What's in a name?
From all appearances, it seems founders have a tough time naming their companies. Look around you, particularly in tech; the naming landscape is very abstract. The upside of an abstract name is the ability to project any meaning you want onto it. But when you pick a name like ‘NewNormal Security’ as we have, it begs a very concrete question; ‘What is the new normal?’ and ‘What was wrong with the old normal?”.
Let's take a look.
Our initial focus is Penetration Testing and API Security Testing, and there are three ‘old to new’ shifts worth calling out. First, and most radical: how code gets written. You know the story — English is the new coding language, agents do the actual coding, and developers orchestrate teams of them to get the work done. The good news: coding productivity is going through the roof. The challenge: agentically developed code carries 2.1x to 2.7x more errors than human written code, depending on the study*. The question is whether all that code is getting properly reviewed, or whether you’re shipping as many vulnerabilities as new capabilities.
Next, most companies only run Pen Testing and API Security Testing when an audit forces them to, once a year, to satisfy regulators, insurers, customers, or partners. That checks a legitimate box. But does it meet the actual goal of being secure? It doesn’t. Not when you could be generating dozens of new vulnerabilities a week, and bad actors continue their efforts during the months between audits.
Last old norm; Security companies tend to hype threat volume and severity - fear sells. And while there are real threats to be addressed quickly and competently, the drama is grossly over done. Tools are often narrow cast so you have to bolt a lot of tools together to get the job done - particularly if you’re testing both network and application surfaces. Those that seem broader in scope are typically the result of bolt-on acquisitions, where nothing is best of breed. They check boxes. You may pass an audit and no one above you may know the difference, but you’re not actually secure. And for all that, they still charge exorbitant prices.
So what does the ‘NewNormal’ look like?
Agentic coding is taking over, but speed does not have to increase security risks. You can implement our scanning solution, ‘NewScan’ into your CICD pipeline and run it in-line with your development process in 20 minutes or less. Yes. You read that correctly. That’s it. 20 minutes. We update the detectors in NewScan every single day, based on the latest reports of CVEs and breaches. Download diffs at whatever interval you’d like, and you’re up-to-date. No begging your vendor for capability enhancements. We handle all the major protocols, categories of logical errors and give you the option to apply either deterministic, non-deterministic detection methods or a combination of both to identify vulnerabilities (recommended). So now you can build code with speed and security. No more looking over your shoulder all the time.
Next, let’s underscore the need to move from testing for annual or quarterly audits to making it an ongoing process that’s either time or event triggered. We understand why most still do it the ‘old way’. Given how cumbersome and expensive the old normal has been relative to the value received, it's completely understandable. But now you have a new option. NewScan is free and NewScan Pro is under $2K/year per CICD pipeline. The barriers to safety in this agentic coding era have been obliterated
Finally, let's talk about what we believe should be the NewNormal for a Security company - our ‘ride or die’ principles. The scope of a solution should be complete or on a clear relentless path to complete. Each component of that solution has to be best of breed (or why bother?). We’ll never hype the volume or severity of issues and will always recommend solutions to each issue. Security is important, but it doesn’t have to be full of drama. We’ll never be dogmatic about approaches to solving a problem when reasonable people can see multiple options, per the ML vs LLM approaches mentioned above. When in doubt, we’ll provide options. Ease-of-use = time savings and collapsed time-to-value for our customers. Testing your applications doesn’t have to be difficult to be effective. We’re focused on affordability for all sizes of companies, while never compromising best-in-class capability.
Its exciting times in the software development and #AppSec world. We see an opportunity to help companies and their development teams move as fast as they can while building products and services that are safe for their business and their customers. So take a moment and come see us at www.newnormalsecurity.com and see our full capabilities for yourself.
Download NewScan for free to get started.