• bitcoinBitcoin(BTC)$75,884.00-1.71%
  • ethereumEthereum(ETH)$2,397.85-3.41%
  • tetherTether(USDT)$1.00-0.04%
  • binancecoinBNB(BNB)$712.60-0.73%
  • rippleXRP(XRP)$1.29-7.42%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$97.10-3.68%
  • tronTRON(TRX)$0.334937-0.81%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-2.43%
  • zcashZcash(ZEC)$1,180.043.41%
  • HyperliquidHyperliquid(HYPE)$77.28-2.30%
  • dogecoinDogecoin(DOGE)$0.080019-3.07%
  • RainRain(RAIN)$0.0139494.37%
  • USDSUSDS(USDS)$1.00-0.02%
  • moneroMonero(XMR)$506.74-1.25%
  • whitebitWhiteBIT Coin(WBT)$77.92-2.47%
  • leo-tokenLEO Token(LEO)$8.89-0.77%
  • chainlinkChainlink(LINK)$10.77-5.44%
  • cardanoCardano(ADA)$0.195124-4.38%
  • stellarStellar(XLM)$0.176229-8.31%
  • Ethena USDeEthena USDe(USDE)$1.00-0.06%
  • daiDai(DAI)$1.000.02%
  • bitcoin-cashBitcoin Cash(BCH)$220.02-0.76%
  • USD1USD1(USD1)$1.00-0.04%
  • litecoinLitecoin(LTC)$51.02-3.21%
  • uniswapUniswap(UNI)$6.26-5.08%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.32-1.69%
  • CantonCanton(CC)$0.091208-3.94%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • hedera-hashgraphHedera(HBAR)$0.074464-2.90%
  • avalanche-2Avalanche(AVAX)$7.30-2.30%
  • nearNEAR Protocol(NEAR)$2.34-2.25%
  • shiba-inuShiba Inu(SHIB)$0.000005-5.01%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.03%
  • suiSui(SUI)$0.69-2.49%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • tether-goldTether Gold(XAUT)$4,325.410.75%
  • crypto-com-chainCronos(CRO)$0.055359-2.69%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • MemeCoreMemeCore(M)$1.10-0.12%
  • BittensorBittensor(TAO)$216.85-5.80%
  • Ripple USDRipple USD(RLUSD)$1.000.01%
  • okbOKB(OKB)$111.11-1.46%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.16%
  • BitwayBitway(BTW)$0.768.09%
  • pax-goldPAX Gold(PAXG)$4,330.300.81%
  • aaveAave(AAVE)$120.10-5.17%
  • AsterAster(ASTER)$0.68-1.26%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0569770.09%
  • mantleMantle(MNT)$0.54-4.90%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Overcoming the Top Security Challenges of AI-Driven Low-Code/No Code Development

April 24, 2024
in AI & Technology
Reading Time: 5 mins read
A A
Overcoming the Top Security Challenges of AI-Driven Low-Code/No Code Development
ShareShareShareShareShare

Low-code development platforms have changed the way people create custom business solutions, including apps, workflows, and copilots. These tools empower citizen developers and create a more agile environment for app development. Adding AI to the mix has only enhanced this capability. The fact that there aren’t enough people at an organization that have the skills (and time) to build the number of apps, automations and so on that are needed to drive innovation forward has given rise to the low-code/no-code paradigm. Now, without needing formal technical training, citizen developers can leverage user-friendly platforms and Generative AI to create, innovate and deploy AI-driven solutions.

But how secure is this practice? The reality is that it’s introducing a host of new risks. Here’s the good news: you don’t have to choose between security and the efficiency that business-led innovation provides.

YOU MAY ALSO LIKE

When AI Goes Rogue, Who’s Legally Responsible?

Meta Is Reportedly Gearing Up To Launch New Smart Glasses Without A Camera

A shift beyond the traditional purview

IT and security teams are used to focusing their efforts on scanning and looking for vulnerabilities written into code. They’ve centered on making sure developers are building secure software, assuring the software is secure and then – once it’s in production – monitoring it for deviations or for anything suspicious after the fact.

With the rise of low code and no code, more people than ever are building applications and using automation to create applications – outside the traditional development process. These are often employees with little to no software development background, and these apps are being created outside of security’s purview.

This creates a situation where IT is no longer building everything for the organization, and the security team lacks visibility. In a large organization, you might get a few hundred apps built in a year through professional development; with low/no code, you could get far more than that. That’s a lot of potential apps that could go unnoticed or unmonitored by security teams.

A wealth of new risks

 Some of the potential security concerns associated with low-code/no-code development include:

  1. Not in IT’s purview – as just mentioned, citizen developers work outside the lines of IT professionals, creating a lack of visibility and shadow app development. Additionally, these tools enable an infinite number of people to create apps and automations quickly, with just a few clicks. That means there’s an untold number of apps being created at breakneck pace by an untold number of people all without IT having the full picture.
  2. No software development lifecycle (SDLC) – Developing software in this way means there’s no SDLC in place, which can lead to inconsistency, confusion and lack of accountability in addition to risk.
  3. Novice developers – These apps are often being built by people with less technical skill and experience, opening the door to mistakes and security threats. They don’t necessarily think about the security or development ramifications in the way that a professional developer or someone with more technical experience would. And if a vulnerability is found in a specific component that is embedded into a large number of apps, it has the potential to be exploited across multiple instances
  4. Bad identity practices – Identity management can also be an issue. If you want to empower a business user to build an application, the number one thing that might stop them is a lack of permissions. Often, this can be circumvented, and what happens is that you might have a user using someone else’s identity. In this case, there is no way to figure out if they’ve done something wrong. If you access something you are not allowed to or you tried to do something malicious, security will come looking for the borrowed user’s identity because there’s no way to distinguish between the two.
  5. No code to scan – This causes a lack of transparency that can hinder troubleshooting, debugging and security analysis, as well as possible compliance and regulatory concerns.

These risks can all contribute to potential data leakage. No matter how an application is built – whether it gets built with drag-and-drop, a text-based prompt, or with code – it has an identity, it has access to data, it can perform operations, and it needs to communicate with users. Data is being moved, often between different places in the organization; this can easily break data boundaries or barriers.

Data privacy and compliance are also at stake. Sensitive data lives within these applications, but it’s being handled by business users who don’t know how (nor even think to) to properly store it. That can lead to a host of additional issues, including compliance violations.

Regaining visibility

As mentioned, one of the big challenges with low/no code is that it’s not under the purview of IT/security, which means data is traversing apps. There’s not always a clear understanding of who is really creating these apps, and there’s an overall lack of visibility into what’s really happening. And not every organization is even fully aware of what’s happening. Or they think citizen development isn’t happening in their organization, but it almost certainly is.

So, how can security leaders gain control and mitigate risk? The first step is to look into the citizen developer initiatives within your organization, find out who (if anyone) is leading these efforts and connect with them. You don’t want these teams to feel penalized or hindered; as a security leader, your goal should be to support their efforts but provide education and guidance on making the process safer.

Security must start with visibility. Key to this is creating an inventory of applications and developing an understanding of who is building what. Having this information will help ensure that if some kind of breach does occur, you’ll be able to trace the steps and figure out what happened.

Establish a framework for what secure development looks like. This includes the necessary policies and technical controls that will ensure users make the right choices. Even professional developers make mistakes when it comes to sensitive data; it’s even harder to control this with business users. But with the right controls in place, you can make it difficult to make a mistake.

Toward more secure low-code/no-code

The traditional process of manual coding has hindered innovation, especially in competitive time-to-market scenarios. With today’s low-code and no code platforms, even people without development experience can create AI-driven solutions. While this has streamlined app development, it can also jeopardize the safety and security of organizations. It doesn’t have to be a choice between citizen development and security, however; security leaders can partner with business users to find a balance for both.

Credit: Source link

ShareTweetSendSharePin

Related Posts

When AI Goes Rogue, Who’s Legally Responsible?
AI & Technology

When AI Goes Rogue, Who’s Legally Responsible?

September 16, 2026
Meta Is Reportedly Gearing Up To Launch New Smart Glasses Without A Camera
AI & Technology

Meta Is Reportedly Gearing Up To Launch New Smart Glasses Without A Camera

September 16, 2026
Agility Unveils Humanoid Built to Work With People
AI & Technology

Agility Unveils Humanoid Built to Work With People

September 16, 2026
Canon’s R8 II Camera Borrowed Its Styling From A Classic SLR Film Camera
AI & Technology

Canon’s R8 II Camera Borrowed Its Styling From A Classic SLR Film Camera

September 16, 2026
Next Post
Lin Qiao, CEO & Co-Founder of Fireworks AI – Interview Series

Lin Qiao, CEO & Co-Founder of Fireworks AI - Interview Series

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
How To Improve The Audio Quality On Your iPhone

How To Improve The Audio Quality On Your iPhone

September 15, 2026
Shelton defeats Alcaraz in latest-ever U.S. Open finish

Shelton defeats Alcaraz in latest-ever U.S. Open finish

September 15, 2026
Rhode Island Gov. McKee loses primary to Foulkes

Rhode Island Gov. McKee loses primary to Foulkes

September 14, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!