News Articles
Secure by Design
For PharmacyID’s Head of Technology, Michael Everett, protecting sensitive identity information starts long before a platform goes live. It begins with its design.
Every day, Australians hand over some of their most sensitive personal information to complete a police check or verify their identity.
Behind that seemingly innocuous transaction sits a complex technology environment responsible for collecting, transmitting, storing and protecting data that people – and the organisations requesting it – need to know is secure.
Michael says this enormous responsibility has shaped a simple philosophy: security should never be an afterthought. It should be “secure-by-design”.
“Secure-by-design means building security into a system from the beginning, rather than treating it as something that is added at the end,” Michael says.
“For a platform like PharmacyID, which handles Nationally Coordinated Criminal History Checks (NCCHC) and Verification of Identity services, that means thinking about security at every stage.”
Three decades behind the technology
As PharmacyID’s Head of Technology, Michael leads the development, infrastructure and security of the technology underpinning its services.
With nearly three decades of experience spanning software development and architecture, systems integration, higher education, health, traffic safety and identity verification, he joined PharmacyID in 2016 and led the complete redevelopment of its web application.
He also developed the RESTful APIs used by PharmacyID client organisations and today oversees its software development, Azure cloud infrastructure and software security posture, including CISO responsibilities and IRAP security assurance activities.
It means security is considered across the entire technology environment – not just at the point where a user enters their details.
Building security from the ground up
For Michael, secure-by-design begins with understanding exactly what information a system will handle, the risks associated with that information and who genuinely needs access to it.
In PharmacyID’s case, that includes sensitive personal and identity information used throughout NCCHC and Verification of Identity processes.
Security considerations therefore extend across the way information is collected, transmitted and stored; how users authenticate; how APIs are protected; how access is controlled; and how suspicious or unusual activity is detected.
In practice, that means multiple layers of protection including strong authentication, role-based access controls, encryption of data in transit and at rest, secure API design, audit logging, vulnerability management and carefully managed cloud infrastructure.
It also means applying the principle of “least privilege” – ensuring users and clients can only access the information they genuinely need.
“If an account or component is ever compromised, limiting access helps limit the potential impact,” Michael says.
Not a one-off security check
At PharmacyID, security is considered throughout the software development lifecycle – from initial requirements and architecture through to coding, testing, deployment and ongoing maintenance.
PharmacyID’s Azure cloud environment is also actively managed because, as Michael says, “using a reputable cloud provider doesn’t automatically make a system secure”.
“It’s about how that environment is configured and managed, understanding the shared responsibility and making sure the right operational controls are in place.”
Independent security assurance, including PharmacyID’s investment in IRAP assessments, provides another layer of scrutiny against recognised security expectations.
Trust has to be built in
For PharmacyID’s clients, much of this work will never be visible.
And that’s precisely the point.
The benefit of secure-by-design is not another step for clients to navigate, but greater confidence in the technology operating behind the service they use.
It helps reduce risk, protect sensitive information, support compliance obligations and provide greater assurance when organisations integrate their own systems with PharmacyID’s services.
Ultimately, Michael says, secure-by-design comes down to something much bigger than technology.
It comes down to trust.
“Clients need to know that the systems they rely on are built to protect their information, support their compliance needs and continue operating reliably,” he says.
“Good security design is not just a technical requirement – it is part of delivering a dependable service.”