The AppSec Management Podcast

The AppSec Management Podcast

Dr. Dag Flachet, Dr. Aram Hovsepyan
Maa Yhdysvallat
Genret Teknologia
Kieli EN
Jaksot 54
Viimeisin 01.09.2026

The AppSec Management Podcast focuses on application security, OWASP guidelines, and security-first compliance. It is aimed at professionals involved in application security programs and anyone interested in the cutting edge of cybersecurity within software applications. The show covers practical strategies for integrating security into development processes and staying ahead of emerging threats.

Jaksot

  • CRA Sessions: Vulnerability Management 01.09.2026 36min
    Vulnerability management is at the core of the Cyber Resilience Act (CRA). But what are the minimal expectations? Annex I, Part 2 lists 8 expectations manufacturers shall implement, yet they remain very abstract.Chapters:00:00 Introduction and a motivating example02:39 CRA: a brief recap08:11 Vulnerability management basics10:00 Revisiting the running example of a smart fridge10:38 Incident management18:25 The definition of an incident24:30 Defect management27:26 Security testing28:35 Patching and updating29:51 Secure deploy33:11 Recap of all required security activities under the CRAAbout this video:Today, the topic of vulnerability management typically makes one think of a SAST, DAST, IAST, SCA scanner. It makes us think of a triaging process and fixing the critical and high severity findings in the attempts to try to keep the risk low. However under the CRA vulnerability management is much broader. Fortunately, at least based on the OWASP SAMM latest benchmark, the industry is doing so much better on vulnerability management than on any other security related activities.Incident detection and response is the first major subtopic under vulnerability management. Especially in larger organizations most of the aspects of incident management are well under control. Amongst the key outstanding issues we typically face is the lack of communication between the product teams and the incident management teams as these are always siloed. Without a clear understanding of the business context the incident management can only focus on generic risks.Under the CRA the definition of an incident is interesting to understand. It differs starkly from the organizational perspective where a minor incident affecting a single user may be overlooked. CRA is all about the sensitivity of the data rather than the volume of the data.Defect management is about making sure that all findings are reported to a centralized defect tracking system, triaged and tackled within pre-defined time frames.Security testing is all about the tooling organizations are so excited about. However just pulling in a scanner is likely to make things worse. Teams must have a full grip on their scanners by tweaking the rulesets and how they tie to the build and deploy process.Patching and updating focuses on regularly patching OS and infrastructure components.Finally, secure deploy is actually a very complex topic as it needs to ensure the authenticity and integrity of the code moving from development to production. Code signing is one of the key controls, yet getting that aspect right is not as straightforward as it seems.All in all, you need a systematic approach to product security. Codific's SAMMY tool can help you out there. SAMMY can enable your gap assessment, improvement planning and demonstrating those improvements. SAMMY has an instrumental integration with JIRA so that your developers don't have to jump into a new tool. SAMMY also features an MCP server that allows your AI tools to generate all sorts of board reports based on your data in SAMMY.Links:👉 Use the SAMMY tool to manage your security posture: https://sammy.codific.com👉 Check the industry standard AppSec management model: https://owaspsamm.org
  • September 11 CRA reporting obligations. What and how to? 26.08.2026 4min
    On September 11, 2026 the CRA reporting obligations come into effect. What exactly are you supposed to repot, to whom and how do you do it.Content from Complycra.eu full article here: https://complycra.eu/what-are-the-cra-obligations-starting-september-11-2026/To use SAMMY Free go to https://sammy.codific.com
  • CRA Horizontal Standards Explained 14.08.2026 14min
    This chapter summarizes the horizontal standards of CRA and is based on resources from complycra.eu. Voices and narrative is AI generated based on in depth resources. For full factual accuracy refer to complycra.eu
  • CRA Sessions: Technical Security Requirements 20.07.2026 28min
    The Cyber Resilience Act makes it mandatory to take security into consideration from a product’s design until sunsetting. But what are these technical security requirements? Is this about yet another checkbox exercise we can "fake it until we make it" along with a bunch of documents we can now effortlessly generate?
  • PRC, Product Risk and Compliance 16.06.2026 4min
    Traditional GRC tools were built for corporate IT, not for modern software development. As regulations like the EU Cyber Resilience Act raise the bar for product-level security, a new discipline is emerging: Product Risk and Compliance (PRC).
  • CRA Sessions: Risk Assessment 09.06.2026 26min
    Risk assessments are the starting point of your application security program and as it turns out your Cyber Resilience Act compliance strategy. If you think about it, it makes absolute sense. If there is no risk, you don't really need security. Unfortunately, that's not the world we are living in and creating a crystal clear understanding of the risk profile for each of your products is essential.Risk has two components to it. It has a more "businessy" component that is related to loss magnitude or impact. This is the component that needs to be dictated by the business.The second risk component is more technical, namely threat event frequency.The combination of the two factors is what we typically think of risk. However it is critical to stress that the first "business"-side of risk is much easier to come up with. It is also relatively limited. It is also the first one in terms of a sequence. This is also precisely what CRA suggests, you need to start with clearly defining the context of your product, its risk and risk acceptance criteria.The second factor, i.e., the actual threats, is virtually unlimited. Once again you need the business side of the story to come up with meaningful threats.In this second episode of our CRA series podcast we dive deep into the risk assessment and threat modeling concepts in the context of the upcoming EU Cyber Resilience Act.
  • What is CRA and why do we care? 02.06.2026 23min
    Lara and I kick off our new series on the EU Cyber Resilience Act (CRA), where we'll go deep on what the regulation actually means for product security teams and how to translate it into concrete application security practice.In this first episode, we cover the foundations:What the CRA is and why it existsWhich products fall under its scope, and which don'tHow compliance requirements differ between product categories (default, important, and critical)The role of horizontal and vertical standards, and how they fit togetherWhat's at stake if you simply ignore the regulation — the penalties, market access consequences, and liability implicationsTo help you figure out where your product stands, we've also built a CRA screening tool that walks you through the key scoping questions and gives you a first read on your obligations.In the coming episodes, we'll move from the regulatory frame into the practical side: what "secure by design," vulnerability handling, SBOMs, and conformity assessments actually look like when you're shipping real products.👉 Try the CRA screening tool: https://sammy.codific.com/cra👉 Subscribe so you don't miss the next episodes.
  • Is security becoming prompt-driven? The future of AppSec in the age of AI 26.05.2026 47min
    AI is changing everything - including how attackers think. But is the security industry keeping up?This webinar, hosted jointly with Toreon, tackles one of the biggest questions in AppSec right now: as AI agents, LLMs, and prompt-driven development become the norm, what does application security even look like?📌 Follow us on LinkedIn: https://www.linkedin.com/company/9420309/🌐 Or visit our website: https://codific.com/🔔 Subscribe for more AppSec tutorials and security framework insights!
  • AppSec at SMEs, how are your peers doing? 19.05.2026 42min
    In this chapter we have the research team of PXL University of Applied Sciences that did an in depth analysis of the state of AppSec processes at SMEs. They report on their outcomes and findings.
  • Operational Security With SAMMY 12.05.2026 10min
    You can use SAMMY for free on sammy.codific.com
  • Appsec Management With SAMMY 05.05.2026 23min
    You can use sammy for free on sammy.codific.com
  • AI in AppSec, May 2026 Update 28.04.2026 21min
    This episode looks at the latest developments around AI tools in Application Security. Guidance and best practices in the new context.
  • Introduction to EU DORA 21.04.2026 21min
    This is deep dive into DORA the EU Digital Operational Resilience Act. For more details refer to the Codific website: https://codific.com/summary-of-dora/
  • CRA Standards 14.04.2026 22min
    This episode covers the EN-40000 standards that serve as a provisional basis for CRA Horizontal Standards. This is the summary of resources collected on complycra.eu for the full story and presentation please refer to the website:https://complycra.eu/cra-standards/
  • Introduction to Secure Control Frameworks 07.04.2026 21min
    This content is a summary of a deep dive by the Codific team. For the full coverage refer to the article on the Codific Website: https://codific.com/secure-controls-framework-a-comprehensive-overview/
  • How to build and manage your appsec program. 31.03.2026 23min
    This is a summary of interviews in the Codific website.For the full stories please refer to the Codific website: https://codific.com/codifics-customers-success-stories/
  • NIS2 Directive: Everything you need to know 24.03.2026 22min
    This is a summary of a deep dive by the Codific team.For the full article please refer to the Codific website:https://codific.com/nis-2-directive-compliance-guide-fines-scope/
  • NIST SSDF 1.2: an introduction 17.03.2026 22min
    This is a summary of a deep dive by Aram Hovsepyan.For the full article refer to the Codific website: https://codific.com/nist-ssdf-1-2-explained/
  • Women in cybersecurity, what it really looks like, and where you can fit 09.03.2026 28min
    In this International Women’s Day interview, we speak with Kim Wuyts, a privacy engineer and privacy by design advocate with 15+ years across security and privacy. Kim helped develop LINDDUN, a privacy threat modeling framework, and regularly speaks at international security and privacy conferences.This conversation is for women who are considering cybersecurity or privacy, women already in tech who want to move into security, and anyone who wants a clearer, more realistic picture of what the work looks like.What we cover:- Why cybersecurity is bigger than “super technical” roles- What the job actually looks like day to day, and why it’s often collaborative and human- How to start small, pick a lens, and stay curious- Ways to “taste the field”, meetups, OWASP, short courses, CTFs, and shadowing security or privacy reviews- The real skill, asking better questions, not knowing everything- Confidence tips, including “I’ll get back to you” and applying before you feel 100% ready- Community and mentorship, how to find your tribeRead the press release here: https://securitybrief.co.uk/story/women-in-cybersecurity-what-it-really-looks-like-and-where-you-can-fit
  • Can we do Application Security with AI? An analysis of Claude Code Security. 03.03.2026 19min
    This episode is based on analysis by Aram Hovsepyan.For the full story refer to his blog post here: https://codific.com/claude-code-security-will-ai-disrupt-application-security/

Suosittu maassa

Tämä podcast esiintyy myös näiden maiden podcast-listoilla.