> Markdown version of [/videos/41-you-can-t-hack-what-you-can-t-see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # You can’t hack what you can’t see Traditional boundary firewalls are obsolete. Since 80% of cloud traffic is internal, perimeter breaches are devastating. Harness microsegmentation and zero trust to make workloads invisible to attackers. - **Speakers:** Reto Kaeser - **Event:** WeAreDevelopers LIVE - **Published:** October 12, 2020 - **Duration:** 29:34 - **URL:** https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see ## Summary Integrating security into the DevOps culture is essential for modern software development, moving it away from being an isolated "ops problem" deployed as an afterthought. By "shifting security left" and tackling vulnerabilities early in the software development lifecycle, engineering teams can build fundamentally stronger architectures. A practical first step during the requirements phase is identifying "abuse cases" alongside use cases; anticipating these attack vectors proactively maps out security needs and provides targeted input for red teams conducting continuous penetration testing. As infrastructure abstracts into hybrid clouds, containers, and serverless functions, traditional boundary firewalls are no longer sufficient. Today, up to 80% of communication in cloud architectures is internal "east-west traffic," meaning malicious actors who breach the perimeter can move freely if given the chance. Defending against these application-layer threats requires microsegmentation—putting a logical firewall in front of every workload based on zero trust architecture. Instead of blacklisting bad actors, developers must define clear communication intent by whitelisting trusted workloads, ultimately limiting the blast radius of any potential network breach. Effectively scaling DevSecOps relies heavily on automation, secure design principles, and "security as code." Designing with data classification, pseudonymization, and anonymization limits exposure of restricted information even in worst-case scenarios. Meanwhile, integrating vulnerability management tools via pre-commit hooks to scan open-source libraries prevents known exploits from ever reaching production. By embedding granular security policies directly into configuration and staying vigilant, developers take true ownership of the workloads they deliver, ensuring continuous compliance and securing agility in the cloud. **Keywords:** devsecops culture, shifting security left, abuse case modeling, continuous penetration testing, open-source vulnerability management, east-west traffic protection, microsegmentation strategies, zero trust architecture, data classification techniques, pseudonymization practices, data anonymization limits, application layer attacks, workload protection, security as code, logical firewalls, real-time compliance, cloud deployment security ## Chapters 1. **Evolving from siloed operations to DevOps culture** (00:17) — Culture plays a massive role in successful DevOps adoption beyond tooling. 1. **Integrating security into the DevOps lifecycle** (02:26) — Left-shifting security creates DevSecOps to protect modern remote workloads. 1. **Identifying abuse cases during requirements gathering** (03:46) — Addressing potential attack vectors early hardens architecture before design begins. 1. **Security challenges of workload abstraction in cloud environments** (07:02) — Containerizing and moving workloads introduces fine-grained connection risks. 1. **Classifying and anonymizing data during system design** (08:48) — Treating restricted data carefully and avoiding unnecessary context reduces exposure risk. 1. **Managing vulnerabilities in open-source libraries early** (11:26) — Catching vulnerable component versions using pre-commit hooks saves downstream remediation time. 1. **Leveraging continuous penetration testing via red teams** (14:27) — Feeding abuse cases directly to testers improves ongoing security posture. 1. **Protecting internal east-west traffic within networks** (16:19) — Shifting focus from external firewalls to safeguarding internal communications between services. 1. **Securing individual workloads systematically at the application layer** (19:01) — Moving security policies away from infrastructure to surround the data directly. 1. **Implementing logical firewalls to enforce microsegmentation** (20:20) — Defining communication restrictions workload-by-workload limits the radius of potential breaches. 1. **Adopting zero-trust principles and whitelisting intentions** (22:09) — Only allowing explicitly approved workloads to access specific services hardens environments. 1. **Automating firewall policies using security as code** (23:51) — Tagging workloads natively in code speeds up policy generation and enforcement. 1. **Reaping the benefits of embedded cloud workload security** (25:41) — Letting protection follow workloads automatically unlocks true agility and scalability. 1. **Staying paranoid to ensure continuous software security** (28:05) — Maintaining a healthy skepticism helps prioritize secure delivery in an increasingly dangerous computing landscape. ## Related Moments - [Embracing DevSecOps and automating the software development lifecycle](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) (from "Maturity assessment for technicians or how I learned to love OWASP SAMM") - [Shifting security left using the DevSecOps approach](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) (from "DevSecOps: Security in DevOps") - [Shifting left and creating internal security champion programs](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Transitioning toward DevSecOps with dynamic scanning and secrets management](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) (from "Enabling automated 1-click customer deployments with built-in quality and security") - [Shifting security testing focus toward critical application logic problems](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) (from "GenAI Is a Junior Dev With Root Access") - [Integrating security practices for devsecops adoption](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) (from "Hosting a modern justice system") ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) ## Related Jobs - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Security Engineer](https://www.wearedevelopers.com/jobs/ext/1574416-security-engineer) at **Twilio** - [Penetration Tester / Red team Specialist](https://www.wearedevelopers.com/jobs/ext/293774-penetration-tester-red-team-specialist) at **Raiffeisen Bank International AG** - [Staff Engineer, Security Engineering Partners](https://www.wearedevelopers.com/jobs/ext/1187268-staff-engineer-security-engineering-partners) at **Twilio**