Skip to content
Artwork for Relating to DevSecOps
TechnologyBusinessCareers

Relating to DevSecOps

Ken Toler and Mike McCabe

A Podcast dedicated to forging iron clad relationships between developers, engineers, operations, and security practitioners by discussing hot topics in the world of DevSecOps. This podcast aims to air out some of the common gripes, misconceptions, and hardships that these teams face in the real world every day.

Play
  • 20 episodes
  • every few months
  • Avg 36 min
  • English
  • S1 · E84
    July 24 · 46 min

    Episode #084: No Humans Required: Agentic Attackers vs. Automated Defenders

    Send us Fan Mail AI is changing the economics of cyberattacks by making them faster, cheaper, and easier to scale. In this episode of Relating to DevSecOps, Ken is joined by Conor Sherman, Chief Security Officer at Sysdig and host of the Zero Signal podcast, to explore what the rise of agentic threat actors means for defenders. Using the Jade Puffer ransomware attack as a real-world example, they discuss how autonomous attackers can discover vulnerabilities, compromise environments, move laterally, adapt their code, identify valuable data, and deploy ransomware with little human involvement. The conversation also looks at how defenders can respond through stronger security architecture, automated patching, real-time detection, automatic response, and AI-assisted modernization. Rather than replacing security fundamentals, AI can help teams apply them faster, handle difficult edge cases, and build more resilient systems. For security teams wondering where to begin, the message is simple: start small, automate one meaningful workflow, and build from there.

  • S1 · E83
    April 29 · 43 min

    Episode #083: AI Mythos, Security Fundamentals, and the Zero-Day Panic Cycle

    Send us Fan Mail Ken and Mike are back in the AI trenches, this time unpacking the hype, fear, and practical security implications surrounding Anthropic’s Mythos preview. As the industry reacts to claims around AI-driven vulnerability discovery and exploit generation, the hosts ask a more important question: are we actually ready to fix what we already know is broken? The conversation cuts through the zero-day panic and focuses on the fundamentals that still matter: patching, hardening, reducing attack surface, validating AI-generated code, and keeping deterministic security checks in place. From supply chain attacks and GitHub Actions misconfigurations to agentic development workflows and the future of CI/CD, Ken and Mike explore where AI may genuinely change the threat landscape and where security teams are still fighting the same old battles. If your organization is rushing to build faster with AI, this episode is a reminder to also use it to build better.

  • S1 · E82
    March 17 · 44 min

    Episode #082: AI Hype, Human Cost

    Send us Fan Mail Ken and Mike are back from the grave to kick off 2026 with a timely debate on the AI panic cycle hitting software and security. They dig into the biggest questions flying around the industry right now: Is AI taking developer and security jobs? Is SaaS dying? Is software engineering being replaced by vibe coding and agents? From maker-checker workflows and token costs to AI-generated bugs, false positives, and attackers using autonomous tooling to move faster, this episode cuts through the hype from both the doomer and evangelist camps. The conclusion: software isn’t dead, security definitely isn’t solved, and the teams that adapt their craft instead of abandoning it will be the ones that keep up.

  • S1 · E81
    Oct 29, 2025 · 21 min

    Episode #081: Burnout by Budget Season: Surviving Q4 in Security

    Send us Fan Mail In this candid and cathartic episode, Ken and Mike unpack the chaos that is Q4 for security professionals. From budget burnouts to end-of-year pentesting sprints, they explore why the final months of the year feel like a perfect storm for stress. Tune in as they share hard-earned lessons, practical advice for maintaining your sanity, and some gentle reminders that not everything needs to ship before Christmas. Whether you’re a tired vendor, an overwhelmed engineer, or just trying to make it to PTO, this episode is for you.

  • S1 · E80
    Aug 25, 2025 · 34 min

    Episode #080: Patch Me If You Can: Compliance, SLAs, and Other Fairytales

    Send us Fan Mail In this no-punches-pulled return from hiatus, Ken and Mike dig deep into the messy middle of vulnerability management, SLA fatigue, and the illusion of compliance. Are we building secure systems or just passing audits? From legacy cruft to exploitable CVEs, this episode unpacks the real-world pressures of SOC 2, the auditor dance, and whether fixing every “critical” is even feasible. Perfect for practitioners trying to balance the checkbox culture with actual risk reduction, this one’s got stories, strategies, and spicy takes. Bonus: tips on managing auditors without losing your mind—or your security posture.

  • S1 · E79
    Jun 10, 2025 · 37 min

    Episode #079: CISOver It: When Dashboards Replace Direction

    Send us Fan Mail In this episode of Relating to DevSecOps, Ken and Mike discuss the challenges faced by CISOs in today's security landscape, particularly the struggle to balance immediate security needs with long-term preventative strategies. They explore the disconnect between security leadership and practitioners, the urgency of addressing security issues, and the importance of understanding the root causes of vulnerabilities. The conversation emphasizes the need for CISOs to engage more deeply with their teams and to focus on effective, context-driven security solutions rather than simply reacting to the latest threats.

  • S1 · E78
    Apr 22, 2025 · 46 min

    Episode #078: 🔥 Burn Your 30-page Policies: Tanya’s Got Better Ideas

    Send us Fan Mail In this must-listen episode of Relating to DevSecOps, Ken welcomes the ever-inspiring Tanya Janca, aka SheHacksPurple—author, AppSec expert, and champion of making security usable. Together, they dig into why so many application security policies fail, why developers ignore them, and how to make them actually work. Tanya shares real-world experiences from both dev and security perspectives, plus her journey from being ignored to lobbying governments for change. From communication failures and TL;DR policy pages to leveraging wikis and code reuse, this episode is a practical masterclass in creating impactful, developer-friendly security standards.

  • Mar 24, 2025 · 31 min

    Episode #077: Is Google Eating the Cloud? 🔥 Wiz.io Acquisition Hot Takes

    Send us Fan Mail In this episode of Relating to DevSecOps, Ken Toler and Mike McCabe dive deep into Google's blockbuster acquisition of Wiz.io for a reported $32 billion. They explore the implications for cloud security, the consolidation of the DevSecOps tooling landscape, and how this move compares to Google’s previous acquisitions like Mandiant and Chronicle. The duo debates the future of multi-cloud strategies, platform fatigue, and whether Wiz will remain the darling of the security community—or get lost in the labyrinth of Google Cloud products. With sharp insights and a dash of hot takes, they paint a picture of a cloud security ecosystem at a pivotal turning point

  • S1 · E76
    Feb 4, 2025 · 33 min

    Episode #076: ShmooBalls & Open Source Brawls: DevSecOps, Risk, and the Final ShmooCon

    Send us Fan Mail Welcome to 2025! Ken and Mike kick off the new year with their security resolutions (or lack thereof) before diving into the bittersweet farewell to ShmooCon, one of the most beloved hacker conferences. Ken shares his experiences from the final event, including insights on hardware hacking, radio security, and the unique hacker culture that made ShmooCon special. They also unpack one of the most practical talks from the conference: a deep dive into open source security tools versus enterprise solutions, highlighting ways security teams can cut costs without sacrificing effectiveness. Speaking of open source, the hosts discuss the controversy surrounding Semgrep’s licensing changes and the rise of OpenGrep, the latest community-driven fork in response to closed-source shifts—drawing parallels to the Terraform/OpenTofu saga. Finally, the duo explores cyber risk from an insurance perspective, breaking down how breaches translate into real-world financial costs (hint: mailing breach notifications alone could bankrupt you). Whether you're a security pro, an open source advocate, or just here for the ShmooBall nostalgia, this episode has something for you!

  • S1 · E75
    Dec 24, 2024 · 36 min

    Episode #075: Ghosts of DevSecOps: Past, Present, and Future

    Send us Fan Mail In this special holiday-themed episode of Relating to DevSecOps, hosts Ken and Mike channel their inner Dickens with a retrospective journey through the "Ghosts of DevSecOps Past, Present, and Future." From lessons learned about security awareness and collaboration challenges of the past, to the growing pains and contradictions of today’s implementation of security basics, they explore it all. Wrapping up with a hopeful look at future innovations like policy-as-code and preemptive security measures, the hosts outline their visions for a more integrated and automated security future. Packed with insights, humor, and holiday spirit, this is a must-listen for those charting the path forward in DevSecOps.

  • S1 · E74
    Dec 9, 2024 · 36 min

    Episode #074: Battling Budgets in Security

    Send us Fan Mail In this episode of Relating to DevSecOps, hosts Ken and Mike tackle the complex challenges of managing security budgets in organizations of all sizes. From small, scrappy teams to sprawling enterprises, they explore how security leaders can navigate tight financial constraints while maintaining strong security postures. They share insights on integrating security into IT operations, leveraging open-source tools, and rethinking traditional budget allocations. Whether you’re a CISO grappling with scaling or a developer looking to improve security outcomes, this discussion is packed with actionable strategies and thought-provoking debates on the future of security spending https://www.youtube.com/watch?v=8U3QzJBCNZ0

  • S1 · E73
    Oct 21, 2024 · 37 min

    Episode #073: Staffing Security in DevSecOps

    Send us Fan Mail In this episode, Ken and Mike discuss the pressing issue of staffing security in the DevSecOps field. They explore the challenges of finding qualified application security professionals, the importance of diverse backgrounds in security roles, and the paradox of understaffed security teams despite a high demand for cybersecurity jobs. The conversation also delves into strategies for mitigating staffing issues, such as empowering security champions within organizations, leveraging automation and tooling, and avoiding bottlenecks in security processes. Throughout the discussion, they emphasize the need for a balanced approach to security that considers both technical and human factors.

  • S1 · E72
    Aug 28, 2024 · 33 min

    Episode #072: Measuring the Immeasurable: The Power and Pitfalls of Metrics in DevSecOps

    Send us Fan Mail Ken and Mike dive deep into the world of metrics and measurement in the context of security and DevSecOps. They explore the critical role metrics play in driving security improvements, from tracking vulnerabilities to gauging the effectiveness of incident response. The hosts discuss what makes a good metric, the importance of aligning metrics with business goals, and the dangers of relying too heavily on numbers alone. They also tackle the challenges of quantifying "squishy" aspects like culture and training effectiveness. Whether you're a seasoned security professional or just getting started, this episode offers valuable insights into the art and science of measurement in security Reference talk: https://www.youtube.com/watch?v=GXTvlQXVCOs&t=0s

  • S1 · E71
    Jun 19, 2024 · 25 min

    Episode #071: Retro Vibes with Retrospectives

    Send us Fan Mail Ken and Mike discuss the importance of postmortems in incident response and security incidents. They explore the definition of postmortems, the value of reflection, the challenges of blame, and the significance of actionable outcomes. They also touch on the transparency of postmortems and the need for root cause analysis. The conversation concludes with a brief announcement about an upcoming conference series.

  • S1 · E70
    May 8, 2024 · 39 min

    Episode: #070: Putting da BOM in SBOM and SCA

    Send us Fan Mail Ken and Mike discuss supply chain security, including software composition analysis (SCA) and software bill of materials (SBOM). They highlight the importance of understanding the components that make up your software and the risks associated with using third-party libraries. They also discuss recent supply chain failures, such as the XZ library hack and the SolarWinds attack. The hosts emphasize the need for organizations to stay up to date with software patches and to consider the security of commercial off-the-shelf software. They caution against placing too much focus on any one security tool or approach, including SBOM, and instead advocate for a well-rounded approach to security.

  • S1 · E69
    Mar 20, 2024 · 32 min

    Episode #069: Your SaaS is Grass

    Send us Fan Mail In this episode Mike and Ken dive into the wild world of SaaS products in DevSecOps. From vendors to security tooling hygiene they cover an often overlooked ecosystem of cloud and software services that may be rotting in the sky of your workloads. Join up for a listen on SaaS Security!

  • S1 · E68
    Feb 21, 2024 · 34 min

    Episode #068: Data Breaches and DevSecOps

    Send us Fan Mail With pep and full youtube energy Ken and Mike discuss the findings of the IBM "Cost of a Data Breach" report and its implications for DevSecOps. They highlight the importance of integrating security into every phase of the software development life cycle and the positive impact it can have on reducing the cost of a data breach.

  • S1 · E67
    Jan 26, 2024 · 35 min

    Episode #067: Welcome to 2024! AppSec Resolutions and A Smhoocon Recap

    Send us Fan Mail Ken and Mike discuss their new year's resolutions related to application security. They also reflect on the impact of AI and its adoption in the industry. The hosts share their experiences attending conferences and highlight interesting talks on topics such as zero-day vulnerabilities and fuzzing LLM models. They discuss the OWASP LLM Top 10 and the evolving perception of AI in the industry. The conversation concludes with a discussion on the definition of DevSecOps and how it has evolved over time, as well as their predictions for DevSecOps in 2024.

  • S1 · E66
    Dec 5, 2023 · 42 min

    Episode #066: Exploration of the Shifting Definition of Shifting Left

    Send us Fan Mail We are joined by incredible guests Mikhail Chechik and Marcus Hallberg as they help us define DevSecOps and emphasize the importance of a security mindset throughout the development process. These two incredible folks explore common misconceptions about shifting left and discuss the challenges of triaging and validating vulnerabilities early in the development lifecycle. We enter in the wild world of this wonderful shifting buzzword and how it applies to incident response, design, people, and the general development process.

  • S1 · E65
    Nov 10, 2023 · 33 min

    Episode #065: LASCON 2023 Recap - AI, a Misunderstood Menace or Magic Bullet

    Send us Fan Mail On this episode of R2DSO Mike and Ken dive into their takeaways and experiences from LASCON 2023 in Austin, TX where AI was both a problem child and praised bringer of salvation in security. Vendors and companies alike are embracing AI with wide eyes and there was no shortage of talks, presentations, and hallway conversations about the topic. Beyond that security is fast accepting that they can't be the department of "No" a consistent theme here on the podcast. The team had a fantastic time at LASCON and we're happy to see where the industry is going!

Showing 1–20 of 20 episodes