Future of Application Security

Tromzo
Future of Application Security

The Future of Application Security is a podcast for ambitious leaders who want to build a modern and effective AppSec program. Doing application security right is really hard and we want to help other experts build the future of AppSec by curating the best industry insights, tips and resources. What’s the most important security metric to measure in 2024? It’s Mean Time to Remediate (MTTR). Download our new MTTR guide: https://lnkd.in/evjcf4Vt

  1. EP 60 - Appian’s Abdullah Munawar on Enhancing Product Security Amid Evolving Development Trends

    22/05/2024

    EP 60 - Appian’s Abdullah Munawar on Enhancing Product Security Amid Evolving Development Trends

    In this episode of the Future of Application Security podcast, Harshil speaks with Abdullah Munawar, Director of Product Security at Appian. Abdullah shares valuable insights into his journey from security assessments and consulting to leading product security efforts, discussing the evolving challenges and strategies for building effective security programs in modern development environments.  He discussed the importance of evolving security practices beyond identification to implementation within organizations, including the need for a holistic approach to product security and focusing on high-priority vulnerabilities. Abdullah also explains the challenges of maintaining data quality in AI companies.  Topics discussed: The transition from consulting to in-house product security and the importance of hands-on experience in understanding the challenges of implementing security fixes and mechanisms. Defining the scope of product security in the context of decentralized development practices and the shift towards "you build it, you manage it" approaches. The changing role and structure of product security teams to address the full stack of security concerns, from architecture and automation to traditional AppSec tasks. Strategies for driving remediation and adoption of security practices, including leadership buy-in, targeted automation, and empathy-building initiatives like security champion programs. Emerging challenges in product security related to AI and data management, such as data poisoning, segregation, and unintended leakage.

    21min
  2. EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability

    14/02/2024

    EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability

    In this episode of the Future of Application Security, Harshil speaks with Christine Gadsby, VP, Product Security at BlackBerry, a software company specializing in cybersecurity. They discuss the new initiatives driving software transparency, like SBOMs and VEX, and how adoption will not only come from regulations but from companies holding their software suppliers more accountable. They also talk about the need for better telemetry practices and more connected tooling and how security professionals can get involved in industry change and mentorship. Topics discussed: The important role frameworks like NIST 800-218 and CISA's Secure By Design will play in establishing standards. The ways in which SBOMs and VEX are driving software transparency that will keep customers safer. How commercial industries will increase their software supplier accountability in response to the rising cost of insecurity. How many companies lack knowledge about what's in the software they sell and the importance of having good telemetry practices. Why lack of good tools and the ability to connect tools is a challenge to product security today. Advice to security professionals about not letting things like SBOM and VEX get away from you as you prepare for the future of software development. How product security professionals can get involved with industry efforts to drive change.

    26min
  3. EP 53 — ReversingLabs's Dave Ferguson on Securing Your Software Supply Chains

    17/01/2024

    EP 53 — ReversingLabs's Dave Ferguson on Securing Your Software Supply Chains

    In this episode of the Future of Application Security, Harshil speaks with Dave Ferguson, Director of Technical Product Management, Software Supply Chain Security at ReversingLabs, which offers software supply chain security analysis platform. They discuss the rising need for software supply chain security as a result of the complexities around how software is built today. They also talk about ways to identify novel attacks through analyzing software behaviors, how efforts like SBOMs and registries help increase transparency, and why software supply chain security needs to evolve from just looking for vulnerabilities. Topics discussed: How Dave's diverse background in security, as well as his piqued interest around the SolarWinds and 3CX attacks, led to his focus on software supply chain security today. How a product manager leads by working with development teams, meeting with customers, incorporating new features and integrations, and helping bring new solutions to market. How the complexities associated with building software today — like open source and automation — have increased the possibility of adversaries slipping in.  Why analyzing software behavior across previous builds and seeing what's changed can help flag novel attacks. Today's trends that are increasing transparency in software creation, including the rising demand for SBOMs and the possibility of trust registries for commercial software. Why software supply chain security approaches need to move beyond just looking at vulnerabilities to find ways to root out all malicious activity. RELATED RESOURCE:  Today, most application security tools are designed to find vulnerabilities, not fix them. What is noise and what is risk? And, more importantly, how do you accelerate the remediation of the most critical vulnerabilities? The answer lies within one key metric — Mean Time to Remediate (MTTR).  Taking a better strategy to decrease your MTTR and keep your organization safe can begin today — download the paper to learn how.

    24min

Classificações e avaliações

5
de 5
4 avaliações

Sobre

The Future of Application Security is a podcast for ambitious leaders who want to build a modern and effective AppSec program. Doing application security right is really hard and we want to help other experts build the future of AppSec by curating the best industry insights, tips and resources. What’s the most important security metric to measure in 2024? It’s Mean Time to Remediate (MTTR). Download our new MTTR guide: https://lnkd.in/evjcf4Vt

Para ouvir episódios explícitos, inicie sessão.

Fique por dentro deste podcast

Inicie sessão ou crie uma conta para seguir podcasts, salvar episódios e receber as atualizações mais recentes.

Selecionar um país ou região

África, Oriente Médio e Índia

Ásia‑Pacífico

Europa

América Latina e Caribe

Estados Unidos e Canadá