VOOZH about

URL: https://thenewstack.io/pro-coders-key-to-stopping-citizen-developer-security-breach/

⇱ Pro Coders Key to Stopping Citizen Developer Security Breach - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2023-01-04 11:20:30
Pro Coders Key to Stopping Citizen Developer Security Breach
API Management / Frontend Development / Security

Pro Coders Key to Stopping Citizen Developer Security Breach

Research firm predicts this will be the year that citizen developers — empowered by low code/no code tools — create a major security breach.
Jan 4th, 2023 11:20am by Loraine Lawson
👁 Featued image for: Pro Coders Key to Stopping Citizen Developer Security Breach
Feature image via Shutterstock

Citizen development has been a buzzword since the emergence of low-code/no-code tooling, but adoption is just now reaching a significant scale. That’s led Forrester to predict this will be the year citizen development will create a headline-worthy security breach.

“Somebody who’s coming from the lines of business typically doesn’t have as much knowledge when it comes to security restraints and security controls, compliance, that sort of thing — but they do have a lot of interest in wanting to build out applications and systems,” said Forrester Research Director Chris Gardner. “Unfortunately, more developers and more apps equals a bigger attack surface area.”

Forty-five percent of organizations have adopted low code/no code, with 26% planning to do so in the next 12 months, Gardner said. In addition to citizen developers, 62% of developers are deploying with low-code/no-code solutions, he added.

While Forrester is predicting one major breach, Gardner said he wouldn’t be surprised if there’s more than one major breach, due to citizen developer environments often not having proper governance policies around them.

How Shell Shored Up Low-Code Security

The oil company Shell is an example of a company that does low code well, Gardner said. The research firm recently did a case study on what Shell calls its Do-It-Yourself (DIY) program. The company breaks out citizen apps into three categories: Green, yellow and red; with green being relatively low risk and red being high risk.

“Green applications are ones that are relatively low risk. If you build out the application, you’re expected to run it and manage it,” Gardner said. “Generally speaking, those are the applications that get stood up most rapidly.”

Yellow applications are where the creator needs to integrate with other systems, and those integrations might require an IT professional to configure, he added.

The red category allows a creator to build the apps but with guidance from IT in order to build it out. There may be integrations with core systems or dealing with systems that have sensitive data, he added.

“Without that green, yellow and red structure, you’re a lot more likely to have a breach; and most environments don’t have these landing zones set up that way for citizen developers,” Gardner said.

What Developers Can Do to Bolster Security

IT should review the roles and access given to citizens developers and create something similar to the Shell governance approach, he said.

Professional developers have a role to play in addressing the security threats citizen developers may create, he said.

“We don’t expect them [developers] to run into this problem as much, because they’re usually well-versed in security and data sensitivity, but they are going to be working alongside folks that don’t necessarily have that educational background,” Gardner said. “It’s going to be critical for them to teach the folks that are learning how to build out these applications in the business.”

Developer involvement will be particularly key when dealing when integration is involved.

“Those folks are going to be involved when you start getting into those higher categories of applications, the yellow and red, where you’re integrating with core systems and systems that have been managing critical systems of record for years, if not decades,” Gardner told The New Stack. “Those developers are going to be highly involved in making those connections and making sure that things get locked down properly.”

API Strategy Falls to Business Rather than IT

Another Forrester prediction that may directly impact developers is their forecast that enterprise business leaders, not IT, will direct more than 40% of the API strategies. That goes against conventional wisdom that IT drives the API strategy, Gardner noted.

“APIs have transcended from being just pure application or infrastructure APIs. There [are] now business APIs, there [are] ones that take advantage of data and take advantage of transactions, and essentially, enable the data economy,” he said “It’s not an IT conversation anymore. IT will make sure it stays secured and locked down and make sure that it’s tightly woven with everything else, but the business leader decides which ones are the most beneficial.”

API strategy is even becoming a board-level topic, as board members and C-level leaders have grasped that APIs can be a central part of the business strategy, he said. That makes sense because the greatest value of APIs comes when organizations use them to create new products, business models, and channels, according to Forrester. This means that leadership in the enterprise business organization should govern API strategy, the research firm said in its predictions.

API Shift Is Significant Change for Developers

Still, it’s a significant change for developers, Gardner added, since valuable information about how APIs are managed will now be coming from the business rather than just IT. IT will still oversee APIs that contain various layers, as well as interface and integration APIs, but increasingly developers will field API requests from business leaders.

“They’re going to start getting requests from the business saying […] ‘Build me that data API that I wanted, build me that transaction API that I wanted,’ and developers are going to be tasked to build those various pieces alongside the APIs that they’re working on,” he said.

Developers will also need to hook into Infrastructure as Code APIs to build out modern, cloud native applications, he said.

“For the developer, this doesn’t change the fact that they’re building out their own APIs for purposes of application connectivity and infrastructure connectivity,” he said. “It does mean that they’re going to start building out APIs for business connectivity — and that’s going to be critical.”

TRENDING STORIES
Loraine Lawson is a veteran technology reporter who has covered technology issues from data integration to security for 25 years. Before joining The New Stack, she served as the editor of the banking technology site Bank Automation News. She has...
Read more from Loraine Lawson
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.