Our secure by design pledge

At ConnectWise, we prioritize the security and trust of our partners. As part of our Secure by Design initiative, we ensure that our practices align with the three core principles set forth by the Cybersecurity and Infrastructure Security Agency (CISA), to safeguard our digital ecosystem.

We are proud to actively participate in helping establish, and pledging our commitment, to the Secure By Design foundational principles and elements.

Read the press release »

people laughing gathered around a conference table

PRINCIPLE ONE

Take ownership of customer security outcomes

This principle highlights the responsibility of vendors and service providers to ensure the security of their products and services. It goes beyond simply delivering tools to customers, emphasizing proactive efforts to protect customers from vulnerabilities and security risks.

We hold ourselves accountable for the security of our products and services. They are meticulously designed with security as a top priority, ensuring end-to-end protection. Our partners can trust us to deliver robust security measures, as we prioritize their security outcomes above all else.

Learn more »

PRINCIPLE TWO

Embrace radical transparency and accountability

This principle focuses on fostering trust by openly communicating about security practices, vulnerabilities, and incidents. Organizations commit to being candid and timely in sharing information, empowering customers with the knowledge they need to make informed decisions.

We recognize that trust is built on openness. As a result, we are dedicated to fostering transparent and candid communication regarding our security practices. Our aim is to provide our stakeholders with the necessary information to trust and verify the integrity of our systems.

Visit our Trust Center »

two people looking at a laptop screen
person with laptop open talking to two other people at a conference table

PRINCIPLE THREE

Lead from the top

This principle underscores the importance of leadership in driving a security-first culture. Senior executives and decision-makers prioritize security as a critical organizational goal, setting the tone and allocating resources to embed security into all operations. This ensures that security is treated as a strategic priority and not just a technical concern.

At ConnectWise our esteemed leadership team places cybersecurity as a top strategic priority, spearheading a company-wide commitment to adhere to Secure by Design principles.

Meet our Leadership Team »

How ConnectWise embraces its "Secure by Design" pledge to CISA

Through our Secure by Design initiative, ConnectWise takes a proactive approach to fulfilling its commitment by adhering to the following seven core pillars of technology and product security:

icon

SSO & multi-factor authentication

Goal: Ensure robust access control for all systems.

Commitment: SSO & MFA across all platforms to enhance security.

How we measure: Track adoption rates and enforce MFA compliance for all users.

Our SSO journey since 2022: A look back »

WE WILL NEVER CHARGE YOU FOR SSO OR MFA

icon

Default passwords

Goal: Eliminate security risks associated with default credentials.

Commitment: Remove default passwords in all products and enforce strong password policies.

How we measure: Audit systems for compliance and report on vulnerabilities addressed.

More tips and guidance on security practices for MSPs »

icon

Reducing entire classes of vulnerability

Goal: Address systemic issues to mitigate broad vulnerability categories.

Commitment: Leverage secure coding practices and frameworks to eliminate these vulnerabilities.

How we measure: Conduct regular code reviews, track vulnerability trends, and assess the effectiveness of threat modeling in reducing vulnerabilities.

icon

Security patches

Goal: Ensure timely patching of vulnerabilities.

Commitment: Maintain an open and transparent policy for reporting vulnerabilities.

How we measure: Track the number of disclosed vulnerabilities and response times.

eBook: Patch management best practices »

icon

Vulnerability disclosure policy

Goal: Facilitate responsible disclosure of secure issues.

Commitment: We will continue to maintain an open and transparent policy for reporting vulnerabilities.

How we measure: Track the number of disclosed vulnerabilities and response times.

Read our vulnerability disclosure policy »

task searching icon

Evidence of intrusions

Goal: Enhance incident detection and response capabilities.

Commitment: Implement advanced monitoring systems to identify intrusion evidence.

How we measure: Track detection rates and response times for identified intrusions.

Learn more about ConnectWise Incident Response Service »

icon

CVEs

Goal: Standardize and share information about vulnerabilities.

Commitment: Assign and disclose CVEs for relevant vulnerabilities.

How we measure: Report on the number of CVEs issued and resolved.

ConnectWise authorized as CVE Numbering Authority »

Frequently asked questions

CISA's Secure by Design initiative is a call to action for technology manufacturers to prioritize security from the very beginning of the product development lifecycle. It emphasizes that security should not be an afterthought, but a core principle integrated into the design, implementation, and maintenance of technology products. By shifting the burden of security from customers to manufacturers, CISA aims to create a safer and more secure technology ecosystem for everyone.

As cyber threats evolve, protecting our partners and their customers is our top priority. Our contribution and participation in the Secure by Design initiative strengthens and renews our commitment to security by implementing rigorous security measures, continuous monitoring, and proactive threat mitigation strategies.

ConnectWise signed the Secure by Design pledge on September 30, 2024. You can read the official announcement on our press release page, ConnectWise Signs Secure by Design Pledge, Reinforcing Commitment to Cybersecurity.

Managed Service Providers (MSPs), IT professionals, and end users who rely on ConnectWise solutions for business operations will benefit from enhanced security, improved compliance, and better threat resilience.

For a comprehensive overview of our security policies and other security measures, please visit ConnectWise Trust Center | Security. Ongoing updates may be posted through various media channels, such as the security site, blog posts or ongoing social media announcements demonstrating progress.

We use industry-standard encryption, role-based access controls, and continuous security monitoring to safeguard customer data. Learn more at ConnectWise | Trust Center | Privacy.

Yes, MFA is a mandatory security feature across ConnectWise products to protect user accounts from unauthorized access.

We conduct rigorous security assessments for all third-party integrations, requiring them to meet our security standards before they can integrate with ConnectWise platforms.

We align with leading security standards such as SOC 2, HIPAA, and GDPR. Learn more at ConnectWise | Trust Center | Compliance.

Partners can stay informed through: