
Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo
Om avsnittet
Changing security culture requires more than distributing policies or buying another training platform. In this recorded AppSec USA presentation, Chris Romeo shares practical ways to influence how an organization thinks and acts about software security. He explains why every organization already has a security culture, how to assess it, and why the assessment must lead to action. The talk explores speaking the language of developers and executives, sharing information openly, building a champions community, and recognizing useful behavior. Chris also describes learning experiences that fit developers’ work and demonstrations that make application risk concrete for leaders. He closes by connecting culture change to observable outcomes, including whether teams resolve security problems more quickly over time.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Chris Romeo:
→ Chris Romeo on LinkedIn
Mentioned in this episode:
→ OWASP SAMM
→ OWASP Juice Shop
→ WebGoat
→ DevSlop
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Security culture hacking at AppSec USA
08:05 Every organization already has a security culture
09:53 Transparency and sharing security knowledge
10:07 Assessing and measuring the starting point
11:39 Turning assessment into an action strategy
12:34 Learning developers’ language and methods
13:49 Speaking to executives about risk and value
14:24 Communication and security’s own assumptions
17:37 Building a deliberate security community
18:06 Champions programs and learning sessions
19:57 Recognition and incentives for useful behavior
22:45 Developer-friendly learning and hands-on practice
27:43 Educating executives about application security
29:04 Demonstrating risk and measuring improvement
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.