Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Palo Alto Networks: Application Security Across the SDLC with Cortex Cloud

Palo Alto Networks
09/23/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


My name is Maria Joseph, Technical Product Marketing Manager for Cortex Cloud at Palo Alto Networks. And today, we're going to talk about application security and why securing applications early in the software development lifecycle is more important than ever. Every application starts with a developer working in an IDE. From there, code moves into version control systems like GitHub, through build and CICD pipelines, and ultimately deployed into production. At every one of these stages, new risks can be introduced. Let's walk through a few examples. It all starts with the developer. Whether code is written manually or generated with AI, vulnerabilities, exposed secrets, and insecure code can all be introduced here. As code moves into version control systems, those vulnerabilities don't just stay with one developer. They become part of the shared code base and can quickly propagate across the development process if they aren't caught early. During the build stage, organizations also need to consider software supply chain security. Vulnerable packages, insecure dependencies, and build pipeline misconfigurations can all introduce additional risk. And if these issues aren't caught early before deployment, they become production risks that attackers may exploit. This leads to one of the biggest challenges in application security. The later a security issue is discovered, the more expensive and disruptive it becomes to fix. So how do organizations prevent these issues from reaching production in the first place? That's where Cortex Cloud comes in. Cortex Cloud application security continuously secures applications across the entire software development lifecycle. It starts with code scanning. Helping developers identify vulnerabilities, expose secrets, and misconfigurations as early as possible when they're the fastest and least expensive to fix. Next, PR checks. PR checks help to validate code changes before they're merged, allowing organizations to enforce security guardrails directly within developer workflows. One of the biggest advantages of Cortex Cloud is flexibility. Security isn't one size fits all. For example, a developer may simply receive a warning while writing code in their IDE. A secret can be blocked before it's committed into GitHub. And before deployment, organizations may choose to block only high-risk vulnerabilities or software packages, allowing lower-risk findings to continue through development. Finding a vulnerability is only part of the story. What makes Cortex Cloud different is context. With context, Cortex Cloud helps you understand whether it actually matters. Rather than simply reporting that something exists with the thousands of issues you're seeing, Cortex Cloud combines application, runtime, and security context from across the platform. Organizations can answer questions like, is the application interfacing? Is it already deployed? Who has access? Is it actually exploitable? Once Cortex Cloud has the context, it can prioritize what needs attention first. Instead of overwhelming teams with thousands of raw findings, Cortex Cloud helps group them into actionable issues and uses AI, environmental context, organizational policies to determine their urgency. This helps developers and security teams focus on the issues that matter most, reduce alert fatigue, and spend more time fixing risk instead of sorting through it. The goal of application security isn't simply to identify more vulnerabilities. It's to help you identify the ones that matter most. The goal of application security isn't simply to identify more vulnerabilities. It's to help developers prevent risk before it reaches production. By embedding security throughout the software development lifecycle and providing the context and prioritization needed to take action, Cortex Cloud helps organizations build secure applications without sacrificing development speed. That's application security with Cortex Cloud.

TL;DR

  • Security risks can enter at every stage of the SDLC — from developer IDEs and version control to CI/CD pipelines — making early detection critical to reducing remediation cost and disruption.
  • Cortex Cloud provides code scanning and pull request checks that integrate directly into developer workflows, catching vulnerabilities, exposed secrets, and misconfigurations before they reach production.
  • Context is the core differentiator: Cortex Cloud combines application, runtime, and security context to determine whether a finding is deployed, internet-facing, and actually exploitable.
  • AI-driven prioritization groups thousands of raw findings into actionable issues, helping teams reduce alert fatigue and focus on the vulnerabilities that pose the greatest real-world risk.

Summary

This short explainer from Palo Alto Networks introduces Cortex Cloud Application Security and its approach to securing the full software development lifecycle (SDLC). Presented by Maria Joseph, Technical Product Marketing Manager for Cortex Cloud, the video walks through the risk surface that exists at every stage of modern application development — from a developer's IDE, through version control systems like GitHub, into CI/CD build pipelines, and ultimately into production. Vulnerabilities, exposed secrets, insecure dependencies, and pipeline misconfigurations can enter at any point, and the later they are discovered, the more costly and disruptive they become to remediate. Cortex Cloud addresses this by embedding security continuously across the SDLC through code scanning, pull request checks, and context-aware guardrails that integrate directly into developer workflows. What distinguishes the platform, according to the presentation, is its use of combined application, runtime, and environmental context to determine whether a finding is actually deployed, internet-facing, and exploitable — rather than simply surfacing raw vulnerability counts. AI-driven prioritization groups related findings into actionable issues, helping development and security teams reduce alert fatigue and focus remediation effort on the risks that matter most, all without slowing delivery velocity.

Chapters

0:00 - Introduction & Why Early Security Matters
0:22 - Risks Across the SDLC
1:46 - Code Scanning & PR Checks
2:18 - Context-Aware Guardrails
2:56 - AI-Driven Prioritization
4:03 - Closing: Security Without Slowing Development

Key Quotes

1:27 "The later a security issue is discovered, the more expensive and disruptive it becomes to fix."
2:42 "Finding a vulnerability is only part of the story. What makes Cortex Cloud different is context."
3:16 "Instead of overwhelming teams with thousands of raw findings, Cortex Cloud helps group them into actionable issues and uses AI, environmental context, organizational policies to determine their urgency."
3:58 "Cortex Cloud helps organizations build secure applications without sacrificing development speed."

FAQ

How does Cortex Cloud integrate with existing developer workflows?

Cortex Cloud embeds security directly into developer tools and processes — providing code scanning within the IDE, pull request checks that validate changes before merging, and pipeline guardrails that can block high-risk findings at deployment without disrupting lower-risk work.

What makes Cortex Cloud's prioritization different from traditional vulnerability scanners?

Rather than reporting every finding equally, Cortex Cloud combines application, runtime, and security context to assess whether a vulnerability is actually deployed, internet-facing, and exploitable. It then uses AI and organizational policies to group findings into prioritized, actionable issues.


Categories:
  • » Cybersecurity » Application Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • DevSecOps
  • AI & Machine Learning
  • Cloud Security
  • Demo
  • Getting Started
  • Software Development Lifecycle
  • SDLC
  • Code Scanning
  • Software Supply Chain Security
  • CI
  • CD Pipeline Security
  • Vulnerability Prioritization
  • AI-Driven Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Palo Alto Networks: Application Security Across the SDLC with Cortex Cloud

              Industry Events (Sponsor Hosted)

              • Sep
                29

                Embracing AI Adoption While Ensuring Robust Security Measures

                09/29/202612:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhanced Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhanced-visibility-and-control-in-your-operations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version