Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Shift Left Becomes Shift Everywhere,

According to Synopsys’ BSIMM11 Study  

by The Gurus
September 18, 2020
in Features
Cybersecurity
Share on FacebookShare on Twitter

According to Synopsys‘ BSIMM11 Study, there are some key trends to take note of when it comes to software security practices.

Firstly, it shows that CI/CD instrumentation and operations orchestration have become standard components of many businesses’ software security initiatives, influencing how they are organised, designed and executed. For example, software security teams are beginning to report into a technology team or CTO instead of reporting to an IT security team or CISO. Additionally, they are changing the way they recruit and organise their talent.  

Secondly, organisations are beginning to automate their activities, converting human processes and decision-making to algorithms, triggered by events in CI/CD pipeline execution. This is one of the ways businesses are addressing resource constraints and cadence management problems.  

Next, the “shift left” concept has advanced to carrying out security activities as soon as the artefacts to be reviewed are available. This could result in “shift left” becoming “shift everywhere” meaning that activities traditionally performed to the left move to the right, including in production.  

Lastly, after a comprehensive review of the data pool, it became seemingly important that there be a separate category (FinTech) for firms that are ISVs specifically for financial services software due to the increase of data within the financial vertical.  

“The way modern software is built and deployed has transformed dramatically over the past few years, so naturally the efforts required to secure that software are changing as well,” said Michael Ware, BSIMM co-author and senior director of technology at Synopsys. “Businesses are critically dependent on software, and modern methodologies have accelerated the speed of development. As a result, there is more software everywhere, and we still need to worry about all the pre-existing software. As a model that constantly evolves to represent the actual practices in use by hundreds of software security groups around the world—including some of the most advanced teams in the world—the BSIMM provides a near-real-time view into how these changes are being implemented to protect the growing software portfolios.” 

Within the last year, the three activities that were added to BSIMM10 have grown exponentially. These were SM3.4 Integrated software-defined lifecycle governance, AM3.3 Monitor automated asset creation and CMVM3.5 Automate verification of operational infrastructure security. This growth reflects how businesses are working to accelerate their software security efforts to the pace of software delivery. Similarly, the BSIMM11 has added an additional two activities in the effort to continue this trend. These are ST3.6 Implementing event-driven security testing and CMVM3.6 Publishing risk data for deployable artefacts.  

BSIMM, or Building Security In Maturity Model, is Synopsys’ eleventh report looking at the software security practices across 130 different organisations in a variety of industries including financial services, FinTech, independent software vendors, cloud, healthcare, Internet of Things, insurance and retail. BSIMM11 outlines the work of over 8,000 software security professionals who are guiding the efforts of almost 500,000 developers.  

BSIMM was created to help organisations plan, execute, measure and improve on their software security initiatives (SSIs). Through the community of other businesses using BSIMM, they are able to compare and contrast their own initiatives along with the data given from others. In the latest report, BSIMM11 shows how organisations are adapting their software security efforts to support digital transformation and modern software development paradigms like DevOps.  

“The BSIMM is an excellent resource for security leaders interested in learning from the collective experiences of their peers, particularly to solve new or emerging challenges,” said Mike Newborn, CISO of Navy Federal Credit Union, a member organisation of the BSIMM community. “Today, most organisations face the challenge of securing a growing portfolio of applications against the backdrop of rapidly evolving and accelerating software development practices. BSIMM11 reflects how many of these organisations are adapting their software security strategies to protect themselves and their customers without stifling innovation or impeding the speed of development.” 

BSIMM provides an important insight into understanding and comparing the strengths and weaknesses of software security initiatives across different industries, driven by data. The three most mature verticals in the BSIMM11 data pool are cloud, Internet of Things and high technology firms. Similarly, it identifies the differences between the three top regulated verticals; financial services, healthcare and insurance with financial services being the most mature, having software security groups in place before the others.  

Read the BSIMM11 Digest or download the full BSIMM11 study. 

 

ShareTweet
Previous Post

Indian government computers compromised

Next Post

Email bungle exposed University of Tasmania students’ personal information

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol