For a long time, cybersecurity has often been treated as the last thing to build, applied to a platform that was already built and is serving customers. Now the approach is breaking down. The vulnerabilities are discovered and exploited faster than bolt-on controls can respond, leaving for organizations no time to catch up. The EU Cyber Resilience Act is making security-by-design a condition of market access: from 11 June 2026, EU countries must have regulatory bodies in place to certify compliance, and from 11 September 2026, manufacturers of digital products must report actively exploited vulnerabilities and severe incidents. The scope of the changes isn’t limited to Europe. A CERT-In advisory in April warned that advances in frontier AI are expanding attackers' capabilities. Indian enterprises respond by focusing their cybersecurity budgets towards identity protection, AI governance and continuous monitoring. The changes occurring in different landscapes point toward the same direction: security should be built in from the start, becoming an integral component.
Zakaria Abidi has spent more than 18 years working inside this shift, building and governing the architecture behind systems that could not simply be redesigned from a blank page. At DigiPaye, he built and structured the company’s engineering organisation from the ground up, defining the technical standards, development processes and delivery methodology behind its SaaS payroll platforms. At INERIS, the French National Institute for Industrial Environment and Risks, he leads enterprise architecture behind the institute’s national research and public-service digital transformation initiatives.
Such regulatory deadlines require from architecture teams something more complicated than filling out a security checklist. Security has to be designed into systems that are often already running and have a wide user base that relies upon them. This is a different and more difficult task compared with building a system from a blank page. That distinction defines the process of how the security actually gets implemented both in government-adjacent institutions and commercial platforms.
Abidi's work at the institute sits inside exactly this constraint. At INERIS, he designed the architecture that supports the development of several modules within the IRiMa programme, which provide services both internally and to BRGM. IRiMa is a major France 2030 research programme co-led by BRGM, CNRS and Université Grenoble Alpes, with Ineris among its participating institutions. The programme as a whole is backed by €51.9 million in funding over eight years. Abidi also served on the governance and evaluation committee responsible for selecting the contractors for a €7.5 million multi-year IT outsourcing framework supporting the modernisation and operation of the institute’s information systems. The framework was divided into two major lots that covered systems and applications as well as network services, awarded to CGI and Axians respectively. This means he worked inside a governance process for a significant public-sector technology programme underpinning the institute’s digital infrastructure .
"At INERIS, even if a decision solves an immediate problem, it can’t be implemented quickly" explains Abidi. "Regulators and funders want to see an evidence trail behind architectural choices. They want to see what was assessed, accepted or ruled out, and what reasons stand behind the decisions. The fact the system works in production isn’t enough."
Commercial platforms undergoing modernisation face an identical architectural question. They need to embed security into a system with live users and existing infrastructure. The constraint remains the same even when the institution, the regulator and the risk profile are completely different.
At DigiPaye, Abidi had to solve this challenge leading the architecture behind a multi-product SaaS environment covering core payroll, white-label accounting portals, and sports platforms. It was part of a group that today processes over 13,000 monthly payslips across more than 1,600 client companies according to its reporting. To maintain legal compliance without disrupting day-to-day operations he had to build a decoupled integration layer which fulfilled the requirements of French collective bargaining agreements (conventions collectives). The approach made it possible to modernise different parts of the system without requiring a full overhaul. The system provided reliable service to clients such as Welcome to the Jungle, a leading French recruitment and employer-branding platform. The modernization also gave DigiPaye a practical foundation for the increasing use of collaborative HR-tech platforms in the future.
"When you think about this approach, security-by-design looks obvious. But it is hard to implement if a platform already has customers that use it every day," says Abidi. "The business can’t be stopped for a while to rebuild the infrastructure. Instead you need to introduce improvements continuously, as a sequence of changes where each can be implemented without taking the system down.”
The DigiPaye experience illustrates the issue many enterprises are facing now: security systems need to be retrofitted into something already in production. In Abidi’s case, it also meant he needed to build the engineering team and establish the standards it operated to. As security becomes an integral part of the architecture from the start, it also moves higher up the organisation, becoming part of core governance. In both settings Abidi has worked in, building a system and establishing its security architecture have converged into a single responsibility.
The EU and India are responding to different pressures, but the solutions seem to be similar. More countries and enterprise companies can be expected to face the same set of issues. As breach costs grow, while AI-driven and supply-chain threats become harder to predict and prevent, more regulators and more enterprise customers start asking the same question before signing a contract. They want to know if security was built into the system from the ground up, or just added afterwards.
"Regulation often gets blamed for slowing down the development. But often it’s the opposite," comments Abidi. "A deadline is sometimes necessary, because otherwise security will lose the priority to someone that feels more urgent."
Some organisations still perceive security as a checklist that gets implemented on a release-day. However, they cannot ignore the shift anymore. If organisations implement the new approach now, they can do it on their own terms, instead of implementing it later, when a regulator's deadline or a security breach forces the decision. Abidi's experience proves that security is an ongoing discipline that cannot be limited to a one-time retrofitted solution.
Depending on the setting this can mean governing a multi-million-euro modernisation programme and getting regulator approval on every architecture decision. This can also mean building a team that could improve platform security continuously without a single outage. In both cases, the work wasn't a separate short-term project. It required a change in how every other decision got made and justified. Abidi’s participation in CRiP (Club des Responsables d'Infrastructure et de Production), which brings together IT infrastructure, cloud and cybersecurity leaders, and his fellowship in Hackathon Raptors (which connects senior engineers across 85+ countries) reflect the same pattern. Security governance is becoming part of how architecture itself is defined, regulated and built.