Relationship Status: "It's Complicated" Developer-Security Expert Dynamics in Scrum
Houda Naji, Marco Gutfleisch, Alena Naiakshina
Abstract
The high number of cyber threats poses significant challenges, with impactful software exploits ranging from data theft to ransomware deployment. Unfortunately, past research highlighted limited security expertise within development teams. Collaboration between developers and security experts, therefore, emerges as one of the few workable means to address this gap. In this paper, we explore the complex interplay between developers and security experts within Scrum, one of the most widely adopted frameworks which actively promotes collaboration, to shed light on their working relationship, challenges, and potential avenues for improvement. To this end, we conducted a qualitative interview study with 14 developers and 13 security experts. Our qualitative results reveal three communication patterns and five shared challenges between the groups affecting the develop-security expert collaboration. Top challenges include consistent interaction difficulties and the lack of workable means to balance business and security needs. As a result, we found that three core Scrum values (openness, respect, courage) are missing from this relationship. Based on our results, we propose recommendations for fostering a healthy collaboration between developers and security experts, both within and beyond Scrum.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 7e3f7ac8-8d00-4821-932a-1dfe2513a803Cited by top-tier papers1
Ask how each one uses itRelated papers
- Women Security Experts Are Not The Enemy: A Qualitative Study on Gender-Related Communication ChallengesAsli Yardim, Stefan Albert Horstmann, Raphael Serafini, Joshua Gabriel Speckels et al.CHI 2025 · 3 citations
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
- Collaborative Work in Malware Analysis: Understanding the Roles and Challenges of Malware AnalystsRei Yamagishi, Shota Fujii, Shingo Yasuda, Takayuki Sato et al.CHI 2025 · 4 citations
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl et al.USENIX Security 2025
- "Your imaging may be stone-cold normal, but if they look sick, they’re going to get admitted": An Investigation of Clinicians’ Perceptions of Impact & Likelihood of Security FailuresRonald E. Thompson III, Hamza Khalid, Hilary Fisher, Rhea Votipka et al.USENIX Security 2026
