← Latest papers
💻 computer science

Low-Code Paradox in DevOps: Security and Governance Insights from Practitioners

This study investigates practitioners' perspectives on the security and governance challenges arising from integrating low-code development platforms into DevOps environments, revealing that while these tools enhance efficiency, they necessitate robust governance and proactive security practices to mitigate associated risks.

Original authors: Muhammad Azeem Akbar, Saima Rafi, Arif Ali Khan

Published 2026-05-19
📖 5 min read🧠 Deep dive

Original authors: Muhammad Azeem Akbar, Saima Rafi, Arif Ali Khan

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Picture: The "Fast-Track" vs. The "Safety Net"

Imagine a construction company that wants to build houses faster. They have two tools:

  1. DevOps: A highly organized, professional team of engineers who work together seamlessly to build, test, and move houses quickly.
  2. Low-Code Platforms (LCDPs): A set of "Lego-like" building kits. These kits allow even people who aren't professional architects (called "citizen developers") to snap together walls and windows very quickly without needing to mix cement or lay bricks by hand.

The paper explores what happens when you try to use these Lego kits inside the professional construction site. The authors call this the "Low-Code Paradox."

The Paradox: The Lego kits make building much faster and easier (efficiency), but they also create new, hidden holes in the walls that burglars (hackers) can sneak through (security risks).

What the Authors Did (The Method)

The researchers didn't just guess; they went out and talked to 12 experienced construction managers and engineers (IT professionals) from Finland, Spain, and China. These people had been using both the professional methods and the Lego kits for years.

They asked them: "When you mix these fast Lego kits with your fast construction process, what goes wrong with security and rules?"

They listened to the answers and looked for common patterns, much like a detective piecing together clues.

What They Found (The Results)

1. The "Double-Edged Sword"

The experts agreed that Low-Code is a double-edged sword.

  • The Good: It automates boring tasks and helps teams build apps faster. It's like having a robot arm that places bricks instantly.
  • The Bad: Because these kits connect to so many other tools (like external power sources or water pipes), they create a larger "attack surface." Think of it like adding a hundred new doors and windows to your house just to make it easier to enter; now, there are a hundred more places for a thief to break in.

2. The "Shadow" Problem

One major issue is Shadow IT. This happens when employees use these Lego kits to build their own tools without telling the IT security team.

  • Analogy: Imagine a worker in the construction site secretly building a side door with a lock they made themselves, without the main security guard knowing. The guard thinks the house is secure, but there's actually an unlocked back door. The paper notes that attackers are increasingly looking for these unauthorized tools.

3. The "SolarWinds" Wake-Up Call

The researchers mentioned a famous real-world hack (SolarWinds) where attackers slipped into big companies through their supply chains.

  • The Lesson: Even if the Lego kit manufacturer says, "We updated the security," it might not be enough. The paper suggests that just having the tool isn't enough; you need to constantly scan the whole house for cracks, not just the front door.

4. The Human Factor

The experts noted that while these tools help teams work together, the people using them often forget about security.

  • Analogy: It's like giving a child a power drill because it's easy to hold. They can build a chair quickly, but they might not realize they just drilled a hole right through the gas line. The paper says that "cyber hygiene" (basic safety habits) is the best way to stop these accidents.

The Proposed Solution: A "Holistic Framework"

The authors didn't just point out the problems; they built a Safety Framework (shown in their Figure 2) to fix them. They suggest three main strategies:

  1. Automated Safety Checks (Shift-Left):
    Instead of waiting until the house is built to check for leaks, you check for them while you are snapping the Lego bricks together. You use automated tools to scan for security holes before the app is even finished.

  2. Zero Trust (The "Never Trust, Always Check" Rule):
    Imagine a high-security bank. Even if you have a key, the guard checks your ID every single time you walk through a door. The paper suggests applying this to software: verify every single request, even from inside the building, and give people only the minimum access they need.

  3. Adaptive Governance (The Rulebook):
    Since anyone can build with these kits, the company needs a strict rulebook.

    • Sandboxing: Let people play with the Lego kits in a "sandbox" (a safe, isolated area) so if they break something, it doesn't crash the whole company.
    • Naming Rules: Make sure everyone names their files and folders the same way so nothing gets lost or confused.
    • Vendor Checks: Before buying a new Lego kit, check if the manufacturer is safe and if they follow your company's rules.

The Bottom Line

The paper concludes that Low-Code and DevOps are a powerful mix, but they require a cultural shift.

You can't just buy the tool and hope for the best. Organizations need to:

  • Treat these new tools with the same seriousness as traditional coding.
  • Accept that you can never be 100% secure, but you can be resilient.
  • Create a culture where everyone cares about security, not just the security team.

In short: Speed is great, but if you don't lock the doors while you're running fast, you'll lose everything. The paper argues that with the right rules and a security-first mindset, companies can enjoy the speed of Low-Code without getting robbed by hackers.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →