Contrast Security provides the industry’s only DevOps-Native AppSec Platform using instrumentation to continuously analyze and protect software from within the application. This enables businesses to see more of the risks in their software and less development delays and AppSec complexity. The Contrast platform integrates seamlessly into development pipelines, enabling easier security bug and vulnerability fixes that significantly speed release cycles. The Contrast Inside AppSec Podcast features informative, engaging interviews with security, development, and business leaders on application security trends and innovation. Visit Contrast Security at contrastsecurity.com.
CISA recently introduced binding order 22-01 to remediate known vulnerabilities. The order requires federal agencies to remediate vulnerabilities that are actively exploited, or potentially lose their authority to operate.
We talk with former government service-men and employees to hear about what this means for federal groups.
Forrester predicts that 25% of developers will be using serverless technologies by the end of next year. There are a lot of benefits from serverless applications: faster release cycles, lower infrastructure costs, and improved efficiencies. Yet, at the same time, organizations are running into application security roadblocks. Legacy application security tools simply cannot scale or keep pace demanded by serverless applications. In response, Contrast just released Contrast Serverless Application Security, which automatically detects security vulnerabilities directly within serverless environments. This empowers developers to quickly validate and prioritize test results for remediation. Contrast’s Head of Cloud-native Security Research Tal Melamed and Director of Product Marketing Blake Connell sat down with the Inside AppSec Podcast team to discuss this new product and what differentiates it from current application security approaches on the market.
Episode #57 Key Takeaways From a New Serverless Application Security Report
Software development is a core component of digital transformation, and the use of serverless technologies is helping to accelerate release cycles to new heights. A panel of serverless application security experts discuss key findings and insights from a new survey report on serverless application security in this Inside AppSec Podcast. The moderated discussion touches on topics such as the current and future outlook of serverless applications, the top application security challenges organizations face in embracing serverless applications, serverless application security best practices and benchmarks, and much more.
Episode #58 New Serverless Application Security Solution Is a Transformative Breakthrough
Contrast Labs was a fledgling organization just a few years ago when Contrast’s CISO David Lindner took on the mantle of leadership. Today, Contrast Labs is a pivotal linchpin—threat modeling to protect Contrast’s network, applications, users, and data from malicious attacks, providing engineering with product ideas, overseeing product bug bounty programs, and competing in capture-the-flag (CTF) events. In addition to discussing each of these topics, Lindner explains how his team has partnered with marketing to generate data-driven bimonthly and annual reports that customers and prospects use to benchmark their application security programs. He also provides his insights on the role of the CISO in the application security space.
2021 Application Security Observability Report
Checklist: 4 Ways To Boost Application Security This Month
Cybersecurity adheres to the belief that the more results you can generate, the better your security model. This is certainly true in the application security space, where the more alerts that are generated, the better an organization's security posture. But this isn't necessarily true. In this Inside AppSec Podcast interview, Contrast's Chief Scientist and Co-founder Arshan Dabirsiaghi and Head of Product Marketing Mahesh Babu discuss why this belief is so firmly entrenched in the application security space and why less is actually more. The interview also touches on Contrast's pipeline-native static analysis tool (Contrast Scan) and how it turns legacy static scanning models on their head to produce faster scan results and dramatically greater accuracy with significant improvements in operational efficiency.
Blog Posts:
MODERN PROBLEMS: TRADITIONAL SECURITY SCANNING WASN’T BUILT FOR TODAY’S PIPELINES https://www.contrastsecurity.com/security-influencers/modern-problems-traditional-security-scanning-wasnt-built-for-todays-pipelines
CONTRAST ANNOUNCES THE FIRST BREAKTHROUGH IN SAST IN 15 YEARS https://www.contrastsecurity.com/security-influencers/contrast-announces-the-first-breakthrough-in-sast-in-15-years
White Paper: WHITE PAPER: PIPELINE-NATIVE SCANNING FOR MODERN APPLICATION DEVELOPMENT https://www.contrastsecurity.com/whitepaper-pipeline-native-scanning-modern-application
The 2021 OWASP Top Ten was a huge research and analytical undertaking involving over 500,000 applications and 200 CWEs. The amount of data analyzed was upwards of 4x greater than what was used for the 2017 OWASP Top Ten release. OWASP Top Ten Co-Lead and Union University Professor Brian Glas discusses how the data was compiled and analyzed and how the OWASP Top Ten categories were reevaluated. This in-depth Inside AppSec Podcast interview also examines the rationales behind each of the 10 categories.
The 2021 OWASP Top Ten contains some significant changes, including several additions. Understanding what changed and why they changed is important for application security professionals. This Inside AppSec Podcast features Contrast Security's CTO and Co-founder Jeff Williams and CISO David Lindner who explore the changes and additions to the Top Ten and how organizations should use the Top Ten to manage their application risks.
The number of vulnerabilities per application in the May-June Bimonthly Application Security Intelligence Report from Contrast Labs remained flat, but the number of serious vulnerabilities jumped. This Inside AppSec Podcast conversation discusses what vulnerability types saw the biggest increases and which ones are the most concerning. The podcast also covers the latest insights into the Contrast RiskScore and findings on attacks and explores trends per languages during May and June.
The percentage of applications with serious vulnerabilities increased significantly over the past year. However, vulnerability prevalence varied across vulnerability type. Knowing which ones are the most prevalent and with the greatest likelihood to impact enables security and development teams to prioritize vulnerability remediation. As developers experience what the two guests—Contrast Security's CTO and Co-founder Jeff Williams and CISO David Lindner—in this Inside AppSec podcast describe as just-in-time security training through real-time, actionable instructions on how to fix vulnerabilities that were introduced into the code, the vulnerability escape rate falls. The two guests also discuss how the RiskScore Index, which catalogs 19 different vulnerability types, enables organizations to pinpoint which vulnerabilities post the highest risk by combining vulnerability and attack data.
2021 Application Security Observability Report:
https://www.contrastsecurity.com/2021-observability-report
The more application security debt an organization carries, the greater the risk and operational inefficiencies. Contrast Security's CTO and Co-founder Jeff Williams and CISO David Lindner reflect on security debt findings in Contrast's 2021 Application Security Observability Report in this Inside AppSec podcast—the first show in a series of three on the report. Areas of discussion include observations on the time required to achieve median time to remediate resolved vulnerabilities and the average amount of time required to remediate a vulnerability (as compared to legacy application security tools). The podcast also covers the newly formulated vulnerability escape rate—the average number of new vulnerabilities introduced over the period of the past year per application—which highlights the importance of just-in-time security learning for developers.
2021 Application Security Observability Report:
https://www.contrastsecurity.com/2021-observability-report
If anything, the recent software supply chain attacks demonstrate the interconnectivity of modern software and the exponential risk one successful exploit poses to thousands of organizations worldwide. Contrast Security's annual 2021 Application Security Observability Report finds that custom code comprises a substantial percentage of active application code. A large percentage of open-source libraries are inactive, and moreover a majority of classes in active libraries are never invoked. Contrast's CTO and Co-founder Jeff Williams and CISO David Lindner discuss these and other application composition findings and insights in this Inside AppSec podcast.
2021 Application Security Observability Report:
https://www.contrastsecurity.com/2021-observability-report
The March–April 2021 Bimonthly AppSec Intelligence Report from Contrast Labs pegs the overall RiskScore Index at 5.06, the lowest since July 2020. This should be good news, especially with the percentage of applications with a serious vulnerability decreasing in this bimonthly time frame. However, the number of applications with serious vulnerabilities remained higher than any month since November. Further, the percentage of applications impacted by specific attack types increased 9% and attacks on Java applications that were viable were up to 3% of applications—a big jump from .5%. Listen to this Inside AppSec podcast interview with Contrast Security CTO and Co-founder Jeff Williams and Sr. Data Analyst and Scientist Katharine Watson to get more details on these trends and others.
Contrast Labs’ Director of Security Research Matt Austin discovered a Remote Code Execution (RCE) vulnerability in Microsoft Teams that could have exposed the Microsoft Teams software supply chain to a malicious exploit that could have impacted millions of users and thousands of businesses. Listen to this podcast interview with Matt to find out how he found the vulnerability and worked with Microsoft to confirm it. Matt also discusses how the Contrast Application Security Platform enables organizations to detect supply chain vulnerabilities and block attacks before they can connect with them.
Incumbent legacy static analysis approaches employ large rule sets to look for code quality issues that require lengthy scan processes and generate large piles of findings—many of which are false positives. Contrast Security's Chief Strategy Officer Surag Patel and Sr. Product Marketing Director Mahesh Babu discuss the addition of Contrast Scan to the Contrast Application Security Platform in this Inside AppSec Podcast. Using a breakthrough pipeline-native static analysis approach that uses a demand-driven algorithm, Contrast Scan delivers speed at DevOps scale (10x faster scans and 45x faster vulnerability remediation). Listen to this podcast to get the details on how you can "scale up" your application security.
Contrast Security’s 2021 State of Application Security in Financial Services Report canvasses a number of topics related to application security in financial services such as how the rapid adoption of DevOps/Agile in financial services is outpacing application security, how application security is inefficient and often slows down release cycles, the amount of time security and development teams spend managing application security, and the risks financial services organizations are facing from application vulnerabilities. This Inside AppSec Podcast with Contrast’s CISO David Lindner and Director of Developer Relations Erik Costlow explores these and other topics in the report.
The recent Contrast Security 2021 Open-source Security Report reveals real-world (and previously undiscovered) aspects about open-source library usage and the risks associated with it. Legacy approaches to open-source security generate alert noise, struggle to track software licensing risks, and poorly integrate with existing CI/CD processes and development tools. Contrast OSS offers a comprehensive DevSecOps model that solves these challenges. In this Inside AppSec Podcast, Contrast open-source subject-matter experts Joe Coletta and Pauline Logan take a look at some of the key findings in the Open-source Security Report and examine core capabilities in Contrast OSS and the Contrast Application Security Platform.
Use of open-source frameworks and libraries offers organizations added scale—the ability to achieve the speed and efficiency demanded by the modern software development life cycle (SDLC). Yet, there are various differences in open-source libraries in terms of vulnerabilities and licensing, and open source can expose applications to significant risk if the right application security approach is not taken. Listen to this Inside AppSec Podcast with Contrast Security subject-matter experts Joe Coletta and Pauline Logan to learn about the risks of open-source code and why you must heed the risk signals to avoid exposing applications to malicious attacks.
2021 is the year of the software supply chain when it comes to cyber risks. Thousands of organizations have been repeatedly hit from multiple points across the software factory attack surface. The January-February 2021 Contrast Labs Bimonthly AppSec Intelligence Report contains trend data reflecting these concerns. In this Inside AppSec podcast, Contrast Security's CISO David Lindner and Sr. Data Analyst and Data Scientist Katharine Watson discuss highlights and key takeaways in the report. Visit our resource page to download this report and more. https://www.contrastsecurity.com/resources/product-info
Go is an open-source programming language that makes it easy to build simple, reliable, and efficient software across various operating systems. But until now, developers and application security specialists were stuck using legacy application security methods that generated high volumes of false positives and struggled to secure application programming interfaces (APIs)—which are often written in Go. In this Inside AppSec podcast, several members of the Contrast product and engineering teams discuss how the Contrast Application Security Platform now supports Go. Listeners will learn how the industry’s first interactive security analyzer virtually eliminates false positives and dramatically improves the efficiency of both application security and development teams.
The metrics many organizations use today to measure the success of their application security programs fail to capture risks that matter to the business and incentivize the wrong outcomes. A comprehensive approach to DevSecOps that uses metrics that reflect actual risk measures areas such as vulnerabilities remediated, mean time to remediate, and blocked attacks that could have exploited a vulnerability. In this Inside AppSec podcast interview, Contrast Security’s Sr. Director of Product Marketing Mahesh Babu discusses these and other facets of DevSecOps metrics that organizations can use to evaluate their DevSecOps maturity. Listeners will learn what DevSecOps metrics matter—and which ones don’t—and how the Contrast Application Security Platform empowers security teams to build data-driven application security programs that reduce risks and improve efficiency.
Traditional perimeter-defense solutions sit outside of applications in production and lack deep insights about applications to more precisely identify potential attacks. The resulting "guessing game" produces high numbers of alerts. Contrast Security's Vikas Phonsa and Blake Connell are experts when it comes to application production runtime protection. In this Inside AppSec podcast, they discuss how perimeter-defense approaches are ineffective in blocking many types of threats and are highly inefficient to deploy and manage—often stretching SecOps teams to breaking points. Contrast Protect supplements traditional perimeter-defense architectures that improve the efficacy of protecting applications while significantly improving the efficiencies of SecOps teams.
Much attention has been given to the software supply chain over the past several months due to the SolarWinds hack. Open-source libraries are a critical part of the software supply chain, and they can pose serious risk if they are not monitored and managed appropriately. Legacy software composition analysis tools equate third-party vulnerabilities on a level playing field. But the reality is most third-party code is never invoked by the applications in which they reside and pose no risk. A group of experts from Contrast Security discuss findings and insights from the new 2021 State of Open-source Security Report by Contrast Labs in this Inside AppSec Podcast. The discussion touches on library complexities as well as five layers of open-source risk.
Kenna Security explores detailed data trends for vulnerabilities in the wild, including those found in applications, in its Prioritization to Prediction research series. The company's research includes attack data that is overlaid on top of the vulnerability datasets to determine risk. This Inside AppSec Podcast interview with Kenna Security CTO and Co-founder Ed Bellis explores application security findings and insights from the Prioritization to Prediction Volume 6 report.
The list of organizations with applications that contain the recently discovered dependency confusion vulnerability continues to grow. Contrast Labs added another one to the list when it identified the vulnerability in an open-source library used by Microsoft Teams. In this Inside AppSec Podcast, Contrast Security's Director of Security Research Matt Austin discusses how he found the vulnerability and what potential risks it posed.
Newly discovered dependency confusion vulnerability found in 35 enterprises—and counting—and threatens software supply chain. Bad actors could inject malicious code without any victim action by redirecting open-source updates to compromised open-source code repos. In this Inside AppSec Podcast, Contrast Security's Director of Security Research discusses why dependency confusion poses a serious threat and how they can detect and remediate the vulnerability before bad actors exploit it.
The latest Bimonthly Application Security Intelligence Report from Contrast Security shows a continued rise in vulnerabilities in .NET applications and a sharp increase in SQL and command injection attacks in late 2020. The percentage of applications with serious vulnerabilities also rose, which should give cause for concern. In this Inside AppSec Podcast, Contrast Security's CISO David Lindner and Sr. Data Analyst and Data Scientist Katharine Watson discuss these and other findings from the November–December 2020 report.
Most risk-scoring models for applications are too simplistic, lacking the breadth of data points needed to provide an accurate risk index. A few open-source projects attempt to build application risk models that are sophisticated enough to account for all of the data and associated nuances needed to pinpoint a risk score that is accurate and meaningful. The problem is that they are too complex to easily implement and manage in an ongoing basis. In response, Contrast Security recently released a RiskScore (Beta V.5) based on an algorithmic risk model that accounts for all of the relevant data points that is also simple to use and manage. This Inside AppSec Podcast interview with Contrast CTO and Co-Founder Jeff Williams, CISO David Lindner, and Sr. Data Analyst and Data Scientist Katharine Watson explores the reasons Contrast developed an algorithmic RiskScore, why and how it plans to release it as an open-source project, how organizations can contribute to it and leverage it, and what the results resemble when it is applied to vulnerability types using Contrast Labs’ application vulnerability and attack data.
With headquarters in Greece and 750-plus employees, Kaizen Gaming delivers casino and sports games that tally more than 200 million annual customer transactions. In this Inside AppSec Podcast, Kaizen Gaming's Technical Security Manager Aggelos Karonis discusses why he and his team turned to application security using instrumentation based on Contrast Security. The podcast interview touches on some of the business outcomes as well as key lessons learned.
The SolarWinds cyberattack has been dubbed the “hack of the decade” with over 18,000 SolarWinds customers affected. It accentuates the critical importance of software security—from technology to processes. In this Inside AppSec Podcast, Contrast Security’s CTO and Co-Founder Jeff Williams discusses emerging details around the hack and implications for application security.
This Inside AppSec podcast interview with Contrast Security's CTO and Co-Founder Jeff Williams examines key findings in Contrast's 2020 State of DevSecOps Report. With 95% of organizations reporting at least one successful application exploit in the past year, development, operations, and security professionals need to take heed and ensure they have the right security measures in place. In addition to application risk, the interview touches on a number of other topics, including the deleterious outcomes resulting from successful exploitations, the huge amount of time security and development teams spend identifying and remediating vulnerabilities, and how and what organizations should measure and track at the board level.
In this Inside AppSec podcast, Contrast Security's CISO David Lindner and Data Scientist Katharine Watson discuss findings from the September–October 2020 Application Security Intelligence Report from Contrast Labs. Serious vulnerabilities and attacks are on the rise and .NET applications are an increasing focus area for cyber criminals, with four of the top five attack types increasing in prevalence for .NET applications by 20% or more.
The Gartner Peer Insights Customers' Choice for Application Security Testing (AST) recognizes AST vendors based on their customer reviews. Contrast scored the highest in the AST category with a 4.8/5.0. In this Inside AppSec podcast, Contrast's VP of Customer Success Scott Chaykin and Head of Customer Marketing Jaweed Metz discuss what Contrast does to ensure customers have great experiences and support using its technology.
The transition from the public to private sector can be difficult for some. This wasn't the case for Jimmy Xu, who serves as the director of Cloud Security and DevSecOps at technology integrator and consultancy Trace3. In this Inside AppSec podcast, Jimmy discusses how he became interested in InfoSec and how he built a successful career in the DoD that set the stage for a transition into the private sector. He also provides insights into key cloud and application security trends and what security and development professionals can do to secure their application environments.
Some of the world's top-performing development teams are in the technology sector. It should not be a surprise that Agile and DevOps adoption rates are the highest among these teams, with pace of change and speed are often critical business differentiators. Those unable to keep up discover their revenues and customer base shrinking. This Inside AppSec podcast examines findings from a recent survey report published by Contrast Security that sought to discover the state of application security with developers in technology companies. Contrast CTO and Co-Founder Jeff Williams comments on the survey findings and provides his unique perspective on what they mean—from challenges to opportunities.
Download the report: https://www.contrastsecurity.com/higher-quality-code-higher-productivity
Contrast Labs’ latest bimonthly research findings (“Application Security Intelligence Report”) unearthed some positive vulnerability and attack trends. Overall application vulnerabilities decreased, and the number of attacks hitting an existing vulnerability in production also shrank to just 1%. But a deeper look reveals cause for concern due to the lack of prioritization in vulnerability management, attacks on .NET applications, and more. Listen to this Inside AppSec podcast with Contrast Security’s CISO David Lindner and Data Scientist Katharine Watson for their insights on these and other trends.
From almost day one of development, Contrast has used the Contrast Application Security Platform to secure and protect TeamServer, the UI and analytics engine for the Contrast platform. In this podcast, David Hafley, the vice president of engineering whose team oversees the development of TeamServer, discusses features and integrations in the Contrast platform that his team uses. Tim Franklin, the business value analysis program manager at Contrast, joins the conversation to overview the cost savings and efficiency gains the company is realizing by using the Contrast platform over a legacy application security approach.
Too often, DevOps and AppSec are spoken about in two different vernaculars. The reality is that they are intertwined at the hip and their individual successes are contingent on one another—whether faster business acceleration, improved efficiencies, or better risk management. In this Inside AppSec podcast, EVOTEK's IT Strategist Greg Sternberg discusses how DevOps and AppSec must be thought of together and spells out some of the key trends that he sees taking place in DevSecOps. Greg also explores his successful career and provides recommendations on how application security professionals can gain the right level of experience and build the right network of connections for career advancement.
As cyber criminals have become more advanced in their use of attack techniques and the digital world expands at a record rate, the need for organizations to assess their risks and develop policies to manage those risks continues to grow. Applications are certainly on the front battle lines, with almost half of data breaches in the past year being tracked back to application vulnerabilities. This podcast features award-winning author and risk assessment and policy development expert Doug Landoll, who discusses strategies that can be deployed to assess application risk, how security frameworks can be used to mitigate and manage that risk, what the future of application risk management may look like, and more.
Contrast Labs’ latest bimonthly research findings (“Application Security Intelligence Report”) looks at application vulnerability and attack trends against COVID-19 data—identifying potential areas of alignment. Attacks on SQL injection and broken access control vulnerabilities were up considerably. With SQL injection vulnerabilities found in more than twice the number of applications than vulnerabilities in general, this serves as a warning light for those responsible for application security. .NET applications were also in the crosshairs of cyber criminals; five .NET vulnerabilities saw double-digit increases over the previous bimonthly report. Contrast Security’s CISO David Lindner and Data Scientist Katharine Watson discuss these and other application vulnerability and attack trends in this Inside AppSec podcast.
Digital transformation is driving a dramatic acceleration in the development of new applications and the evolution of existing ones. But the expanded application attack surface and demands for greater velocity in application development cycles ratchet up risk and impede innovation. Contrast’s “2020 Application Security Observability Report” provides development, security, and operations professionals with a deep dive and analysis around application vulnerabilities, attacks, open-source frameworks and libraries, and median and mean time to remediate. In this Inside AppSec Podcast, Contrast’s CTO and Co-Founder Jeff Williams discusses key highlights in each of these areas and explores actionable insights that will empower organizations to accelerate application security to the speed of the business.
Contrast Labs publishes research findings based on customer vulnerability and attack data in a bimonthly report. The March-April report pinpoints what percentage of applications contain vulnerabilities and how many vulnerabilities exist on average per application. It also identifies vulnerability attacks that spiked the most over the two-month time frame as well as which vulnerabilities pose the greatest risk based on prevalence and likelihood factors. In this Inside AppSec podcast, Contrast Security’s Data Scientist Katharine Watson and Union University’s Assistant Professor of Computer Science Brian Glas discuss key findings in the report and some of the most relevant takeaways for development, security, and operations teams.
Legacy application security approaches simply cannot scale to the velocity demands of modern software development. As they lack vulnerability context because they run outside of the software, they slow development cycles, impede innovation, and incur substantial inefficiencies and cost. When applications are released into production, this same outside-in approach generates huge numbers of false positives while requiring operations teams to spend significant time calibrating and recalibrating perimeter defenses such as web application firewalls. Instrumentation disrupts this outside-in security approach by embedding security within the software. In this Inside AppSec podcast, Contrast’s CTO and Co-Founder Jeff Williams discusses this paradigm shift and why it offers a much more efficient, effective application security model.
Application performance management anchored its foundation in instrumentation, empowering developers to detect and diagnose application performance problems while writing code to meet the business’s service-level requirements. The same is happening in the area of application security, where instrumentation unlocks automation, dramatically improves accuracy, and speeds vulnerability detection and remediation. New Contrast Security Board Member Joe Sexton spent numerous years of his career in the cybersecurity and application development markets, including serving as the President of Worldwide Field Operations at AppDynamics and Executive VP of Global Sales at McAfee. In this Inside AppSec interview, Joe discusses application security from the perspective of the board and the opportunities security instrumentation offers to security, development, and operations leaders.
Digital transformation forms a critical part of almost every organization's business strategy. DevOps and Agile are critical enablers as organizations seek to accelerate their business by enhancing existing applications and developing new ones. But DevOps and Agile—along with containers, microservices, and multiple clouds—introduce new complexities and challenges. In this Inside AppSec podcast, IBM's Developer Advocate JJ Asghar discusses what trends he is seeing in the marketplace and what tips and tactics DevOps leaders and professionals can use to eliminate or minimize the hurdles they face. JJ also provides observations on COVID-19 and its impact on how organizations are tackling DevOps to solve challenges and tap opportunities in a post-COVID-19 world.
The U.S. Department of Energy’s Pacific Northwest National Laboratory reports that one-quarter of software vulnerabilities appear on social media sites—GitHub, Twitter, and Reddit—before they are logged in the National Vulnerability Database. Cybersecurity professionals aren’t the only ones to notice; cyber criminals are busy exploiting this gap. Should professionals tasked with application security be using social media to identify software vulnerabilities? Or is there a better way? In this podcast interview, Contrast Security’s Director of Developer Relations Erik Costlow discusses what challenges this presents to security and development teams and what strategies they can employ to ensure their newly uncovered vulnerabilities are not caught in the crosshairs of cyber criminals.
Developers are embracing Python programming language in growing numbers. It is the most studied language among developers and is used for myriad applications. As a dynamic programming language (as opposed to Java and C that are static languages), variable type is not determined in the application until runtime. For application security to accurately and effectively do its job, Python code must be evaluated in runtime. But this is not possible with legacy AppSec approaches such as static application security testing (SAST) and dynamic application security testing (DAST). A different approach using instrumentation that embeds security within software is needed. In this podcast, three members from Contrast Security discuss how interactive application security testing (IAST) tests applications in runtime is the answer: Trish Reilly, Product Marketing Manager for Contrast Assess, Subhash Arja, Head of Product for Contrast Assess, and Justin Leo, Technical Product Manager for Contrast Assess.
Historically, application security was only in the peripheral purview of the CISO/CSO. But times are changing according to executive cybersecurity recruiter André Tehrani (partner at Recrewmint). In this podcast (part two of a two-part series), André discusses why his firm’s clients are placing application security at the top of the list of skillsets and experience when they engage his firm to identify and recruit new CISOs/CSOs. Firms in the midst of recruiting their next CISO/CSO will learn how to vet candidates for the right application security experience, while CISOs/CSOs looking for their next career opportunity will gain valuable recommendations on how they can use their application security experience to differentiate themselves from other candidates.
This podcast—the first in a two-part series—features an interview with André Tehrani, a partner at Recrewmint, a firm focused singularly on cybersecurity recruiting services at the executive level. André explains how the role of the CISO/CSO has never been so difficult. C-suite executives and boards of directors are seeking CISOs/CSOs with not only the technical cybersecurity skills and experience but also broad business acumen. Soft skills are more than just differentiators for winning candidates today; they are requisites. CISOs/CSOs with this unique combination of technical and business capabilities have a distinct advantage over other candidates who lack their breadth of skill sets and experience. By listening to this podcast, CEOs and boards of directors will discuss what other companies are emphasizing in their CISO/CSO searches, while CISO/CSO candidates will gain critical insights on what skill sets and experience matter the most to prospective employers.
Open-source software (OSS) is critical to software development by accelerating time to market while reducing operating costs. But like any software, OSS introduces layers of risk—both security and IP. Successfully managing OSS is increasingly tied to automating application security processes. Leveraging automation, organizations can track open-source components in use, understand underlying layers of risk, and enable effective mitigation actions. In this Inside AppSec podcast interview, the second podcast in a two-part series, Contrast Security’s Sr. Product Marketing Manager for Contrast OSS Joe Coletta delves into what organizations need to do when securing OSS—involving everything from having the right security policies in place, to establishing continuous visibility, to filtering out noise to focus on the risk that matters most.
We live in a software-driven world where the market demands feature-rich applications delivered at breakneck speeds. Adoption of third-party open-source software (OSS) is a key enabler. More and more open-source frameworks and libraries are being tapped in applications. Use of open-source code by developers grew 40% this past year alone. But as often happens with digital innovation, open source increases security and licensing risks for teams that do not have the right controls in place. In this Inside AppSec podcast interview, the first podcast in a two-part series, Contrast Security’s Sr. Product Marketing Manager for Contrast OSS Joe Coletta speaks about the trends around open source and delineates the types of risks that exist when open source is used in development.
Contrast Security has experienced tremendous growth over the past year, and company culture remains a critical priority. Alignment of unique business practices such as a hybrid workforce, use of OKRs to align individual metrics with companywide metrics, and a customer-centric focus have helped Contrast to scale its business and transform the AppSec marketplace through its DevOps-Native AppSec platform based on instrumentation. In this podcast, Babak Dehnad, the vice president of People at Contrast, discusses why Contrast was named an Inc. magazine Best Workplaces award winner and provides recommendations to other late-stage growth startups on how they can use company values and culture to propel their businesses forward. He argues that COVID-19 work-from-home mandates thrust these issues even further into the limelight, often being the difference between a productive and engaged workforce versus one that is without direction.
There are many options when it comes to the application security (AppSec) market. Many traditional approaches are inefficient, ineffective, and lack the scale demanded by modern DevOps and Agile application development. Code halts, false positives, and even false negatives inflict many organizations, slowing development cycles and drowning DevOps and SecOps teams in vulnerability alerts that pose no risk to the application in question. Contrast Security offers a paradigm shift by embedding security instrumentation within the software, automating vulnerability identification and the remediation verification. It also enables developers to fix vulnerabilities while they are coding and extends instrumentation into production runtime. In this Inside AppSec podcast, Contrast’s Chief Strategy Officer Surag Patel and Director of Customer Marketing and Advocacy Jaweed Metz discuss the AppSec market, including the Gartner “2020 Magic Quadrant for Application Security Testing,” and how Contrast is transforming the space.
Organizations are turning to DevOps and Agile development to address the speed and agility requirements digital transformation demands. As the number of applications increase and their sophistication grows, so are the number of application programming interfaces (APIs) that connect to them. These offer an attractive target to cybercriminals, with experts predicting that APIs will soon become the #1 targeted attack vector in the enterprise. In this podcast, Contrast Security’s Director of Developer Relations Erik Costlow discusses how API vulnerabilities pose serious risks to applications and what development and security professionals can do to protect the APIs used by their applications.
Solving the risks associated with perimeter defenses that rely on web application firewalls (WAFs) requires a transformational approach to application security (AppSec). In this podcast, the second in a two-part series on application runtime security, Contrast Security’s Head of Product Marketing for Contrast Protect Derek Rogerson and Director of Developer Relations Erik Costlow explain how runtime application self-protection (RASP) addresses the failings of perimeter security by embedding security instrumentation within applications in runtime. Listeners will also learn the critical requirements they need to seek when evaluating different RASP solutions.
There is widespread concurrence that the web application firewall (WAF) is insufficient when it comes to protecting web applications. In this podcast interview, the first in a two-part series on application runtime security, Contrast Security’s Head of Product Marketing for Contrast Protect Derek Rogerson discusses how a WAF runs on the perimeter and lacks the context needed to identify which attacks pose a risk and which ones do not. This results in piles of false positives that consume valuable time to remediate. Plus, because WAFs employ signatures to identify potential threats, they fail to pinpoint unknown threats and zero-day attacks. Finally, WAFs require regular recalibration to accommodate threat changes, which often is a heavy lift for most security teams.
Contrast Labs publishes research findings based on customer vulnerability- and attack-related data in a bimonthly report format. A broader and deeper understanding of trends around vulnerabilities and attacks enables security teams and developers to hone their application security defense strategies and tactics for optimal outcomes. The latest report includes details around what vulnerabilities are the most prevalent as well as the most likely to be attacked. Not every application is the same, with a subset containing a large number of vulnerabilities as compared to a majority that have significantly fewer. For this Inside AppSec episode, Jeff Williams, CTO and Co-founder at Contrast Security, and David Lindner, Director of Application Security at Contrast, discuss key findings from the report and provide actionable takeaways for developers and security professionals.
Old-school application security approaches such as static and dynamic testing fail. Dynamic application security testing (DAST) misses many vulnerabilities, leaving organizations at serious risk. Static application security testing (SAST) uses signature-based approaches that pinpoint huge volumes of false positives that incur substantial inefficiencies for both security and development teams. In addition to requiring time-consuming code halts, both SAST and DAST also struggle immensely when it comes to APIs that are connected to individual applications. Security instrumentation changes the paradigm, integrating security sensors into application routes that allow developers to manage vulnerabilities as they are coding within the application itself. In this podcast, Contrast Security’s Chief Strategy Officer Surag Patel explains how doing so speeds development cycles, facilitates collaboration between security and development teams, and improves efficiencies by eliminating false positives and automating time-consuming, manual workflows.
The latest draft update of new requirements from the National Institute of Standards and Technology (NIST) confronts the failures of traditional application security tools that use static and dynamic testing approaches. The new NIST standards include guidance on the adoption of instrumentation in the form of interactive application security testing (IAST) and runtime application self-protection (RASP) tools. These standards are critical for reducing alert noise, minimizing interruptions to the development cycle, and prioritizing vulnerabilities that pose the greatest risk. In this Inside AppSec podcast, Contrast’s CTO and Co-founder Jeff Williams delves into the details of these two new standards and their implications for security and development teams.
Traditional application security approaches use brute line-by-line code scanning that halts operations and development and generates piles of false positives. And they don’t work: Development teams are unable to determine how much of their application attack surface has been assessed for vulnerabilities. An integrated capability within Contrast Assess, Route Intelligence enables developers to know the full extent of their application security posture. It also automates vulnerability identification and remediation verification, saving development and security teams hundreds of hours annually in manual, time-consuming processes. This Inside AppSec Podcast explores Route Intelligence and what it means for developers and security professionals with three subject-matter experts from Contrast Security: David Hafley, director of engineering; Subhash Arja, head of product for Contrast Assess; and Trish Reilly, principal product marketing manager for Contrast Assess and Route Intelligence.