Collaborate to Mitigate: Building Stronger Connections Between Developers and Security Teams
January 10, 2024

Scott Gerlach
StackHawk

The complex, turbulent and disconnected relationship between developers and security teams has been ongoing for more than a decade. Stemming back to the early digital transformation days, faster software development lifecycles, the introduction of cloud environments, along with the proliferated use of APIs, has led to mass friction between the two parties.

Before rapid digitization, when software releases were infrequent and cyber threats were sparse, the collaboration between these two teams, or lack thereof, was more inconspicuous. Developers and engineers would develop code, and security teams would become aware of new applications once in production. However, as the speed of application development has accelerated and with security testing and reviews now required daily, the lack of cohesivity and unification among these teams has become undeniable.

While developers are facing internal pressure to build next-generation applications at astronomical speed, security teams are wrangling with an increasingly volatile cyber threat landscape, growing consumer concerns for applications built to secure their data, and the broad surface of threats they have to cover along with API security. According to Palo Alto Networks' 2022 What's Next In Cyber survey, 71% of CISOs state that security slows down DevOps in their organizations. In most instances, the roadblocks faced by both teams comes down to a lack of clear communication and the absence of workflow policies and procedures, which often prove detrimental.

So how can organizations start to bridge this gap and enable these teams to perform together at the highest level?

Well, it starts with developers and security teams realizing that their goals are more common than they think: bringing innovative software applications to market efficiently and securely. There are myriad ways organizations can break down the silos, reduce conflict and ensure that these two teams become valuable partners.

Start with Leadership

The role of leadership is paramount in bridging the gap between security teams and developers, underscoring the imperative of security as a shared responsibility. In much the same way that accounting assumes responsibility for financial matters, requiring engagement from every organizational member for financial success, security necessitates a collective effort. Leadership teams play a crucial role in setting the tone for this collaboration, emphasizing that security is not solely the concern of those with "security" in their titles but is a shared priority across all roles.

IT leaders should critically assess which teams hold responsibility for different aspects of the application security process and clearly communicate to DevOps, engineering, product, and security teams. Once well-defined processes and roles are established and communicated effectively, it becomes equally important to collect and review feedback from all key stakeholders involved in product development, engineering, and security.

Outlining processes and setting appropriate timeframes for security testing and remediation are critical steps in solidifying a robust and cohesive approach to application security.

Consider Developers When Purchasing Security Tooling

Engage with your developer counterparts to understand the tech stack they use and how they build software/applications. Building a shared understanding of their workflow and gaining insights into tool preferences provides an advantage in creating a solid foundation for bridging the relationship gap. Investigate tools that developers will genuinely like and use. Don't exclude developers from the equation; if they have time, ask for feedback or involve them as key stakeholders in the evaluation process.

Implement Joint KPIs

Setting and pursuing shared goals is another aspect that can significantly enhance cohesive working practices between security and development teams. Rather than having each team working at cross-purposes. The goals and metrics developers and security teams share will vary within every organization, largely depending on their industry, the types of software delivered and how applications are hosted. These types of KPIs can include change failure rate, issue resolution time, time to patch and time to value.

At the end of the day, both teams want to help their company succeed, but differing motivations, mindsets, and KPIs often lead to miscommunication and a lack of collaboration. Bringing together these two perspectives into one shared language will ease the conflict that stands in the way of accelerating growth and success within software development companies. A united front will safeguard organizations from today's most advanced threats.

Scott Gerlach is CSO and Co-Founder of StackHawk
Share this

Industry News

April 25, 2024

JFrog announced a new machine learning (ML) lifecycle integration between JFrog Artifactory and MLflow, an open source software platform originally developed by Databricks.

April 25, 2024

Copado announced the general availability of Test Copilot, the AI-powered test creation assistant.

April 25, 2024

SmartBear has added no-code test automation powered by GenAI to its Zephyr Scale, the solution that delivers scalable, performant test management inside Jira.

April 24, 2024

Opsera announced that two new patents have been issued for its Unified DevOps Platform, now totaling nine patents issued for the cloud-native DevOps Platform.

April 23, 2024

mabl announced the addition of mobile application testing to its platform.

April 23, 2024

Spectro Cloud announced the achievement of a new Amazon Web Services (AWS) Competency designation.

April 22, 2024

GitLab announced the general availability of GitLab Duo Chat.

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.