Survey Surfaces Lots of Room for DevSecOps Improvement
好的,我现在要帮用户总结这篇文章的内容,控制在100字以内。首先,我需要快速浏览文章,抓住主要信息。 文章讲的是一个针对506名网络安全领导和从业者的调查。结果显示,虽然80%的人表示安全和DevOps团队在使用共享的可观测性工具,但只有45%的人认为这两个团队在工具和工作流程上非常一致。这说明尽管他们在使用相同的工具,但协作仍有很大的改进空间。 另外,93%的受访者所在组织使用至少三种安全运营工具,其中45%使用六种或更多。超过一半的人认为他们有太多点解决方案,而100%的人认为统一的日志、指标和跟踪平台对安全和DevOps团队有价值。这表明他们意识到整合工具的重要性。 还有,调查发现很多网络安全团队对自己的工具缺乏信心。虽然92%的人认为他们的SIEM平台有效减少了检测和响应威胁的时间,但只有51%的人认为非常有效。同样地,虽然92%的人认为他们的SIEM平台能够扩展以满足需求,但只有52%的人非常有信心。 此外,云的采用推动了安全和云运营工具的现代化,75%的人表示云采用驱动了现代化。同时,70%的人表示他们已经完全或大部分自动化了威胁检测和响应过程。 最后,AI和机器学习工具被广泛认为是减少警报疲劳和提高检测准确性的关键。96%的组织已经采用了AI到一定程度。 总结一下:调查揭示了安全与DevOps团队在协作、工具整合以及对现有解决方案的信心方面存在挑战,并强调了云和AI在未来的潜力。 </think> 一项针对506名网络安全领导者的调查显示,尽管80%的安全与DevOps团队正在使用共享的可观测性工具,但仅45%的受访者认为双方在工具与工作流程上高度一致,表明两支团队间的协作仍存在较大改进空间。 2026-1-28 19:56:31 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

A survey of 506 cybersecurity leaders and practitioners working for organizations with more than 500 employees, published today, finds that while 80% report security and DevOps teams are using shared observability tools, less than half (45%) say the two teams are very aligned on tooling and workflows compared to 43% that said these teams are somewhat aligned

Conducted by the research firm UserEvidence on behalf of Sumo Logic, the survey also finds 93% of respondents work for organizations using at least three security operations tools, with 45% using six or more. More than half (55%) said they have too many point solutions in their security stack and all (100%) agreed that a unified platform for logs, metrics, and traces would be valuable for their security and DevOps teams.

Chas Clawson, vice president of security strategy at Sumo Logic, said the survey makes it clear that there is still significant room for improvement when it comes to collaboration between DevOps and cybersecurity teams even though many of them are now finally using the same observability tools and platforms.

For example, only 37% strongly agree that their security tooling is designed for modern application environments and a full 87% agree that unified security and monitoring tooling would improve team efficiency. A full 89% also agree that real-time threat detection is a top priority for their team.

As development velocity increases and applications require more sophisticated features and integrations, respondents noted that factors such as application complexity (56%) and DevOps acceleration (51%) prompt their organizations to update tooling, the survey finds.

Additionally, the survey finds that many cybersecurity teams lack confidence in their tools. Even though 92% say their current security information event management (SIEM) platform is effective at reducing mean time to detect and respond to threats, only slightly more than half (51%) said their current SIEM platform is very effective at reducing mean time to detect and respond to threats.

Similarly, even though 92% said their current SIEM platform scales to meet their needs, only 52% are very confident their current SIEM can scale to meet future security and cloud operations needs, a capability that 90% of respondents described as being important. On average, respondents ingest 4.14 data sources into their SIEM, with 36% using five or more data sources.

However, the number of data sources is likely to exponentially increase in the age of artificial intelligence (AI) which suggests that many legacy SIEM platforms will not be able to keep pace as the number of data sources continues to increase, noted Clawson.

In total, nearly half (48%) have adopted a cloud and on-premises mix of platforms, while 37% have a multi-cloud strategy. Three quarters (75%) said cloud adoption drives modernization for security and cloud operations tooling, with 88% reporting that cloud-native platforms simplify their security operations

Overall, the survey finds 70% of respondents say they’ve fully or mostly automated their threat detection and response process, with 25% reporting that those processes are fully automated.

A total of 63%, however, also said high operational cost is their biggest pain point, while 55% report struggling with too many point solutions in their security stack.

A full 90% also said artificial intelligence (AI) and machine learning tools are extremely or very valuable in reducing alert fatigue and improving detection accuracy, with nearly all (96%) reporting their organization has adopted AI to some extent.

It’s not clear to what degree AI might one day drive organizations to restructure their IT teams, but it is apparent fundamental change is coming. The issue now is determining what tools and platforms might be required to reduce the current level of friction that makes change more difficult than anyone wants to experience.

Recent Articles By Author


文章来源: https://securityboulevard.com/2026/01/survey-surfaces-lots-of-room-for-devsecops-improvement/
如有侵权请联系:admin#unsafe.sh