1999 Chevrolet S10 Blazer parked in the sand dunes at the Atlantic ocean in Morocco.

AppSec Rig Inspection

Make your AppSec system resilient.

What keeps my AppSec system fragile?

False assumptions

Initiatives around ownership, security culture, or an expensive new tool are always experiments based on assumptions. There is no guarantee that your money, time, and effort will pay off. That's the nature of complex problems.

Get a Rig Inspection if you want to leverage deep system understanding to come up with grounded hypotheses.

Decide based on system understanding.

Shaky foundation

Your AppSec efforts won't succeed if you lack a strong foundation. How much impact your initiatives can have depends on the relationship between leadership and AppSec. You need a strong mandate and clear communication.

Get a Rig Inspection if you want to strengthen your foundation with leadership and align your goals.

Thrive based on strong relationships.

Single point of failure

As AppSec Lead, you are the natural single point of failure of your AppSec system. That doesn't mean the system has to be visible only in your head. When you are unavailable, a well-documented System Manual can save the day.

Get a Rig Inspection if you want a documented, transferable snapshot of your system that you can build upon.

Rest based on shared responsibility.

1999 Chevrolet S10 Blazer in the Sahara desert in Morocco, used to illustrate the Rig Inspection story.

Why should I get a Rig Inspection?

Because it keeps you from wasting your energy on the wrong problems.

Let me take you on a short trip into the Sahara to show you what I mean.

That evening I was tired, sweaty, and just wanted to get to my camp spot. Then suddenly, my car stopped. I knew it. But I didn't want to believe it. Annoyed, I hit the gas, and sand flew straight through the open window into my face. Awesome.

So I got out, aired down the tires, and started digging sand away to make room for the recovery boards. But my car just sat there like a stranded whale and refused to move an inch. "What the f...? Why is it not moving?!" I paused for a moment. Then I saw it: There was no weight on the wheels. My car was sitting on too much sand. "Yeah, more digging..."

But at least I was finally solving the right problem.

Dealing with structural AppSec problems like unrealistic expectations, implicit responsibilities, and destructive cultural patterns is exhausting. But it is necessary.

The Rig Inspection helps you identify the underlying problems that are undermining your AppSec efforts.

Anne's dog Suschka in the Sahara desert in Morocco, ready to take on the next AppSec challenge.

Who is the Rig Inspection for?

You've already checked many boxes off the list. You have tools in place for vulnerability management, defined processes for incident response and zero-day management, and maybe even started your security champions program.

But still your software is not as secure as you'd planned?

That's expected. You've done all the necessary groundwork, but you've mainly worked on complicated problems. Now you must deal with the world of complex problems. A world where you can only observe in retrospect why your solution worked. A world of hypotheses and experiments.

That's where the Rig Inspection can really help you.

I don't want to lie to you. The Rig Inspection alone is not going to make your AppSec system resilient. You know, you will still need to dig sand. But the Rig Inspection provides you with the insights to know where you need to dig.

That means you must be willing to work with the results.

Otherwise the Rig Inspection will be just another waste of energy for you.

What do you get from a Rig Inspection?

AppSec System Manual

The AppSec System Manual is a detailed, documented snapshot of your AppSec system. It lists your currently applied AppSec measures, all roles involved in developing secure software, and how responsibility is distributed among them.

It shows your system from three different angles: who officially, actually, and ideally owns what.

It provides the system understanding you need to come up with grounded hypotheses to solve complex problems.

Leadership Briefing

The Leadership Briefing is tailored to your executive leadership.

It provides them with a high-level summary of your system's resilience, highlights underlying structural problems, and explains why those complex problems can only be addressed with structured experiments.

The briefing includes recommendations on how executive leadership shapes the success of your initiative. As the backbone of your system, their actions matter most.

Owner's Briefing

The Owner's Briefing is tailored to the AppSec Lead or team, the owner of your AppSec system.

It provides them with detailed guidance on how to work with the AppSec System Manual and how to keep it up to date.

The briefing includes a set of grounded hypotheses about where their system is currently most fragile and recommendations on how these can be tested with structured experiments.

Close-up of the repair manual for an old Chevy Blazer, representing the idea of looking under the hood of an AppSec system.

What method does the Rig Inspection use?

The Rig Inspection is based on system understanding. We replace false assumptions with grounded hypotheses, define structured experiments, and decide in advance what data to collect. That way, we ensure you can actually learn from that experience and adjust for the next cycle.

Therefore, the Rig Inspection is conducted in two phases.

First, we make your AppSec system visible.

In this phase I'll review your policies and conduct interviews with different roles on your team. From these two perspectives I'll map out your system and we'll get to understand how responsibility is officially distributed and how it's actually distributed.

Second, we check where it's most fragile and define next steps.

In this phase I'll compare your system to my AppSec Ownership Model, which suggests how responsibility should be distributed in a resilient AppSec system. From this third perspective I'll derive grounded hypotheses on why certain ownership is not taken up and we'll discuss ideas for experiments to move responsibility to the right place.

Your Rig Inspection at a glance

How it works

We start with a kick-off call. You provide your policies, and we agree together on who to interview.

I then conduct the interviews and analyze everything we’ve gathered. From there, we meet again to go through the findings together.

Nothing gets imposed on you. We work toward hypotheses and experiments you actually agree with, so you walk away with something you can start on immediately.

What happens next

After the Rig Inspection, you are well prepared to tackle complex challenges. You leave with a well-documented, transferable system snapshot, first levers, and written guidance to optimize your AppSec system for resilience.

If you want additional support steering your AppSec system, check out the Trail Guide.

If this feels like too much right now, start smaller with the Clarity Compass instead.

The deal

We’ll make your current system visible and find a first lever to build resilience into it.

From there, it's up to you: running the experiments, enabling ownership, and making your AppSec system less dependent on you one step at a time.

Investment:

29,000 USD

Expected duration: 2-3 months

Ready to face your complex AppSec problems?

Awesome. Let's talk and see if the Rig Inspection is right for you right now.
I’m currently taking on two founding clients for the Rig Inspection at a reduced rate. That's your chance to shape the structure of the AppSec System Manual with me.

0 / 1000
You’re reaching out – of course I’ll get back to you. That’s literally why this form exists. Your info will only be used for this purpose. Wanna know more?Privacy Policy.

Still wondering if the Rig Inspection works for you?

1999 Chevy Blazer parked beneath an acacia tree at sunset in Morocco, reflecting AppSec built from the road.