Katie Norton, an Industry Analyst at IDC specializing in DevSecOps and software supply chain security, shares her insights on the evolving AppSec landscape. She discusses key trends for 2024, including the ongoing debate of platform versus point products, the impact of 'Developer Tax' on productivity, and the role of AI in automating code fixes. Katie also highlights her research focus for 2025, touching on Application Security Posture Management and the significance of storytelling to bridge the gap between security and development teams.
Katie Norton emphasizes the shift towards proactive security measures in response to open-source vulnerabilities, highlighting a critical evolution in application security practices.
The merging of various security categories into cohesive platforms signifies a trend towards better integration and collaboration between cloud security, observability, and DevOps tools.
Deep dives
Importance of Diverse Perspectives in Cybersecurity
Having a diverse set of voices in cybersecurity is crucial for addressing the varied threats present in the landscape today. This podcast highlights the insights of professionals from different backgrounds, as they discuss the influence of roles such as developers, IT specialists, and analysts on security practices. Katie Norton, an industry analyst, emphasizes that her prior experience in data administration allows her to approach security with fresh eyes, challenging some long-held beliefs. This demonstrates how varied perspectives can drive innovation and improvement in security measures.
Emerging Trends in Application Security
The conversation reveals significant trends in application security, particularly the shift towards more proactive security measures in response to open-source vulnerabilities. There is a noticeable pivot from traditional Software Composition Analysis (SCA) methods to innovative technologies focusing on securing software supply chains. Norton identifies this evolving landscape as critical for organizations to enhance their security posture and adapt to more sophisticated threats. The increase in focus on malware analysis and malicious package detection reflects a growing understanding of the complexities surrounding open-source security.
The Shift Towards Platform Consolidation
A noteworthy trend is the merging of various security categories and tools into cohesive platforms, facilitating a more interconnected approach to application security. Norton discusses how traditional silos in application security are breaking down, leading to better integration of cloud security, observability, and DevOps tools. As organizations aim for efficiency and simplicity, this trend suggests that security solutions will increasingly overlap, allowing for streamlined purchasing decisions and implementations. This consolidation ultimately enhances security effectiveness by reducing the fragmentation in tooling, promoting better collaboration among teams.
Challenges in Securing AI Applications
The security of AI applications presents complex challenges that warrant dedicated research and attention. There is a dual focus on securing AI technologies while utilizing AI to bolster application security. The podcast addresses the necessity for established AppSec vendors to adapt and enhance their capabilities to address AI-related risks, from model vulnerabilities to prompt injection. As AI continues to permeate various applications, it becomes vital for security strategies to evolve, ensuring that AI systems are securely integrated into organizations without compromising overall security integrity.
In this episode of Resilient Cyber, we catch up with Katie Norton, an Industry Analyst at IDC who focuses on DevSecOps and Software Supply Chain Security. We will dive into all things AppSec, including 2024 trends and analysis and 2025 predictions.
Katie and I discussed:
Her role with IDC and transition from Research and Data Analytics into being a Cyber and AppSec Industry Analyst and how that background has served her during her new endeavor.
Key themes and reflections in AppSec through 2024, including disruption among Software Composition Analysis (SCA) and broader AppSec testing vendors.
The age-old Platform vs. Point product debate concerns the iterative and constant cycle of new entrants and innovations that grow, add capabilities, and become platforms or are acquired by larger platform vendors. The cycle continues infinitely.
Katie's key research areas for 2025 include Application Security Posture Management (ASPM), Platform Engineering, SBOM Management, and Securing AI Applications.
The concept of a “Developer Tax” and the financial and productivity impact legacy security tools and practices are having on organizations while also building silos between us and our Development peers.
The role of AI in corrective code fixes and the ability of AI-assisted automated remediation tooling to drive down remediation timelines and vulnerability backlogs.
The importance of storytelling, both as an Industry Analyst and in the broader career field of Cybersecurity.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode