DevSecOps is DevOps with security built in, so the real question is whether adding security practices to your pipeline is worth it. For almost any team shipping software that handles customer data, it is.
DevOps on its own optimizes for speed and reliability. Security is left to a separate team or a later stage, which tends to mean vulnerabilities are found late, fixed slowly, or shipped to production. DevSecOps keeps the speed of DevOps while catching many of those issues earlier, when they are cheaper and faster to fix.
The trade-off is noise. Adding several scanners to a pipeline can bury developers in findings, many of them duplicates or issues that are not exploitable in practice. If that noise is not managed, developers start ignoring results and the program loses credibility. Successful DevSecOps programs pair their scanners with a way to deduplicate, prioritize, and route findings so developers only see the work that matters.
