DevSecOps: The Approach to Security by Design

Ajay Unni
Ajay Unni CEO,StickmanCyber
October 9, 2026 9 min read

Software development has evolved significantly in recent years. Processes like Agile development and DevOps along with technologies like cloud computing have made it quicker and more efficient than ever and this has largely been beneficial.

Developers can streamline the process and expedite a software release cycle, and users can get their hands on the finished product in a shorter period of time.

However, this can pose a problem from a cybersecurity standpoint because security standards aren’t always able to keep pace. In fact, in a 2015 IBM and Ponemon Institute study, about 65 percent of respondents strongly agreed that the rush to release mobile apps was putting their security at risk.

It’s a major problem that needed addressing, and that’s where DevSecOps comes in.

What’s the Purpose of DevSecOps?

According to software engineer Shannon Lietz, “The purpose and intent of DevSecOps is to build on the mindset that ‘everyone is responsible for security’ with the goal of safely distributing security decisions at speed and scale to those who hold the highest level of context without sacrificing the safety required.”

It’s a proactive approach to cybersecurity where secure practices are embedded into the entire lifecycle of software development. DevSecOps represents an underlying philosophy where security is weaved into the very fabric of development rather than merely being applied after the fact.

In other words, it’s security by design. Australia’s cyber security agency, ASD’s ACSC, describes Secure by Design in the same terms: a proactive approach that embeds cyber security into the design, development and operation of products and services from the outset.

While there’s a lot that goes into it, this methodology involves some core principles.

Automation

Just like with DevOps, speed and efficiency play a major role in DevSecOps. So it should come as no surprise that automation is a central tenet.

This is done by implementing cutting-edge security controls and automated testing throughout the entire development lifecycle. Some specific techniques include:

  1. Logging and event monitoring
  2. Configuration and patch management
  3. User and privilege management
  4. Vulnerability assessment
  5. Compliance with industry standards

Team Collaboration

Relationships between the members of a dev team are extremely important. With DevSecOps, there’s the understanding that no one operates within a vacuum and that team collaboration is essential to the overall quality of the finished product.

That’s why there’s an emphasis on eliminating silos between those responsible for software development, security and so on. Instead, security is viewed as a team responsibility where individual members strive for optimal security as a collective unit.

This brings us to our next point.

Shared Threat Intelligence

Another key part of the DevSecOps manifesto is that team members should openly exchange security-related information with one another rather than keeping it to themselves. If a vulnerability is suspected, it’s critical that others are made aware of it as quickly as possible.

Lietz summarises it well by saying, “The mindset established by DevSecOps lends itself to a cooperative system whereby business operators are supplied with tools and processes that help with security decision making along with security staff that enable use and tuning for these tools.”

In other words, everyone’s in on security and intelligence flows freely. This way threats can be promptly addressed, thus reducing the chances of major security flaws.

Continuous Security Monitoring

The manifesto also calls for 24×7 proactive security monitoring, meaning you don’t wait for an incident to occur and then react to it. Rather you consciously seek out vulnerabilities before cyber attackers have the chance to exploit them.

This involves a “not if but when” approach to security. Threats are imminent, so they should be sought out.

In this regard, team members are basically putting themselves in the shoes of the enemy and thinking like they would. And it’s this mindset that makes DevSecOps so effective. The fact that it’s such an aggressive approach is what stamps out many issues before they have the chance to fully materialise.

The Benefits

At this point, we have a basic understanding of the purpose of DevSecOps as well as its underlying principles.

But how does this benefit your organisation? And what practical advantages does it offer?

Better Overall Security

First of all, you can expect tighter security from the top down. Because it’s a fundamental priority throughout the entire development lifecycle, there tends to be an overall reduction in vulnerabilities.

Rather than tackling security after software has been developed, your platform should be secure right from the start.

And this creates a virtuous cycle by eliminating a lot of the stress during development, minimising the impact of glitches, ensuring a safer user experience, and so on.

Improved Communication

As we mentioned earlier, collaboration is a huge part of this methodology. When everyone is responsible for security, it tends to create an atmosphere where various team members across different departments communicate with one another openly.

This means you’re less likely to find a person thinking, “It’s okay, someone else will take care of it.” Instead, everyone is working hand in hand to amplify security.

Two colleagues reviewing work together on a laptop, illustrating improved communication in DevSecOps teams

There’s an element of transparency there that may not have existed otherwise. In turn, this helps keep everyone on the same page and prevents a clog from forming in the communication pipeline.

What’s interesting is that this can often have a positive impact on the macro level. By implementing DevSecOps, it’s common to find that the improved communication rubs off on a company’s culture where transparency becomes the norm.

And this can have a tremendous impact.

Make Fixes Quickly

Time is of the essence when it comes to cybersecurity. DevSecOps puts your organisation in a position where you can swiftly respond to vulnerabilities and fix them quickly.

Rather than letting something fester and jeopardise the overall quality of your end product, you can take care of it and keep moving forward.

Not only is this important for staying one step ahead of cyber criminals. This ultimately allows you to expedite your time-to-market and puts your software in the hands of users in less time—something that’s very important in hyper-competitive industries.

Ensure Compliance

There are several security-based regulations in place mandating that organisations meet certain standards—in Australia, for example, the Privacy Act 1988 and, for APRA-regulated entities, CPS 234. As you’re probably aware, failure to comply can have some very unsavoury consequences primarily in the form of penalties.

But this approach naturally lends itself to compliance regardless of what the specific regulation may be. On top of that, you’ll be better prepared whenever those regulations inevitably change and new requirements are added.

A Better Reputation

Consumers are more aware of cybersecurity than ever. With the number of incidents on the rise—ASD’s ACSC responded to over 1,200 cyber security incidents in 2024–25, an 11% increase on the previous year—people want to be sure that the companies they do business with are taking security seriously. They want to know that they’re in good hands when using their software.

Jason Hart, writing in CSO about a 2017 Gemalto survey of more than 10,000 consumers worldwide, puts things into perspective:

  1. 67 percent of consumers fear that they will fall victim to a data breach in the future
  2. 62 percent believe that companies are primarily responsible for the security of their information
  3. 93 percent say they would take or consider taking legal action against an enterprise that has been breached

So it’s reasonable to assume that the proactive nature of DevSecOps where you actively hunt down threats will be appealing to most consumers. They know that you’re doing everything within your power to ensure their digital safety.

Not only can this help you avoid poor publicity, it can often be the catalyst for a boost in brand equity and give your company an edge over the competition.

Increased Revenue

When consumers aren’t worried about the safety of your product, it often translates into more sales. Just put yourself in your average customer’s shoes for a second.

Would you feel more comfortable doing business with a company that uses advanced security tactics or one that’s lax about security and takes a reactive approach?

Of course it would be the former. We live in a day and age where cyber attacks are all over the news, which has created somewhat of a paranoia for many people.

As a result, many are only willing to do business with brands with beefy security measures. And besides the increase in immediate sales, this can potentially contribute to the longevity of your company as well.

Implementation

With immense benefits like these, you’re likely interested in learning more about how you can actually implement DevSecOps into your organisation. One of the best ways to get started is to actively adopt these principles so that your collective mindset aligns with the DevSecOps manifesto.

It’s unrealistic to expect a complete transformation overnight. But making gradual changes and taking it step-by-step should allow you to eventually adopt this type of framework.

To learn more, you’ll want to check out the DevSecOps website (devsecops.org). There you’ll find their detailed manifesto, a blog, resources and more.

A New Standard of Security

At the end of the day, DevSecOps is about one main thing—bridging the gap between development and security.

Close-up of colourful lines of code on a screen, representing secure software development

It’s what allows dev teams to build and launch software within a short timeframe, while still addressing security concerns. This way you’re able to deliver a quality product that’s airtight from a security standpoint.

And with software development evolving at an increasingly rapid rate, it’s likely that this methodology will only continue to grow in importance.

If the concept of DevSecOps resonates with you, there are other forms of proactive cybersecurity that you might want to explore as well. And if you are looking to solve a particular cybersecurity challenge, share your requirements and our expert team will be in touch.

Image credits: in-post image 1, Christina Morillo / Pexels; in-post image 2, Markus Spiske / Pexels.

Frequently asked questions

What is the difference between DevOps and DevSecOps?

DevOps brings development and operations teams together to release software faster and more reliably. DevSecOps adds security to that collaboration, so security checks, decisions and responsibility are built into every stage of the pipeline rather than handled by a separate team just before release. The aim is to keep the speed of DevOps without sacrificing security.

What does “shift left” mean in DevSecOps?

Shifting left means moving security activities earlier in the software development lifecycle, towards design and coding, instead of leaving them until testing or after release. The OWASP DevSecOps Guideline describes the goal as detecting security issues, whether in the design or in application code, as fast as possible. Issues found early are usually easier to fix.

What security tests are used in a DevSecOps pipeline?

Common automated checks include secrets scanning to catch leaked credentials, static application security testing (SAST) of source code, software composition analysis (SCA) of open-source components, dynamic application security testing (DAST) of running applications, and infrastructure-as-code scanning for misconfigurations. The OWASP DevSecOps Guideline lists these as part of a basic secure pipeline.

Is there a framework for DevSecOps?

There is no single DevSecOps standard, but several frameworks help. NIST’s Secure Software Development Framework (SP 800-218, February 2022) sets out secure development practices that can be added to any development lifecycle, and ASD’s Secure by Design guidance helps Australian technology manufacturers build security in from the outset. The OWASP DevSecOps Guideline offers practical pipeline advice.

Does DevSecOps replace penetration testing?

No. Automated scanning in the pipeline finds many common issues quickly, but it complements rather than replaces independent penetration testing, where skilled testers look for flaws that tools miss, such as business-logic weaknesses. Standards such as PCI DSS v4.0.1 still require internal and external penetration testing at least once every 12 months and after significant changes.

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment