Skip to content
Artwork for The AppSec Management Podcast

The AppSec Management Podcast

Dr. Dag Flachet, Dr. Aram Hovsepyan

This podcast is about application security, OWASP and security first compliance. It is targeted at those involved with application security programmes and anyone interested in the frontier of cybersecurity in applications.

Play
  • 21 episodes
  • weekly
  • Avg 24 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S4 · E6
    Tuesday · 36 min

    CRA Sessions: Vulnerability Management

    Vulnerability management is at the core of the Cyber Resilience Act (CRA). But what are the minimal expectations? Annex I, Part 2 lists 8 expectations manufacturers shall implement, yet they remain very abstract.Chapters:00:00 Introduction and a motivating example02:39 CRA: a brief recap08:11 Vulnerability management basics10:00 Revisiting the running example of a smart fridge10:38 Incident management18:25 The definition of an incident24:30 Defect management27:26 Security testing28:35 Patching and updating29:51 Secure deploy33:11 Recap of all required security activities under the CRAAbout this video:Today, the topic of vulnerability management typically makes one think of a SAST, DAST, IAST, SCA scanner. It makes us think of a triaging process and fixing the critical and high severity findings in the attempts to try to keep the risk low. However under the CRA vulnerability management is much broader. Fortunately, at least based on the OWASP SAMM latest benchmark, the industry is doing so much better on vulnerability management than on any other security related activities.Incident detection and response is the first major subtopic under vulnerability management. Especially in larger organizations most of the aspects of incident management are well under control. Amongst the key outstanding issues we typically face is the lack of communication between the product teams and the incident management teams as these are always siloed. Without a clear understanding of the business context the incident management can only focus on generic risks.Under the CRA the definition of an incident is interesting to understand. It differs starkly from the organizational perspective where a minor incident affecting a single user may be overlooked. CRA is all about the sensitivity of the data rather than the volume of the data.Defect management is about making sure that all findings are reported to a centralized defect tracking system, triaged and tackled within pre-defined time frames.Security testing is all about the tooling organizations are so excited about. However just pulling in a scanner is likely to make things worse. Teams must have a full grip on their scanners by tweaking the rulesets and how they tie to the build and deploy process.Patching and updating focuses on regularly patching OS and infrastructure components.Finally, secure deploy is actually a very complex topic as it needs to ensure the authenticity and integrity of the code moving from development to production. Code signing is one of the key controls, yet getting that aspect right is not as straightforward as it seems.All in all, you need a systematic approach to product security. Codific's SAMMY tool can help you out there. SAMMY can enable your gap assessment, improvement planning and demonstrating those improvements. SAMMY has an instrumental integration with JIRA so that your developers don't have to jump into a new tool. SAMMY also features an MCP server that allows your AI tools to generate all sorts of board reports based on your data in SAMMY.Links:👉 Use the SAMMY tool to manage your security posture: https://sammy.codific.com👉 Check the industry standard AppSec management model: https://owaspsamm.org

  • S3 · E15
    August 26 · 4 min

    September 11 CRA reporting obligations. What and how to?

    On September 11, 2026 the CRA reporting obligations come into effect. What exactly are you supposed to repot, to whom and how do you do it. Content from Complycra.eu full article here: https://complycra.eu/what-are-the-cra-obligations-starting-september-11-2026/ To use SAMMY Free go to https://sammy.codific.com

  • S3 · E14
    August 14 · 14 min

    CRA Horizontal Standards Explained

    This chapter summarizes the horizontal standards of CRA and is based on resources from complycra.eu. Voices and narrative is AI generated based on in depth resources. For full factual accuracy refer to complycra.eu

  • S4 · E5
    July 20 · 28 min

    CRA Sessions: Technical Security Requirements

    The Cyber Resilience Act makes it mandatory to take security into consideration from a product’s design until sunsetting. But what are these technical security requirements? Is this about yet another checkbox exercise we can "fake it until we make it" along with a bunch of documents we can now effortlessly generate?

  • S3 · E13
    June 16 · 4 min

    PRC, Product Risk and Compliance

    Traditional GRC tools were built for corporate IT, not for modern software development. As regulations like the EU Cyber Resilience Act raise the bar for product-level security, a new discipline is emerging: Product Risk and Compliance (PRC).

  • S4 · E4
    June 9 · 26 min

    CRA Sessions: Risk Assessment

    Risk assessments are the starting point of your application security program and as it turns out your Cyber Resilience Act compliance strategy. If you think about it, it makes absolute sense. If there is no risk, you don't really need security. Unfortunately, that's not the world we are living in and creating a crystal clear understanding of the risk profile for each of your products is essential.Risk has two components to it. It has a more "businessy" component that is related to loss magnitude or impact. This is the component that needs to be dictated by the business.The second risk component is more technical, namely threat event frequency.The combination of the two factors is what we typically think of risk. However it is critical to stress that the first "business"-side of risk is much easier to come up with. It is also relatively limited. It is also the first one in terms of a sequence. This is also precisely what CRA suggests, you need to start with clearly defining the context of your product, its risk and risk acceptance criteria.The second factor, i.e., the actual threats, is virtually unlimited. Once again you need the business side of the story to come up with meaningful threats.In this second episode of our CRA series podcast we dive deep into the risk assessment and threat modeling concepts in the context of the upcoming EU Cyber Resilience Act.

  • S4 · E3
    June 2 · 23 min

    What is CRA and why do we care?

    Lara and I kick off our new series on the EU Cyber Resilience Act (CRA), where we'll go deep on what the regulation actually means for product security teams and how to translate it into concrete application security practice.In this first episode, we cover the foundations:What the CRA is and why it existsWhich products fall under its scope, and which don'tHow compliance requirements differ between product categories (default, important, and critical)The role of horizontal and vertical standards, and how they fit togetherWhat's at stake if you simply ignore the regulation — the penalties, market access consequences, and liability implicationsTo help you figure out where your product stands, we've also built a CRA screening tool that walks you through the key scoping questions and gives you a first read on your obligations.In the coming episodes, we'll move from the regulatory frame into the practical side: what "secure by design," vulnerability handling, SBOMs, and conformity assessments actually look like when you're shipping real products.👉 Try the CRA screening tool: https://sammy.codific.com/cra👉 Subscribe so you don't miss the next episodes.

  • S4 · E2
    May 26 · 47 min

    Is security becoming prompt-driven? The future of AppSec in the age of AI

    AI is changing everything - including how attackers think. But is the security industry keeping up?This webinar, hosted jointly with Toreon, tackles one of the biggest questions in AppSec right now: as AI agents, LLMs, and prompt-driven development become the norm, what does application security even look like?📌 Follow us on LinkedIn: https://www.linkedin.com/company/9420309/🌐 Or visit our website: https://codific.com/🔔 Subscribe for more AppSec tutorials and security framework insights!

  • S4 · E1
    May 19 · 42 min

    AppSec at SMEs, how are your peers doing?

    In this chapter we have the research team of PXL University of Applied Sciences that did an in depth analysis of the state of AppSec processes at SMEs. They report on their outcomes and findings.

  • S3 · E10
    April 28 · 21 min

    AI in AppSec, May 2026 Update

    This episode looks at the latest developments around AI tools in Application Security. Guidance and best practices in the new context.

  • S3 · E9
    April 21 · 21 min

    Introduction to EU DORA

    This is deep dive into DORA the EU Digital Operational Resilience Act. For more details refer to the Codific website: https://codific.com/summary-of-dora/

  • S3 · E8
    April 14 · 22 min

    CRA Standards

    This episode covers the EN-40000 standards that serve as a provisional basis for CRA Horizontal Standards. This is the summary of resources collected on complycra.eu for the full story and presentation please refer to the website: https://complycra.eu/cra-standards/

  • S3 · E7
    April 7 · 21 min

    Introduction to Secure Control Frameworks

    This content is a summary of a deep dive by the Codific team. For the full coverage refer to the article on the Codific Website: https://codific.com/secure-controls-framework-a-comprehensive-overview/

  • S3 · E6
    March 31 · 23 min

    How to build and manage your appsec program.

    This is a summary of interviews in the Codific website. For the full stories please refer to the Codific website: https://codific.com/codifics-customers-success-stories/

  • S3 · E5
    March 24 · 22 min

    NIS2 Directive: Everything you need to know

    This is a summary of a deep dive by the Codific team. For the full article please refer to the Codific website: https://codific.com/nis-2-directive-compliance-guide-fines-scope/

  • S3 · E4
    March 17 · 22 min

    NIST SSDF 1.2: an introduction

    This is a summary of a deep dive by Aram Hovsepyan. For the full article refer to the Codific website: https://codific.com/nist-ssdf-1-2-explained/

  • S3 · E3
    March 9 · 28 min

    Women in cybersecurity, what it really looks like, and where you can fit

    In this International Women’s Day interview, we speak with Kim Wuyts, a privacy engineer and privacy by design advocate with 15+ years across security and privacy. Kim helped develop LINDDUN, a privacy threat modeling framework, and regularly speaks at international security and privacy conferences.This conversation is for women who are considering cybersecurity or privacy, women already in tech who want to move into security, and anyone who wants a clearer, more realistic picture of what the work looks like.What we cover:- Why cybersecurity is bigger than “super technical” roles- What the job actually looks like day to day, and why it’s often collaborative and human- How to start small, pick a lens, and stay curious- Ways to “taste the field”, meetups, OWASP, short courses, CTFs, and shadowing security or privacy reviews- The real skill, asking better questions, not knowing everything- Confidence tips, including “I’ll get back to you” and applying before you feel 100% ready- Community and mentorship, how to find your tribeRead the press release here: https://securitybrief.co.uk/story/women-in-cybersecurity-what-it-really-looks-like-and-where-you-can-fit

Showing 1–20 of 21 episodes