
AppSec Unlocked
AppSec Unlocked is a podcast focused on application security, helping listeners understand complex security concepts. It is designed for security professionals, developers, and curious learners at any level. The show aims to demystify application security one episode at a time, making the topic more accessible and approachable.
Episodes

S2E12 -The Future of Security Training
Season 2: Training & AwarenessEpisode 12: The Future of Security TrainingWe're at the season finale on the theme of Training & Awareness. We're going to finish off the season by looking ahead to the future of security training and awareness. Over the past eleven episodes, we've covered everything from Security Champions to cloud security. Now it's time to explore what's

S2E11 - Security Training for Remote Teams
Season 2: Training & AwarenessEpisode 11: Security Training for Remote TeamsIn this episode, we're looking at a challenge that's become increasingly critical: security training for remote teams. We'll explore how to build and maintain a strong security culture when your team is distributed across different locations, time zones, and even continents.

S2E10 - Cloud Security Awareness
Season 2: Training & AwarenessEpisode 10: Cloud Security AwarenessIn this episode, we'll be talking about cloud security awareness and exploring why traditional security thinking falls apart in the cloud, and how to build a new security mindset for the cloud era.

S2E9 - Secure Development Lifecycle Training
Season 2: Training & AwarenessEpisode 9: Secure Development Lifecycle TrainingIn this episode, we’ll look into Secure Development Lifecycle training, or SDL. We're going to explore how to build security into every phase of your development process—from initial planning through deployment and beyond.

S2E8 - The Human Factor - Social Engineering Defense
Season 2: Training & AwarenessEpisode 8: The Human Factor - Social Engineering DefenseIn this episode, we'll be diving deep into what many consider the most persistent security threat: social engineering. We'll explore why humans are often called the weakest link in security – and more importantly, what we can do about it.

S2E7 - Crisis Response Training: Preparing for the Inevitable
Season 2: Training & AwarenessEpisode 7: Crisis Response Training: Preparing for the InevitableIn this episode we're diving deep into crisis response training. Because in security, it's not if a crisis will happen, but when. Every organization will face security incidents—that's simply the reality of our digital landscape today.

S2E6 - Executive Security Awareness - Speaking the Board's Language
Season 2: Training & AwarenessEpisode 6: Executive Security Awareness - Speaking the Board's LanguageIn this episode, we learn from special guest and seasoned CISO Mangaraja Saut Martua on how to communicate security risks to executives, board-level security awareness program and how to translate technical risks into business impact.

S2E5 - Secure Coding Bootcamps - From Theory to Practice
Season 2: Training & AwarenessEpisode 5: Secure Coding Bootcamps - From Theory to PracticeLast episode, we discussed building a security culture. Today, we're getting hands-on with one of the most effective ways to improve security: secure coding bootcamps

S2E4 - Security Culture by Design
Season 2: Training & AwarenessEpisode 4: Security Culture by DesignIn our previous episode, we dove into measuring security awareness. Today, we're tackling something more fundamental: how to build security into your organization's DNA. We're talking about creating a security culture by design.

S2E3 - Measuring Security Awareness - Metrics That Matter
Season 2: Training & AwarenessEpisode 3: Measuring Security Awareness - Metrics That MatterIn our previous episodes, we explored building Security Champions programs and effective developer training. Today, we're tackling a challenge that keeps many CISOs up at night: How do you actually measure if your security awareness programs are working?

S2E2: Developer Security Training - Beyond Annual Compliance
Season 2: Training & Awareness
Episode 2: Developer Security Training - Beyond Annual Compliance
In our last episode, we talked about building an effective Security Champions program. Today, we're tackling something even bigger: How to make security training actually work for developers.

S2E1: Building a Security Champions Program That Actually Works
Season 2: Training & Awareness
Episode 1: Building a Security Champions Program That Actually Works
In this episode we'll talk about the most important security program you're not running correctly: The Security Champions program.

Season 2 Intro: Training and Awareness
Intro to Season 2 of AppSec Unlocked
Welcome to Season 2 where we're diving into something critical that often gets overlooked in the world of cybersecurity: Training and Awareness.

Help! There’s too many Vulnerabilities! A Practical Guide to Tackling Open-Source Security
Season 1: Open Source Security
Episode 11: Help! There’s too many Vulnerabilities! A Practical Guide to Tackling Open-Source Security

S1E10 - A FAIR Approach to Vulnerability Patch Prioritization
Season 1: Open Source Security
Episode 10: A FAIR Approach to Vulnerability Patch
Prioritization
In this episode of AppSec Unlocked, we dive into the fascinating topic of using a FAIR approach to Vulnerability Patch prioritization, where we explore how organizations can better prioritize vulnerabilities in their open-source software using the FAIR model and EPSS. And we have Denny Wan, an expert o

S1E9 - Open-Source Vulnerability Management Policy: A Balanced Approach
Season 1: Open Source Security
Episode 9: Open-Source Vulnerability Management Policy: A Balanced Approach
In today's rapidly evolving cybersecurity landscape,
managing vulnerabilities in open-source components has become increasingly
complex. While traditional approaches relying solely on CVSS scores have their
merits, they may not be sufficient to address the exponential growth in
discovered vul

S1S8 - A Cautionary Tale on Supply Chain Attacks: My Recent Encounter with a Compromised NPM Library
Season 1: Open Source Security
Episode 8: A Cautionary Tale on Supply Chain Attacks: My Recent Encounter with a Compromised NPM Library
This is a rebroadcast from the CyberBites podcast as it is related to application security and open source supply chain.

S1E7 - Introduction to SSVC
Season 1: Open Source Security
Episode 7: Introduction to StakeholderSpecific
Vulnerability Categorization (SSVC)
Introduction to a transformative risk-based approach to vulnerability management
Why SSVC, especially when we already have CVSS
How SSVC works and how to use it
Challenges and considerations
Real-world example

S1E6 - Software Composition Analysis Selection Criteria
Season 1: Open Source Security
Episode 6: Software Composition Analysis Selection Criteria
The Language of Love (and Code)
Accuracy: The Goldilocks Zone
Speed: Because Time is Money (and Sanity)
Remediation: The Path of Least Resistance
User-Friendly: No Computer Science Degree Required
Timing is Everything
The Never-Ending Story

S1E5 - Embarking on the Open Source Security Journey
Season 1: Open Source Security
Episode 5: Embarking on the Open Source Security Journey.
When Organisations Take the Leap
The Crucial Role of Awareness and Buy-in
The First Steps: Gaining Visibility
Key Takeaways for a Successful Program
Practical Steps and Resources

S1E4 - 5 Steps for Securing Your Open Source Supply Chain
Season 1: Open Source Security
Episode 4: 5 Steps for Securing Your Open Source Supply Chain
Most modern applications are assembled from open-source components with developers typically writing less than 15% of the code for their application. Here are the 5 Steps for securing your open source supply chain.
Step 1: Maintain a Software Bill of Materials (SBOM)
Step 2: Perform Due Diligence - Scan

S1E3 - How Secure Is Open Source Software
Series 1: Open-Source Security
Episode 3: How Secure Are Your Open Source Software
Get ready for an eye-opening episode that could change the way you think about the building blocks of modern applications.
The Open-Source Paradox
The Security Controls Gap
The Open-Source Enigma
The Due Diligence Disparity
The Cost of Insecure Open Source: A Walk Down Memory Lane
Best Practices for Secure Op

S1E2 - Do Your Applications Have A Software Bill of Materials?
Season 1: Open Source Security
Episode 2: Do Your Applications Have A Software Bill of Materials?
“Oh, I didn’t realise we were exposed to as I didn’t think that application was using .”
I often heard such comments during the initial stages of our application security uplift. There was a lack of visibility on what open-source components applications relied on. Developers were often surprised, an

S1E1 - You're Using More Open-Source Than You Realize
Season 1: Open Source Security
Episode 1: You're Using More Open-Source Than You Realise
We're diving into a topic that might surprise you: "You're Using More Open-Source Than You Realize." Get ready for an eye-opening episode that could change the way you think about your applications.
• The Open-Source Reality Check
• Real-World Example: The Log4j Wake-Up Call
• The Rise of AI in Develo

Introduction
Welcome to AppSec Unlocked, the podcast that's all about
demystifying application security and empowering developers and security professionals alike. I'm your host, Edwin Kwan, and I'm thrilled to kick off this exciting journey with you.
What is AppSec Unlocked?
AppSec Unlocked is your key to understanding the complex world of application security. Whether you're a seasoned secu
Recommended

English Vocabulary Help

این نقطه

Solved Murders - True Crime Stories

紐約鳥|New York Aperture

Doctor Zhivago Slow Read

Apple News In Conversation

The Young and Called Podcast .

Jubal Phone Pranks from The Jubal Show

پلی لیست | PlayList

English with Olivia | Slow Conversations & Vocabulary

Bible Tea

TED Talks Daily