Panel Discussion
Climate vs. Weather: How Do We Sustainably Make Software More Secure?
#1about 4 minutes
The conflict between initial velocity and long-term quality
Business pressures like deadlines and budgets often prioritize rapid proof-of-concept development over establishing sustainable software quality and security from the start.
#2about 4 minutes
Addressing the security education gap for developers
Integrating a secure system development lifecycle (SDLC) into university and bootcamp curricula is crucial for changing the industry's culture and embedding security from the ground up.
#3about 6 minutes
Why development teams need multidisciplinary specialists
Instead of expecting every developer to master security, performance, and usability, teams should adopt a model with specialists like security champions.
#4about 5 minutes
Expanding security awareness beyond the development team
Creating a robust security culture requires educating everyone from young people on data privacy to management on IT fundamentals, reinforced by practices like phishing simulations.
#5about 4 minutes
Exploring the need for regulation in software development
The panel discusses whether software engineering needs formal regulations, similar to civil engineering, to improve safety and why the intangible nature of data breaches makes this challenging.
#6about 8 minutes
How to begin implementing security in a new project
Security should start with requirements and design, using accessible techniques like simplified threat modeling and attack trees to identify potential risks early in the development lifecycle.
#7about 11 minutes
Using security tooling effectively without slowing developers
Effective tooling involves a mix of static analysis (SAST), red team tools, and unit tests, but success depends on managing false positives and matching the tool's rigor to the application's risk profile.
#8about 6 minutes
Panelists share their wishes for a more secure future
Panelists wish for improvements ranging from better communication and fewer dependencies to a perfect body of security knowledge and smarter IDE integrations.
#9about 4 minutes
What panelists love about working in cybersecurity
The panelists conclude by sharing their passion for the field, highlighting the noble goal of protecting people, the constant learning, and collaborative problem-solving.
Related jobs
Jobs that call for the skills explored in this talk.
Technoly GmbH
Berlin, Germany
€50-60K
Intermediate
Network Security
Security Architecture
+2
VECTOR Informatik
Stuttgart, Germany
Senior
Kubernetes
Terraform
+1
Matching moments
01:06 MIN
Malware campaigns, cloud latency, and government IT theft
Fake or News: Self-Driving Cars on Subscription, Crypto Attacks Rising and Working While You Sleep - Théodore Lefèvre
05:55 MIN
The security risks of AI-generated code and slopsquatting
Slopquatting, API Keys, Fun with Fonts, Recruiters vs AI and more - The Best of LIVE 2025 - Part 2
03:16 MIN
Improving the developer feedback loop with specialized tools
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
03:58 MIN
Making accessibility tooling actionable and encouraging
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
05:01 MIN
Comparing the security models of browsers and native apps
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
01:15 MIN
Crypto crime, EU regulation, and working while you sleep
Fake or News: Self-Driving Cars on Subscription, Crypto Attacks Rising and Working While You Sleep - Théodore Lefèvre
01:32 MIN
Organizing a developer conference for 15,000 attendees
Cat Herding with Lions and Tigers - Christian Heilmann
02:55 MIN
Why developers often undervalue their time and paid tools
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
Featured Partners
Related Videos
Panel discussion: Developing in an AI world - are we all demoted to reviewers? WeAreDevelopers WebDev & AI Day March2025
Laurie Voss, Rey Bango, Hannah Foxwell, Rizel Scarlett & Thomas Steiner
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Why Security-First Development Helps You Ship Better Software Faster
Michael Wildpaner
DevSecOps: Security in DevOps
Aarno Aukia
You can’t hack what you can’t see
Reto Kaeser
Building Security Champions
Tanya Janca
Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?
Tino Sokic
Related Articles
View all articles



From learning to earning
Jobs that call for the skills explored in this talk.

Code Healers LLC
Hinesville, United States of America
Remote
€30-40K
Intermediate
Senior
.NET
React
JavaScript
+2

Code Healers LLC
Hinesville, United States of America
Remote
€20-30K
Junior
Intermediate
React
JavaScript
TypeScript
+1




Accenture
Municipality of Madrid, Spain
API
C++
GIT
Java
.NET
+25

SAP AG
Sankt Leon-Rot, Germany
Junior
Go
Azure
DevOps
Puppet
Docker
+6

Onintigritissecurity
Remote
Splunk
Network Security
