Anne, her dog Suschka and her old Chevy Blazer in winter on Lofoten island, Northern Norway.

Your AppSec Guide

Building resilient AppSec systems from the road.

Where classic consulting keeps AppSec fragile

Borrowed capacity

Outsourcing can make things move faster for a while, but it doesn't make your AppSec system more resilient. The work gets done externally, while the knowledge and decision-making capability stay outside your organization.

You fail to build internal capability.

Externalized responsibility

External support can create momentum for a while, but momentum built on outside pressure doesn't last. When someone else keeps pushing, reminding, and following up, teams don't learn to carry the responsibility themselves.

You fail to build internal ownership.

Generic solutions

When support relies soley on a predefined framework, your system gets pushed into a model before your terrain is understood. You will see progress, but only measured against the framework, not your actual reality. Your effort gets lost in complexity.

You may fail to solve the actual problem.

Anne working on her Chevy Blazer, representing how she learned to build AppSec programs by doing the work and getting my hands dirty.

How I learned to build AppSec systems

My road into cybersecurity was a bumpy off-road trail, fueled by curiosity and a stubborn drive to fix real-world problems. Somewhere along the way, AppSec responsibility was handed to me like a hot potato: a rough roadmap, no team, and a simple instruction: “Go fix it.” So I did. Over the next four years, I built an AppSec system from scratch inside a German software company with several hundred employees, including its security champions program.

That meant working with developers, project leads, operations, the CISO, and executive management. It also meant learning how differently these roles think, decide, communicate, and define success.

I learned AppSec the hard way: by getting my hands dirty.

Before AppSec, I spent five years as a software developer: first at a 50-person company, where I later took a detour building its privacy management system. Second, in the company where I later built the AppSec system. That way I gained insight into two very different companies from both angles: the development view from inside the team, and the management view.

That is why I treat AppSec as a system that has to work across people, priorities, processes, and constraints, not just as a stack of tools, policies, or isolated measures.

Anne working on her camper build with a power drill, taking full ownership.

How I learned that ownership matters

During the first 18 months of building my AppSec system, we had to deal with two critical zero-days: Log4Shell and Spring4Shell. Both hit the software world hard, but our own experience with them was completely different.

When Log4Shell happened, an internal message on Friday afternoon made me believe things were taken care of. By Monday, I realized I was wrong: the process was not as clearly defined as I had assumed.

Four months later, on a Wednesday, rumors about Spring4Shell started spreading. This time, I was alarmed. That same evening, two developers reproduced the exploit in our environment. “Ok, this is real.” While the team worked on a patch, I started identifying affected projects, contacting project leaders, and coordinating the unusually high number of parallel deployments needed.

When Spring4Shell was officially confirmed on Thursday afternoon, we had already patched around 80% of affected projects on our list.

By Friday noon, we were done. This time, responsibility was clearly distributed, so everyone could own their part and handle the situation smoothly. Later, we formalized the process.

Experiences like this taught me that a resilient AppSec system is grounded in ownership.

My working principles

Understand the system

Understand the system

I treat AppSec as a complex system that lives inside another complex system: your organization. Reducing friction means shaping culture.

Make expectations explicit

Make expectations explicit

I dig deep to uncover implicit expectations and turn them into explicit, commonly agreed standards. That creates the foundation for real ownership.

Optimize before investing

Optimize before investing

Throwing more money at the problem rarely fixes it. I first look for pragmatic fixes in what is already there, so new investments can create real impact.

Encourage critical thinking

Encourage critical thinking

I expect people to think for themselves. Instead of fixed instructions, I create room for honest, open discussions. That is how internal capability is built.

Anne sitting with her dog on a mountain hike in Senja, Norway, representing experience with navigating real terrain and complex AppSec programs.

Who will you work with?

If you're still wondering who is behind AppSec Adventure...

Hey, I'm Anne.

When I'm not in front of a computer, you will probably find me behind the wheel of my good old Chevy Blazer exploring some remote areas across Europe, Northern Africa and hopefully Central Asia soon. That's because I packed my life into this old car to live full-time on the road.

Having a call in the desert of Morocco or beside a road in Northern Norway? That's my normal life. But I'm sorry, sometimes you will just watch cars pass by somewhere on a road. Don't expect epic views in the background every time.

In my free time, I love exploring nature with my dog Suschka and capturing my adventures with my camera. Well, that's kind of obvious.

So, who will you be working with?

Someone who is pragmatic, self-sufficient and always ready for a campfire, a beer and some crazy adventure stories.

The foundation of a resilient AppSec system is explicit expectations and properly distributed responsibility. If you want to learn more or even get started yourself:
Chevy Blazer crossing a wooden bridge in the Bosnian mountains – symbolizing resilience and navigation through rough terrain.