
DEF CON 32 - Transforming AppSec Protecting 'Everything as Code' - Kunal Bhattacharya
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 45:00
In an "everything is code" world, application security faces challenges from role blurring, data overload, and shifting responsibilities, demanding context-driven, balanced practices rather than over-reliance on developers or automation.
Key Takeaways:
• Role blurring in CI/CD pipelines undermines ownership and context; clear separation between developers, security, and operations is fading 5:56.
• Data explosion in vulnerability management requires better architecture and correlation, not just more tools 6:32.
• Developers should not bear all security burdens—shifting left too much creates bottlenecks and overloads 13:35–14:00.
• Contextual, role-specific training for developers is more effective than generic security education 15:52–16:29.
• Unified vulnerability management is possible only through data unification, not tool or policy unification—remediation must account for asset-specific risk and effort 25:54–29:10.
• AI can assist with patching and PR generation but should not enable auto-remediation without solid foundational practices in asset and policy management 35:02–37:35.
Security must evolve with context, not just tools—developers are not the root problem, but education and organizational structure need improvement.
Sources:
- 5:56 Role blurring in CI/CD pipelines.
- 6:32 Data challenges in vulnerability management.
- 13:35–14:00 Over-reliance on developers in shift-left practices.
- [15:52–16:29](https://www.youtube.com/wat
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hi uh my name is Kunal bachara I a senior security leader and adviser um my security Journey has been pretty long before I came into security I've done a bunch of different things uh was a developer was s adman was QA uh architect uh finally moved to security and never looked back um I also have had the privilege of building a homegrown bug boundi program before the likes of hacker one I don't know if they are the spons answer uh but U uh and then eventually moved into a lot of the security stuff and I just considered myself to be a u lifelong learner uh apart from security uh I guess I'm a average Runner swimmer um Dad whatever um yeah so that's me Sarah you want to introduce yourself hi everyone my name is Sarah har I lead vulnerability management at docy sign I in in the vulnerability m…