Logo

dev-resources.site

for different kinds of informations.

Prevention: It's Time to Save Those Millions

Published at
9/3/2024
Categories
devops
appsec
security
operations
Author
bfuller
Categories
4 categories in total
devops
open
appsec
open
security
open
operations
open
Prevention: It's Time to Save Those Millions

I started watching the series New Amsterdam. Initially, I thought it might be inspirational. It鈥檚 about a public hospital in NYC. If you haven鈥檛 watched it and plan to, I won鈥檛 spoil anything. I just started season 2, and the inspiration is flowing. The series takes a more socially conscious approach to problems.

That aspect is timely as I鈥檓 working on the 3M贸r one-minute pitch for the accelerator program. At a previous company, we aimed to create a world of visibility for our DevOps teams to help them respond to incidents and make better choices. In that sense, we were an IDP moving towards incident response.

Prevention to Save a Million

Recently, Incident.io announced they are combining incident response with context. I鈥檓 curious to see where that goes. This problem is crucial. It will be interesting to see how IDPs develop in the coming years compared to incident response tools.

Back to New Amsterdam. One thing I love is the show鈥檚 ability to highlight systemic issues and find creative solutions. They don鈥檛 always work鈥攊t is a drama, so there are heartfelt failures. But they strive to solve real systemic problems, and I feel like DevOps is doing the same right now. All these great tools approach issues with the philosophy that an ounce of prevention is worth a million. The reality is, that incidents can cost mid-sized companies up to $1M per year.

That鈥檚 what I appreciate about the Next Wave of DevOps. We鈥檙e acknowledging that we鈥檝e YOLO鈥檇 it, but now it鈥檚 time to prioritize prevention. DevOps, Platform Eng, and SREs have been doing this through SLOs and SLIs. We have tools targeting infrastructure, code, and security prevention. We need tools that tune and correct the gaps because those gaps are more like chasms that can鈥檛 be ignored.

Fixing the Information Gap

At 3M贸r, we鈥檙e addressing a specific gap or chasm鈥攖he missing slice of data that keeps Security and DevOps teams in conflict. It鈥檚 not about Shifting Left; it鈥檚 about being Better Together. Shifting Left can be contentious. It requires numerous tools and scaffolding for a smooth transition. We believe there鈥檚 a better way.

3M贸r is at the convergence of Security and DevOps teams. What data do both teams need to communicate and appropriately prioritize work? The time is now for a single tool with Security data formatted for DevOps teams to assess risk. We鈥檙e calling it Context Driven Prioritization Management (CDPM). It allows teams to mitigate unplanned work, reduce future risk, and respond more efficiently when a zero-day vulnerability emerges. If you want to learn more or be an early tester, sign up through our website.

Photo courtesy of WOCinTech

Featured ones: