Essays
Writing on application security
Twenty-six years of arguing about the same handful of problems: why developers dislike security, what a security champion program actually requires, whether the tools we buy do what we think they do. Written between 2022 and 2023, and grouped here by subject, because the subject is what you came for. The fundamentals have not expired.
The Security Journey Years
Building a company and selling it, written down a year at a time while it was happening. Read in order rather than newest first — this is the one run of essays where the dates are the structure.
- The day I met John Chambers.... and quit
- What I Learned in Year One of MY "Security Journey"
- What I Learned in Year Two of MY "Security Journey"
- What I learned in Year 3 of MY "Security Journey."
- What I Learned in Year Four of MY "Security Journey"
- What I Learned in Year 5 of MY Security Journey
- Saying goodbye to Security Journey
Developers & Security Culture
Simple software security: do we ask too much of developers?
As security professionals, we recognize software security's crucial role in protecting sensitive data, maintaining user trust in applications, and ensuring the overall safety of the software landscape.
How to get started in cybersecurity
I've been in cybersecurity for 25+ years, and the most popular question I get is my recommendation for how people can get started.
The Security Champion Framework
After the release of the Threat Modeling Manifesto, which was a gigantic success, both as a collaborative working group amongst fifteen Threat Modeling exp…
AppSec, We Have a Problem: Not Everyone Knows How to Code
" Therefore, everything an AppSec team does should focus back on this single core statement.
6 ways to develop a security culture from top to bottom
” With our modern dependence on technology and security, nobody would dare to make this statement.
The 3 most crucial security behaviors in DevSecOps
What if I told you that you could change the security posture of your entire DevOps team without ever documenting a single line of a process?
4 steps to transforming developers into security people
Developers are everywhere because software is everywhere. Try to think of an organization that doesn’t employ at least a few developers to maintain their code.
How developers can take the lead on security
On the Internet, detection and reporting of vulnerabilities in software is a daily occurrence. Where do those vulnerabilities originate?
Information security needs community: 6 ways to build up your teams
Every application security and SecOps organization needs to connect people under the banner of security.
4 ways to engage developers who couldn't care less about security
You would think that there is not a single developer on earth who has avoided the impact of a data breach or security vulnerability.
Why developers dislike security—and what you can do about it
Developers dislike security but won’t always admit it. They dislike the security function because it doesn’t understand development and often tries to force a process and toolset on them.
Why marketing security to your org matters—and how to do it right
What if we told you that as a security professional, a portion of your responsibility is marketing? You would likely tell us we are crazy.
Why cybersecurity pros need to learn how to code
There is an age-old debate in security: Should cybersecurity professionals know how to code? Should they invest the time and effort to learn?
DevOps security culture: 12 fails your team can learn from
Will DevOps and DevSecOps still be relevant in 50 years? Today's DevOps technology will be long gone, but some cultural pieces may still be around.
How to hack your security culture
Changing security culture appears straightforward at first glance: You tell people to do things differently than before, and then stand back and wait for lower vulnerability counts and improved code.
AppSec Programs & Practice
Guard rails and paved roads 🛣️
Guard rails and paved roads -- how do they fit together in application security?
Doing AppSec Wrong 🤦♂️
I spoke with a chap about AppSec, and he shared a story of a team he worked with as a Product Manager.
Security utility or what we all really want
On a recent podcast episode of the Security Table, the gang and I discussed the Lastpass breach and the impact of security products as utilities.
Thirty-one random #AppSec Thoughts
Over October 2022, for NCSAM, I shared thirty-one random AppSec thoughts.
OWASP Proactive Controls: the answer to the OWASP Top Ten
The OWASP Proactive Controls is one of the best-kept secrets of the OWASP universe.
OWASP Top 10 2021: 7 action items for app sec teams
In the world of application security, the OWASP Top 10 2021 is the most famous—or infamous—of documents.
Secure Development Lifecycle: The essential guide to safe software pipelines
Customers demand secure products out of the box, so security should be a top priority that should be top of mind for everyone.
A security practitioner's guide to software obsolescence
Unlike wine and cheese, the software does not get better with age—in fact, its security strength decreases over time.
A primer on secure DevOps: Why DevSecOps matters
I’ve been in the world of security for 20-plus years, I have seen trends come and go, but I’ve never seen anything as disruptive to the entire technology e…
OWASP API Security Top 10: Get your dev team up to speed
" Now, in 2019, application programming interfaces (APIs) serve as the backbone of modern software, and they keep on devouring everything in their path, fr…
A developer's guide to attacker motivation in the supply chain
Face it. Your software supply chain is under attack. You'd have to be hiding under a rock or in a bunker under the sea not to realize it.
6 application security lessons every team should study
When you build a skyscraper, how important is the foundation? It's crucial.
How to put the S (for security) into your IoT development
A joke about the Internet of Things has been shared around Twitter over the past few months; I saw it attributed to a guy named Tim Kadlec.
The state of DevSecOps: 5 best practices from the front lines
Ladies and gentlemen, citizens of the Internet, could this be the year when DevSecOps finally catches on everywhere?
How to do application security on a budget
As a bit of a thought experiment, I asked myself, “What if I had to develop an application security program with a budget of zero dollars?
The Security Journey Years
Looking back and forward on a twenty-five-year career in cyber security
I got into security almost by accident. After graduating from university, my wife and I moved to Northern Virginia in 1997.
Saying goodbye to Security Journey
Dear Security Journey, As I prepare to depart the company, I’ve had time to reflect on what Security Journey means and why Deb and I built it the way we did.
What I Learned in Year 5 of MY Security Journey
While the year 2020 is not one we'll soon forget, this was a year of extreme growth for Security Journey. We doubled in size, from four people to nine.
What I Learned in Year Four of MY "Security Journey"
2019 was quite a year for Security Journey, as we added additional team members, and are about to double the size of our sales staff.
What I learned in Year 3 of MY "Security Journey."
Startups are challenging. They push you to the edge and back.
What I Learned in Year Two of MY "Security Journey"
I'm two years into my Security Journey as Co-Founder and CEO.
What I Learned in Year One of MY "Security Journey"
It has been almost a year since I left my cushy job at Cisco Systems and embarked on my own "Security Journey" as CEO of my own company.
The day I met John Chambers.... and quit
The day was November 5, 2015, and the place was San Jose, California. I was hosting Cisco SecCon 2015.
Threat Modeling
The best threat modeling representation
"A representation is the foundation of threat modeling. It is the item that threat modelers use to capture the essence of the thing they are modeling.
Threat modeling and a lack of tools
I've been threat modeling for quite some time. I could argue that I started threat modeling at a high level in 1997 when I started my first job working for one of the first security consulting firms, Arca Systems.
The Hybrid Approach to Threat Modeling
In the pursuit of studying the AppSec person and program in the wild, today's research unpacks the voluntary mandatory debate on threat modeling.
Why OWASP's Threat Dragon will change the game on threat modeling
Threat modeling has always been a dream of mine. Not that I sit around and dream of threat modeling all day, but I dream of embedding a process of security threat modeling within an entire development organization.
How to put the Threat Modeling Manifesto into action
If you have not yet seen the Threat Modeling Manifesto, then you’re missing out.
Testing & Tooling
The API is the Heart of the Modern Web
As I reflect on the release of the new OWASP API Security Top Ten and its new categories, it strikes me that the API is the heart of the modern web.
Does Anyone Need DAST?
We did an episode of the Security Table a few weeks ago addressing DAST. The premise was exploring reasonable application security.