Stefan Van Gansbeke’s Post

A few weeks ago, Emmanouil Perselis provided valuable insights into the application security approach at CM-MC, sparking a lively discussion at the Belgian Cyber Security Coalition Focus Group on application security. He discussed various aspects, including different application development stacks, IDE plugins for early SCA, SAST, and container scanning, a mix of internal and external pen testing, Copilot development support, and triage based on exploitation prioritization. In breakout sessions, we addressed topics such as legacy systems, initial onboarding, prioritization, and triage. We delved into the 'No Triage' principle by applying the latest stable versions of container platforms. Additionally, we tackled the vulnerabilities backlog by emphasizing the ownership of product owners and risk sign-off by the business. It's always fascinating to bring together application security experts from a wide range of organizations—academia, startups, and medium to large enterprises—for valuable open discussions on this often underemphasized area of application security. Kudos for Emmanouil Perselis and thanks for hosting the session to Taco Mulder and Sebastien Deleersnyder #CM #MC #cybersecurity #applicationsecurity

To view or add a comment, sign in

Explore topics