A strange thing happens every 6 months in software teams where cricitcal application vulnerabilities are uncovered and the CTO is aghast at why this nightmare keeps repeating itself.
The answer to this conundrum is in the video.
Naturally, after spending big on giving security training to the dev team...
After spending big on security consultants, it's reasonable for the CTO to expect his devs to take care of these issues in the development cycle, right?
Wrong.
Why?
Because experience tells us that doing ad-hoc, sporadic activities like training and annual pentesting is a sure-fire way of wasting money.
There is a formula that you can apply to fix this issue.
When you apply this formula, not only do your devs find and fix vulnerabilities before your ship the next release of your app.
But they will also be learning new security skills on the job...
Without coughing up extra for "training".
It's also very likely to stop spiteful conversations about who's to blame for those vulnerabilities.
Find out more here: https://www.audacix.com/2022/04/softw...