For every company in every industry, competition is as likely to come from an unknown startup as it is from long-established rivals.
In the modern economy, if you’re not innovating fast enough, you’ll get run over by someone who is. This fear of death can be a powerful motivator. Some of the biggest challenges to incumbents are leadership teams resting upon their laurels, deeply-embedded cultural norms and long-standing silos erected by software development, application security and IT operations teams.
These entrenched cultural norms and silos fuel friction, decrease velocity and diminish security and innovation. This race to out-innovative one’s competition has led to high-performing organisations chasing increased deployment velocities, but often ignoring the quality parts being used to manufacture their applications – creating increasingly ignored security problems.
It was 2003 when Bruce Schneier penned: “Today there are no real consequences for having bad bad security or having low-quality software of any kind. Even worse, the marketplace often rewards low quality. More precisely, it rewards additional features and timely release dates, even if they come at the expense of quality.”
16 years later, and for too many organisations, not much has changed. As nimble organisations deliver new innovations using DevOps principles, adversaries are also upping their game, something we saw in a series of high-profile and devastating cyberattacks last year.
Adversaries have the intent and ability to exploit security vulnerabilities in the software supply chain – and in some cases plant the vulnerabilities themselves. They have increased scale through automation and improved breach success through precision targeting.
If CISOs don’t align with developers and understand their role in fighting back, helping to automate security directly into the DevOps pipeline, then we’ll never be able to win.
Automating Security In
The industry currently lacks meaningful open source security controls. The most common way to introduce controls is through the application of open source governance policies across a software supply chain. But, when more than 5,500 IT professionals were asked if their organisation employed open source governance policies, just 63% responded positively. That percentage degraded further when participants were asked if they followed the policy. Further evidence of the lack of cybersecurity hygiene was revealed by 67% of survey participants who admitted to not having meaningful controls over what open source components are used in their applications.
Combine this with insight from the 2019 State of the Software Supply Chain report, which found that last year 51% of JavaScript packages downloaded had a known vulnerability and 10% of Java packages had a known vulnerability, and it becomes evident how important open source security needs to be for every enterprise.
The good thing, however, is that there is a path forward. Automation works. The same report mentioned above showed that organisations automating open source governance as part of a managed software supply chain practice reduced the percentage of vulnerable components used in finished applications by 55%.
Simply put, modern software supply chains can only operate safely when protected with automated security and quality assessments of these open source components. The stark volume of artefacts consumed by organisations today would outpace any attempt to manually review them to determine their health. Machines can accomplish checks in milliseconds where humans might take hours to reach similar conclusions.
- IKEA reveals plans to go carbon positive by 2030
- WeWork’s WiFi security could be putting companies at risk
- IFA’s can win by tackling regulation the ‘evergreen’ way
This reality is akin to the need for robotic analysis of parts being assembled on as high-velocity electronics manufacturing line – human examinations could never keep pace and are prone to error.
This sentiment was echoed in Forrester’s Top Recommendations For Your Security Program (March 2018) where analysts advised: “Automate faster than evil does. If you thought your security team struggled with alert volume – and alert fatigue – then Manual methods to detect, investigate, and respond to threats will guarantee failure in the near future.”
The question is not can CISOs help develop secure software? Certainly, you can. The application economy can grow and prosper in regulated, secure environments if managed properly. On the other hand, if companies decide to ignore proper cybersecurity hygiene, they’re putting their entire customer base at risk.
- Iain Slater is the sales director at Barrier Networks and has worked in cyber security for almost 15 years. He started his career in cyber security at Bloxx, a Scottish technology company that was eventually acquired by Akamai. Since then he has worked in both sales and security architecture across most vertical markets, utilising his experience and knowledge to help organisations of all sizes improve their cyber security posture.






