DefectDojo and Bringing Quality Appsec Tools to Small Appsec Teams – Greg Anderson – ASW #312
All appsec teams need quality tools and all developers benefit from appsec guidance that's focused on meaningful results. Greg Anderson shares his experience in bringing the OWASP DefectDojo project to life and maintaining its value for over a decade. He reminds us that there are tons of appsec teams with low budgets and few members that need tools to help them bring useful insights to developers.
Segment Resources:
- https://owasp.org/www-project-defectdojo/
- Three-quarters of CISOs surveyed reported being "overwhelmed" by the growing number of tools and their alerts: https://www.darkreading.com/cloud-security/cisos-throwing-cash-tools-detect-breaches
- As many as one-fifth of all cybersecurity alerts turn out to be false positives. Among 800 IT professionals surveyed, just under half of them stated that approximately 40% of the alerts they receive are false positives: https://www.securitymagazine.com/articles/97260-one-fifth-of-cybersecurity-alerts-are-false-positives
- 91% of organizations knowingly released vulnerable applications, 57% of vulnerabilities are left unresolved by developers, 32% of CISOs deploy vulnerable code in the hopes it won’t be discovered, 56% of developers struggle to prioritize vulnerability fixes: https://info.checkmarx.com/future-of-application-security-2024
Announcements
Paul's Security Weekly has been nominated for a SANs Difference Maker Award for Podcast, Livestream, or Video Series of the year! Thank you to all of our listeners for helping us continue this podcast for the past 19 years! We would appreciate it if you'd vote for us before October 4th by visiting https://securityweekly.com/DMA
Want to shape the future of identity? Identiverse 2025 is looking for dynamic speakers like you to share groundbreaking ideas with over 3,000 identity and access management leaders. Join the most influential voices in IAM and help drive innovation in our industry. Submit your presentation proposal today at securityweekly.com/idvcfp
Guest
Greg Anderson is the founder, creator, and CEO of DefectDojo. His mission is to prevent breaches by making visibility and scalability a reality for all in security.
Greg is a seasoned security practitioner and an active participant in the global community, having served as a member of the Board of Directors for the OWASP Foundation, performed assessments for the United States Department of Defense (Pentagon), and presented research on compromising CI/CD pipelines at DEFCON. Greg has also presented at AppSec USA and AppSec EU.
Greg started his career as a penetration tester with a focus on unconventional attack vectors and how to maximize their impact before focusing on DefectDojo.