Isaac Evans

Simple Steps to Kill DevSec without Giving Up on Security

The 'shift left' movement has largely failed. Learn how to build effective security guardrails that your developers won't ignore.

Simple Steps to Kill DevSec without Giving Up on Security
#1about 5 minutes

The corrosive effect of false positives in security tools

Traditional code scanners overwhelm developers with a high rate of false positives, eroding trust and causing important alerts to be ignored.

#2about 1 minute

Why the original "shift left" security movement failed

The shift left movement often failed because it simply redirected a high-noise firehose of security alerts from security teams to developers without improving signal quality.

#3about 1 minute

How Android and iOS successfully hardened their platforms

The significant increase in the market price for zero-day exploits for Android and iOS demonstrates their success in making software more expensive to hack.

#4about 6 minutes

Adopting a secure guardrails over security gates mindset

Effective security programs use secure guardrails, like providing secure defaults and actionable fixes, to guide developers without blocking their workflow.

#5about 3 minutes

Prioritize securing new code over fixing the backlog

Since vulnerabilities are exponentially more likely to be found in new code, focusing security efforts there provides a greater return than trying to fix the entire existing backlog.

#6about 3 minutes

The ROI of basic security training and securing LLMs

Elevating developers to a basic level of security awareness yields the largest reduction in vulnerabilities, a principle that now extends to securing code generated by LLMs.

#7about 3 minutes

A practical formula for an effective AppSec program

An application security program's effectiveness is a product of its components, where a poor signal-to-noise ratio can nullify all other efforts.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

Related Articles

View all articles
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
Hello there! This is the 2nd "out of the can" edition of 3 as I am on vacation in Greece eating lovely things on the beach. So, fewer news, but lots of great resources. Many around the topic of security. Enjoy! News and ArticlesGoogle Pixel phones t...
Dev Digest 138 - Are you secure about this?
CH
Chris Heilmann
Dev Digest 110 - XY marks the spotty security
This time we give you a collection of links about the XZ backdoor, solve the last CODE100 puzzle, announce the next round of it, let you play with colours and explain why Lava lamps are great to keep the web secure.News and ArticlesThe big piece of n...
Dev Digest 110 - XY marks the spotty security
DC
Daniel Cranney
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev
Inside last week’s Dev Digest 194 . 🧠 Learn how to become an AI-native software engineer 🤷‍♂️ How can you stand out when anyone can build anything? 👂 Whisper Leak allows listening to encrypted chats 🐝 What’s new the OWASP2025 Top Ten List 🙅‍♀️ Curse...
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev

From learning to earning

Jobs that call for the skills explored in this talk.