Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Fact Or Fiction: Dispelling Low-code Security Misconceptions In The Age Of The Citizen Developer
Articles

Fact Or Fiction: Dispelling Low-code Security Misconceptions In The Age Of The Citizen Developer

Yad JauraBy Yad JauraDecember 23, 2021Updated:January 9, 20234 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
US Offers $10 Million For Russian Ransomware Operator's Capture
US Offers $10 Million For Russian Ransomware Operator's Capture
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The burgeoning skills gap, an urgent lack of coders and the need for growing businesses to transform at pace has ushered in a rise in citizen developers over recent years. When empowered with low-code platforms, which require minimal or no actual code, these developers can create applications by themselves with very little intervention from IT.

However, whilst the revelation that application development can be placed in the hands of anyone within the business is a positive one, there is also a growing concern that, by doing so, security could be at risk.

Last year, it was estimated that internal security misconfigurations accounted for as many as 10% of all breaches, with one of the most recent – and prolific – being the Microsoft Power Apps data leak. Due to the incident, 38 million personal information records across more than 1,000 web apps were said to have been exposed, including particularly sensitive information such as COVID-19 contact-tracing details, vaccination appointments, social security numbers and millions of names and email addresses.

Inevitably, such an event caused many to question the security surrounding low-code tools and with it, a handful of misconceptions have started to emerge. Here we uncover the current myths and misconceptions associated with low-code development, distinguishing fact from fiction to reveal how businesses can reap the benefits such tools have to offer, whilst ensuring the security of their organisations.

Misconception #1:

Development should be left to the experts, or else security is at risk

The Microsoft Power Apps incident certainly cast doubt over the security of applications developed using low-code, with many quick to put this down to the skills gap associated with citizen developers. However, vulnerabilities can be introduced by IT teams and even pro-developers, the very people assumed to be the savviest about such risks. In fact, this was the case for Microsoft, where a default security setting was missed by a pro-developer.

Whilst an easy miss in this situation, it is important to note that most professional developers step into their first role without any security training. Few computer science degrees focus on security, and most don’t even stipulate a single secure development or secure design course. 

Ultimately, whilst those not specifically trained in development can be less conscious of the security implications, the issue isn’t exclusive to citizen developers. As we’ve seen, even pro-developers can get it wrong sometimes.

Misconception #2:

Low-code is less secure than other development software

False. Low-code isn’t inherently less secure than other software. In fact, it’s generally more secure, as enterprise low-code platforms include prebuilt security and governance controls for every application. These platforms provide visual tools and building blocks for speeding up and simplifying app development, making it easier to develop technically secure apps versus traditional coding.

But, like professional coding tools or other software products, low-code can still be misconfigured – as evidenced in the Microsoft Power Apps incident – and security defaults can be insufficient.

Instead, there is a real need for experts to review the security defaults and configurable guardrails of low-code platforms, aimed at scaled citizen developer programs, as well as ensuring that security awareness is part of any internal development strategy.

It’s crucial that businesses consider prevention, not cure, and since low-code platforms vary in their security offerings, the onus is on business leaders to select a platform with sensible security defaults.

Misconception #3:

Once I choose a low-code provider, security is out of my hands  

Wrong again. The security guardrails surrounding low-code can vary drastically from provider to provider. That’s why choosing the right supplier is essential to ensure security is prioritised. To help maintain development security, find out what security, management and governance controls are provided by your chosen low-code provider and make sure you understand what controls you will have and how those controls will be assigned. It may seem obvious, but it is also important to check what data security and privacy controls are included.

Fact:

Low-code is a powerful tool for development, but only with the right guardrails in place

Low-code, when used by citizen and pro-developers, can empower businesses to turbo-charge transformation and its potential shouldn’t (and needn’t) be overshadowed by security fears. Much like any technology, the possibilities of low-code development are endless, but it does require the right guardrails to be put in place to embrace it effectively.

When used and managed successfully, low-code can add a greater level of protection to a business – without stifling innovation. With pressure surrounding digital transformation always on, and growing increasingly competitive, innovative and digitally-savvy organisations must not abandon security in the race to break new ground.

Yad Jaura

Yad Jaura, Product Marketing Manager at Netcall

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

    June 10, 20255 Mins Read

    Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

    May 13, 20254 Mins Read

    Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

    May 13, 20253 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}