Global Report Reveals the Need for the Convergence of Observability and Security as Rising Complexity of Cloud-Native Development Exposes Organizations to Heightened Security Risks
Dynatrace (NYSE: DT) released findings from a global survey of 1,300 chief information security officers (CISOs) revealing challenges in managing software security amidst complex hybrid and multicloud environments. Key insights include:
- 68% of CISOs cite increased difficulty in vulnerability management due to software supply chain complexity.
- Only 50% are confident their software is fully tested for vulnerabilities before deployment.
- 81% anticipate increased vulnerability exploits if DevSecOps is not improved.
- 86% view AI and automation as essential for DevSecOps success.
The report underlines the pressing need for better integration of observability and security practices in organizations to mitigate risks effectively.
- 86% of CISOs believe AI and automation are critical for DevSecOps success.
- Dynatrace platform can reduce vulnerability identification and prioritization time by up to 95%.
- 68% of CISOs report challenges in vulnerability management due to increased complexity.
- Only 12% of organizations have a mature DevSecOps culture.
- 50% of CISOs lack confidence that software is thoroughly tested before production.
The complimentary report, The convergence of observability and security is critical to realizing DevSecOps potential, is available for download.
Findings from the research include:
-
More than two-thirds (
68% ) of CISOs say vulnerability management is more difficult because the complexity of their software supply chain and cloud ecosystem has increased. -
Only
50% of CISOs are fully confident that the software delivered by development teams has been completely tested for vulnerabilities before going live in production environments. -
77% of CISOs say it’s a significant challenge to prioritize vulnerabilities because they lack information about the risk these vulnerabilities pose to their environment. -
58% of the vulnerability alerts that security scanners alone flag as “critical” are not important in production, wasting valuable development time chasing down false positives. -
On average, each member of development and application security teams spends nearly a third (
28% ) of their time – or 11 hours each week – on vulnerability management tasks that could be automated.
“Organizations are struggling to balance the need for faster innovation with the governance and security controls they established to keep their services and data safe,” said Bernd Greifeneder, Chief Technology Officer at
Additional findings include:
-
75% of CISOs say the prevalence of team silos and point solutions throughout the DevSecOps lifecycle makes it easier for vulnerabilities to slip into production. -
81% of CISOs say they will see more vulnerability exploits if they can’t make DevSecOps work more effectively; however, just12% of organizations have a mature DevSecOps culture. -
86% of CISOs say AI and automation are critical to the success of DevSecOps and overcoming resource challenges. -
76% of CISOs say the time it takes between the discovery of zero-day attacks and their ability to patch every instance is a significant challenge to minimizing risk.
“Despite a widespread understanding of the many benefits of DevSecOps, most organizations remain in the early stages of adopting these practices due to siloed data that lacks context and limits analytics,” continued Greifeneder. “To overcome this, they should use solutions that converge observability and security data and are powered by trusted AI and intelligent automation. This is precisely what we architected the
The report is based on a global survey of 1,300 CISOs in large organizations with more than 1,000 employees, conducted by
About
Curious to see how you can simplify your cloud and maximize the impact of your digital teams? Let us show you. Sign up for a free 15-day
View source version on businesswire.com: https://www.businesswire.com/news/home/20230420005335/en/
meg.brenner@dynatrace.com
Source:
FAQ
What did Dynatrace announce in their April 2023 press release?
How many CISOs participated in Dynatrace's survey?
What percentage of CISOs anticipate more vulnerability exploits if DevSecOps isn't improved?
What is the significance of AI in DevSecOps according to the Dynatrace survey?