What is Cyber Security By Design?

Ajay Unni
Ajay Unni CEO,StickmanCyber
October 7, 2026 6 min read

Hackers are not going anywhere, anytime soon. The burgeoning new wave of hackers is tech-savvy and hell-bent on causing maximum damage. Virtually all organisations face constant threat from cyber-attack; unfortunately, it’s a matter of when, not if, someone tries to hack your data. Times have changed, and responding to attacks as they happen is simply not enough. The most effective way to strengthen cyber security is to plan ahead for a digital defence that covers all aspects of your business.

Be proactive, not reactive

Traditionally, organisations have taken a reactive approach to cyber security – responding to threats as they occur, rather than pro-actively protecting and managing cyber risk. Today’s sophisticated hackers are always finding new opportunities for attack, which makes it mission-critical to stay on the offence with cyber security. Managing compliance for multiple security standards has also proven challenging, with cyber security not visible at the board level or even considered to be a business priority. That is, of course, until a data breach occurs and it becomes everybody’s problem.

This fragmented approach is ineffective – and dangerous. The consequences of a cyber-attack can be devastating, such as loss of customer confidence, ruined reputation, and costly legal ramifications. Not to mention the potential destruction of your entire business.

Make cyber safety everyone’s problem, not just IT

To be fully effective, cyber security must be owned at the board level, and not just managed by the IT department or a board member with tech expertise. ‘Ready for a Hack,’ an article in the April 2016 issue of Company Director, is a case in point. It tells the story of Distribute.IT – a now non-existent Australian website hosting business – which was forced to close its doors after a hacker attacked its systems in 2011 and deleted thousands of its clients’ websites. The hacker targeted a specific employee who was deemed to be ‘vulnerable’, bypassing all security measures and locking out the IT team who could only watch on, defenceless. The message is clear. Cyber security needs to be broad in scope, and senior management needs to recognise that it’s a whole-of-business challenge.

That advice still stands. In their Cyber security priorities for boards of directors 2025-26, the Australian Signals Directorate (ASD) and the Australian Institute of Company Directors (AICD) say boards should treat cyber security as a core governance and enterprise risk.

A comprehensive framework for digital defence

The US Government recognised the urgency of protecting critical infrastructure from cyber attacks. In 2013 President Barack Obama ordered the National Institute of Standards and Technology (NIST) to create a cyber security framework. The NIST Framework was based on input from more than 3,000 workshop attendees. StickmanCyber’s own Ajay Unni participated in NIST’s Cybersecurity Framework workshop held in Gaithersburg, Maryland, US in April 2016.

NIST released CSF 2.0 in February 2024 and widened its scope to organisations of all sectors and sizes. Its six core Functions are: Govern, Identify, Protect, Detect, Respond and Recover. Govern is new in version 2.0 and covers how an organisation’s cyber security risk management strategy, expectations and policy are set, communicated and monitored. The diagram below shows the five original Functions of CSF 1.1 and their categories.

NIST Cybersecurity Framework 1.1 diagram showing the five original Functions – Identify, Protect, Detect, Respond and Recover – and their categories

The NIST Framework shifts the balance from reactive compliance to proactive cyber risk management. Being proactive improves communication and collaboration on cyber security issues across divisional, management, and board levels, putting the organisation in the best position to comply with current and future regulatory standards.

Adopting the framework can also serve as evidence of implementing appropriate measures to prevent cyber-attack, which may help your legal position in the event of a breach.

Cyber Security By Design is a comprehensive protection for your business

A proactive, company-wide approach is the key to long-term cyber security. StickmanCyber’s approach to cyber security by design provides a dynamic, cost-effective, and customised framework that helps safeguard your business from cyber attack:

Tailored risk-based cyber security

Instead of one-size-fits-all, we customise cyber security to meet your specific needs, risk tolerance, and resources available, with the focus firmly on risk minimisation.

Collaboration for best results

The lack of visibility of cyber security at the board level and senior management is a common problem for security professionals within large organisations. Our methodology promotes external and internal collaboration and buy-in. Cyber security is quickly integrated into more business functions, such as new product development and infrastructure design, meaning your business is more fully protected.

Keeping you on the front foot

Cyber security is constantly changing. With new technology and smarter cybercriminals, a dynamic approach enables rapid evolution to keep security steps ahead of hackers. Our methodology is designed to be flexible, always keeping you on the front foot.

Customised cyber security

Our methodology adapts the industry gold standard NIST Cyber Security Framework, alongside standards such as ISO 27001 and Australia’s Essential Eight, to bring you a proactive, broad-scale, and customised approach to managing cyber risk.

Remember – hacking will happen at some point. It really does pay to be proactive. To find out more about safeguarding your business now and into the future please contact us.

Frequently asked questions

What is the difference between secure by design and secure by default?

Secure by design means building security into the design, development and operation of products, services and systems from the outset, rather than fixing problems after release. Secure by default means a product is secure out of the box, with strong security settings already turned on, so customers don’t have to configure it themselves. ASD and the AICD encourage boards to check whether the technology their organisation uses or provides is both.

Who is responsible for cyber security in an organisation?

Everyone has a role, but accountability sits with the board and senior management. ASD and the AICD advise boards to treat cyber security as a core governance and enterprise risk, set clear accountability and reporting, and build a strong security culture. Day-to-day controls are usually run by IT or security teams, a managed security provider, or both, under that oversight.

Is the NIST Cybersecurity Framework mandatory in Australia?

No. The NIST Cybersecurity Framework is voluntary, and many Australian organisations use it as a structure for managing cyber risk. Some Australian requirements are mandatory for certain organisations: for example, the Protective Security Policy Framework requires non-corporate Commonwealth entities to implement all Essential Eight strategies to at least Maturity Level Two, and APRA-regulated entities must meet CPS 234.

How can a business start building cyber security by design?

Start by identifying your most critical systems and information – the ‘crown jewels’ ASD recommends protecting first – and assessing your current controls against a recognised framework such as NIST CSF 2.0, ISO 27001 or the Essential Eight. Turn the gaps into a prioritised roadmap, give the board regular reporting on progress, and build security requirements into new projects from the start.

Does cyber security by design apply to small businesses?

Yes. NIST designed CSF 2.0 for organisations of all sectors and sizes, and ASD publishes cyber security advice written specifically for small business. A smaller organisation may not implement every control a large enterprise would, but it can still plan security into its systems, suppliers and processes from the start and focus first on its biggest risks.

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment