Security by Design for Software Developers
Security by design: what it means in practice
As software becomes more deeply embedded in critical systems, devices, and services, cybersecurity is no longer optional, it must be an integral part of your design and development process. With NIS2 and the Cyber Resilience Act (CRA) raising the bar for digital product security, software teams must adapt now.
For whom?
- Software developers & tech leads at start-ups and scale-ups
- Engineering teams building cloud, SaaS, mobile, or embedded applications
- Product owners integrating security & compliance into their lifecycle
- CTOs and decision-makers responsible for secure architecture
- Any team member asking: “How secure is our product?”
Key insights
This masterclass helps start-ups, scale-ups, and small to mid-sized software companies understand what “security by design” really means and how to implement it without losing development speed or agility. Whether you’re just getting started or facing pressing security questions, this session will help you take confident steps toward building trusted applications.
Programme
| Time | Subject |
| 09:00 – 09:30 | Welcome & Introduction • Overview of the masterclass objectives • Current challenges in software security • Regulatory context: NIS2 & Cyber Resilience Act |
| 09:30 – 12:30 | Application Security in Practice • Key concepts of Application Security (AppSec) • Security maturity models (SAMM, DSOMM) • Quick AppSec scans on your code • Integrating security and compliance into DevOps • Building a “secure by design” culture in small teams • Choosing scalable tools and workflows |
| 12:30 – 13:30 | Lunch Break |
| 13:30 – 17:00 | Hands-On Threat Modeling Workshop • Step-by-step introduction to threat modeling (STRIDE, attack trees, DFDs) • Guided modeling of threats in your own product • Identifying attack surfaces and trust boundaries • Prioritizing risks and designing mitigation strategies • Practical tools and templates for immediate use |
| 17:00 | Closing & Next Steps • Summary of key takeaways • How to continue building secure applications • Q&A |
Registration
Seats are limited to ensure an interactive and personalized experience.
Join us to learn, practice, and take the next step toward secure, compliant, and trusted software.
Integrating security from the design phase
Why is Security by Design no longer an option but a necessity today? In this article, discover how to structurally embed security from the very first design decisions throughout your software development process, with a focus on threat modelling, compliance (NIS2, Cyber Resilience Act) and resilient architectures. Get inspired by a clear step-by-step approach and a practical use case.
Flemish companies can take advantage of a subsidy from VLAIO for this course
This programme is part of Industriepartnershap in which 13 Flemish innovation partners offer an integrated service to stimulate growth and innovation in the Flemish industry in the 6 following themes: AI, Cybersecurity, Circularity, Digitisation, Climate & Energy and Industry 4.0. They do so under the leadership of Agoria and Sirris and with the support of Agentschap Innoveren & Ondernemen.
Date
Location
Price
Language
English
