Proportionate, or it does not happen
The reason most Security by Design programs stall is that they apply the same heavyweight review to every project, so the business routes around them. The workable version triages first: a short questionnaire in business language establishes criticality (data, exposure, dependencies, regulatory scope), and only the projects that warrant it go through threat modeling, a risk analysis such as EBIOS Risk Manager, and formal review gates. Everyone else gets a checklist they can actually complete.
What the regulations expect
NIS2 lists secure development and acquisition among the risk-management measures management must approve; the Cyber Resilience Act makes security by design and by default a legal requirement for products with digital elements, with vulnerability handling for the product’s support period. For a manufacturer or a software vendor, the practice is no longer an internal preference but the design of a compliance obligation.
Where it lands in a GRC platform
A Security by Design workflow produces exactly the objects a risk register needs: the initiative, its criticality, the feared events, the requirements chosen and the evidence that they were met. Kept in the same system as the register and the control set, each project’s residual risk rolls up into the enterprise picture and its open requirements become owned actions, instead of ending in a review deck nobody reopens. The review deck becomes a record, and the record stays alive.