DevSecOps Is Failing Because Security Is Still Being Sold as a Product, Not a Practice

https://hackernoon.imgix.net/images/cLDJAQhP4BVCHnCDkpG5zp1i5Qp2-4883a9v.jpeg

At RSA Conference this year there were 650+ security vendors. All of them were selling security products. Almost none of them were selling security practices.

This distinction sounds academic. It isn't.

A security product gives you a tool and a dashboard. A security practice gives you a discipline that gets embedded into how your engineers work every day.

The security industry has spent 30 years optimising for selling products. The result: organisations with extraordinary tooling and catastrophic outcomes. The average enterprise uses 76 security products. The average cost of a data breach keeps climbing.

Why Products Don't Solve the Problem

Security products solve the problem of not having a particular security product. They do not solve the problem of not having a security practice.

I see this pattern constantly: a CISO presents the board with a security incident. The board asks "how could this happen?" The CISO requests budget for...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE