Report Reveals the Need for the Convergence of Observability and Security as Rising Complexity of Cloud-Native Development Exposes Australian Organisations to Heightened Security Risks
Posted: Thursday, Apr 27

i 3 Table of Contents

Report Reveals the Need for the Convergence of Observability and Security as Rising Complexity of Cloud-Native Development Exposes Australian Organisations to Heightened Security Risks
From KBI

78% of CISOs say they will see an increase in vulnerability exploits if they canโ€™t make DevSecOps work more effectively

Sydney, April 27, 2023ย โ€“ย Dynatraceย (NYSE: DT), the leader in unified observability and security, has announced the findings of an independent global survey of 1,300 chief information security officers (CISOs), including 100 respondents from Australia, in large organisations.ย The research reveals that CISOs find it increasingly difficult to keep their software secure as their hybrid and multicloud environments become more complex, and teams continue to rely on manual processes that make it easier for vulnerabilities to slip into production environments.ย It also finds that the continued use of siloed tools for development, delivery, and security tasks is hindering the maturity of DevSecOps adoption. These insights highlight the growing need for the convergence of observability and security to fuel data-driven automation that enables development, security, and IT operations teams to deliver faster, more secure innovation.

The complimentary report,ย Theย convergence of observability and security is critical to realszing DevSecOps potential, is available for download here:ย https://www.dynatrace.com/info/ciso-report-devsecops-potential/

Findings from the Australian data include:

  • 61% of CISOs say vulnerability management is more difficult because the complexity of their software supply chain and cloud ecosystem has increased.
  • Only 55% of CISOs are fully confident that the software delivered by development teams has been completely tested for vulnerabilities before going live in production environments.
  • 77% of CISOs say itโ€™s a significant challenge to prioritise vulnerabilities because they lack information about the risk these vulnerabilities pose to their environment.
  • 56% of the vulnerability alerts that security scanners alone flag as โ€œcriticalโ€ are not important in production, wasting valuable development time chasing down false positives.
  • On average, each member of development and application security teams spends nearly a third (29%) of their time โ€“ or 11 hours each week โ€“ on vulnerability management tasks that could be automated.

โ€œOrganisations are struggling to balance the need for faster innovation with the governance and security controls they established to keep their services and data safe,โ€ said Bernd Greifeneder, Chief Technology Officer at Dynatrace. โ€œThe growing complexity of software supply chains and the cloud-native technologyย stacksย that provide the foundation for digital innovation make it increasingly difficult to quickly identify, assess, and prioritise response efforts when new vulnerabilities emerge. These tasks have grown beyond human ability to manage. As such, development, security, and IT teams are finding that the vulnerability management controls they have in place are no longer adequate in todayโ€™s dynamic digital world, exposing their businesses to unacceptable risk as a result.โ€

Additional Australian findings include:

  • 77% of CISOs say the prevalence of team silos and point solutions throughout the DevSecOps lifecycle makes it easier for vulnerabilities to slip into production.
  • 78% of CISOs say they will see more vulnerability exploits if they canโ€™t make DevSecOps work more effectively; however, just 6% of organisations have a mature DevSecOps culture.
  • 86% of CISOs say AI and automation are critical to the success of DevSecOps and overcoming resource challenges.
  • 82% of CISOs say the time it takes between the discovery of zero-day attacks and their ability to patch every instance is a significant challenge to minimising risk.

โ€œDespite a widespread understanding of the many benefits of DevSecOps, most organisations remain in the early stages of adopting these practices due to siloed data that lacks context and limits analytics,โ€ continued Greifeneder.ย โ€œTo overcome this, they should use solutions that converge observability and security data and are powered by trusted AI and intelligent automation. This is precisely what weย architectedย the Dynatrace platform to do. As a result, our customers have reduced the time they spend identifying and prioritising vulnerabilities by up to 95 percent, helping them deliver faster, more secure innovation that keeps them at the forefront of their industries.โ€

The report is based on a global survey of 1,300 CISOs (including 100 in Australia) in large organisations with more than 1,000 employees, conducted by Coleman Parkes and commissioned by Dynatrace in March 2023. The sample included 200 respondents in the U.S., 100 each in the UK, France, Germany, Spain, Italy, the Nordics, the Middle East, Australia, and India, and 50 each in Singapore, Malaysia, Brazil, and Mexico.

About Dynatrace

Dynatraceย (NYSE: DT) exists to make the worldโ€™s software work perfectly. Our unified software intelligence platform combines broad and deep observability and continuous runtime application security with the most advanced AIOps toย provide answers and intelligent automation from data at an enormous scale. This enables innovators to modernise and automate cloud operations, deliver software faster and more securely, and ensure flawless digital experiences. Thatโ€™s why the worldโ€™s largest organisations trust the Dynatraceยฎ platform to accelerate digital transformation.

Curious to see how you can simplify your cloud and maximize the impact of your digital teams? Let us show you. Sign up for aย free 15-day Dynatrace trial.ย https://www.dynatrace.com/trial/

The Production Team
The KBI Production Team is a staff of specialist technology professionals with a detailed understanding across much of cybersecurity and emerging technology. With many decades of collective industry experience, as well as expertise in marketing & communications, we bring news and analysis of the cybersecurity industry.
Share This