Cloud-native security is gaining traction as a new vector for vendors trying to tackle both the growing use of cloud native platforms and the increased attention those platforms are getting from hackers. However, a challenge remains in getting the developer community that is vital to the cloud-native landscape to better buy into the security needs of that market.

The Cloud Native Computing Foundation’s (CNCF) most recent member survey found that security was considered a “container challenge” by 32% of respondents, which was third just behind “complexity” and “cultural challenges with development.” However, just 7% of respondents classified themselves as a “security engineer.”

A number of security providers have focused their efforts on this space and have recently begun to reap the rewards. Snyk and Aqua Security both recently closed on significant funding rounds that bolstered their unicorn status and showed the importance of their respective approaches to the venture capital market.

And Palo Alto Networks last month plunked down $156 million to acquire DevOps security startup Bridgecrew. Palo Alto Networks said it will fold the startup’s technology, which codifies infrastructure configuration during development, into its Prisma Cloud security platform to allow it to integrate cloud security across the application lifecycle.

Larger vendors are taking notice. Google, for instance, recently shined light on its plans to devote and fund two Linux kernel developers solely to security maintainers at the Linux Foundation.

Dan Lorenc, staff software engineer at Google, explained that the move was done to both support knowledgeable maintainers that want to work on securing open source software platforms, and also to provide a template for other vendors that might be looking to do something similar.

“We're talking about this just to kind of normalize it and make it approachable and show other companies how they can participate, too,” Lorenc said. “I think a lot of people in the industry want to, they just struggle to find out how.”

More specific to developers, Lorenc noted that there is growing interest in targeting their skills at the security space, but that there remains a familiarity hurdle that needs to be overcome.

“There's always been some mysticism around security,” Lorenc said. “I think most developers are interested in it, or curious about it, or pay attention to it in some fashion.”

He said that many developers have different mindsets when it comes to security, explaining that “some people like working on features that they can finish and wrap up and be done with,” while there is also a job security aspect as well. “You're not going to run out of work to do and people like being able to have a huge list of things and go pick one and work on it.”

Security Shifting Left Toward Developers

Sysdig is another one of those security vendors that has made a name for itself in targeting the cloud-native space. The firm recently contributed more core components to the Falco runtime security platform that it developed into the Cloud Native Computing Foundation (CNCF).

Loris Degioanni, CTO and founder of Sysdig, noted that developer interest in security is growing in line with the rise of continuous integration, continuous development (CI/CD) pipelines and increased use of microservices.

He explained that CI/CD “essentially brings security much closer to developers” as part of the “shift left” movement. “Developers can have feedback from the security practices point of view much earlier in the development cycle of the application that engages them as it exposes them to the good ideas and the annoyances of security, so they’re stimulated to participate.”

In terms of the microservices push, which Degioanni said was directly tied to the growing use of Kubernetes, “these services are a construct that is much closer to the developers, so it gives us many more opportunities to enhance and make security better in a way that is better exposed as a construct for the developer to interact with.”

Degioanni’s comments echoed that of Google’s Lorenc in that there is a focus on trying to bridge that perceived gap between developers tasked with working in a walled environment and the security world where those walls are replaced with real-world reality.

“Security can be pretty intimidating,” Lorenc added. “Most developers don't consider themselves security experts. They know that security can be pretty scary. If you don't get it right, if you get tiny little subtle things wrong, then you might screw up something big. Everybody wants to do it, nobody knows how so nobody does it even though they're curious and interested.”