Introduction to the Security Landscape
Production endpoints have long been seen as attack points and are thus defended with robust measures. In response, attackers have pivoted to compromise applications in development. Tools and components, from your code editors to your build and delivery processes, are now under attack.
That’s what we want to focus on in this book—exploring and detailing how to develop secure applications. It focuses on points in the software development life cycle (SDLC) where your products or procedures could be compromised before going live and discusses ways you can prevent or defend against such attacks.
This book also includes real-world hack incidents. These incidents are intended to help break down how a hack happened—how the attackers gained access to applications, what they did with the applications, and how it impacted the company and its customers—to arm you with the necessary facts to keep your applications secure.
These facts serve two purposes:
- Help you evaluate the recommendations in this book and develop effective strategies and implementations for your company
- Provide verifiable data points to drive buy-in across the spectrum of stakeholders you influence
Note
When mentioning the companies involved in these incidents, please understand that the intent is not to shame them or create a sense of sensationalism. All stories shared in this book were already reported in the press. By not anonymizing them, the goal is to maintain transparency, allowing you to verify the details if you wish, while also saving you the effort of doing so.
GitGuardian has been helping companies defend their applications and resources since 2017 and has over 500,000 customers using their software and services with both on-premises and cloud options available.
This book is designed to give software development managers, department heads, and C-level professionals an evidence-based overview of the threat landscape for application development and provide actionable insights that will help their teams develop securely throughout the SDLC, from ideation to monitoring in production.