Cyber Security
Shift Left Shifted the Blame
Developers are now taking the risk
Editorial
Needed for every device, every application, every day
An endpoint becomes compromised, credentials are harvested, applications are accessed legitimately, data is discovered and privilege expands from there. Security teams may manage these as separate technologies, but attackers rarely see the distinction. That's increasingly influencing how organisations are approaching security architecture.
One of the more interesting developments over the past year has been the growing emphasis on attack paths rather than individual controls. Knowing that an endpoint is vulnerable or an application is misconfigured is useful, but understanding how those weaknesses combine to expose critical assets is proving far more valuable. Security teams are becoming less interested in isolated findings and more interested in identifying the routes an attacker is most likely to exploit.
The effect of all this is also changing the role of endpoint telemetry. Modern endpoint platforms generate an extraordinary amount of information, but on its own that data has limited operational value. The real benefit comes when it is correlated with identity, application activity, cloud workloads and network behaviour to build a much clearer picture of organisational risk. Context has become considerably more valuable than volume.
Businesses are deploying new SaaS platforms, integrating AI services and exposing APIs at a pace that often exceeds traditional governance processes. Every new application introduces another set of permissions, identities, integrations and data flows that security teams need to understand. Visibility is becoming just as important as vulnerability management.
Employees are rapidly incorporating AI into everyday workflows, often through browser-based applications that sit outside established procurement processes. From a security perspective, these are simply more applications interacting with corporate identities and sensitive information. Understanding how those applications are being used, what data is being shared and whether organisational policies are being followed has quickly become part of mainstream endpoint and application security.
Perhaps the biggest operational challenge is one of scale. Large organisations may now be managing hundreds of thousands of endpoints alongside hundreds of SaaS applications, each producing its own telemetry, alerts and policy decisions. Few security teams have the resources to investigate everything. The priority is increasingly becoming confidence rather than completeness—having sufficient visibility to identify the activity that genuinely represents organisational risk. That's why so many conversations now revolve around platform consolidation
The objective is not simply to reduce the number of security products. It is creating a connected view of identities, endpoints, applications and data that allows analysts to understand how seemingly unrelated events fit together. The more fragmented that picture becomes, the harder it is to identify meaningful threats before they become business incidents.
Endpoint and application security remain distinct disciplines, but operationally they are becoming part of the same conversation. Organisations are no longer securing devices in isolation or protecting applications independently. They are trying to understand how users, devices, applications and data interact across the business, because that is increasingly how attackers view the environment too.
Endpoint and application security continue to evolve as organisations embrace cloud-native architectures, AI and increasingly connected environments. If you have practical experience securing endpoints, protecting applications or reducing attack paths across modern infrastructures, we'd like to hear your perspective.