Most firms say DevSecOps needs to up its game to be effective

A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
(Image credit: Shutterstock)

Siloed teams, the growing complexity of hybrid and multi-cloud environments, as well as the persistent reliance on manual processes all make vulnerabilities easier to slip into production environments, and harder to spot and address. 

Without improved effectiveness in DevSecOps, vulnerability exploits will continue rising both in numbers and destructive power. 

This is according to a new report from Dynatrace, which surveyed 1,300 chief information security officers (CISOs) in large organizations around the world, finding 75% agree the prevalence of team silos and point solutions throughout the DevSecOps lifecycle makes it easier for vulnerabilities to slip into production.

DevSecOps risk

Furthermore, Dynatrace found four in five (81%) of CISOs say they expect to see more vulnerability exploits if they can’t make DevSecOps work more effectively - despite just 12% of organizations saying they have a “mature” DevSecOps culture. 

While Dynatrace does not detail what “mature” DevSecOps culture entails, it did say that 86% of CISOS see AI and automation as “critical” to the success.

In fact, 77% of CISOs say it’s a “significant challenge” to prioritize vulnerabilities because they lack information about the risk these vulnerabilities pose to their environment, and 58% of the vulnerability alerts that security scanners alone flag as “critical” are not important in production. Individual DevSecOps team member spends more than a quarter (28%) of their time on vulnerability management tasks that could be automated. With automation, each member could free up to 11 hours of their time - each week.

Also, three-quarters (76%) of CISOs believe the time between discovering a zero-day attack and being able to patch every endpoint presents a “significant challenge”.

According to Bernd Greifeneder, Chief Technology Officer at Dynatrace, businesses should use solutions that “converge observability and security data and are powered by trusted AI and intelligent automation”. 

DevSecOps is short for Development, Security, and Operations, and generally refers to a business approach in which product security is not an afterthought or something that’s addressed at the end of a product’s development cycle, but rather something that’s baked in throughout the entire IT lifecycle and is a shared responsibility of multiple teams.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Hacker Typing
Racing against time on a menacing caldera: survey finds majority of organizations take days to tackle critical vulnerabilities, each of them a potential open goal for cybercriminals
Holographic representation of cloud computing over open businessman's hand
Businesses are struggling to address vulnerabilities hidden in phantom dependencies
API
Businesses are being plagued by API security risks - with nearly 99% affected
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
Cyber-security
Empowering developers with cutting-edge security training
Cartoon Phishing
Hackers use GenAI to attack more frequently and effectively
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Toni Collette in Hereditary
Everything leaving Netflix in April 2025 – from the scariest movie ever made to a beloved DreamWorks animation with 99% on Rotten Tomatoes
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Close up of Leica M11-P viewfinder
I wince at the prospect of the rumored Leica M11-V – here's why