VOOZH about

URL: https://thenewstack.io/keeping-up-with-the-hare-establishing-a-devsec-culture/

⇱ Keeping up with the Hare: Establishing a DevSec Culture - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2021-06-02 12:00:16
Keeping up with the Hare: Establishing a DevSec Culture
contributed,sponsor-checkpoint,sponsored,sponsored-post-contributed,
DevOps / Security

Keeping up with the Hare: Establishing a DevSec Culture

Organizations must figure out how to work with developers and the DevOps automation culture to deliver secure, continuous release cycles – and quickly.
Jun 2nd, 2021 12:00pm by Hillel Solow
👁 Featued image for: Keeping up with the Hare: Establishing a DevSec Culture
Featured image via Pixabay.
Check Point sponsored this post.
Hillel Solow
Hillel is a cloud security architect and evangelist at Check Point Software Technologies.

Speed is the primary goal of modern application developers. However, with speed comes complexity. Organizations have no choice but to tackle security challenges. In fact, the time difference today between when code is written and when it runs is shortening. Nearly 60% of companies report deploying multiple times a day, once a day or once every few days. Furthermore, the scope of the threat landscape is accelerating as cloud adoption accelerates, making security a challenge for DevSec.

Organizations are now faced with how to effectively integrate security. This is where you need security at the speed of development.

How to Move Faster: Security, Automation and Optimization

Application developers move fast and may make mistakes, but those can be resolved within the next release cycle. Security teams don’t have the same luxury. They’re faced with the pressure to always be right while also not hindering developers.

This means that organizations must figure out how to work with developers and the DevOps automation culture to still deliver secure, continuous-release cycles — and quickly. With security automation, everywhere is key. Automation is critical.

With developers releasing updates so quickly, they are also distributing risks immediately, which means security must be plugged into development toolchains that automatically enable posture checks and protections without slowing things down. This is the only way to ensure rapid remediation and reduce risks.

Take steps to remove friction. In addition, remediation steps must be automated whether to fix issues or streamline security processes. Enable developers to do their jobs securely without adding work. Consider providing tools to automate tasks, such as generating permissions for serverless functions.

It’s important to note that even with enhanced automation, security analysts must continue to stay diligent. A study of 1,027 US and UK IT and IT security practitioners conducted by the Ponemon Institute reveals that “74% of respondents say automation is not capable of performing certain tasks that the IT security staff can do and 54% of respondents say automation will never replace human intuition and hands-on experience.”

Automation should be seen as an evolution that will allow security teams to focus on more strategic projects. A recent post on Dark Reading shared five tips for you to hone your skills to stay well ahead of the automation curve and evolve your role.

Check Point Software Technologies is a leading provider of cyber security and threat prevention. Check Point CloudGuard provides unified cloud native security for networks, assets and workloads — automating cloud security, preventing threats, and managing posture — across multicloud environments.
Learn More
The latest from Check Point

Building on DevSecOps

In order to optimize modern application security, DevSecOps best practices and team dynamics need to evolve with automation.

Nigel Kersten, Puppet’s field chief technology officer, stressed the importance of deploying automation at scale in DevSecOps practices. “There are a few common errors we see that enterprises are facing, the biggest one is trying to implement DevSecOps without scaled automation that is well understood and trusted by all the relevant stakeholders.” Kersten continued, “Without that, organizations will end up with the same manual processes and the same conflicting incentives. Then, instead of DevSecOps, these businesses are left with just Dev, Sec and Ops.”

Gina Smith, research manager at IDC Asia, stated, “Old security processes that put security at the middle or end of the process are just too expensive and inefficient now.” Smith continued, “Building security planning, testing and monitoring into every phase of the DevOps pipeline is about bridging the age-old division — and enmity — among developers, IT and security.”

Having cloud native security solutions that are tightly integrated with a development and operations process and tools will be key in helping move toward a more DevSecOps operating environment.

When done effectively, this combination is a true win for security. The 2020 State of Pentesting report examined which security vulnerabilities are found reliably using machines versus human expertise. “The study found that both humans and machines bring value when it comes to finding specific classes of vulnerabilities. Humans ‘win’ at finding business logic bypasses, race conditions and chained exploits, according to the report.”

The truth is organizations of the future will require teams and technology to be working in unison.

Cloud with Confidence

Organizations need to evolve automation tools and the manner in which teams operate to address the unique security needs of modern cloud applications. Automation tools need to be integrated early into the development cycles to address security and compliance issues prior to deployment, with the ability to automate runtime security assessments to prevent threats. This will not only improve security but also development cycles.

To learn more about cloud native security automation through Check Point Cloud Guard, read the Check Point ebook Re-Imagine: A Guide to Unified and Automated Cloud-Native Security.

Check Point Software Technologies is a leading provider of cyber security and threat prevention. Check Point CloudGuard provides unified cloud native security for networks, assets and workloads — automating cloud security, preventing threats, and managing posture — across multicloud environments.
Learn More
The latest from Check Point
TRENDING STORIES
Hillel is a cloud security architect and evangelist at Check Point Software Technologies.
Read more from Hillel Solow
Check Point sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma, Enable.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.