The benefits and challenges of integrating security into the software delivery lifecycle
In September 2017, US consumer credit reporting agency Equifax announced a massive data breach that affected 147 million consumers. Sensitive information such as names, social security numbers, and dates of birth, credit card and driver’s license data fell into the hands of hackers. Equifax ended up having to pay US$700 million to settle federal and state investigations and a further US$425 million in compensation to affected customers. It was one of the largest cybersecurity incidents in history.
The root of the breach was Equifax’s failure to patch – a known vulnerability in open-source web application framework Apache Struts. In addition, the investigation report found that there was an “execution gap between IT policy development and operation.” This suggests that the agency’s engineering, operations, and security teams did not integrate operational or security practices into the development workflows or application life cycles, which is a major DevOps security issue.
Instead of leaving themselves open to such incidents, companies should integrate security as a major part of their DevOps philosophy and factor it into the software development process.
That said, there are challenges that go with the benefits of this approach, so it’s wise to take a look at both sides of the coin.
What is DevOps?
It turns out that DevOps itself can be rather hard to explain. “There’s been a few misinterpretations of it, and it’s a very loose definition in many ways,” says Nigel Kersten, field chief technology officer of US automation software company Puppet. Part of that confusion might come down to its extremely broad definition.

Nigel Kersten, field chief technology officer at Puppet / Photo credit: Puppet
At its core, DevOps takes software engineering principles and best practices and applies them to the entire software delivery cycle. This affects how the process plays out, involving shifts in the way security, infrastructure, operations, management, and change management are carried out.
For example, DevOps automates certain functions of the software delivery cycle. Following its principles, an engineering team can write code to indicate how a web application should be deployed and automated, and then build a “self-service interface” for it, says Kersten. As such, anyone who needs to use this code or infrastructure can simply request for it themselves through the interface, without needing to file a ticket or waiting for an engineer to help them.
On top of this, DevOps also breaks down silos between teams in an organization, allowing disparate units like the development and IT teams to work together and deliver software quickly. DevOps does this by taking functions that aren’t normally expressed in code – like a rule change for a network firewall – and allowing them to be so, providing a “common language” that all teams can use to make changes and updates seamlessly.
Benefits of integrating security
There’s a common perception that the speed of software delivery goes in direct contrast to the quality of the software itself. This is why information security is often an afterthought in the software development process.
But this shouldn’t be the case.
“It turns out that, if you adopt security practices early in the process, not only do you deliver software quicker, but it tends to be more reliable as well,” points out Kersten.
Security is a major consideration in any software, and not prioritizing it means release teams may neglect security recommendations just to meet deadlines.
Keeping security at the forefront helps companies save time and money, as any flaws discovered during the testing phase can be picked up and solved immediately. Catching bugs from the beginning before they grow into something much more troublesome down the line – or worse, discovered only when customers are using the software – reduces risks and costs.
Challenges of incorporating security
However, the collaborative nature of DevOps may cause issues for some, and this is no different when getting the security and delivery teams to work together.
“A lot of people in IT are used to working in a particular manner, and you’re asking them to change the way they work,” says Kersten.
Having spent years or even decades creating an operational playbook, changing these processes to add in security measures and forcing the team to work with others could be challenging. Instead of encouraging change, some managers may become protective of their turf instead.
It’s also a pain point for the security team to collaborate with new units and people. Puppet recognized this problem after putting together its 2019 State of DevOps Report, which aims to highlight the importance of integrating security into the software delivery process.
In the report, security teams described high levels of friction when being forced to work with their non-security counterparts. Among those surveyed, 65% reported feeling the most friction when teams were “minimally” integrated – this goes up to 70% when teams were “selectively” integrated.

Chart taken from Puppet’s 2019 State of DevOps Report / Photo credit: Puppet
Interestingly, respondents from all roles reported the lowest feelings of friction when teams were completely assimilated. This suggests that businesses should commit to the change and ride out any initial waves of discomfort, as teams tend to run more smoothly once they are fully combined.
Another issue when applying security measures is that it will affect software delivery speeds initially, as new practices are introduced into areas where they weren’t needed before. Thankfully, this eventually dissipates as teams get more used to the new cycle of work.
Finally, deeper security integration doesn’t always mean that audits will turn up fewer issues. However, it does result in auditors being able to give more specific or focused feedback, which is more helpful and actionable than broad observations.
Cognitive barriers to overcome
While integrating security into any DevOps practice may seem like a no-brainer, many companies still don’t carry out the proper measures. In a 2019 survey of 1,310 IT decision-makers, 54% of respondents were less likely to say that IT security teams were “always consulted.”
Conducted by Japanese cybersecurity company Trend Micro, the survey also found that 40% of respondents felt that IT security slowed down their organization’s progress in DevOps.
But that’s not to say IT departments are blind to the importance of being more careful. In the same report, 94% of respondents were aware of the security risks in implementing DevOps initiatives. However, their resistance to change was still strong, despite knowing the dangers. Further education on the subject may be the catalyst for better outcomes.
Puppet’s 2019 State of DevOps report outlines findings and considerations that companies should take note of when implementing DevOps in their operations.
Visit Puppet’s website to download the full report.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.
Recommended reads
Life’s a game, and AI agents are Animoca’s new play
Indonesian AI startup goes global
Forrest Li on scaling Sea, building smarter bots, and founder grit
An AI assistant that joins sales calls and scores team skills
Beyond the check: Why VCs need more than capital
SGX’s CEO says it doesn’t need a unicorn to win
SMEs want AI too, but not the kind Big Tech is selling
Oatside’s alt-milk rise hits a profitable gear
Alibaba’s financial health in 12 charts
Asia’s telcos bundle AI into mobile plans. Will it pay off?
Editing by Winston Zhang, Jaclyn Teng, and Eileen C. Ang
(And yes, we’re serious about ethics and transparency. More information here.)
