

AppSec Adventure
Can you trust it when...
...your security hero is gone?
Every organization has these security heroes you can just call when something bad happens.
Who are your security heroes? What happens when they are on holiday, sick or simply leave tomorrow?
Who would fix it then?
...delivery pressure spikes?
This new feature or product that should have been shipped yesterday? We've all been there.
What corners would get cut to speed up delivery? Would you even notice when security gets cut?
What would get sacrificed?
...a critical incident hits?
No security budget can ensure your software will be 100% secure. Incidents are part of the game.
So let's face it: would a critical incident turn into a disaster, or are you prepared to handle it smoothly?
How painful would it be?


What causes AppSec programs to break down?
They are built on a false assumption.
Most AppSec programs focus on tools, policies and processes. Some may even go further by including people through training and Security Champions programs.
Nothing wrong with that, as long as you are on a paved road.
Besides all those measures, you are dealing with conflicting priorities, cultural friction, implicit expectations, unclear responsibilities, different personalities and always limited budget.
Does this sound like a nicely paved road?
Your terrain is much closer to navigating a rough off-road track with mud, deep sand or sharp rocks. Maybe you even need to cross a few rivers.
That's why you need to build a resilient AppSec system.
What causes AppSec programs to break down?


They are built on a false assumption.
Most AppSec programs focus on tools, policies and processes. Some may even go further by including people through training and Security Champions programs.
Nothing wrong with that, as long as you are on a paved road.
Besides all those measures, you are dealing with conflicting priorities, cultural friction, implicit expectations, unclear responsibilities, different personalities and always limited budget.
Does this sound like a nicely paved road?
Your terrain is much closer to navigating a rough off-road track with mud, deep sand or sharp rocks. Maybe you even need to cross a few rivers.
That's why you need to build a resilient AppSec system.


How does a resilient AppSec system differ?
A common AppSec program is basically a set of isolated measures. Success is often meassured by activity. How many developers did you train? How many vulnerabilities where discovered and closed?
But AppSec doesn't happen isolated.
It is built around an existing system that produces software: your Software Development Lifecycle (SLDC). AppSec just enhances this system to make sure, the output is secure.
Let's imagine you want to reach North Cape in winter. The last kilometers can only be driven in a convoy behind a snowplow because the conditions are so harsh.
At that point, success is no longer just about a car that can handle the conditions.
The road must stay open. The convoy must work together. The snowplow must clear the road. The entire system must continue to function despite difficult conditions.
That's the difference:
AppSec programs can work for years while individual heroes compensate for missing system resilience. In a resilient AppSec system, you don't need heroes.
You design a system that can handle rough conditions.
How does a resilient AppSec system differ?


A common AppSec program is basically a set of isolated measures. Success is often meassured by activity. How many developers did you train? How many vulnerabilities where discovered and closed?
But AppSec doesn't happen isolated.
It is built around an existing system that produces software: your Software Development Lifecycle (SLDC). AppSec just enhances this system to make sure, the output is secure.
Let's imagine you want to reach North Cape in winter. The last kilometers can only be driven in a convoy behind a snowplow because the conditions are so harsh.
At that point, success is no longer just about a car that can handle the conditions.
The road must stay open. The convoy must work together. The snowplow must clear the road. The entire system must continue to function despite difficult conditions.
That's the difference:
AppSec programs can work for years while individual heroes compensate for missing system resilience. In a resilient AppSec system, you don't need heroes.
You design a system that can handle rough conditions.


How do you build a resilient AppSec system?
You can't improve a system you don't understand.
Before you can optimize for resilience, you need to understand your current system. The one that produces software and the extension designed to ensure it meets your desired level of security.
Second, you can discover where your system is most fragile at the moment and improve it.
If you're ready to start, you can choose between two routes:
The solo expedition:
Use the AppSec Ownership Model to analyze your own system and explore how responsibility could be distributed in a resilient AppSec system.
The guided route:
Book your Terrain Check to get a structured analysis of your current AppSec system, identify fragile areas and define practical next steps towards resilience.
How do you build a resilient AppSec system?


You can't improve a system you don't understand.
Before you can optimize for resilience, you need to understand your current system. The one that produces software and the extension designed to ensure it meets your desired level of security.
Second, you can discover where your system is most fragile at the moment and improve it.
If you're ready to start, you can choose between two routes:
The solo expedition:
Use the AppSec Ownership Model to analyze your own system and explore how responsibility could be distributed in a resilient AppSec system.
The guided route:
Book your Terrain Check to get a structured analysis of your current AppSec system, identify fragile areas and define practical next steps towards resilience.


Why resilience matters to me
When I built my own AppSec program from scratch, I was just a developer suddenly handed responsibility for AppSec. Of course I made the same mistake. I kept pushing and became the security hero. When I took 3 months off to travel, nothing moved.
That's when I knew I had to start building a system that works without me.
After I left the company, I embraced traveling overland full-time. The ultimate freedom: just me, my dog, and my Chevy on the road. I soon learned I had heavily underestimated the fact I was giving up all traditional safety nets: no home, no regular paycheck.
Then I faced the worst case: engine damage in the Pyrenees.
My entire lifestyle depended on that old Chevy, and it was gone. But the system I had built around it was resilient. My mindset, resources and my great support network got me back on the road with a new Chevy Blazer.
Losing my car was painful, but the experience proved that I can trust my system.
To be truly free, we need security built from within. We need a resilient system.
Why resilience matters to me


When I built my own AppSec program from scratch, I was just a developer suddenly handed responsibility for AppSec. Of course I made the same mistake. I kept pushing and became the security hero. When I took 3 months off to travel, nothing moved.
That's when I knew I had to start building a system that works without me.
After I left the company, I embraced traveling overland full-time. The ultimate freedom: just me, my dog, and my Chevy on the road. I soon learned I had heavily underestimated the fact I was giving up all traditional safety nets: no home, no regular paycheck.
Then I faced the worst case: engine damage in the Pyrenees.
My entire lifestyle depended on that old Chevy, and it was gone. But the system I had built around it was resilient. My mindset, resources and my great support network got me back on the road with a new Chevy Blazer.
Losing my car was painful, but the experience proved that I can trust my system.
To be truly free, we need security built from within. We need a resilient system.

