DevSecOps: Breaking Out of the Silo
When it comes to effective DevSecOps, it’s all about choosing the right solution, adding value early in the process and teamwork. Synack Director of Communications Blake Thompson Heuer sits down with Federal Solutions Architect Josh Mason to discuss how organizations can bridge the culture gap…
Overview
When it comes to effective DevSecOps, it’s all about choosing the right solution, adding value early in the process and teamwork. Synack Director of Communications Blake Thompson Heuer sits down with Federal Solutions Architect Josh Mason to discuss how organizations can bridge the culture gap between development teams who want to push out a product and security who want to find vulnerabilities faster.
Full transcript
Read transcript
Hello, and welcome to SYNAC Unplugged. I'm your host, Blake Thompson Hoyer, head of communications here at SYNAC. And joining me today is none other than Josh Mason, who is a solutions architect in the federal space here. Josh, welcome to Unplugged. Thanks for having me, Blake. We're gonna jump right into a conversation about DevSecOps. And in particular, this, old expression I've heard, a one ten, one hundred rule of, of of production. Can you tell me a little more about Yeah. So classically, in any sort of manufacturing or production,
there are several stages. There's the create like, the planning, the creation, and then once something's out in the world. Now when you have to go and fix a problem in that that system, there is a price that goes along with it. If you can solve the problem back in the planning stage, it's gonna be your cheapest fix because then you go you don't have to change any machining. You don't have to change any coding. You don't have to change anything that, like, is more than just written on paper and ideas.
Once you get into starting to build something, starting to code a program, Then if you find any issues, it has to be fixed as an idea and you actually have to fix whatever it is, the the defect in the code, in the manufacturing, wherever. Once something's out in the world, that price ten times increases. Where now you have to pull things back. There's other infrastructure there. And then you have to go through the whole process again to get it to a fixed state in cyber and in
software development. If we test something in production, the cost to fix it is gonna be super high, which is why so many people look at left of boom solutions where if you bring that testing into the development stage or even utilizing testers as part of the planning, you can make your solutions a lot cheaper. So it's interesting. You know, Synack, obviously, we're a pen testing company. We have penetration testing as a service. We are typically testing more on that production level. How do you bridge that gap?
How do you take insights from production, bring them back to development teams, maybe help some of those dev sites from production, bring them back to development teams, maybe help some of those DevSecOps folk along the way? How would you go about bridging that culture gap in between development, just wanting to push out product and security, wanting to find those vulnerabilities, fix them, maybe prevent them from occurring in the first place? Place. Yeah. Often in in house security, they've got their their role. And, traditionally, so many organizations end up siloed, and cybersecurity or security in general rests on its own. If security is able to mesh and help,
reach out and try to add value at earlier stages, because if people understand code, then they might be able to plug in and help not just find security bugs, but other bugs and quality assurance type issues and add some value earlier into the process. And if they've gone through that training, they probably also understand a bit bit of the planning. So in that organization, if they can tune in and be brought in even earlier and add some value there and try to help fix those problems in the organization.
They're not just saving the company money, but hopefully helping people have less stress and get to their final product easier. With external testers, there is the ability to start touching things while they're still in the production environment before they've gone public. And with certain missions or, getting a hacker perspective, you could actually move that even further left and have someone look at source code or be brought in during the planning process if there isn't someone in house to do that.
No lines match that search.
Speakers
Synack
Solutions Architect, Federal
Watch next
Unplugged
1 min
Nov 4, 2024
ATO Pentesting
Shifting pentesting left in the software development life cycle has numerous benefits. From a compliance standpoint to the ability to catch critical vulnerabilities before an adversary…
Katie Bowen Synack
1 min watch
Demo Series
15 min
Sep 24, 2024
Application Security Testing in the Development Lifecycle
With developers pushing out software faster than ever, organizations are looking to ensure the security of their applications so bad actors can’t take advantage of potential…
Greg Copeland Synack
15 min watch
Demo Series
11 min
Nov 25, 2025
Synack's Agentic AI Pentest for Speed and Scale
This video is a practical walkthrough of how Synack’s Agentic AI delivers fast, scalable, and high-certainty pentesting. Learn how security teams can offload high-volume compliance testing…
Mark Kuhr Synack
11 min watch
Next step
Run the test instead of evaluating the idea.
Define a scope, run a Sara AI pentest against it, and see which findings are confirmed as real and exploitable. Then compare that with what your current testing returns.


