VOOZH about

URL: https://thenewstack.io/4-reasons-to-shift-left-and-add-security-earlier-in-the-sdlc/

⇱ 4 Reasons to Shift Left and Add Security Earlier in the SDLC - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-05-25 06:50:23
4 Reasons to Shift Left and Add Security Earlier in the SDLC
contributed,sponsor-orca,sponsored,sponsored-post-contributed,
Cloud Native Ecosystem / Security

4 Reasons to Shift Left and Add Security Earlier in the SDLC

With the right cloud technology in place, development teams can securely build and test code for applications with the DevOps and security operations teams, and ultimately achieve faster runtimes with fewer security issues.
May 25th, 2022 6:50am by Keith Mokris
👁 Featued image for: 4 Reasons to Shift Left and Add Security Earlier in the SDLC
Featured image via Pixabay.
Orca sponsored this post.
Keith Mokris
Keith Mokris, VP of product marketing at Orca Security, is a cloud security expert with expertise in secure software development. Keith focuses on cloud security for cloud native and multicloud environments through integration of CNAPP technology.

Agility and flexibility are the hallmarks of a modern, cloud native tech stack that can handle complex digital transformation initiatives, from built to production.

As market forces reveal profitable opportunities in a post-pandemic society, improving the software development life cycle (SDLC) has become a focal point that companies are looking at closely, specifically to manage security risks in the CI/CD pipeline and post-production phases of the SDLC.

With the right cloud technology in place, organizations can enable their development teams to securely build and test code for applications with the DevOps and security operations teams and ultimately achieve faster runtimes with fewer security issues over time in production.

Secure Applications and Code as a Marketplace Differentiator

In 2020, 90% of reported breaches involved web applications as the top hacking vector. Consumers are getting caught in the crosshairs as their personally identifiable information (PII) is exposed in high-profile breaches and sold on the dark web. Shipping secure code faster to production means more revenue, less downtime and less chance of a security breach. User privacy and security are important to consumers, and businesses can market accordingly.

Threat actors adapting tactics, techniques and procedures to reach their objectives are moving at faster attack rates than ever, making it inadvisable to develop software without DevSecOps technology and DevOps processes and team in place. A strong DevOps foundation requires an investment in the team members, tools and organizational structure needed to see results in key performance indicators over time.

Agentless cloud security and compliance for AWS, Azure, Google Cloud, and Kubernetes – in a fraction of the time and operational costs of other solutions.
Learn More
The latest from Orca

Shifting Security Left in the CI/CD Pipeline

The CI/CD pipeline is a sequence of steps that any developer has to go through to deliver an efficient end product. Failure at any step triggers notifications to the responsible developers.

These are the three basic stages in the CI/CD pipeline:

Build Stage

This is the stage at which the code is taken from the source stage and is combined with its dependencies. It is then compiled to deploy the final application on the production server. Container images and IaC templates are scanned on the developer desktop or as part of regular, CI/CD workflows. Automated tests are executed to validate the code’s authenticity and the quality of the final product before it is deployed on the production server.

Deploy Stage

Registries are continually monitored to ensure application images are secure before deployment, with guardrail policies in place to prevent insecure deployments. Once the source code has passed all the tests and no flaws or bugs are seen, it is then deployed in various environments, like staging and production.

Run Stage

Production environments are monitored for risks with contextual alerts and risk prioritization, as well as integrations with ticketing and notification tools. The CI/CD pipeline imposes strict regulations to protect PII. PII security compliance is a requirement and a priority.

The implementation of CI/CD in the DevOps pipeline enables developers to easily identify the defects and other software/application quality issues that need to be resolved without breaking the code. When shift-left security is added to the next layer in the software development life cycle, the CI/CD pipeline can be strengthened even further. Shift-left security applies DevSecOps principles and tooling automation as a dynamic integration to enforce security in the built-test-run life cycle.

Organizations can gain four distinct advantages when shift-left capabilities are integrated into the CI/CD pipeline:

  • Increase the security posture of applications

The right cloud platform can scan container images, and in IaC templates, help identify vulnerabilities or misconfigurations across the entire development lifecycle. Look for cloud security capabilities that provide shift-left scanning results with insights into the production environment for the security operations team, which can work with DevOps and development teams quickly if potential attack paths are combined with existing risks.

  • Prevent of security risks early in the SDLC

By detecting issues early on, code issues are easier and less costly to fix. When code is in production and critical issues arise, the costs to fix not only impacts teams, it also impacts revenue.

  • Deploy applications to production faster

When security is integrated early and often into the CI/CD pipeline, organizations can identify flaws early, rather than in production. This prevents security from being “bolted on” at the end of the development process, when applications can be delayed if major security flaws are found that cannot be easily fixed.

  • Improve security outcomes by reducing workflow friction

Unplanned work negatively impacts the security team and can lead to alert fatigue. By integrating security into the CI/CD process and empowering developers and DevOps to own the scanning process themselves while using the same platform as the security team, teams improve collaboration, avoid friction and manage security risks proactively from development through runtime.

Shifting Security Left Unifies Development, DevOps and the SOC

Collaboration is critical for the security and development teams, especially when timelines have to change. The security operations center (SOC) team may need to train on cloud technologies and capabilities, while the cloud team may need help understanding how the organization performs risk management.

Understanding the roles and responsibilities of these teams and the security functions each fulfill is critical to managing security risks. In some scenarios, security teams can act as enablers for cloud engineering, teaching teams how to be self-sufficient in performing threat-modeling exercises. In other situations, security teams can act as escalation paths during security incidents. Last, security teams can also own and operate underlying platforms or libraries that provide contextual value to more stream-oriented cloud engineering teams, such as IAC scanning capabilities, shared libraries for authentication and monitoring, and support of workloads constructs, such as secure service meshes.

When looking at the technology opportunities, security leaders have more options than ever to choose the right investments to advance cloud security with purpose-built SDLC capabilities that provide visibility and context from development to runtime. These options can bring cross-functional teams together to unify workstreams, manage security risks and grow ROI.

Agentless cloud security and compliance for AWS, Azure, Google Cloud, and Kubernetes – in a fraction of the time and operational costs of other solutions.
Learn More
The latest from Orca
TRENDING STORIES
Keith Mokris, VP of product marketing at Orca Security, is a cloud security expert with expertise in secure software development. Keith focuses on cloud security for cloud native and multicloud environments through integration of CNAPP technology.
Read more from Keith Mokris
Orca sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.