Bridging the Gap: Uniting Security and Development

Bridging the Gap Resource Tile

In this OX Security webinar, moderator Boaz Barzel is joined by David Coral (Repsol), Ria (SAP), Miglen (Payhawk), Gabriel Enright (Vodafone Group), and Liad (Rakuten Viber) to discuss how to unite development and security. The panel digs into why the gap exists and why closing it matters, the opportunities and risks of AI and machine learning (including “Shadow AI”), and how a secure-by-design, platform approach with reusable patterns can take security off developers’ plates. They explore the cultural relationship between developers and security, how to make security actionable through clear requirements and communication, and how to treat compliance as a budgeted floor rather than a roadblock, closing with practical best practices for bridging the gap.

Key Takeaways

  • Security and development are both pillars of secure innovation. Friction between deadline-driven developers and risk-averse security hurts efficiency and morale; releasing insecure code costs far more to fix later.
  • AI cuts overhead but raises new risks. AI and ML help remove false positives and scan for malware, but they need a human in the loop and can generate insecure code at scale, including “Shadow AI” from unapproved tools.
  • Abstract security with reusable secure patterns. A platform approach bakes security into pipelines, images, and patterns so developers build in a secure environment by default, and only genuinely new gaps get deep scrutiny.
  • Make security actionable, not a 600-row spreadsheet. Translate threats and compliance into clear requirements and acceptance criteria, prioritize critical apps, and own security education, communication, and awareness.
  • Culture and empowerment beat “us versus them.” Foster security-conscious developers, share objectives (velocity and posture), use security champions, and tailor the “security suit” to the company’s DNA.
  • Treat compliance as the floor, and budget for it. Compliance is a cost and the minimum bar; a breach can end the business, so set expectations early, build the basics like identity and access management, and plan compliance into projects.

Video Transcript

Speakers

boaz li image

Boaz Barzel

View on LinkedIn

Product Marketing and Enablement, OX Security (host/moderator)

Leads product marketing and enablement at OX Security and moderates the session.

David Corral

David Coral

View on LinkedIn

Security by Design and Security Architecture, Repsol

Leads security-by-design and security architecture globally at Repsol, with over 15 years in cyber security.

Rhea Michael Anthony

Rhea Michael Anthony

View on LinkedIn

Product Security Architect Associate, SAP

A product security architect associate at SAP, focused on developing baseline security practices for AI.

Miglen Evlogiev

Miglen Evlogiev

View on LinkedIn

Head of Information Security, Payhawk

Leads information security at Payhawk (Bulgaria’s first unicorn) and founded a cyber security foundation, with a development background and time at Amazon and HP.

Gabriel Enright

Gabriel Enright

View on LinkedIn

Principal Architect, Vodafone Group

A principal architect on the platform team at Vodafone Group, delivering secure platforms across the group.

Liad Shnell

Liad Shnell

View on LinkedIn

Engineering and Security Lead, Rakuten Viber

Leads engineering and security at Rakuten Viber, a super app serving hundreds of millions of users.

FAQ

The speed of development and constantly evolving attackers make security innovation critical. Friction between deadline-driven developers and risk-averse security leads to insecure releases that cost far more to fix after the fact.

They help remove false positives, scan code for malware, and automate the identify-fix-report cycle, but they need a human in the loop and can introduce insecure code, including business-logic flaws, at scale.

Developers using unapproved AI coding tools the organization hasn’t vetted, introducing code (and potential vulnerabilities) from unknown sources, an evolution of Shadow IT that’s hard to get back out of a model.

Abstract it with reusable secure patterns, pipelines, and images so developers build securely by default, and reserve deep security review for genuinely new gaps rather than re-reviewing every project from scratch.

Explain the context, make security actionable through requirements and acceptance criteria, prioritize critical apps, foster a security-conscious culture, share objectives across teams, and empower developers to own their code.

Treat it as the minimum bar and a cost to budget into projects. Set expectations early, translate it into technical requirements, build the basics (identity and access management), and go beyond it, because non-compliance risks the business and a breach can end it.