SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Beyond DevSecOps: Why Devs and SecOps must unite for API and AppSec protection

Beyond DevSecOps: Why Devs and SecOps must unite for API and AppSec protection

Mon, 14th Sep 2026 (Today)
Gajendran Subramaniam
GAJENDRAN SUBRAMANIAM Senior Manager – Managed Security Services Fastly

Open and strong lines of communication and engagement between engineers and analysts is more important than ever when trying to combat a rapidly evolving threat landscape. With APIs now serving as a primary attack vector for modern business, the value of a close, continuous relationship between the builders of web and mobile applications and the security teams protecting them has skyrocketed.  

To date, the industry has focused heavily on "Shifting Left." Developers have had to adopt a security mindset, incorporate secure-by-design principles and deploy formal security gates into their CI/CD pipelines. While these DevOps efforts mean fewer vulnerabilities reach production, a critical question remains: what happens after that application or API goes live?

This is where organisations must "Shield Right," ensuring ongoing protection through active threat hunt and traffic monitoring, often via an outsourced Security Operations Centre (SOC) or Managed Security Services (MSS). 

Turning your SOC from a black box into a strategic partner

A managed security service arrangement, whether an outsourced SOC, or through a red, blue or purple team threat hunting capability, is only as effective as its understanding of the environment, systems and application estate it's been engaged to protect.

That's why it's critical for developers to explain to the SOC team how their system works, why certain design decisions were made, what are its dependencies or interdependencies, what constitutes 'normal' in terms of API operation and traffic profile, and how the system is intended to respond to the anomalous conditions. Where a SOC lacks this knowledge or visibility, determining whether an observed traffic pattern represents legitimate or potentially malicious use is incredibly difficult.

Feature

Siloed Approach (The Old Way)

Integrated Dev & SecOps (The New Way)

Knowledge Sharing

SOC operates blindly on black-box applications and APIs.

Devs share architecture, API schemas, and traffic baselines with SOC.

Security Phasing

Security is an afterthought or gatekeeper before launch.

Security is embedded from design (Shift Left) to continuous monitoring (Shield Right).

Incident Response

Ticket ping-pong; Devs and SOC use different terminology.

Unified response using a shared language and common tooling.

Consider a common scenario: A new API endpoint is pushed to production.  In a siloed environment, the SOC might flag a sudden, expected spike in legitimate traffic as a DDoS attack causing unnecessary downtime and panic. In an integrated environment, the SOC already knows about the launch, recognises the baseline traffic, and focuses instead on hunting for actual malicious payload anomalies.

High-performing organisations take this a step further by giving security operations personnel a seat at the table during new application builds. This level of early involvement provides massive benefits to the organisation's overall security posture, including:

  • Proactive Design: SecOps can influence the build to create operational efficiencies for ongoing management and protection later.
  • Deep Context: Operational teams gain an inside line on how the application or API is intended to function, thereby eliminating guesswork.
  • Shared Language: When a threat emerges, engineers and analysts can communicate using the exact same terminology in bug reporting and tickets, dramatically speeding up remediation.

Tight integration means everyone is on the same page. Applications are securely built and can be protected with the benefit of knowledge on an ongoing basis.

Actionable steps to align your teams today

A well-skilled managed security services provider has vehicles available to help open and strengthen communication lines between software engineering and security operations.

Readiness drills that are conducted at the start of a managed services engagement are one such vehicle. These drills simulate attack response to improve a customer organisation's preparedness. Crucially, they afford the organisation an opportunity to fine-tune its security strategy while identifying personnel-related gaps, particularly around communication and coordination, inviting an open dialogue on how to address them.

In conclusion, while organisations certainly benefit from managed security services, those benefits multiply when developers and SecOps break down their silos. By sharing API schemas, understanding traffic baselines, and maintaining a continuous feedback loop, you ensure your applications are not just securely built, but resiliently protected.