O
11
c/devsecopsjamie794jamie7941mo ago

Overheard a junior dev say 'security is a blocker' and I had to bite my tongue

Last week in a standup, one of our junior folks called the vuln scan gates 'a blocker' and asked why we can't just deploy and patch later. I get the speed pressure, but we had a CVE in a library two years ago that took down a payment endpoint for 6 hours on a Monday. That outage cost us around $14k in lost transactions and three angry customers. Has anyone else dealt with a team that sees early security checks as friction instead of insurance, and how do you get them to buy in without sounding like the compliance police?
1 comments

Log in to join the discussion

Log In
1 Comment
luna_craig58
Oh boy, my friend's team skipped a scan once and lost a whole day to a bad library update, never again.
2