Riccardo.Bozzato
2026-07-10

Why Ops and Security Must Be Friends (Not Frenemies)

Security
Operations
Culture

For years, the relationship between operations and security teams has been adversarial. Security says "no" — operations finds a way around it. Security adds a gate — operations discovers a bypass. The result is a brittle, theater-of-security posture that frustrates everyone.

The fundamental problem is that most security frameworks were designed for a different era. They assume that security can be a separate function that reviews and approves. But in modern DevOps environments, velocity is survival. If security slows things down, teams will route around it — intentionally or not.

The Ops-Security Alignment Framework changes this by requiring every security control to earn its place. The rule is simple: every control must map to an ops metric. If it doesn't improve uptime, reduce MTTR, or lower error rates, it needs to be rethought.

How to start:

  1. Audit your current security controls. For each one, ask: what ops metric does this improve?
  2. Replace manual approval gates with automated policy checks (policy-as-code).
  3. Measure security adoption by ops velocity, not compliance scorecards.
  4. Review quarterly — if a control isn't moving an ops needle, deprecate it.

The teams that get this right don't see security as a cost center. They see it as a force multiplier. When security makes ops faster (not slower), everyone wins.

Recommended by Riccardo

Some links in this post are Amazon affiliate links. You pay nothing extra, I get a small commission that helps keep this site running. Every book or tool I recommend has been personally tested and curated.

Enjoyed this post?

Share it with a colleague or reach out to discuss.