The State of Cloud-Native Application Security Is at a Crossroads
June 29, 2023

Shahar Man
Backslash Security

The pace of cloud-native innovations is accelerating — more enterprise organizations are deploying code multiple times per week, with many doing so daily. In fact, the percentage of large organizations that deploy code to production daily is expected to increase from 5% in 2021 to 70% in 2025 (IDC FutureScape).

Cloud-native has changed application development in other significant ways. The configuration of the layers of cloud-native applications (e.g. code, containers, apps as containers) is now done with Infrastructure as Code (IaC) tools, which effectively blur the lines between application security (AppSec) and infrastructure security. Security risks that were once squarely in the domain of AppSec now bleed over into infrastructure security.

Access to complementary cloud-native capabilities does not extend to AppSec teams, who struggle to match the pace of their development counterparts and take Infrastructure security into account. This burden is compounded by current AppSec solutions like SAST and SCA, which often produce excessive low-value alerts and "noise" because assessments are performed without the full cloud context required.

My colleagues and I at cloud-native application security provider Backslash Security have been fascinated by the fact that dev teams outnumber AppSec teams and the amount of alert noise the latter struggle with on a daily basis. We wanted to dig deeper, so we commissioned a report to find out from US-based AppSec professionals (managers and engineers) themselves how they are faring with these dynamics at play. The resulting report, Breaking the Catch-up Cycle: The New Cloud-Native AppSec Paradigm Survey Report, illuminated our understanding of AppSec teams' day-to-day challenges and their perspective on the solution capabilities needed to likewise usher in their own cloud-native era.


Appsec Teams Using Cloud-Native Solutions See Declining Utility for Traditional Appsec Solutions

The study revealed that SAST and SCA solutions — long considered staples of the AppSec ecosystem — are losing ground, with just 32% using either of the tools extensively. However, there's evidence that the size and resources of enterprises do influence what solutions are used by its AppSec teams. Enterprise organizations with lower employee headcounts (<5,000 employees) use SAST and SCA technologies more extensively, as they lack the budget and resources to abandon the tools in favor of more complex solutions.

Enterprises Using Traditional Appsec Tools Are Subject to a Costly "Defensive Tax"

AppSec teams using current solutions spend an inordinate amount of time to compensate for their shortcomings. Over half (58%) of AppSec teams report that they spend 50%+ their workday chasing vulnerabilities, and a mind-blowing 89% of AppSec respondents said they spend at least 25% of their time on the same pursuit.

As the old adage goes, "Time is Money." AppSec professionals forced to work in a state of perpetual defense instead of establishing and driving a comprehensive cloud-native application security program has consequences. It introduces Defensive Tax, which refers to the financial loss suffered by stifled efficiency and innovation. By conservative estimates, enterprises lose an average of $1.2 million annually to unnecessary operating costs.

Low "Signal-To-Noise" Ratio Is Chief of Several Prevailing Appsec Solution Shortcomings

The challenge of noisy AppSec solutions were well documented by the time cloud-native development innovations came into play. However, its arrival substantially magnified the "signal-to-noise" shortcomings current AppSec solutions have. Research showed that most oft-cited grievances AppSec had regarding their solutions were: "Prioritizing findings takes a considerable amount of time" (at 48%); and "Existing AppSec tools are pretty noisy" (at 45%). Nearly all respondents (94%) had multiple grievances, but respondents working on the front lines — AppSec engineers — consistently cited more grievances with current tools than the AppSec managers surveyed.

Appsec Solution Shortcomings Can Negatively Affect Other Professional Spheres of the Enterprise

Nearly all AppSec professionals surveyed said current cloud-native AppSec tooling limitations drove negative business impact across multiple aspects of their enterprise organization. The list of challenges includes: increased friction between AppSec and development teams (39%); jeopardized ability to generate revenue (39%); and an inability to retain high-value dev talent (38%) and AppSec talent (35%).

Despite a Consensus on the Cloud-Native Solution Capabilities They Need, Most Appsec Teams Are Not Enabled by Their Organizations to Act

The new cloud-native AppSec paradigm is best characterized by three core tenets: end-to-end visualization of cloud-native app threat models (reduces manual work); correlating AppSec risk to an app's exposure to the outside world; and effective differentiation between general code weakness and critical vulnerabilities.

Despite the consensus of this paradigm within the AppSec world, there is a considerable gap between what AppSec teams need and the enablement to introduce change. While 85% of respondents agree it's critical to differentiate between real security risks and noise in their daily work, only 38% feel that their organization is enabled to do so. This trend persists across all of the most other critical capabilities, including: "Correlating security findings to the developer or dev team responsible for the fix" (78% vs. 43%); "Meeting compliance standards" (78% vs. 38%); "Analyzing threat impact in the context of their production environment" (74% vs 30%); and "Efficient triaging between Dev and AppSec" (73% vs. 42%).

The State of Cloud-Native Application Security Is in a State of Flux - How Do We Move the Needle Forward?

Much like the inflection point that led to the development life cycle shift from the legacy waterfall model to today's model of continuous development, the insights gained from this study illustrate that we've arrived at a similar point for AppSec tools — one that will prompt its adaptation to today's new, cloud-native reality. The cloud-native application development paradigm calls for a new, unified approach to application security — spanning code, application, and production context. Traditional dividing lines between application security and cloud security are quickly dissolving, and this study makes it abundantly clear that today's teams need only the enablement for the tools and technologies that similarly bridge the gap of this dichotomy and meet cloud-native application development where it stands.

Shahar Man is Co-founder and CEO of Backslash Security
Share this

Industry News

November 20, 2024

Spectro Cloud completed a $75 million Series C funding round led by Growth Equity at Goldman Sachs Alternatives with participation from existing Spectro Cloud investors.

November 20, 2024

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, has announced significant momentum around cloud native training and certifications with the addition of three new project-centric certifications and a series of new Platform Engineering-specific certifications:

November 20, 2024

Red Hat announced the latest version of Red Hat OpenShift AI, its artificial intelligence (AI) and machine learning (ML) platform built on Red Hat OpenShift that enables enterprises to create and deliver AI-enabled applications at scale across the hybrid cloud.

November 20, 2024

Salesforce announced agentic lifecycle management tools to automate Agentforce testing, prototype agents in secure Sandbox environments, and transparently manage usage at scale.

November 19, 2024

OpenText™ unveiled Cloud Editions (CE) 24.4, presenting a suite of transformative advancements in Business Cloud, AI, and Technology to empower the future of AI-driven knowledge work.

November 19, 2024

Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade developer portal based on the Backstage project.

November 19, 2024

Pegasystems announced the availability of new AI-driven legacy discovery capabilities in Pega GenAI Blueprint™ to accelerate the daunting task of modernizing legacy systems that hold organizations back.

November 19, 2024

Tricentis launched enhanced cloud capabilities for its flagship solution, Tricentis Tosca, bringing enterprise-ready end-to-end test automation to the cloud.

November 19, 2024

Rafay Systems announced new platform advancements that help enterprises and GPU cloud providers deliver developer-friendly consumption workflows for GPU infrastructure.

November 19, 2024

Apiiro introduced Code-to-Runtime, a new capability using Apiiro’s deep code analysis (DCA) technology to map software architecture and trace all types of software components including APIs, open source software (OSS), and containers to code owners while enriching it with business impact.

November 19, 2024

Zesty announced the launch of Kompass, its automated Kubernetes optimization platform.

November 18, 2024

MacStadium announced the launch of Orka Engine, the latest addition to its Orka product line.

November 18, 2024

Elastic announced its AI ecosystem to help enterprise developers accelerate building and deploying their Retrieval Augmented Generation (RAG) applications.

Read the full news on APMdigest

November 18, 2024

Red Hat introduced new capabilities and enhancements for Red Hat OpenShift, a hybrid cloud application platform powered by Kubernetes, as well as the technology preview of Red Hat OpenShift Lightspeed.

November 18, 2024

Traefik Labs announced API Sandbox as a Service to streamline and accelerate mock API development, and Traefik Proxy v3.2.