Tech »  Topic »  The patching treadmill: Why traditional application security is no longer enough

The patching treadmill: Why traditional application security is no longer enough


Find-and-fix security once made sense, but AI-assisted development, continuous deployment, and exploding vulnerability backlogs are changing the rules. The old application security playbook is breaking down fast.

Dmitry Nogaev/iStock/Getty Images Plus

Follow ZDNET: Add us as a preferred source on Google.

ZDNET's key takeaways

  • Continuous deployment makes old security models feel obsolete.
  • Vulnerability backlogs are overwhelming development teams.
  • Application security needs to move toward code creation.

For all the time I've spent exercising on treadmills, I've always found them faintly demoralizing. You thump-thump-thump over and over again, but get nowhere. It's a lot of effort. You always work up a bit of a sweat, but ultimately feel unfulfilled. This feeling is reinforced the next day, when you have to do it all over again.

In many ways, application security is like that treadmill. Once the coding is done, security teams (or customers) find flaws ...


Copyright of this story solely belongs to zdnet.com . To see the full text click HERE