
Matt Clapham -- The Technical Debt Ceiling
Om avsnittet
Every software organization accumulates technical debt, but security debt raises the cost and risk of every future change. Matt Clapham joins Chris at the Converge conference to explain how startups and enterprises incur debt through rushed decisions, flawed architectures, outdated dependencies, and products that outlive their original assumptions. They distinguish general technical debt from security-specific consequences, examine the effect on development and operations, and discuss ways teams can keep the problem visible. Matt argues for deliberate limits—a technical debt ceiling—supported by refactoring, dependency maintenance, prioritization, and clear ownership. The goal is not zero debt, but a sustainable level that does not prevent teams from improving or securing the product.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Matt Clapham:
→ ProdSec on X
→ Converge Detroit
Mentioned in this episode:
→ Converge Detroit
→ OWASP Dependency-Check
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Defining the technical debt ceiling
01:41 Technical debt in IoT and application security
02:58 People, process, and technology causes
05:19 How enterprises accumulate debt
06:58 Technical debt versus security debt
08:08 The impact of a flawed foundation
09:59 Reducing and managing technical debt
12:16 Third-party software and dependency risk
13:30 Products that never update components
16:25 Additional strategies for sustainable systems
18:20 Setting a practical debt goal
19:17 Resources and final recommendations
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.