SlideShare a Scribd company logo
Silver Linings for Miles:
DevOps for Building Secure
Solutions
zane@signalsciences.com
@zanelackey
apb@datadoghq.com
@andrewbecherer
Who are these guys anyway?
• Zane built and led the Etsy Security Team
(spoiler alert: much of what this presentation
is about) and co-founded Signal Sciences
• Andrew ran a large application security
consulting practice for iSEC/NCC Group and
is now leading the Datadog Security Team
(spoiler alert: also much of what this
presentation is about)
This talk is about lessons learned being at
the forefront of the shift to agile/continuous
deployment/DevOps
For security teams, the world has changed
in three fundamental ways:
– Agility means code deployment is trending to
near-instantaneous
– Security is no longer the gatekeeper to
deployment
– If security is a blocker, it will be routed around
Near-instantaneous deployment?
A simulation of deploying code in the waterfall model
What is this shifting to?
An agility example: Etsy pushes to
production 50 times a day on average
Constant iteration in production via feature
flags, ramp ups, A/B testing
But doesn’t the
rapid rate of
change mean
things are less
secure?!
Actually, the opposite is
true
They key to realize is vulnerabilities occur in
all development methodologies
…But there’s no such thing as an out-of-
band patch in continuous deployment
They key to realize is vulnerabilities occur in
all development methodologies
…But there’s no such thing as an out-of-
band patch in continuous deployment
Compared to:
“We’ll rush that security fix. It will go out …
in about 6 weeks.”
- Former vendor at Etsy
What makes continuous deployment safe?
What makes continuous deployment safe?
Visibility
Silver Lining for Miles: DevOps for Building Security Solutions
Source: http://www.slideshare.net/mikebrittain/advanced-topics-in-continuous-deployment
The same hard lessons are slowly shifting to
security
Ex: Which of these is a quicker way to spot
an attack?
Silver Lining for Miles: DevOps for Building Security Solutions
Silver Lining for Miles: DevOps for Building Security Solutions
Increase agility by surfacing security visibility
for everyone, not just the security team
Having to talk to security to get security
awareness causes delays
Having to talk to security to get security
awareness causes delays
Delays get routed around
To embrace agility, security has to
decentralize
Without strong gating we
never get security eyes
on code
Did you ever really, I
mean really, have
security eyes on code?
Let’s do better.
…But there’s no such thing as an out-of-
band patch in continuous deployment
“Communities of practice are groups of people
who share a concern, a set of problems, or a
passion about a topic, and who deepen their
knowledge and expertise in this area by
interacting on an ongoing basis.“
…But there’s no such thing as an out-of-band
patch in continuous deployment
Design for “aliveness.”
Challenge: Maintain
informality while building
trust across time-zones.
Can we measure it?
…But there’s no such thing as an out-of-
band patch in continuous deployment
Pro-move: Link your local
practices to global
practices to build
Extended Knowledge
Systems.
In closing, remember…
Silver Lining for Miles: DevOps for Building Security Solutions
Lessons Learned:
– Embracing DevOps/Agile/Continuous
Deployment helps not harms security
– Visibility is the key to moving quickly and
safely
– You (in the general case) are never going to
be able to hire enough staff, so steal everyone
else’s
Thank you!
zane@signalsciences.com @zanelackey
apb@datadoghq.com @andrewbecherer

More Related Content

PDF
Ops Happen: Improve Security Without Getting in the Way
PPTX
Amy DeMartine - 7 Habits of Rugged DevOps
PPTX
The Journey to DevSecOps
PPTX
The R.O.A.D to DevOps
PDF
What we learned from three years sciencing the crap out of devops
PPTX
Open Source Defense for Edge 2017
PPTX
Security and DevOps Overview
PDF
Shifting Security Left - The Innovation of DevSecOps - ValleyTechCon
Ops Happen: Improve Security Without Getting in the Way
Amy DeMartine - 7 Habits of Rugged DevOps
The Journey to DevSecOps
The R.O.A.D to DevOps
What we learned from three years sciencing the crap out of devops
Open Source Defense for Edge 2017
Security and DevOps Overview
Shifting Security Left - The Innovation of DevSecOps - ValleyTechCon

What's hot (17)

PPTX
2016 virus bulletin
PDF
Building Security Controls around Attack Models
PPTX
451 AppSense Webinar - Why blame the user?
PDF
New Barriers of Transformation
PDF
The Rise of DevSecOps - Fabian Lim - DevSecOpsSg
PPTX
Cloud, DevOps and the New Security Practitioner
PPTX
451 and Endgame - Zero breach Tolerance: Earliest protection across the attac...
PDF
DevSecOps - The big picture
PDF
Continuous Delivery to Continuous Operations, DevOps & SRE = Continuous Culture
PPTX
DEVSECOPS: Coding DevSecOps journey
PPTX
Outpost24 webinar - Why security perfection is the enemy of DevSecOps
PDF
Building a Modern Security Engineering Organization
PPTX
Turning security into code by Jeff Williams
PPTX
State of DevSecOps - DevOpsDays Jakarta 2019
PDF
Chaos engineering for cloud native security
PPTX
State of DevSecOps - DevSecOpsDays 2019
PDF
Why does security matter for devops by Caroline Wong
2016 virus bulletin
Building Security Controls around Attack Models
451 AppSense Webinar - Why blame the user?
New Barriers of Transformation
The Rise of DevSecOps - Fabian Lim - DevSecOpsSg
Cloud, DevOps and the New Security Practitioner
451 and Endgame - Zero breach Tolerance: Earliest protection across the attac...
DevSecOps - The big picture
Continuous Delivery to Continuous Operations, DevOps & SRE = Continuous Culture
DEVSECOPS: Coding DevSecOps journey
Outpost24 webinar - Why security perfection is the enemy of DevSecOps
Building a Modern Security Engineering Organization
Turning security into code by Jeff Williams
State of DevSecOps - DevOpsDays Jakarta 2019
Chaos engineering for cloud native security
State of DevSecOps - DevSecOpsDays 2019
Why does security matter for devops by Caroline Wong
Ad

Viewers also liked (15)

PDF
Guns, Germs and Microservices w/ John Willis and Josh Corman
PDF
Release Engineering and Rugged DevOps: An Intersection?
PPTX
Applying DevOps Principles to Address Dynamic Changes in Cyber Security
PPTX
Rugged DevOps at Scale with Rich Mogull
PPTX
Lean Security
PDF
2016 - IGNITE - No Assholes
PPTX
Continuous and Visible Security Testing with BDD-Security
PDF
Rugged DevOps: Bridging Security and DevOps
PPTX
DevOps & Security: Here & Now
PDF
Devops security-An Insight into Secure-SDLC
PDF
DevSecOps - Building Rugged Software
PDF
Security DevOps - Free pentesters' time to focus on high-hanging fruits // Ha...
PPTX
Implementing an Application Security Pipeline in Jenkins
PPTX
Continuous Security Testing with Devops - OWASP EU 2014
KEY
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
Guns, Germs and Microservices w/ John Willis and Josh Corman
Release Engineering and Rugged DevOps: An Intersection?
Applying DevOps Principles to Address Dynamic Changes in Cyber Security
Rugged DevOps at Scale with Rich Mogull
Lean Security
2016 - IGNITE - No Assholes
Continuous and Visible Security Testing with BDD-Security
Rugged DevOps: Bridging Security and DevOps
DevOps & Security: Here & Now
Devops security-An Insight into Secure-SDLC
DevSecOps - Building Rugged Software
Security DevOps - Free pentesters' time to focus on high-hanging fruits // Ha...
Implementing an Application Security Pipeline in Jenkins
Continuous Security Testing with Devops - OWASP EU 2014
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
Ad

Similar to Silver Lining for Miles: DevOps for Building Security Solutions (20)

PDF
The State of DevSecOps
PPTX
State of DevSecOps - GTACS 2019
PDF
The New Security Playbook: DevSecOps
PPTX
Safely Removing the Last Roadblock to Continuous Delivery
PPTX
2016 - Safely Removing the Last Roadblock to Continuous Delivery
PPTX
2022 DOI SKILup Days_Your Developers Decide Your Security Posture_Not Your Se...
PPTX
DOIS22 Why you need Cloud-agnostic practices to fuel your DevSecOps adoption ...
PDF
dotSecurity2017
PPTX
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
PDF
A journey into Application Security
PDF
Agile Relevance in the age of Continuous Everything ....
PDF
Security Chaos Engineering: Sustaining Resilience in Software and Systems 1st...
PPTX
O'Reilly SACon 2019 - (Continuous) Threat Modeling - What works?
PDF
The Future of DevSecOps
PPTX
ROOTS2011 Continuous Delivery
PPTX
Continuous Delivery
PDF
Shift Left Security – Guidance on embedding security for a Digital Transforma...
PPTX
SCS DevSecOps Seminar - State of DevSecOps
PDF
Building Security Into Your Cloud IT Practices
PDF
DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective
The State of DevSecOps
State of DevSecOps - GTACS 2019
The New Security Playbook: DevSecOps
Safely Removing the Last Roadblock to Continuous Delivery
2016 - Safely Removing the Last Roadblock to Continuous Delivery
2022 DOI SKILup Days_Your Developers Decide Your Security Posture_Not Your Se...
DOIS22 Why you need Cloud-agnostic practices to fuel your DevSecOps adoption ...
dotSecurity2017
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
A journey into Application Security
Agile Relevance in the age of Continuous Everything ....
Security Chaos Engineering: Sustaining Resilience in Software and Systems 1st...
O'Reilly SACon 2019 - (Continuous) Threat Modeling - What works?
The Future of DevSecOps
ROOTS2011 Continuous Delivery
Continuous Delivery
Shift Left Security – Guidance on embedding security for a Digital Transforma...
SCS DevSecOps Seminar - State of DevSecOps
Building Security Into Your Cloud IT Practices
DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective

More from SeniorStoryteller (20)

PPTX
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...
PPTX
Where Bits & Bytes Meet Flesh and Blood - Joshua Corman
PDF
Implementing DevOps in a Regulated Environment - DJ Schleen
PPTX
Scaling Rugged DevOps to Thousands of Applications - Panel Discussion
PPTX
Making Security Agile - Oleg Gryb
PDF
What We Learned from Four Years of Sciencing the Crap Out of DevOps - Nicole ...
PDF
Release Engineering & Rugged DevOps: An Intersection - J. Paul Reed
PDF
Requirements Gathering for a Successful Rugged DevOps Implementation - Hasan ...
PDF
Ops Happens: DevOps Beyond Deployment - Damon Edwards
PDF
Building Security In - A Tale of Two Stories - Laksh Raghavan
PDF
Breaking Bad Equilibruim - John Willis
PPTX
NuGet Package Management Done Right
PPTX
Hero's Tookit: Start Your Rugged DevOps Journey with Nexus, Jenkins and Docker
PPTX
The End of Security as We Know It - Shannon Lietz
PPTX
Software Supply Chain Automation Removes Roadblocks to Rugged DevOps
PDF
Heroes’ Journey: Learning from Successful DevOps Transformations
PPTX
Rugged DevOps: Aligning Your Team and Your Powers for Success
PPTX
Create Rugged Applications: Managing Your Software Supply Chain
PPTX
Aligning Your Team and Your Powers for Success
PPTX
Leveraging Nexus Repository Manager at the Heart of DevOps
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...
Where Bits & Bytes Meet Flesh and Blood - Joshua Corman
Implementing DevOps in a Regulated Environment - DJ Schleen
Scaling Rugged DevOps to Thousands of Applications - Panel Discussion
Making Security Agile - Oleg Gryb
What We Learned from Four Years of Sciencing the Crap Out of DevOps - Nicole ...
Release Engineering & Rugged DevOps: An Intersection - J. Paul Reed
Requirements Gathering for a Successful Rugged DevOps Implementation - Hasan ...
Ops Happens: DevOps Beyond Deployment - Damon Edwards
Building Security In - A Tale of Two Stories - Laksh Raghavan
Breaking Bad Equilibruim - John Willis
NuGet Package Management Done Right
Hero's Tookit: Start Your Rugged DevOps Journey with Nexus, Jenkins and Docker
The End of Security as We Know It - Shannon Lietz
Software Supply Chain Automation Removes Roadblocks to Rugged DevOps
Heroes’ Journey: Learning from Successful DevOps Transformations
Rugged DevOps: Aligning Your Team and Your Powers for Success
Create Rugged Applications: Managing Your Software Supply Chain
Aligning Your Team and Your Powers for Success
Leveraging Nexus Repository Manager at the Heart of DevOps

Recently uploaded (20)

PDF
KodekX | Application Modernization Development
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Machine learning based COVID-19 study performance prediction
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Big Data Technologies - Introduction.pptx
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
A Presentation on Artificial Intelligence
KodekX | Application Modernization Development
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Chapter 3 Spatial Domain Image Processing.pdf
Unlocking AI with Model Context Protocol (MCP)
Understanding_Digital_Forensics_Presentation.pptx
Network Security Unit 5.pdf for BCA BBA.
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Review of recent advances in non-invasive hemoglobin estimation
Per capita expenditure prediction using model stacking based on satellite ima...
Machine learning based COVID-19 study performance prediction
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Big Data Technologies - Introduction.pptx
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
“AI and Expert System Decision Support & Business Intelligence Systems”
A Presentation on Artificial Intelligence

Silver Lining for Miles: DevOps for Building Security Solutions