• Skip to main content
  • Skip to primary sidebar
  • Skip to footer

DevelopSec

  • Home
  • Podcast
  • Blog
  • Resources
  • About
  • Schedule a Call

James Jardine

July 7, 2026 by James Jardine

Is 100% Secure Software Possible?

With the uptake of AI coding agents, and all the other AI capabilities, more people have been floating the idea of 100% secure software. I would argue that there is no such thing as 100%, due to a lot of factors, but I wanted to talk a little bit about how we may get closer. Use of AI The interesting thing that AI brings to the table is the ability to create agents with skills focused on being able to assess the security of the code written by another agent, and work together to remediate the … [Read more...] about Is 100% Secure Software Possible?

Filed Under: General Tagged With: ai, applicaiton security, AppSec, owasp, qa, secure coding, secure development

October 23, 2024 by James Jardine

Application Security Starts With IT

Building secure applications has to start with the IT department. We have fought the battle for far to long in trying to have a different group responsible for securing our applications. Whether you call it application security, product security, devsecops, or something else. It just doesn't work. These different groups can help in identifying and implementing some processes, but secure code starts with the development team. If we really want to start building more secure applications we have … [Read more...] about Application Security Starts With IT

Filed Under: General Tagged With: app sec, app testing, application security, product security, secure development, security testing

October 21, 2024 by James Jardine Leave a Comment

Security Awareness: Beyond Typical Training

Do you force your users to take security awareness modules once a year on generic security topics.  Do you feel like it is making the impact you are expecting?  We all know that security is everyone’s responsibility and to be successful everyone needs to play their part. Unfortunately, we don’t do a great job of really defining how security fits within each person’s area. Instead, we force generic phishing simulations and then assign annual awareness training modules. Modules that … [Read more...] about Security Awareness: Beyond Typical Training

Filed Under: General, Training Tagged With: security, security awareness

May 7, 2024 by James Jardine

Ep. 121: Evolving Ransomware: Unique Tactics For Payment

In this episode I talk about the evolving world of ransomware. I discuss a few examples of unique tactics the malicious actors are using to put pressure on organizations to pay the ransom. Referenced Articles: https://www.theregister.com/AMP/2024/04/30/finnish_psychotherapy_center_crook_sentenced/ https://www.darkreading.com/cyber-risk/hackers-weaponize-sec-disclosure-rules-against-corporate-targets https://www.theregister.com/2024/01/05/swatting_extorion_tactics/ For more info go to … [Read more...] about Ep. 121: Evolving Ransomware: Unique Tactics For Payment

Filed Under: Podcast Tagged With: breach, cyber, data breach, Extortion, information security, infosec, Payments, ransomware, security

April 6, 2024 by James Jardine

Security.txt for Vulnerability Disclosure

Have you heard of RFC 9116? If not, I understand. I don't really know anything by RFC numbering and that is ok. RFC 9116 is a document put out by the Internet Engineering Task Force (IETF) related to vulnerability disclosure. It is important to note that this is not a standard, but for informational purposes only.  So what does it do? The focus of this document is on the security.txt file and the format of it. Security.txt is a simple text file that helps an organization describe their … [Read more...] about Security.txt for Vulnerability Disclosure

Filed Under: General Tagged With: bug bounty, secure code, secure development, security, security.txt, vulnerability, vulnerability disclosure, web policies

March 26, 2024 by James Jardine

QA Can Do Security Testing

Does your appsec team struggle with trying to perform security testing on all of your applications? Do you struggle with trying to find more resources for your team to scale your team?  What is your relationship with the QA team? Often times, we focus on the developers and overlook the QA team. Why? QA engineers are professional testers. The big difference is that they focus on verifying functionality works instead of focusing on how functionality could be mis-used. This shouldn't be a reason … [Read more...] about QA Can Do Security Testing

Filed Under: General, Training Tagged With: AppSec, product security, qa security, secure development, security, security testing

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 21
  • Go to Next Page »

Primary Sidebar

Contact Us:

Contact us today to see how we can help.
Contact Us

Footer

Company Profile

Are you tackling the challenge to integrate security into the development process? Application security can be a complex task and often … Read More... about Home

Resources

Podcasts
DevelopSec
Down the Security Rabbithole (#DTSR)

Blogs
DevelopSec
Jardine Software

Engage With Us

  • Email
  • GitHub
  • Twitter
  • YouTube

Contact Us

DevelopSec
Email: james@developsec.com



Privacy Policy

© Copyright 2018-2026 Developsec · All Rights Reserved