Bridging the Divide: Flexibility and Security

F5 Ecosystem | May 01, 2019

What do you do when you need two things, but ‘everyone knows’ that the two are mutually exclusive?

There’s been a long-standing myth within the networking and security communities: secure software architectures are inflexible, and agile-delivered software is less secure. But hold on – is there any evidence to support that software developed using an iterative model is inherently less secure? If there is, my ‘research’ (read: Googling) hasn’t really found it.

Indeed, you can make a credible argument that a faster delivery cycle and an automated, streamlined release process reduces risk by reducing the overall vulnerability exposure time.

So, is there really a divide between flexibility and security? Sadly, I’d still say that yes, there is.

However, I’m not convinced that an agile software lifecycle introduces any more inherent code vulnerabilities (although some of the new platforms – like container management systems certainly introduce new surfaces to attack), as the application code is only part of the overall security posture of an organization.

Recognizing that all software contains defects, IT technology stacks also contain security controls external to the application code such as network firewalls, intrusion detection systems, and web application firewalls. Many of these systems need to track application behavior and respond to newly discovered threats in frameworks or operating systems. Ideally these systems need to be as agile as the software delivery lifecycle. Because if they’re not then one of two things will happen – either the security controls are seen as impacting delivery velocity and time to value, or they won’t be providing the protection they were put in place for. Neither of these things are exactly optimal.

The obvious solution is to move the security control model to one closer to the software delivery lifecycle model, and indeed the DevSecOps movement is beginning to apply software engineering and DevOps practices to delivering security controls and to sharing the responsibility for security with everyone in a team, even if the deep expertise stays with a highly experienced, specialized team of practitioners.

Matching this cultural transformation is a technological evolution, where the implementation of security controls, becomes integrated into the software delivery pipeline. Where the security controls accompany each new software iteration through test, staging and deployment, not just bolted on at the end. Where telemetry and trackability elements are injected and traced across multiple points in the stack. Where new metrics that help identify, track, and report on adversaries can be quickly gathered and analyzed.

To make this possible, your technology stack needs to collaborate as much as your teams. That’s one of the most interesting possibilities in a future F5 + NGINX organization. With a portfolio that goes from network firewall to application server, and across all the layers in between, the possibilities for a more agile, more integrated, and more informative set of security controls are huge. The promise of enterprise-class security and visibility injected with lightweight agility has the potential to give everyone on the team the tools, information, and (relative) peace of mind they are looking for.

For more about the advantages of bringing F5 and NGINX together, check out a post from F5’s CEO introducing the ‘Bridging the Divide’ blog series.

Share
Tags: 2019

About the Author

Robert Haynes
Robert HaynesTechnical Marketing Manager

More blogs by Robert Haynes

Related Blog Posts

The everywhere attack surface: EDR in the network is no longer optional
F5 Ecosystem | 11/12/2025

The everywhere attack surface: EDR in the network is no longer optional

All endpoints can become an attacker’s entry point. That’s why your network needs true endpoint detection and response (EDR), delivered by F5 and CrowdStrike.

F5 NGINX Gateway Fabric is a certified solution for Red Hat OpenShift
F5 Ecosystem | 11/11/2025

F5 NGINX Gateway Fabric is a certified solution for Red Hat OpenShift

F5 collaborates with Red Hat to deliver a solution that combines the high-performance app delivery of F5 NGINX with Red Hat OpenShift’s enterprise Kubernetes capabilities.

F5 accelerates and secures AI inference at scale with NVIDIA Cloud Partner reference architecture
F5 Ecosystem | 10/28/2025

F5 accelerates and secures AI inference at scale with NVIDIA Cloud Partner reference architecture

F5’s inclusion within the NVIDIA Cloud Partner (NCP) reference architecture enables secure, high-performance AI infrastructure that scales efficiently to support advanced AI workloads.

F5 Silverline Mitigates Record-Breaking DDoS Attacks
F5 Ecosystem | 08/26/2021

F5 Silverline Mitigates Record-Breaking DDoS Attacks

Malicious attacks are increasing in scale and complexity, threatening to overwhelm and breach the internal resources of businesses globally. Often, these attacks combine high-volume traffic with stealthy, low-and-slow, application-targeted attack techniques, powered by either automated botnets or human-driven tools.

Volterra and the Power of the Distributed Cloud (Video)
F5 Ecosystem | 04/15/2021

Volterra and the Power of the Distributed Cloud (Video)

How can organizations fully harness the power of multi-cloud and edge computing? VPs Mark Weiner and James Feger join the DevCentral team for a video discussion on how F5 and Volterra can help.

Phishing Attacks Soar 220% During COVID-19 Peak as Cybercriminal Opportunism Intensifies
F5 Ecosystem | 12/08/2020

Phishing Attacks Soar 220% During COVID-19 Peak as Cybercriminal Opportunism Intensifies

David Warburton, author of the F5 Labs 2020 Phishing and Fraud Report, describes how fraudsters are adapting to the pandemic and maps out the trends ahead in this video, with summary comments.

Deliver and Secure Every App
F5 application delivery and security solutions are built to ensure that every app and API deployed anywhere is fast, available, and secure. Learn how we can partner to deliver exceptional experiences every time.
Connect With Us