Security breaches are top of mind for DevOps professionals spread thin by a lack of sufficient talent, but there's a disconnect between the principle of shifting security left and actually doing it, according to GitLab's 2022 Global DevSecOps survey.
The DevOps platform provider's annual survey reached 5,000 relevant decision makers and highlighted significant increases in DevOps platform usage, the prevalence of DevSecOps, continuous integration/continuous delivery (CI/CD), and test automation in DevOps teams.
But the main overarching concern identified is the "very real threat security breaches represent." To that point, shifting security left in the development process is commonly touted as best practice and has become a major factor for decision makers choosing a DevOps platform or related technologies, the report explained.
GitLab found 57% of security team members claim their organization has already shifted left or plans to this year, and one-third of security teams are planning a shift left more than two years from now. In addition, the survey found security is the top investment area for 2022, with cloud computing in second place.
While the desire to move security left is undoubtedly present, the report revealed a disconnect between the promise of shifting left and reality in terms of financial investment. Just 10% of respondents said they've received additional budget for security.
This is compounded by the fact that security professionals and developers still aren't the best of friends. "While it may be a bit simplistic to suggest sec and dev really don’t get along, year after year the data continues to support that they at least don’t always see eye to eye," the report reads.
The survey found 50% of security professionals agree unidentified vulnerabilities can still be traced back to developer mistakes a whopping 75% of the time, and less than 20% of security team members say developers find between half and three-quarters of all bugs.
This isn't due to a lack of developer accountability according to the report. Fifty-seven percent of respondents said security is a performance metric for developers at their company, but 56% claimed it's difficult to make developers truly prioritize fixing code vulnerabilities.
And despite the prevalence of the concept of shifting left, security vulnerabilities are still most likely to be found by security teams after the code is in a test environment, not by developers at the beginning of the process.
GitLab says it has heard these sentiments implying dev-sec tension since 2020, but the percentage of security team members "complaining" about developers significantly decreased from last year, "perhaps a sign of improving relations," the report reads.
Sprawling Toolchains, Strained TeamsAside from the pressure to shift left and lack of investment in doing so, DevOps teams face challenges related to toolchain sprawl and a dry talent pipeline.
The survey found 44% of DevOps teams use between two and five tools, 41% use between six and 10 tools, and 69% of respondents wish they were consolidated. Toolchain sprawl impacts speed and productivity with twice as many developers spending a fourth to a half of their time on maintaining or integrating toolchains compared to last year's survey results.
A common motivation for toolchain consolidation is that time-consuming toolchain maintenance uses hours that could be spent on compliance, which was cited by 37% of respondents. Another 35% said they want consolidation to remove the complexity of consistent monitoring across multiple tools. "Clearly, teams are tired of paying the 'toolchain tax,'" the report explained.
In addition to navigating complexity and prioritizing security, developers are challenged by an insufficient labor pool, the economy, and the impacts of COVID-19. "There was a strong sense of culture change and dread of looming, complicated technologies, with a clear undercurrent of 'we may not be ready for this,'" GitLab reported.
Comments