PodParley PodParley

Unravelling Trends In Data Security With Danny Allan

Are you curious about the ever-changing landscape of data security? In this episode, we are joined by Danny Allan, the newly appointed Chief Technology Officer at Snyk, to delve into the evolving landscape of data security. In our conversation, we discussed his professional background and how he went from hacking security systems at university to becoming a security expert at Snyk. Hear about his experience in dynamic application security testing and the challenges and opportunities of working for large companies. We unpack how controlling human actions can reduce security vulnerabilities, the nuances of running cloud-hosted services, and how the techniques used for static application security testing have changed. Danny explains the importance of considering security aspects during the early stages of software development and how governance has integrated into data security measures. Gain valuable insights into the ever-changing landscape of data security, AI’s potential role in revolutionizing security practices, and much more.

Episode 149 of the The Secure Developer podcast, hosted by Danny Allan, Guy Podjarny, titled "Unravelling Trends In Data Security With Danny Allan" was published on March 20, 2024 and runs 36 minutes.

March 20, 2024 ·36m · The Secure Developer

0:00 / 0:00

Are you curious about the ever-changing landscape of data security? In this episode, we are joined by Danny Allan, the newly appointed Chief Technology Officer at Snyk, to delve into the evolving landscape of data security. In our conversation, we discussed his professional background and how he went from hacking security systems at university to becoming a security expert at Snyk. Hear about his experience in dynamic application security testing and the challenges and opportunities of working for large companies. We unpack how controlling human actions can reduce security vulnerabilities, the nuances of running cloud-hosted services, and how the techniques used for static application security testing have changed. Danny explains the importance of considering security aspects during the early stages of software development and how governance has integrated into data security measures. Gain valuable insights into the ever-changing landscape of data security, AI’s potential role in revolutionizing security practices, and much more.

Episode Summary

Are you curious about the ever-changing landscape of data security? In this episode, we are joined by Danny Allan, the newly appointed Chief Technology Officer at Snyk, to delve into the evolving landscape of data security. In our conversation, we discussed his professional background and how he went from hacking security systems at university to becoming a security expert at Snyk. Hear about his experience in dynamic application security testing and the challenges and opportunities of working for large companies. We unpack how controlling human actions can reduce security vulnerabilities, the nuances of running cloud-hosted services, and how the techniques used for static application security testing have changed. Danny explains the importance of considering security aspects during the early stages of software development and how governance has integrated into data security measures. Gain valuable insights into the ever-changing landscape of data security, AI’s potential role in revolutionizing security practices, and much more.

Show Notes

In this episode, Guy Podjarny is joined by Danny Allan, the new CTO at Snyk. Danny shares his fascinating career journey that has taken him in and out of the application security space over the past 20+ years.

They discuss how application security practices like static analysis (SAST) and dynamic scanning (DAST) have evolved, with SAST becoming much faster and easier to integrate earlier in the development cycle. Danny reflects on what has changed and what has surprisingly stayed the same since his earlier days in AppSec.

The conversation digs into the intersections between application security, data security, cloud security, and how these domains are becoming more interconnected as the same teams take on responsibilities across these areas. Danny draws insights from his recent experience at Veeam, highlighting how practices like data immutability and multi-person authorization grew in importance to combat ransomware threats.

Looking ahead, Danny and Guy explore the potential impact of AI/ML on application security. From automating threat modeling to personalizing vulnerability findings based on developer interests to generating rules and fixes, Danny sees AI unlocking many opportunities to transform AppSec practices.

Overall, this episode provides a unique perspective spanning Danny's 20+ year career in security. His experiences illustrate the evolution of AppSec tooling and processes, the blurring of domains like app/data/cloud security, and how AI could radically reshape the future of application security.

Links

Follow Us

Follow Us

Why Download WinRAR: The Essential Tool for File Compression on Windows WallaceSchultz WinRAR is a popular tool for compressing and decompressing files on Windows. Developed by RARLAB, this software is known for its efficiency in optimizing file organization, storage, and data transfer. With seamless integration into the Windows context menu, creating RAR or ZIP files is quick and easy. Downloading WinRAR provides a fast, secure, and reliable solution for managing files on your computer. The Secure World Foundation Podcast Secure World Foundation This podcast features content produced by the Secure World Foundation (SWF), an endowed, private operating foundation that promotes cooperative solutions for space sustainability and the peaceful uses of outer space. The Foundation acts as a research body, convener and facilitator to promote key space security, and other related topics, and to examine their influence on governance and international development. The Future Healthcare Today Podcast Future Healthcare Today Welcome to the Future Healthcare Today podcast. Join us as we explore the rapidly changing healthcare industry from the perspectives of providers, payers, and pharmaceutical and life sciences organizations. In each episode, we'll bring you engaging conversations with industry leaders and technology experts who are driving innovation in search of better patient outcomes and a more efficient healthcare system. We’ll dive into a wide range of topics including telehealth, how AI is changing patient experiences and drug developments, as well as best practices on how to secure critical data and PII. You will gain insights on how to put technology to work to improve patient outcomes, streamline operations, and reduce the costs of innovation. To learn more, check out our website:https://futurehealthcaretoday.com More Women Promoted Katy McFee Are you an ambitious woman who's been stuck at the sr. manager or director level, watching peers advance despite your consistently stellar performance? Do you find yourself drowning in back-to-back meetings, unable to carve out time for lunch, much less time for professional development? You are not alone. Breaking through to the executive level isn't about working harder—it's about transforming how others perceive your leadership.Join Katy McFee, a former tech executive and Forty under 40 winner turned leadership coach. Through her leadership programs, Forbes.com writing and keynote speaking, she's empowered hundreds of women to secure promotions and thrive in their roles. When she's not helping over 100,000 women on social media crush their career goals, she's raising 3 kids and running ultramarathons—proving that resilience isn't just a buzzword, it's a lifestyle.Each week on More Women Promoted, dive into practical strategies
URL copied to clipboard!