Project Resources and Deliverables

The repository brings together the outputs of the SECDES project: practical presentations, whitepapers, starter kits and external articles. If you want recordings of past webinars, you can find them on the media page.

Featured deck

Building Secure Applications in the Age of AI

A concise presentation on how AI-assisted development can introduce insecure code, risky dependencies and unsafe workflows, and what teams need to do to keep secure software practices intact.

Download PDF
Whitepaper

Practical Comparison of Threat Modeling Tools and Approaches for Small Teams

A whitepaper exploring several threat modeling approaches and the trade-offs that matter when smaller teams need an approach that is both lightweight and useful.

Download whitepaper
Whitepaper

Dependency Tracking and SBOM: Strengthening Software Supply Chain Security

A whitepaper on software supply-chain visibility, SBOM benefits, adoption challenges and practical guidance for stronger dependency governance.

Download whitepaper
Starter kit

Threat Modeling Workshop Starter Kit

A starter kit for teams that want practical assets for running threat modeling activities and building a stronger security mindset.

Download ZIP

Articles and online reading.

External articles and explainers that expand on secure software development, SecDevOps, API security and maturity models.

Article Dutch

Zeven essentiele principes voor het schrijven van veilige programma's

A Dutch article explaining why secure coding practices need to be embedded early in development rather than added as a late-stage correction.

Read online
Article Dutch

Softwarebeveiliging meten met OWASP SAMM

A Dutch introduction to OWASP SAMM as a practical model for assessing and improving software security maturity.

Read online
Article Dutch

Strategieen voor softwarebeveiliging in de ontwikkelingscyclus

A Dutch article comparing DevOpsSec, DevSecOps and SecDevOps approaches and the trade-offs between them.

Read online
Article Dutch

SecDevOps: beveiliging als cruciaal deel van het ontwikkelingsproces

A Dutch article on treating security as a foundational design concern rather than a late addition to the delivery pipeline.

Read online
Article Dutch

De 4 belangrijkste SecDevOps-uitdagingen aangepakt

A Dutch article on common organizational and tooling challenges that arise when teams adopt SecDevOps practices.

Read online
Article Dutch

Waarom API-beveiliging essentieel is voor elke organisatie

A Dutch article explaining why API security deserves focused attention in modern application portfolios.

Read online
Article Dutch

Hoe stel je een API-beveiligingsplan op?

A Dutch article describing how to create a structured API security plan that fits broader secure software practices.

Read online
Article Dutch

Concrete maatregelen voor het beveiligen van je API's

A Dutch article with practical technical measures such as access control, validation, encrypted communication and testing for API security.

Read online

Presentations and downloadable materials

Slide decks, whitepapers, workshop materials and practical resources produced during the project.

Presentation

By-design Cybersecure Digital Products

An introduction to the SECDES project and the case for integrating security into architecture, testing and governance practices from the start.

Download PDF
Presentation

An Introduction to Threat Modeling

A presentation explaining the role of threat modeling in the secure software development lifecycle and why it matters for SaaS teams.

Download PDF
Presentation

Leveraging Product Management to Shift Left in Small SaaS Teams

A deck on how product leaders can help integrate security concerns earlier by understanding customer risk, value and delivery trade-offs.

View on SlideShare
Presentation

Keeping pace with OAuth's evolving security practices

A practical deck covering current OAuth security recommendations and the direction of the standard.

Download PDF
Presentation

Automated Security Testing

A presentation on weaving static analysis, dynamic testing and scanning into delivery pipelines so security checks become repeatable and useful.

Download PDF
Presentation

Software supply chain security, NIS2 and SBOM

A deck connecting supply-chain incidents, new regulations and the role of SBOMs in improving visibility and governance.

Download PDF
Presentation

An Overview of Threat Modeling Tools

A presentation comparing what threat modeling tools can help with in practice and how to evaluate them as a smaller team.

Download PDF
Presentation

Security and Privacy Architecture through Risk-driven Threat Assessment

A presentation introducing SPARTA and explaining how risk-driven threat assessment can support reuse and prioritization in security architecture work.

Download PDF
Presentation

OpenAPI as a Security Tool

A presentation on using OpenAPI specifications for security review, testing, automation and runtime support.

Download PDF
Presentation

Introduction to SAMM

A practical introduction to the OWASP SAMM framework and how it can guide targeted security improvement work.

Download PDF

SecDes

Security by design, translated into practical guidance for software teams.

© 2024-2026 SECDES. All rights reserved.

Project

Led by Sirris and DistriNet, with support from VLAIO. The project focuses on helping smaller software companies turn secure software development into repeatable practice.

View repository