SPONSORED

DevOps, CyberSecurity and their game of Ping-Pong.

Continuing our evaluation of legacy DAST vs Modern DAST, we’ve taken a light-hearted look at the operational and process challenges experienced by DevOps, Cybersecurity teams and QA when preparing Apps for release to the wild.

Likening the process to a game of ping-pong*, with DevOps and Cybersecurity teams batting stuff back and forth, here’s what we imagine it must feel like on both sides of the net.

Ping!
Ping!
Agile organisations are releasing ever-more apps to meet growing business demands.

There’s an inevitable increase in demand to meet operational and commercial objectives, with over half of all businesses increasing the number of apps they release 100-fold. DevOps teams are expanded to keep pace with the demand.

Each release needs security testing, increasing the workload and pressure on security teams.

While the commercial and operational benefits are significant, so too are the security risks if releases aren’t thoroughly checked. Cybersecurity teams are already under pressure as the overall risk landscape increases. More apps testing means more pressure.

Pong!
Pong!

Ping!
Ping!
Build the cybersecurity team to match the growth in DevOps

Seems obvious, more apps, more DevOps staff, so build the cybersecurity team accordingly.

Cybersecurity is a specialisation and these specialists are in short supply

Testing is historically a semi-automated or manual process so, while there are a number of tools available to search for risks, they all require interpretation by a qualified security professional to evaluate and determine risk, grade them and identify real risk from false positives.

Pong!
Pong!

Ping!
Ping!
Understandable, but DevOps need to schedule workload

As you’d expect, the growing demand for apps leads to delivery pressures and dev teams need to plan work, including code amendments from security testing.

All this leads to backlog and compromise, with security teams being asked to prioritise risks so DevOps can finish and release apps.

Welcome to Security Debt

Prioritisation doesn’t remove security risk so, as teams compromise on which fixes they’ll address, businesses are faced with a growing security shortfall – or debt.

Operational imperatives prevail, but accountability is a reality with the teams looking to ensure their reputations – and ultimately jobs - remain intact.

Pong!
Pong!

Ping!
Ping!
Accountability – backlog and breaches

Who’s at fault for the backlog, bottlenecks and where does responsibility lie when a breach occurs?

Things are hotting up now, with accountability and responsibility being battled with no shortage of all-out smashes and unexpected spin.

Game-point
Hang on. Isn’t everyone on the same side? Shouldn’t everyone be winners?
How to achieve the Ping without the Pong!
Automation

Legacy DAST has been around for years to support the security process, but these tools still require manual intervention.

Modern DAST is unique and, in the hands of DevOps, they’re able to test as they go. Using automation and AI, it gives them fast, accurate test results with no false-positives.

This means, cybersecurity teams are only testing a final version, not every stage.

Ping!
Ping!

Ping!
Ping!
Licensing model – unlimited access

Legacy DAST and associated licensing models are a considerable constraint.

Modern DAST is cloud-based, so the whole DevOps team can use it without restriction.

Speed

Because DevOps are carrying out security testing, its easier to schedule workloads, resulting in faster turnaround of your all your apps. More apps, delivered faster.

Ping!
Ping!

Ping!
Ping!
Accountability

DevOps are in full control here, so there’s no ping pong between teams, less need for prioritisation of work and more bugs corrected.

Resource

But what about the security team? How do they fit in?

With the mundane testing taken care of, security teams can focus on the wider threat landscape within the business

Ping!
Ping!

Ping!
Ping!
Match Point! Team performance!

The Modern DAST has given ownership and control to DevOps to better manage their workloads, removed the complexities associated with traditional security testing - like false positives - reduced the need for security debt and released security teams to focus on the risks that really matter.

Ping!

 

(* Ping-pong: UK slang for Table Tennis)

The company they keep
Any technology is only as good as the companies who trust it enough to buy it.

Bright Security are no exception, but we we're impressed with their customer portfolio. Here are some of the brands they work with:


Join the discussion
Related Articles
Application Security Infographic  - AppSec and the Modern CISO
Infographic - AppSec and the Modern CISO

AUTOMATED Application Security Testing​ for SOFTWARE DEVELOPERS

Application Security 6 Web Application Security Best Practices
Application Security Security debt in the name of application development
Application Security Game-changing​ DevSecOps
Application Security API Security:  The Complete Guide
API Security: The Complete Guide

A must-read for DevOps and Cyber Security leaders

Application Security Developers and Cyber Security teams
Application Security Does application development boom mean security debt bust?
Application Security Digital Transformation and its Impact on Application Security
Digital Transformation and its Impact on Application Security

Digital transformation is different in every organisation, but a key contingent involves the business implementing new strategies around how they deploy technology and the security required to keep business assets safe

Application Security Application Security Testing
Application Security Testing - 3 Types and 4 Security Solutions

Application security testing can be categorized into three types: black-box, grey-box, and white-box testing.

Application Security On Demand Webinar: Hitting Legacy DAST Challenges Head On
[WEBINAR]: Hitting Legacy DAST Challenges Head On

Bright Security is the industry's first zero-false positive, fully automated AI-DAST platform built for developers and modern development environments.

Application Security Application Security Testing
Application Security Testing

Security Misconfiguration: Impact, Examples and Prevention

Application Security Build Secure Apps & APIs. Fast
Build Secure Apps & APIs. Fast

Sign up for free trial. No credit card required.

Application Security MODERN DAST
MODERN DAST – The Winning Approach to Microservices Security

The Winning Approach to Microservices Security

Application Security MODERN DAST
MODERN DAST - Empowering DevOps

NeuraLegion helps significantly improve application security at a lower cost by providing no false-positive, AI-powered DAST & Fuzzer solutions, purpose-built for modern development environments.

Application Security Is your API security testing process mature enough?
Is your API security testing process mature enough?

Power and control in the hands of DevOps. Scanning in minutes, not hours

Application Security Straight Talking: Why application security testing practices need to change
Straight Talking: Why application security testing practices need to change

Richard Dickinson, EMEA Sales Director, Bright Security

Application Security Modern DAST
Modern DAST

Delivering stability, control, cost savings and speed to market

Application Security Modern Dynamic Application Security Testing (DAST)
Modern Dynamic Application Security Testing (DAST)

Enabling the ‘Shift Left’. FAST

Share this story

User Rating
Rate the Article

Click the link below to rate this article

Rate this article

Book a Demo

Automate & Scale with Security Testing at the Speed of DevOps

Learn more

We're a community where IT security buyers can engage on their own terms.

We help you to better understand the security challenges associated with digital business and how to address them, so your company remains safe and secure.

Interested in what you see? Get in touch, and let's start a conversation Get in touch