Welcome to our in-depth article on IT security in the realm of software development. The importance of securing your software cannot be overstated, especially when digital transformation is happening at an unprecedented scale, courtesy of cloud technologies and containerization. Today, we’re synthesizing the invaluable insights from Vladyslav Cherednychenko, the Head of IT Security Engineering at About You, one of Europe’s largest Fashion eCommerce platforms.

IT-Security Insights – Why You Should Read This Article:

Comprehensive Understanding of the Importance of IT Security in Software Development:

  • Our it security article delves deep into the necessity of integrating IT Security measures right from the inception of the software development cycle. This section equips you with the knowledge of why it’s crucial to consider security as an integral part of software design.

eCommerce Expert Opinions:

  • Gain valuable insights from our Rock the Prototype podcast interview and real case information featuring IT Security and Software Development experts. Firsthand experience and advice provide a well-rounded understanding of the topic.

Actionable Steps for Implementation:

  • Don’t just learn about the “what” and “why”; we guide you through the “how”. Our article includes practical steps for incorporating IT Security into your software development processes.

Cutting-Edge Trends and Technologies:

  • Stay updated on the latest advancements in IT Security that could revolutionize how security is implemented in software development. Understanding these trends could give you a competitive edge.

Common Pitfalls and How to Avoid Them:

  • Learn about the mistakes that organizations commonly make when it comes to integrating IT Security into software development, and gain practical tips on how to avoid them.

Legal and Compliance Relevance:

  • Beyond just the technicalities, we also discuss the legal implications of not incorporating IT Security into software development, helping you understand the potential risks and liabilities.

Benefits to Business and ROI:

  • Understand how a secure development approach not only protects the organization but can also offer a competitive advantage and improve customer trust.

Whether you’re a software developer, an IT Security professional, or a business decision-maker, this article offers a comprehensive look into why and how IT Security should be an inseparable part of software development. Given the rising threats in the digital world, can you afford not to read it?

About the Expert

Vladyslav’s journey into the world of IT security began in Ukraine, where he earned his bachelor’s degree in data protection and security.

Initially starting as a DevOps engineer, he transitioned into cybersecurity, eventually completing his masters in the field.

With over five years of experience at About You, he climbed the ranks to become the Head of Information Security Engineering.

About You: More Than Just an eCommerce Platform

About You isn’t just a retail destination; it has a dual business model. Aside from its retail wing, the company has a Software as a Service (SaaS) business model called ‘Scale,’ where it offers its backend infrastructure to other eCommerce platforms. With an expertise in handling high-load systems and providing a stable eCommerce experience, About You has already acquired several customers for this service.

Vladyslav Cherednychenko - Head of IT Security Engineering at About You

Why is IT Security Critical?

The Rising Threat Landscape

Cybersecurity has never been more vital. In recent years, the rate of cyberattacks, particularly ransomware attacks, has escalated exponentially. Organisation and companies across all industries are at an increasing risk of becoming victims, paying hefty ransoms and facing reputational damage.

Regulatory Concerns and Client Demands

European governments are also tightening the screws, with regulations like GDPR coming into play. Moreover, in the B2B landscape, clients are demanding proof of robust security policies and certifications before establishing business relations.

The Cost Factor

Contrary to popular belief, investing in a dedicated IT security team is far less costly in the long run than facing the aftermath of a cyberattack. About You itself has been proactive about investing in IT security since its early days. While pentesting is a effective method it is a must to raise internal awareness of IT Security topics in any organization and to ensure internal IT Security professionals and to embed it security practices in any team.

How About You Handles IT Security: A Structured Approach

IT Security Team Composition

The company has a centralized IT security team comprising around 10 experts, with plans to expand further. This team is organized into four key circles:

  1. Application Security: This circle is responsible for internal penetration testing and code reviews. They assist other development teams in writing secure code.
  2. DevSecOps: This circle integrates security into the development processes. They employ tools that ensure both the applications and infrastructure remain secure.
  3. Governance, Risk, and Compliance (GRC): This circle ensures that the company meets all the external compliance requirements. They are regularly involved in audits and communicate the company’s security posture to potential B2B clients.
  4. Incident Response: This circle is specifically tailored to monitor infrastructure for any malicious or unusual activities and to act upon them.

Shared Responsibilities for IT Security

While each circle has its subject matter experts, there are some shared responsibilities, like incident response, to ensure that the entire team can act in case of an emergency.

Overlooking IT security is a perilous mistake that companies can’t afford anymore. At the end any organization needs to align their IT strategies to focus on security as a priority, taking a leaf from About You’s structured and comprehensive approach to managing IT security at scale.

If you are looking to bolster your IT security, it’s not just about having measures in place, but about having a continually evolving strategy to deal with an ever-changing threat landscape. After all, the safety of your company—and your customers—depends on it.

The Importance of IT Security in the Software Landscape

The cyber threat landscape is constantly evolving, with the number of cyberattacks, especially ransomware, reaching new highs year after year. As the potential costs associated with cybersecurity incidents continue to skyrocket, About You has invested heavily in  security from its early days. This is not just to comply with regulatory requirements like GDPR but also to meet the security demands of B2B clients and safeguard the company’s reputation.

IT-Security within the organizational Structure: Units and Circles

At About You, the IT security team is organized into ‘Units’ and ‘Circles.’ With over 300 developers across more than 20 software development teams, About You employs a centralized security unit, subdivided into four specialized circles:

  1. Application Security: Focuses on internal penetration testing, code reviews, and advising development teams on secure coding practices.
  2. SecOps: Integrates security tools and practices into the development processes, helping keep both applications and infrastructure secure.
  3. GRC (Governance, Risk, and Compliance): Takes care of compliance requirements, external audits, and ensuring that security policies are in place and up-to-date.
  4. Incident Response: Monitors the infrastructure for any malicious or unusual activities and responds to security incidents.

The circles work both independently on their projects and collaboratively when needed. Weekly knowledge-sharing sessions, incident response exercises, and quarterly goal-setting meetings are part of the team’s routine to maintain effective cross-functional knowledge flow.

The IT-Security Threat Landscape in E-commerce

Two significant types of web-based threats About You encounters are:

  1. Web Scraping: Automated tools that scan the website to collect data like pricing.
  2. Shopping Bots: Sophisticated bots designed to buy exclusive items, often to resell them at higher prices.

The challenge lies in differentiating these bots from genuine customer activities without impacting the user experience negatively.

IT Security Challenges and Advice

Threat Detection and Mitigation

IT security teams face the challenge of fingerprinting attackers accurately without affecting genuine users. This requires agile and innovative tooling solutions to strike a balance between user experience and security.

Infrastructure Visibility

For an organization to defend against threats successfully, complete visibility into its infrastructure is crucial. Vladyslav recommends a multi-tool approach for continuous monitoring, automated by using different tactics from both a defender’s and attacker’s perspective.

In a fast-paced digital age, IT security in software development is not just an option but a necessity. Strategies for effective threat detection, incident response, and infrastructure visibility are vital for any organization to safeguard its assets and reputation. The ongoing challenge is to balance robust security measures with a seamless user experience, a mission that companies like About You are striving to perfect.

IT Security strategies, roles and functions in IT Security teams, pentesting and improving software development and protecting IT infrastructure - Rock the Prototype Podcast

IT-Security-Strategies, roles and functions in IT-Security-Teams, pentesting and improving software development and protecting IT infrastructure – Rock the Prototype Podcast: IT Security in Software Development with Vladyslav Cherednychenko

Implementing Robust IT Security Measures in Organizations

In today’s fast-paced tech landscape, striking the right balance between innovation and security can be challenging. Here are some insights on how organizations can manage security for their software development without hindering growth.

IT Security by Default

“Security by Default” is an effective approach that allows organizations to maintain speed without sacrificing safety. Instead of building every element from scratch, engineers can utilize secure templates created by the security or operations teams. These templates for things like databases contain built-in security measures, thus saving time and ensuring adherence to security standards.

Continuous Compliance Scans

One strategy is to continuously scan your infrastructure for non-compliance. Establish what constitutes a “secure resource” and use automated tools to identify deviations. When a discrepancy is found, the responsible team can promptly correct it. This tactic is particularly beneficial when utilizing Infrastructure as Code (IaC), which helps avoid manual changes and enhances security.

Role of Red and Blue Teaming

Conducting “red team” and “blue team” exercises within the IT security team allows one group to simulate cyberattacks while the other defends against them. This approach tests the effectiveness of security measures and fosters a security-first mindset within the organization.

IT-Security and the Human Factor

Often described as the “weakest link” in cybersecurity, humans can also be the strongest line of defense when properly educated. A rapid scale-up in technology doesn’t mean that your security can scale up just as quickly. Investing in training for employees, particularly engineers, can pay off in improved risk mitigation.

Vulnerability Management

It’s not just about identifying vulnerabilities; it’s about committing to fix them. Organizations should establish clear processes for finding and resolving security flaws. Keeping a balanced ratio between discovered and fixed vulnerabilities each month prevents security risks from accumulating.

Secure Coding Guidelines and Code Reviews

Maintaining up-to-date secure coding guidelines on an accessible platform like Confluence can make it easier for developers to adhere to security best practices. Moreover, complement these with regular code reviews and white-box penetration tests to ensure that your codebase remains secure.

IT Security Tools and Technologies

While the specific tools used may vary and be considered sensitive information, many organizations trust a blend of open-source, commercial, and custom-built solutions. Services like AWS and Cloudflare offer robust security options, which can be used in conjunction with code scanners and other vulnerability management tools.

Recommendations for Startups

For companies just starting to focus on IT security, it’s crucial not to over-engineer solutions. First, take care of the basics and cover as much ground as possible with minimal time investment. As you identify the most significant threats, then you can invest more resources into specialized solutions.

Shift Left Approach

The “Shift Left” approach emphasizes the importance of introducing security measures as early as possible in the development process. Early identification of issues can save enormous amounts of time and money compared to rectifying a fundamental problem after launch.

By incorporating these strategies into your organizational processes, you not only build a more secure infrastructure but also foster a culture of security-awareness that empowers your team to be proactive rather than reactive in dealing with IT security challenges.

Surprising Outcomes of Neglected IT Security

When it comes to IT security, it’s all about preventing what you don’t see coming. One example from our experience demonstrates this well. In the early stages of developing our scalable product offering, we found significant vulnerabilities during penetration tests. These tests exposed security gaps, especially in identity and access management. Without this testing, we could have unknowingly exposed our clients to severe risks.

Team Collaboration in IT Security

Our team comprises various roles, such as developers, DevOps engineers, platform engineers, and security engineers, among other typical corporate roles like product owners and managers. A majority of the work, including writing and deploying the code, takes place within development teams. Security concerns are addressed by specialized security engineers, but sometimes, barriers exist between the development and security teams. This can be due to a lack of familiarity or prior collaboration.

Effective Communication Strategies

One way to improve this collaborative culture is by establishing routines that encourage interaction between teams. Effective communication doesn’t have to be formal; a more personal connection often makes it easier for team members to ask questions or seek advice. This helps the security team establish a reputation for being helpful rather than punitive, thereby fostering better collaboration.

Challenges and Opportunities in Collaboration

The primary challenge in collaboration often comes down to a misalignment of priorities. While security engineers might push for immediate fixes to vulnerabilities, it’s essential to understand that development teams also have other tasks to focus on. Business needs must be balanced with security requirements. One way to improve this balance is through ongoing engagement from the security team – not just identifying vulnerabilities but also helping development teams understand and fix them.

The Future of IT Security: AI and More

The landscape of IT security is rapidly evolving, with significant developments like the integration of Artificial Intelligence (AI) and centralization of tooling. While AI has been around for a while, it’s becoming increasingly important in threat detection and response. However, implementing AI isn’t without its challenges. The risks include potential model poisoning, increased alert fatigue due to false positives, and false negatives where the AI model fails to detect real threats.

These are just a few possibilities for increasing your it security level with support of AI. Remember that the human factor’s essential. The integration of IT security within the software development process is not just a technical endeavor; it also hinges on the human element. While technology like AI can bolster your security measures, the insights and judgments of a skilled IT security team are invaluable. Learn how to effectively blend technology and human expertise for a secure software development lifecycle.

Implications for Software Development

AI also poses both challenges and opportunities for software development. One concern is that AI models, trained on historical data, might propagate past errors or vulnerabilities. But on the flip side, AI can speed up development processes, although it should not replace human judgment.

Conclusion

IT Security is not just a necessity but a must-have in today’s technology-dependent world. It requires ongoing vigilance and a collaborative approach. Striving for small, incremental improvements in your company’s security posture can yield significant benefits in the long run. It’s better to advance by 1% every day than to stay stagnant. This incremental progress could make all the difference in your company’s future of an secure infrastructure and software landscape.

About the Author:

Sascha Block

I am Sascha Block – IT architect in Hamburg and the initiator of Rock the Prototype. I want to make prototyping learnable and experiential. With the motivation to prototype ideas and share knowledge around software prototyping, software architecture and programming, I created the format and the open source initiative Rock the Prototype.