DevSec For Scale Podcast – Security Best Practices w/ Dr. Chase Cunningham
In this inaugural episode of the “DevSec for Scale” podcast, hosted by Jeremy Hess from Akeyless, the discussion revolves around the importance of embedding security within the development lifecycle, especially for startups. Jeremy introduces Dr. Chase Cunningham, known as Dr. Zero Trust, the creator of Forrester’s Zero Trust Extended framework. Chase shares his insights on how small businesses often underestimate their value as targets for cyberattacks, emphasizing the necessity of proactive security measures to protect intellectual property and resources. The conversation highlights the need for a shift-left approach to security, integrating it into the development pipeline from the onset to avoid costly refactoring later.
Dr. Cunningham elaborates on the misconception among small businesses that they are insignificant targets for cyber threats. He explains how even minimal setups with a few developers can face substantial security challenges due to the rapid expansion of access points and resources. Crypto-jacking, where adversaries hijack cloud resources for cryptocurrency mining, is cited as a prevalent threat. Chase stresses that security should be an integral part of the development process, not an afterthought. He advocates for robust identity and access management to safeguard against breaches, highlighting the inefficacy of traditional, piecemeal approaches like spreadsheets for managing security.
The discussion concludes with a focus on practical steps for small businesses to enhance their security posture. Dr. Cunningham advises startups to identify and manage their assets and implement effective identity and access management practices. He emphasizes that security solutions should be lightweight and seamlessly integrated into the development workflow to avoid hindering productivity. The conversation also touches on the broader implications of security in business, such as compliance and the competitive advantage of demonstrating strong security practices. Ultimately, the episode underscores the critical role of security in the growth and success of startups.