Episódios

  • Episode #072: Measuring the Immeasurable: The Power and Pitfalls of Metrics in DevSecOps
    Aug 28 2024

    Send us a Text Message.

    Ken and Mike dive deep into the world of metrics and measurement in the context of security and DevSecOps. They explore the critical role metrics play in driving security improvements, from tracking vulnerabilities to gauging the effectiveness of incident response. The hosts discuss what makes a good metric, the importance of aligning metrics with business goals, and the dangers of relying too heavily on numbers alone. They also tackle the challenges of quantifying "squishy" aspects like culture and training effectiveness. Whether you're a seasoned security professional or just getting started, this episode offers valuable insights into the art and science of measurement in security

    Reference talk:

    https://www.youtube.com/watch?v=GXTvlQXVCOs&t=0s

    Exibir mais Exibir menos
    34 minutos
  • Episode #071: Retro Vibes with Retrospectives
    Jun 19 2024

    Send us a Text Message.

    Ken and Mike discuss the importance of postmortems in incident response and security incidents. They explore the definition of postmortems, the value of reflection, the challenges of blame, and the significance of actionable outcomes. They also touch on the transparency of postmortems and the need for root cause analysis. The conversation concludes with a brief announcement about an upcoming conference series.

    Exibir mais Exibir menos
    26 minutos
  • Episode: #070: Putting da BOM in SBOM and SCA
    May 8 2024

    Send us a Text Message.

    Ken and Mike discuss supply chain security, including software composition analysis (SCA) and software bill of materials (SBOM). They highlight the importance of understanding the components that make up your software and the risks associated with using third-party libraries. They also discuss recent supply chain failures, such as the XZ library hack and the SolarWinds attack. The hosts emphasize the need for organizations to stay up to date with software patches and to consider the security of commercial off-the-shelf software. They caution against placing too much focus on any one security tool or approach, including SBOM, and instead advocate for a well-rounded approach to security.

    Exibir mais Exibir menos
    40 minutos
  • Episode #069: Your SaaS is Grass
    Mar 20 2024

    Send us a Text Message.

    In this episode Mike and Ken dive into the wild world of SaaS products in DevSecOps. From vendors to security tooling hygiene they cover an often overlooked ecosystem of cloud and software services that may be rotting in the sky of your workloads. Join up for a listen on SaaS Security!

    Exibir mais Exibir menos
    33 minutos
  • Episode #068: Data Breaches and DevSecOps
    Feb 21 2024

    Send us a Text Message.

    With pep and full youtube energy Ken and Mike discuss the findings of the IBM "Cost of a Data Breach" report and its implications for DevSecOps. They highlight the importance of integrating security into every phase of the software development life cycle and the positive impact it can have on reducing the cost of a data breach.

    Exibir mais Exibir menos
    34 minutos
  • Episode #067: Welcome to 2024! AppSec Resolutions and A Smhoocon Recap
    Jan 26 2024

    Send us a Text Message.

    Ken and Mike discuss their new year's resolutions related to application security. They also reflect on the impact of AI and its adoption in the industry. The hosts share their experiences attending conferences and highlight interesting talks on topics such as zero-day vulnerabilities and fuzzing LLM models. They discuss the OWASP LLM Top 10 and the evolving perception of AI in the industry. The conversation concludes with a discussion on the definition of DevSecOps and how it has evolved over time, as well as their predictions for DevSecOps in 2024.

    Exibir mais Exibir menos
    35 minutos
  • Episode #066: Exploration of the Shifting Definition of Shifting Left
    Dec 5 2023

    Send us a Text Message.

    We are joined by incredible guests Mikhail Chechik and Marcus Hallberg as they help us define DevSecOps and emphasize the importance of a security mindset throughout the development process. These two incredible folks explore common misconceptions about shifting left and discuss the challenges of triaging and validating vulnerabilities early in the development lifecycle. We enter in the wild world of this wonderful shifting buzzword and how it applies to incident response, design, people, and the general development process.

    Exibir mais Exibir menos
    43 minutos
  • Episode #065: LASCON 2023 Recap - AI, a Misunderstood Menace or Magic Bullet
    Nov 10 2023

    Send us a Text Message.

    On this episode of R2DSO Mike and Ken dive into their takeaways and experiences from LASCON 2023 in Austin, TX where AI was both a problem child and praised bringer of salvation in security. Vendors and companies alike are embracing AI with wide eyes and there was no shortage of talks, presentations, and hallway conversations about the topic. Beyond that security is fast accepting that they can't be the department of "No" a consistent theme here on the podcast. The team had a fantastic time at LASCON and we're happy to see where the industry is going!

    Exibir mais Exibir menos
    33 minutos