VOOZH about

URL: https://thenewstack.io/address-the-communication-gap-between-dev-and-security-teams/

⇱ Address the Communication Gap Between Dev and Security Teams - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2021-12-16 08:52:53
Address the Communication Gap Between Dev and Security Teams
contributed,sponsor-rezilion,sponsored,sponsored-post-contributed,
DevOps / Security / Software Development

Address the Communication Gap Between Dev and Security Teams

If security and development teams are working independently of one another, it could lead to product security problems.
Dec 16th, 2021 8:52am by Joan Goodchild
👁 Featued image for: Address the Communication Gap Between Dev and Security Teams
Photo by cottonbro from Pexels.
Rezilion sponsored this post.
Joan Goodchild
Joan heads the content efforts for Rezilion. She has worked on security content for more than a decade, has written for Dark Reading and Security Boulevard, and previously served as editor-in-chief for CSO Online.

As many organizations probably already know, development and security teams have a communication problem. Often they are communicating poorly, or not at all. This presents a big problem for any organization looking to succeed with DevSecOps and deliver secure applications.

If security and development teams are working independently of one another — or even worse, at odds with one another — that could lead to significant problems with regard to product security.

A report by research firm Ponemon Institute in 2020 noted that organizations are at risk when application security and development don’t have a common vision for delivering the software capabilities the organization needs in a secure manner.

There must be a fundamental agreement that security is integrated throughout the application development process. As businesses push developers to build and deliver code on a continual basis and at a rapid rate, the perception of security as a hindrance emerges, the report noted.

Cultural Divide

As part of the research, Ponemon Institute surveyed 581 security practitioners who are involved in and knowledgeable about their organization’s application security activities, and 549 who are involved in and knowledgeable about their organization’s software application development process. Seventy-seven percent of developer respondents said the cultural divide affects their ability to meet deadlines, while 70% of the security respondents said the divide is putting the security of applications at risk.

A large majority of the security respondents said that the state of security is undermined by developers, who don’t care about the need to secure applications early in the software development lifecycle.

It’s clear that the two factions do not always have the same goals for success. Developers are looking to create innovative software products quickly, leveraging automation to speed up processes as much as possible. The security of the finished products is not typically uppermost in their minds.

The security team, on the other hand, wants to ensure that code is secure and as devoid of vulnerabilities as possible. This can help ensure that the final software offering is safe to use, but this can also slow the pace of development.

These and other differences can create lots of friction, which in turn can lead to turf battles, lack of cohesiveness and even lower-quality products. Given this scenario, organizations need to make sure that the teams take steps to break down any barriers that exist and learn to understand each other better.

Find Common Ground

One good practice is to find common ground between the two areas. Discovering and fixing vulnerabilities — or preventing them in the first place — should be the shared responsibility of both the security and development teams.

After all, good quality software should arrive in production or on the market with as few vulnerabilities as possible. It’s in the best interest of both teams to see that it does. Once they fully realize this commonality, they need to collaborate to determine the best ways to address vulnerabilities.

Just getting together to resolve security/development issues, in fact, can help bolster relationships. If members of the two teams meet on a regular basis, they might tend to develop greater empathy for each other and learn to be more flexible. They might come to realize that they’re working toward a common goal and seek ways to cooperate more.

Deploying DevSecOps and leveraging DevSecOps automation can play a major role in fostering teamwork among developers and security professionals. The idea of bringing products to market not only quickly, but securely as well, should appeal to both groups.

Rezilion is an autonomous cloud workload protection platform that requires no manual configuration and automatically returns any compromised service to a known-good state, thus enabling DevOps to continuously deploy without risk and eliminating friction between developers and security practitioners.
Learn More

Leadership Must Step Up

Another key to success is having senior-level executive support for initiatives that bring security and development teams together. CISOs would be a natural choice to lead the efforts, given their overall responsibilities for ensuring all aspects of cybersecurity and their involvement in DevSecOps. But CIOs, COOs or other senior executives, could also lend support to such efforts.

As the Ponemon Institute noted, senior leadership must create an environment that encourages teamwork, collaboration and accountability. Most organizations are not actively taking steps to encourage security and development to work more effectively as a team, it said. Only 36% of security respondents and 45% of developer respondents think their organizations’ senior leadership is aware of this problem.

That has to change, and leaders need to grasp the importance of having security and development teams work as a cohesive, harmonious unit. With so many organizations advancing their digital transformation efforts and introducing new online services, it’s more important than ever that these two factions not only get along, but excel through effective collaboration.

Rezilion is an autonomous cloud workload protection platform that requires no manual configuration and automatically returns any compromised service to a known-good state, thus enabling DevOps to continuously deploy without risk and eliminating friction between developers and security practitioners.
Learn More
TRENDING STORIES
Joan heads the content efforts for Rezilion. She has worked on security content for more than a decade, has written for Dark Reading and Security Boulevard, and previously served as editor-in-chief for CSO Online.
Read more from Joan Goodchild
Rezilion sponsored this post.
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.