IT leaders are out of touch with development team progress


A new study reveals that 40 percent of respondents don't know whether their development teams are behind or ahead of schedule, and 27 percent say they have trouble following the teams' progress to ensure they are meeting their goals.
The research from Couchbase, based on a survey of 650 senior IT decision makers, shows 88 percent of respondents are aware of the challenges faced by development teams.
Agile Pentesting offers developers more control and flexibility


Pentest as a Service (PtaaS) company Cobalt is today launching Agile Pentesting, a new offering that provides more control and flexibility to better meet the needs of businesses through versatile, ad hoc testing.
Agile Pentesting allows organizations to identify and address vulnerabilities at a faster, more frequent rate to minimize risk. This contrasts with what Cobalt calls 'comprehensive pentesting', which is often done in support of business drivers like compliance or M&A activity, the new offering helps accelerate customers' DevOps journeys while aligning with their CI/CD pipelines.
How improving the application experience can deliver for business [Q&A]


Spending on cloud services is showing no sign of slowing down, but IT and security leaders are realizing that applications need to have high availability and strong performance in order to be effective.
Application experience management is therefore becoming a key element of enterprise strategy. We spoke to Jason Dover, VP product strategy at Progress, to find out why.
Supply chain issues lead to mobile app vulnerabilities


A new study from Symantec's Threat Hunter team looks at how upstream supply chain issues can make their way into mobile apps, making them vulnerable.
Issues identified include mobile app developers unknowingly using vulnerable external software libraries and SDKs, as well as companies outsourcing the development of their mobile apps then ending up with vulnerabilities that put them at risk.
Taking a holistic approach to application security [Q&A]


Application security is becoming mainstream, and that's a good thing as it means that security testing is becoming an embedded aspect of the software development life cycle (SDLC). It also means that automated security testing tools are becoming faster, more sophisticated, and better integrated, so they're less likely to slow down developers or burden them with too many trivial findings or false positives.
But as good and necessary as AppSec testing tools are, it's not nearly enough simply to buy them and run them -- you need to buy the right ones and configure them correctly so that they help build security into your SDLC without bogging it down. It's important to implement a security strategy and a plan. It’s also important to employ developers with the skills to build trust into your software -- a concept known as 'holistic AppSec'.
Security drives DevOps platform adoption


Nearly three-quarters of respondents to a new survey have adopted -- or plan to adopt within a year -- a DevOps platform in order to meet rising industry expectations around security, compliance, toolchain consolidation, and faster software delivery.
The study from GitLab shows security has overtaken even cloud computing as the number one investment area across DevOps teams at global organizations.
DevSecOps delivers significant results but take up remains low


Only 22 percent of organizations have developed a formal DevSecOps strategy integrating security into software development lifecycle processes, according to a new report.
But the study from Mezmo shows an overwhelming percentage of those that do have a strategy report a positive impact on accelerating incident detection (95 percent) and response (96 percent) efforts.
Log4j and why it's not safe to relax yet [Q&A]


The Log4j vulnerability first hit the headlines in December last year. Since then we've heard less about it, but it hasn't gone away, like most vulnerabilities it has a long tail.
A recent report from the Cybersecurity Safety Review Board takes a comprehensive look at the vulnerability and what can be learned from it.
Enterprises struggle with application modernization


According to a new study 93 percent of enterprise IT leaders say the application modernization process is challenging due to staffing, tools, training and other issues.
The survey from Asperitas finds 30 percent of IT leaders say identifying the right tools and technologies is the most difficult part of the process, while 20 percent say it's finding staff with the right experience.
New solution makes it easier to manage machine learning models


More than 80 percent of organizations do not have the necessary visibility and control over their machine learning models or how they're deployed throughout the ML model development lifecycle.
To deal with this problem, Iterative has built an open-source model registry solution that allows teams to easily manage models with full context around model lineage, version, production status, data used to train the model, and more.
Banks choose to build their own tech solutions


While banks are investing in technology solutions to meet increasing demands, a new study shows that 61 percent prefer to build their own technology stack, rather than buy technology solutions from a third party.
The study from IT services company NTT DATA surveyed 900 senior banking respondents across 12 countries and examines the state of corporate banking following the COVID-19 pandemic.
How no-code platforms are helping meet enterprise business challenges [Q&A]


According to a November Wall Street Journal article, Gartner predicts global revenue in the low-code application platforms market will exceed $14 billion by 2025. Also, in a Forrester Research poll earlier this year of over 1,800 corporate tech officials at global companies, roughly 37 percent say they currently use low-code, no-code or digital process automation tools.
No-code is undoubtedly having its time in the sun and looks to be here for the long term. We recently caught up with Vinod Kachroo, CEO of no-code technology platform Innoveo, to learn more about what's driving the demand for no-code and what kind of ROI companies can realistically anticipate from it.
DevSecOps and the importance of threat modeling [Q&A]


In the past security has been something that was added only at the end of the development process. But as release cycles have accelerated this is no longer a viable approach.
DevSecOps (development, security and operations) is all about automating the integration of security at every phase of the software development lifecycle.
Popularity of open source software leads to security risks


The widespread use of open source software within modern application development leads to significant security risks, according to a new report.
The research from developer security firm Snyk and the Linux Foundation finds 41 percent of organizations don't have high confidence in their open source software security.
Why do development projects fail?


Why do development projects fail? And perhaps more importantly what do senior management need to understand about why they fail? Those are the questions that a new study from AI platform vFunction sets out to answer.
Based on a survey by Wakefield Research of 250 US software developers and architects, at a senior level within enterprises of 5,000 or more staff, it looks at the differences in goals, challenges and reasons for failure between business leaders and architects.
Recent Headlines
Most Commented Stories
Betanews Is Growing Alongside You
Only a fool still uses Windows 7
© 1998-2025 BetaNews, Inc. All Rights Reserved. Privacy Policy - Cookie Policy.