
Overview
Information security is an important aspect of projects and teams as much as it is an important aspect of the software that’s produced. In the latter’s case, it’s all about software system’s ability to keep information safe and secure. In this case, it’s all about a software team’s ability to keep information safe and secure. This may not be limited to just customer information, but important business information, such as commercially sensitive documents, software source code, personal information or the security of the IT systems and network. In this way, the people and processes that make up the software teams and projects form an important “human firewall” (Piper, 2024a).
Cybersecurity quality starts with the culture of the project team, company and software industry. Testers are well placed to use their skills to critically question, analyse, identify, evaluate and report on problems with project team security as they would with software security. It’s also important to embed this type of security-thinking throughout the project team, testing function and company, and be the champions within their teams when it comes to supporting information security teams by alerting them to potential threats, by leading by example.
Approach
Approaches to assessing and building a secure team include (Piper, 2024a) (Piper, 2024b).:
- Skills: Cybersecurity included job roles and titles, and skills in competency matrices for performance and promotion reviews
- Training: Regular, mandatory and optional training, and time to do so, enhance skills as part of team growth
- Awareness: Regular reminders of security quality every sprint and how it balances with time/cost and other quality dimensions
- Agency: A shared responsibility of security quality and empowerment to make changes
- Testing: Everyone identifying and reporting on security issues with testers leading by example and coaching others to do so
- DevSecOps: Embedding security into the software development cycle
- Tools: Using tools and technology to support testers with their project team human firewall
Action Plan
The main approach is to develop an action plan of what testers can do. For example, give extra opportunities for testers to do information cybersecurity training and certification, including possible mentoring and shadowing of information security personnel. This not only helps to upskill testers and fill the cybersecurity skills gap, but acts as a recruiting and retention tool, and opens up possibilities for career switches for testers who want to go on to explore a career in cybersecurity. (Piper, 2025)
Methods
When testing, possible threats to the information cybersecurity of software project teams could include:
- Shadow: Use of third-party software (including development libraries) and other IT solutions without knowledge or approval of IT
- GenAI: Use of AI tools in teams where company information is being shared with the learning algorithms without permission or full extent of risk
- File Share: Use of unapproved file sharing sites, tools or links
- Comms: Use of unapproved communication tools to share messages
- Layer: Lacking or breaches in defence in layers:
- Administrative: Missing or incomplete documented policies, procedures and training materials
- Physical: Lack of secure building access (e.g. fobs, keycards) including secure working-from-home (WFH) setup
- Technological: Lack of perimeter, VPNs, anti-virus software, or incorrect use of individual username and passwords with correct privileges and permissions and multi-factor authentication
- Unaware: Talk about cybersecurity during sprint meetings or mentioned-in-passing (MIP) to judge overall awareness of team or lack of training
- Unskilled: Assess learning opportunities and availability of optional or mandatory training, what training is available and when?
Citations & Further Reading
- Piper, S. (2024a). Five Smart Ways to Invest in Your Human Firewalls. ISC2 Knowledge Vault.
- Piper, S. (2024b). Security Industry 101: A ‘Crash Course’ For Security Newbies. ISC2 Knowledge Vault.
- Piper, S. (2025). Bridging the Gap: Strategies to Overcome the Cybersecurity Skills Shortage. ISC2 Knowledge Vault.
Updated: 2025-03-16