Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By Ayal Cohen, OpenText
Director of Product Management, Functional Testing Portfolio
The development world is at a crossroads.
Organizations must decide if they will continue to go down the traditional
DevOps and SecOps path in which the two groups work in silos. The other choice
is to take the road less traveled – a route that embraces AI-powered DevSecOps.
First, what is DevSecOps? It is the integration of Developer Operations (DevOps),
Security Operations (SecOps) and IT Operations (ITOps). Basically, it enmeshes
security testing and practices into all points of the software development and
delivery life cycle instead of at the end, unifying it into a one coherent
process from planning to testing to post-deployment activities. When AI is
implemented into the equation, it opens the door further to several benefits.
Here are our predictions for DevSecOps and AI for 2025:
AI-powered DevSecOps’ shift-left approach changes
development and testing as we know it
During the upcoming year, an integrated AI-powered DevSecOps
pipeline will be adopted by more companies. Those who make the shift will
discover the advantage of breaking down the silos between development, quality
and security teams. Enhanced efficiency is realized in the process due to the
reduction of redundant activities, freeing up skilled engineers to do more
complex and new development tasks. Also, it produces more reliable software
with automated testing and security checks taking place earlier in process
versus at the end. Afterall, the unification of DevOps, SecOps and ITOps makes
sense in the technology world as everything is becoming interconnected and the
reliance on the cloud is more prominent.
Companies realize DevSecOps reduces technical debt
Technical debt is a significant issue that is often out of mind
until the debt comes due. Among the reasons technical debt accumulates is
because development teams sometimes skip testing steps in a rush to meet
deadlines, leading to the need to fix problems or recode at a later date. As
DevSecOps becomes a more prevalent practice, more development teams will
discover when properly implemented it reduces the amount of technical debt.
There are several reasons for this. One is DevSecOps identifies technical debt
by utilizing automated testing, especially if it is powered by AI. A second
reason is AI-fuelled DevSecOps practices provide insight and incentive to
prioritize the forms of technical debt to address first, including both DevOps
and SecOps issues. Finally, DevSecOps changes the culture from a
business-as-usual mindset to a proactive one in which there is constant
improvement. It is predicted that more companies will more rapidly adopt
DevSecOps due to its inherent ability to reduce technical debt, a benefit that
is not limited to just security.
Companies to take offensive in
cybersecurity
With
the ability to discover security vulnerabilities earlier in the development
process, those companies that have instituted an AI-powered DevSecOps program
will be able to take a more proactive mindset. The use of AI allows predictive
analytics to find potential weakness and threats early and deploy fixes and
countermeasures before an attack occurs. It allows companies to anticipate
which type of attacks will occur. And when an attack does occur, AI can be used
to respond extremely fast and adjust on the fly in response to changes in the
attack.
Cybersecurity battles to become machine
versus machine
While AI is a valuable tool for
companies to detect security vulnerabilities in their software and systems, it
is unfortunately an asset for cybercriminals in seeking out attack targets and
determining the types of attacks. The use of AI by bad actors will explode,
delivering more powerful attacks. How can attackers do this? Just like with
companies who look for issues in their own systems, cyber attackers will use AI
to find these same issues. Compounding the problem is that AI-powered attacks
are extremely difficult to detect since algorithms over time adapt to defences.
AI is also used in multiple forms of attack, such sending personalized emails,
creating realistic (deepfake) videos or audio recordings, reverse engineering
(model stealing), and data poisoning to compromise security system
performance. The bottom line is that AI-powered threats make the cyber
world more dangerous than ever before. Because of this, a number for companies
will find it necessary to turn to AI – either by itself or as part of a
DevSecOps program – to combat the advanced threats. Ultimately, the use of AI
by bad actors will force companies to step up their security efforts to stay
ahead of the threats.
These
four predictions feed into one overarching prognostication: Companies and
organizations already using DevSecOps will enhance their activities, and the
number of companies adopting DevSecOps will accelerate in the coming months. It
is also believed AI will be increasingly utilized in DevSecOps movement. The
predictions above will be drivers in this shift. One other benefit to the
adoption of DevSecOps and AI is that companies will have the ability to
increase innovation due to unshackling resources from redundant and simple
tasks. Those companies who resist implementing DevSecOps run the risk of
falling behind.
##
ABOUT THE AUTHOR
Ayal currently serves as Director of
Product Management, Functional Testing Portfolio at OpenText DevOps Cloud
solutions. His primary focus is managing the Functional Testing line of
business, driving portfolio strategy, investment decisions and AI/ML technology
vision. During his 20-plus year career, he also has amassed extensive
experience in cloud delivery, enterprise Agile, and DevOps, with a strong focus
on aligning product vision with corporate goals to achieve sustainable
competitive advantage.






