Meet Our Guest

Dominic Willson

Co-Founder at Sprintworks

Dominic Willson is a Software Engineer, Solutions Architect and Co-Founder at Sprintworks, a bespoke software development consultancy based in Manchester. He’s an experienced technology leader, having grown 180-engineer software departments and set technical direction for 45+ engineers across UK Civil Service product teams, with a background spanning big-data platforms, serverless architectures and high-performance distributed systems.

At Sprintworks, Dominic and the team build bespoke software for clients from startups to enterprises, baking security, automation and DevOps in from day one. He frequently speaks at industry events, mentors tech startups through investment rounds, and is a strong advocate for growing Manchester’s tech talent.

Dominic Willson and Adam Myers

ONE-PAGER

Secure by Design Explained with Sprintworks

Best Practices & Lessons Learned

Most software still gets built fast, then secured later. Secure by Design flips that, building protection into the foundation from the very first decision, rather than patching it on once something breaks.

This one-pager distils Dominic Willson’s key lessons on applying Secure by Design principles at any scale, from startup MVP to enterprise platform, including how to threat model before writing a line of code and where AI-generated software introduces risk. A practical reference for founders, engineers and security leaders building software fast.

Download One-Pager

Episode Transcript

Adam Myers:

Hello and welcome to our podcast, Tales from the CyberLab. My name’s Adam Myers. I’m the sales director here at CyberLab, and I’ll be your host for today. Joining me is Dominic – welcome. Thank you. Can you just tell us a little bit about your role and what you do at Sprintworks?

Dominic Willson:

Yeah, so I’m a Co-Founder at Sprintworks, we’re a software engineering consultancy. I’ve been a software engineer for most of my career, starting off in the game industry back in the early days and moving now into secure software engineering at scale.

Adam Myers:

Yeah, brilliant. So we’re going to be talking today around Secure by Design. So I guess for people who are kind of new to the podcast, could you just expand a little bit and just what is Secure by Design?

Dominic Willson:

Yeah, so Secure by Design is essentially building security into your architecture from day one rather than panicking and adding it at a later date.

Adam Myers:

Okay, so I guess that’s maybe different to how other businesses do things, isn’t it? So if you are thinking ‘security from day one’, is that kind of the principle there as opposed to later down the line having to maybe change and modify, you’re doing it from the off?

Dominic Willson:

Yeah, yeah. So it all comes down to a set of principles that you are applying from the first minute of thinking about product. In agile software development, the whole idea is to build things quickly and get value to the customer within weeks, not years. And that you would think is against what Secure by Design is because when you think Secure by Design, you think large scale systems, banks, massive retail customers think of Jaguar Land Rover, etc. But actually you could apply a lot of those principles from the very early days. And it’s all around the concept of defence in depth and zero trust architectures and things like that.

Adam Myers:

Is this relatively new or is this something that’s always happened or have you found that you are in a little bit of a niche where you’re adding real value because it’s saving time, project time, I would imagine, and you do things maybe quicker and I guess AI’s helping with that to some extent.

Dominic Willson:

Yeah, certainly. And not, but yeah, I’m sure we’ll come to that in a bit. Secure by Design dramatically speeds up the speed that you can build a project from start to finish because you are not then having to worry about all of the complexities of patching things in at the end. I don’t know, you might do a penetration test at some point in the future and that will flag up something that is a fundamental change to your whole architecture.

The idea of Secure by Design is to think about all of those things early on. And as senior principle software engineers, you tend to think about a lot of these problems from day one, but even if you’re not, there are a set of principles that you can follow.

Adam Myers:

So are you anticipating what could go wrong? Is that where you start? You kind of thinking “this could be a problem.” This is, like you said, those core principles. Is that a fundamental of how you map that and view that, I guess?

Dominic Willson:

Yeah, ultimately you are trying to think ahead on what an attacker could do. You’re putting yourself as a software engineer in the shoes of an attacker and how they would tend to break into systems. So you might have a mobile app or a cloud-based web app or your banking app or something like that, and they all have different risk appetites and your way of thinking about those problems are going to change. But ultimately the principles that underlie all of this are the same.

Adam Myers:

Amazing. So Dom, you’ve got a background with building large scale technology platforms in cyber security. What made you take that experience and start Sprintworks in Manchester? We’re from Manchester. I’m very proud that we work in the same office. I guess, how did it all start?

Dominic Willson:

Yeah, I mean, I’ve been working in cyber security for a long time now, and as I said before that in the games industry. And ended up outsourcing millions of pounds of contracts to suppliers and didn’t always get the quality that I’d expect from that and the security from day one that you’d expect from that. And well, ultimately a few years ago I went out to San Francisco and saw what that startup culture could be like, the collaboration, I guess the vibe of some really nerdy nerds building some really cool products. But they didn’t lose that sort of collaborative nature. In fact, it was huge and that massively inspired me to start a business. I came across, well, I’ve been working with my co-founder, Sam, for a very long time. And we have talked about this over and over in our previous jobs and eventually just got to the point where we’re like, it’s time. Let’s give it a punt and see what happens!

Adam Myers:

And Manchester, so we work very closely to Dish, Manchester Digital, and it feels like Manchester’s got this real tech vibe at the moment. It feels like it’s buzzing. There’s a lot of businesses in Dish. So shout out to anyone that’s in Manchester working with us or closely. It’s buzzing, isn’t it, when you’re in the office and it’s great to see Manchester in such a great place.

Dominic Willson:

Yeah. And Dish as well is such an exciting place. It’s where we met ultimately. And we’ve been able to scale in Dish. And because of the community that comes with that as well, as I said, the collaborative nature that I saw in San Francisco walking around and speaking to businesses. I saw that and I see that in Dish and the Manchester tech ecosystem and beyond as well as organisations like Manchester Digital that are out there supporting businesses and providing opportunities for them to scale.

And I firmly believe that Manchester is the best city to start a startup in the UK for sure, and maybe even Europe is fastest growing tech capital in Europe apparently. And now we’re getting to the point where GMCA, Greater Manchester Combined Authority, are funding startup projects with no expectations ultimately. They are trying to help jumpstart businesses. And it’s small amounts of money, but it is really, really working. And we are seeing that in the products that we work with and the companies that we work with. Some of them have or would not exist without that startup fund. And they’ve been able to transform that into successful businesses and scale where they previously wouldn’t have existed. So it’s really, really cool vibe.

Adam Myers:

Yeah. So I know our audience that are from Manchester and looking at the tech startup scene and reach out to us, we can give an advice of how that helped us and equally put you in touch through the likes of Manchester Digital and Dish. Dom, you’ve worked in retail, healthcare, logistics, government, and supply chains, so lots of industries. Does Secure by Design work the same in every sector or does it change? How does that fit depending on vertical?

Dominic Willson:

Yeah, it’s really interesting, isn’t it? Because ultimately the principles you would expect to stay the same and they do. But the scale of which they are applied and audited and tested and the requirements of organisations like governments and healthcare, and especially large retails and retailers now after we’ve seen over the last year or so, they apply more stringent requirements. But ultimately when you’re a startup building an app that might be going into healthcare, you still need to apply those principles from day one. And it makes a huge difference to the products that come out of it.

Adam Myers:

Yeah. And I guess it’s like regulation, sensitive data, people signing off that process there, isn’t it, depending on.

Dominic Willson:

Yeah it becomes a bit more clunky, I would say. But ultimately you still need to build your products in a way that’s going to apply them from the ground up because ultimately if you’re building a startup now, your expectation is for that to be at an enterprise scale in large organisations in a supply chain at some point. Otherwise, what’s the point?

Adam Myers:

Dream big, I think!

Dominic Willson:

Yeah, dream big. And so you are baking them in from day one and ultimately it doesn’t cost you anymore to do that. If you start from day one with that mindset of the Secure by Design kind of mindset, we’re not saying that you have to invest millions of pounds into your product from day one. By thinking about these things from day one, you can make the choices in the architectures, in the dependencies, in the products, the technologies, tech stack that you use such that you kind of get that for free.

And ultimately some of these larger platforms, they’re very restricted by legacy software and legacy requirements and legacy organisations come with their own problems. And so you can often, as a small company or a greenfield project, move for a lot faster than they can, but then on the other side of it, you can start to apply some of those principles to those environments as well.

Adam Myers:

Yeah, because I’ve seen that in tech. So over 20 years in tech, you see that where there’s a legacy system that underpins and holds everything back. And in a perfect world, we’d get rid of this and we won’t do this way in today’s world. And technology’s moving so fast. It feels like the framework that you’re putting on the ground, what you’re doing in the early phase is setting you up for that future success in it where you’re not going to be held back. You’re almost applying a very disciplined process and structure to a startup. But like you said, the dream is to become an enterprise business or something on a large scale, I would imagine. So I guess that helps you way down the line, doesn’t it? Instead of being held back, you’re in a great place.

Dominic Willson:

Yeah, and we see this as a really good example of this in the logistics company that we work with. And we look after the entire digital estate from goods-in to goods-out and all of their suppliers as well. And that kind of migration from legacy platform to new, well, those can happen in tandem. And yes, the legacy platforms maybe aren’t as secure as you would hope they were because they were built 15 years ago and nobody’s really looked after them since. But it’s that mindset of, well, we got here to this point now where we can invest in these platforms and that would not have happened had we not had those legacy platforms in place. So there’s a sort of cost benefit there and you have to take it with a pinch of salt, I suppose, and build the systems in a way that you can migrate and use both. And you can still get the Secure by Design, agile software development, when you’re getting things to people in a matter of days or weeks, you’re getting them in production. But you choose a small subset of that problem set that’s their biggest bottleneck right now. Make sure you’re building that secure from day one and then expand from there rather than trying to take the whole thing and replace it. That’s when you end up really putting your Secure by Design at risk because you’re trying to rush things. You’re not thinking about the product. You’re going to make people upset because you’re not necessarily putting security first. So yeah, there are definitely means and ways to do that that work for both secure software and building a product that people actually want to use.

Adam Myers:

Amazing. So you’ve always got a vast amount of knowledge. Is there a way that if any of our audience are listening and they want to maybe reach out and they’re probably looking at this themselves now and thinking I could do with Dom’s advice and maybe going down that path with you guys, what’s the best way for them to reach out to you and how would they get in touch to maybe run some of these ideas by you and projects?

Dominic Willson:

Yeah, feel free to reach out to us on LinkedIn or on the sprintworks.dev as well. Find us there and contact us through that.

Adam Myers:

Amazing. Listening to this episode, one thing becomes really clear. Secure by Design only works if someone actually checks the design is secure and follows the right framework and principles as discussed in this episode. Our build reviews assess the system design and the core components following the Secure by Design principles. And if you’d like to understand more of how we can help with these Build Reviews and look at key infrastructure and technologies, please reach out on the link below or check out our website at cyberlab.co. Uk. But for now, back to the episode. So moving into our topic, it’s going to be around AI and cloud. I’m sure you were prepared for this. So when you’re building something today, cloud, mobile, AI powered, how would you actually go about identifying what could go wrong before it actually does? And yeah, what’s the plan there?

Dominic Willson:

Yeah, so again, we’ve seen this with some customers recently, but there are means and ways and frameworks which help you determine how an attacker might attack a system. And there’s the STRIDE framework and then there’s also MITRE Attack. And we tend to use these to help us assess platforms and assess products and apps and whatever system for their vulnerabilities and their potential vulnerabilities before you’ve even started with a line of code. Again, that kind of doesn’t gel naturally with these sort of agile mindset, building an MVP as fast as you can, getting it in production, but it’s taking a step back from that and assessing that in smaller chunks as well. And so building that methodology into your mind as a software engineer, as a principal software engineer, senior software engineer especially, and solutions architect so that you are bringing a lot of that security mindset from day one and applying that to your three-week sprint or whatever it might be. And also thinking about the longer term implications of choosing an authentication provider that has a sieve that has holes all over the place, you’re not going to do that. But you get that from experience, not necessarily from just deciding in the moment, I guess.

Adam Myers:

And I think you said there’s a real, I think, top tip there. You said, “what can an attacker do here needs to happen before a line of code is written?” You said that a couple of times now. And I think that’s something for our audience to listen to and take notes of, isn’t it? It feels like that’s a sort of punchy saying of maybe just think before maybe you’re writing code.

Dominic Willson:

Yeah, it’s a mindset change, I think. Every line of code that you’re making, every Jira ticket that you are writing, you need to be thinking about the security implications of that. And you can use these threat modelling exercises that I mentioned to teach yourself how to think in that way almost. And they’re really useful for large scale platforms, especially. The whole idea behind them is that you take that step back as an attacker and think how are they going to try and get into your system? Is it that you’ve left the front door open and they walk straight in? Well, if they’ve happened to do that, then you need to start thinking about defence in depth. If they did get into the front door, are all of your crown jewels in a safe inside your house? Is that kind of way of thinking of how do you build these onion layers, I suppose, around your platforms or multiple onions network together in a way that you can then create a more resilient architecture at that scale as you grow. But again, thinking about baking that in from day one.

Adam Myers:

And I guess it’s like IP. We did a podcast previously and it’s around IP and keeping that IP. And I guess as you’re building, a lot of that is protecting that, isn’t it as well? So you might have a great idea, but someone else might try and take the idea. So again, Secure by Design is helping you with keeping hold of your copyright and whatever that might be and how you look after the thing that you’re building as well.

Dominic Willson:

Yeah. I mean, yes, you touched on it before. It’s only getting harder. The scale and speed of attacks and cyber attacks. We’ve seen it a lot in the recent year with Jaguar Land Rover, Co-op, M&S. They’re getting higher profile, which is good for secure software engineering because now we’re now starting to think a bit more about security baked in from day one and maybe a little bit panicked going, “Oh, have we done a good enough job?” And fingers crossed. But it’s definitely changing the way that the defence is happening and the products are built, but it’s also changing the way that our adversaries are trying to break into systems. And now with AI coming along and making our days easier and harder, our adversaries have no limits. They can run thousand agents attacking all of your systems as quickly as they possibly can. You’re in a pretty tight spot if you aren’t on the other side of that building secure systems from that day one point.

Adam Myers:

Yeah. And I guess AI, you touched on that, so we’re going there. But you can generate in minutes now, can’t you? You can generate code and software. Is this a good thing? Is it risk? I guess there’s pros and cons. Do you want to just expand a touch on what you see and you’re using it, you’re probably – Oh yeah, of course. What are your thoughts that you can maybe share with the audience?

Dominic Willson:

Yeah, I mean we pride ourselves in being an AI-first software engineering consultancy. And that doesn’t necessarily mean we’re making any more money out of that. We ultimately build products faster and charge our customers less. But by doing so, we get to work with more customers, we get to help them scale faster and build cooler tech in a much shorter amount of time than our competitors, which is great. But then you’re starting to see the use of AI vibe coding assistance, I suppose, in prevalence across the world now. And you’ve got people who have never even known a software developer building software products in an afternoon with a few credits and validating their ideas and building their MVPs and trying things out. And I personally, we think it’s great. And we have customers come to us. We actually have a service now that’s called Vibe Coding Rescue because we’ve had customers come to us that have essentially gotten to the point where they’ve built a really cool MVP using lobbable replit, whatever. And they’ve gotten it to a point where they’ve put it in front of customers or users and they’ve gone, “Oh, this is great. Can I use this?” And we’re like, “Yeah, but I have no idea how secure it is. I have no idea where your data’s going. I have no idea what the code base does at any point.” And it’s really high risk. And these platforms have prioritised value to customer and not necessarily secure software, which we’re definitely seeing as a much higher risk now. And AI in software engineering especially is introducing a lot of risks if you don’t have those guardrails in place and these platforms don’t necessarily have those guardrails in place. So something we try and do is, we don’t try and do, we do, is bake these guardrails in from day one. And it all comes back to that Secure by Design mindset of, well, are you automating your testing? Are you automating your end-to-end deployment? Are you doing security scanning on every line of code that a developer makes? And that kind of shift left mentality that I mentioned before. You are doing this as close to the developer writing code as possible and not just before it goes into production. You’re getting somebody in QA to go and say, “Oh yeah, that’s all right.” And so it’s baking those guardrails in from day one so that when you are using AI copilots, and we do use AI copilots, a lot, you are able to trust but verify what those copilots are doing. So you’re able to essentially get code into the point where you are in code review in a pull request or whatever, and you’re in a pretty good confident place where the rest of the platform is secure, but you’re still getting a human on top of that code for now to the point where you are confident in the same way that you would be with a junior software engineer is day one of being a software engineer. You would review all their code. Well, AI is in the same position at the moment. It might not always be, but right now that is hugely important. And the vibe coding apps, which are great for prototyping and great for validating ideas, they don’t have that process. Your data when it sits in those platforms, there are reports of, I don’t know, your API keys for your, I don’t know, Google login or your anthropic API keys or whatever. They’re all sat in the code base leaked out onto the internet and nobody’s really checking that. And so it’s those sorts of things that you need to be really careful of. And a penetration test always picks something up. So these platforms are going out and being used by real people with that real data, quite sensitive data in some cases. If you are not putting those guardrails around that, something is going to go walk about, I suppose.

Adam Myers:

Yeah. And I guess the risk is when something can be done so quick that you can run fast and you’re just like, “We’re here, we’ve landed, we’re at this great place, so let’s just keep going at this pace.” Like you said, it’s almost taking a step back, isn’t it, and just going, “Do we understand the risks here that we might be going too fast for where this project is?” If you can get someone in minutes, it’s now like, okay, we’re here without maybe doing the checks that you should be doing. I think pen testing, you touched upon that, obviously something that we do. CREST and CHECK-certified penetration testing company, work very closely with dev teams, some projects. I think it’s key, isn’t it, to be testing and doing that after major project change or delivery and making sure we’re doing those pen tests and stress testing systems?

Dominic Willson:

Yeah, it really is. And it’s something that we do constantly in all of our products and our techniques and platforms that are always penetration tested during and after the build process, because we don’t want to be marking our own homework. We trust ourselves to build secure systems, but then there’s always something you can miss and you need to validate that both for our customers’ peace of mind, I suppose, and our own.

Adam Myers:

Yeah. And it’s like the rubber stamp and a second set of eyes, isn’t it? Just to say this is as we think it is. And like I said, that’s a good process too at bake in. So just to include the episode, if there’s one top tip you can give to our audience of what, and maybe we’ll summarise this podcast, what would it be if you were to give us your hot take on things?

Dominic Willson:

Yeah, I think it would be that secure mindset from day one. Keep that at the top of your mind, and don’t let it slide in the interest of trying to build stuff as fast as possible and keep your customers happy. You both need to do that by building product and by making sure that they’re not going to have a data leak in a year from now.

Adam Myers:

Yeah, amazing. Well, thank you, Dom, for joining us. I’ll see you in Dish probably in about 20 minutes. But that concludes this episode of Tales from the CyberLab. Join us next time for a brand new episode. Until then, Stay Secure.