PodParley PodParley

DevSecCon Panel

Episode 68 of The Secure Developer features some fantastic content from a panel at DevSecCon London. Clint Gibler, Research Director at the NCC Group is joined by Doug DePerry, Director of Defense at Datadog, Tash Norris, Head of Product Security at Moonpig, Jesse Endahl, CSO at Fleetsmith, and Zane Lackey, CSO at Signal Sciences. The discussion begins with a dive into building a good security culture within a company and ways to get other members of an organization interested in security.

Episode 68 of the The Secure Developer podcast, hosted by Doug DePerry, Zane Lackey, Clint Gibler, Tash Norris, Jesse Endahl, Guy Podjarny, titled "DevSecCon Panel" was published on July 2, 2020 and runs 70 minutes.

July 2, 2020 ·70m · The Secure Developer

0:00 / 0:00

Episode 68 of The Secure Developer features some fantastic content from a panel at DevSecCon London. Clint Gibler, Research Director at the NCC Group is joined by Doug DePerry, Director of Defense at Datadog, Tash Norris, Head of Product Security at Moonpig, Jesse Endahl, CSO at Fleetsmith, and Zane Lackey, CSO at Signal Sciences. The discussion begins with a dive into building a good security culture within a company and ways to get other members of an organization interested in security.

Today’s episode of The Secure Developer features some fantastic content from a panel at DevSecCon London. Clint Gibler, Research Director at the NCC Group is joined by Doug DePerry, Director of Defense at Datadog, Tash Norris, Head of Product Security at Moonpig, Jesse Endahl, CSO at Fleetsmith, and Zane Lackey, CSO at Signal Sciences. The discussion begins with a dive into building a good security culture within a company and ways to get other members of an organization interested in security. Some of the strategies explored include cross-departmental relationship building, incentivizing conversations with the security team through swag and food, and embedding security within development teams. We then turn our attention to metrics. There are often competing priorities between developers and security, which can cause tension. The panel shares some of the security metrics that have and have not worked for them, and we also hear different takes on the often-divisive bug count metric. Next up is a dive into working with limited personnel and financial resources, one of the most common constraints security teams face. We hear how the panel approaches prioritization, adding value to the organization as a whole, and the importance of making the security capabilities digestible to the developers. After this, the panel explores risk quantification and subsequent communication. While it's difficult to quantify risk precisely, there are some effective strategies such as risk forecasting. Along with this, techniques on communicating with executives in resonant ways to convey the severity of potential threats are also shared. Other topics covered include policy-driven vs technical-driven security and skilling up less technical teams, how to know when security is ‘done,’ and incentives for upholding security protocols!

Follow Us

The Secure World Foundation Podcast Secure World Foundation This podcast features content produced by the Secure World Foundation (SWF), an endowed, private operating foundation that promotes cooperative solutions for space sustainability and the peaceful uses of outer space. The Foundation acts as a research body, convener and facilitator to promote key space security, and other related topics, and to examine their influence on governance and international development. The Secure Woman Podcast Your Lifestylist Im your Lifestylist,Welcome to the Secure Woman podcast. Where I talk about the tools to elevating your thinking, move pass past trauma and we talk about healing is a journey. Our conversations are geared towards help women master their emotions and manifest their dream life, we are moving full throttle pass the pain. This podcast is for those looking to WIN past the pain. Support this podcast: https://podcasters.spotify.com/pod/show/yourlifestylist/support Secure the Future Dave Maasland Secure the Future is een maandelijkse podcast over digitale beveiliging. Met CISO’s, voor CISO’s. Over hoe we vandaag beschermen om morgen veiliger te zijn.Ik ben Dave Maasland en in de Secure the Future podcast ga ik in gesprek met vooraanstaande securityleiders in ons land. Je leert als CISO hoe vakcollega’s naar dit vak kijken, juist in deze tijd. Hoe gaan we om met de huidige ransomwarecrisis? Hoe bereiden we ons voor op dreigingen in de toekomst? Hoe begin je in het CISO-vak? En hoe zet je een sterk securityframework neer?Kortom: het is tijd om CISO’s in Nederland met elkaar te verbinden en meer kennis uit te wisselen. Natuurlijk ga ik ook met hen in gesprek over wie ze zijn als mens en hoe ze hier zijn gekomen.Luister daarom elke maand naar de Secure the Future podcast dé podcast over digitale beveiliging met CISO’s, voor CISO’s. The Reezy London Podcast The Reezy London Podcast Diving into the mind of Reezy London on his quest to secure financial longevity, happiness, & his interests in today’s world
URL copied to clipboard!