article thumbnail

Beyond DevSecOps: Why fintech companies need to consider DevSecRegOps

CIO Business Intelligence

As the vice president of enterprise architecture and technology strategy at Discover Financial Services, I think about this question often as we work to design our tech stack. As a practice, DevSecOps is a way to engrain practices in your SDLC that ensures security becomes a shared responsibility throughout the IT lifecycle.

Company 361
article thumbnail

7 types of tech debt that could cripple your business

CIO Business Intelligence

Just as no one wants to run mission-critical systems on decade-old hardware, modern SDLC and DevOps practices must treat software dependencies the same way keep them updated, streamlined, and secure. The average app contains 180 components , and failing to update them leads to bloated code, security gaps, and mounting technical debt.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Scaling security: How to build security into the entire development pipeline

CIO Business Intelligence

That’s why Discover® Financial Service’s product security and application development teams worked together to shift security left by integrating security by design and conducting early security testing often to identify vulnerabilities prior to hitting deployment. There’s a security issue.”

Security 306
article thumbnail

What CEOs really need from today’s CIOs

CIO Business Intelligence

Modern delivery is product (rather than project) management , agile development, small cross-functional teams that co-create , and continuous integration and delivery all with a new financial model that funds “value” not “projects.”.

article thumbnail

The hidden cost of insecure code: More than just data breaches

CIO Business Intelligence

When significant breaches like Equifax or Uber happen, it’s easy to focus on the huge reputation and financial damage from all that compromised user data. The financial damages and customer impacts are immediate and substantial. For sure – those headline costs are massive, no question.

Data 283
article thumbnail

How to make your developer organization more efficient

CIO Business Intelligence

To combat wasted time and effort, Discover® Financial Services championed a few initiatives to help developers get back to what they do best: developing. Employing automation for tasks that many engineers face throughout their SDLC helps to shift focus towards human value-add activities. The result?

article thumbnail

Safeguarding Ethical Development in ChatGPT and Other LLMs

SecureWorld News

Hostile threat actors assume the role of a medical provider, financial institution, or other legitimate supplier (impersonation). Why should AI get a pass on S (Secure) SDLC methodologies? Imagine a sophisticated attacker who cunningly injects malicious prompts into an LLM to manipulate its output and deceive unsuspecting users.