Select your language

80% of cyberattacks are carried out at the application layer

Colombia. Security in the use of applications is one of the concerns that is most manifested by entrepreneurs due to the risks sometimes represented by access and use of these computer tools. 

Therefore, the A3SEC Group, an expert in cybersecurity, has become an important ally for companies in the public and private sector; made known the new trends of security integration, in the development of secure code, in an efficient way; reducing the interaction gap between the development team and the security team. 

The director of A3SEC's Mexico office, Israel Gutierrez, noted that in order to have a threat-free environment, it is necessary to secure applications by searching, remediating and preventing security vulnerabilities. He said that we must reduce risks and improve the operation of authentication, encryption and auditing, in order to integrate defense mechanisms into corporate security. 

The executive assured that 80% of computer attacks are against applications and of these 30% are successful, so quick and timely action is required by developers to protect applications in case of an attack. "Protection should be part of a process and not an extra function in the development of applications," he said. 

- Publicidad -

He pointed out that several tools such as SATS, which is static analysis, DAST, dynamic analysis and IAST, which is interactive analysis, are used to detect attacks and defend their applications. 

For his part, Ronen Riesenfeld, Security Engineer in Checkmarx LATAM Applications, said that it is necessary to act in time and quickly to prevent attacks from having negative effects on the security of corporations. He said that to reduce vulnerability you have to build security competence in developers, make them participate in the value of security and understand that this is a commitment of all. 

Riesenfeld noted that important challenges to develop defenses, including rapid release, process compliance, improving staff skills, reducing time and costs through developer empowerment. 

For the expert, the ideal is that the development of security aspects in applications occurs within the construction cycle, in order to prevent possible attacks or deal with them in a timely manner in case they occur. 

For Gutiérrez, through DevSecOps the development of applications and their implementation is improved and it can be ensured that it has 5 times fewer failures than its counterparts, which makes it more effective when it comes to security, since it recovers failures 96 times faster. 

He pointed out that through this mechanism there is a much faster process with less risk and stressed that the culture of safe development must be part of the whole process. "We must have solutions to integrate them more naturally into the security process," Gutierrez said. 

When making a demonstration, Riesenfeld pointed out that when performing a scan of the applications, it is possible to incorporate security or quality rules of each company, which allows greater integration. 

- Publicidad -

He highlighted how the scan can be scheduled to be carried out at times when there is less volume of work and in this way go through the entire application, detect where the vulnerability is and how to solve it. If there are several you can proceed in the same way, which saves time and money.
 

Santiago Jaramillo
Santiago JaramilloEmail: [email protected]
Editor
Comunicador social y periodista con más de 15 años de trayectoria en medios digitales e impresos especializados para América Latina. Actualmente Editor de las revistas Ventas de Seguridad, Gerencia de Edificios y Coordinador académico del Congreso TecnoEdificios.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter