and defence in depth follow next. Together, these form the architectural backbone of the system.

Operational integrity principles then take over. This includes secure coding practices, logging and monitoring, incident response, and vulnerability and patch management. Supply-chain controls round out the design side. They cover everything from signed build artifacts to software bills of materials (SBOMs).

On the default side, the playbook addresses what ships in the box. That means minimized default services, no shared admin credentials, encrypted communication from the first connection, and unique per-device secrets. Guided protection principles then help users stay secure after setup. They do this through mandatory onboarding steps, automatic updates, and clear warnings whenever someone disables a protection.

Notably, ENISA treats these life-cycle stages as iterative rather than sequential. A vulnerability found in production should trigger a return to earlier threat-modeling and risk-assessment steps, not just a quick patch and a shrug.

Threat Modeling Without the Overhead

Many small teams avoid threat modeling because it sounds like a multi-week exercise reserved for enterprise security departments. In practice, ENISA pushes back on that assumption directly.

The playbook recommends Adam Shostack’s four-question framework as a lightweight starting point. What are we working on? What can go wrong? What are we going to do about it? Did we do a good enough job? Teams can answer these with a single diagram and a short list of top threats. A simple table mapping each threat to its mitigation rounds out the exercise.

The goal isn’t exhaustive documentation. It’s a minimum viable model that’s fast to produce and easy to refresh. Crucially, it should stay tightly coupled to real design decisions. A threat model nobody updates after the first release isn’t worth building in the first place.

Proving It, Not Just Claiming It

One of the more forward-looking sections of the playbook covers machine-processable attestation. Instead of relying on a static PDF report that nobody reads after the audit, ENISA describes how security claims can be expressed as structured, machine-readable data.

For instance, a signed attestation might state that a product enforces TLS 1.3 with AES-256 encryption. That claim then links to actual evidence, such as a configuration scan, a test result, or a build log. Automated systems can verify the claim without waiting on a human reviewer.

For an SME, this matters because it replaces expensive manual audits with automated checks that run on every release. Still, the playbook is careful to note the limits. An attestation alone doesn’t prove a product is secure. Verification and independent assessment remain separate, necessary steps. Structured evidence simply makes both of those steps faster and cheaper to carry out.

How to Start Without Boiling the Ocean

Twenty-two playbooks can feel overwhelming for a five-person engineering team. Fortunately, ENISA anticipated this reaction and suggests a progressive adoption path instead.

Start by establishing context. Define your product’s scope, users, and top risks using the lightweight threat-modeling approach described above. From there, build a foundational baseline covering secure coding practices, logging and monitoring, vulnerability management, and supply-chain controls. If your product handles user access, add restrictive initial access and secure-by-default communication to that baseline too.

Only after that foundation is in place should teams work through the remaining playbooks. Prioritize them by your specific risks and deployment context, not by the order they appear in the document. Progressive adoption isn’t an excuse to delay CRA obligations, though. It’s simply a realistic sequence for teams working with limited time and limited hands.

The Takeaway

Secure by design has always been easy to endorse and hard to operationalize. ENISA’s playbook doesn’t remove that difficulty entirely. But it does turn a vague principle into 22 checklists a small team can actually run through before shipping. Given the CRA’s incoming requirements, that shift from aspiration to action is exactly what most manufacturers need right now.

If your team hasn’t run a lightweight threat model yet, that’s the natural place to start. Everything else in the playbook builds outward from there, one release gate at a time.

For teams already navigating CRA compliance, the playbook is also worth reading alongside Annex C of the original document. It maps each of the 22 principles directly to specific CRA essential requirements, which can save real time when you’re building an internal compliance case. In other words, the checklist work you do for engineering reasons doubles as evidence for regulatory reasons too.

Source: ENISA, Secure by design and default playbook

 

Supply Chain Cyber Risk: What Boards Must Know in 2026

One weak vendor can now shut down an entire company. That’s not a warning anymore. It’s already happened, more than once.

The World Economic Forum’s Global Cybersecurity Outlook 2026 confirms it. Supply chain risk has become the single biggest cybersecurity challenge for large organizations. For boards, this is no longer a topic to delegate. It’s a governance issue.

This article explains why the risk has grown so fast. It also outlines what directors and executives should be asking their teams right now.

The Numbers Behind the Shift

According to the report, 65% of large companies now name supply chain vulnerabilities as their greatest barrier to cyber resilience. That’s up sharply from 54% just a year earlier.

Why the jump? Because today’s digital supply chains are deeply interconnected. A breach at one supplier can cascade through an entire ecosystem. It can hit production, operations, and even other customers, all at once.

Clearly, this isn’t a hypothetical risk. In fact, it’s already playing out in boardrooms around the world.

Real Incidents, Real Costs

Consider Jaguar Land Rover. In 2025, a single cyberattack halted production for five weeks. In fact, the attack disrupted more than 5,000 suppliers at once.

The direct financial impact was severe: £196 million in cyber-related costs, and a nearly 25% drop in quarterly revenue. The wider UK economy absorbed an estimated £1.9 billion in losses. The government even stepped in with a £1.5 billion loan guarantee to stabilize the supply chain.

Or take Asahi, the Japanese beverage maker. A cyberattack in late 2025 knocked out core IT systems. As a result, staff had to revert to pen and paper just to track inventory.

Similarly, in Europe, a relatively small breach at an airport check-in vendor caused widespread flight delays and cancellations. The technical fix was simple. Still, the business disruption was not.

Together, these cases send a clear message to leadership. A vendor’s weakness quickly becomes your company’s crisis.

Why Trust in Vendors Is Breaking Down

At the heart of this problem is a simple, uncomfortable truth. Most companies can’t fully verify the security of the vendors they depend on.

The WEF report calls this “inheritance risk.” In plain terms, it means inheriting a vendor’s vulnerabilities without knowing they exist. It now ranks as the top supply chain concern in the survey.

Close behind is a lack of visibility. Many organizations simply don’t have a clear map of their extended supply chain. As a result, they can’t manage risks they can’t see.

Finally, there’s concentration risk. Businesses increasingly depend on a small number of critical providers, like major cloud platforms. So, if one of those providers fails, the damage can spread across thousands of companies overnight.

What the Most Resilient Companies Do Differently

The report draws a clear line between resilient organizations and the rest. The difference comes down to specific, board-visible practices.

Highly resilient companies involve their security teams in procurement decisions 76% of the time. Less resilient companies do this only 53% of the time. In other words, security earns a seat at the table before you sign contracts, not after a breach.

Similarly, 74% of resilient companies formally assess their suppliers’ security maturity. Only 48% of less resilient companies do the same.

Resilient companies also rehearse for failure. As a result, 44% run joint incident simulations with their supply chain partners, compared to just 16% of less resilient peers. That preparation pays off: only 15% of highly resilient companies report weak incident response planning, versus 37% of the rest.

The Board’s Role Is No Longer Optional

Board engagement now separates resilient companies from vulnerable ones. The data on this point is striking.

Among highly resilient organizations, 99% report active board involvement in cybersecurity. Just over half receive regular updates on cyber risks. Nearly half say their board has a clearly defined oversight role.

By contrast, boards at less resilient companies disengage far more often. That gap in oversight directly tracks the gap in outcomes.

For directors, the takeaway is simple. Cybersecurity oversight isn’t a technical checkbox. Instead, it’s a core part of enterprise risk management, alongside financial and operational risk.

Questions Every Board Should Be Asking

Given all this, what should leadership actually do? A few focused questions can drive real change.

First, ask how security teams take part in vendor selection. If procurement moves forward without a security review, that’s a governance gap worth closing.

Second, ask for a map of critical dependencies. Specifically, leadership should know which vendors, if breached, would cause the most damage.

Third, ask whether the company has tested its response with key partners. Because a plan nobody has rehearsed often fails when it matters most.

Finally, ask how the company manages concentration risk. After all, relying on a single critical provider, without a backup plan, is a strategic vulnerability, not just a technical one.

The Bottom Line

Supply chain risk has moved from the server room to the boardroom. The WEF’s 2026 findings make that shift impossible to ignore.

However, the path forward is well defined. Companies that involve security early, map their dependencies, and rehearse their response are measurably more resilient.

For boards, the message is direct. Ask the hard questions now, before a vendor’s weakness becomes your headline.

Source: World Economic Forum, Global Cybersecurity Outlook 2026, January 2026.

Small Business Cybersecurity: The Warning Signs in WEF’s 2025 Report

Cybercrime is no longer a big-company problem. In fact, small and mid-sized businesses are now the weakest link in the chain.

That’s the clear message from the World Economic Forum’s Global Cybersecurity Outlook 2025. The report surveyed hundreds of business and security leaders worldwide. Its findings paint a worrying picture for smaller businesses.

This article breaks down what the report found. It also explains what small business owners and managers can do about it, starting today.

The Gap Between Small and Large Businesses Is Widening

According to the WEF report, 35% of small businesses now say their cyber defenses fall short. That figure has grown sevenfold since 2022, when it stood at just 5%.

Large companies, meanwhile, are moving the other way. By comparison, only 7% of large companies now report weak defenses, down from 13% a few years ago.

In other words, big companies are getting stronger. Small companies are falling further behind. And because supply chains link small vendors to large enterprises, this gap puts everyone at risk.

The report is blunt about it. At the WEF’s 2024 Annual Meeting on Cybersecurity, 71% of cyber leaders agreed on one point. Small businesses, they said, have already reached a tipping point. Many can no longer defend themselves against today’s threats.

Why Smaller Companies Struggle to Keep Up

Several factors explain this widening gap. Understanding them is the first step toward closing it.

A shortage of skilled people. The report identifies a global shortfall of 2.8 million to 4.8 million cybersecurity workers. Small businesses feel this shortage the hardest. That’s because they rarely compete with large firms on salary or perks.

Only 14% of businesses say they have the talent they need. For small businesses, the skills gap ranks second on their list of barriers. Only the sheer complexity of today’s threats ranks higher.

Limited budgets and resources. Larger companies can afford dedicated security teams, advanced tools, and outside consultants. Smaller businesses typically can’t. That means fewer defenses are in place when an attack happens.

Growing complexity everywhere. World tensions, new rules, and fast-moving tech are all adding pressure. Nearly 60% of businesses say world tensions have already reshaped their security plans. Small teams simply have less time to track every new development.

The Threats Small Businesses Should Watch Closely

In practice, not every cyberthreat affects every business equally. The WEF report highlights a few that matter most right now.

Ransomware still tops the list. Across all business sizes, 45% of respondents rank ransomware as their top cyber risk. Attackers increasingly rent out ransomware tools to less skilled criminals. As a result, there are more attackers, more often.

Fraud and phishing are close behind. Roughly one in five respondents named cyber-enabled fraud, including phishing and fake payment requests, as their top worry. These attacks often target smaller businesses. Why? Because staff may not get the same security training larger firms provide.

AI-made deepfakes are an emerging risk. Criminals now use generative AI to convincingly fake the voice and video of executives. In fact, research cited in the report found a 223% jump in deepfake tools traded on the dark web. That happened within a single year. More than half of surveyed security leaders now see deepfakes as a real threat.

Third-party and supply chain risk is real, even if it doesn’t feel that way. Large companies rank supply chain risk as their top concern. That’s largely because they depend on smaller vendors like you. If your systems get compromised, the damage can spread to every partner you work with.

What Small Businesses Can Do Right Now

Still, the report isn’t just a warning. It also points to practical steps that make a measurable difference, even without a large security budget.

First, invest in your people. The WEF report found that 76% of businesses are closing the skills gap by training current staff. Fewer rely only on hiring new specialists. So, basic security training for your whole team, not just IT staff, goes a long way toward preventing phishing and fraud.

Second, get leadership involved. The report found that 62% of highly resilient businesses give leaders regular updates on cyber risks. Only 29% of less resilient businesses do the same. In short, cybersecurity works best as a business priority, not just a technical one.

Third, prepare for ransomware directly. Because it remains the top risk, don’t leave it to chance. Keep offline backups. Test your response plan. And make sure everyone knows their role during an attack.

Fourth, verify unusual requests. AI-made deepfakes and impersonation scams are rising fast. So, train employees to double-check unusual payment requests or executive instructions. A quick phone call before acting can stop a scam cold.

Finally, ask questions of your vendors and partners. If you supply larger companies, for example, expect them to ask about your security practices. Getting ahead of those questions builds trust and protects your business relationships.

The Bottom Line

The WEF’s 2025 report makes one thing clear. Strong cyber defenses are no longer optional for small businesses. The gap between large and small companies is real, and it’s growing.

However, the report also shows that real progress doesn’t need a big budget. Training your team, involving leadership, and preparing for common threats can go a long way.

Cybersecurity may feel like a big-company problem. But as this year’s report shows, small businesses can no longer afford to think that way.

Source: World Economic Forum, Global Cybersecurity Outlook 2025, January 2025.

Cyber compliance should no longer be a barrier to growth

Proving cyber maturity has become a hurdle to clear before a business can grow. For many organizations, compliance now sits on the critical path of every deployment, every tender, and every audit.

Three everyday situations show exactly how.

  • A project manager needs sign-off from the cyber team before deploying a new application — and that approval can take weeks if the right evidence isn’t already in place.
  • An IT vendor has to prove its security posture during a tender, typically through an ISO 27001 or SOC 2 certification — and one missing document can knock them out of the running.
  • An organization has to prove compliance to regulators, under frameworks like NIS2, DORA, or the CRA — each with its own evidence requirements and its own deadline.

A pace traditional methods can’t follow

Cyberattacks are accelerating. AI is rolling out everywhere. Regulatory requirements keep multiplying, often on the same team, at the same time.

As a result, security teams face more demands with the same limited resources. The frameworks themselves keep stacking, too: NIS2, DORA, and the CRA now overlap for many organizations, each with its own audit cadence and its own evidence trail.

Traditional approaches relied mainly on manual human review, and they simply can’t keep pace anymore. Spreadsheets, one-off audits, and point-in-time certifications suited a slower, more predictable risk environment — not continuous, AI-accelerated change.

Yet when companies innovate at the speed of AI, proving cyber compliance has to move at that same speed. Otherwise, compliance stops protecting the business and starts holding it back.

SharpenCISO: an augmented GRC platform

That’s exactly why we built SharpenCISO.

Our platform automates up to 80% of the manual work needed to demonstrate cyber compliance and manage risk in real time. This isn’t about removing people from the process. It’s about freeing your team from repetitive evidence-gathering, so their expertise goes where it creates the most value: judgment calls, risk decisions, and strategic conversations with the business.

Concretely, SharpenCISO automates the collection of cyber maturity evidence for four audiences at once:

  • Regulators, across frameworks like NIS2, DORA, and the CRA
  • Internal security (SSI) teams, who need continuous visibility instead of a once-a-year snapshot
  • Certification bodies, for standards like ISO 27001 or SOC 2
  • Client tenders and RFPs, where proof of security maturity now shapes business outcomes and risk decisions

One evidence base. Four audiences. No duplicated effort.

Turning cybersecurity into a competitive advantage

That’s our ambition. Proving cyber maturity should never slow an organization down.

Done right, it does the opposite. It builds trust with regulators and customers. It speeds up projects instead of gating them. And it opens doors — deals, partnerships, and markets — that used to stay closed until the paperwork caught up.

Compliance shouldn’t be the brake. It should be the accelerator.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #RiskManagement #SecureAI #AISecurity