How Does Security Enable the Application Economy?

TL;DR
Security should be designed into applications from the beginning, enabling rapid development, trusted access, and business growth while protecting data. As traditional network boundaries disappear, organizations must replace rigid denial with informed, low-friction decisions across mobile endpoints, ambient data, connected devices, and APIs, using identity, data science, and predictive analytics to manage risk at scale.
Transcript
Executive Vice President, CA Technologies, Amit Chatterjee. Good afternoon, everyone. It is great to be here. You can feel the buzz everywhere. When you think about the time that I'm gonna be up here, about twenty-five minutes, fifty thousand data records will be breached. Welcome to what keeps you up at night. One billion records alone in 2014. Th... Read More
Key Insights
- Applications are engines of business success and expressions of a company's brand. Established enterprises are adding software capabilities because digital products, analytics, and application experiences increasingly determine how organizations innovate, interact with users, and compete in the application economy.
- Security is most effective when architected into solutions from the beginning. Treating it as a bolt-on can slow application delivery or expose the business to avoidable risk, while making it a forethought allows protection to support rapid development, continuous updates, and growth.
- The traditional security perimeter is disappearing as employees, customers, and partners use tablets, smartphones, wearables, and multiple platforms. Modern controls must provide flexible, friction-free access to applications and data without relying on a simple distinction between people inside and outside the organization.
- The security of know replaces automatic denial with informed decisions. Data science, predictive analytics, customer knowledge, and contextual signals can help organizations recognize legitimate users, reduce access friction, and build trust at scale while still protecting systems and information.
- Connected things require identities just as people and accounts do. The transcript anticipates two hundred billion connected things by 2018, including cars, refrigerators, and baby monitors, making identity and access management essential for devices whose compromise could create physical as well as digital consequences.
- Ambient data includes information flowing through clouds, mobile devices, sensors, logs, social media, and other sources without fitting neatly inside a firewall. Its high volume, variety, and velocity create valuable business insights, but those insights and the systems processing them must be secured.
- Security can lower operating costs by enabling trusted digital transactions. Banks want human involvement in fewer than five percent of transactions, and Bank of America's CEO said replacing mobile banking technology with people would require about seventy thousand employees, illustrating the scale of automation's economic value.
- Secure APIs can become routes to market by exposing data and capabilities to applications, customers, suppliers, and partners. The transcript attributes sixty percent of eBay's revenue and ninety percent of Expedia's revenue to APIs, while describing transaction volumes reaching billions or more per day.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How should companies design security for the application economy?
Companies should make security a forethought that is architected into applications and supporting systems from the beginning. It should enable rapid development, immediate updates, personalized experiences, and trusted access while still protecting information and infrastructure. This approach treats security as a business capability that supports growth, cost management, and customer trust, rather than as a bolt-on added after development is complete.
Q: Why can security no longer depend on a network perimeter?
A clear boundary between inside and outside the organization no longer reflects how enterprises operate. Employees, customers, and partners access applications and data through smartphones, tablets, wearables, and multiple platforms across a broad ecosystem. Security therefore needs flexible, friction-free controls based on identity and relevant context, rather than assuming that a connection is trustworthy merely because it originated within a traditional corporate network.
Q: What does moving from the security of no to the security of know mean?
Moving from the security of no to the security of know means replacing reflexive access denial with informed, context-aware decisions. The approach uses data science, predictive analytics, and knowledge about customers to distinguish trusted activity from risk. It aims to preserve protection without creating unnecessary friction, because users may quickly abandon an online business when they cannot gain convenient access to its services.
Q: How does security support faster application development?
Security supports faster development when controls are incorporated into application architecture and delivery processes rather than attached at the end. The transcript reports that ninety-four percent of surveyed CXO leaders faced pressure to produce applications at record speeds. Integrated protection helps teams develop and update services rapidly while managing access and data risk, allowing security to enable the delivery process instead of becoming a late-stage obstacle.
Q: Why does the Internet of Things create new security challenges?
The Internet of Things expands security beyond human users and conventional computers to connected cars, refrigerators, baby monitors, sensors, and other devices. The transcript projects two hundred billion connected things by 2018, each requiring a unique identity and appropriate access controls. A compromised connected object can create consequences beyond exposed email, including interference with physical devices such as a car while it is being driven.
Q: What is ambient data, and why must it be secured?
Ambient data is information that flows across organizational environments without being classified simply as inside a firewall, in the cloud, or on a mobile device. It includes social media, unstructured content, logs, sensor readings, and device data arriving with high volume, variety, and velocity. Organizations must secure it because it contains insights that can improve applications and support business growth, while also creating expanded exposure.
Q: How can security reduce business operating costs?
Security can reduce costs by allowing more transactions and services to occur digitally without direct employee involvement. The transcript says banks want to touch fewer than five percent of all transactions. It also cites Bank of America's CEO saying that replacing the bank's mobile technology with people would require about seventy thousand employees. Trusted authentication and protected digital services therefore support substantial automation and operational efficiency.
Q: Why are secure APIs important to application-based businesses?
Secure APIs allow organizations to combine data and functions from different back-end sources into purpose-built applications. They also make it possible to collaborate with customers, suppliers, and partners while turning previously isolated content into a route to market. Their commercial importance is illustrated by the transcript's claims that APIs account for sixty percent of eBay's revenue and ninety percent of Expedia's revenue.
Summary & Key Takeaways
-
The application economy turns software into both a business engine and a public expression of the brand. Enterprises therefore need security that supports rapid application development and continuous improvement. Treating protection as an architectural requirement from the beginning helps organizations pursue growth without leaving security as a late-stage obstacle or add-on.
-
Traditional organizational boundaries are disappearing as employees, customers, and partners connect through smartphones, tablets, wearables, and other devices. At the same time, social, log, sensor, and device data flows at high volume, variety, and velocity. Security must use identity, analytics, and contextual knowledge to provide trusted access across this unwired environment.
-
Secure APIs let organizations combine back-end resources into purpose-built applications and share valuable capabilities with customers, suppliers, and partners. They can also become important routes to market. The central message is that modern security must enable collaboration and fast delivery while protecting access, information, infrastructure, and trust throughout the application ecosystem.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator