Programer sitting on desk discussing with mixed team of software developers

DevOps, Done Right: The hidden risk emerging in modern software development

Software development is evolving beyond the code developers write. As organizations adopt AI-assisted development, questions are also emerging around how secure AI-generated code truly is. Modern applications are assembled from many interconnected components. AI-generated code, open source libraries, APIs, container images and infrastructure defined through configuration files and infrastructure-as-code templates all shape how systems are built. Developers increasingly orchestrate complex environments rather than writing every element manually.

This shift has expanded the scope of software development. It has also introduced a new challenge: Organizations must maintain visibility into risks embedded within increasingly complex application environments.

Recent research from Omdia highlights how rapidly the development landscape is changing. Nearly 66% of organizations already use generative AI tools or AI development assistants and many more plan to adopt them in the next two years.

Applications are also becoming more modular, automated and distributed. As a result, the distance between creating code and fully understanding its downstream implications continues to grow.

The changing relationship between developers and the systems they build

For much of the history of software development, engineers typically wrote the core application logic themselves. They understood the dependencies that they introduced and reviewed changes carefully before deployment. Security reviews, testing practices and peer reviews reinforced that familiarity and helped identify risks early.

That relationship is evolving. AI-assisted development tools now generate significant portions of application logic. Infrastructure environments are defined through configuration templates. Applications depend on large ecosystems of open source components and managed platform services.

Open source plays a large role in cloud-native development. More than 66% of organizations report adopting open source software in their cloud-native applications, according to Omdia research.

This model allows teams to build powerful systems efficiently. It also makes it more difficult to maintain visibility into every dependency, configuration and infrastructure relationship within an application.

Most of this code is compiled successfully and passes automated tests. Hidden risks often still exist within the system. For example, a dependency can contain a known vulnerability. A configuration can expose sensitive resources and an infrastructure definition can introduce overly permissive access controls.

These issues often remain invisible until much later in the development lifecycle.

Why risk often surfaces late

Many organizations rely on security processes that operate later in the software delivery lifecycle.

Security scans run during CI/CD pipelines. Infrastructure policies are validated during deployment stages. Compliance checks occur shortly before production releases.

These safeguards are essential. However, they frequently identify issues only after development work has already been completed and shared across teams.

Modern development practices compound this challenge by introducing frequent changes through automated pipelines and continuous delivery.

Remediation becomes more disruptive at that stage. Developers must revisit earlier changes. Security teams must triage large volumes of findings. Release timelines can slow while teams resolve issues that might have been identified earlier.

As application environments grow more complex, relying primarily on downstream security checks is increasingly difficult to sustain.

Modern systems introduce new layers of risk

Modern applications depend on far more than application code alone. Open -source libraries, container images, APIs, cloud services, and infrastructure configurations all influence how applications operate in production.

Infrastructure itself has become programmable. Configuration files and infrastructure-as-code templates determine how environments are provisioned, connected and secured. Organizations are rapidly adopting these technologies. Omdia reports that more than half of organizations already use infrastructure-as-code to provision cloud infrastructure and adoption continues to grow.

Each layer introduces potential risks, many of which emerge through the relationships between components rather than within a single piece of code. A vulnerable library can become exploitable only when combined with a particular service exposure. An infrastructure configuration can also unintentionally create new access paths between services.

Understanding these relationships requires visibility that extends beyond traditional code scanning or isolated security checks.

The need for earlier risk intelligence

Organizations are rethinking how development risk is identified.

Downstream security checkpoints alone cannot keep pace with modern development environments. Risk signals must appear closer to where development work occurs.

Developers need visibility into potential vulnerabilities while writing code and defining infrastructure. Security insights must connect signals from code, dependencies, and infrastructure configurations. Teams also need context to understand which issues present the greatest potential impact to their applications.

Embedding risk awareness earlier in development workflows allows organizations to identify and resolve issues while the development context remains fresh.

A shift toward risk-aware development

Software development continues to evolve. Maintaining trust in modern systems requires deeper visibility into how code, dependencies, and infrastructure interact across the development lifecycle.

The future of development will depend on how effectively organizations can identify, understand and manage the risks embedded within complex application environments.

Organizations that gain earlier visibility into those risks will be better positioned to maintain innovation while protecting reliability and security.

Explore how teams are using IBM Concert to bring risk intelligencet into developer workflows

Watch the replay of the fix vulnerabilities at the source (in less than 30 minutes) webinar

Learn more about code risk intelligence: Securing AI coding at scale in real time

Sign up for the IBM Secure Coder Technical Preview

Read the Omdia report: Developer-focused security fuels productivity for business growth 

Source: Omdia, Developer-focused Security Fuels Productivity for Business Growth, March 2026 Results are not an endorsement of IBM. Any reliance on these results is at the third party’s own risk.

Author

Lindsey Fritz

Product Marketing Manager, IBM Concert

Related solutions
IBM Engineering Lifecycle Management

Unifies systems and software development to improve collaboration, ensure traceability and accelerate delivery of complex products with confidence.

Explore IBM Engineering Lifecycle Management
DevOps solutions

Eliminate late security checks and manual toil while gaining clear visibility.

Explore DevOps solutions
Cloud consulting services

Unlock new capabilities and drive business agility with IBM’s cloud consulting services. Discover how to co-create solutions, accelerate digital transformation and optimize performance through hybrid cloud strategies and expert partnerships.

Explore cloud consulting services
Take the next step

Learn how IBM Engineering Lifecycle Management (ELM) and IBM DevOps solutions unify development, improve visibility and reduce risk.

  1. Discover IBM Engineering Lifecycle Management
  2. Explore DevOps solutions