SPONSORED

Does application development boom mean security debt bust?

Richard Dickinson, Sales Director, EMEA, Bright Security
Application development continues to increase in support of digital transformation programmes, with the majority of organisations now releasing 100 times the amount of code they did 10 years ago.

In many of these enterprises, software developers now outnumber cyber security professionals by as much as 100:1.  Historically SAST enables developers to test code for accuracy during the build cycle to enhance their performance.  This means they’re more easily able to keep pace with their growing workload. organisations create their own competitive edge using innovative software.

For business agility and the drive to shift left, this is obviously good news as organisations create their own competitive edge using innovative software.

Building a Perfect Storm

The flip side to this, however, is that during the development process no allowance has been made for testing for security vulnerabilities throughout the SDLC.  This tends to take place at the eleventh hour by security teams following what can be months of work by development teams.

Going back to the 100:1 ratio, lack of resources in security teams causes bottlenecks in this part of the process, with cyber teams buckling under the strain.

Not only that, if vulnerabilities are detected at this late stage, apps have to be returned to development to unpick code further slowing down release cycles.

This drives up costs and creates notional ping-pong between two key organisations in the application delivery process.





Security Debt Russian Roulette

The alternative to this is a worrying trend towards the acceptance of Security Debt as a quid-pro-quo.  For the uninitiated, security debt is a variant of technical debt that occurs when organisations don’t invest enough money or resources into security efforts upfront.

The term compares the pressures of monetary debt with the long-term burden developers and IT teams face when security shortcuts are taken.

Worryingly, current statistics estimate 86% of organisations knowingly deploy vulnerable applications into production. 

They don’t do this because it's an ideal scenario, they do it because their current resources, processes and solutions do not give them an AppSec option that can be deployed during the SDLC which would better equip them to meet deployment deadlines.

This needs to change if organisations want to maintain brand integrity, mitigate reputational damage and failed compliance due to application security failures.

Make my Day – Pull the Trigger!

Security professionals are specialists and are always going to be responsible for all aspects of cyber security within their organisations.  But with a modern take on DAST, it’s possible to give development teams the tools to test for security vulnerabilities by testing during the SDLC.

By testing running apps and business logic on every commit, it allows developers to validate vulnerabilities and fix them to improve code quality during the SDLC. With results returned immediately with no false positives, it means they hand over apps fit for release.

No more bottlenecks. No more 11th-hour testing. No more security debt relating to application security.

Where is this wonder of modern DAST?

Nexploit from Bright Security is available as a SaaS service for the whole development team, it’s simple to learn and easy to use

The company they keep
Any technology is only as good as the companies who trust it enough to buy it.

Bright Security are no exception, but we we're impressed with their customer portfolio. Here are some of the brands they work with:


Join the discussion
Related Articles
Application Security Infographic  - AppSec and the Modern CISO
Infographic - AppSec and the Modern CISO

AUTOMATED Application Security Testing​ for SOFTWARE DEVELOPERS

Application Security 6 Web Application Security Best Practices
Application Security Security debt in the name of application development
Application Security Game-changing​ DevSecOps
Application Security API Security:  The Complete Guide
API Security: The Complete Guide

A must-read for DevOps and Cyber Security leaders

Application Security Developers and Cyber Security teams
Application Security Digital Transformation and its Impact on Application Security
Digital Transformation and its Impact on Application Security

Digital transformation is different in every organisation, but a key contingent involves the business implementing new strategies around how they deploy technology and the security required to keep business assets safe

Application Security Application Security Testing
Application Security Testing - 3 Types and 4 Security Solutions

Application security testing can be categorized into three types: black-box, grey-box, and white-box testing.

Application Security On Demand Webinar: Hitting Legacy DAST Challenges Head On
[WEBINAR]: Hitting Legacy DAST Challenges Head On

Bright Security is the industry's first zero-false positive, fully automated AI-DAST platform built for developers and modern development environments.

Application Security Application Security Testing
Application Security Testing

Security Misconfiguration: Impact, Examples and Prevention

Application Security Build Secure Apps & APIs. Fast
Build Secure Apps & APIs. Fast

Sign up for free trial. No credit card required.

Application Security MODERN DAST
MODERN DAST – The Winning Approach to Microservices Security

The Winning Approach to Microservices Security

Application Security MODERN DAST
MODERN DAST - Empowering DevOps

NeuraLegion helps significantly improve application security at a lower cost by providing no false-positive, AI-powered DAST & Fuzzer solutions, purpose-built for modern development environments.

Application Security DevOps, CyberSecurity and their game of Ping-Pong.
DevOps, CyberSecurity and their game of Ping-Pong.

Continuing our evaluation of legacy DAST vs Modern DAST, we’ve taken a light-hearted look at the operational and process challenges experienced by DevOps, Cybersecurity teams and QA when preparing Apps for release to the wild

Application Security Is your API security testing process mature enough?
Is your API security testing process mature enough?

Power and control in the hands of DevOps. Scanning in minutes, not hours

Application Security Straight Talking: Why application security testing practices need to change
Straight Talking: Why application security testing practices need to change

Richard Dickinson, EMEA Sales Director, Bright Security

Application Security Modern DAST
Modern DAST

Delivering stability, control, cost savings and speed to market

Application Security Modern Dynamic Application Security Testing (DAST)
Modern Dynamic Application Security Testing (DAST)

Enabling the ‘Shift Left’. FAST

Share this story

Rate the Article

Click the link below to rate this article

Rate this article

We're a community where IT security buyers can engage on their own terms.

We help you to better understand the security challenges associated with digital business and how to address them, so your company remains safe and secure.

Interested in what you see? Get in touch, and let's start a conversation Get in touch