Relating to DevSecOps cover image

Relating to DevSecOps

Latest episodes

undefined
Jun 10, 2025 • 37min

Episode 079: CISOver It: When Dashboards Replace Direction

The discussion highlights the tough balancing act CISOs perform between immediate security needs and long-term strategies. They dive into the disconnect between security leadership and practitioners and emphasize the importance of engaging teams to tackle root causes of vulnerabilities. The pitfalls of relying on one-size-fits-all security tools are explored, advocating for tailored solutions. The conversation also addresses the complexities of incident response in the evolving Web3 landscape, stressing the need for deep analysis over surface-level metrics.
undefined
Apr 22, 2025 • 47min

Episode #078: 🔥 Burn Your 30-page Policies: Tanya’s Got Better Ideas

In this engaging chat, Tanya Janca, known as SheHacksPurple, shares her insights as an AppSec expert and author. She discusses why traditional security policies often flop and how to make them more effective. Bridging the gap between developers and policy writers is key—Tanya emphasizes the need for practical, simplified guidelines. She also touches on her advocacy work in enhancing cybersecurity within government sectors. Tune in for her tips on empowering developers and making security accessible!
undefined
Mar 24, 2025 • 32min

Episode #077: Is Google Eating the Cloud? 🔥 Wiz.io Acquisition Hot Takes

Send us a textIn this episode of Relating to DevSecOps, Ken Toler and Mike McCabe dive deep into Google's blockbuster acquisition of Wiz.io for a reported $32 billion. They explore the implications for cloud security, the consolidation of the DevSecOps tooling landscape, and how this move compares to Google’s previous acquisitions like Mandiant and Chronicle. The duo debates the future of multi-cloud strategies, platform fatigue, and whether Wiz will remain the darling of the security community—or get lost in the labyrinth of Google Cloud products. With sharp insights and a dash of hot takes, they paint a picture of a cloud security ecosystem at a pivotal turning point
undefined
Feb 4, 2025 • 34min

Episode #076: ShmooBalls & Open Source Brawls: DevSecOps, Risk, and the Final ShmooCon

Send us a textWelcome to 2025! Ken and Mike kick off the new year with their security resolutions (or lack thereof) before diving into the bittersweet farewell to ShmooCon, one of the most beloved hacker conferences. Ken shares his experiences from the final event, including insights on hardware hacking, radio security, and the unique hacker culture that made ShmooCon special.They also unpack one of the most practical talks from the conference: a deep dive into open source security tools versus enterprise solutions, highlighting ways security teams can cut costs without sacrificing effectiveness. Speaking of open source, the hosts discuss the controversy surrounding Semgrep’s licensing changes and the rise of OpenGrep, the latest community-driven fork in response to closed-source shifts—drawing parallels to the Terraform/OpenTofu saga.Finally, the duo explores cyber risk from an insurance perspective, breaking down how breaches translate into real-world financial costs (hint: mailing breach notifications alone could bankrupt you). Whether you're a security pro, an open source advocate, or just here for the ShmooBall nostalgia, this episode has something for you!
undefined
Dec 24, 2024 • 36min

Episode #075: Ghosts of DevSecOps: Past, Present, and Future

Join a festive journey through the evolution of DevSecOps, filled with holiday anecdotes and valuable insights. Discover the increasing importance of security awareness as teams move from silos to collaboration. Examine the gap between corporate claims about collective responsibility and the reality for developers. Delve into the challenges of integrating AI and automation in security practices. Finally, embrace the changing mindset of security professionals as they adopt innovative technologies for a stronger future.
undefined
Dec 9, 2024 • 36min

Episode #074: Battling Budgets in Security

Send us a textIn this episode of Relating to DevSecOps, hosts Ken and Mike tackle the complex challenges of managing security budgets in organizations of all sizes. From small, scrappy teams to sprawling enterprises, they explore how security leaders can navigate tight financial constraints while maintaining strong security postures. They share insights on integrating security into IT operations, leveraging open-source tools, and rethinking traditional budget allocations. Whether you’re a CISO grappling with scaling or a developer looking to improve security outcomes, this discussion is packed with actionable strategies and thought-provoking debates on the future of security spendinghttps://www.youtube.com/watch?v=8U3QzJBCNZ0 
undefined
Oct 21, 2024 • 37min

Episode #073: Staffing Security in DevSecOps

Send us a textIn this episode, Ken and Mike discuss the pressing issue of staffing security in the DevSecOps field. They explore the challenges of finding qualified application security professionals, the importance of diverse backgrounds in security roles, and the paradox of understaffed security teams despite a high demand for cybersecurity jobs. The conversation also delves into strategies for mitigating staffing issues, such as empowering security champions within organizations, leveraging automation and tooling, and avoiding bottlenecks in security processes. Throughout the discussion, they emphasize the need for a balanced approach to security that considers both technical and human factors.
undefined
Aug 28, 2024 • 34min

Episode #072: Measuring the Immeasurable: The Power and Pitfalls of Metrics in DevSecOps

Send us a textKen and Mike dive deep into the world of metrics and measurement in the context of security and DevSecOps. They explore the critical role metrics play in driving security improvements, from tracking vulnerabilities to gauging the effectiveness of incident response. The hosts discuss what makes a good metric, the importance of aligning metrics with business goals, and the dangers of relying too heavily on numbers alone. They also tackle the challenges of quantifying "squishy" aspects like culture and training effectiveness. Whether you're a seasoned security professional or just getting started, this episode offers valuable insights into the art and science of measurement in securityReference talk: https://www.youtube.com/watch?v=GXTvlQXVCOs&t=0s
undefined
Jun 19, 2024 • 26min

Episode #071: Retro Vibes with Retrospectives

Send us a textKen and Mike discuss the importance of postmortems in incident response and security incidents. They explore the definition of postmortems, the value of reflection, the challenges of blame, and the significance of actionable outcomes. They also touch on the transparency of postmortems and the need for root cause analysis. The conversation concludes with a brief announcement about an upcoming conference series.
undefined
May 8, 2024 • 40min

Episode: #070: Putting da BOM in SBOM and SCA

Send us a textKen and Mike discuss supply chain security, including software composition analysis (SCA) and software bill of materials (SBOM). They highlight the importance of understanding the components that make up your software and the risks associated with using third-party libraries. They also discuss recent supply chain failures, such as the XZ library hack and the SolarWinds attack. The hosts emphasize the need for organizations to stay up to date with software patches and to consider the security of commercial off-the-shelf software. They caution against placing too much focus on any one security tool or approach, including SBOM, and instead advocate for a well-rounded approach to security.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app