Software is now embedded in almost every part of modern business.
It supports how organisations communicate, collaborate, analyse information, deliver services and operate critical systems. But as reliance on software grows, so does the potentially harmful business impact whenever software is insecure, poorly maintained or compromised within the supply chain.
That is why software security can no longer be treated as a purely technical issue. It is a business resilience issue, a supply chain issue and, in many cases, a national resilience issue.
In January 2026, Nexor became a signatory of the UK Government’s Software Security Ambassadors Scheme (the scheme), created to champion secure software development and support a more resilient cyber ecosystem. The scheme helps drive adoption of the voluntary Software Security Code of Practice, which sets out expectations for improving the security and resilience of software across the market. (GOV.UK)
This blog is the first in a series exploring why the scheme matters, what the Software Security Code of Practice is aiming to achieve and how Secure by Design (SbD) thinking can help organisations build greater confidence in the software they rely on.
Software is part of the trust chain
Organisations often think about software in terms of functionality. Does it do what we need? Does it integrate with our systems? Does it improve efficiency?
Those questions matter. But they are no longer enough.
Every piece of software also represents a point of trust. Trust that it has been developed securely. Trust that any vulnerabilities are managed responsibly. Trust that security updates are maintained. Trust that suppliers can communicate risks clearly. Trust that the software will not become the weakest link in a wider operational environment.
This is especially important across sectors such as Defence, Government, Law Enforcement and Critical National Infrastructure, where software often supports sensitive information, essential services and complex operational decisions.
In these environments, trust is not abstract. It has to be designed, tested, evidenced and maintained.
Why the Software Security Code of Practice matters
The UK Government’s Software Security Code of Practice (the code) was developed to improve the security and resilience of software that organisations and businesses rely on. It is designed to support software vendors and customers in reducing the likelihood and impact of software supply chain attacks and other software resilience incidents. (GOV.UK)
The code recognises a simple but important point: many software-related incidents are not inevitable. They are often made more likely by avoidable weaknesses in development and maintenance practices or made worse by poor communication between software suppliers and their customers. (GOV.UK)
That distinction matters.
Software security is not only about finding and removing vulnerabilities when they exist. It is about reducing the chance of avoidable weaknesses being introduced in the first place. It is about making secure development more consistent. It is about helping customers understand the risks associated with the software they use.
The Software Security Code of Practice provides a shared baseline for that conversation.
What the Software Security Ambassadors Scheme is designed to do
The Software Security Ambassadors Scheme brings together organisations that have agreed to work with government to champion the Software Security Code of Practice across industry and business sectors.
Ambassadors support the scheme by promoting adoption, showcasing practical implementation and providing feedback to inform future policy improvements. Nexor is listed as one of the scheme’s signatories, alongside organisations including the National Cyber Security Centre (NCSC), Cisco, NCC Group, Palo Alto Networks, Sage and others. (GOV.UK)
For Nexor, this is a natural fit.
Our work has always centred on helping organisations protect, manage and share sensitive information across often complex environments. Whether through secure information exchange products, high-assurance architectures, research & innovations services or secure digital solutions, we understand that resilience depends on more than technology alone.
It depends on good practice, clear assurance, strong governance and a shared understanding of risk.
Secure by Design, not secure by chance
Secure by Design is often discussed as a principle, but its value comes from how it is applied in practice.
It means considering security early, rather than adding controls after decisions have already been made. It means understanding the environment software will operate in, the risks it may introduce and the responsibilities suppliers and customers each hold.
For software vendors, this could include secure development practices, vulnerability management, secure configuration, clear documentation and ongoing maintenance.
For customers, it could include asking better questions of suppliers, understanding software dependencies, assessing risk across the supply chain and ensuring that security expectations are clear from the outset.
Neither software vendors nor their customers can solve these challenges alone.
Secure software depends on a relationship between those who build it and those who rely on it.
Why this matters for the supply chain
Software supply chains are increasingly complex.
A single product may rely on third-party software libraries, open-source components, application integration, development tools, hosting environments and external suppliers. The resulting ecosystem delivers efficiency and innovation, but it also creates risk.
If organisations do not understand where their software comes from, how it is maintained or how security issues are communicated, they may be exposed to risks they cannot see.
That is why the Software Security Code of Practice is so relevant. It helps shift the conversation from “is this software secure?” to more practical questions, such as:
How has this software been developed?
How are vulnerabilities identified and managed?
How are customers informed about risks?
What dependencies does this software rely on?
How is security maintained throughout the software lifecycle?
What evidence supports the supplier’s security claims?
These questions help organisations move from assumption to assurance.
Nexor’s perspective
At Nexor, we see software security as part of a much wider trust challenge.
When information moves between systems, organisations or security boundaries, confidence matters. Organisations need to trust the software, the data, the controls and the processes that sit behind them.
This is why high-assurance thinking remains so important. It encourages organisations to consider how security is designed, how risk is controlled and how trust can be evidenced throughout the lifecycle.
The Software Security Ambassadors Scheme provides an opportunity to support that wider conversation. Not just by promoting the Software Security Code of Practice, but by helping organisations think about what secure software means in real operational environments.