Why you need a security champions program
Blog post from GitLab
A survey by Forrester Research highlighted that 33% of security professionals experienced security breaches, primarily due to vulnerabilities in applications. These breaches indicate a worrying trend where applications are becoming prime targets for attacks, necessitating improved security measures. A significant issue is the disconnect between developers and security professionals, who often disagree on security practices and responsibilities. The GitLab 2020 Global DevSecOps Survey revealed widespread finger-pointing and a lack of security ownership, emphasizing the need for better collaboration. Amy DeMartine from Forrester suggested implementing a security champions program to bridge this gap, where champions can guide developers in real-time by providing contextual security advice. This approach aims to enhance developers' understanding of security, especially in handling open-source vulnerabilities, which have been increasing. Given the lack of secure coding education in top computer science programs, such champions serve as vital intermediaries to foster secure coding practices. To establish a successful program, organizations should secure funding, select empathetic security leaders, and continually measure and improve security practices, ultimately integrating security champions within development teams to scale security effectively.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 1 | 818 | 271 | 91 | +9% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.