VOOZH about

URL: https://thenewstack.io/upskilling-developers-to-meet-todays-security-challenges/

⇱ Upskilling Developers to Meet Today's Security Challenges - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2021-10-06 08:44:31
Upskilling Developers to Meet Today's Security Challenges
contributed,sponsor-cncf,sponsored,sponsored-post-contributed,
DevOps / Security / Software Development

Upskilling Developers to Meet Today’s Security Challenges

JFrog’s Yoav Landman and Moran Ashkenazi share what it means from the CTO and CISO perspectives for a developer to shift left.
Oct 6th, 2021 8:44am by Lori Lorusso
👁 Featued image for: Upskilling Developers to Meet Today’s Security Challenges
Photo by Christina Morillo from Pexels.
CNCF sponsored this post.

The average person trusts that the software is secure that they use to bank online, watch movies, make purchases, order dinner, etc. They fill in the captcha; they check the box alerting the website that they are not a robot; they confirm they’re human; and are being “secure.” But what we have all come to realize is that filling in a captcha isn’t going to protect us from software vulnerabilities and supply chain attacks such as the Solar Winds and Colonial Pipeline hacks. Our first line of defense is the developers who write the code.

Shifting Left to Secure Software

Lori Lorusso
Lori is the DevRel community manager for JFrog. She manages the SuperFrogs program and supports the developer advocates at JFrog. She is a co-organizer of VJUG (virtual Java User Group) and frequently volunteers to support other JUGs at virtual and in-person events.

Developers are going to code at an extremely rapid pace, but how do we close the gap between speedy development and checking that our build info — all the information collected by the build agent, including dependencies, artifacts, project modules, etc. — is secure? How can we accomplish both goals of fast development and deployment while verifying that we are not at risk of an attack? The term “shift left” is widely used to describe bringing security scanning and compliance components to the onset of development, instead of being a costly afterthought, and this is the standard we hope all developers reach.

I sat down with JFrog CTO Yoav Landman and CISO Moran Ashkenazi to find out what it means from the CTO and CISO perspectives for a developer to shift left.

Both agreed that education and upskilling is key to reorient developers, so that shifting left to add security to their development process is no longer a shift but a standard practice.

“As the CISO,” said Ashkenazi, “my responsibility is to empower developers to make the right decisions. It’s very challenging because there is a knowledge gap. We want our developers to understand the breadth and depth of potential security vulnerabilities, to look for the red flags so they can independently make the right decisions and adjust their development accordingly. But sometimes they don’t have the knowledge to do that. It is my job to give them the tools [and] the training, and work with them to expand their knowledge. Security tools put the guardrails in place for the developers so they can better understand if there are vulnerabilities or weaknesses in their code as they develop. Developers should be empowered by security and not blocked — securing the products is a mutual responsibility between the security team and development.”

The Cloud Native Computing Foundation (CNCF) hosts critical components of the global technology infrastructure including Kubernetes, OpenTelemetry, and Argo. CNCF is the neutral home for cloud native collaboration, bringing together the industry’s top developers, end users, and vendors.
Learn More
The latest from CNCF

Landman echoed that sentiment. “I fully agree that we don’t need to block developers, but empower them and make them understand that security is just another form of debugging,” he said. “Developers are excited about gaining knowledge and making educated decisions to avoid risk and costly mistakes.”

“Getting hacked is not just [about] getting hacked,” Landman continued. “Getting hacked can mean going out of business; it can be game over. We are creating more and more software, automating processes, speeding up development release cycles and everyone from consumers to corporations to governments are in a digital transformation phase. We are writing code, adopting others’ code, adding more layers and complexities to our software, [so] the incentive for the ‘dark forces’ is only getting bigger. Practicing DevSecOps, closing the trust and knowledge gaps between devs and security teams, having failsafes in place to help mitigate vulnerabilities, scanning and failing a build before it goes into production when an issue is discovered — [these] are ways we can defend our software. But we need to start at the onset; we need to start with the developer.”

Get Ready with Tools and Training

👁 Image

With all the buzzword bingo circulating in the tech community around the software bill of materials (SBoM) and supply chain security, one thing is certain: Software is running the world and there are a lot of bad actors out there looking for opportunities to penetrate vulnerabilities. When they are successful, the outcome is chaos. Consumers lose trust, and companies can pay astronomical costs to repair the damage that was done — or lose their business altogether. Companies need to upskill their developers and supply the tools and training necessary to create a stronger, more cohesive DevOps or DevSecOps team. Security starts with development and education is the shift they need to get their job done.

👁 Image

To learn more about DevOps and other cloud native technologies, consider coming to KubeCon+CloudNativeCon North America 2021 on Oct. 11-15.

The Cloud Native Computing Foundation (CNCF) hosts critical components of the global technology infrastructure including Kubernetes, OpenTelemetry, and Argo. CNCF is the neutral home for cloud native collaboration, bringing together the industry’s top developers, end users, and vendors.
Learn More
The latest from CNCF
TRENDING STORIES
Lori is the DevRel community manager for JFrog. She manages the SuperFrogs program and supports the developer advocates at JFrog. She is a co-organizer of VJUG (virtual Java User Group) and frequently volunteers to support other JUGs at virtual and...
Read more from Lori Lorusso
CNCF sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.