Resilient Cyber

Resilient Cyber w/ Katie Norton - AppSec Industry Analysis & Trends

Feb 24, 2025
Katie Norton, an Industry Analyst at IDC specializing in DevSecOps and software supply chain security, shares her insights on the evolving AppSec landscape. She discusses key trends for 2024, including the ongoing debate of platform versus point products, the impact of 'Developer Tax' on productivity, and the role of AI in automating code fixes. Katie also highlights her research focus for 2025, touching on Application Security Posture Management and the significance of storytelling to bridge the gap between security and development teams.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Non-Tech Background

  • Katie Norton's background is in research and data analytics, not security.
  • Her husband, a developer, helps her understand technical concepts like Kubernetes.
INSIGHT

Shifting Open-Source Security

  • Traditional Software Composition Analysis (SCA) tools are becoming less effective.
  • Open-source security now requires more proactive approaches beyond reactive manifest scanning.
INSIGHT

Platform vs. Point Product Cycle

  • The platform vs. point product debate is an ongoing cycle.
  • Innovative point solutions often grow into platforms or get acquired, and the cycle continues.
Get the Snipd Podcast app to discover more snips from this episode
Get the app