2021 DevSecOps Predictions - Part 1
January 27, 2021

DEVOPSdigest asked DevOps and development experts from across the industry for their 2021 DevSecOps predictions:

DEVSECOPS BECOMES MASS MOVEMENT

In 2021 we expect to see the continued acceleration of Kubernetes deployment in production. As budgets become less constrained by concerns related to the pandemic and as enterprise confidence increases, cloud-native projects previously put on pause will start to resume. With that, we will see an additional increase in the holistic scale and scope of Kubernetes deployments. As such, demand for resources that support Kubernetes ecosystems, such as Kubernetes-native security controls, will also increase as they enable greater integration with DevOps and DevSecOps processes and methodologies. Accordingly, DevSecOps is no longer a niche strategy taking a backseat to DevOps — now it's a mass movement.
David Van Everen
VP of Marketing, StackRox

The year 2020 has been marked by the rapid progress of transformational DevOps paradigms such as: co-development in global communities, platform agnosticism, serverless computing, infrastructure-as-a-code, end-to-end workspace with unified experience across entire software lifecycle. That DevOps transformation has offered a unique opportunity for application security. For the first time in a decade, it is realistic to create and integrate security in a complete DevOps, thus making it DevSecOps. Absence of unified DevOps, along with absence of native tools, was an obstacle for Sec. Now, the obstacle has gone. A critical step toward DevSecOps has been taken by DevOps itself, which started offering its own application security technologies. Application security vendors, as well as open-source security communities, have started addressing this emerged opportunity as well. They have begun integrating their existing technologies in the unified DevOps, thus serving it with intermediate solutions (intermediate — because those solutions have not been designed for new pparadigms). At the same time, those security vendors/communities have been/will be rapidly developing native solutions for the emerged DevOps. Those combined efforts will assure that, through 2022, DevSecOps community grow bigger than in the previous ten years combined.
Joseph Feiman, PhD
Chief Strategy Officer, WhiteHat Security

The shift to remote work in 2020 moved digital transformations into high gear. However, as organizations eye the finish line, they're realizing the bottlenecks they removed to streamline development operations are just being replaced with new ones created due to security not being integrated into their workflows. 2021 will put SecDevOps at the top of every organization's must-do to realize the full benefits of their digital transformation. By automating their application security program in tandem with the existing development workflow, enterprises will realize that secure development operations are not just about reducing cyber-risk, but overall business risk by improving efficiency, reducing time-to-market, and accelerating revenue through de-risked project delivery. 
Brittany Greenfield
CEO & Founder, Wabbi

In 2021, we will see DevSecOps become more instrumental and have greater influence in secure application development and delivery. DevSecOps may be an oxymoron to some who don't believe it's possible to have both rapid and secure code delivery. However, DevSecOps' approach of building security into the rapid release cycles is proving to be successful at optimizing security while enabling business goals such as accelerating productivity. I believe it will be the key to allowing application security solutions to go beyond offering the best of breed protection, by also providing the required flexibility, automation, scale and elasticity that can play along the pace of continuous development cycles. This ultimately allows both security and DevOps staff to be successful supporting the company's business goals.
Ben Zilberman
Application Security Director, Radware

DevSecOps will penetrate the entire IT domain. DevSecOps has been about injecting safety in the development lifecycle, reducing any vulnerability and augmenting business value. The companies' shift to DevSecOps would bring in greater collaboration in the software development processes as it ensures that the software development process always remains immaculate, effective, and operative.
Aliaksandr Liakh
DevOps Software Engineer, Exadel

FULL END-TO-END INTEGRATION OF PROCESSES THROUGH DEVSECOPS

While Engineering, Product, and Operations have been unified as part of the DevOps movement, it'll be 2021 when Security finally joins the team.  As the policies and controls Security defines become part of the product requirements, Security will become embedded into DevOps workflows to become part of the acceptance criteria for work items in development and operations at every step of the SDLC. This is not just about operations embedding security tools into their continuous integration and deployment, but rather a full end-to-end integration of the processes through Secure DevOps (SecDevOps) orchestration. This keeps the team focused on winning the game of shipping quality product to market in a timely and efficient manner.
Kent Welch
VP of Engineering, Wabbi

NETOPS, SECOPS AND DEVOPS COME TOGETHER

Successfully executing a process as complicated as cloud-native app adoption requires the involvement of many different teams. Many enterprises think they only really need developer and DevOps teams to drive cloud-native app adoption. As a result, they end up with unsecured, poorly performing cloud-native apps, if they even get that far. In 2021, DevOps teams will deploy more collaborative infrastructure platforms that will enable them to bring in NetOps and SecOps to help "share the load, but without delays" to better transition to a successful cloud-native environment. These groups will collaborate far more effectively and openly than they have in the past.
Ankur Singla
CEO, Volterra

DEVOPS AND SECURITY ELIMINATE THE FRICTION

Looking ahead to 2021, it will no longer be sustainable for organizations to have such a distinct division between DevOps and security teams. Traditional approaches of passing code from development to production, with a security review before launch, are no longer seen as acceptable in an increasingly competitive digital marketplace, where speed, agility, and superior customer experience are paramount. This has been an ongoing challenge. DevOps teams are moving quickly while security teams, which are often much smaller than their DevOps counterparts, are struggling to keep up, ultimately creating friction between the groups. This friction often results in one team's goals being prioritized more highly than the others — usually DevOps being enabled to move quickly and bypass security. Without collaboration between the two groups, we see things like apps with critical vulnerabilities being deployed into production and solutions being released with no visibility into the compliance posture. In 2021, we will see organizations start to recognize the need to eliminate this friction and as a result, they will implement more processes that encourage early stage collaboration between DevOps and security. Security teams will find ways to encapsulate their requirements in language that DevOps teams understand and can consume as part of their design and build processes.
Jeremy Snyder
Senior Director of Business Development and Solution Engineers, Cloud Security, Rapid7

DevOps and DevSecOps evolve into "platform teams"

New "platform teams" will take the lead on enterprises' strategy for what historically been within the purview of cloud operations, security, and development tooling functions, to provide a higher-level abstraction to application developers. This frees the developers to focus on the business application itself, with less concern about the underlying infrastructure often required by DevOps-oriented teams. One challenge here will be finding the talent able to take this broader architectural view.
Liz Rice
VP Open Source Engineering, Aqua Security

BACKUP AND DR COMBINE WITH DEVSECOPS

Following the first-ever Cloud Native Data Management Day co-located with KubeCon NA 2020, we see data management capabilities like backup and disaster recovery becoming more integrated into the fabric of DevSecOps workflows. Capabilities that were considered a production afterthought will start shifting left with backup capabilities baked into "golden development stacks" providing automatic protection policies even for applications that might be added at a later time. With this enterprises will increasingly look at data as a core asset and will take cost arbitrage advantages for data computation across public and private clouds. This means enterprise ops teams will employ solutions that provide them the optionality of Kubernetes application mobility that can efficiently and holistically move entire applications, not just parts like storage subsystems or individual databases.
Gaurav Rishi,
Head of Product, Kasten by Veeam

DEVSECOPS DISAPPEARS

DevSecOps will disappear and DevOps will have security baked in. Here is security that's relevant during coding and security that's relevant during operations but there has never been a separate "Sec" in DevOps. Both security activities will become an integral part of their respective "halves" of the DevOps loop.
Tobias Kunze
CEO and Co-Founder, Glasnostic

The fervor around DevSecOps will cool because the market and analysts will recognize that security in development, delivery and production needs to be built in at a fundamental level, thus obviating the need to think about DevSecOps as somehow separate from DevOps.
Tim Johnson
Senior Product Marketing Manager - CD, CloudBees

Go to 2021 DevSecOps Predictions - Part 2

Share this

Industry News

July 25, 2024

Backslash Security introduced its Fix Simulation and AI-powered Attack Path Remediation capabilities.

July 25, 2024

Check Point® Software Technologies Ltd. announced the appointment of Nadav Zafrir as Check Point Chief Executive Officer.

July 25, 2024

Sonatype announced that Sonatype SBOM Manager, its Enterprise-Class Software Bill of Materials (SBOM) solution, and its artifact repository manager, Nexus Repository, are now available in AWS Marketplace, a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on Amazon Web Services (AWS).

July 24, 2024

Broadcom unveiled the latest updates to VMware Cloud Foundation (VCF), the company’s flagship private cloud platform.

July 24, 2024

CAST launched CAST SBOM Manager, a new freemium product designed for product owners, release managers, and compliance specialists.

July 24, 2024

Zesty announced the launch of its Insights and Automation Platform.

July 23, 2024

Progress announced the availability of Progress® MarkLogic® FastTrack™, a UI toolkit for building data- and search-driven applications to visually explore complex connected data stored in Progress® MarkLogic® platform.

July 23, 2024

Snowflake will host the Llama 3.1 collection of multilingual open source large language models (LLMs) in Snowflake Cortex AI for enterprises to easily harness and build powerful AI applications at scale.

July 23, 2024

Secure Code Warrior announced the availability of SCW Trust Agent – a solution that assesses the specific security competencies of developers for every code commit.

July 23, 2024

GFT launched AI Impact, a new solution that leverages artificial intelligence to eliminate technical debt, increase developer efficiency and automate critical software development processes.

July 23, 2024

Code Metal announced a $13M seed, led by Shield Capital.

July 22, 2024

Atlassian Corporation has achieved Federal Risk and Authorization Management Program (FedRAMP) “In Process” status and is now listed on the FedRAMP marketplace.

July 18, 2024

Mission Cloud announced the launch of Mission Cloud Engagements - DevOps, a platform designed to transform how businesses manage and execute their AWS DevOps projects.

July 18, 2024

Accelario announces the release of its free TDM solution, including database virtualization and data anonymization.