Speaking
25 talks, 58 stages, since 2014
RSA Conference every year from 2015 to 2025, OWASP AppSec on both sides of the Atlantic, and the microphone at the first conference ever dedicated to threat modeling. The subjects change; the argument does not. Security is a culture problem wearing an engineering costume, and developers are the only people positioned to solve it.
On sabbatical through 2026, so no engagements this year. Still glad to talk about conference sessions, workshops, and internal engineering all-hands beyond that — get in touch if you are programming an event.
Chairing & programming
ThreatModCon 2023
Founding team & emcee
The first conference ever dedicated to threat modeling. Chris was part of the team that founded it and emceed the inaugural edition, giving the opening and closing remarks and presenting the first Adam Shostack Award. His engagement with the conference ended after that edition.
RSA Conference
Program Committee
Ten years on the committee that selects what RSA Conference programmes in application security — on the other side of the table from the speakers, deciding which talks the industry hears.
OWASP Triangle
Chapter Lead
Ran the local OWASP chapter — the unglamorous end of community work, and the end where people actually learn things.
Cisco SecCon
Organiser & Host
Cisco’s internal security conference, run for an engineering population of tens of thousands.
Talks
2025
The Next Twenty Years: What AppSec Needs to Do to Cement the Future
Twenty years of application security produced a profession, a toolchain and a standards body. An argument about what the next twenty have to produce instead.
2025
The Startup Operating System
How a security startup actually runs, from someone who has built and sold two — delivered to RSAC’s innovation track rather than its AppSec one.
2024
Secure and Privacy by Design Converge with Threat Modeling
Security by design and privacy by design are the same discipline wearing different badges, and threat modeling is where they meet.
2024
Why the “Secure by Design” pledge won’t save us from AppSec failures
A pledge is not a practice. What signing up to secure-by-design actually costs, and why most of the organisations that signed will not pay it.
2024
The Paradox of Secure and Private by Design and Default
Secure by design and private by design pull against each other more often than the pledges admit. Where the tension is real, and how to decide it.
2024
The Modern Application Security Rocket Ship
Where application security is actually going, as against where the vendor floor says it is going.
2023
Zero Trust Threat Modeling
Zero trust is an architecture claim. Threat modeling is how you find out whether the claim is true of the thing you actually built.
2023
The Application Security State of the Union
An annual survey of what changed in application security, what did not, and which of the two is being oversold. Delivered five times in 2023, retitled slightly at each.
2023
Open Source Software: The Good, The Bad, The Ugly
A panel with Shannon Lietz and Ryan Skinner on what the industry gets wrong about depending on code it did not write.
2022–2023
Ten DevSecOps Culture Failures
Ten ways a DevSecOps programme dies, each one taken from a real team, and what the failure looked like from the inside.
2022
Elite Security Champions Build Strong Security Culture
What separates a security champions programme that changes how developers work from one that produces a mailing list.
2021–2022
Using the Threat Modeling Manifesto to Build an Enterprise Threat Modeling Program
Taking the Manifesto from a set of values to a programme that survives contact with an enterprise change process.
2021
Developers Dislike Security: Ten Frustrations and Resolutions
Ten specific things security teams do that developers hate, and what to do instead of each one.
2021
DevSecOps Culture: Laughing Through the Failures
The failures are funnier in hindsight and more useful than the success stories.
2020
10 Things I Wish Every Developer Knew about Security
The ten things that would prevent most of what application security teams spend their week on.
2019–2020
Cheaper by the Dozen: Application Security on a Limited Budget
Twelve things worth doing when the application security budget is nothing, ordered by what they return.
2018
Security Culture Hacking: Disrupting the Security Status Quo
Culture change treated as an engineering problem — find the pressure points, apply force there.
2018
Building an AppSec Program with a Budget of $0: Beyond the OWASP Top 10
The OWASP projects nobody talks about, assembled into a programme that costs nothing but time.
2017–2018
How to Transform Developers into Security People
Not "train developers on security" — actually change what they care about, which is a different and harder task.
2017–2018
AppSec Behaviors for DevOps Breed Security Culture Change
The specific behaviours, at the level of what someone does on a Tuesday, that move a DevOps team’s security culture.
2016
AppSec Awareness: A Blue Print for Security Culture Change
The blueprint drawn from building Cisco’s programme, given four times on two continents — and his first talk at RSA Conference.
2015–2016
Cisco’s Security Dojo: Raising the Application Security Awareness of 20,000+
The programme that trained twenty thousand engineers, and what breaks at that scale that does not break at two hundred.
2015
Application Security Awareness: Building an Effective and Entertaining Security Training Program
How twenty thousand Cisco engineers were taught security by a team that decided the training had to be entertaining — and the ten things that made it work.
2014
DevOps & AppSec: Why They Matter in an IoT World
A panel on what connected devices do to the argument for building security in, held while much of the industry still treated IoT as a fad.
2014
Dysfunctional Testing
Product-based penetration testing, and how much of it tests the wrong thing.
Training & workshops
Threat Modeling Championship: Breaker vs. Builder
3-hour workshop · red team against blue team, against the clock
Advanced Security Threat Modeling: Red vs. Blue
Learning Lab · co-facilitated with Michael Burch
Security Threat Modeling
Two-hour Learning Lab, run twice · co-facilitated with Michael Burch
Hands-on Threat Modeling
2-hour workshop
Building a World Class Security Champions Program
Birds of a Feather · facilitated discussion under Chatham House Rule
Building an AppSec Program on the Cheap with OWASP
Peer2Peer discussion, capacity-limited · three annual runs
Building an AppSec Program with OWASP
Full-day training
Changing Security Culture
Interactive table exercise · companion to the Security Culture Hacking talk
Threat Modeling: uncover vulnerabilities without looking at code
Workshop
AppSec Fundamentals
Full-day training
Guest appearances
- Security Champion Veterans Explain All
- Supercharge Threat Modeling with Software Supply Chain Security
- Designing Secure and Private Software by Default
- Why “shift-left” isn’t good enough
- RSAC 2024 Recap: Top Trends & Takeaways
- AppSec Unbounded: Embrace “Secure and Privacy by Design”
- Building a Successful Security Champions Program
- AppSec and DevSecOps track discussion
- The Role of AI in Application Security
- Threat Modeling Lab — a hands-on workshop
- Shift Left? — The Hedge 212
- The Great Debate: Does DAST work for DevSecOps?
- Threat Modeling and Software Supply Chain Security
- Threat Modeling Roundtable
- Building a Grassroots Security Champions Program
- The state of application security
- Learning Application Security
- SBOMs, provenance, security champions and third-party risk
- The Security Champions Framework
- Threat Modeling Manifesto in a Mobile First World
- Application Security at Scale
- Threat Modeling with Chris Romeo — The Hedge 164
- Chris Romeo Talks Security Journey Exit
- How a Cybersecurity Professional Broke Out as an Entrepreneur
- Successes and Failures at Security Training
- DevSecOps Culture: Laughing Through the Failures
- Threat Modeling for Product Managers
- Threat Modeling the Software
- Chris Romeo and the State of Security — The Hedge 48
- How to Transform Developers Into Security People
- The Threat Modeling Manifesto: From Theory to Practice
- Threat Modeling Manifesto launch panel
- AppSec Awareness and Security Culture
- Things Every Developer Should Know About Security
- Creating Security Champions with Continuous Education in DevSecOps
- Building a Security Mindset
- IoT Security: the Security Development Lifecycle Way
- On Changing Culture
- The Cisco Security Ninja program