Accelerate or Die
December 05, 2019

David Archer
Contrast Security

A few years ago, I worked as a developer for a software provider, delivering applications to customers using their own servers. I don't want to say how long ago that was, but "DevOps" wasn't a thing back then and cloud was in its infancy. We were playing around at trying to be an agile team, using continuous integration and releasing updates with new features (but mostly hotfixes!) every week. We sneered at some of the other teams dropping six monthly releases and they accused us of being reckless with our continuous releases. Either way, our security team would poke at the apps from time to time and struggled to get a handle on what we were releasing.

Fast forward to 2019 and things have changed. A lot. Not only has the pace of development increased exponentially, but organizations have increasingly relied on their software to act as a differentiator against the competition. Yet, in this race to provide value to the customer, security teams are being stretched to the limit.

Back in the day, security teams needed only make sure that the servers were patched and that the firewall was set up effectively, they would probe applications for vulnerabilities every six months at best. They'd build a wall around the app, maybe even throw in a VPN to stop it being accessed from the bad guys.

So, what's changed? Today, we've split that one monolith app into a dozen microservices, each with their own tech stack (it is best practice to let developers choose). We're now pushing changes hourly to these microservices hopeful this will trigger a pipeline which will push this app into production. We're now running the app in a container — which the developers probably chose — within an orchestration platform in the cloud. On top of that lets sprinkle on some cloud solutions such as file storage, messaging and expose a bunch of APIs to a mobile app of our partners (bye bye VPN). You get where I'm going with this, there is a lot more security work to do.

At this point we should consider the alternative. Slow things down, put the breaks on. It is time to accelerate or die. It is like what we are seeing in the retail industry. There, some of our oldest and most respected brands on the high street are struggling to keep up with their digital counterparts. They're falling behind in the race and without becoming more agile there is one inevitable conclusion. Today a brand will only get you so far, you need to accelerate your development to compete, or your company will join the dozens already in the corporate graveyard.

What does this mean for application security?

We know that applications are the most common cause of data breaches, so we need to make sure we're making the effort to secure them. However, web applications are prickly. They're built on a mix of complex technologies, have a heap of vulnerability types (regardless of language) and they're having to morph daily, or hourly.

In the past we've taken the approach of penetration testing our applications and throwing a Web Application Firewall (WAF) in front of them, but these approaches require a lot of time and expertise. These are expensive and much sort after commodities. You might try to circumvent this by training your developers on security. Whilst this is something I would always advocate to a certain extent, it is a strategy that is based on hope and it's still all too easy to slip up.

When faced with complexity there has always been a consistent approach adopted by engineers to understand what's happening on the inside: instrumentation. Think about an airplane, factory or even the family car, sensors are deployed throughout to provide insight as to how the system is running from the inside. It's the same with software. It is far better to deploy sensors inside software to conduct ongoing security analysis of the application. This provides continuous, fast and accurate feedback to developers in a language they understand. On top of this, it lets developers know whether they are using vulnerable libraries and can block attacks on applications which WAFs would otherwise miss.

David Archer is a Sales Engineer at Contrast Security
Share this

Industry News

January 26, 2023

Ubuntu Pro, Canonical’s comprehensive subscription for secure open source and compliance, is now generally available.

January 26, 2023

Mirantis, freeing developers to create their most valuable code, today announced that it has acquired the Santa Clara, California-based Shipa to add automated application discovery, operations, security, and observability to the Lens Kubernetes Platform.

January 25, 2023

SmartBear has integrated the powerful contract testing capabilities of PactFlow with SwaggerHub.

January 25, 2023

Venafi introduced TLS Protect for Kubernetes.

January 25, 2023

Tricentis announced the general availability of Tricentis Test Automation, a cloud-based test automation solution that simplifies test creation, orchestration, and scalable test execution for easier collaboration among QA teams and their business stakeholders and faster, higher-quality, and more durable releases of web-based applications and business processes.

January 24, 2023

Harness announced the acquisition of Propelo.

January 23, 2023

Couchbase announced its Couchbase Capella Database-as-a-Service (DBaaS) offering on Azure.

January 23, 2023

Mendix and Software Improvement Group (SIG) have announced the release of Mendix Quality & Security Management (QSM), a new cybersecurity solution that provides continuous deep-dive insights into security and code quality to immediately address risks and vulnerabilities.

January 23, 2023

Trunk announces the public launch of CI Analytics.

January 23, 2023

Panaya announced a new Partnership Program in response to ongoing growth within its partner network over the past year.

January 23, 2023

Cloudian closed $60 million in new funding, bringing the company’s total funding to $233 million.

January 19, 2023

Progress announced the R1 2023 release of Progress Telerik and Progress Kendo UI.

January 19, 2023

Wallarm announced the early release of the Wallarm API Leak Management solution, an enhanced API security technology designed to help organizations identify and remediate attacks exploiting leaked API keys and secrets, while providing on-going protection against hacks in the event of a leak.

January 19, 2023

ThreatModeler launched Threat Model Marketplace, a cybersecurity asset marketplace offering pre-built, field-tested threat models to be downloaded — free for a limited time — and incorporated into new and ongoing threat modeling initiatives.

January 18, 2023

Software AG has launched new updates to its webMethods platform that will simplify the process by which developers can find, work on and deploy new APIs and integration tools or capabilities.