Integrate, integrate, integrate

Issue 8 2022 Infrastructure

It is time to adopt a security-focused approach to DevOps, one that integrates the security alarm bells and whistles into the flair and speed of development without the traditional frictions and complexities. A survey undertaken by ESG found that 68% of respondents were considering adopting developer-focused security solutions and shifting security to developers.

This is a good thing. As good a thing as DevOps itself – an approach that Forrester describes as one that “consistently reduces time to market, increases enterprise agility, and makes businesses more resilient”.

It’s also why the research firm believes that one of the key areas in which DevOps will advance is in the evolution of practices. Replacing processes will see security and risk personnel shifting to the left and joining projects at the start, rather than wedged into the middle or the end. It’s a view shared by Mandla Mbonambi, CEO of Africonology, who believes that the shift to the left has become as important and essential to the success of a DevOps project as the expertise and capabilities of the teams themselves.

“Security threats are evolving at such a rapid pace that organisations have to embed intense agility into their operations and development processes to keep up and stay secure,” he says. “Developers need to do more than just include security into their systems, they must embrace security within their own best practices and processes. This moves the DevOps approach to security, away from a ‘fill the gaps at the end’ mentality and towards a more robust and resilient one.”

Empowered by technology and security

Forrester believes that this transformation of mindset and strategy can fundamentally determine the success of an organisation in the future. The firm says that high-performing companies will be those which implement code-based change management empowered by technology and security, and that put security and development on the same tier. It’s not an unrealistic ideal, either. The ESG survey found that most security teams are comfortable with developers taking on security testing, with the biggest concern being that this could put undue pressure on development teams.

“There is a risk that by putting security into the development space, companies feel that they are saving money by incorporating the two, without giving the development teams the time or resources they need to perform both roles effectively,” says Mbonambi. “This could then potentially open solutions and the business to even greater risk, as neither the development nor the security is given the attention to detail they need. Speed to market is a very real pressure and teams can end up compromising when there shouldn’t be any compromise at all.”

It's not worth the compromise either. The European Cybersecurity Agency (ENISA) annual report of the threat landscape in 2022 reinforced the concerns that organisations and DevOps teams share when it comes to security risks. The report identified eight primary threat categories across ransomware, malware, social engineering, threats against data, denial of service (DDoS), internet threats, disinformation-misinformation, and supply chain attacks. It also emphasised how denial of service, zero-day exploits, and phishing have grown in both sophistication and use case.

The latter has evolved into spear-phishing, whaling, smishing and vishing, while DDoS attacks have become more complex at a greater scale. The ESG survey found that 38% of organisations had lost data due to the insecure use of APIs, and 37% had suffered an exploit because of vulnerabilities in internal code. This adds to 35% with services compromised due to account credentials, and 34% who had their systems exploited due to vulnerabilities in open-source software. The list does go on – the reality is that security remains a consistent and persistent priority.

“Ultimately, there shouldn’t be a trade-off when it comes to security in DevOps or development in security,” concludes Mbonambi. “Give your teams the best possible support at every point, be it security, operations or development, and ensure that they have the resources and time they need to architect solutions that are resilient and secure. This will not only embed a level of robustness into your business and your services, but it will save you money and time in the long term. Consider using an outsourced, third-party service provider to bolster your teams and to ensure that deadlines are met without compromise.”




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Upgrade your PCs to improve security
Information Security Infrastructure
Truly secure technology today must be designed to detect and address unusual activity as it happens, wherever it happens, right down to the BIOS and silicon levels.

Read more...
The hidden cost of cheap networking gear
Duxbury Networking Infrastructure
When it comes to building a network, price is always a consideration, especially in the current economic climate, but there is a difference between smart spending and short-term savings with long-term losses.

Read more...
Open source code can also be open risk
Information Security Infrastructure
Software development has changed significantly over the years, and today, open-source code increasingly forms the foundation of modern applications, with surveys indicating that 60 – 90% of the average application's code base consists of open-source components.

Read more...
Fastest PCIe Gen 5.0 NVMe SSD
Products & Solutions Infrastructure
Sandisk has unveiled the WD_BLACK SN8100 NVMe SSD with PCIe Gen 5.0 technology, an internal SSD delivering speeds up to 14 900 MB/s and capacities up to 4 TB, with 8 TB solutions available soon.

Read more...
Unified storage solution
Products & Solutions Infrastructure
CASA Software has announced the local availability of Nexsan’s upgraded unified storage solution, Unity NV4000, which is ideal for mixed workloads, from virtualisation and video surveillance to secure backup and recovery.

Read more...
Suprema unveils BioStar Air
Suprema neaMetrics News & Events Access Control & Identity Management Infrastructure
Suprema launches BioStar Air, the first cloud-based access control platform designed to natively support biometric authentication and feature true zero-on-premise architecture. BioStar Air simplifies deployment and scales effortlessly to secure SMBs, multi-branch companies, and mixed-use buildings.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
Advanced surveillance storage from ASBIS
Infrastructure Surveillance Products & Solutions
From a video storage solutions perspective, SkyHawk drives, designed for DVRs and NVRs, offer high capacity, optimised firmware, and a reliability workload rating of hundreds of terabytes per year.

Read more...
Power surges are killing our networks
Duxbury Networking Infrastructure
With power surges and lightning strikes becoming an all-too-familiar threat to South African infrastructure, Duxbury Networking is calling on local installers and network integrators to follow proper grounding protocols.

Read more...
A passport to offline backups
SMART Security Solutions Technews Publishing Editor's Choice Infrastructure Smart Home Automation
SMART Security Solutions tested a 6 TB WD My Passport and found it is much more than simply another portable hard drive when considering the free security software the company includes with the device.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.