The CISO's Guide for Implementing DevSecOps in the Enterprise
Chapter Summary

Floor van Eijk
CISO @ NN Group
DevSecOps at NN Group
In this chapter Floor van Eijk, CISO of NN Group, writes about the incorporation of security into DevOps, the differences between DevOps and DevSecOps, and how they emerged as separate entities due to circumstances and timing. Incorporating security into DevOps is an essential process that attracts diverse perspectives and experiences, along with contrasting attitudes and opinions. According to van Eijk, to achieve security by design, a focus on skills and the right mindset is required.
There is also an emphasis on the importance of asking “why?” and starting small to set up for success when it comes to security at scale. Governance, culture, and mindset play crucial roles in achieving security in DevOps. Collaboration and upskilling are integral parts of scaling security. And finally, van Eijk believes that embedding security as a quality of products is necessary to ensure alignment with CI/CD principles and pipelines to automate quality checks, including security. Would you like to know how to scale security into hundreds of DevOps teams? Then Floor van Eijk’s chapter is an essential read!
BIO

Floor van Eijk is Chief Information Security Officer (CISO) of NN Group, an international financial services company with a presence in 11 countries from Europe to Japan. Floor van Eijk has over 20 years’ experience in IT implementation programs, managing IT teams and organizational transformations. Starting her career at Accenture enabled her to learn quickly in this area and work on IT transformations at various companies in the financial services industry.
Floor has been working at NN Group for over 10 years. She has held various roles in the IT organization, from managing business-driven IT application teams to technical IT infrastructure teams. She has been focusing on security for the last three years, more than one of which as CISO of NN Group. Floor thrives on embracing complex challenges, building strong and engaged teams, and delivering innovation and added value.
In her free time, Floor enjoys playing team sports and going running with friends through the dunes and by the sea. Her next goal is to run a half-marathon in Leiden, Netherlands. Floor also enjoys good food, music, the company of family and friends, and watching her two sons grow.
About the Book

As a leading provider of DevSecOps services, DevOn has seen firsthand how organizations can benefit from these transformations. But despite the widespread adoption of DevSecOps, there are still many misconceptions about what it is and what it can help you achieve. In this book, we address common concerns and misconceptions about DevSecOps, drawing on the insights of technology leaders from a variety of European organizations.
If you’re a modern-day leader looking to assess your organization’s performance or embark on a DevSecOps transformation, this book is a must-read. With the help of Irfaan Santoe, Rahul Sah, and Markus van Duijn, we’ve gathered the perspectives of 10 technology leaders from leading organizations to provide a comprehensive understanding of the current state and future of DevSecOps. Don’t miss out on the opportunity to gain valuable insights and learn from their organizations' performance.
Book Launch Event
About the Authors
Irfaan Santoe

Irfaan is a CISO, an Entrepreneur in InfoSec, and a Thought Leader in secure DevOps. He is on a mission to close the gap between the IT world of Development, Operations, and Security. Irfaan is the OWASP Chapter Leader in the Netherlands and actively contributes to open-sourcing security.
Rahul Sah

The Global CEO of DevOn, a technology consulting and software delivery organization, Rahul is passionate about helping organizations accelerate their journey toward high-performance enterprises.
Markus van Duijn

A DevOps enthusiast with 15 years of experience in agile, CI/CD, DevOps, security and leadership, Markus has seen firsthand how DevOps gets companies to a higher level by coaching, teaching, and experiencing DevOps principles
LEARN HOW THESE FRONTRUNNERS USE DEVSECOPS







DevSecOps Visions from
10 European Information Security Leaders
Gain Insights from Information Security Leaders. Click on photos to read Speaker Chapters.
"Implementing DevSecOps in the Enterprise: A Guide for CISOs" BOOK
TAP INTO OUR EXPERTISE & RECEIVE YOUR COMPLIMENTARY COPY!
Find motivation and receive tailored advice in just 15 minutes!!