Curated articles, resources, tips and trends from the DevOps World.
It’s a tale as old as time: developers want to ship an app but are lambasted with security requests, and security teams want to secure an app but are brought in too late to do their job without knocking some heads in the process. The ensuing result is usually insecure code and frustrated teams.
Last week we discussed how using risk-based decisions can help speed up pipelines. You can watch the webinar on demand and read a summary of the session below. The speed of software development today allows us to get products to market at a faster pace than ever before.
DevSecOps increases the number of issues found and the speed at which they’re to be dealt with. In reality, only a small number of issues will pose a massive risk to the business. Unfortunately, security tools only give part of the risk picture when they return an issue.
Security tools can be noisy. In 20 years, we haven’t seen a single security tool return a set of issues that are 100% what needs to be worked on. Ultimately, there are a few main aspects to triaging lists of security issues to achieve better results from your tools.
Companies are developing and shipping software faster than ever before. The very nature of DevOps means that developers can work in an always-on mode, getting finished products into customers’ hands in a flash.
All teams present in the app development process have pressures on them to get work done fast and efficiently. With DevOps processes and CI/CD pipelines humming, the last thing you want is for security to slow things down or complicate the existing workflows.
At Uleska, we focus on moving security testing away from experts running manual tests and move it to automating security checks into existing processes.
According to VMware, the first half of 2020 saw a 238% increase in cyberattacks targeting financial institutions. And according to IBM and the Ponemon Institute, the average cost of a data breach in the financial sector in 2021 is $5.72 million.
Adding automation to one part of a process can then flood another part of a process. With DevSecOps, we’re allowing more security tools to find more issues in more projects.
Many security departments and management teams want to improve their processes. DevSecOps introduces the ability for much more granular measurements than traditional manual security testing. Even simple measures can highlight gaps and areas for improvement where the budget can be spent.
Have valuable insights to share with the DevOps community? Submit your article for publication.
Get the latest DevOps news, tools, and insights delivered to your inbox.
Made with pure grit © 2025 Jetpack Labs Inc. All rights reserved. www.jetpacklabs.com