• About
  • Subscribe
  • Contact
Wednesday, May 7, 2025
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Technology

Collaboration and culture: keys to DevSecOps success

Prashanth Nanjundappa by Prashanth Nanjundappa
March 23, 2023
Photo by RODNAE Productions: https://www.pexels.com/photo/group-of-people-wearing-shirts-spelled-team-7551442/

Photo by RODNAE Productions: https://www.pexels.com/photo/group-of-people-wearing-shirts-spelled-team-7551442/

Across the Asia Pacific region, cyber threats have continued to plague organisations big and small, disrupting operations and exposing sensitive info to malicious actions.

For developers, too, security is crucial as cyber threats can cause applications to malfunction, making it harder for customers to have their needs met and for employees to conduct their work. As a result, businesses will have to direct more focus on resolving issues and dealing with legal repercussions, leaving them no time and resources to improve their service offerings.

Aligning security with the software development lifecycle (SDLC), then, is the key to delivering fortified apps that fulfil end-user expectations. However, our recent Progress survey, DevSecOps: Simplifying Complexity in a Changing World, shows that 51% of organisations are only somewhat familiar with how security fits into DevSecOps.

DevSecOps success depends on culture and collaboration

Simply put, successful DevSecOps adoption requires developers and security teams to deliver high-quality services in a short amount of time without compromising security and compliance.

During this process, communication plays a key role in striking a balance between those two aspects. Often, however, there are barriers that can hinder the collaboration between the two teams. For example, if they operate with different functions, processes, and tools, this can hamper their ability to communicate inputs and determine the best courses of action. When asked about the state of collaboration between their developers and security staff, only 30% of organisations said they are confident.

Aligning both teams' operations requires the use of infrastructure as code (IaC), which supports a uniform application deployment process. By executing a single script, users will be able to automate the development of services and functions as part of the continuous integration/continuous delivery (CI/CD) pipeline. This allows organisations to reduce operational costs, enable faster time-to-market and minimise errors brought on by manual processes.

Organisational culture might also pose another challenge as both teams need to depend on one another to enable cybersecurity in product development.

For example, developers need to allow security teams to actively participate in incorporating security tools and practices in the SDLC process while security teams need to communicate the business risks of having a weak posture to developers so that they are aware of the responsibilities they have in ensuring a positive user experience. Our survey echoes this with 71% of organisations agreeing that culture is the biggest barrier to successful DevSecOps progress.

During the proof-of-concept stage of the SDLC process, both teams must review their security configurations to determine what changes need to be made before the software is deployed for use. This will enable security gaps to be plugged in and end-users to receive consistent coverage, which will boost the business' competitiveness and regulatory compliance.

Cybersecurity comes from the top

A security-first mindset provides a critical foundation for building secured apps. The best way of building this mindset is through training and upskilling programs that can transform developers into cybersecurity experts.

Most organisations are aware of this as 61% of them are looking to increase investment in continuous learning for developers and engineers. With training modules and courses centred around cloud and Kubernetes frameworks, developers will be able to effectively reinforce their operations from threat actors.

These programs should be combined with application experience (AX) platforms that allow businesses to optimise their services while enabling security features. Integrating this platform can give DevSecOps teams full visibility of their network traffic as well as early insights into malicious behaviour. Through analysis algorithms, AX platforms can also apply effective responses, such as secondary authentication measures and prevention of access.

Apart from focusing on technology and training, leaders also need to work with security teams in drawing up and enforcing security policies. This means clearly defining roles and procedures so that developers know what they must do to align their operations with cybersecurity.

Successful DevSecOps comes from developers working together with security teams to

integrate a security-first approach to application development. This is crucial — especially as organisations accelerate the creation of new services — in safeguarding users while ensuring that their services remain operational or can be recovered. Moreover, it can also build digital trust, which will encourage more customers to do business and push organisations ahead of the rest.

Related:  IDC: AI uses cases in APAC remain isolated projects
Tags: culture and collaborationDevSecOpsIoCProgresssoftware development life cycle
Prashanth Nanjundappa

Prashanth Nanjundappa

Prashanth Nanjundappa is VP of product management at Progress. He has spent his entire career of over 20 years in the tech world, managing cross-functional high-performance teams, focused on building, and launching enterprise and consumer products globally. In the first 12 years of his career, Prashanth worked as a developer, technical lead, and architect for mobile, video-broadcast and OTT, SaaS and PaaS products. Prior to joining Progress, he led the product management teams for high-tech B2B and enterprise products at companies like Cisco and Knowlarity. He has spent time working in Italy, France, and South Korea. Prashanth has an engineering degree in Electronics & Communication from Bangalore University and an MBA from the Indian School of Business (ISB) Hyderabad.

No Result
View All Result

Recent Posts

  • Agentic AI-powered AppSec platform launched for the AI era
  • IDC forecasts GenAI alone will grow at a 59.2% CAGR
  • Dataiku brings new AI capabilities to create and control AI agents
  • Microsoft reveals the rise of a new kind of organisation in the AI era
  • St Luke’s ElderCare enhances data security and user experience with Juniper

Live Poll

Categories

  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CISO
  • CISO strategies
  • Cloud, Virtualization, Operating Environments and Middleware
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Education
  • Education
  • Finance
  • Finance & Insurance
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe