From Siloed Metrics to AI-Augmented Continuous Security Insights at SKILup Days 2024
In an era of escalating cyberthreats, the traditional separation between DevSecOps and SecOps metrics is leaving organizations vulnerable. Siloed approaches fail to provide the cohesive insights needed to detect vulnerabilities early and respond effectively to incidents. Emerging technologies like generative AI and machine learning (ML) offer transformative potential to bridge these gaps, enabling the creation of intelligent continuous security metrics that adapt and learn in real-time.
This session will explore how combining DevSecOps and SecOps metrics with AI-powered solutions can redefine security management. We’ll examine three real-world security events where traditional metrics failed and demonstrate how AI and ML could have delivered predictive insights, faster incident responses, and enhanced vulnerability detection. Attendees will leave with practical knowledge of how to apply generative AI and ML to build smarter, unified continuous security metrics that safeguard against today’s sophisticated threats.
Transcript
Hey, uh, welcome to my skill obsession on from siloed metrics to ai, augmented continuous security insights. I wish to thank people CERT and Techron Learning program committees for allowing me the opportunity to speak to you today. Um, if you don't know me, my name's Mark Horn Beak.
I am CEO and principal consultant of a little boutique consulting firm called Engineering DevOps Consulting. And as your name implies, you can see what I consult with. I'm also the author of some books, for example, the Engineering DevOps book.
And, uh, recent title just published two months ago called Continuous Testing Quality Security and Feedback. I'm also a member of I-E-E-E-A lifetime member, and, um, I'm a member of the Deming Institute, the and the Value Stream Management Consortium. I'm also an ambassador for People Cert and the DevOps Institute.
I have been a principal consultant for more than 90 different continuous engineering, uh, DevOps, DevSecOps and SRE transformations, mostly with very large organizations, both, um, public and, uh, enterprise and, uh, or institutions as well. I literally just celebrated my 50th year of my career in September of this year. So I guess I'm one of the old guys.
That's why they call me DevOps the Gray, I suppose. Uh, so since publishing engineering DevOps five years ago, I've been pointing out that in an era of escalating cyber threats and interestingly, these threats continue to escalate over this time. The traditional separation between DevSecOps and SecOps metrics is leaving organizations vulnerable siloed approaches failed to provide cohesive insights needed to detect vulnerabilities early and to respond effectively to incidents in production.
So emerging technologies like generative AI and machine learning offer transformative potential to bridge these gaps, enabling the creation of intelligent continuous security metrics that adapt and learn in real time across the, uh, development and production boundaries. Included this session will explore how combining DevSecOps and SecOps metrics with AI augmented solutions can redefine security management. We'll examine three real world security events where traditional metrics failed, and to demonstrate how AI and ML could have delivered predictive insights faster, uh, faster incident responses, enhanced vulnerability detection.
And you should get from this some level of knowledge about how to apply AI and machine learning to build smarter unified security insights to safeguard against these more sophisticated threats. Uh, one item to note, I did promise in case you guys, uh, came through my LinkedIn that anyone that attends this session in person, I am quite happy to send you a free copy of my most recent book, an ebook copy, uh, continuous testing, quality security, and feedback. com.
Okay, let's, uh, get started here. So there are several goals in the presentation. First of all, to understand what is continuous security itself and the current state of siloed DevSecOps and SecOps 'cause that's fundamental to understanding the rest of this.
Uh, the second is really to explore problems with silos of DevSecOps and SecOps metrics in particular, and then identify AI applications for unified continuous security insights, which is more than just metrics implementing ai, augmented, continuous security insights. I'll talk about how we can go about implementing these things, and I'll end up with a brief summary of some key takeaways that help you get started on your own journey if you wanna actually go ahead and, you know, implement these AI augmented continuous security insights. Okay, so let's, first of all, what the first topic understand what is continuous security and really the current state of siloed DevSecOps and SecOps?
Uh, so there are really stark differences between DevSecOps and SecOps and the challenges they face due to their cultural as well as operational silos. DevSecOps prioritizes rapid software delivery focusing on things like CICD automation, while SecOps emphasizes stability, risk, and compliance with focusing on monitoring, detection and incident response in production environments. One of the curious things about DevSecOps that I think some people at least don't seem to realize is even though, you know, SecOps is in the name DevSecOps, there's really not a whole lot of in, you know, in, in information within DevSecOps practice themselves about what you should do is security after deployment to production, and that's where SecOps comes into play.
So that's, uh, sometimes not understood by people. It's a little, uh, interesting. The lack of a cohesive security strategy across these teams and boundaries is often causing, you know, misaligned goals, fragmented tools, and in general measures that don't really overlap very well or don't integrate very well.
So this disconnect is further exacerbated by legacy structures, insufficient training, and the slow adoption of integrated security tools. I mean, honestly, I will sort of summarize a lot of that and just say, you know, the complexity of it all. And that's where, again, AI can help to try to deal with the complexity of some people already complaining about the complexity of DevSecOps alone or SecOps alone.
So, oh my goodness, if we start integrating these things, it's gonna be more complex. So you, you know, one could argue they can't even really do what I'm talking about as continuous security unless you have the help from AI tools. So for organizations to truly secure their environments, we need to bring these teams together, aligning their tools, data communication strategies, under one, you know, cohesive security framework.
And of course, that's what the next slide talks about. Uh, AI assisted continuous security focused on applying AI augmented, uh, security practices across the entire software development lifecycle and production operations. So in DevSecOps, the goal is to prevent vulnerabilities during planning engineering and in the CICD pipelines, ensuring that security is integrated from the start.
But once you move code into, you know, production with SecOps, the focus shifts to defending against exploits and attacks on the production environments. What makes AI augmented continuous security powerful is its ability to provide real-time threat detection, automated security testing in a seamless integration of security measures across both development and operations. So this assures that we progress from development to production and security remains a constant and a, you know, proactive element of, of the work.
So let's compare, you know, the traditional approaches of DevSecOps and SecOps With AI admitted continuous security and in Dev SecOps, the focus on shifting security left, integrating security measures into development and the pipelines and ensuring vulnerabilities are caught early SecOps, on the other hand, is concerned with product in production security focusing on monitoring and protecting live systems from exploitation. While I AI, augmented continuous security goes a step further by applying end-to-end security practices continuously securing every phase from development through the production by leveraging AI and machine learning. The key advantage of using AI is the ability to reduce complexity, lower costs, minimize resource requirements, uh, and, uh, allowing organizations to enhance security coverage while maintaining efficiency.
In fact, you could almost say that it makes it feasible without AI is pretty tough. Uh, over the last five years, we've seen a significant increase in very real world impacts of security breaches. For example, ransomware payments surge 171% while, uh, cybersecurity insurance premiums have increased by 96%.
So a lot of increases in costs there. The cost of forensic investigations now reached millions of dollars for breach with organizations facing lawsuits, reputational damage and business losses, often for months, uh, after the event, compliance penalties have also risen as regulatory scrutiny intensifies, and long-term organization disruptions have become a reality. But these trends demonstrate that organizations really need a proactive, you know, AI augmented continuous security approach to prevent costly breaches and minimize damage.
By adopting AI driven security practices, organizations can stay ahead of evolving threats and reduce, you know, the financial, legal and reputational risks. So let's explore the problems with siloed DevSecOps and, um, SecOps metrics. Let's look at the, um, in DevSecOps, the focus is on shifting security left, integrating security measures into the pipelines.
As we said, ensuring vulnerabilities are caught early. These metrics are primarily inward focused, reporting the results of security scanners and tasks of software that is transiting through the CICD pipeline. SecOps, on the other hand, is concerned within production security defense focusing on monitoring and protecting live systems from external threats and exploitations.
Uh, despite the concepts of collaboration, which are certainly, you know, uh, espoused by the DevSecOps and SecOps communities. Um, this in reality, uh, continues to be a gap in many organizations. There's a lack of co, uh, correlation between development vulnerabilities and runtime threats and missed patterns in complex attack scenarios due to the fragmented nature of the data.
When we examine some real world breaches, such as the SolarWinds supply chain attack and the log four J vulnerability in the Equifax breach, uh, that we've seen recently, we see that many of these incidents occurred due to gaps in both DevSecOps and SecOps practices and the SolarWinds breach, for example, attackers exploited weaknesses in the software supply chain. If AI, augmented continuous security had been applied, insights from continuous testing and patching could have identified the te the tampering much earlier for the log four J incident, AI augmented tools could have flagged vulnerable versions of the library and automatically patched systems. As soon as the vulnerability was disclosed.
Uh, the Equifax, uh, breach highlighted the importance of continuous monitoring with AI tools could have provided ongoing scans and threat detection that would've alerted teams to the un unpatched vulnerability. In all cases, AI augmented continuous security integrates both DevSecOps and SecOps practices enabling continuous realtime protection against the emerging threats, you know, across the lifecycle. And there are plenty of other examples on the slide that we don't have time to talk about, but in each case, you can, uh, look at them and understand how continuous security with AI support could have helped.
There are several environments where AI, augmented continuous security becomes essential. Large enterprises where DevSecOps and SecOps teams often operate in silos, uh, AI enables automated collaboration and coordination ensuring security is embedded across both development and production. In cases where software suppliers are separated from their customers, ai augmented security enables continuous threat monitoring, ensuring that the software is secure even as it integrates with the customer's environment.
Where government institutions and military applications where sensitive information is at stake, AI can manage continuous compliance checks, real time threat detection and security policy enforcement and network infrastructure. Situations where software manufacturers are disconnect from the network system operators, AI ensures that both software and the network are secured in tandem and in industries like finance, healthcare, and critical infrastructure where security breaches can have catastrophic consequences. ai, augmented continuous security provides the continuous protection needed to meet regulatory requirements and defend against every evolving threats.
So let's look at, um, AI applications for continuous insights. Generative AI and machine learning are revolutionizing, uh, security elevation by significantly reducing the manual effort required for tasks like threat detection, vulnerability management compliance checks. First of all, gen AI can accelerate tasks to analyze vast amounts of data and generate meaningful insights, helping identify potential security threats in real time.
Uh, for example, automated complex network patterns and user behavior that can drive detection of anomalies that might indicate a security breach before it even happens. Uh, secondly, tools augmented with machine learning applications driven by ai. Augmented task automation improves vulnerability scanning by using algorithms, prioritizing categorizing risks based on, you know, uh, based on their potential impact.
This ensures that the most critical threats are addressed, first, reducing the chances of oversight and altogether, uh, gen AI and machine learning augmentation facilitate more intelligent automated solutions. Fundamentally, AI transforms the way compliance is managed by automating what has traditionally been a very manual and resource intensive process. First of all, AI can continuously monitor systems and application for compliance with regulatory frameworks and security standards.
Instead of waiting for periodic audits or manually checking adherence policies, AI ensures compliance in real time. AI can reduce the manual workload involved in compliance checks and AI's ability to quickly assess and adapt to changes in regulations ensures that compliance remains a continuous process, not a reactive one. AI can also automate threat detection by continuously, uh, analyzing vast amounts of data from across your systems in real time.
Using machine learning, AI can identify unusual patterns of behaviors that indicate potential threats or vulnerabilities. Uh, this enhances speed and accuracy. Once the threat's detected, AI can automatically initiate mitigation steps, and ultimately, AI automation ensures that your systems are continuously monitored with real-time identification and response as well, reducing the risk of damage.
AI can also significantly improve vulnerability management by helping automate processes from detection to remediation, identify vulnerabilities faster by continuously scanning code infrastructure and systems. Using, for example, AI agents. It, uh, analyzes vast amounts of data, as we said before, uh, including known vulnerability databases.
And using machine learning can detect potential weaknesses. Once vulnerabilities are identified, AI can automatically prioritize them based on risk, and finally, even automate the patching process itself. Uh, three types of continuous security insights are important to help understand the progress of the transformations, the effectiveness of the solution, and the impact on the business mission.
To understand the progress of AI augmented continuer security transformation efforts, we look at the percentage of automated security checks and CICD pipelines and compare vulnerabilities detected pre-production versus post-production. Things like meantime to detect, as well as DevSecOps, SecOps collaboration metrics like joint incident response paths. Uh, as far as, um, effectiveness insights, these are derived from improvements to things like meantime to remediate reduction in security incidents, false alerts, compliance and costs, metrics and insights, uh, business mission insights such as downtime due to security breaches and security spending as a percentage of IT budgets are critical to understand the overall effectiveness.
So these metrics are important to demonstrate how AI augmented security improves, uh, security outcomes and business performance. So let's look at how you can implement AI enhanced continuous security insights. Leadership is where you start, right?
Leadership sets the tone for a whole security culture. Prioritizing security is in the decision making processes, resource allocation, communication in general leader, set the tone for the entire organization and champion security as a core value and not just a checkbox. Empowering teams to take ownership, providing continuous security education and awareness, or at least budgeting for that collab.
Uh, supporting collaboration between development, operational security teams, uh, establishing security policies and metrics, prioritizing, encouraging a shift left mentality for trying to identify security concerns early, both on the production side and the development side, and building a security of accountability and communication. Just some of the ways that, you know, the importance that, um, leaders play in this whole process. So start with leadership.
Basically, AI assisted value stream engineering is a game changer because it identifies both efficiency and security by automating key processes and optimizing workflows that are layer above the CICD pipelines and in production monitors. And that's the key, right? You're not looking typically at just an individual CICD pipeline.
When you're looking at continuous security across all of these environments, you need to be able to aggregate the data across the different environments. So as organizations scale and threats evolve, traditional manual approaches struggle to keep up as well as traditional, you know, monitoring, uh, approaches struggle to keep up. So AI helps overcome these challenges by making security metrics and insights at the next level.
So, ai, augmented virtual, uh, value stream engineering streamlines process by automating repetitive monitoring and analysis tasks that would traditionally be very manual and time consuming. This is actually a short version of my blueprint that illustrates how to use AI for front end, uh, and end-to-end value stream engineering transformations, including how you can establish observability metrics and analysis for insights. The very first step is to use ai, uh, to generate standard templates and artifacts that are used in different sections of the value stream.
And then those templates include things like codified standards for specifications, processes and output artifacts. And these templates and artifacts are then version managed so they can evolve over time as the organization continues to improve its practices across the end-to-end value stream, then people trained in the use of the generative AI generates standard compliant code and ai augmented tools are used to orchestrate and, and automate security tasks across the DevSecOps. Value stream results are generated from ai, augmented observability tools.
Results in analysis tools are processed by people with, you know, with assistance of the generative AI tools. Uh, basically this creates a closed loop in which AI is continuously, you know, directed, controlled and approved at every step. Uh, ultimately where human users are, are still in control, but trained and, uh, reciprocally, you know, help, uh, what they're doing and help each other.
The AI tool sets are used at every stage in the value stream, as well as in combination with that generative AI help of automation. So this slide provides a prescriptive guidance, and again, very high level. Uh, but to give you an idea, the major steps.
First of all, take inventory and, and assess where you are, what are your gaps in the current metrics? And you're looking at, uh, DevSecOps across SecOps. Adopt AI tools.
Decide what tools you're going to use for automation. Things like chat, GBT or Bard or other customized ML models, uh, for both the DevSecOps side and the SecOps side. Tried to get agreement on what those are gonna use.
Then train the models using historical data, both predictive generative AI systems can be used to that. Automate responses to implement AI driven playbooks and reduce the manual interventions. So finally, let's talk about key takeaways.
There are several takeaways from my talk. If you summarize the whole talk in just a few bullets. Essentially, ai, augmented automation of threat detection, vulnerability management and compliance reduces manual efforts and enhances real time end-To-end security responses, ai, augmented continued security transforms, siloed DevSecOps and SecOps reactive metrics to more unified proactive insights by predicting lifecycle vulnerabilities and mitigating risks and gap where they can cause harm.
And, uh, key metrics such as reduced incident response times, faster deployments, enhanced compliance demonstrates the success of AI and improving security and efficiency. The bottom line call to action if you want to evaluate your current DevSecOps and SecOps metrics and augmented current, you know, a unified set of insights with AI towards automating, uh, with tools and automated practices using ai. So that's, uh, basically my talk.
And, you know, I would encourage you to learn more about this topic. You're to say you're welcome to pick up a copy of my book. dot com.
I will gladly send you an eCopy of the book, and, uh, I wish you the best on the rest of your day and your conference. Thank you for your attention. I appreciate it.