Our secure by design pledge
At ConnectWise, we prioritize the security and trust of our partners. As part of our Secure by Design initiative, we ensure that our practices align with the three core principles set forth by the Cybersecurity and Infrastructure Security Agency (CISA), to safeguard our digital ecosystem.
We are proud to actively participate in helping establish, and pledging our commitment, to the Secure By Design foundational principles and elements.

PRINCIPLE ONE
Take ownership of customer security outcomes
This principle highlights the responsibility of vendors and service providers to ensure the security of their products and services. It goes beyond simply delivering tools to customers, emphasizing proactive efforts to protect customers from vulnerabilities and security risks.
We hold ourselves accountable for the security of our products and services. They are meticulously designed with security as a top priority, ensuring end-to-end protection. Our partners can trust us to deliver robust security measures, as we prioritize their security outcomes above all else.

PRINCIPLE TWO
Embrace radical transparency and accountability
This principle focuses on fostering trust by openly communicating about security practices, vulnerabilities, and incidents. Organizations commit to being candid and timely in sharing information, empowering customers with the knowledge they need to make informed decisions.
We recognize that trust is built on openness. As a result, we are dedicated to fostering transparent and candid communication regarding our security practices. Our aim is to provide our stakeholders with the necessary information to trust and verify the integrity of our systems.

PRINCIPLE THREE
Lead from the top
This principle underscores the importance of leadership in driving a security-first culture. Senior executives and decision-makers prioritize security as a critical organizational goal, setting the tone and allocating resources to embed security into all operations. This ensures that security is treated as a strategic priority and not just a technical concern.
At ConnectWise our esteemed leadership team places cybersecurity as a top strategic priority, spearheading a company-wide commitment to adhere to Secure by Design principles.
How ConnectWise embraces its "Secure by Design" pledge to CISA
Through our Secure by Design initiative, ConnectWise takes a proactive approach to fulfilling its commitment by adhering to the following seven core pillars of technology and product security:
SSO & multi-factor authentication
Goal: Ensure robust access control for all systems.
Commitment: SSO & MFA across all platforms to enhance security.
How we measure: Track adoption rates and enforce MFA compliance for all users.
WE WILL NEVER CHARGE YOU FOR SSO OR MFADefault passwords
Goal: Eliminate security risks associated with default credentials.
Commitment: Remove default passwords in all products and enforce strong password policies.
How we measure: Audit systems for compliance and report on vulnerabilities addressed.
Reducing entire classes of vulnerability
Goal: Address systemic issues to mitigate broad vulnerability categories.
Commitment: Leverage secure coding practices and frameworks to eliminate these vulnerabilities.
How we measure: Conduct regular code reviews, track vulnerability trends, and assess the effectiveness of threat modeling in reducing vulnerabilities.
Security patches
Goal: Ensure timely patching of vulnerabilities.
Commitment: Maintain an open and transparent policy for reporting vulnerabilities.
How we measure: Track the number of disclosed vulnerabilities and response times.
Evidence of intrusions
Goal: Enhance incident detection and response capabilities.
Commitment: Implement advanced monitoring systems to identify intrusion evidence.
How we measure: Track detection rates and response times for identified intrusions.
CVEs
Goal: Standardize and share information about vulnerabilities.
Commitment: Assign and disclose CVEs for relevant vulnerabilities.
How we measure: Report on the number of CVEs issued and resolved.
Vulnerability disclosure policy
Goal: Facilitate responsible disclosure of secure issues.
Commitment: We will continue to maintain an open and transparent policy for reporting vulnerabilities.
How we measure: Track the number of disclosed vulnerabilities and response times.
Frequently asked questions
What is Secure by Design?
CISA's Secure by Design initiative is a call to action for technology manufacturers to prioritize security from the very beginning of the product development lifecycle. It emphasizes that security should not be an afterthought, but a core principle integrated into the design, implementation, and maintenance of technology products. By shifting the burden of security from customers to manufacturers, CISA aims to create a safer and more secure technology ecosystem for everyone.
Why did ConnectWise align with Secure by Design?
As cyber threats evolve, protecting our partners and their customers is our top priority. Our contribution and participation in the Secure by Design initiative strengthens and renews our commitment to security by implementing rigorous security measures, continuous monitoring, and proactive threat mitigation strategies.
When did ConnectWise sign the Secure by Design pledge?
ConnectWise signed the Secure by Design pledge on September 30, 2024.
Who benefits from Secure by Design?
Managed Service Providers (MSPs), IT professionals, and end users who rely on ConnectWise solutions for business operations will benefit from enhanced security, improved compliance, and better threat resilience.
What security measures has ConnectWise implemented under Secure by Design?
For a comprehensive overview of our security policies and other security measures, please visit ConnectWise Trust Center | Security. Ongoing updates may be posted through various media channels, such as the security site, blog posts or ongoing social media announcements demonstrating progress.
How does ConnectWise protect customer data?
We use industry-standard encryption, role-based access controls, and continuous security monitoring to safeguard customer data. Learn more at ConnectWise | Trust Center | Privacy.
Has ConnectWise implemented Multi-Factor Authentication (MFA)?
Yes, MFA is a mandatory security feature across ConnectWise products to protect user accounts from unauthorized access.
What steps are taken to ensure the security of third-party integrations?
We conduct rigorous security assessments for all third-party integrations, requiring them to meet our security standards before they can integrate with ConnectWise platforms.
Is ConnectWise compliant with industry security standards?
We align with leading security standards such as SOC 2, HIPAA, and GDPR. Learn more at ConnectWise | Trust Center | Privacy.
How can partners stay informed about security updates?
Partners can stay informed through:
- Security bulletins and advisories within the Trust Center
- RSS Alerts
- Webinars, Blogs, MSP Threat Reports, and much more at the Resource Center.