Opens in a new tab
vmblog logo 2024 wht (updated)

StackHawk 2023 Predictions: Shifting Left in 2023 – Giving Security Control to Developers

Share: 

David Marshall | Published: January 18, 2023

vmblog-predictions-2023 

Industry executives and experts share their predictions for 2023.  Read them in this 15th annual VMblog.com series exclusive.

Shifting Left in 2023: Giving Security Control to Developers

By Scott Gerlach, Co-founder and Chief Security Officer at StackHawk

As software is being built and released more rapidly and security breaches continue to increase in frequency and severity, companies are making more serious overtures to shift their security strategies left and take a proactive approach by giving more control to the developer teams. In 2023, we expect to see more organizations adopt a DevOps philosophy for application security with developers getting involved in identifying and resolving vulnerabilities as part of the software development process.  

Developers will be empowered to find and fix security vulnerabilities  

Developers are the key to fixing application vulnerabilities, yet they have been disconnected from the security process until a fix is needed. This is something we can expect to change in 2023. Developers are growing tired of disruptive fix cycles that occur after code is in production and they’ve lost the context of a project. They will feel more empowered to take control of finding and fixing security vulnerabilities throughout the development lifecycle and request tools that align with their standard workflows.  

Customers will increasingly demand developer-facing application security 

Because security teams and legacy tooling cannot keep up with the rapid pace of continuous software delivery, customers are beginning to demand solutions that enable their developers to address security issues within the software development lifecycle. Giving developers the power to resolve vulnerabilities within their workflows allows organizations to address issues more efficiently before they make it to production and become difficult and expensive to resolve. This will require teams to adopt security tools that can be automated in CI/CD pipelines and coincide with code reviews and other automated software tests. 

Increasing demand for cloud-native solutions 

Similarly, legacy industry players are beginning to recognize the demand for cloud-native security solutions. In response, they will either make these solutions available for their customers or make moves to acquire these solutions to add to their portfolios.  
 
Because security breaches have become more of an inevitability than a distant what-if, developer teams are steeling themselves for future attacks and working to find ways to stop vulnerabilities before they become larger issues. Shifting left is a natural next step to achieve this, as developers can identify vulnerabilities before they reach production or deployment and therefore become larger problems. In recognition of this, we expect that the legacy players in the industry will make more concerted efforts, like acquisitions, to help their customers shift left. 

Increased reliance on APIs 

As organizations come to rely more on APIs to increase their development speed, they will also see a rise in specific API-targeted attacks. This should come as no surprise: all the sensitive data a hacker would want to access is stored and centralized in the API that an application’s front end and other integrations interact with. 

The spotlight on API attacks should serve as a wake-up call to organizations regarding the current gap in protection, with many security teams still getting it wrong by focusing on production monitoring as the sole means of API security. CISOs need to move to a more holistic approach, which includes proactive security testing, in order to close the gap as software is being increasingly built API first. That means bringing developer-first tools that enable teams to find and fix API security issues early in the development lifecycle to the front line and shifting production monitoring to a secondary line of defense. 

Overall, we should expect to see a more proactive and developer-led approach to resolving security vulnerabilities during the software development lifecycle, while easing some of the pressure on security teams and preventing issues from reaching production. 

## 

ABOUT THE AUTHOR

Scott-Gerlach 

Scott Gerlach is Co-founder and Chief Security Officer at StackHawk, a Denver-based startup making application security testing part of software delivery. Scott brings over two decades of security and engineering experience to his current role, having served as CSO, CISO, and in other executive leadership functions at companies like SendGrid, and GoDaddy.