{"id":8170,"date":"2016-08-17T10:46:53","date_gmt":"2016-08-17T10:46:53","guid":{"rendered":"http:\/\/www.devopsonline.co.uk\/?p=8170"},"modified":"2016-08-17T10:46:53","modified_gmt":"2016-08-17T10:46:53","slug":"why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks","status":"publish","type":"post","link":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/","title":{"rendered":"Why developers must be enabled to build better code to defend against cyberattacks"},"content":{"rendered":"

Janet Worthington, Senior Product Manager, Veracode<\/a>, explains why security and DevOps must collaborate to build a more secure future.<\/em><\/p>\n

Collaboration has been the key to successful IT development for over 10 years. The proliferation of open source software code, for example, has enabled the speedy development of millions of applications, fostering a culture of innovation and positive change to the market.<\/p>\n

However, while open source software has enabled the quick development of apps, it has also arguably been the birthplace of many security vulnerabilities in long supply chains \u2013 which is why it is critical that all apps are built with security in mind from the outset.<\/p>\n

In a utopian world, this would be an easy step to take. However, that is not the world we live in today, and the relationship between developers and the security team hasn\u2019t always been a strong one. Traditionally, the IT security team have been typecast as the ones slowing the development process, finding gaps in the design and sending developers back to the proverbial drawing board.<\/p>\n

Yet, even with both the security and development teams agreed on the importance of delivering a high quality application, security procedures are still too often considered late in the development cycle. And if the process of providing continuously secure software wasn\u2019t difficult enough, this certainly doesn\u2019t make it any easier.<\/p>\n

Great expectations of speed<\/h2>\n

Developers are expected to produce high quality code, continuously and at speed. After all, delays cost market share and allow rivals to take the lead. However, this can have a detrimental effect on the quality of code developed, with recent research suggesting most developers (85%) believe vulnerability remediation<\/a> harms their potential to produce features and products on time and on budget.<\/p>\n

The poll also found that 70% of software and application developers<\/a> often feel pressure to release updates that could override security concerns \u2013 again potentially putting companies, and their customers at risk.<\/p>\n

The economic cost of insecure DevOps<\/h2>\n

Veracode\u2019s research<\/a> into application development revealed a startling 63% of internally developed applications are non-compliant with OWASP Top 10 standards (the widely accepted standard for application security), when initially assessed for security.<\/p>\n

And while these may seem like micro issues, when considered as part of the wider economic picture, there are serious fiscal consequences to overlooking security. Indeed, research<\/a> from Veracode and the Centre for Economics and Business Research (CEBR) revealed that cyberattacks cost UK companies \u00a334 billion a year in lost revenue and subsequent increased IT spending every year.<\/p>\n

How security and DevOps can work together<\/h2>\n

It is widely accepted from most DevOps teams that having the ability to detect and amend security issues at an early stage of the software development lifecycle (SDLC) would streamline the process. However, turning this sentiment into a tangible reality is a significant challenge for many organisations.<\/p>\n

A recent report into the state of DevOps<\/a> found the best performing development teams spend half the time correcting security issues when they take security head on all the way through the SLDC. Indeed, it is when security is left to the final hurdle that long delays and wider issues typically emerge.<\/p>\n

The benefits of automation<\/h2>\n

In the age of the cyberbreach, in which two thirds of large UK businesses were hit by cyber breach or attack in past year,<\/a> there must be further consideration paid to cybersecurity at the app development stage \u2013 and automation should play a key role.<\/p>\n

Today, advanced technology enables development teams to deliver secure code at DevOps speed, by \u2013 for example \u2013 automating security into the SLDC and into a continuous integration (CI) or continuous deployment (CD) pipeline.<\/p>\n

Avoiding analogue coding in the digital age<\/h2>\n

By enabling developers to scan full applications or individual components as they write them, they can make improvements before sending the software for a formal policy or security review. This helps eliminate the \u2018scan and scold\u2019 dynamic that\u2019s existed in the past, where even scans of early versions of code directly shared results with security and risk teams.<\/p>\n

This can create the perception of software risk or compliance failures for the business well before the application is launched or the developer had a chance to make changes \u2013 often putting a halt on the potential for innovation and growth, and sustaining what has become an analogue approach in today\u2019s digital age.<\/p>\n

However, with the seamless integration of security into the development process, development teams are safer in the knowledge that testing is occurring throughout the entire process \u2013 ensuring that software is secure from its origin to when it goes to market. After all, the safeguarding of data is key to any positive user experience, and stronger collaboration between development and security will only enhance this prospect.<\/p>\n

 <\/p>\n

Edited for web by Cecilia Rehn<\/a>.<\/p>\n

 <\/p>\n","protected":false},"excerpt":{"rendered":"

Janet Worthington, Senior Product Manager, Veracode, explains why security and DevOps must collaborate to build a more secure future. Collaboration has been the key to successful IT development for over 10 years. The proliferation of open source software code, for example, has enabled the speedy development of millions of applications, fostering a culture of innovation…<\/p>\n","protected":false},"author":123458,"featured_media":8171,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","pmpro_default_level":"","footnotes":""},"categories":[2],"tags":[145,721,297,67,112,720,252],"yoast_head":"\nWhy developers must be enabled to build better code to defend against cyberattacks - DevOps Online North America<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why developers must be enabled to build better code to defend against cyberattacks - DevOps Online North America\" \/>\n<meta property=\"og:description\" content=\"Janet Worthington, Senior Product Manager, Veracode, explains why security and DevOps must collaborate to build a more secure future. Collaboration has been the key to successful IT development for over 10 years. The proliferation of open source software code, for example, has enabled the speedy development of millions of applications, fostering a culture of innovation...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/\" \/>\n<meta property=\"og:site_name\" content=\"DevOps Online North America\" \/>\n<meta property=\"article:published_time\" content=\"2016-08-17T10:46:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png\" \/>\n\t<meta property=\"og:image:width\" content=\"640\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Yashesh Patel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@DevOpsAmerica\" \/>\n<meta name=\"twitter:site\" content=\"@DevOpsAmerica\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Yashesh Patel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/\"},\"author\":{\"name\":\"Yashesh Patel\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435\"},\"headline\":\"Why developers must be enabled to build better code to defend against cyberattacks\",\"datePublished\":\"2016-08-17T10:46:53+00:00\",\"dateModified\":\"2016-08-17T10:46:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/\"},\"wordCount\":803,\"publisher\":{\"@id\":\"https:\/\/devopsnews.online\/#organization\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png\",\"keywords\":[\"automation\",\"cyberattack\",\"cybersecurity\",\"DevOps\",\"security\",\"speed to market\",\"Veracode\"],\"articleSection\":[\"Featured\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/\",\"url\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/\",\"name\":\"Why developers must be enabled to build better code to defend against cyberattacks - DevOps Online North America\",\"isPartOf\":{\"@id\":\"https:\/\/devopsnews.online\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png\",\"datePublished\":\"2016-08-17T10:46:53+00:00\",\"dateModified\":\"2016-08-17T10:46:53+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#primaryimage\",\"url\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png\",\"contentUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png\",\"width\":640,\"height\":400,\"caption\":\"DevOps security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/devopsnews.online\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Why developers must be enabled to build better code to defend against cyberattacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/devopsnews.online\/#website\",\"url\":\"https:\/\/devopsnews.online\/\",\"name\":\"DevOps Online North America\",\"description\":\"by 31 Media Ltd.\",\"publisher\":{\"@id\":\"https:\/\/devopsnews.online\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/devopsnews.online\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/devopsnews.online\/#organization\",\"name\":\"DevOps Online North America\",\"url\":\"https:\/\/devopsnews.online\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png\",\"contentUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png\",\"width\":198,\"height\":64,\"caption\":\"DevOps Online North America\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/DevOpsAmerica\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435\",\"name\":\"Yashesh Patel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g\",\"caption\":\"Yashesh Patel\"},\"sameAs\":[\"https:\/\/devopsnews.online\"],\"url\":\"https:\/\/devopsnews.online\/author\/yashesh-patel\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Why developers must be enabled to build better code to defend against cyberattacks - DevOps Online North America","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/","og_locale":"en_US","og_type":"article","og_title":"Why developers must be enabled to build better code to defend against cyberattacks - DevOps Online North America","og_description":"Janet Worthington, Senior Product Manager, Veracode, explains why security and DevOps must collaborate to build a more secure future. Collaboration has been the key to successful IT development for over 10 years. The proliferation of open source software code, for example, has enabled the speedy development of millions of applications, fostering a culture of innovation...","og_url":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/","og_site_name":"DevOps Online North America","article_published_time":"2016-08-17T10:46:53+00:00","og_image":[{"width":640,"height":400,"url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png","type":"image\/png"}],"author":"Yashesh Patel","twitter_card":"summary_large_image","twitter_creator":"@DevOpsAmerica","twitter_site":"@DevOpsAmerica","twitter_misc":{"Written by":"Yashesh Patel","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#article","isPartOf":{"@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/"},"author":{"name":"Yashesh Patel","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435"},"headline":"Why developers must be enabled to build better code to defend against cyberattacks","datePublished":"2016-08-17T10:46:53+00:00","dateModified":"2016-08-17T10:46:53+00:00","mainEntityOfPage":{"@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/"},"wordCount":803,"publisher":{"@id":"https:\/\/devopsnews.online\/#organization"},"image":{"@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#primaryimage"},"thumbnailUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png","keywords":["automation","cyberattack","cybersecurity","DevOps","security","speed to market","Veracode"],"articleSection":["Featured"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/","url":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/","name":"Why developers must be enabled to build better code to defend against cyberattacks - DevOps Online North America","isPartOf":{"@id":"https:\/\/devopsnews.online\/#website"},"primaryImageOfPage":{"@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#primaryimage"},"image":{"@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#primaryimage"},"thumbnailUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png","datePublished":"2016-08-17T10:46:53+00:00","dateModified":"2016-08-17T10:46:53+00:00","breadcrumb":{"@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#primaryimage","url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png","contentUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2016\/08\/devops-security.png","width":640,"height":400,"caption":"DevOps security"},{"@type":"BreadcrumbList","@id":"https:\/\/devopsnews.online\/why-developers-must-be-enabled-to-build-better-code-to-defend-against-cyberattacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/devopsnews.online\/"},{"@type":"ListItem","position":2,"name":"Why developers must be enabled to build better code to defend against cyberattacks"}]},{"@type":"WebSite","@id":"https:\/\/devopsnews.online\/#website","url":"https:\/\/devopsnews.online\/","name":"DevOps Online North America","description":"by 31 Media Ltd.","publisher":{"@id":"https:\/\/devopsnews.online\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/devopsnews.online\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/devopsnews.online\/#organization","name":"DevOps Online North America","url":"https:\/\/devopsnews.online\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/","url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png","contentUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png","width":198,"height":64,"caption":"DevOps Online North America"},"image":{"@id":"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/DevOpsAmerica"]},{"@type":"Person","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435","name":"Yashesh Patel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g","caption":"Yashesh Patel"},"sameAs":["https:\/\/devopsnews.online"],"url":"https:\/\/devopsnews.online\/author\/yashesh-patel\/"}]}},"_links":{"self":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/8170"}],"collection":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/users\/123458"}],"replies":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/comments?post=8170"}],"version-history":[{"count":0,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/8170\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/media\/8171"}],"wp:attachment":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/media?parent=8170"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/categories?post=8170"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/tags?post=8170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}