Opens in a new tab
vmblog logo 2024 wht (updated)

Does your operations infrastructure support your security goals?

Share: 

operational infrastructure

By Jamie Dicken, Senior Director of Security Platforms and Architecture at GitLab

For software companies, security is central to software quality. That makes security excellence a competitive advantage. But narrowing the gap between security goals and operational reality is harder than it looks.

In many cases, organizations encounter a common scenario: You just approved the purchase of an AI security tool that automatically detects and triages vulnerabilities during production. It perfectly complements your vision for advanced security with comprehensive CI/CD automation, mature platform engineering, and sophisticated security orchestration.

Then, onboarding reveals a messier picture. Your security stack doesn’t align with how your engineering counterparts operate, and existing legacy systems generate manual work for teams that must toggle between different tools to fill gaps and check alerts. As a result, any efficiency gains the new tool offered are often lost.

If this sounds familiar, you’re not alone. This challenge is common across many enterprise software factories. For large software producers navigating high operational complexity, well-intentioned additions to a security program can introduce even more complexity, creating unexpected problems. Security shifts from an enabler to a bottleneck.

Security excellence requires operational maturity

To scale security operations effectively, you first need a clear picture of the processes already underpinning your organization’s security. Operational maturity varies across organizations, but three indicators signal readiness to implement more advanced security capabilities.

  1. Modern architecture. Mature organizations use platforms that make meeting security standards easier. Modernizing architecture with cloud-native solutions simplifies updates and maintenance, unlike legacy systems weighed down by technical debt and complexity.
  2. Automated, well-documented deployment processes. Mature teams automate pipelines and use API-driven operations to eliminate busy work and scale their security programs. They also document their processes and collaborate closely with infrastructure and reliability teams to maintain sophisticated monitoring and visibility across all systems. Less mature organizations often depend on manual processes and institutional knowledge. This dependence makes it nearly impossible to replicate workflows and engage in cross-functional collaboration efficiently.
  3. A proactive, flexible security culture. Culture can simplify or complicate how your organization responds when problems arise during implementation. A culture that promotes blameless post-mortems and proactivity helps teams evaluate mistakes and implementation gaps, reducing the likelihood of future problems. Teams locked in reactive cycles within their existing workflows may struggle as their security programs grow.

Progress depends on building efficiency and reducing technical debt, without relying on linear scaling. Organizations on the mature end of these indicators will find it easier to scale their security programs.

Build a solid foundation before expanding your program

If your organization has yet to achieve these maturity indicators, prioritize strengthening your existing operational engineering foundations before adding more advanced capabilities.

Hybrid security approaches tend to work best during this transition. As you modernize CI/CD pipelines, strangler-fig solutions gradually bridge legacy systems and modern platforms, helping you maintain security coverage while incrementally modernizing tooling and processes. This approach lets your security program continue growing while preserving software velocity.

Avoid setting aggressive transformation timelines or overloading teams. Simultaneous re-platforming and process overhauls can cause widespread disruption and slow the pace and effectiveness of both initiatives.

Time is your most important investment. Organizations managing both high complexity and significant modernization efforts should expect this process to take up to 48 months. While shorter timelines are possible, rushing the process may risk failed implementation and place unrealistic demands on teams. Inform leadership of the multi-year timeline and flag anticipated milestones along the way.

A roadmap toward increasing operational readiness could follow these phases:

Phase 1 Stabilize and Plan: Assess the current state of your software security operations and identify transformation requirements. Begin building a hybrid security architecture that supports legacy and modern systems and establish a transformation roadmap with milestones and success metrics.

Phase 2 Foundation Building: Work to reduce technical debt and begin deploying hybrid models that launch modern platforms alongside legacy systems. Pilot automated capabilities in high-value areas of your program that already demonstrate ROI and incorporate cultural initiatives that reduce organizational resistance and build momentum.

Phase 3 Acceleration: Continue transformation momentum. Assess progress on legacy system migration and modernization efforts, and ensure that emerging platform capabilities enable self-service.

Phase 4 Optimization: Measure how your program improves efficiency relative to your baseline. Confirm the status of legacy constraints and evaluate how further security automation can accelerate business velocity.

Every organization’s path through these phases will look different.

Operational maturity strengthens security investments

Real business value begins with solid operational foundations. Organizations constrained by legacy systems, technical debt, and manual processes will face significant challenges achieving security excellence, no matter how much they invest in tooling. Operational maturity shapes whether a new solution becomes a productivity driver or costly shelfware.

Organizations that get their software security tools and processes right first will find that their investments in advanced security capabilities deliver the transformational value and competitive differentiation those tools promise.

##

ABOUT THE AUTHOR

jamie dicken of gitlab

Jamie Dicken is the Senior Director of Security Platforms and Architecture at GitLab, leading Security Architecture, Security Research, and AppSec. Her expertise spans product security, AppSec, DevSecOps, security tooling and automation, and GRC.

Before transitioning into cybersecurity, she spent 8 years as a software engineer and technical manager at two Fortune 15 healthcare companies. Now she focuses on protecting systems like the ones she used to build and transforming how engineering teams and security professionals work together.

Jamie is passionate about leading high-performing teams, executing strategic initiatives, and mentoring others. Outside of work, she enjoys adventures with her two boys and husband, crafting, and spending time outdoors.