Tag
OWASP SAMM
You’ve made the decision to create a product security program, congratulations! Here are five recommendations to help you on your journey:
Leadership commitment
Leadership commitment is crucial. Building a product security program will require changes in ways of working,...
agentic
Imagine it’s a Monday morning. Your developers are barely past the login screen, and an AI agent has already drafted a feature, written the tests, opened a pull request, and flagged a dependency that needs updating. By the time standup...
ai
Imagine it’s a Monday morning. Your developers are barely past the login screen, and an AI agent has already drafted a feature, written the tests, opened a pull request, and flagged a dependency that needs updating. By the time standup...
appsec
Imagine it’s a Monday morning. Your developers are barely past the login screen, and an AI agent has already drafted a feature, written the tests, opened a pull request, and flagged a dependency that needs updating. By the time standup...
cyber security
You’ve made the decision to create a product security program, congratulations! Here are five recommendations to help you on your journey:
Leadership commitment
Leadership commitment is crucial. Building a product security program will require changes in ways of working,...
metrics
I had the opportunity to speak at OWASP Global AppSec 2025 on the topic of Metrics That Matter: Driving AppSec Success with Data-Driven Insights.

Abstract
“What gets...
You’ve made the decision to create a product security program, congratulations! Here are five recommendations to help you on your journey:
Leadership commitment
Leadership commitment is crucial. Building a product security program will require changes in ways of working,...
owasp
You’ve made the decision to create a product security program, congratulations! Here are five recommendations to help you on your journey:
Leadership commitment
Leadership commitment is crucial. Building a product security program will require changes in ways of working,...
product security
Imagine it’s a Monday morning. Your developers are barely past the login screen, and an AI agent has already drafted a feature, written the tests, opened a pull request, and flagged a dependency that needs updating. By the time standup...
You’ve made the decision to create a product security program, congratulations! Here are five recommendations to help you on your journey:
Leadership commitment
Leadership commitment is crucial. Building a product security program will require changes in ways of working,...
sdlc
Imagine it’s a Monday morning. Your developers are barely past the login screen, and an AI agent has already drafted a feature, written the tests, opened a pull request, and flagged a dependency that needs updating. By the time standup...
I had the opportunity to speak at OWASP Global AppSec 2025 on the topic of Metrics That Matter: Driving AppSec Success with Data-Driven Insights.

Abstract
“What gets...
You’ve made the decision to create a product security program, congratulations! Here are five recommendations to help you on your journey:
Leadership commitment
Leadership commitment is crucial. Building a product security program will require changes in ways of working,...
security champion
You’ve made the decision to create a product security program, congratulations! Here are five recommendations to help you on your journey:
Leadership commitment
Leadership commitment is crucial. Building a product security program will require changes in ways of working,...
speaking
I had the opportunity to speak at OWASP Global AppSec 2025 on the topic of Metrics That Matter: Driving AppSec Success with Data-Driven Insights.

Abstract
“What gets...