Pros and cons of DIY software development: low-code/no-code

Low-code / no-code software development enables someone who doesn’t know any programming languages, and has no training in software development, to create software to suit their needs. 

Using a drag-and-drop user interface, people can easily choose the elements that they need from a library, and put them together to create a website or other application without having advanced coding skills and with no-code, people need no coding skills at all. 

In this blog we go over the benefits and disadvantages of low code/no code for your organisation, risks of invisible code and how to get the best for your business from low code / no code development.

 

You may have had some exposure to low-code / no-code already:  
  • Consider WordPress, SquareSpace and Wix, for example, all of which let you add a mix of plugins to a template to create a website with functionality that works for you, and designed to your taste
  • Or IFTTT IFTTT, which lets you connect your apps to do time-saving and interesting things, such as:
  • Instructing your robot lawnmower to shelter if the weather forecast predicts heavy rain.
  • Or, when you publish a new YouTube video, automatically publish it as a WordPress post.
  • And you don’t have to create a single line of code. 

So, low-code/no-code development has been around for a while, but is becoming increasingly popular, and is expanding beyond simple website building. 

 

Benefits of low-code / no-code 

There are undeniably some benefits to this kind of citizen development, though they all come with some caveats. These benefits include the following: 

  • Low-code/no-code means that people without much coding experience (or, indeed, any at all) may be able to create software that does what they need.
  • It can help with the talent shortage problem in that you may not need to hire a software developer—or it may be able to free up the time of your existing development team to do more complex work.
  • By getting creatives or business people to create applications, you might get some innovative results.
  • Development time might be reduced due to the simplicity of the drag-and-drop creation tools, with automated testing, deployment and hosting.
  • And this kind of platform makes integration with external data sources and tools easier.

 

Disadvantages of low-code / no-code 

Those caveats? Unsurprisingly, there are reasons why coders are highly trained, and therefore expensive: 

  • It’s going to be tempting to plunge straight in, missing out the planning and design steps that a developer would consider up front. 
  • The low-code/no-code platform that you chose may not provide you with the options to do exactly what you wanted—so you might need a coder to help and finish the task.
  • Unlike a developer, you may not have been trained in logic, so might need some help for particularly complex business needs.
  • You may need specialist tests to check that the results you get out are correct; or you may need to clean and tidy the data before putting it into your newly developed app. Again, a professional developer can help with this.
  • The code generated may create more code than necessary, so you might need a professional coder to make it leaner, cleaner and more efficient.
  • People with no coding experience may not know what the security risks are, and how to avoid them; you’ll be relying on the platform provider’s coders to avoid security holes.

 

Risks of invisible code 

Low-code / no-code doesn’t, of course, mean that there isn’t any code. It just means that you can’t see it. The code is still there, underlying the plug and play elements, and it may contain bugs and security issues. Again, you are relying on the provider to ensure it is as free from bugs as possible. 

These are the business issues:  

  • You are dependent on the provider; what happens to your business if the provider has an outage? Who owns the source code?
  • There’s no easy way to transfer between low-code / no-code providers, so you are locked in.
  • Depending on the pricing policy, adding extra functionality may prove to be more expensive than you’d planned.
  • And do you really want your chief accountant, MD or HR manager, to be doing this instead of their day job?

 

And then there are the potential security issues:  
  • As mentioned above, you have low visibility of the source code, the testing procedures and the third-party integrations that have gone into your chosen platform.
  • There are the risks of shadow IT: your business may end up with applications and devices accessing your systems and processing your data that you don’t know about.
  • Then there are the governance and compliance issues: who is storing and processing your data—and is any of it sensitive? 
  • You may need to create new policies and procedures to control access and to manage this new way of working.

 

OWASP lists the top 10 security risks of low-code / no-code, if you’d like to look at them in detail.

 

Tips for getting the best out of low-code / no-code 

In summary, low-code / no-code is great for low budget, low risk applications; but maybe not so good for complex apps processing sensitive data. 

Whatever you’re planning to develop using low-code or no-code tools, here are some tips to help you keep your business secure: 

  • Use a low-code/no-code platform from a reputable vendor.
  • Ask the vendor about how they’ve built-in and tested security, so that you are confident they have considered this in developing the platform and the modules.
  • Ask them whether they have security certifications.
  • Consider asking for a software bill of materials, so that you know exactly what has gone into the platform and modules.
  • Ask where the platforms (and your data) will be hosted, and make sure you check and comply with any personal or sensitive data security requirements.
  • Control access to these platforms (both admin access and general staff access), so that you know who is doing what with your data.
  • Train your staff, so that they are aware of the security implications of what they are building.
  • And don’t forget to add the apps being developed (and of course the platform you are using) to your inventory of assets.

 

In summary, low-code / no-code can be a great option for low budget, low risk applications; but maybe not so good for complex apps processing sensitive data. Think carefully about what you want to use it for, and how you will manage its usage. And then, if you decide to go ahead, have fun with it —development of an application to suit your needs should be very satisfying. 

Leave a Reply

Your email address will not be published. Required fields are marked *