Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Maintenance and diagnostics

Secure by design and secure by default

Also known as: Security by design, Secure by design, Secure by default

German: Secure by Design, Secure by Default

In product security engineering, secure by design means that security is built into a product from the requirements and architecture onward, while secure by default means that the product is delivered with secure settings active, so that users do not need to harden it before safe use.

  • Maintenance
  • OT security

In one sentence

Secure by design builds security into a product from the start; secure by default ships it with secure settings already active.

Example

A new controller ships with all unused services disabled, forces a password change at first login and signs its firmware, instead of relying on the user to harden it.

How it applies

  • Engineering: Secure by design means threat modeling, security requirements, secure coding and security testing within a secure development lifecycle, as described for component suppliers in IEC 62443-4-1.
  • Commissioning: Secure by default means insecure options such as default passwords, open ports or unencrypted protocols are off unless explicitly enabled. Any enabled option should be documented.
  • Compliance: The EU Cyber Resilience Act (CRA) requires products with digital elements to be made available with a secure by default configuration, among other essential requirements. Applying the principles supports compliance but does not by itself establish it.
  • Documentation: Security documentation should describe the default configuration, the consequences of changing it, hardening guidance and how updates are delivered. Users need to know which settings they may relax and what risk that creates.

Secure by design vs. secure by default

Secure by design is about how the product is developed. Secure by default is about the state in which it is delivered. A product can be securely designed yet shipped with insecure defaults, which is why both are named together.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on IEC 62443-4-1 and the Cyber Resilience Act

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!