Many organizations treat Common Vulnerabilities and Exposures (CVEs) as first-class citizens. Some even enforce strict […]
Application security (AppSec) remains one of the toughest challenges modern organizations are facing. Despite heavy[…]
By embracing the Japanese Kaizen philosophy of continuous incremental improvement, your AppSec program can evolve[…]
Your DevSecOps pipeline is fast, automated, and built to scale. But is security truly integrated,[…]
About 4 years ago I have joined the OWASP Software Assurance Maturity Model (SAMM) project[…]
In this technical article, we will explore how to improve your DevSecOps processes by integrating[…]
This article contains a variety of different cybersecurity statistics and trends of 2025 and recent[…]
Most security issues in software stem from one simple problem: teams try to fix them[…]
Youāve probably heard the saying, āYou canāt manage what you donāt measure.ā If you are[…]
Official framework, regulation and standard pages mentioned in this article CRA GDPR OWASP SAMM[…]
Modern software development moves fast, and so do the security challenges that come with it.[…]
Understanding OWASP SAMM is only the beginning. The real value comes from using it to[…]











