Despite Low Adoption, DevSecOps Improves Incident Detection and Response
August 30, 2022

Tucker Callaway
Mezmo

It's no shock that many organizations have adopted modern software development processes and are leveraging cloud platforms. Some of these companies are already incorporating security into their software development lifecycle (SDLC), while others see it as a mountain they have yet to scale.

A new report from observability data platform provider Mezmo and Enterprise Strategy Group (ESG) shows that the current adoption of DevSecOps is low but it's poised for future growth. Based on a survey of 200 DevOps and IT/information security professionals, only 22% of organizations have a formal DevSecOps strategy, but 62% are evaluating use cases or have a plan to implement it.

DevSecOps is set to gain market traction as it accelerates detecting and responding to attacks in an organization's infrastructure. Most organizations leveraging DevSecOps report improvements in incident detection (95%) and response (96%) efforts. If developers can quickly get accurate information on coding issues that need to be fixed within their workflows, they can efficiently remediate security issues. Of those who've implemented DevSecOps, 84% believe getting developers the right data and tools is the key to success.

Roadblocks to DevSecOps Success

According to the survey, many participants who have not yet transitioned to DevSecOps responded that they anticipated the biggest challenges would be creating a collaborative culture and leveraging security best practices. However, those who have adopted DevSecOps revealed that data capture and analysis are the top obstacles.

As organizations increase the speed and volume of releases to serve more customers, they collect huge amounts of data. Organizations report capturing hundreds of terabytes (32%) and even petabytes (6%) of data per month.

Capturing, processing, and storing this amount of data is costly, which is why it's no surprise that most organizations (69%) don't capture specific data sources. This is a problem if there's an incident and the organization has incomplete data for a comprehensive analysis and quick response. Not to mention this scale of data is time-consuming to analyze, especially if you don't have the right tools in place to parse and route it. An average of 17.5 person-hours is the time it takes to triage and understand security incidents—an amount that 82% of companies would like to reduce.

Observability Data Drives Efficiency

To move fast and build secure applications, organizations need solutions that help them fully harness the value of their data. They must choose the right tools that optimize speed and efficiency and work for multiple data consumers, including developers, ITOps, and security. Leveraging observability data can help drive efficiency by providing insight for better troubleshooting, debugging, and incident response.

Many organizations (91%) use more than one tool to get the most value from their data. This makes it hard for multiple teams to access the data they need to do their jobs. Not having a "single source of truth" (55%) is the greatest challenge holding teams back.

As the report reveals, DevSecOps can be a game-changer for organizations. To overcome current obstacles, a successful strategy involves incorporating security tools and processes into development so that developers can build and deploy secure applications without being slowed down.

Tucker Callaway is CEO of Mezmo
Share this

Industry News

March 18, 2024

Kubiya.ai announces the launch of its DevOps Digital Agents.

March 18, 2024

Aviatrix® introduced Aviatrix Distributed Cloud Firewall for Kubernetes, a distributed cloud networking and network security solution for containerized enterprise applications and workloads.

March 18, 2024

Stride announces the general availability of Stride Conductor, its new autonomous coding product that transforms the software development landscape.

March 14, 2024

CircleCI unveiled CircleCI releases, which enables developers to automate the release orchestration process directly from the CircleCI UI.

March 13, 2024

Fermyon™ Technologies announces Fermyon Platform for Kubernetes, a WebAssembly platform for Kubernetes.

March 13, 2024

Akuity announced a new offer targeted at Enterprises and businesses where security and compliance are key.

March 13, 2024

New Relic launched new capabilities for New Relic IAST (Interactive Application Security Testing), including proof-of-exploit reporting for application security testing.

March 12, 2024

OutSystems announced AI Agent Builder, a new solution in the OutSystems Developer Cloud platform that makes it easy for IT leaders to incorporate generative AI (GenAI) powered applications into their digital transformation strategy, as well as govern the use of AI to ensure standardization and security.

March 12, 2024

Mirantis announced significant updates to Lens Desktop that makes working with Kubernetes easier by simplifying operations, improving efficiency, and increasing productivity. Lens 2024 Early Access is now available to Lens users.

March 12, 2024

Codezero announced a $3.5 million seed-funding round led by Ballistic Ventures, the venture capital firm dedicated exclusively to funding entrepreneurs and innovations in cybersecurity.

March 11, 2024

Prismatic launched a code-native integration building experience.

March 07, 2024

Check Point® Software Technologies Ltd. announced its Check Point Infinity Platform has been ranked as the #1 Zero Trust Platform in the latest Miercom Zero Trust Platform Assessment.

March 07, 2024

Tricentis announced the launch and availability of SAP Test Automation by Tricentis as an SAP Solution Extension.

March 07, 2024

Netlify announced the general availability of the AI-enabled deploy assist.

March 07, 2024

DataStax announced a new integration with Airbyte that simplifies the process of building production-ready GenAI applications with structured and unstructured data.