Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AppSec and development silos: what security teams need to change


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AppSec friction with development is the top pain point for 39% of respondents in an OX Security poll, ahead of alert fatigue at 19% and DevOps integration gaps at 18%, showing that misalignment now delays releases and leaves vulnerabilities exposed after deployment. The real issue is not effort but disconnected workflows, metrics, and remediation context that turn security into a late-stage bottleneck.

NHIMG editorial — based on content published by OXSecurity: AppSec and development team friction, disconnected toolchains, and remediation strategy

By the numbers:

  • The friction between security and development teams came in first, with 39% of the votes.
  • The second and third pain points were lack of integration with DevOps tools at 18% and alert fatigue and prioritization at 19%.

Questions worth separating out

Q: How should security teams reduce AppSec friction in modern delivery pipelines?

A: Start by moving security checks into the tools developers already use, such as pull requests, CI/CD stages, and code review workflows.

Q: Why do disconnected AppSec tools create more risk than visibility?

A: Visibility without context creates delays, and delays create exposure.

Q: How can teams prioritise AppSec findings more effectively?

A: Prioritise findings by exploitability, reachability, and privilege.

Practitioner guidance

  • Embed findings into the delivery pipeline Push security checks into pull requests and CI/CD gates so developers see issues before merge and release.
  • Prioritise by exploitability and business impact Replace raw scanner counts with a ranking model that weighs reachability, exposure, and likely blast radius.
  • Assign shared ownership for remediation Tie each critical finding to a named engineering owner and a clear remediation path inside the normal workflow.

What's in the full article

OXSecurity's full article covers the operational detail this post intentionally leaves for the source:

  • The specific 30+ disclosures and 10+ CVEs referenced in the webinar teaser, which are useful if you need concrete case material for internal discussions.
  • The detailed AppSec pain-point poll results from FS-ISAC 2024, including the breakdown of where teams said friction, integration gaps, and alert fatigue were most severe.
  • The practical examples of developer-centric workflow integration, including how OX Security frames contextual remediation inside CI/CD and code review processes.
  • The metrics and programme changes suggested for tracking remediation velocity, secure code coverage, and shared ownership over time.

👉 Read OXSecurity's analysis of AppSec and development team friction →

AppSec and development silos: what security teams need to change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AppSec friction is now a governance failure, not just a workflow annoyance. When security findings arrive too late to influence design or merge decisions, the organisation is effectively choosing detection after exposure. That creates a structural mismatch between engineering velocity and risk control. The practitioner takeaway is that AppSec success depends on policy embedded in delivery, not separated from it.

A question worth separating out:

Q: Who is accountable when critical AppSec findings reach production?

A: Accountability should sit with both security and engineering leadership, because the failure is usually systemic rather than individual. If a vulnerability reaches production, the programme should ask where the workflow broke, whether risk was prioritised correctly, and whether remediation ownership was clear before release.

👉 Read our full editorial: AppSec and development misalignment is now a delivery risk



   
ReplyQuote
Share: