What is it about?
Fast-moving software teams need security testing that fits their existing ways of working. This study reports the experience of a 23-person identity-services team at a large US software organization as it introduced Dynamic Application Security Testing (DAST), which checks running web applications for security weaknesses. Over three months, the team trialled ZAP before adopting Burp Suite, integrating security scans into its GitLab development pipeline and Kanban workflow. We interviewed 10 team members about adoption, challenges, and opportunities for improvement. All were willing to continue using DAST, and eight felt the product was more secure. Participants generally reported little disruption to their daily work, although scans ran quarterly and a dedicated engineer handled much of the integration. Challenges included limited time, difficult-to-interpret reports, and prioritizing security work alongside delivery commitments.
Featured Image
Photo by Annie Spratt on Unsplash
Why is it important?
Security tools can identify vulnerabilities, but their value depends on whether teams can adopt them and act on the findings. This report shows how that process unfolds in a working organization, where technical compatibility, staff capacity, management support, and delivery pressures all matter. The findings offer practical guidance: automate scans, assign clear responsibility, improve the readability of reports, provide security training, and combine DAST with other security practices. They also highlight an important trade-off: limiting scan frequency and focusing on higher-severity findings can make adoption manageable, but may fall short of the frequent feedback expected in Agile development.
Perspectives
We wanted to understand security testing from the perspective of the people responsible for adopting and maintaining it. Having the first author embedded in the team allowed us to document both the integration process and practitioners’ experiences. The study reinforced that introducing a security scanner is not simply a configuration task: it requires ownership, collaboration, and capacity to respond to findings. We hope these lessons help other teams plan security integration around their actual working conditions, while continuing to improve testing frequency, reporting, and security awareness.
Arpit Thool
Virginia Polytechnic Institute and State University
Read the Original
This page is a summary of: Practitioner Perspectives of DAST Integration in Agile Development Workflows: An Experience Report, July 2026, ACM (Association for Computing Machinery),
DOI: 10.1145/3803437.3805256.
You can read the full text:
Contributors
The following have contributed to this page







