Secure development lifecycle (SSDLC): what it is and how to put it in place
What the secure development lifecycle is, what happens in each phase, what SAST, DAST and SCA add, and where to start if you have nothing in place today.
This page is revised once a year and stays at the same address, so that each revision can be read against the one before it. It is not a list of headlines: it is what we are actually seeing arrive at companies in Spain, how it gets in, and what has changed in the part that is no longer optional because a regulation requires it.
This is the first English edition of a guide Asperis revises once a year in Spanish, and it is worth starting where the Spanish edition starts, because what changed is itself the diagnosis. The previous version of this page was written in early 2024 and described six threats: ransomware, phishing, attacks on critical infrastructure, data leakage, the supply chain and insecure IoT. That diagnosis was not wrong, but three things were missing from it and one of them was large.
What stays the same, because it is still true: ransomware leads, the most frequent way in is still a person, and the supply chain has stopped being a rare case.
If ransomware were only encryption, a good backup would solve it. It has not been only that for a long time.
The pattern we see has two levers: first they take the data, then they encrypt. The backup gives you back your operations, not your confidentiality, and the negotiation becomes a negotiation about publication. That is why the sites that name the victims who do not pay exist, and they double as a shop window for the next one.
The other change is structural: whoever gets in and whoever encrypts are usually no longer the same people. An initial access broker sells the way in, and ransomware as a service supplies the rest. That lowers the technical level needed to attack you and raises the number of people who can.
What actually changes the outcome, in order: backups the attacker cannot delete (an immutable backup, or one kept offline), a restore somebody has tested end to end, and segmentation so that one compromised machine does not reach all the others. All three are checked from the inside, which is what an internal network pentest does.
Ransomware makes the papers and email fraud takes the money quietly. It does not need malware: it needs a genuine invoice and a changed account number.
The three most repeated forms are CEO fraud, changing a supplier’s bank account inside a genuine email thread, and payroll diversion. All of them fit inside business email compromise, and none of them triggers a technical alert, because the email usually comes from a legitimate account.
What is new in the last period is that verifying by voice has stopped being worth anything: cloning a recognisable voice is now cheap. The control that still works is procedural rather than technological: no change of bank details is accepted through the same channel it arrived on, with no exception for seniority, which is exactly what this fraud exploits. It is worked through in the guide to identity theft and impersonation.
It is the most important underlying change since the previous version of this page, and it particularly affects the Spanish mid-sized company, which is usually a supplier to larger ones.
It happens along two different routes that are worth not confusing:
The practical consequence is that now they are going to ask you. Security clauses in contracts have stopped being an annex nobody read, and more and more companies ask their suppliers for concrete evidence: a test report, a certificate, or both.
Most of the intrusions we see do not start with an exploit, they start with a valid credential. And that changes where you have to look.
In Microsoft 365 environments, where a great deal of Spanish business keeps its mail and its files, this is a specific and bounded configuration review: M365 hardening.
It is worth separating the noise from what is being seen.
What has really changed is the cost of the deception. A flawless email in Spanish, adapted to your sector and to the person receiving it, no longer takes time or language skills. Spelling mistakes as a warning sign are finished, and internal training has to stop teaching them that way.
What is new is surface of your own. Companies are connecting assistants to their data and to their tools, and that creates a kind of failure that did not exist before: inputs the model reads as instructions, agents with more permissions than they need, and data leaving through a channel nobody considered a channel. It gets tested, and that is what we do in AI pentesting.
What has not changed is the boring part: people still get in through a credential, through an unpatched system and through somebody who clicks.
It is worked through in cybersecurity and artificial intelligence, including why the prompt injection that makes the headlines is not the one that matters.
It is the block that was missing entirely from the previous version, and for a lot of companies it is the real reason they are reading this.
The useful question is not which of them applies to you in the abstract, but what concrete evidence you are going to have to put in front of an auditor or a customer, and whether you have it today.
This page gives criteria, not statistics. If you need figures for a board, go to the source and cite it with its date, rather than repeating a percentage with no year, which is exactly what the previous version of this same page did.
And where to start, if you have to choose: identity and a second factor that cannot be relayed, patching what faces the internet after first finding out what faces the internet, backups the attacker cannot delete and that somebody has restored, and then checking all of it by attacking it. The full order is in the guide to cybersecurity for companies, how to choose who you give the work to is in the guide to cybersecurity companies in Spain, and a specific case can be put to us through contact.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Talk to a senior pentesterPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.