Transforming from Security Silos to AI-Assisted Continuous Security – Predict 2025
This session introduces how AI can revolutionize the way we approach Continuous Security, end-to-end, across development and operations. It prescribes how AI-augmented tools, and AI-Assisted workflow practices can enhance integrated security automation practices, enable faster detection of vulnerabilities, and improve incident response. The session provides new and unique, practical, prescriptive insights, with customer use cases, on how organizations can transition, with AI-assistance, from traditional, silo ’ed DevSecOps and SecOps models to an AI-assisted Continuous Security approach that’s more efficient, proactive, and resilient.
Today we are facing a new wave of cyberattacks where AI is playing a central role. Criminals are using AI-driven attacks that dynamically adapt and improve, making them harder to detect and combat. Recent advances in generative and predictive AI-augmented tools, and AI-assisted workflows, facilitate the transformation, which previously would have been considered too complex, and too time-consuming to attempt by most organizations.
This session will cover how to:
1. Implement AI-Assisted Continuous Security across the entire software lifecycle, ensuring a seamless and proactive approach to threat management and security automation.
2. Unify DevSecOps and SecOps into a cohesive AI-driven security framework that covers all stages of the value stream, going beyond traditional siloed security models.
3. Select and integrate AI-powered tools for tasks such as vulnerability detection, automated compliance checks, and real-time incident response, improving security in both development pipelines and production environments.
4. Measure the ROI and business value of adopting AI-Assisted Continuous Security, understanding its impact on reducing costs, improving efficiency, and enhancing overall security posture.
5. Align security strategies with organizational goals, fostering effective collaboration between DevSecOps and SecOps teams to achieve continuous automated security across the enterprise.
6. Apply best practices and leverage real-world case studies to mitigate risks, avoid breaches, and stay ahead of evolving cyber threats using AI.
Transcript
Hey, welcome to my session on transforming from security silos to Intelligent continuous Security. I wish to thank Textron Predict 25 program Committee for allowing me this opportunity to speak to you today. My name's Mark Hornby.
I am CEO and principal consultant of a little en, uh, boutique consulting firm called Engineering DevOps Consulting. I'm also author of some books engineering DevOps, as well as the more recent one eng, uh, continuous testing, quality security and feedback. I'm a member of IEEE, the Deming Institute in the Value Street Management Consortium.
I'm also an ambassador of People Cert and the DevOps Institute. And, um, my general, uh, area of focus, of course is DevOps. I've been the pre principal consultant for more than 90 different continuous engineering DevOps, DevSecOps and SRE transformations Over my 50 year career, uh, since publishing engineering DevOps five years ago, I've been pointing out that in an area of, uh, in the era, I should say, of escalating cyber threats, the traditional separation between DevSecOps and SecOps is leaving organizations vulnerable.
Uh, siloed approaches fail to provide the cohesive insights needed to detect vulnerabilities early and respond effectively to incidents. That's, uh, despite the fact that, you know, DevSecOps has SecOps in the name, really they're still siloed operations. Typically, in many organizations, emerging technologies like generative AI and machine learning now offer more transformative potential to bridge the gaps, enabling the creation of intelligent continuous security, uh, adapting and, uh, learning in real time.
So, this session will explore how unifying DevSecOps and SecOps with AI augmented solutions can redefine security management. We'll examine real world security events where traditional metrics failed and demonstrate how AI and ML could, you know, have delivered predictive insights faster, um, have faster incident responses, enhanced vulnerability detection, and I'll leave you with some practical knowledge of how to apply generative AI and ML to build smarter more unified continuous security insights of a safeguard against today's sophisticated threats. So one item of note, anyone who attends this session in person, I offer a free ebook copy of my latest book, continuous Testing, quality Security, and Feedback.
com. All right, so without further ado, let's, uh, get started. So here's my prediction, uh, basically in a nutshell as far as predict is concerned.
Now, the Predict 25 event is all about predictions. So my prediction is that this year, a new security framework, which I call intelligent continuous security, will bridge the longstanding silos between DevSecOps and SecOps. Creating unified approach to proactive cyber defense by leveraging AI organizations will automate threat detection, streamline compliance, and achieve end-to-end security with unprecedented speed and accuracy.
I'm calling it in, uh, intelligent continuous security because basically it leverages in AI and com, the combination of DevOps and DevSecOps and SecOps. I would say that, uh, you know, a relevant quote comes to mind. William Gibson's is an acclaimed American Canadian writer, often referred to as the father of Cyberpunk, uh, for his groundbreaking work in cyber, in, uh, science fiction such as his 1984 novel, uh, is particularly known for envisioning the a digital future and the rise of the internet in this, uh, famous quotation.
The future's already here. It's not, it's just not evenly distributed. Well, hopefully it'll become more distributed in 20 24, 5.
Okay, so the session introduces a number of things that I hope are good takeaways for you. Um, how AI can revolutionize the way we approach continuous security end to end across both development and operations, uh, portions of a value stream and, uh, services. It prescribes how AI, augmented tools and AI assisted workflow practices can enhance integrated security automation practices, enable faster detection of vulnerabilities and improve incident response, and provides new and, uh, hopefully unique practical prescriptive insights with the customer use cases.
How organizations can transition with AI assistance from a traditional siloed DevSecOps and siloed model to, uh, AI assisted continuous security approach that's more efficient and resilient. I'll focus on, uh, first of all, uh, an understanding of what I mean by continuous security itself and why it's crucial for modern, uh, security practices, especially in large organizations, will also explore how to transition from the traditional sometimes siloed models, but more unified approach and how AI plays a vital role in this transformation. In fact, it one could argue it's, you know, it's the enabler, uh, already security people complain things are too complex and without AI's help, maybe this isn't even completely feasible, but, um, it makes it more feasible.
So by helping to automate and assist in threat detection and all the different aspects of security, the ultimate goal is to help you bridge the gap between development and operations. While leveraging AI to make the make it feasible, intelligent, continuous security focuses on applying ai augmented security practices across the entire development lifecycle and production operations. In DevSecOps, the goal is to prevent vulnerabilities during planning engineering, and in CICD pipelines, assuring that security is integrated from the start all the way up to delivery to production.
Once the release is deployed into production, SecOps focuses on shifting to defending against exploits and attacks in production environments. What makes AI assisted or intelligent continued security more powerful is its ability to provide realtime threat detection, automated security testing, and seamless integration of security measures across both development and operations. This ensures that we, as we progress from development, production security, uh, remains a constant and a proactive aspect.
There are stark differences between DevSecOps and SecOps and the challenges they face due to cultural, as well as, uh, operational, you know, siloed activities. DevSecOps prioritizes rapid software delivery, focusing on CICD automation. Well dev, well, SecOps emphasizes stability, risk, and compliance with a focus on monitoring, detection and incident response and production environments.
The lack of a cohesive security strategy between these teams is often caused by misaligned goals, fragmented tools, uh, measures that don't overlap. Uh, this disconnect is further exacerbated by legacy structures, insufficient training, and the slow adoption of integrated security tools. For organizations to truly secure their environments, we need to bring these team together, aligning their tools, data communication strategies under one cohesive security framework.
There are a large number of environments where intelligent continuous security becomes and has become, you know, as as absolutely essential. For instance, in large organizations where DevSecOps and SecOps teams operate in silos, AI enables continuous collaboration and coordination, uh, ensuring the security is embedded across both development and production. In cases where software suppliers are separated from their customers, AI assistance security enables continuous threat monitoring, ensuring that software security even as it integrates with the customer's environment.
For government, institutions and military applications where sensitive information is at stake, AI can manage continuous compliance checks, real-time threat detection, security policy enforcement, and network infrastructure where software manufacturers are disconnected from network system operators. AI ensures that both the software and the network aspects are secured in tandem in industries like finance secure or healthcare critical infrastructure. You know, where security breaches can have a catastrophic consequence.
AI assisted continuous security can provide continuous protection needed to meet regulatory requirements and defend against ever evolving cyber threats. Today, you know, we're facing a new wave of cyber attacks where AI is playing a central role. Criminals are using AI driven attacks that dramatically and dynamically adapt and approve, improve making their attacks harder to detect and combat.
Uh, criminals are using AI driven phishing attacks, for example, that dynamically adapt and approve making them harder to detect polymorphic malware, such as Deep blocker uses AI to change its behavior and evade traditional security measures. We're also seeing the rise of AI generated fake media like DeepFakes, which are being used or fraud and extortion. Additionally, ransomware attacks are becoming more sophisticated with AI helping to evade, uh, detection by continuously altering attack patterns.
Criminals are also leveraging botnets with AI for command and control operations, making these attacks more coordinated and harder to shut down. Organizations need intelligent continuous security to match these advanced AI based threats and ensure they're well protected. Uh, recent advances in generative and predictive ai augmented tools and AI assisted workflows facilitate the transformation of security prevention and defense, uh, uh, which previously would've considered too complex and too time consuming to attempt by most organizations.
Just to be clear and to put a bow on it, so to speak, intelligent Continued security is a strategy that leverages AI and automation to enhance the integration of security measures into continuous development, delivery and operations. This goal is to proactively reduce frequency, impact and response times of security events while continuously improving detection and resolution through data-driven insights and adaptive mechanisms. Uh, this strategy builds on continuous security principles by embedding proactive and intelligent security practices into the entire software lifecycle.
It ensures real-time adaptability to emerging threats, maintains software integrity and fosters trust through enhanced visibility and automation. Int intelligence con, intelligent continuous security goes, you know, way beyond just traditional approaches that rely solely on agile DevSecOps and SecOps by integrating AI driven automation, continuous insights, and proactive security across the entire lifecycle. While Agile focuses on speed collaboration and reliable software delivery, DevSecOps integrates security into development pipelines to ensure vulnerabilities are detected early, and SecOps defends production and systems responding to threats and ensuring operational security.
These frameworks focusing on integration of security incrementally, but still rely heavily on manual intervention, siloed tools and periodic uh, processes. Intelligent continuous security provides end-to-end security coverage by combining AI driven intelligence automation and real time monitoring across the entire development, deployment, and production lifecycle. Focusing on continuous feedback and learning to predict, detect, and mitigate threats proactively and ensures security is not just a separate phase of practice, but is always on an intelligent process.
Uh, ai, DevSecOps and SecOps rely on tools for automation, uh, and generally are reactive in their workflows and require manual analysis to act on security results. And intelligent continuous security uses AI and machine learning to identify vulnerabilities faster with predictive analytics, automating threat detection or remediation processes, and prioritizing security risks intelligently based on real-time data and reducing workflows. A agile DevSecOps and SecOps, uh, um, it shifted, uh, left DevOps in DevOps.
It shifted left to address issues earlier in development, but it still focuses on prevention and compliance. SecOps in is inherently reactive, focusing on detecting and responding to threats post-deployment, whereas intelligent continuous security shifts security both left and right, ensuring continuous monitoring feedback and action before, during, and after deployment. In the ICS intelligent continuous security framework, I outline, uh, eight pillars of practice continuous security culture in which we foster a organization-wide mindset where security is a shared responsibility embedded in every process and decision across the lifecycle.
Continuing security awareness and training, providing ongoing education and training to ensure all team members understand and address evolving security threats, security integration in the lifecycle, so seamlessly embedding security practices and tools throughout the development, deployment and operations. Lifecycles, uh, automated security testing. So utilizing automated tools and techniques to ensure continuous detection of vulnerabilities and compliance occurs with within security standards, proactive security risk management.
So anticipating, evaluating and mitigating potential security risks before the impact systems. Rapid, uh, incident response and develop and execute different response plans to, uh, minimize damage and downtime during security incidents, continuous monitoring and, uh, and compliance. Maintaining realtime vigilance over systems to ensure security and compliance to regulatory and organizational standards are met.
And finally, security feedback and continuous improvement. Using feedback, uh, loops, uh, to refine security practices and adapt to new challenges proactively. The following specific gaps were identified during a recent assessment, just to, as an example, uh, inconsistent AI usage.
While some teams use machine learning to identify code vulnerabilities, others depended on outdated scanning tools, uh, a lack of unified metrics. Agile developers measured success by sprint velocities. Uh, well SecOps tracked incident response times, leaving, you know, really no shared understanding of the end-to-end security health.
And the third finding was, you know, siloed communication. You know, critical security feedback from SecOps wasn't getting its way back to the agile teams, and this was leading to recurring issues in the code base. So these are some actual examples from a, a recent assessment and for one organization.
Uh, as a result of the evaluation, the team decided to investigate an intelligent continuous security approach to address the following needs. You know, there's always people, process and, uh, technology concerns. So in the people area, it's all about, you know, addressing cultural concerns, collaboration, again, training and awareness pillar we talked about and processes.
It's getting unified security integration activities going AI driven automation. So using AI in a smarter way, uh, real time feedback loops, end-to-end visibility where developers and, uh, DevOps engineers, SecOps engineers gain a single source of truth of their integrated dashboards. Uh, and technologies, again, there many possibilities here.
It's always the case of where do you focus first, but AI enhanced observability tools is a good place to start real-time collaboration platforms. Again, things like having a unified dashboard that's used by both development and ops and AI driven testing. Uh, so having common testing tools, or at least being able to, uh, understand each other's testing results is a good idea.
And that was some of the recommendations. Here are some examples of other incidents, you know, uh, demonstrating the necessity of intelligent continued security practices, integrating security testing, monitoring, patching and response times. Uh, you can examine, for example, you know, the solar wind supply chain attack log four J, Equifax, you know, many of these incidents occurred, and when you really look at it due to gaps between DevSecOps and SecOps practices, and in some cases gaps within those practices as well.
Um, in the SolarWinds breach, for example, attackers exploited weaknesses in the software supply chain. If ai, augmented continuous security had been applied, insights from continuous testing and patching could have identified tampering earlier for log four J. You know, AI augmented tools could have flagged vulnerable, vulnerable versions of the library and automatically patched systems as soon as the vulnerability was disclosed.
Now, the Equifax breach, for example, highlights importance of continuous monitoring. AI tools could have provided ongoing scans and threat detection that would've alerted teams to the unpatched vulnerability. In all these cases, integrated, uh, continuous security, intelligent continuous security would've integrated both DevSecOps and SecOps practices, enabling continuous real-time protection against emerging threats across the entire lifecycle.
This is a, a breakdown of of the MoveIt, uh, supply chain ransomware attack that occurred in May 23. The, uh, ransomware got gang exploited a zero day vulnerability in MoveIt file transfer software to steal sensitive data. That's costs of this were enormous.
Ultimately between 200 and $500 million to some estimates, impacts across financial services, education and governance institution, uh, uh, areas. The attack highlights the critical need for proactive security measures, uh, as DevSecOps focus on vulnerability protection. While SecOps handles exploit defense, the failure to implement patches and address new vulnerabilities immediately led to widespread disruption.
Uh, this case illustrates the importance of continuously monitoring and enhancing security through software lifecycle. This chart shows how intelligent continuing security could have played a critical role in mitigating the move at supply chain attack. First, with AI driven vulnerability detection, the platform could have identified the SQL injection vulnerability earlier, even before it was exploited AI scans and testing code in real time flagging vulnerabilities and automatically suggesting patches.
In this case, rapid patching would've accelerated if AI can orchestrate the deployment of patches across multiple environments simultaneously. Uh, beyond patching for active threat monitoring, powered by AA would've, uh, provided real time alerts. Allowing the organization to respond to potential threats before they escalate can also enhance the effectiveness of system hardening.
And, uh, security chaos experiments could have, um, help with continuous testing security defenses, making them more resilient to attacks. Um, uh, in general, continuous security would've reduced response times, mitigated the breach impact and enhanced protection. To successfully implement intelligent continuous security organizations need to focus on a strategic transformation that begins with vision and, uh, goal alignment.
This includes setting clear objectives and aligning security goals with business priorities. Uh, next conducts strategic assessments, which involve discovery surveys, gap assessments, current straight, uh, value stream mapping to, to establish a baseline. From there, a comprehensive strategic plan is developed.
The, you know, the plan includes future state value stream map analysis, themes, uh, definition tool selection, roadmaps, implementation, uh, determining what's the appropriate governance and monitoring to ensure accountability throughout the transformation. In general, the entire process is accelerated by leveraging AI assisted tools to analyze results, provide insights, and guide the implementation by following the strategic blueprint organizations achieve a secure, you know, AI driven future. This slide is a prescription for transformation after a strategic roadmap is established, uh, using the blueprint in the prior slides, uh, the implementation roadmap is divided into four themes.
So theme one is usually about preparing your AI platforms test environments and tools includes metrics and workflows that will be used to monitor and track progress. Theme two, focus on standardization, migrating applications to standardized pipelines, farming centers of excellence for continuous security training. Theme three expands the security coverage to include additional applications and the condensed training.
And finally, theme four, optimizing security processes by accelerating test creation, excel execution and analysis. Each theme builds on the last one to create a fully optimized and scalable AI security environment. One thing I often find, which is frustrating to me, is people love to jump to theme four without, uh, investing in the earlier ones because they think they know the answer, but in reality, it often causes them to have to backtrack later and end up costing and wasting more time than it would've if it followed the approach in the first place.
Yeah, there are problems with traditional measurement approaches, uh, for SecOps and DevSecOps. In SecOps, the focus is on shifting security left, integrating security measures into the development of and CICD pipelines, ensuring vulnerabilities are caught earlier. Uh, DevSecOps metrics are primarily inward focused, reporting the results of security scanners and tasks of software that's transiting the CICD pipeline.
Well, SecOps, on the other hand, is concerned with in production security defense focusing on monitoring and protecting live systems from external threats exploiting exploitations. So despite the concepts of collaboration, you know, that are espoused between dev and ops and SEC teams, in reality, there's often a lack of co of co correlation between development vulnerabilities and runtime threats. And miss missing patterns and complex attack scenarios happen due to the fragmented nature of the data that's being reported.
Instead, you, you know, you really should look at three different types of continuous security insights that are important to help understand not only the progress of a transformation, but the effectiveness of the solution as it transforms and the impact on the business mission. So to understand the progress, um, you know, look at things like the percentage of security checks and CICD pipelines and compare vulnerabilities detected pre-production versus post-production, meantime to detect, as well as DevSecOps, SecOps collaboration metrics, things like joint incident response plans, incident insights are derived from, uh, sorry. Effectiveness insights are derived from improvements to meantime to remediate, um, reduction in security incidents, false alerts, compliance and costs, making those things visible across the whole life cycle.
And business mission insights can be things such as downtime due to security breaches and security spending as a percentage of IT budget, uh, to understand the overall effectiveness of your strategy. Uh, these metrics basically are important to understand how AI augmented continuous security improves outcomes and performance of at the business level. Uh, platform engineering these days is a hot topic, but frankly, it's not really a new concept as far as I can tell.
In having been involved in platforms for many, many years, the idea of providing a simple to use portal for stakeholders greatly, uh, simplifies the use of many tools and tech stacks needed for day-to-day tasks. Certainly that is true for security as well. Uh, platform engineering, specifically around intelligent contingent security, brings together automated and AI enhanced capabilities into a centralized environment to manage security across the entire software lifecycle.
The platform provides continuous monitoring, automated compliance checks and proactive incident response. That's an opportunity for platform engineers. One of the greatest advantages here is the scalability.
It offers helping your organization stay ahead of emerging threats by enabling real-time detection and mitigation. While aligning development ops and security teams creating more efficient security posture. Intelligent continued security helps close a number of critical gaps that arise from siloed, uh, DevSecOps and SecOps practices.
Some of the key gaps include inconsistent or delayed threat detection manual processes that lack automation, fragmented security postures across development and ops. These gaps lead to vulnerability, blind spots, misaligned security objectives, and slow response to threats, uh, especially emerging threats. By leveraging ai, we achieve continuous monitoring, real time detection, automation across the lifecycle, ensuring they're no longer, uh, operating in isolation, but integrating and unifying across, uh, the lifecycle.
Alright, I think I skipped this line. Yeah. As we move through AI assisted transformation, it's important to avoid common pitfalls.
I'm not gonna read this whole chart, but basically, you know, for example, lack of team alignment can lead to delays. So it's critical to create shared goals and hold regular cross team security standups sufficient automation is another issue. Automating security processes such as CSD, patch management and incident response is key.
Uh, ensuring real-time monitoring is important. Siloed tools, you know, try to align tools better and, you know, try to, uh, really focus on continuous improvement. Uh, o over omitting, that is a critical error because there's always gonna be ongoing requirements changes.
Also, it's important to motivate and successfully manage transformations. And no doubt, you know, there's a complex topic and, uh, it's important to educate, aligned, and motivate people to keep, uh, to get momentum and to keep momentum going. Uh, demonstrating value with clear IRI examples is a good approach.
Developing necessary skills, fostering culture shift towards automation, or just some ideas, encouraging innovation with teams, adapting pro, uh, project management processes that support transformations rather than just compliance and strengthened. Vendor partnerships are, are some examples. So as we wrap up, you know, um, there's some advantages of continuous security, intelligent continuous security.
We want just summarize with that. First, we see I ai, augmented security teams, uh, improving safety deployments and enhancing threat detection across the lifecycle, providing faster and more accurate results, and, um, reducing false positives, providing more efficient vulnerability management and adaptive security automation to some examples. Continuing on this, uh, conferences theme of predictions.
You know, if I look further ahead, you know, I believe in a longer term future where security is heading towards what I'm just, uh, penciling as something I call the SEC dev and ops model, where, you know, as we get, uh, more security becomes and AI becomes more integrated into security practices, traditional distinctions between development, security and operations, I think are going to blur faster. Lead times, continuous delivery and shift left strategies are already pushing security towards faster deployments. Uh, AI will push this further, enabling predictive threat analytics, autonomous security measures, and AI automa augmented decision making with advances like feature flag rollouts and no shift deployment models.
You know, smart automation will allow us to secure systems with minimal human intervention. So it's exciting future where security becomes part of the fabric of all operations. So my last slide, if you wanna learn more about intelligent continuous security, continuous testing, quality engineering, DevSecOps with SRE, I encourage you to get a copy of my new book.
And again, if you're attending this talk, uh, send me an email, I'll send you an e e-version. com. Thank you for your attention.
I appreciate it. I hope you have, uh, good conference for the rest of the talks. Thank you.



