EP 53 — ReversingLabs's Dave Ferguson on Securing Your Software Supply Chains

EP 53 — ReversingLabs's Dave Ferguson on Securing Your Software Supply Chains

In this episode of the Future of Application Security, Harshil speaks with Dave Ferguson, Director of Technical Product Management, Software Supply Chain Security at ReversingLabs, which offers software supply chain security analysis platform. They discuss the rising need for software supply chain security as a result of the complexities around how software is built today. They also talk about ways to identify novel attacks through analyzing software behaviors, how efforts like SBOMs and registries help increase transparency, and why software supply chain security needs to evolve from just looking for vulnerabilities.

Topics discussed:

  • How Dave's diverse background in security, as well as his piqued interest around the SolarWinds and 3CX attacks, led to his focus on software supply chain security today.
  • How a product manager leads by working with development teams, meeting with customers, incorporating new features and integrations, and helping bring new solutions to market.
  • How the complexities associated with building software today — like open source and automation — have increased the possibility of adversaries slipping in.
  • Why analyzing software behavior across previous builds and seeing what's changed can help flag novel attacks.
  • Today's trends that are increasing transparency in software creation, including the rising demand for SBOMs and the possibility of trust registries for commercial software.
  • Why software supply chain security approaches need to move beyond just looking at vulnerabilities to find ways to root out all malicious activity.

RELATED RESOURCE:

Today, most application security tools are designed to find vulnerabilities, not fix them. What is noise and what is risk? And, more importantly, how do you accelerate the remediation of the most critical vulnerabilities? The answer lies within one key metric — Mean Time to Remediate (MTTR).

Taking a better strategy to decrease your MTTR and keep your organization safe can begin today — download the paper to learn how.

Avsnitt(60)

EP 60 - Appian’s Abdullah Munawar on Enhancing Product Security Amid Evolving Development Trends

EP 60 - Appian’s Abdullah Munawar on Enhancing Product Security Amid Evolving Development Trends

In this episode of the Future of Application Security podcast, Harshil speaks with Abdullah Munawar, Director of Product Security at Appian. Abdullah shares valuable insights into his journey from sec...

22 Maj 202421min

EP 59 - Nat Mokry on Advancing Application Security in the Gaming Industry

EP 59 - Nat Mokry on Advancing Application Security in the Gaming Industry

In our latest episode of the Future of Application Security podcast, Nat Mokry, VP of Application & Product Security at Xbox (formerly of Activision Blizzard at the time of recording), shares valuable...

24 Apr 202426min

EP 58 — Asana's Felix Matenaar on Building Resilient Security Practices for the Future

EP 58 — Asana's Felix Matenaar on Building Resilient Security Practices for the Future

In this episode of the Future of Application Security podcast, Harshil interviews Felix Matenaar, Head of Product Security at Asana. Felix shares insights into his journey from Germany to Silicon Vall...

10 Apr 202432min

EP 57 —  Clari's Steve Lukose on Using SLAs as Benchmarks for Businesses

EP 57 — Clari's Steve Lukose on Using SLAs as Benchmarks for Businesses

In this episode of the Future of Application Security, Harshil speaks with Steve Lukose, Vice President of Security at Clari, about how security is becoming a business enabler rather than just an orga...

27 Mars 202427min

EP 56 — Aruneesh Salhotra on Why Security is Everyone’s Job

EP 56 — Aruneesh Salhotra on Why Security is Everyone’s Job

In this episode of the Future of Application Security, Harshil speaks with Aruneesh Salhotra, CEO and Fractional CISO, SNM Consulting Inc. They discuss the unique challenges and opportunities of appli...

28 Feb 202424min

EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability

EP 55 — BlackBerry's Christine Gadsby on What's Driving Software Supplier Transparency and Accountability

In this episode of the Future of Application Security, Harshil speaks with Christine Gadsby, VP, Product Security at BlackBerry, a software company specializing in cybersecurity. They discuss the new ...

14 Feb 202426min

EP 54 — LPL Financial's Chad Girouard on Improving Application Security Through Better Tools and Relationships

EP 54 — LPL Financial's Chad Girouard on Improving Application Security Through Better Tools and Relationships

In this episode of the Future of Application Security, Harshil speaks with Chad Girouard, AVP Application Security at LPL Financial, a provider of investment and business solutions. They discuss how s...

31 Jan 202423min

Populärt inom Business & ekonomi

framgangspodden
varvet
rss-jossan-nina
rss-svart-marknad
rss-borsens-finest
badfluence
avanzapodden
uppgang-och-fall
svd-tech-brief
bathina-en-podcast
fill-or-kill
lastbilspodden
rss-dagen-med-di
rss-kort-lang-analyspodden-fran-di
tabberaset
rss-inga-dumma-fragor-om-pengar
24fragor
kapitalet-en-podd-om-ekonomi
rikatillsammans-om-privatekonomi-rikedom-i-livet
borsmorgon