Industry insights

The impact of open source on cybersecurity

Dave Wreski
October 3, 2022 by
Dave Wreski

Open-source software is one of the most innovative developments of the past few decades. Open-source is code that is publicly available and editable. While this sounds dangerous for security, it can actually significantly improve it by allowing anyone to fix errors. Applying the open-source methodology of collaboration to cybersecurity can greatly affect everyone’s security.

When the Internet was new, issues of security and credential theft were primary concerns. Now, consumers are pressuring vendors to be transparent with data collection, vulnerability disclosure and security weaknesses. Open source provides transparency, but more is still needed to develop collaboration between the communities.

I have developed applications to provide the privacy and protection that organizations need, using open source much more securely and cost-effectively than the proprietary alternatives. Here are some tips organizations can use to realize the benefits of the open-source development model, proactively protecting your users and assets.

Phishing simulations & training

Phishing simulations & training

Build the knowledge and skills to stay cyber secure at work and home with 2,000+ security awareness resources. Unlock the right subscription plan for you.

Using open-source software with cybersecurity

Using open-source software can help organizations keep their technology more secure. From a cybersecurity team’s perspective, with a smaller development team, it is easier to keep publicly available software up to date against the latest exploits than closed-source software.

Since open-source code is visible to the public, anyone can find and fix bugs and exploits that the developers might have missed. Bug bounty programs, which offer rewards to anyone who identifies an error or vulnerability in a computer program, now play a role. Bug bounties can be found throughout the big tech space, including Google, Microsoft, Facebook, Apple, and some smaller firms.

Furthermore, if several large organizations are using the same open-source software, several large cybersecurity teams may be going through the code. Using open-source software makes securing a company’s technology collaborative, allowing better security for everyone involved.

The difference open source can make in cybersecurity

Rethinking the role of open-source software can change cybersecurity by making defense a collaborative effort. Without open-source security, each company’s cybersecurity teams are solely responsible for their own security. Open-source defense tools becoming mainstream would benefit every company that uses an open-source tool because, when a company fixes a bug or adds code to strengthen their systems, they strengthen the defense of every other company that uses the same open-source software.

Unifying cyber-defense benefits not only small companies who would otherwise not have the capability to create a strong defense but also larger companies. These larger companies often fall into the trap of spending money on cybersecurity tools without knowing what they really do. They tend to think that the bigger their cybersecurity budget, the more secure they are. In reality, many of these tools are redundant or unnecessary, and even the best cybersecurity defenses leave gaps. Collaboration among cybersecurity tools creates a unified, stronger defense against cyberattacks by closing these gaps. When one team fixes an exploit, that exploit will not work against any other organization.

Open source can also make strides in email security solutions and defense. Affordable and unified software can play a big role in the face of a cyberattack and in protecting business email. Because of the availability and transparency of open-source code, these products can be engineered to achieve superior levels of quality, reliability and security over a longer time than projects that do not use the open-source development model.

Leveraging open source can be powerful

Before starting Guardian Digital, I worked for UPS, where I found an easier way to develop open-source security applications than the proprietary alternatives at the time. Although open-source software is more popular than ever—open-source development is now the focus of some of the biggest technology companies — the cybersecurity world has fallen behind. It has yet to take advantage of open source.

Cybersecurity companies rarely collaborate, meaning that even if a company develops an innovative new tool or software, it will likely not spread very far, leaving others open to attacks that already have solutions. Many attackers utilize open-source code and collaboration to develop their attacks, and defenders doing the same can strengthen the security of every user.

Phishing simulations & training

Phishing simulations & training

Build the knowledge and skills to stay cyber secure at work and home with 2,000+ security awareness resources. Unlock the right subscription plan for you.

Key takeaways

Primary concerns about the internet’s integration into society may still be ongoing, but the focus has shifted to vendors offering full disclosure of data collection, vulnerabilities and security weaknesses. Innovation and businesses are continuing to grow, and so should the reliability of the systems and infrastructure these organizations use.

Open source is a community built on visibility and collaboration, which may prove to be the most resourceful tool in the cybersecurity industry.

Dave Wreski
Dave Wreski

Dave Wreski is the founder and chief executive officer of Guardian Digital, Inc., the open-source business email security provider. Already established as an internet security expert and network architect at UPS, Dave was captivated by the power of open-source development as a basis for internet and email security. He founded Guardian Digital in 1999 and developed a one-of-a-kind, powerful program to defend against the most sophisticated business email threats. In believing that email security is more than just a product but, in fact, a process, Dave is dedicated to providing Guardian Digital clients top-class customer support, ease of implementation and cost-effectiveness.