Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • DevOps Security Lessons current page
Link copied

DevOps Security Lessons

Aug 23, 2021
Author:
Raef Meeuwisse 2020 Headshot
​Raef Meeuwisse
Cybersecurity Expert and Author
Blog banner default
DevOps Security Lessons
Raef Meeuwisse 2020 Headshot
​Raef Meeuwisse
Cybersecurity Expert and Author

There is no doubt that the realization of DevOps can offer substantial operational advantages. The problem is that if you talk to ten different organizations about how they define and deliver DevOps—you will get ten different answers.

By the time you take into account the number of development technology options, and then the plug-ins available to the technologies and the cloud infrastructure variations – you already have more chances of winning the US Powerball lottery (1 in 292 million, in case you are interested) than running a DevOps stack and setup that is identical to one running in another company.

This is great news for the criminal hacking fraternity – many of whom enjoy picking through the open ports and misconfigurations to find opportunities. With that said, here is some good news for you:

Embedding fully-effective security in DevOps environment may *seem* impossible but trust me when I say that it only *seems* that way. Anything hackers can find a way to compromise – security people can find a way to fix.

When the “cloud-first” mindset emerged, I was out auditing some of those suppliers – and what customers usually told me on the way in was: “it’s so cheap, we don’t need all that security software anymore because it’s cloud!”

The truth was a little different. You might not need exactly the same security technologies – but the security principles remained the same.

It’s a similar situation with DevOps--the technologies and principles have moved on, but the underlying security engineering objectives endure.

Your DevOps department may not be solely reliant on a monolithic architecture anymore – but it does have its own security requirements – and you still need to know you can count on the myriad “other” dependencies (or at least deploy a contingency option, should things go wrong).

Recently, I presented at a webinar hosted by BeyondTrust, which is now available to watch on-demand here: Does your DevOps Environment have this Critical Security Vulnerability? (Most do).

This webinar focuses on what lessons we can draw from where DevOps environments are failing with regards to security. This webinar examines where things go wrong, what the clear indicators of failure look like, and how to assess roughly where you think your own organization is on the DevOps security maturity pathway.

This webinar is based on my experience from auditing, managing, and overseeing security across several dozen development environments – and if you don’t learn anything from it – then you must already have had similar work experiences to me and just be chasing down some CPE!


Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Patch Tuesday December 2017
    Dec 13, 2017 Patch Tuesday December 2017
    Blog
    1m
  • Top Cybersecurity Trends to Watch for 2021: The Hacking of Time, M/L Data Poisoning, Data Privacy Implodes, & More
    Oct 27, 2020 Top Cybersecurity Trends to Watch for 2021: The Hacking of Time, M/L Data Poisoning, Data Privacy Implodes, & More
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.