Panel Discussion

Climate vs. Weather: How Do We Sustainably Make Software More Secure?

Unlike civil engineering, software often lacks rigorous safety standards. Learn how to build a security climate, not just react to security weather.

Climate vs. Weather: How Do We Sustainably Make Software More Secure?
#1about 4 minutes

The conflict between initial velocity and long-term quality

Business pressures like deadlines and budgets often prioritize rapid proof-of-concept development over establishing sustainable software quality and security from the start.

#2about 4 minutes

Addressing the security education gap for developers

Integrating a secure system development lifecycle (SDLC) into university and bootcamp curricula is crucial for changing the industry's culture and embedding security from the ground up.

#3about 6 minutes

Why development teams need multidisciplinary specialists

Instead of expecting every developer to master security, performance, and usability, teams should adopt a model with specialists like security champions.

#4about 5 minutes

Expanding security awareness beyond the development team

Creating a robust security culture requires educating everyone from young people on data privacy to management on IT fundamentals, reinforced by practices like phishing simulations.

#5about 4 minutes

Exploring the need for regulation in software development

The panel discusses whether software engineering needs formal regulations, similar to civil engineering, to improve safety and why the intangible nature of data breaches makes this challenging.

#6about 8 minutes

How to begin implementing security in a new project

Security should start with requirements and design, using accessible techniques like simplified threat modeling and attack trees to identify potential risks early in the development lifecycle.

#7about 11 minutes

Using security tooling effectively without slowing developers

Effective tooling involves a mix of static analysis (SAST), red team tools, and unit tests, but success depends on managing false positives and matching the tool's rigor to the application's risk profile.

#8about 6 minutes

Panelists share their wishes for a more secure future

Panelists wish for improvements ranging from better communication and fewer dependencies to a perfect body of security knowledge and smarter IDE integrations.

#9about 4 minutes

What panelists love about working in cybersecurity

The panelists conclude by sharing their passion for the field, highlighting the noble goal of protecting people, the constant learning, and collaborative problem-solving.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

Related Articles

View all articles
AG
Andre Braun, GitLab
Now is the time for industrialized software development
Now is the time for industrialized software development Recently, I received a letter from my car’s manufacturer alerting me to a recall. They had discovered a defective part and wanted to replace it. It was easily fixed, and I might have forgotten a...
Now is the time for industrialized software development
DC
Daniel Cranney
Is Software Development Making the Climate Crisis Worse?
The incredible rate at which technology is developing is clear for all to see. Each week here at WeAreDevelopers, we hear about exciting innovations in the realms of hardware, software, devices, infrastucture, and (of course) AI. Each one presents op...
Is Software Development Making the Climate Crisis Worse?
CH
Chris Heilmann
Exploring AI: Opportunities and Risks for Developers
In today's rapidly evolving tech landscape, the integration of Artificial Intelligence (AI) in development presents both exciting opportunities and notable risks. This dynamic was the focus of a recent panel discussion featuring industry experts Kent...
Exploring AI: Opportunities and Risks for Developers

From learning to earning

Jobs that call for the skills explored in this talk.

DevSecOps Engineer

DevSecOps Engineer

Accenture
Municipality of Bilbao, Spain

API
Scrum
DevOps
Docker
Kubernetes
+1
DevSecOps Engineer

DevSecOps Engineer

Accenture
Municipality of Madrid, Spain

API
Scrum
DevOps
Docker
Kubernetes
+1
DevSecOps

DevSecOps

Accenture
Municipality of Madrid, Spain

Senior
Go
API
C++
HTML
Java
+16