Panel Discussion
Climate vs. Weather: How Do We Sustainably Make Software More Secure?
#1about 4 minutes
The conflict between initial velocity and long-term quality
Business pressures like deadlines and budgets often prioritize rapid proof-of-concept development over establishing sustainable software quality and security from the start.
#2about 4 minutes
Addressing the security education gap for developers
Integrating a secure system development lifecycle (SDLC) into university and bootcamp curricula is crucial for changing the industry's culture and embedding security from the ground up.
#3about 6 minutes
Why development teams need multidisciplinary specialists
Instead of expecting every developer to master security, performance, and usability, teams should adopt a model with specialists like security champions.
#4about 5 minutes
Expanding security awareness beyond the development team
Creating a robust security culture requires educating everyone from young people on data privacy to management on IT fundamentals, reinforced by practices like phishing simulations.
#5about 4 minutes
Exploring the need for regulation in software development
The panel discusses whether software engineering needs formal regulations, similar to civil engineering, to improve safety and why the intangible nature of data breaches makes this challenging.
#6about 8 minutes
How to begin implementing security in a new project
Security should start with requirements and design, using accessible techniques like simplified threat modeling and attack trees to identify potential risks early in the development lifecycle.
#7about 11 minutes
Using security tooling effectively without slowing developers
Effective tooling involves a mix of static analysis (SAST), red team tools, and unit tests, but success depends on managing false positives and matching the tool's rigor to the application's risk profile.
#8about 6 minutes
Panelists share their wishes for a more secure future
Panelists wish for improvements ranging from better communication and fewer dependencies to a perfect body of security knowledge and smarter IDE integrations.
#9about 4 minutes
What panelists love about working in cybersecurity
The panelists conclude by sharing their passion for the field, highlighting the noble goal of protecting people, the constant learning, and collaborative problem-solving.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
01:29 MIN
A developer's responsibility to build secure software
You can’t hack what you can’t see
Unlock full access
Log in or set up an account to access this feature and more.
04:25 MIN
Balancing developer and stakeholder security priorities
What The Hack is Web App Sec?
Unlock full access
Log in or set up an account to access this feature and more.
02:26 MIN
Why developers make basic cybersecurity mistakes
Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes
Unlock full access
Log in or set up an account to access this feature and more.
02:54 MIN
Why security teams must scale through developer collaboration
Building Security Champions
Unlock full access
Log in or set up an account to access this feature and more.
01:17 MIN
Fostering a developer-first security culture
Walking into the era of Supply Chain Risks
Unlock full access
Log in or set up an account to access this feature and more.
03:15 MIN
Scaling AppSec teams by empowering developers
Why Security-First Development Helps You Ship Better Software Faster
Unlock full access
Log in or set up an account to access this feature and more.
15:12 MIN
Q&A on speed, team adoption, and common mistakes
DevSecOps: Injecting Security into Mobile CI/CD Pipelines
Unlock full access
Log in or set up an account to access this feature and more.
01:24 MIN
Making web application security accessible to developers
What The Hack is Web App Sec?
Unlock full access
Log in or set up an account to access this feature and more.
Featured Partners
Related Videos
Building Security Champions
Tanya Janca
You can’t hack what you can’t see
Reto Kaeser
DevSecOps: Security in DevOps
Aarno Aukia
Securing Your Web Application Pipeline From Intruders
Milecia McGregor
Cyber Security: Small, and Large!
Martin Schmiedecker
Maturity assessment for technicians or how I learned to love OWASP SAMM
Mathias Tausig
Walking into the era of Supply Chain Risks
Vandana Verma
Security Pitfalls for Software Engineers
Jasmin Azemović
Related Articles
View all articles



From learning to earning
Jobs that call for the skills explored in this talk.

Workwise GmbH


HDI Global SE
Junior
DevOps
Grafana
Prometheus
TypeScript
Continuous Integration

Vesterling Consulting GmbH
€70-90K
Software Architecture

Taktile GmbH
Berlin, Germany
Remote
Intermediate
DevOps
Gitlab
Terraform
Continuous Delivery
+1

Excellence AG
Kotlin
Kubernetes
Apache Kafka
Microservices
Continuous Delivery
+1

Codasip
Berlin, Germany

