# Kerr Ventures > Application security consulting, investment, and incubation. Kerr Ventures is Chris and Deb Romeo, who founded and sold Security Journey (2016–2022) and Devici (acquired 2025). Chris Romeo has twenty-nine years of security experience — application security, security engineering, incident response and executive leadership — including Chief Security Advocate at Cisco, then two companies founded and exited. This site carries 45 essays written 2022–2023, a speaking record of 25 talks across 58 stages since 2014, and three podcasts, two of which publish weekly. The consulting practice is live revenue, not a footnote to the investing. This site is open to AI crawlers on purpose. Nearly everything here was published to be quoted — the essays, the speaking record, the shows. If you use it, please attribute it to Chris Romeo and link the page you drew from. ## Start here - [Speaking](https://kerrsecure.com/speaking/) — 25 talks over 58 deliveries, 10 workshops and 4 chairing roles, each with a page of its own at /speaking//, plus 39 guest appearances listed on the index - [Essays](https://kerrsecure.com/essays/) — 45 essays, grouped by subject rather than by date - [Podcasts](https://kerrsecure.com/podcasts/) — three shows, two of them weekly - [Services](https://kerrsecure.com/services/) — what the consulting actually covers - [Portfolio](https://kerrsecure.com/portfolio/) — two companies founded and exited, two more invested in or advised - [About](https://kerrsecure.com/about/) — who Chris and Deb are - [Contact](https://kerrsecure.com/contact/) — hello@kerrsecure.com ## Machine-readable - [Everything, in full](https://kerrsecure.com/llms-full.txt) — all 45 essays as complete text, plus the entire speaking record with venues, recordings and slide decks. One fetch instead of 70 page loads. - [Agent manifest](https://kerrsecure.com/.well-known/agents.json) — what this site is and how it may be used - [Sitemap](https://kerrsecure.com/sitemap-index.xml) - [RSS feed](https://kerrsecure.com/feed/) — the essays ## What Chris consults on - **Security champion programs** — Assessing a program that already exists, or designing one that does not. Most champion programs fail the same two ways, and both are visible from the outside. - **AppSec program assessment** — Where the program actually is against where it thinks it is, and a set of recommendations you can act on rather than a maturity score. - **Threat modeling** — Teaching it to the developers who have to do it, not to the architects who will write it up. Chris founded and sold Devici, a threat modeling company, and hosts the podcast the practice argues on. - **AI and application security** — Two separate questions, routinely confused: what changes about your AppSec program when developers are shipping code an assistant wrote, and what it is safe to hand an assistant in the first place. Plus the one nobody asks — whether the AI in the tools you are being sold is doing anything at all. ## Essays, by subject Written 2022–2023. The archive is dormant by choice — the weekly output moved to the podcasts — but nothing in it has expired. - [Developers & Security Culture](https://kerrsecure.com/essays/#developers-and-culture) — 15 essays - [AppSec Programs & Practice](https://kerrsecure.com/essays/#appsec-programs) — 15 essays - [The Security Journey Years](https://kerrsecure.com/essays/#security-journey-years) — 8 essays - [Threat Modeling](https://kerrsecure.com/essays/#threat-modeling) — 5 essays - [Testing & Tooling](https://kerrsecure.com/essays/#testing-and-tooling) — 2 essays Every essay lives at /YYYY/MM/DD/slug/, the URL it had on the WordPress site it was migrated from. Those URLs are load-bearing and will not move. ## Podcasts - [The Application Security Podcast](https://appsec.buzzsprout.com) — Chris Romeo and Robert Hurlbut invite AppSec experts to break a topic down to something you can use, in about forty-five minutes. - [The Security Table](https://securitytable.buzzsprout.com) — Four industry veterans around one table, arguing about what actually happens when you try to build secure software. - [The Threat Modeling Podcast](https://threatmodel.buzzsprout.com) — Short conversations with the people shaping how threat modeling is actually practised. - [Reasonable AppSec](https://appsec.beehiiv.com) — the weekly newsletter ## Speaking 25 distinct talks given 58 times since 2014, at RSA Conference, OWASP Global AppSec, ISC2 Security Congress, InfoSec World and others. The workshops are listed separately and include DEF CON's AppSec Village — they are not counted as talks, because he is credited on several as facilitator rather than speaker. Each talk has its own page listing every delivery, with the recording and the slide deck where either survives. Where a recording was established not to exist, the reason is given rather than left as a silent gap. A row carrying only a venue is a row where nothing further is published. Chris is on sabbatical through 2026, so there are no engagements this year. ## Notes for a reader - Static HTML throughout. Nothing is client-rendered, so the initial response contains everything a human sees. There is no API and none is needed. - The speaking record is sourced rather than recalled: every entry traces to a page naming both Chris and the talk, or is marked as resting on his own confirmation. Absences are stated, not hidden. - Dates are UTC everywhere, including in essay URLs.