Chief Technology Officer, Director, and Co-Founder

Matias Madou, Ph.D.

"Before I created my own company, I was helping to build tools that were quite good at finding vulnerabilities in code, but they didn’t give any context sensitive guidance or fix security problems. I wanted to build a solution that would help developers write secure code, that would guide them in real time when they are writing and help prevent them from introducing a problem and make it trivial to fix. Developers needed their own Sensei for secure coding."

About

Matias Madou, Ph.D.

Matias is a researcher and developer with more than 15 years of hands-on software security experience. He has developed solutions for companies such as Fortify Software and his own company Sensei Security. Over his career, Matias has led multiple application security research projects which have led to commercial products and boasts over 10 patents under his belt. When he is away from his desk, Matias has served as an instructor for advanced application security training courses and regularly speaks at global conferences including RSA Conference, Black Hat, DefCon, BSIMM, OWASP AppSec and BruCon.

Matias holds a Ph.D. in Computer Engineering from Ghent University, where he studied application security through program obfuscation to hide the inner workings of an application.

Resource hub

Articles by Matias Madou, Ph.D.

more posts
Badge showing a smiling cartoon woman raising her fist with text Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security Infrastructure as Code Series - Business Logic

This vulnerability can occur when coders fail to properly implement business logic rules, which could leave their applications vulnerable to different kinds of attacks should a malicious user choose to exploit them.

Learn More
Hidden door disguised as a bookshelf in a wooden library with old leather-bound books.
Blog
Filter Label
This is some text inside of a div block.

Hiding in plain sight: Why the SolarWinds attack revealed more than malicious cyber risk

If ever there was something to ruin Christmas in the cybersecurity industry, it’s a devastating data breach that is on track to becoming the largest cyberespionage event affecting the US government on record.

Learn More
Red Equifax sign on a pole in front of a glass office building under a cloudy sky.
Blog
Filter Label
This is some text inside of a div block.

Root cause of Equifax hack is web app vulnerability

Once again, the root cause of the Equifax hack is a web app vulnerability. These type of vulnerabilities have been around for over a decade but are still so relevant today.

Learn More
Chessboard with a white hand holding a white king piece capturing a black king piece.
Blog
Filter Label
This is some text inside of a div block.

OWASP’s 2021 list shuffle: A new battle plan and primary foe

Injection attacks, the infamous king of vulnerabilities (by category), have lost the top spot to broken access control as the worst of the worst, and developers need to take notice.

Learn More
Icon of a purple microphone with blue wireless signal waves above it.
Blog
Filter Label
This is some text inside of a div block.

Moving from academic research to industry is non-trivial

Show 139: Matias Madou discusses secure development training and software security testing research

Learn More
Badge with a person raising fist inside and text 'Coders Conquer Security Share and Learn Series'.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security OWASP Top 10 API Series - Broken Object Level Authorization

In general, object level authorization checks should be included for every function that accesses a data source using an input from the user, and failure to do so comes at a great risk.

Learn More
Person stirring a smoky potion in a wooden cauldron with open books and candles around.
Blog
Filter Label
This is some text inside of a div block.

Strike first, strike hard: Why curated secure coding courses extend no mercy to cyber threats

A curated course containing the exact modules in which your developers would need to show proficiency will have a potent impact, and allow them to hit the ground running when it comes to security best practices in their day-to-day work.

Learn More
Grid of 30 diverse illustrated avatars showing different hairstyles, skin tones, and attire.
Blog
Filter Label
This is some text inside of a div block.

What security practices do 300,000 developers really do?

Almost 300,000 developers across approximately 95,000 applications use BSIMM8 to help plan, execute and measure their software security initiatives (SSIs).

Learn More
Person in a red hoodie wearing a glowing LED mask with X eyes and stitched mouth at night.
Blog
Filter Label
This is some text inside of a div block.

ClickShare Vulnerabilities May Have Been Patched, But They Mask a Much Bigger Problem

Shifting security fixes back towards the development process isn't easy, but is necessary in today's world where even seemingly simple devices like presentation tools are both surprisingly complex, and also networked into everything else.

Learn More
Person wearing headphones working on a computer at sunset by a large window.
Blog
Filter Label
This is some text inside of a div block.

Webinar: Are you ready to put the "Sec" in DevOps?

We must get to a stage where security is seen as a shared responsibility across the entire organization, and throughout the SDLC. This is certainly possible when you commit to a fully-fledged, highly supportive DevSecOps environment.

Learn More
Logo with a person raising fist, surrounded by text: Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security OWASP Top 10 API Series - Missing Function Level Access Control

The missing function level access control vulnerability allows users to perform functions that should be restricted, or lets them access resources that should be protected.

Learn More
Badge with smiling person raising fist inside, text saying Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security OWASP Top 10 API Series - Broken Authentication

Authentication often acts as a gateway to both an application and potentially to the rest of a network, so they are tempting targets for attackers. If an authentication process is broken or vulnerable, there is a good chance that attackers will discover that weakness and exploit it.

Learn More
Complex industrial oil and gas refinery with pipes, stairs, and metal structures in monochrome.
Blog
Filter Label
This is some text inside of a div block.

"Explosive" cyber attacks in Oil and Gas are life threatening

The only thing that prevented an explosion was a mistake in the attackers computer code, the investigators said.

Learn More
Close-up of a geometric light sculpture with glowing tubular shapes forming a complex pattern.
Blog
Filter Label
This is some text inside of a div block.

Prevention in the age of the never-ending attack surface

Software development is no longer an island, and when we account for all aspects of software-powered risk - everything from the cloud, embedded systems in appliances and vehicles, our critical infrastructure, not to mention the APIs that connect it all - the attack surface is borderless and out of control.

Learn More
Red bird graffiti painted on a brick wall with wings spread as if flying.
Blog
Filter Label
This is some text inside of a div block.

Security-aware developers: AppSec needs you!

Developers are in a great position to make a lucrative jump into AppSec.

Learn More
Blog
Filter Label
This is some text inside of a div block.

Do software vendors care as much about security as you do?

It’s safe to say that the past couple of years have been transformational for cybersecurity standards, and while not mandatory, it should be a goal for all organizations to follow suit, and scrutinize vendor security practices as though they are part of their own internal security program.

Learn More
Badge with a cartoon coder raising a fist, text says Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security OWASP Top 10 API Series - Mass Assignment

The mass assignment vulnerability was born as a result of many modern frameworks encouraging developers to use functions that automatically bind input from clients into code variables and internal objects.

Learn More
Hand touching a plasma ball with red and blue electric streams inside glowing in darkness.
Blog
Filter Label
This is some text inside of a div block.

Stop disrupting my workflow! How you can get the right security training at the right time

We started to think about what we could do to reduce the barrier to getting training when you need it, and how micro-learning could be implemented into your workflow in a more seamless way.

Learn More
Vertical golden light streaks cascading down against a black background.
Blog
Filter Label
This is some text inside of a div block.

Poor coding patterns can lead to big security problems… so why do we encourage them?

Developers won’t have a positive impact on vulnerability reduction without a foundational understanding of how the vulnerabilities work, why they are dangerous, what patterns cause them, and what design or coding patterns fix them in a context that makes sense in their world. A scaffolded approach allows layers of knowledge to give a full picture of what it means to code securely, defend a codebase, and stand up as a security-aware developer.

Learn More
Orange smiley face and white text saying STAY SAFE painted on asphalt.
Blog
Filter Label
This is some text inside of a div block.

Zero-day attacks are on the rise. It's time to plan a defensive edge.

Zero-day attacks, by definition, give developers zero time to find and patch existing vulnerabilities that could be exploited, because the threat actor got in first. The damage is done and then it’s a mad scramble to fix both the software and reputational damage to the business. Attackers are always at an advantage, and closing that edge as much as possible is crucial.

Learn More
Five airplanes flying in formation leaving white smoke trails arcing in the blue sky near the sun.
Blog
Filter Label
This is some text inside of a div block.

Turning boring PCI-DSS compliance into a meaningful exercise for everybody: Part 1 - AppSec

This is part 1 of a two-part series on successful PCI-DSS compliance within an organization. In this chapter, we detail how AppSec specialists can work closely with development managers to empower developers, strengthen the SSDLC and get specific outcomes from general legislation.

Learn More
Close-up of glowing filament inside a vintage-style incandescent light bulb against black background.
Blog
Filter Label
This is some text inside of a div block.

Want developers to code with security awareness? Bring the training to them.

We already know there is too much going on in a workday, so what incentive do developers have to schlep off to a classroom, or context-switch to go through five steps to access static theory-based training?

Learn More
Close-up of numerous shiny metallic bullets piled together.
Blog
Filter Label
This is some text inside of a div block.

If AppSec tooling is the silver bullet, why are so many companies not firing it?

There are a few reasons why AppSec tools are not being utilized as we might have come to expect, and it’s less about the tools and their functionality, and more about how they integrate with a security program as a whole.

Learn More
Close-up of a book edge with the phrase 'From the real experts' written in script.
Blog
Filter Label
This is some text inside of a div block.

Expert Interview: Infrastructure as Code with Oscar Quintas

We'd like to shine the spotlight on one of our experts, Oscar Quintas. He's part of our Product Content team, working as a Senior Security Researcher. He's also our resident sorcerer on all things Infrastructure as Code (IaC).

Learn More
Colorful layered cake with star decorations on a floral plate with blue stand against dark background.
Blog
Filter Label
This is some text inside of a div block.

Happy birthday SQL injection, the bug that can’t be squashed

It's SQL injection’s 22nd birthday, and despite this vulnerability being old enough to drink, we’re letting it get the better of us instead of squashing it for good.

Learn More
Close-up of a red and yellow dragon toy with open mouth and detailed scales on teal background.
Blog
Filter Label
This is some text inside of a div block.

For developers to help slay the cybercrime beast, training is a quest in two parts

The playing field between the heroes and villains in cybersecurity is notoriously unfair. Sensitive data is the new gold, and attackers adapt quickly to circumvent defenses, exploiting security bugs large and small for potential paydirt.

Learn More
Badge with a person raising their fist, text reads Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security OWASP Top 10 API Series - Lack of Resources and Rate Limiting

This vulnerability occurs when too many requests come in at the same time, and the API does not have enough computing resources to handle those requests. The API can then become unavailable or unresponsive to new requests.

Learn More
Abstract glowing figure made of blue and white dots reaching out hands in a dark space.
Blog
Filter Label
This is some text inside of a div block.

The cybersecurity issues we can’t ignore in 2022

When it comes to battling against cybercriminals, we need to stay as in step with them as possible, preempting their playgrounds with a preventative mindset. Here’s where I think they might start making waves in the coming year:

Learn More
Badge with a smiling cartoon woman raising a fist and text 'Coders Conquer Security Share and Learn Series'.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security Infrastructure as Code Series: Missing Function Level Access Control

Without infrastructure-level access control in perfect order, it opens up an entire enterprise to attackers, who can use that vulnerability as their gateway for either unauthorized snooping or a full attack.

Learn More
Detailed anatomical model of a human heart with colorful arteries and veins on a stand.
Blog
Filter Label
This is some text inside of a div block.

Death by Doki: A new Docker vulnerability with serious bite (and what you can do about it)

Cyberattacks are only getting more frequent, and threats affecting Linux-based infrastructure are becoming more common, with the end goal being an opportunity to crack open a loot chest of sensitive data stored in the cloud.

Learn More
Circular emblem with text Coders Conquer Security Share and Learn Series and a cartoon figure waving inside.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security OWASP Top 10 API Series - Excessive Data Exposure

The actual mechanics behind this vulnerability are similar to others, but excessive data exposure, in this case, is defined as involving legally protected or highly sensitive data.

Learn More
View from inside a Mercedes-Benz car with driver and colorful light trails outside windshield at night.
Blog
Filter Label
This is some text inside of a div block.

When good microwaves go bad: Why embedded systems security is the next boss battle for developers

Much like web-based software, APIs, and mobile devices, vulnerable code in embedded systems can be exploited if it is discovered in the wild by an attacker.

Learn More
White astronaut figurine holding a flag in the foreground with three blurred astronauts behind on black background.
Blog
Filter Label
This is some text inside of a div block.

Turning boring PCI-DSS compliance into a meaningful exercise for everybody: Part 2 - CISOs and developer awareness

This is part 2 of a mini-series on PCI-DSS compliance within an organization. In this final chapter, we detail how CTOs and CISOs can lead from the top in reducing cyber risk and making the process seamless, successful... and maybe a little fun for developers.

Learn More
Stack of books including Ready Player One by Ernest Cline and The Hitchhiker's Guide to the Galaxy by Douglas Adams.
Blog
Filter Label
This is some text inside of a div block.

Is your organization really DevSec-ready? Put it to the test.

With your organization in mind, think about these questions in the context of your role. How would it fare when put to the DevSec test?

Learn More
Shiny blue beetle on green ivy leaves against a light green background.
Blog
Filter Label
This is some text inside of a div block.

Why SQL Injections Are The Cockroaches of the AppSec World (and how CISOs can eradicate them once and for all)

There's a well-known theory that cockroaches can survive basically anything - even a nuclear explosion.

Learn More
Badge with smiling person raising fist, text reads Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security OWASP Top 10 API Series - Insufficient Logging and Monitoring

The insufficient logging and monitoring flaw mostly happens as a result of a failed cybersecurity plan in regards to logging all failed authentication attempts, denied access, and input validation errors.

Learn More
Badge with a woman raising her fist and text Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security Infrastructure as Code Series: Insecure Cryptography

These days, having critical data like passwords, personal information and financial records hashed while at rest is a cornerstone of any cybersecurity defense.

Learn More
Blueprint-style wireframe sketch of a website layout with sections labeled in French.
Blog
Filter Label
This is some text inside of a div block.

Making moves with NIST: Our human-led position on the future of cyber defense

The recent cybersecurity Executive Order from the Biden Administration has certainly got the security industry talking, especially those who are looking to win over developers to the importance of applying secure coding best practices in their day-to-day work.

Learn More
Blog
Filter Label
This is some text inside of a div block.

A cyberattack occurs every 39 seconds. Is the government finally equipped to fight back?

We need to reinforce a human-led approach to cybersecurity best practices, and it’s going to get better results than a heavy reliance on automation, tools, and reaction to problems that have already been embedded and discovered.

Learn More
Silhouette of a man's profile against a glowing blue circular background on black.
Blog
Filter Label
This is some text inside of a div block.

Elevated security intelligence: Guided courses helping developers get NIST-ready

Developers are among those who are most up close and personal with code, in addition to security configurations and access control. Their security skills must be nurtured, and to achieve the high standards as outlined by NIST, a hands-on course structure might just be the efficient way to tackle it, especially with large development cohorts.

Learn More
Hand gripping the joystick control inside an aircraft cockpit with flight instrument displays.
Blog
Filter Label
This is some text inside of a div block.

Introducing Missions: The next phase of developer-centric security training

We're thrilled to announce a brand new feature release on the Secure Code Warrior platform: Missions. This all-new challenge category is the next phase in developer-ified security training, moving users from the recall of security knowledge, to applying it in a real-world simulation environment.

Learn More
Laptop on wooden table showing a row of yellow rubber ducks on its screen.
Blog
Filter Label
This is some text inside of a div block.

The future of work is flexible, and it's great for cybersecurity

Whether discomfort comes from the unknowns of a new way of working, a little mistrust, or perhaps not believing remote work, I find that companies who are resistant to it tend to fall behind in terms of attracting top talent, maintaining global reach and frankly, moving with the times.

Learn More
Silver badge with woman waving inside and text Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security Infrastructure as Code Series: Plaintext Storage of Passwords

The key to most computer security these days involves passwords. Even if other security methods are employed, like two-factor authentication or biometrics, most organizations still employ password-based security as one element of their protection.

Learn More
Close-up of turbine blades and central hub in a mechanical or jet engine.
Blog
Filter Label
This is some text inside of a div block.

One line of code, $1 million

The cost to change one line of code on a piece of avionics equipment is $1 million, and it takes a year to implement. For Southwest Airlines, whose fleet is based on Boeings 737, it would "bankrupt"

Learn More
Red Swiss Army knife with multiple blades, scissors, and tools extended against a dark background.
Blog
Filter Label
This is some text inside of a div block.

Suffering from a surfeit of security tools

A deluge of complex security tools is making cybersecurity even more challenging for CISOs.

Learn More
Badge with a smiling person in yellow and text Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Build secure coding skills at every stage of the SSDLC

Secure Code Warrior has built a GitHub Action that brings contextual learning to GitHub code scanning. This means developers can use a third-party action like the Snyk Container Action to find vulnerabilities, and then augment the output with CWE-specific, hyper-relevant learning.

Learn More
Man in blue hoodie sitting on couch with hands covering face, next to cardboard boxes and trays.
Blog
Filter Label
This is some text inside of a div block.

My pentester, my enemy? Developers reveal what they really think about pentesting and static analysis results

Penetration testing and static analysis scanning tools (better known as SAST) are just part of the overall process to mitigate security risks, operating rather independently from what we do - until the code bounces back to us for hotfixes, of course!

Learn More
Desk setup with a keyboard, white coffee mug, phone, two succulent plants, and a sign reading 'NO BAD DAYS'.
Blog
Filter Label
This is some text inside of a div block.

Starting "left of left": Is secure code always quality code?

Code of a certain level of quality is by its definition also secure, but all secure code is not necessarily good quality. Is starting “left of left” the formula to ensure pure secure coding standards?

Learn More
Badge with a woman raising her fist, text reads Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security Infrastructure as Code Series - Using Components From Untrusted Sources

The vulnerability-inducing behavior that we are going to focus on here is using code from untrusted sources, a seemingly benign practice that is causing big problems.

Learn More
Bald man in white shirt resting his chin on his hand, looking thoughtfully to the side.
Blog
Filter Label
This is some text inside of a div block.

Equifax security issues uncovered in 2016

Skip forward to 2016 and a security researcher found a common vulnerability known as cross-site scripting (XSS) on the main Equifax website, according to a tweet from a researcher who goes by the name x0rz.

Learn More
Logo with a smiling cartoon coder raising a fist, text reads Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security OWASP Top 10 API Series - Improper Assets Management

This vulnerability is more of a human or management problem that allows older APIs to remain in place long after they should have been replaced by newer, more secure versions.

Learn More
Two men working together at a desk, one writing notes, the other focused on a laptop.
Blog
Filter Label
This is some text inside of a div block.

Champions vs. coaches: Why every development team needs both

Many companies who are kicking goals in their cybersecurity approach have implemented an official security champion program, bestowing key security responsibilities - everything from liaising between teams and general cheerleading, to overseeing best practices - onto individuals who show aptitude and passion for such a role.

Learn More
Close-up of light blue metal surface heavily covered in irregular brown rust patterns and streaks.
Blog
Filter Label
This is some text inside of a div block.

Rust is the most-loved programming language for the fifth time. Is it our new security savior?

Rust incorporates known and functional elements from commonly used languages, working to a different philosophy that disposes of complexity, while introducing performance and safety.

Learn More
Badge with a person raising a fist inside with text Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security OWASP Top 10 API Series - Disabled Security Features/Debug Features Enabled/Improper Permissions

It's likely a little more prevalent in APIs, but attackers will often attempt to find unpatched flaws and unprotected files or directories anywhere in a network. Coming across an API that has debugging enabled or security features disabled just makes their nefarious work a little easier.

Learn More
Blue neon sign on dark wood wall reads: Wake up. Kick ass. Repeat.
Blog
Filter Label
This is some text inside of a div block.

How to Become a Kick-Ass DevSecOps Engineer

The world is starting to move on past Waterfall, Agile, and now DevOps, so what is the next solution? And as a developer, what is your role in keeping pace with these changes in approach?

Learn More
Close-up of illuminated orange steel beams and girders of a bridge structure at night.
Blog
Filter Label
This is some text inside of a div block.

Why scaffolded learning builds security-strong developers

As an industry, we should never expect developers to become security experts, but organizations can adopt new standards for developer enablement so they can produce higher quality software.

Learn More
Silver badge with cartoon woman raising fist and text Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security Infrastructure as Code Series: Insufficient Transport Layer Protection

At times, applications will also share data with other programs as part of an overall workload. Unless the transport layer is protected, it makes it vulnerable to both outside snooping and unauthorized internal viewing.

Learn More
Abstract colorful neon numbers and shapes projected on dark walls in a dim room with faint people shadows.
Blog
Filter Label
This is some text inside of a div block.

National Cybersecurity Awareness Month: More than a phishing expedition

Every organization can utilize Cybersecurity Awareness Month to refresh their security awareness, and this year, were also launching a new, free app for the coding community!

Learn More
Pile of assorted colorful plastic building blocks scattered closely together.
Blog
Filter Label
This is some text inside of a div block.

Building trust: The path to true security synergy between AppSec and developers

A relationship that is built on the shaky foundations of mistrust is, well, best approached with low expectations. Sadly, this can be the state of the working relationship between developers and the AppSec team within an organization.

Learn More
Badge with cartoon woman raising fist with text: Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security Infrastructure as Code Series: Security Misconfiguration - Improper Permissions

Security misconfigurations, especially those of the improper permissions variety, most often happen whenever a developer creates a new user or grants permission for an application as a tool in order to accomplish a task.

Learn More
Badge with a smiling woman raising her fist and text Coders Conquer Security Share and Learn Series.
Blog
Filter Label
This is some text inside of a div block.

Coders Conquer Security Infrastructure as Code Series: Disabled Security Features

Attackers will always attempt to find easily exploitable vulnerabilities first and may even use a script to run through common weaknesses. It's not unlike a thief checking all the cars on a street to see if any doors are unlocked, which is a lot easier than smashing a window.

Learn More
Sequence of nine red moons showing phases of a lunar eclipse against a black sky.
Blog
Filter Label
This is some text inside of a div block.

Have you overestimated your organization’s security maturity?

With a persistent skills shortage at odds with the deluge of code being written to satisfy the world’s software needs, many businesses are falling behind in their cybersecurity strategy and existing infrastructure. It’s time we took an honest look at our overall cybersecurity maturity, and assessed the viable quick wins that are right in front of us.

Learn More
Silhouettes of three people talking inside a building with large windows overlooking a cityscape.
Blog
Filter Label
This is some text inside of a div block.

How world-class CISOs are winning more budget and board trust in 2023

CISOs are finding themselves in an increasingly fraught position: Protect more assets, ship more code, reduce a bigger attack surface, and do it with rapidly diminishing financial resources. It’s an inescapable fact that cybersecurity is viewed as a cost center, and despite an organization’s security program being what stands in the way of a threat actor making them tomorrow’s disastrous headline, security leaders must do more to sell in and prove the overall business value of the department, in language that makes sense to the executive body.

Learn More
Person with tattoos using a white point-of-sale device while another holds a Visa card nearby.
Blog
Filter Label
This is some text inside of a div block.

With the right support, developers can lead your organization to superior PCI DSS 4.0 compliance

Learn More
Blog
Filter Label
This is some text inside of a div block.

Driving Meaningful Success for Enterprise Secure-by-Design Initiatives

Our latest research paper, Benchmarking Security Skills: Streamlining Secure-by-Design in the Enterprise is the result of deep analysis of real Secure-by-Design initiatives at the enterprise level, and deriving best practice approaches based on data-driven findings.

Learn More
Unlocked shield lock icon connected to cloud, settings, web page, and three keys on blue tech background.
Blog
Filter Label
This is some text inside of a div block.

The Benefits of Benchmarking Security Skills for Developers

The growing focus on secure code and Secure-by-Design principles requires developers to be trained in cybersecurity from the start of the SDLC, with tools like Secure Code Warrior’s Trust Score helping measure and improve their progress.

Learn More
Blog
Filter Label
This is some text inside of a div block.

Reactive Versus Preventive Security: Prevention Is a Better Cure

The idea of bringing preventive security to legacy code and systems at the same time as newer applications can seem daunting, but a Secure-by-Design approach, enforced by upskilling developers, can apply security best practices to those systems. It’s the best chance many organizations have of improving their security postures. 

Learn More
Illustration of an unlocked shield lock linked to cloud, control sliders, a window, and three keys against blue background.
Blog
Filter Label
This is some text inside of a div block.

Trust Score Reveals the Value of Secure-by-Design Upskilling Initiatives

Our research has shown that secure code training works. Trust Score, using an algorithm drawing on more than 20 million learning data points from work by more than 250,000 learners at over 600 organizations, reveals its effectiveness in driving down vulnerabilities and how to make the initiative even more effective.

Learn More
Webinar
Filter Label
This is some text inside of a div block.

Benchmarking Security Skills: Streamlining Secure-by-Design in the Enterprise

Finding meaningful data on the success of Secure-by-Design initiatives is notoriously difficult. CISOs are often challenged when attempting to prove the return on investment (ROI) and business value of security program activities at both the people and company levels. Not to mention, it’s particularly difficult for enterprises to gain insights into how their organizations are benchmarked against current industry standards. The President’s National Cybersecurity Strategy challenged stakeholders to “embrace security and resilience by design.” The key to making Secure-by-Design initiatives work is not only giving developers the skills to ensure secure code, but also assuring the regulators that those skills are in place. In this presentation, we share a myriad of qualitative and quantitative data, derived from multiple primary sources, including internal data points collected from over 250,000 developers, data-driven customer insights, and public studies. Leveraging this aggregation of data points, we aim to communicate a vision of the current state of Secure-by-Design initiatives across multiple verticals. The report details why this space is currently underutilized, the significant impact a successful upskilling program can have on cybersecurity risk mitigation, and the potential to eliminate categories of vulnerabilities from a codebase.

Learn More
Secure Code Warrior logo and text about reclaiming critical thinking in AI-augmented secure software development.
Blog
Filter Label
This is some text inside of a div block.

Reclaiming Critical Thinking in AI-Augmented Secure Software Development

The AI debate isn't about use, but application. Discover how to balance the need for AI productivity gains with robust security by relying on developers who deeply understand their code.

Learn More
Secure Code Warrior logo with text: The Agentic Era Arrived Early. Don't Get Caught Off Guard by Late AI Governance.
Blog
Filter Label
This is some text inside of a div block.

The Agentic Era Arrived Early: Don’t Be Caught Off Guard

Anthropic's Claude Mythos represents a permanent, fundamental shift in how every security leader must approach their security program, especially with patch management of legacy systems.

Learn More
Stack of white documents with blue lines and a blue folded corner on a purple gradient background.
Whitepapers
Filter Label
This is some text inside of a div block.

Forge your fortress: Six essential pillars of developer enablement in software security

In this white paper, security expert and Secure Code Warrior CTO & Co-Founder Matias Madou, Ph.D. will discuss:The six pillars you need to roll out effective security education and enablement for your development cohort. Lessons learned from ten executives implementing security programs at the enterprise level, and common pitfalls to avoid on your road to success.

Learn More