TL;DR: AppSec friction with development is the top pain point for 39% of respondents in an OX Security poll, ahead of alert fatigue at 19% and DevOps integration gaps at 18%, showing that misalignment now delays releases and leaves vulnerabilities exposed after deployment. The real issue is not effort but disconnected workflows, metrics, and remediation context that turn security into a late-stage bottleneck.
NHIMG editorial — based on content published by OXSecurity: AppSec and development team friction, disconnected toolchains, and remediation strategy
By the numbers:
- The friction between security and development teams came in first, with 39% of the votes.
- The second and third pain points were lack of integration with DevOps tools at 18% and alert fatigue and prioritization at 19%.
Questions worth separating out
Q: How should security teams reduce AppSec friction in modern delivery pipelines?
A: Start by moving security checks into the tools developers already use, such as pull requests, CI/CD stages, and code review workflows.
Q: Why do disconnected AppSec tools create more risk than visibility?
A: Visibility without context creates delays, and delays create exposure.
Q: How can teams prioritise AppSec findings more effectively?
A: Prioritise findings by exploitability, reachability, and privilege.
Practitioner guidance
- Embed findings into the delivery pipeline Push security checks into pull requests and CI/CD gates so developers see issues before merge and release.
- Prioritise by exploitability and business impact Replace raw scanner counts with a ranking model that weighs reachability, exposure, and likely blast radius.
- Assign shared ownership for remediation Tie each critical finding to a named engineering owner and a clear remediation path inside the normal workflow.
What's in the full article
OXSecurity's full article covers the operational detail this post intentionally leaves for the source:
- The specific 30+ disclosures and 10+ CVEs referenced in the webinar teaser, which are useful if you need concrete case material for internal discussions.
- The detailed AppSec pain-point poll results from FS-ISAC 2024, including the breakdown of where teams said friction, integration gaps, and alert fatigue were most severe.
- The practical examples of developer-centric workflow integration, including how OX Security frames contextual remediation inside CI/CD and code review processes.
- The metrics and programme changes suggested for tracking remediation velocity, secure code coverage, and shared ownership over time.
👉 Read OXSecurity's analysis of AppSec and development team friction →
AppSec and development silos: what security teams need to change?
Explore further
AppSec friction is now a governance failure, not just a workflow annoyance. When security findings arrive too late to influence design or merge decisions, the organisation is effectively choosing detection after exposure. That creates a structural mismatch between engineering velocity and risk control. The practitioner takeaway is that AppSec success depends on policy embedded in delivery, not separated from it.
A question worth separating out:
Q: Who is accountable when critical AppSec findings reach production?
A: Accountability should sit with both security and engineering leadership, because the failure is usually systemic rather than individual. If a vulnerability reaches production, the programme should ask where the workflow broke, whether risk was prioritised correctly, and whether remediation ownership was clear before release.
👉 Read our full editorial: AppSec and development misalignment is now a delivery risk