
Episode #115
Have We Shifted Cybersecurity Too Far Left? | Rick Clark | Episode 115
Send us Fan Mail Moving security left was supposed to reduce risk. Instead, many organizations have made developers responsible for hundreds of controls they cannot realistically understand, manage, or consistently enforce. In this episode of Musings from the Cyber Trench, I sit down with Rick Clark, a cloud, open-source, Linux, and platform engineering leader with three decades of experience, to discuss whether cybersecurity has shifted too far left. We examine how organizations can build security controls directly into their platforms, reduce control sprawl, respond faster to vulnerabilities, and measure software delivery based on business and security outcomes, not deployment speed alone. Rick shares practical insights on: Embedding security controls into CI/CD platforms so they are applied automatically Keeping control ownership with information security while reducing the burden on developers Restoring architectural oversight without unnecessarily slowing delivery Reviewing legacy controls instead of carrying them unchanged from on-premises environments into the cloud Using AI to enforce security controls rather than simply producing code faster Measuring software delivery against business value, compliance, and risk Recovering from zero-day vulnerabilities through standardized containers and centralized platform control Using mutual TLS and end-to-end identity tracking to secure platform communications Protecting sensitive data, private keys, and certificates from immature AI agents The central takeaway is straightforward: developers should write secure code, but they cannot carry the organization’s entire cybersecurity, operations, compliance, and cost-management burden. Security teams must define the controls, and platform teams must make those controls consistent, automatic, and easier to use. ABOUT RICK CLARK Rick Clark has 30 years of experience across cloud computing, open source, Linux, platform engineering, and security. He led the development of Ubuntu Server, led engineering for the Rackspace Cloud and helped found OpenStack, worked in the CTO’s office at Cisco Systems, and helped build the Reliance Jio cloud infrastructure in India. ZERO TRUST READINESS ASSESSMENT Responsible for ICAM, Zero Trust, or identity security within a federal agency, prime contractor, or large regulated enterprise? If you are trying to move from strategy to execution, start with Zephon’s Zero Trust Readiness Assessment: https://zephon.tech/zt Questions or guest suggestions? defend@zephon.tech Responsible for ICAM, Zero Trust, or identity security in a federal agency, prime, or large regulated enterprise? If you’re trying to move from strategy to execution, start with Zephon’s Zero Trust Readiness Assessment: zephon.tech/zt Questions or guest ideas? Email defend@zephon.tech



