DevArmor
AppSec

Application Security: Challenges and Opportunities in The AI Era.

Amir Kavousian
#appsec#ai

Application Security (AppSec) is the most labor-intensive function in cybersecurity. Despite significant advancements in tools and automation, AppSec remains a notable bottleneck in the Software Development Lifecycle (SDLC). The Shift Left philosophy recommends running security checks earlier in the SDLC, making fixing issues cheaper and faster. However, existing Shift Left tools have failed to solve the fundamental issue of application security: developers have little to no context of security considerations, while security engineers have a very limited context of the application code, architecture, and infrastructure. As a result, AppSec has become a linear, labor-intensive process that requires time and effort from both AppSec teams and developers.

In the past few months, I have spoken with more than 60 practitioners to identify top AppSec pain points from the engineering teams’ perspective. Some of these organizations don’t yet have a dedicated AppSec team and are using Shift Left tools to help identify vulnerabilities in their code. Some others have mature AppSec programs with dedicated teams. A few trends showed up in most of my conversations with these practitioners that could help shed light on the shortcomings of current AppSec programs and why we need to rethink AppSec, especially in the AI era.

Traditional AppSec is slow and expensive

Shift Left tools have failed to empower developers to take charge of the security of applications

Security budget moderation and AI adoption are top priorities for executives

In short, traditional, manual AppSec processes are slow and expensive. Shift Left tools add more complexity instead of helping engineers fix vulnerabilities. Companies want to change how they handle app security to keep their security teams lean while transitioning to the AI era.

Automation is the only way security teams can keep up with engineering, especially as AI co-pilots drive development velocity up. Emerging technologies such as LLMs have the potential to fundamentally revolutionize AppSec by automating highly manual and time-consuming tasks. In the next article in this series, I will expand on the opportunities for the future of AppSec in the AI era.

← Back to Blog