The Elephant in AppSec
The Elephant in AppSec
Podcast Description
Time to discuss AppSec issues no one talks about.
Podcast Insights
Content Themes
The podcast covers a wide range of application security topics, including measuring AppSec ROI, API security, threat modeling, and the integration of security with product management. For example, episodes like 'Can You Really Quantify AppSec ROI?' challenge listeners to think critically about how security initiatives are evaluated, while 'How to Fix API Security Before It's Too Late' dives deep into proactive measures for securing APIs.

Time to discuss AppSec issues no one talks about.
My guest today is Petra Vukmirovic, Head of Information Security and IT at Numan, and she also works with DevArmor on automating threat modeling and security design reviews.
Outside of that she started the OWASP Threat Model Library, an open collection of real threat models the community can learn from.
What makes her path unusual is that she didn't come to AppSec through development, she came through emergency medicine, where she worked as a doctor.
In this episode, we talked about what transfers from the ER to incident response, which is mostly the protocols: risk scores, runbooks, decision trees you can follow when things are on fire. She also thinks threat modeling stops too early. Most teams model protective controls and stop, when recovery deserves the same attention.
We also got into automating threat models with LLMs, catching drift between the model and the code, and where design reviews end and threat modeling begins.
And much more!
This podcast is brought to you by
Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.

Disclaimer
This podcast’s information is provided for general reference and was obtained from publicly accessible sources. The Podcast Collaborative neither produces nor verifies the content, accuracy, or suitability of this podcast. Views and opinions belong solely to the podcast creators and guests.
For a complete disclaimer, please see our Full Disclaimer on the archive page. The Podcast Collaborative bears no responsibility for the podcast’s themes, language, or overall content. Listener discretion is advised. Read our Terms of Use and Privacy Policy for more details.