Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecurityCybersecurity News

Shift left: Beyond the cybersecurity buzzword

By Scott Gerlach
security-buzzwordsfp1170x658.jpg

Image via Freepik

December 2, 2022

Shift left is one of the most popular terms within modern cybersecurity, used heavily in vendor marketing campaigns and as a headlining topic at industry conferences worldwide. As a result, the core objective and best approach to shift left has become unclear. While shift left has increased in popularity in recent years, it’s important to recognize that it is not a new concept. 


Years ago, organizations utilized the waterfall method of development, kicking off a project, scoping requirements, then designing, building, testing, and deploying software. Using this model, flaws and bugs made it all the way to the testing phase before they were identified, ticketed and sent back to development teams to fix. This method made it costly to resolve flaws. Through the gradual evolutions of DevOps and the creation of CI/CD tools, the process of fixing bugs naturally evolved to earlier in the release cycle — the founding of shifting left.


By integrating testing measures sooner in the life cycle, developers were enabled to fix issues faster as teams were immediately notified about problematic code. Code could also be pushed to production faster as teams no longer wait on manual review, and testing policies were consistent throughout. This was a huge win for productivity. 


Shift Left and Security Testing

But what does shift left mean when applied to security testing? Security testing is unique, as it usually does not take place until the code is live in production. Shifting security left is utilizing the same principles that improved efficiencies in quality testing and applying them to how teams find and fix security flaws. Shifting security left makes testing frequent, automated, and consistent. 


There are many benefits to shifting security left. This includes:

  • Secure and efficient delivery of new software: Perhaps the most important reason to shift left is the efficiencies it creates in delivering secure software. By embedding security testing to release cycles, security flaws can be discovered and remediated faster. 
  • Empowers developers: Enabling developers to own security testing means that they spend less time handling security bugs, allowing them to focus on more high-priority tasks — i.e., writing code. Snyk estimates that developers spend, on average, 8 hours investigating and remediating a security bug after the security team has created a ticket. Shifting security left means that this entire cycle can be short-circuited as developers can fix security bugs the same way they fix all other flaws.
  • Scaling security responsibilities: The ratio of AppSec to Engineering teams is 1:100, leaving security unable to keep up with the speed as engineers are deploying new software. Shifting security left means organizations can consistently scale efforts across the company. Security leaders can set the policies and monitor the state of application security over time, while developers can review vulnerable findings and work on fixes as they push new code. This allows security teams to keep a pulse on the security of web applications and APIs and focus more on collaborating with developers on complex issues.
  • Better protection of apps: Shifting security testing left also means better protection of organizational applications, APIs and microservices. 


Now that we’ve explored the benefits of shifting security left, let’s delve into how organizations can begin (and continue to sustain) such a process: 

  • Invest in developer-first tooling: Security tools with a developer-first approach are built for shifting left. Choose a solution that helps developers fix security flaws in addition to surfacing them. Some features to look for include detailed fix guides, well-maintained docs, and first-class integrations with popular DevTools.
  • Automate security testing *in* CI/CD: Adding automated security tests in CI/CD makes security part of the software development lifecycle instead of a disjointed process. Find a modern tool that integrates with popular CI/CD providers to start testing early and often.
  • Partner with developers in their preferred environment and leverage their existing workflows: Application security has to revolve around developers and their processes to reduce the number of vulnerabilities that make it into production. Align security testing with other software tests, such as unit and integration tests, to encourage developers to ship secure code by design.

This article originally ran in Today’s Cybersecurity Leader, a monthly cybersecurity-focused eNewsletter for security end users, brought to you by Security magazine. Subscribe here.

KEYWORDS: application security DevOps risk management software security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Scott Gerlach is CSO and co-founder at StackHawk.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Glasses in front of coding on screen

The Good Hackers Security Leaders Can’t Afford to Ignore

Coding

6 Data Breaches to Know About (June 2026)

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • code-enews

    Don't Shift Left, Start Left: Why Developers Should Be the First Line of Defense

    See More
  • leadership

    Beyond Talking the Talk: Building Cybersecurity into a Company’s DNA

    See More
  • Medicine and medical equipment

    Beyond the breach: The ongoing fragility of healthcare cybersecurity

    See More

Related Products

See More Products
  • The Complete Guide to Physical Security

  • The Database Hacker's Handboo

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing