Secure by default

Issue 7 2020 Editor's Choice

As the cybersecurity landscape changes and evolves and IoT continues to proliferate, so do the challenges being faced by businesses.


Tertius Wolfaardt.

It is worth noting that not all hacks consist of an elite team of sophisticated hackers. The reality may be more of an opportunistic hacker looking for exploitable vulnerabilities and weaknesses in a network or just plain old human mistakes or oversight. To add to that, there are huge data breaches reported due to configuration problems. While it is widely acknowledged that education on new technologies is hugely important, it is essential that technology vendors support those that are installing and commissioning these systems, to minimise human mistakes and configuration issues.

Simply put, a Secure by Default strategy means taking an holistic approach to solving security problems at the root cause, rather than treating the symptoms of a cybersecurity defect and therefore acting at scale to reduce the overall harm to a system or type of component. Secure by Default covers the long-term technical effort to ensure that the right security primitives are built into software and hardware. It also covers the equally demanding task of ensuring that those primitives are available and usable in such a way that the market can readily adopt them.

This area has never been so important for businesses. Poor set-up and configuration increases the risk of devices providing a platform for unauthorised access.

The worst that can happen

At Axis, we’ve experienced businesses questioning the danger of a cybersecurity breach, stating: “What’s the worst that can happen? They will only get access to the video feeds but won’t get into our network.” This is a dangerous scenario and mindset.

If a technology does follow Secure by Design principles, it will have embedded out-of-box cybersecurity principles built in, which would inevitably have prevented this incident from occurring. To support our technologies, Axis has aligned Secure by Default to recommendations made within industry best practices.

• Password prompt – In order to access the device, there will be an out of box password for the user. During the setup, we will prompt you to change it.

• Password strength indicator – There is a strength indicator advising of the effectiveness of the password. Due to most large enterprises having their own corporate password policies, we won’t dictate and approve the password used, but will advise.

• HTTPS encryption – Hyper Text Transfer Protocol Secure (HTTPS) is the secure version of HTTP, the protocol over which data is sent between your browser and the website that you are connected to. The ‘S’ at the end of HTTPS stands for ‘Secure’. It means all communications between your browser and the website are encrypted.

• 802.1x – IEEE 802.1X is an IEEE Standard for port-based Network Access Control (PNAC). It is part of the IEEE 802.1 group of networking protocols. It provides an authentication mechanism to devices wishing to attach to a LAN or WLAN.

• Remote access DISABLED (NAT traversal) – While there are operational benefits to being able to remotely access devices, this is a function that needs to be enabled and the necessary procuration should be followed when this has been enabled to protect the device.

Axis understands the importance of securing our technologies, and while no technology is ever 100% secure, we follow technical considerations such as Secure by Default.

For more information contact Axis Communications, +27 11 548 6780, [email protected], www.axis.com

‘Secure by design’ in IT


Gregory Dellas.

By Gregory Dellas, security presales, CA Southern Africa.

Consider the construction of a bank, an embassy or some type of secure installation. Before brick and mortar is laid down, the secure design of the building is already in the blueprints. Things such as the entrance and exit points, the location of a vault, thickness of the walls, anchor points for gates, grades of steel, mounting brackets for CCTV, cable conduits for wiring and so forth, all this is planned prior to construction. The facilities for security need to be designed alongside the functional facilities.

Software development without security by design is like a flimsy residential building that must then be renovated with thicker walls, strong gates, CCTV, guard huts etc., all at a later stage. This is called overlaid or retroactive security, not very secure or efficient and will never be as safe as a building that had security by design. The same issues apply to retroactive security in IT.

IT ‘Security by Design’ means putting in mechanisms like encryption, granularity, segregation, reporting and such into the solution early on in the design stage, before ever getting to a public release. Furthermore, continuous vulnerability testing is done throughout the development lifecycle. The means for improvement and operational testing are also built in to enhance security post deployment.

For more information, contact CA Southern Africa, +27 11 417 8594, [email protected]


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Making drone security more accessible
Editor's Choice Integrated Solutions Residential Estate (Industry) AI & Data Analytics IoT & Automation
Michael Lever discusses advances in drone technology, focusing on cost reductions and the implementation of automated services, including beyond line of sight capabilities, for residential estates with SMART Security Solutions.

Read more...
Private fire services becoming the norm?
Technews Publishing SMART Security Solutions Editor's Choice
As the infrastructure and service delivery in many of South Africa’s major cities decline, with a few, limited exceptions, more of the work that should be done by the state has fallen to private companies.

Read more...
View from the trenches
Technews Publishing SMART Security Solutions Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
There are many great options available to estates for effectively managing their security and operations, but those in the trenches are often limited by body corporate/HOA budget restrictions and misunderstandings.

Read more...
SMART Estate Security Conference KZN 2025
Arteco Global Africa OneSpace Technologies SMART Security Solutions Technews Publishing Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
May 2025 saw the SMART Security Solutions team heading off to Durban for our annual Estate Security Conference, once again hosted at the Mount Edgecombe Country Club.

Read more...
Get the AI fundamentals right
Leaderware Editor's Choice Surveillance AI & Data Analytics
Much of the marketing for CCTV AI detection implies the client can just drop the AI into their existing systems and operations, and they will be detecting all criminals and be far more efficient when doing it.

Read more...
SMART Surveillance Conference in Johannesburg
Arteco Global Africa Technews Publishing SMART Security Solutions Axis Communications SA neaMetrics Editor's Choice Surveillance Security Services & Risk Management Logistics (Industry) AI & Data Analytics
SMART Security Solutions hosted its annual SMART Surveillance Conference in Johannesburg in July, welcoming several guests, sponsors, and speakers for an informative and enjoyable day examining the evolution of the surveillance market.

Read more...
South African fire standards in a nutshell
Fire & Safety Editor's Choice Training & Education
The importance of compliant fire detection systems and proper fire protection cannot be overstated, especially for businesses. Statistics reveal that 44% of businesses fail to reopen after a fire.

Read more...
LidarVision for substation security
Fire & Safety Government and Parastatal (Industry) Editor's Choice
EG.D supplies electricity to 2,7 million people in the southern regions of the Czech Republic, on the borders of Austria and Germany. The company operates and maintains infrastructure, including power lines and high-voltage transformer substations.

Read more...
Standards for fire detection
Fire & Safety Associations Editor's Choice
In previous articles in the series on fire standards, Nick Collins discussed SANS 10400-T and SANS 10139. In this editorial, he continues with SANS 322 – Fire Detection and Alarm Systems for Hospitals.

Read more...
Wildfires: a growing global threat
Editor's Choice Fire & Safety
Regulatory challenges and litigation related to wildfire liabilities are on the rise, necessitating robust risk management strategies and well-documented wildfire management plans. Technological innovations are enhancing detection and suppression capabilities.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.