Matt Clapham -- The Technical Debt Ceiling episode artwork

EPISODE · Jun 6, 2017 · 22 MIN

Matt Clapham -- The Technical Debt Ceiling

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Every software organization accumulates technical debt, but security debt raises the cost and risk of every future change. Matt Clapham joins Chris at the Converge conference to explain how startups and enterprises incur debt through rushed decisions, flawed architectures, outdated dependencies, and products that outlive their original assumptions. They distinguish general technical debt from security-specific consequences, examine the effect on development and operations, and discuss ways teams can keep the problem visible. Matt argues for deliberate limits—a technical debt ceiling—supported by refactoring, dependency maintenance, prioritization, and clear ownership. The goal is not zero debt, but a sustainable level that does not prevent teams from improving or securing the product.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Matt Clapham:→ ProdSec on X→ Converge DetroitMentioned in this episode:→ Converge Detroit→ OWASP Dependency-CheckFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Defining the technical debt ceiling01:41 Technical debt in IoT and application security02:58 People, process, and technology causes05:19 How enterprises accumulate debt06:58 Technical debt versus security debt08:08 The impact of a flawed foundation09:59 Reducing and managing technical debt12:16 Third-party software and dependency risk13:30 Products that never update components16:25 Additional strategies for sustainable systems18:20 Setting a practical debt goal19:17 Resources and final recommendations

Episode metadata supplied by the publisher feed · Published Jun 6, 2017

Embed this episode

Every software organization accumulates technical debt, but security debt raises the cost and risk of every future change. Matt Clapham joins Chris at the Converge conference to explain how startups and enterprises incur debt through rushed decisions, flawed architectures, outdated dependencies, and products that outlive their original assumptions. They distinguish general technical debt from security-specific consequences, examine the effect on development and operations, and discuss ways te...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Matt Clapham -- The Technical Debt Ceiling

0:00 22:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 22 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 6, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!