

Your AppSec Guide
Where classic consulting keeps AppSec fragile
Borrowed capacity
Outsourcing can make things move faster for a while, but it doesn't make your AppSec system more resilient. The work gets done externally, while the knowledge and decision-making capability stay outside your organization.
You fail to build internal capability.
Externalized responsibility
External support can create momentum for a while, but momentum built on outside pressure doesn't last. When someone else keeps pushing, reminding, and following up, teams don't learn to carry the responsibility themselves.
You fail to build internal ownership.
Generic solutions
When support relies soley on a predefined framework, your system gets pushed into a model before your terrain is understood. You will see progress, but only measured against the framework, not your actual reality. Your effort gets lost in complexity.
You may fail to solve the actual problem.


How I learned to build AppSec systems
My road into cybersecurity was a bumpy off-road trail, fueled by curiosity and a stubborn drive to fix real-world problems. Somewhere along the way, AppSec responsibility was handed to me like a hot potato: a rough roadmap, no team, and a simple instruction: “Go fix it.” So I did. Over the next four years, I built an AppSec system from scratch inside a German software company with several hundred employees, including its security champions program.
That meant working with developers, project leads, operations, the CISO, and executive management. It also meant learning how differently these roles think, decide, communicate, and define success.
I learned AppSec the hard way: by getting my hands dirty.
Before AppSec, I spent five years as a software developer: first at a 50-person company, where I later took a detour building its privacy management system. Second, in the company where I later built the AppSec system. That way I gained insight into two very different companies from both angles: the development view from inside the team, and the management view.
That is why I treat AppSec as a system that has to work across people, priorities, processes, and constraints, not just as a stack of tools, policies, or isolated measures.
How I learned to build AppSec systems


My road into cybersecurity was a bumpy off-road trail, fueled by curiosity and a stubborn drive to fix real-world problems. Somewhere along the way, AppSec responsibility was handed to me like a hot potato: a rough roadmap, no team, and a simple instruction: “Go fix it.” So I did. Over the next four years, I built an AppSec system from scratch inside a German software company with several hundred employees, including its security champions program.
That meant working with developers, project leads, operations, the CISO, and executive management. It also meant learning how differently these roles think, decide, communicate, and define success.
I learned AppSec the hard way: by getting my hands dirty.
Before AppSec, I spent five years as a software developer: first at a 50-person company, where I later took a detour building its privacy management system. Second, in the company where I later built the AppSec system. That way I gained insight into two very different companies from both angles: the development view from inside the team, and the management view.
That is why I treat AppSec as a system that has to work across people, priorities, processes, and constraints, not just as a stack of tools, policies, or isolated measures.


How I learned that ownership matters
During the first 18 months of building my AppSec system, we had to deal with two critical zero-days: Log4Shell and Spring4Shell. Both hit the software world hard, but our own experience with them was completely different.
When Log4Shell happened, an internal message on Friday afternoon made me believe things were taken care of. By Monday, I realized I was wrong: the process was not as clearly defined as I had assumed.
Four months later, on a Wednesday, rumors about Spring4Shell started spreading. This time, I was alarmed. That same evening, two developers reproduced the exploit in our environment. “Ok, this is real.” While the team worked on a patch, I started identifying affected projects, contacting project leaders, and coordinating the unusually high number of parallel deployments needed.
When Spring4Shell was officially confirmed on Thursday afternoon, we had already patched around 80% of affected projects on our list.
By Friday noon, we were done. This time, responsibility was clearly distributed, so everyone could own their part and handle the situation smoothly. Later, we formalized the process.
Experiences like this taught me that a resilient AppSec system is grounded in ownership.
How I learned that ownership matters


During the first 18 months of building my AppSec system, we had to deal with two critical zero-days: Log4Shell and Spring4Shell. Both hit the software world hard, but our own experience with them was completely different.
When Log4Shell happened, an internal message on Friday afternoon made me believe things were taken care of. By Monday, I realized I was wrong: the process was not as clearly defined as I had assumed.
Four months later, on a Wednesday, rumors about Spring4Shell started spreading. This time, I was alarmed. That same evening, two developers reproduced the exploit in our environment. “Ok, this is real.” While the team worked on a patch, I started identifying affected projects, contacting project leaders, and coordinating the unusually high number of parallel deployments needed.
When Spring4Shell was officially confirmed on Thursday afternoon, we had already patched around 80% of affected projects on our list.
By Friday noon, we were done. This time, responsibility was clearly distributed, so everyone could own their part and handle the situation smoothly. Later, we formalized the process.
Experiences like this taught me that a resilient AppSec system is grounded in ownership.
My working principles
Understand the system
I treat AppSec as a complex system that lives inside another complex system: your organization. Reducing friction means shaping culture.
Make expectations explicit
I dig deep to uncover implicit expectations and turn them into explicit, commonly agreed standards. That creates the foundation for real ownership.
Optimize before investing
Throwing more money at the problem rarely fixes it. I first look for pragmatic fixes in what is already there, so new investments can create real impact.
Encourage critical thinking
I expect people to think for themselves. Instead of fixed instructions, I create room for honest, open discussions. That is how internal capability is built.


Who will you work with?
If you're still wondering who is behind AppSec Adventure...
Hey, I'm Anne.
When I'm not in front of a computer, you will probably find me behind the wheel of my good old Chevy Blazer exploring some remote areas across Europe, Northern Africa and hopefully Central Asia soon. That's because I packed my life into this old car to live full-time on the road.
Having a call in the desert of Morocco or beside a road in Northern Norway? That's my normal life. But I'm sorry, sometimes you will just watch cars pass by somewhere on a road. Don't expect epic views in the background every time.
In my free time, I love exploring nature with my dog Suschka and capturing my adventures with my camera. Well, that's kind of obvious.
So, who will you be working with?
Someone who is pragmatic, self-sufficient and always ready for a campfire, a beer and some crazy adventure stories.
Who will you work with?


If you're still wondering who is behind AppSec Adventure...
Hey, I'm Anne.
When I'm not in front of a computer, you will probably find me behind the wheel of my good old Chevy Blazer exploring some remote areas across Europe, Northern Africa and hopefully Central Asia soon. That's because I packed my life into this old car to live full-time on the road.
Having a call in the desert of Morocco or beside a road in Northern Norway? That's my normal life. But I'm sorry, sometimes you will just watch cars pass by somewhere on a road. Don't expect epic views in the background every time.
In my free time, I love exploring nature with my dog Suschka and capturing my adventures with my camera. Well, that's kind of obvious.
So, who will you be working with?
Someone who is pragmatic, self-sufficient and always ready for a campfire, a beer and some crazy adventure stories.

