Modern app delivery requires a continuous approach to security

At the Tanzu Division of Broadcom, we focus on how our customers can get the most out of cloud native environments while protecting against the slew of new vulnerabilities and attacks targeting their critical business apps.

At the Tanzu Division of Broadcom, we focus on how our customers can get the most out of cloud native environments while protecting against the slew of new vulnerabilities and attacks targeting their critical business apps. As important as prevention is, reducing the time it takes to recover from a breach or other issues is just as critical, if not more. This is particularly important for our customers functioning in highly regulated industries who have to keep up with continually changing security, privacy, and compliance requirements.

We’ve found that the best way to secure large and diverse application estates is to integrate security-enhancing capabilities and processes throughout the entire application dev and delivery cycle. This means approaching security as an integral and continuous part of the cycle. In working with our many global customers, we recommend the following best practices for a continuous approach to security:

Weave security in all your processes

Adding security earlier in the app dev and delivery cycle is widely recognized as a best practice. However, sometimes it is not enough. Over the years, we have seen that attack vectors are targeting multiple phases of the software delivery cycle, and in some cases, shifting security left has come to mean shifting security decisions on to developers. This undue burden can become disruptive and slow down the app delivery process. With cyberattacks hitting various aspects of the software supply chain, it is imperative to make security an integrated aspect of the software delivery lifecycle.

With this in mind, we designed Tanzu Platform to make security easy, while also reducing friction between dev and platform teams. We do this by allowing for separation of concerns and enabling golden paths curated by the platform engineering team. Tanzu Platform also supports patterns and technologies made popular by Spring Framework, leveraging the Buildpacks model, and the incredible Bitnami software catalog on which Tanzu Application Catalog is based.

Turn on your automation superpower

Infusing policy-based automation into your application platform is one of the best ways to enforce and scale security policies. Platform engineers need to partner with security and compliance teams to create policies based on changing industry guidelines, vulnerability threat level, audit requirements–just to name a few. Doing this reduces friction in the app dev and delivery process, increases security and compliance leaders’ peace of mind, and empowers platform engineers to deliver a secure and frictionless path to production that ultimately yields value-generating innovation.   

Adopt a “continuous upgrade” culture

Security is not a one-time thing. Infrastructure needs to be secure by design and continuously updated. Introduced several years ago, the 3Rs – Rotate, Repave, and Repair continue to be our north star when it comes to ensuring Tanzu Platform is among the most secure cloud native application platforms. More specifically, the 3Rs mandate that you: 

  • Rotate system credentials every few minutes or hours.
  • Repave every server and application in the datacenter every few hours to a known, good state.
  • Repair vulnerable operating systems and application stacks consistently within hours of patch availability.

Ensuring all software is up to date with the most recent patches, security fixes, and regulatory compliance means continuously checking the health of your system and running the most secure versions. This can be overwhelming without the right mindset and processes. So, in addition to keeping up with patches, upgrades, and bug fixes, we recommend that our customers embrace a continuous upgrade and compliance mindset. Read about what we mean by continuous upgrade culture here.

Every day, companies are competing for customers and seeking ways to capitalize on market trends and capture new revenue opportunities. At Tanzu, we advocate that technology leaders should treat security as an accelerator rather than an outcome or a one-time “check the box” requirement.

For more about Tanzu’s approach to application security, visit the Tanzu and Security page.

About Purnima Padmanabhan

Broadcom

Purnima Padmanabhan is Vice President and General Manager of Broadcom’s Tanzu Division. Prior to joining Broadcom, she was Senior Vice President and General Manager of VMware’s Modern Applications & Management Business and was responsible for application modernization, cloud native application development and multi-cloud management. She previously led the company’s Cloud Management Business. Ms. Padmanabhan has extensive experience building and launching innovative products in cloud infrastructure, security and enterprise mobility. Prior to joining VMware, she was CEO of Cavirin, a cloud security company, where she drove a turnaround. She was previously COO of MokaFive, a desktop virtualization company, and was responsible for global product operations. Ms. Padmanabhan holds an MBA from Stanford University and an M.S. in Computer Engineering from University of Southern California.

Randy Howe
Read More

Latest

Study suggests fibroid rates in Latina women may be lower than previously thought

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

Rimas Entertainment Presents SONAR: ‘A Record Label Where Artists Can Develop with Freedom’

The label's roster includes Cris MJ, Yan Block, Hades66 and more. Jesús Rodríguez, head of label, SONAR SONAR / Rimas Entertainment Español Rimas Entertainment officially unveils SONAR, a record label focused on the development and projection of artists within the Latin music market, Billboard can announce exclusively today (April 29). The initiative is part of

YouTube’s Tuma Basa to Exit as Director of Black Music & Culture

MusicAfter eight years at the streaming giant, the...

Feza – Khanyisa

MusicDOWNLOAD MP3 SONG...

Newsletter

Don't miss

Study suggests fibroid rates in Latina women may be lower than previously thought

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

Rimas Entertainment Presents SONAR: ‘A Record Label Where Artists Can Develop with Freedom’

The label's roster includes Cris MJ, Yan Block, Hades66 and more. Jesús Rodríguez, head of label, SONAR SONAR / Rimas Entertainment Español Rimas Entertainment officially unveils SONAR, a record label focused on the development and projection of artists within the Latin music market, Billboard can announce exclusively today (April 29). The initiative is part of

YouTube’s Tuma Basa to Exit as Director of Black Music & Culture

MusicAfter eight years at the streaming giant, the...

Feza – Khanyisa

MusicDOWNLOAD MP3 SONG...

The Vogue Business Funding Tracker

Introducing the Vogue Business Funding Tracker, a running list highlighting the most notable and intriguing investment and M&A activity in fashion and beauty. From emerging disruptors to legacy giants undergoing major changes, we spotlight the deals that are shifting the dynamics of the sectors we cover, including fashion, beauty, tech and sustainability. April 2026 Icicle

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day