My initial learnings with Nexor
I joined Nexor having made the decision to return to a career in technology, and it was both energising and intimidating. I discovered the industry had moved fast in the time I was away, and I found myself stepping into a new challenge, working in Nexor’s information security pillar. Although I had experience in this area, I was out of touch, and I couldn’t help but feel a bit out of place at first. The term “Secure by Design” was everywhere, sprinkled in slide decks, echoed in strategy meetings, repeated like a mantra.
At first, it sounded like another buzzword. I was sceptical: was this just a rewording of old practices? Had "Secure by Afterthought" been subjected to some good PR?
It turned out that returning with a fresh set of eyes would be my superpower.
Seeing it differently
Looking at the wider industry through the lens of someone re-entering the field, it was clear that something wasn’t quite aligning. While “Secure by Design” was being promoted as a core principle, what I observed more broadly was often still “Secure by Afterthought”. Security was an add-on, introduced late in the development cycle, just before release, or worse, after something had already gone wrong.
This observation wasn’t about any one organisation, but reflected a long-established status quo that security are the gatekeepers, the naysayers and blockers to agile, fast-moving development. Often seen as the part you do when the “real” work has been done, designing, coding, testing, the tangible and recognise milestones. And to be fair, that’s how security had historically shown up: isolated, reactive, and always a step behind the code.
This perspective stems from a time when security, like other functions, operated in silos. Dev teams built the app, tossed it over the fence, and security teams poked holes in it. Naturally, this bred a cyclical dive into increasing friction and blame. Security became the villain in the story, the natural nemesis of the developer. Undermining the hard work and endless hours of toil in breathing life into the creation without a hint of remorse or empathy, let alone actual insight.
But I realised there was an opportunity here, not just to learn, but to help reframe the entire narrative and take action to redress the imbalance. So what did I do?
From apprehensive to active
I didn’t want to be another voice simply pointing out what was wrong in the wider field. So, I got involved:
I embedded myself into development teams, joining daily stand-ups and sprint planning sessions. I listened more than I spoke at first, but gradually started offering input on how security could be integrated naturally, not disruptively, into existing workflows.
I attended planning conferences and events, shaping agendas to include security topics that didn’t just scare people into compliance, but empowered them to build more confidently.
I championed cross-functional collaboration, pushing for teams where security experts were seen not just as advisors, but as “core contributors”, helping solve problems early, not just find faults late.
I made sure people knew who I was and how I could be of benefit, showing flexibility in my approach, casting aside the “Thou shalt” archetype to offer risk-based advice that supported the development and incorporated security into the features.
Security, I’ve come to realise, is most powerful when it’s invisible, when it’s part of every decision, every design conversation, every commit, without becoming a burden.
The shift toward collaboration
To truly achieve Secure by Design, the industry as a whole needs more than awareness; we need structural change:
Cross-functional teams must include people with security expertise from day one. Not to rubber-stamp decisions, but to shape them and add to the effort to realise them.
Security professionals need to lean in, to solve problems alongside developers, to help build, not just audit.
Leaders must support and reward secure thinking just as much as delivery speed.
The goal isn’t to slow down innovation or development; it’s to build systems that are secure, sustainable and resilient. Because in the long run, bolting on security leads to rework, mistrust, and missed opportunities.
Secure by Design isn’t a buzzword; it’s a culture
Coming back to a technology career and being dropped into Nexor’s information security pillar gave me a new appreciation for how mindsets can change, and how quickly they can calcify again. Secure by Design isn't just a security initiative. It's a cultural shift. It’s about seeing security as a design principle, not a gatekeeper. It’s about ensuring that our systems are not just built to work but built to last. In sum, it is a critical component for any enterprise that takes enterprise decision-making seriously.
And the shift starts with people who are willing to ask questions, challenge the status quo, work across boundaries and lean in.
Final thoughts
I came back unsure of where I’d fit in, but at Nexor, I have found a real purpose in helping bridge the gap between security and development. What began as hesitation turned into passion. And what seemed like a buzzword is now something I help bring to life every day, with every team I support.
Nexor takes Secure by Design seriously, and what I’ve experienced here is a genuine commitment to embedding it into both culture and process. We don’t need to choose between speed and security. We need to choose better habits, better collaboration, and better understanding.
It’s time to leave “Secure by Afterthought” behind… for good.