惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
Last Week in AI
Last Week in AI
月光博客
月光博客
D
DataBreaches.Net
WordPress大学
WordPress大学
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
Recent Announcements
Recent Announcements
宝玉的分享
宝玉的分享
MyScale Blog
MyScale Blog
C
Check Point Blog
F
Fortinet All Blogs
B
Blog
小众软件
小众软件
Vercel News
Vercel News
罗磊的独立博客
有赞技术团队
有赞技术团队

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
The benefits of a customer-centric cloud security mindset
Wiz Team · 2023-03-07 · via Wiz Blog | RSS feed

There’s not much Clint Gibler, Head of Security Research at Semgrep, doesn’t know about global cloud security trends. A well-respected industry thought leader, Gibler is also the co-founder of the tl;dr sec newsletter, which curates and summarizes the latest security tools and research each week.  

Gibler recently joined CloudSec 360 to share actionable insights on building a market-leading, scalable security program. During the session, Gibler discussed how security culture is changing and new ways to manage risk. Here are some of Gibler’s key takeaways about customer-centric security and how to put it into practice. 

Software development is sprinting, now security must too 

The pace of innovation has accelerated exponentially in the last decade, thanks to the adoption of developments such as cloud containerization and infrastructure as code. Containerization enables new apps to be built in isolation as fully packaged products, which can then be shipped quickly, securely and with minimum friction – while infrastructure as code eliminates the need to manually manage IT. 

The result is that DevOps teams can now drop daily – rather than quarterly – software updates, enabling firms to respond to user feedback, fix bugs, and innovate faster than ever.  

This acceleration in software shipping times creates big challenges for security teams, however, who must develop new strategies to execute at speed or risk being seen as a blocker of innovation. 

Gibler says that to keep pace, security teams must undergo a mindset change, working closely with engineers and developers, treating them as customers and treating security as a customer-focused product.  

What does customer-centric security look like?  

Gibler stressed that security teams should add value for everyone within an organization. They need to collaborate with developers and engineers, rather than expecting them to endure separate user interfaces for security tools, workarounds and barriers. A proactive approach in which security teams add value for multiple stakeholders is the way ahead.  

“Many security teams now realize that building (tooling, libraries, automation) adds a lot more value than finding bugs and breaking things,” he says. “It’s the difference between helping stakeholders do the right thing, rather than acting as a gatekeeper and preventing people from doing what they need to do.” 

Four initial steps towards a customer-centric security function 

So, how do you shift your team’s focus from bug hunting to becoming a customer-focused springboard for innovation? Gibler suggests that all security teams should consider the following four steps on their transformation journey:   

  1. Create self-service resources with security baked in

    Security teams need to shift their focus from finding bugs and vulnerabilities downstream to introducing security-by-design at the development front line. This involves creating the tools and resources that dev teams need to accomplish their goals with security baked in. Try to befriend the Platform Engineering team, or whichever team creates software for the rest of your organization - this can be a great way to get security controls built in to standard tools and libraries across your company.

  2. Embed staff across teams 

    Consider initiating a rolling program of job swaps between security, DevOps and engineering to grow a customer-centric security function. Security team members can be embedded in DevOps or engineering for six months: Gibler shares, “They should be taking tickets, building out features, shipping code for production and doing exactly what developers are doing” in order to break down silos and build empathy. This also works in the other direction, with an engineer doing a stint on a security team. 

  3. Ensure security is easily understood and consumed

    Systems and processes should be designed to encourage secure behavior. Wherever possible, it should also be “as easy as clicking a button or reconfiguring a line of code,” says Gibler. “If developers aren’t behaving as the security team wants, it’s not because ‘they don’t get it’. It’s because the value proposition hasn’t been made clear enough, or they have to take too many additional steps.” 

  4. Build shared capabilities 

    Consider how security initiatives and tools can deliver value across the organization. For example, building an asset inventory is valuable for security teams in knowing what to protect, but it can also help finance understand your cloud bill and engineering knows which teams own what services. Similarly, security teams can use code scanning to find vulnerabilities or opting out of secure defaults, and engineering teams can use it to enforce coding standards or do code refactoring at scale. 

View the full CloudSec 360 session, featuring Clint Gibler, now for more actionable insights on building a scalable security program so that you can ship software quickly and securely with minimum friction.