Opens in a new tab
vmblog logo 2024 wht (updated)

Bridgecrew by Prisma Cloud 2022 Predictions: DevSecOps will go beyond the hype

Share: 

David Marshall | Published: December 22, 2021

 

Industry executives and experts share their predictions for 2022.  Read them in this 14th annual VMblog.com series exclusive.

DevSecOps will go beyond the hype

By Guy Eisenkot, Bridgecrew Senior Director of Product Management, Palo Alto Networks

Although DevSecOps is undoubtedly not a new concept, a quick look at Google Trends shows that “DevSecOps” hit an all-time high in searches in 2021. In the past year, we’ve seen an influx of DevSecOps job postings-both dedicated DevSecOps practitioners as well as more DevSecOps-related responsibilities within security and engineering teams. On top of the well-documented security shortage, this new trend signals a major resourcing demand. To fill that gap, we’ve witnessed a rush of startups and established security companies coming to market with DevSecOps related offerings.

All of these indicators point to one thing-we are at peak DevSecOps hype. But in reality, after every tradeshow (in-person finally!) and meeting, we walk away with the same realization-the DevSecOps hype hasn’t yet turned into action for the majority of organizations. Of course, the digital-native and cloud-native organizations are ahead of the curve, but for the late and even early majority, DevSecOps has a long way to go.

We think (and hope) that 2022 will be the year it will move beyond the hype.

We expect to see organizations go from DevSecOps discovery to actually start to implement cultures, processes, and tools to bridge the gap between development, security, and ops.

So what impact will that have on existing security and development teams and for organizations as a whole?

From security teams, we expect to see more consultative rather than blocking approaches. After years of talking up automation, audits are still mostly manual. We think 2022 might actually be a year that security (and compliance) will embrace automation and work more closely with developers. Collaboration when creating and implementing proactive security strategies will be key to security’s DevSecOps success. The narrative that developers need to be more security-minded will also be flipped the other way around. We’ll start to see security teams become more fluent in the code they secure and educated about and hands-on with their software supply chains.

At the same time, developers will start to have more responsibility for security. Instead of just being security “champions,” developers will start to have more visible roles in building secure software. This is a huge part of making DevSecOps actionable. No matter how many guardrails or how much alerting security implements, developers will find a way around if their work is disrupted. Security will have to work with developers to strike the right balance.

By being more involved in security conversations, developers will dictate what tools are chosen. Where solutions already exist, they will be more vocal about how they’re implemented and may even start to hold legacy security tooling accountable for good developer experiences. As part of this shift, we also expect to see more engineering teams and individual contributors start to own KPIs beyond just lines of code or features released, but also how secure or security issue-free their software is.

In that same vein, DevSecOps’ impact will go beyond engineering and security teams as organizations leverage their proactive security approaches as business health metrics. We expect to see more data points related to secure coding practices-tied to breaches avoided-show up in annual and quarterly reports and even S-1 filings.

Lastly, we need to figure out the resourcing challenge for this prediction to have a real chance at reality. Tools are important, but having the right team to actually implement change is moreso. Although secure code training (across both application and infrastructure layers) will play a part in getting new and existing talent up to speed, we see this as being one of the most difficult barriers to mainstream DevSecOps adoption.

So what will all this amount to? We expect to see a decline in security breaches involving known vulnerabilities and misconfigurations. This will lead to a decline in breaches overall and the cost of breaches. We expect attackers will evolve to be more sophisticated, but this will at least slow them down significantly.

##

ABOUT THE AUTHOR

Guy Eisenkot 

Guy Eisenkot is the Bridgecrew Senior Director of Product Management at Palo Alto Networks. Prior to that he was a product manager at RSA Security.