3

Cloud complexity and manual processes contributing to security risks: survey

 1 year ago
source link: https://itwire.com/business-it-news/security/cloud-complexity-and-manual-processes-contributing-to-security-risks-survey.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Thursday, 27 April 2023 09:14

Cloud complexity and manual processes contributing to security risks: survey

By Stephen Withers
Dynatrace CTO Bernd Greifeneder

Dynatrace CTO Bernd Greifeneder

A survey conducted for software intelligence specialist Dynatrace shows CISOs find the growing complexity of hybrid and multicloud environments makes it increasingly difficult to keep software secure, and that the continuing use of manual processes helps vulnerabilities reach production environments.

Another finding of the 1,300-person (100 of them in Australia) survey is that the ongoing use of siloed tools for development, delivery, and security tasks is a brake on DevSecOps maturity.

Australia-specific findings include:

• 86 percent of CISOs said AI and automation are critical to the success of DevSecOps and overcoming resource challenges.

• 82 percent say the time it takes between the discovery of zero-day attacks and their ability to patch every instance is a significant challenge to minimising risk.

• 78 percent said they will see more vulnerability exploits if they can't make DevSecOps work more effectively; however, just 6 percent of organisations have a mature DevSecOps culture.

• 77 percent said the prevalence of team silos and point solutions throughout the DevSecOps lifecycle makes it easier for vulnerabilities to slip into production.

• 77 percent said it is a significant challenge to prioritise vulnerabilities because they lack information about the risk these vulnerabilities pose to their environment.

• 61 percent said vulnerability management is more difficult because the complexity of their software supply chain and cloud ecosystem has increased.

• Only 55 percent of CISOs are fully confident that the software delivered by development teams has been completely tested for vulnerabilities before going live in production environments.

• 56 percent of the vulnerability alerts that security scanners alone flag as "critical" are not important in production, wasting valuable development time chasing down false positives.

• On average, each member of development and application security teams spends 29 percent of their time (11 hours each week) on vulnerability management tasks that could be automated.

"Organisations are struggling to balance the need for faster innovation with the governance and security controls they established to keep their services and data safe," said Dynatrace CTO Bernd Greifeneder.

"The growing complexity of software supply chains and the cloud-native technology stacks that provide the foundation for digital innovation make it increasingly difficult to quickly identify, assess, and prioritise response efforts when new vulnerabilities emerge. These tasks have grown beyond human ability to manage. As such, development, security, and IT teams are finding that the vulnerability management controls they have in place are no longer adequate in today's dynamic digital world, exposing their businesses to unacceptable risk as a result."

He added "Despite a widespread understanding of the many benefits of DevSecOps, most organisations remain in the early stages of adopting these practices due to siloed data that lacks context and limits analytics.

"To overcome this, they should use solutions that converge observability and security data and are powered by trusted AI and intelligent automation. This is precisely what we architected the Dynatrace platform to do. As a result, our customers have reduced the time they spend identifying and prioritising vulnerabilities by up to 95 percent, helping them deliver faster, more secure innovation that keeps them at the forefront of their industries."

The convergence of observability and security is critical to realizing DevSecOps potential report is available for download here.

The survey was carried out by Coleman Parkes, with respondents were drawn from the US, the UK, France, Germany, Spain, Italy, the Nordics, the Middle East, India, Australia, Singapore, Malaysia, Brazil and Mexico.

Read 481 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here


Lead-Machine_pink_600x260.jpg

GARTNER MARKET GUIDE FOR NDR 2022

You probably know that we are big believers in Network Detection and Response (NDR).

Did you realise that Gartner also recommends that security teams prioritise NDR solutions to enhance their detection and response?

Picking the right NDR for your team and process can sometimes be the biggest challenge.

If you want to try out a Network Detection and Response tool, why not start with the best?

Vectra Network Detection and Response is the industry's most advanced AI-driven attack defence for identifying and stopping malicious tactics in your network without noise or the need for decryption.


Download the 2022 Gartner Market Guide for Network Detection and Response (NDR) for recommendations on how Network Detection and Response solutions can expand deeper into existing on-premises networks, and new cloud environments.

DOWNLOAD NOW!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK