12 DevSecOps Trends to Watch Right Now - Part 1
August 05, 2021

Jayne Groll
DevOps Institute

Baking security into your software and apps from the beginning is more important than ever. Without security, your development lifecycle is open to bugs and vulnerabilities putting your organization and customers at risk. DevSecOps is an augmentation of DevOps, allowing for security practices to be integrated into the DevOps approach. This approach shifts security to the left ensuring that security is implemented in the beginning of the development lifecycle.

While DevSecOps practices are still evolving, there are many trends to keep an eye on. I asked several speakers and sponsors for the upcoming SKILup Day as well as several DevOps Institute Ambassadors to weigh in on the hottest DevSecOps trends. Here's what they shared:

Sponsor, Kendall Miller
President, Fairwinds

The answer is in the question itself, the merging of security into DevOps, when historically it's been a separate practice. Now people are realizing that separating security is a mistake — it all needs to be paired together out of the gate. In the same way that the merging of dev and ops requires great tooling but leads to organizational change and efficiency gains, the addition of security also requires great tooling … but leads to incredible organizational change. So the trend is the merging itself and the tools that make the merge possible. It's really hard to bolt security on afterwards, and as the world increasingly adopts tools like Kubernetes, service ownership is increasingly common, and it must include security from the get-go.

Sponsor, Guy Eisenkot
VP of Product, Bridgecrew by Prisma Cloud

One of the biggest DevSecOps trends is shifting anything, and everything left. To make it easier, faster, and cheaper to address vulnerabilities and misconfigurations, security and compliance teams are looking for ways to collaborate with DevOps and engineering to embed guardrails earlier in the DevOps lifecycle. Whether that's in the IDE or part of build pipelines, getting early feedback helps minimize context-switching for engineers, saves DevOps time prioritizing fixes for issues found in runtime, and reduces risk.

The key for this to be successful, however, is to strike a healthy balance between enforcing security policies and moving fast. If security feedback becomes too noisy, engineers will ignore it, and if it becomes a blocker, they'll find a way around it. Either way, friction will ensue, and you'll end up having to scale back your DevSecOps efforts.

Sponsor, Rob Cuddy
Global Application Security Evangelist, HCL Software DevOps

The top trend is getting developers more involved in threat modeling activities and collaborating on them with security professionals. In 2019 Puppet Labs identified this as the #1 practice for having an impact and improving security posture. (page 35 of the 2019 State of DevOps Report)

Sponsor, Yasser Fuentes
Cloud Workload Security Technical Product Manager, Bitdefender

Security must now keep up with DevOps and the software delivery lifecycle and cadence acceleration. As a result, key areas such as Compliance, Vulnerability Management, Identity Access Management, Encryption and overall built-in security have to move at this same very high speed, otherwise non-secure code would end up deeming their software as unusable and off-market. One of the most feasible solutions (at least at a glance) for CISOs has been the adoption of the shared-ownership model of security, which facilitates application component owners to detect and fix their own related vulnerabilities. The same is true as per software intended to be sold to and used by the US Government - requirements oblige software companies to report, mitigate and fix any related vulnerabilities. However, the reality is that this is not and won't be by any means even close to 50 percent of what's required in order to ensure that the application is secure.

Sponsor, Joni Klippert
Co-Founder and CEO, StackHawk

The number of API-related security incidents is on the rise with Peloton, Coursera, and the latest Experian breach being recent examples from the last 12 months. And API security risk is going to get worse – Gartner cites that by 2022, API abuses will be the attack vector most responsible for data breaches.

Leading DevSecOps teams are beginning to awaken to the threat of API security, and updating their programs accordingly. Teams are proactively implementing processes to manage core API security principles like access control, rate limiting, data exposure testing, and vulnerability testing, in CI/CD to find issues before they are released to prod.

Like application security, API security doesn't have a silver bullet. DevSecOps teams need to implement the right tools from the planning stages of development to make sure their APIs are protected.

Stephen Walters
Sales Engineer, Everbridge

In my opinion, the top trend in DevSecOps right now is organizations and groups trying to understand exactly what it means to them. Just as we had many years of people asking the question, "What is DevOps?" before finally realizing that there is not an all conclusive answer, but merely a base construct and an ideology, so we are seeing the same happen with DevSecOps. Yes, this time we have a slight jump on that, but the greatest challenge now, as then, is the cultural change that many traditional operators are having to face in the way they conduct their roles in day-to-day security.

For example, in traditional models, security has operated, or been made to operate, in a way that reflects its culture - closed, secretive and isolated from other functions - the greatest silo of siloes. That has to change in a DevSecOps culture, where security must be open, integrated and part of the enterprise ecosystem. That is a seismic change for many and it requires a lot of effort upfront from all parties.

Learn more about DevSecOps and similar topics, by registering for an upcoming SKILup Day. Or, start your upskilling journey by learning more about the benefits of DevOps Institute membership.

Go to 12 DevSecOps Trends to Watch Right Now - Part 2, providing even more expert opinions on DevSecOps.

Jayne Groll is CEO of DevOps Institute
Share this

Industry News

March 18, 2024

Kubiya.ai announces the launch of its DevOps Digital Agents.

March 18, 2024

Aviatrix® introduced Aviatrix Distributed Cloud Firewall for Kubernetes, a distributed cloud networking and network security solution for containerized enterprise applications and workloads.

March 18, 2024

Stride announces the general availability of Stride Conductor, its new autonomous coding product that transforms the software development landscape.

March 14, 2024

CircleCI unveiled CircleCI releases, which enables developers to automate the release orchestration process directly from the CircleCI UI.

March 13, 2024

Fermyon™ Technologies announces Fermyon Platform for Kubernetes, a WebAssembly platform for Kubernetes.

March 13, 2024

Akuity announced a new offer targeted at Enterprises and businesses where security and compliance are key.

March 13, 2024

New Relic launched new capabilities for New Relic IAST (Interactive Application Security Testing), including proof-of-exploit reporting for application security testing.

March 12, 2024

OutSystems announced AI Agent Builder, a new solution in the OutSystems Developer Cloud platform that makes it easy for IT leaders to incorporate generative AI (GenAI) powered applications into their digital transformation strategy, as well as govern the use of AI to ensure standardization and security.

March 12, 2024

Mirantis announced significant updates to Lens Desktop that makes working with Kubernetes easier by simplifying operations, improving efficiency, and increasing productivity. Lens 2024 Early Access is now available to Lens users.

March 12, 2024

Codezero announced a $3.5 million seed-funding round led by Ballistic Ventures, the venture capital firm dedicated exclusively to funding entrepreneurs and innovations in cybersecurity.

March 11, 2024

Prismatic launched a code-native integration building experience.

March 07, 2024

Check Point® Software Technologies Ltd. announced its Check Point Infinity Platform has been ranked as the #1 Zero Trust Platform in the latest Miercom Zero Trust Platform Assessment.

March 07, 2024

Tricentis announced the launch and availability of SAP Test Automation by Tricentis as an SAP Solution Extension.

March 07, 2024

Netlify announced the general availability of the AI-enabled deploy assist.

March 07, 2024

DataStax announced a new integration with Airbyte that simplifies the process of building production-ready GenAI applications with structured and unstructured data.