Embedding cybersecurity into SaaS and digital product development
The SecDes project (in full By-Design Cybersecure Digital Products) focuses on companies that are building SaaS solutions. These companies, often small or medium-sized, are increasingly using complex software architectures within their products. Integrating effective security measures within these complex architectures is a difficult task. The risks of incidents and data breaches are real. At the same time, many SaaS companies are feeling increasing pressure from the market, driven by legislation such as NIS2 and the European Cyber Resilience Act to demonstrate that their software is secure enough to manage their customers' often critical data.
The goal of this project, initiated by KULeuven DistriNet and SIRRIS and supported by VLAIO, is to help SaaS companies improve the security of their digital products, even if they have limited cybersecurity experience.
Context
For many software and SaaS companies, security is still an afterthought – something dealt with only at the end of development. This leads to higher risks, unexpected costs and delays. At the same time, the number of cyber threats is rising, and the pressure from customers and regulators to ensure security is increasing.
SECDES addresses this challenge with a tailored approach for digital product development, putting security-by-design front and centre.
Objective and results
SECDES aims to help software companies take a structured approach to cybersecurity from the earliest design phases. The project will evaluate how tooling can support SaaS teams in maintaining a security-by-design posture.
Approach
The SECDES approach is practice-oriented and based on co-creation:
- Tools and methods are developed and refined together with pioneering SaaS companies
- Pilot cases are set up in various sectors
- Lessons learned are shared widely through articles, guides and events
- The methodology is aligned with agile development and DevSecOps principles
SECDES bridges the gap between technical cybersecurity expertise and the day-to-day work of software teams.
Target group
SECDES targets:
- companies that are building SaaS solutions
- Product owners, developers, DevOps and security teams
- CTOs and R&D or innovation managers
Funding - timing
- Project type: COOCK
- Project number: HBC.2023-0259
- Duration: Feb 2024 - Dec 2026
- Funding: VLAIO
Links
Project website: www.security-by-design.be
Partners
DistriNet is a KU Leuven research group embedded in the Department of Computer Science, and is part of the imec-KU Leuven Security and Privacy Center. The scope of DistriNet’s research is twofold: ICT security with an emphasis on secure software, secure systems, and software engineering for security, and distributed systems. DistriNet’s knowledge and expertise in these domains resulted in a strong international position in the domains of secure software, systems and services, and in security & privacy engineering.
https://distrinet.cs.kuleuven.be
The Agency for Innovation and Entrepreneurship (VLAIO) is a governmental organisation of the Flemish government for all entrepreneurs in FLanders. The mission of VLAIO is to stimulate and support innovation and entrepeneurship and to contribute to a favorable business-climate in Flanders.
https://www.vlaio.be


