Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Veracode and DevOps.com Research Shows Formal Education Leaves Developers Without Necessary Skills to Succeed in DevSecOps World

by The Gurus
August 17, 2017
in Editor's News
Share on FacebookShare on Twitter

New research shows that software developers are not receiving the training they need to be successful as DevOps becomes the prevalent approach to building and operating digital products and services. In today’s application-centric economy that gap could have real impact on the productivity of businesses in every industry, as well as on the security and quality of the software that underpins the digital economy. To view the infographic and access to the full research report, visit the Veracode blog.
The 2017 DevSecOps Global Skills Survey, sponsored by Veracode, a leader in securing the world’s software, and acquired by CA Technologies (NASDAQ:CA), and DevOps.com, found that while 65 percent of DevOps professionals believe it is very important to have knowledge of DevOps when entering IT, they’re not receiving the necessary training through formal education to be successful in today’s DevSecOps world (70 percent). DevSecOps refers to the practice of integrating security into the development and testing of software for a “shift left” mentality for faster, better quality outcomes.
The on-demand nature of today’s digital economy has driven the need to focus on innovation and improve the overall workflow of the modern enterprise. Implementing DevSecOps processes, in software development and deployment as a means of fuelling this effort, has highlighted the fact that today’s formal education for IT and development professionals has not evolved in the same way, or as quickly, as development has shifted. Those surveyed said that their IT workforce is only somewhat prepared (55 percent) or not prepared (nearly 30 percent) with the skills necessary to securely deliver software at the speed of DevOps. In fact, nearly 40 percent of hiring managers surveyed reported that the hardest employees to find are the all-purpose DevOps gurus with sufficient knowledge about security testing. This poses a significant challenge, as more than 50 percent of organisations said that either the entire organisation or some of their teams are currently utilising DevOps practices.
 
DevSecOps Adoption Requires Organisations to Minimise the Skills Gap
Although nearly 80 percent of respondents have a bachelor or master’s degree – with 50 percent reporting that they studied and earned degrees in computer science – there is still a lack of cybersecurity knowledge prior to entering the workforce. The survey found that 70 percent of respondents said the security education they received is not adequate for what their current positions require, and that they’re learning their most relevant professional skills on the job (65 percent).
“With major industry breaches further highlighting the need to integrate security into the DevOps process, organisations need to ensure that adequate security training is embedded in their DNA,” said Alan Shimel, editor-in-chief, DevOps.com. “As formal education isn’t keeping up with the need for security, organisations need to fill the gap with increased support for education.”
According to the survey, slightly less than half of respondents said their employers paid for additional training since their entry into the workforce – and nearly seven in 10 developers report that their organisations provide them with inadequate security training. Third-party training, either in the classroom or through e-learning, was identified by one in three surveyed as the most effective way to gain new, relevant skills – but the study confirmed that very few are afforded the opportunity (four percent).
“WannaCry and Petya are just two recent examples of large-scale cyberattacks that further demonstrate the importance of security in today’s exceedingly digital world. Despite this apparent need, security practices and secure software development isn’t required to earn a degree in IT or computer science,” said Maria Loughlin, VP of Engineering, Veracode. “Our research with DevOps.com highlights the fact that there are no clear shortcuts to address the skills gap. Higher education and enterprises need to have a more mature expectation around what colleges should teach and where organisations need to supplement education given the ever-changing nature of programming languages and frameworks. The industry will have to come together to ensure the safety of the application economy.”
 
Methodology
The study, commissioned by Veracode and conducted by DevOps.com, surveyed nearly 400 DevOps professionals globally. To read more about how DevSecOps builds a bridge between fast and secure software development, download Veracode’s Developer’s Guide to the DevSecOps Galaxy.
 
About Veracode
Veracode, acquired by CA Technologies, enables the secure development and deployment of the software that powers the application economy.
With its combination of automation, process and speed, Veracode becomes a seamless part of the software lifecycle, eliminating the friction that arises when security is detached from the development and deployment process. As a result, enterprises are able to fully realise the advantages of DevOps environments while ensuring secure code is synonymous with high quality code.
Veracode serves more than fourteen hundred customers worldwide across a wide range of industries. The Veracode Platform has assessed more than 2 trillion lines of code and helped companies fix more than 27 million security flaws.
Learn more at www.veracode.com, on the Veracode blog and on Twitter.
Copyright © 2017 Veracode, Inc. All rights reserved. All other brand names, product names, or trademarks belong to their respective holders.
 
About MediaOps
MediaOps is the premier global media resource for the emerging technology sector including DevOps, Security and Containerisation.  Their sites, including DevOps.com and Container Journal attracts and engages a thriving online community of technology professionals around the world. Resources include award-winning editorial from expert journalists, webinars, live events and more. As the leader in these emerging segments, MediaOps can create powerful, integrated marketing and communication platforms for clients.

Tags: CyberCybrsecurityDevOpstechVeracode
ShareTweet
Previous Post

Web application attacks accounted for 73% of all incidents says report

Next Post

Cyberattack on Scottish parliament 'could last days', MSPs warned

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol