Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Adding A Human Firewall: The Role Of Developers In Protecting The Supply Chain
Articles

Adding A Human Firewall: The Role Of Developers In Protecting The Supply Chain

Matias MadouBy Matias MadouOctober 24, 2022Updated:December 8, 20224 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Supply Chain Cyber Security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In 2022, some of the world’s biggest technology companies, including Microsoft and T-Mobile, fell victim to attacks by the cybercrime group LAPSUS$, with members of the hacking group operating from the UK and Brazil. While the breaches differed in scope and size, many of them made active use of vulnerabilities in third-party applications to access a company’s network.

Once inside, the LAPSUS$ attackers could steal valuable data or hold the company to ransom, threatening to steal the source code of their most sensitive products unless they were paid.

While LAPSUS$ has earned a particular reputation for high-profile targets, these kinds of attacks are no longer out of the norm. In fact, over the past 18 months, they have become especially prevalent with a growing number of bad actors looking to exploit technology applications that offer security vulnerabilities.

Many organisations will naturally want to throw money and technology at the problem, but, in fact, the best line of defence is people, in particular, the software developers many businesses already employ in-house. Let’s explore how developers can serve as a “human firewall” in the technology supply chain to secure applications used as gateways to network access.

Looking into the data

Organisations first need to be aware that the software products they frequently use feature inherent bugs and security flaws. This is typically the result of a stressed application development cycle that prioritises speed and functionality above security.

In partnership with Evans Data, Secure Code Warrior polled 1,200 active software developers in December of 2021 for our State of Developer-Driven Security Survey. The numbers highlighted some alarming industry trends, chief among them that 67% of developers admitted that they routinely left known vulnerabilities and exploits in their code.

This is not generally the fault of the developers themselves, but rather that of the systems they work in. Under the constant pressure of tight deadlines, these employees prioritise functionality over security. Many also lack security-related training or any real knowledge about fixing common code-level security problems.

Only 14% of those surveyed said application security was their top concern during development, falling behind priorities such as code quality, application performance, and the ability to solve real-world problems.

Making use of in-house development

To make security improvements, organisations need to lean on and rely on their development team. Properly-trained in-house developers can act as a firewall for company systems, writing software that is inherently secure, and overseeing best practice access control in elements like APIs to improve the      overall security posture of the business.

Developers have a front-row seat to an organisation’s security challenges and can strengthen security practices that match how employees leverage applications. In-house developers are at the front lines      of cyber defence. Given time and comprehensive training, these developers can fortify software with appropriate security measures.

As we’ve seen from the SolarWinds breach and others like it, supply chains will remain a key area for attack. Since these types of platforms can ship with vulnerabilities, in-house developers can provide additional security features to close these down.

Ideally, platform vendors will improve the cybersecurity of their platforms before shipping, but it may take a rash of more high-profile breaches before that happens. Business consumers cannot continue to operate in a world where the security of their platforms is unknown. Work with your development      team to add security features to avoid these types of attacks.

Change needs to happen now

Organisations continue to face cyber threats from a wide range of different sources. The reliance on automation, tools, and a reactive response to security incidents has long stood alone, but the increasingly sophisticated threat landscape requires more vigorous defence.

A human-led approach to software security leveraging security-skilled developers can close this gap. Organisations must focus on the talent already in their business to help improve the security posture and reduce supply chain-embedded vulnerabilities. Often, developers want to learn these skills but lack the time or incentive to do so. Improved training that empowers them, together with automation and security tools, can provide a pathway to long-term success that was previously unachievable.

Matias Madou

Co-founder and CTO

  • Matias Madou
    How Can Organisations Protect Themselves From Cyberattacks In An Increasingly Virtual World?
  • Matias Madou
    How To Become A Kick-Ass DevSecOps Engineer
  • Matias Madou
    Why SQL Injections Are The Cockroaches Of The Appsec World (and how CISOs can eradicate them once and for all)

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read

OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

January 22, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}