As more organizations started to use low-code/no-code software development technology through citizen developers, Forrester analysts expect this will lead to a headline security breach at a major enterprise by next year.
The developer workforce is diversifying with early adopters of citizen development reaching significant scale, which means the potential security breach surface is exploding and as is a greater need for risk management, Forrester analysts noted in a new report.
Low-code/no-code platforms have been used to replace core applications and many enterprises have started to build out governance programs around citizen development. Chris Gardner, VP and research director at Forrester, told SDxCentral there will be critical data living within these applications.
However, those citizen developers “aren't necessarily ready for developing code. They're a bit of amateurs and they're not really trained on things like application security or data sensitivity,” Gardner said. “So we believe that there's going to be a headline security breach because of that.”
The analysis firm’s recent Developer Survey showed that 39% of respondents stated their organizations currently use low-code to empower citizen developers and another 27% plan to do so in the next year.
On the positive side, the low-code/no-code and citizen development strategy offers an opportunity to address the developer shortage challenges the industry is facing and get more applications built by people that aren’t necessarily trained as traditional developers, Gardner noted.
He expects the talent shortage and developer gap will continue in 2023.
“There's gonna continue to be this separation between the folks that are traditional coders and are highly sought after and difficult to find in 2023, and the folks that are more citizen developers that can be trained on these low-code and no-code platforms that will be easier to find and easier to fill positions with," Gardner said.
Lacework recently warned against overlooking the increased security risks of adopting low-code/no-code.
“A lot of the time when these people are building an application within that platform, they’re building just that context. They don’t have the security knowledge and so a lot of strong defaults need to be built in, which aren’t there yet,” Lacework‘s Cloud Strategist Mark Nunnikhoven told SDxCentral in an earlier interview.
Forrester: Low-Coders Should Understand Shift Security LeftOrganizations should bring in the security teams to review access and roles given to citizen developers who use the low-code/no-code platform, while implementing security guardrails and a governance policy, Forrester noted in the report.
Gardner explained that there are two types of developers: one is “more professional” and familiar with DevOps, DevStack, site reliability, and engineering; and the other is “a whole group of business-level leaders” who don’t have discipline or the knowledge of DevOps or shifting security left.
The latter should engage security teams into the development process, he said. “It shouldn't just be low-coders building applications on their own.”
There should be training, guidelines, controls, and rules put in place so that citizen developers can build secure and logical models and applications that won’t leak data, Gardner added.
Organizations should also apply zero-trust principles to reduce the risk. “The average low-code developers are not that familiar with zero trust, so just even training them on zero-trust principles is a good thing,” he said.
Comments