Secure By Design, Secure By Default
DevOps.com, Tuesday, October 14th, 2025
'Shift left' has become a favorite mantra of engineering, IT and software teams. The idea is simple: Move critical practices earlier in the development process so that problems can be caught sooner and fixed more cheaply.
It started with testing, then design, then DevOps, and now it's security's turn. Secure by design, secure by default. Just shift it left.
But there's a problem. If you shift everything left, what's on the right?
The term 'shift left' sounds appealing, but it's based on the notion that software development is a neat, linear process with design on the left and production on the right. That model might make sense on a Gantt chart, but real-world software is complex and messy. And complex and messy have important implications for how to think about security.