
AppSec Adventure
What does taking AppSec off-road mean?


I approach AppSec the same way I build my overlanding vehicle: not for an abstract ideal, but for the terrain ahead.
A good AppSec program is not built around theory. It has to fit the company it supports: the size of the organization, the number of teams and projects, the way people work together, the technologies they use, the decisions they can make, and the existing security culture.
That is why I do not start with generic roadmaps. I start by understanding where your organization really stands, how your development process works today, what is slowing it down, and what kind of support your development teams actually need from your AppSec program.
From there, we can figure out what to improve and how to make your AppSec program work in the real world.
Two ways to work with me
The AppSec Ownership Model


We are all responsible for AppSec. Does that sound right to you?
Shared responsibility fails when it is not built on clear accountability.
I developed a practical AppSec Ownership Model to help you set clear expectations for each role. You can explore it on my blog.
- Understand which roles need to own which parts of AppSec.
- Dive into each role for clear responsibilities and boundaries.
- Learn how to bring in external expertise without losing independence.
Apply it to your context: Where is accountability currently missing?
Am I your AppSec guide?


It’s pretty simple. If you’re only here to check boxes, please move on. If you want to build real resilience, then you’re in exactly the right place – and I’m glad you’re here. You need someone who doesn’t just talk about resilience. You need someone who lives it. I built my whole life around resilience.
I chose freedom over security when I embraced full-time overland travel in my old 4x4 Chevrolet Blazer. That means being ready to fix whatever comes my way. Whether the car breaks down, gets stuck, or I'm just really sick and need to recover somewhere remote.
On the road or in security, I know I won’t have all the answers right away. But I’ll figure it out, using the skills and tools I have to make the best of it.
It's your choice:
- Go the corporate route, hire the suit, buy tools you don’t need and check your boxes.
- Or work with someone who helps you build something that actually works in the wild.
For me, AppSec isn’t about limiting your freedom to build your vision. It’s about being prepared for the road ahead and keep moving.
Just like I constantly prep for the next off-road challenge by learning how to fix my rig, carrying the right gear, recovering when stuck, or leaning on my network when I need it – we’ll build your AppSec strategy to be just as ready for your next epic expedition in software.


