<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1"><url><loc>https://kerrsecure.com/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/4-ways-to-engage-developers-who-couldnt-care-less-about-security/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/devops-security-culture-12-fails-your-team-can-learn-from/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/how-to-do-application-security-on-a-budget/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/how-to-hack-your-security-culture/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/how-to-put-the-threat-modeling-manifesto-into-action/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/the-day-i-met-john-chambers-and-quit/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/the-state-of-devsecops-5-best-practices-from-the-front-lines/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/what-i-learned-in-year-3-of-my-security-journey/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/what-i-learned-in-year-5-of-my-security-journey/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/what-i-learned-in-year-four-of-my-security-journey/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/what-i-learned-in-year-one-of-my-security-journey/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/what-i-learned-in-year-two-of-my-security-journey/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/why-cybersecurity-pros-need-to-learn-how-to-code/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/why-developers-dislike-security-and-what-you-can-do-about-it/</loc></url><url><loc>https://kerrsecure.com/2022/08/28/why-marketing-security-to-your-org-matters-and-how-to-do-it-right/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/4-steps-to-transforming-developers-into-security-people/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/6-application-security-lessons-every-team-should-study/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/6-ways-to-develop-a-security-culture-from-top-to-bottom/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/a-developers-guide-to-attacker-motivation-in-the-supply-chain/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/a-primer-on-secure-devops-why-devsecops-matters/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/a-security-practitioners-guide-to-software-obsolescence/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/how-developers-can-take-the-lead-on-security/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/how-to-put-the-s-for-security-into-your-iot-development/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/information-security-needs-community-6-ways-to-build-up-your-teams/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/owasp-api-security-top-10-get-your-dev-team-up-to-speed/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/owasp-top-10-2021-7-action-items-for-app-sec-teams/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/secure-development-lifecycle-the-essential-guide-to-safe-software-pipelines/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/the-3-most-crucial-security-behaviors-in-devsecops/</loc></url><url><loc>https://kerrsecure.com/2022/08/29/why-owasps-threat-dragon-will-change-the-game-on-threat-modeling/</loc></url><url><loc>https://kerrsecure.com/2022/09/06/appsec-we-have-a-problem-not-everyone-knows-how-to-code/</loc></url><url><loc>https://kerrsecure.com/2022/09/24/the-hybrid-approach-to-threat-modeling/</loc></url><url><loc>https://kerrsecure.com/2022/10/29/threat-modeling-and-a-lack-of-tools/</loc></url><url><loc>https://kerrsecure.com/2022/11/05/the-best-threat-modeling-representation/</loc></url><url><loc>https://kerrsecure.com/2022/11/10/owasp-proactive-controls-the-answer-to-the-owasp-top-ten/</loc></url><url><loc>https://kerrsecure.com/2022/11/19/thirty-one-random-appsec-thoughts/</loc></url><url><loc>https://kerrsecure.com/2022/12/31/saying-goodbye-to-security-journey/</loc></url><url><loc>https://kerrsecure.com/2023/01/01/the-security-champion-framework/</loc></url><url><loc>https://kerrsecure.com/2023/01/08/looking-back-and-forward-on-a-twenty-five-year-career-in-cyber-security/</loc></url><url><loc>https://kerrsecure.com/2023/01/21/security-utility-or-what-we-all-really-want/</loc></url><url><loc>https://kerrsecure.com/2023/02/07/how-to-get-started-in-cybersecurity/</loc></url><url><loc>https://kerrsecure.com/2023/05/21/does-anyone-need-dast/</loc></url><url><loc>https://kerrsecure.com/2023/07/05/doing-appsec-wrong-%F0%9F%A4%A6%E2%99%82%EF%B8%8F/</loc></url><url><loc>https://kerrsecure.com/2023/07/05/simple-software-security-do-we-ask-too-much-of-developers/</loc></url><url><loc>https://kerrsecure.com/2023/07/28/guard-rails-and-paved-roads-%F0%9F%9B%A3%EF%B8%8F-2/</loc></url><url><loc>https://kerrsecure.com/2023/08/04/the-api-is-the-heart-of-the-modern-web-2/</loc></url><url><loc>https://kerrsecure.com/about/</loc></url><url><loc>https://kerrsecure.com/contact/</loc></url><url><loc>https://kerrsecure.com/education/</loc></url><url><loc>https://kerrsecure.com/essays/</loc></url><url><loc>https://kerrsecure.com/podcasts/</loc></url><url><loc>https://kerrsecure.com/portfolio/</loc></url><url><loc>https://kerrsecure.com/privacy/</loc></url><url><loc>https://kerrsecure.com/services/</loc></url></urlset>