Traditional secure software development lifecycles are struggling to keep pace with AI-assisted development, expanding application and API attack surfaces, and increasingly automated delivery environments, according to new research from Info-Tech Research Group. The global IT research and advisory firm released a blueprint on Aug. 10 advising organizations to evolve conventional SSDLCs into intelligent, capabilities-driven models that embed adaptive security throughout the software lifecycle.
The report, Develop a Strategic Plan for Intelligent Application Security, is aimed at IT and security leaders who need to assess their application security maturity and build a roadmap for evolving risks. The firm's findings show that an intelligent SSDLC can shift security from a roadblock to an enabler of faster, more resilient application delivery.
"Building a scalable and adaptive application security program through an intelligent approach positions security as a business enabler," said Ahmad Jowhar, senior research analyst at Info-Tech Research Group. "It strengthens foundational practices, increases development velocity, and ensures resilience across modern development pipelines, empowering organizations to deliver securely at scale."
What is an intelligent SSDLC?
An intelligent SSDLC embeds security capabilities throughout every stage of software delivery, combining intelligent tooling and automation with human expertise. It also requires careful coordination with developers and operations teams. Info-Tech's research identifies four key obstacles preventing organizations from modernizing their security practices:
- Fragmented coordination between security, development, and operations teams.
- Limited visibility into maturity and capability gaps across the software lifecycle.
- Adoption of new tools without proper integration or governance alignment.
- No risk-based prioritization model to focus investment on the most important business opportunities and security threats.
Organizations often adopt security tools without integrating them into existing workflows or aligning them with governance requirements. That fragmentation is especially risky when AI-assisted development accelerates release cycles and increases the attack surface for applications and APIs.
How to develop a strategic security plan
Info-Tech's blueprint outlines three phases for developing an intelligent application security strategy. The first phase has security, application, and business stakeholders identify business opportunities and security threats, establish metrics, and define governance roles.
The second phase involves security, IT risk, privacy, compliance, and business stakeholders with existing maturity across application security capabilities. They then determine target states based on risk, business priorities, readiness, and automation potential. The third phase moves to planning: security and application leaders develop gap-closing initiatives, assess costs and benefits, and build a roadmap to present to leadership.
For security leaders managing increasingly complex development pipelines, this kind of strategic planning can help shift security's role from a bottleneck to an element that supports faster delivery. Those leading such modernization efforts may benefit from structured training on how to apply AI to security operations and IT strategy. The AI for Cybersecurity Analysts Learning Path covers threat detection and security automation, while the AI for IT Managers Learning Path addresses AI strategy and operational changes-both relevant when building an intelligent application security program.
Why this matters for IT and development professionals
Executives It takes the report's three-phase framework to map out priority capabilities, assess current maturity across the software lifecycle, and build a roadmap-the difference between buying more tools aimed at specific gaps and having a thoughtful strategy to get value from them. For developers and security operations teams, this approach means better integration of security into development workflows and fewer last-minute security roadblocks. For IT and security leaders, it shifts the conversation from "security slows us down" to "security enables secure delivery at scale."
Account to the complete blueprint, including the Capabilities Assessment Tool and Strategic Plan Template, from Info-Tech Research Group. The firm is one of the many resources available to IT leaders, though its recommendations on intelligent SSDLC suggest a practical direction for enterprises that have invested heavily in DevSecOps practices and need to modernize them under AI-driven development pressure.
Your membership also unlocks: