UK government launches industry 'ambassadors' scheme to champion software security improvements
The scheme aims to boost software supply chains by helping organizations implement the Software Security Code of Practice
The UK government has launched a new scheme to boost adoption of the Software Security Code of Practice by appointing a series of industry champions.
Under the plans, a cohort of ‘Software Security Ambassadors’ will promote the code of practice across various different sectors, showcasing examples of practical implementation and giving feedback to inform future policy improvements.
The first batch of participating organizations includes the Department for Science, Innovation, and Technology (DSIT) itself, along with the National Cyber Security Centre (NCSC).
Make Password Security Your New Year's Resolution
Get 50% off Keeper Personal and Family plans, and 30% off Keeper Business Starter today!
Accenture, Cisco, ISACA, Lloyds Banking Group, Sage, Palo Alto Networks, and others have also backed the scheme.
"By acting as ambassadors, signatories are committing to a process of transparency, development and continuous improvement. The implementation of this code of practice will take time and, in doing so, may bring to light issues that need to be addressed," DSIT said in a statement confirming the announcement.
"Signatories and policymakers will learn from these issues as well as the successes and challenges for each organization and, where appropriate, will share information to help develop and strengthen this government policy."
What is the Software Security Code of Practice?
The Software Security Code of Practice was unveiled by the NCSC in May last year, setting out a series of voluntary principles defining what good software security looks like across the entire software lifecycle.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Aimed at technology providers and organizations that develop, sell, or procure software, the code offers best practices for secure design and development, build-environment security, and secure deployment and maintenance.
The code also emphasizes the importance of transparent communication with customers on potential security risks and vulnerabilities.
Developed with the NCSC, the code is designed to reflect internationally recognized best practices, such as the US Secure Software Development Framework (SSDF) and the EU’s Cyber Resilience Act (CRA).
Software security in the spotlight
The launch of the code came in direct response to growing concerns surrounding software security on both sides of the Atlantic. In the US, for example, the Secure by Design Pledge was launched by CISA in 2023.
This voluntary scheme asks software developers and providers to place a stronger emphasis on product security.
According to figures from the DSIT, more than half (59%) of organizations experienced software supply chain attacks in the past year, underlining the growing risks faced by UK enterprises and consumers alike.
In a separate survey from ISC2, more than half of respondents identified software vulnerabilities in supplier products as the most disruptive cybersecurity threat to their organisation’s supply chain.
ISC2 said it plans to help drive adoption of the code by promoting awareness through educational and thought leadership content, and referencing it in relation to certifications, training, and guidance that support secure software development.
It will also work with organizations across the software supply chain to encourage practical implementation and require its own partners to incorporate it.
“Promoting secure software practices that strengthen the resilience of systems underpinning the economy, public services and national infrastructure is central to ISC2’s mission,” said Tara Wisniewski. ISC2 EVP for advocacy and strategic engagement.
“The code moves software security beyond narrow compliance and elevates it to a board-level resilience priority. As supply chain attacks continue to grow in scale and impact, a shared baseline is essential and through our global community and expertise, ISC2 is committed to helping professionals build the skills needed to put secure-by-design principles into practice.”
FOLLOW US ON SOCIAL MEDIA
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Apple is speeding up software patching due to AI security concerns – here’s what you need to knowNews Apple is speeding up its software patching processes amid rising concerns that AI is helping hackers to spot and exploit flaws at a far quicker pace.
-
Enterprises are shipping so much AI-generated code they can't control or secure itNews As AI coding becomes commonplace, organizations are struggling to control what they are shipping
-
Alert issued over critical vulnerabilities in Linux’s AppArmor security layer – more than 12 million enterprise systems are at risk of root accessNews Researchers have warned Linux flaws allow unprivileged local users to gain root privileges and weaken container isolation
-
AI-generated code is fast becoming the biggest enterprise security risk as teams struggle with the ‘illusion of correctness’News Security teams are scrambling to catch AI-generated flaws that appear correct before disaster strikes
-
The open source ecosystem is booming thanks to AI, but hackers are taking advantageNews Analysis by Sonatype found that AI is giving attackers new opportunities to target victims
-
So much for ‘trust but verify’: Nearly half of software developers don’t check AI-generated code – and 38% say it's because it takes longer than reviewing code produced by colleaguesNews A concerning number of developers are failing to check AI-generated code, exposing enterprises to huge security threats
-
AI-generated code is now the cause of one-in-five breaches – but developers and security leaders alike are convinced the technology will come good eventuallyNews AI coding tools now write 24% of production code globally, but it's risky and causing issues for developers and security practitioners alike.
-
US Senator calls for Microsoft FTC probe over ‘gross cybersecurity negligence’ – Ron Wyden claims the tech giant has provided ‘dangerous, insecure software’ to the US governmentNews Ron Wyden, a Democratic senator from Oregon, has written to the chair of the FTC calling for an investigation into Microsoft's cyber practices.


