Cloudanix Joins AWS ISV Accelerate Program

Codifying Security: The Evolution from Detection to Prevention in Cloud Native DevSecOps

Master DevSecOps by codifying security. Learn to solve the Maker-Checker problem, prioritize via EPSS, and move toward 100% automated cloud-native remediation.

The transition from DevOps to DevSecOps is not just about adding a security person to the room; it is about fundamentally codifying security into the infrastructure itself. As organizations move from on-premise “pet” ecosystems to ephemeral cloud-native environments, the strategies for securing them must evolve from simple detection to automated remediation and prevention.

We spoke with Kayra Otaner, Director of DevSecOps at Roche, about this evolution. With over 20 years of experience across Wall Street, ADP, and FICO, Kayra offered a masterclass on structuring DevSecOps for scale, the “maker-checker” problem in automation, and why culture always eats strategy for breakfast.

You can read the complete transcript of the epiosde here >

How has DevSecOps evolved beyond just “Shifting Left”?

The popular definition of “shift left” is synonymous with early detection, but that is only the first phase.

  • Beyond Detection: While detection is critical, the industry is seeing a huge step toward auto-remediation and prevention capabilities.
  • The Log4j Reality: Kayra uses the Log4j incident as a prime example. Detecting 10,000 instances is useless if you cannot remediate them. The evolution of DevSecOps is about closing the loop—detecting, preventing, and remediating issues automatically.
  • True DevSecOps: The field is moving away from being two separate disciplines (DevOps + SecOps) into a complete loop where prevention technologies play a central role.

What is the difference between implementing DevSecOps in small vs. large organizations?

There is no “one size fits all” approach. The strategy depends entirely on the resources available.

  • Small Organizations (The Startup Model): In a small setup, you might have 10 developers, 5 ops members, and only 1 security person. Here, the only viable path is to upskill the developers to do more security work—essentially creating a “security escrow” model.
  • Large Organizations (The Enterprise Model): Large enterprises have the resources to flip this model. Instead of asking developers to do security, they upskill security practitioners to do development.
    • Dedicated Pipelines: Security teams build separate, dedicated pipelines (pre-commit hooks, pre-push hooks) that run security checks on behalf of the dev teams.
    • Zero Trust Pipeline: This approach, which Kayra presented at RSA, decouples security from the developer’s direct responsibility, allowing security teams to operate checks without slowing down the primary CI/CD flow.

How do you balance speed and security without becoming the “Team of No”?

Security is often viewed as a speed bump. To change this, security teams must rebrand themselves from the “Team of No” to the “Team of How”—showing developers how to implement security easily.

To balance this, organizations should use a tiered tollgating strategy rather than a blanket policy:

  • Tier 1 (Mature Teams): Teams that model good behavior and have secure threat models get a “rating” (e.g., 7/10) rather than a hard block.
  • High Risk (Critical Apps): Teams handling sensitive data or high monetary volume get strict tollgating with “four eyes” on everything.
  • Below Average Metrics: Teams that fall below the organizational median for vulnerability-per-developer ratios are automatically targeted for stricter checks.

Why is the “Maker-Checker” problem critical in Security Automation?

Automation is key, but Kayra warns against a fundamental flaw in many DevSecOps implementations: asking developers to write their own security policies.

  • Codifying Security: Just as DevOps is codifying infrastructure (Terraform, Ansible), DevSecOps must be codifying security.
  • The Maker-Checker Problem: You cannot ask the person building the software to also write the code that checks if it is compliant. This violates the segregation of duties.
  • Segregation of Duties: Policy-as-Code (using tools like Rego or Checkov) must be owned and written by dedicated security professionals, not the developers. This ensures an independent audit trail and avoids the conflict of interest inherent in self-policing.

How should organizations approach Cloud Native Security?

Moving to the cloud requires a shift from “lift and shift” to understanding the 4 Cs of Cloud Native Security:

  1. Cloud
  2. Cluster
  3. Container
  4. Code
  • The Container Advantage: The true benefit of the cloud is not just running VMs elsewhere, but leveraging containerization to minimize risk. By using distroless or properly hardened images, organizations can minimize the attack surface they inherit from open source software.

  • Decoupling: Cloud native security requires decoupling security mechanics from the OS level (the “pet VM world”) and managing them via the control plane or CRDs (Custom Resource Definitions) inside the cluster.

How can teams manage the overwhelming volume of Supply Chain Vulnerabilities?

With an average of 77 CVEs disclosed every day, manual management is impossible.

  • Prioritization via EPSS: Organizations must stop assuming every CVE is exploitable. Instead of relying solely on CVSS scores, they should use the Exploit Prediction Scoring System (EPSS). This data-driven approach predicts the likelihood of exploitation, allowing teams to prioritize the vulnerabilities that actually matter.
  • Immutable Infrastructure: By focusing on proper containerization and immutable infrastructure, the reliance on patching live systems diminishes. You cannot go back and fix a library like Log4j on a live system easily; you must rely on rebuilding hardened containers.

What is the future of DevSecOps and AI?

The landscape is moving toward three distinct tracks that must execute simultaneously:

  1. Detection: Expanding capabilities to near 100%.
  2. Auto-Remediation: Currently, less than 10% of issues are auto-remediable, but vendors like Moderna and OpenRewrite are pushing this toward 20-30% in the next few years.
  3. Prevention: The ultimate goal is preventing issues before they exist using cloud-native build packs and proper architecture.

The Role of AI: Tools like ChatGPT and Copilot play heavily into the auto-remediation space but are not yet reliable enough for prevention. They should be used experimentally (reliable ~80% of the time) to speed up fixes, but not relied upon blindly.

Conclusion: The Three Pillars of Modern DevSecOps

Kayra O’Tanner’s insights make it clear: DevSecOps is no longer just a buzzword for “culture.” It is a technical discipline defined by codifying security.

To succeed, organizations must move beyond simple detection and embrace the three pillars simultaneously:

  • Detection (finding the bad).
  • Auto-Remediation (fixing the bad automatically).
  • Prevention (stopping the bad from entering).

By acknowledging the “maker-checker” problem and utilizing advanced metrics like EPSS, security teams can finally move at the speed of development without compromising on risk.

People Also Read

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo