Skip to content
TrackPodcasts
technologyNov 7, 202322:41pending

The Limits of Shift-Left: What’s Next for Developer Security

About this episode

The practice of "shift left," which involves moving security concerns to the code level and increasing developers' responsibility for security, is facing a backlash, with both developers and security professionals expressing concerns. Peter Klimek, director of technology at Imperva, discusses the reasons behind this backlash in this episode.

Some organizations may have exhausted the benefits of shift left, while the main challenge for many isn't finding vulnerabilities but finding time to address them. Security attacks are now targeting business logic vulnerabilities rather than dependencies, which shift left tools are better at identifying. These business logic vulnerabilities are often tied to authorization decisions, making them harder to address through code-level tools. Additionally, attacks increasingly focus on the frontend, such as API development and cart attacks.

Klimek emphasizes the need for development and security teams to collaborate and advocates for using DORA metrics to assess the impact of security efforts on the development pipeline. Some organizations may reach a point where the tools added to the development lifecycle become counterproductive, he notes. DORA metrics can help determine when this occurs and provide valuable insights for security teams.

Learn more from The New Stack about Developer Security and Imperva:

Why Your APIs Aren’t Safe — and What to Do about It

What Developers Need to Know about Business Logic Attacks

Are Your Development Practices Introducing API Security Risks?

Get every episode summarized

Each time The New Stack Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

The Limits of Shift-Left: What’s Next for Developer Security

The New Stack Podcast

0:00
22:41

More episodes

More from The New Stack Podcast

View all episodes →