AppSec Evolution: Navigating the Path to Maturity

app sec boaz

In this Black Hat 2024 CyberRisk TV interview, Security Weekly’s Mandy Logan talks with Boaz Barzel of OX Security about how application security is maturing. They trace the shift from a discovery-first era to one focused on generating context, automated prioritization and consolidation down to root-cause fixes, and discuss how frameworks like secure by design and OSC&R fit in. Boaz argues that almost every company is now a software company, that the biggest challenge is manual AppSec work, and that AppSec is fundamentally different because remediation sits with developers, which calls for a continuous, real-time, evidence-backed approach that OX aims to deliver.

Key Takeaways

  • AppSec maturity is shifting from discovery to context. Listing vulnerabilities isn’t enough when code ships daily; the next level is automated prioritization and consolidation down to the few root-cause fixes that matter.
  • Use frameworks, but fix your current risk first. Secure by design, SLSA, and NIST help long term, but with huge backlogs the priority is understanding current posture and the risks to fix now.
  • OSC&R brings the whole picture together. The Open Software Supply Chain Attack Reference converges ADR, application security testing, supply-chain security, and ASPM to show how exposed you are and how attackers see you.
  • Almost every company is now a software company. Roughly 90%+ have an AppSec role and 50%+ treat AppSec as a top-five board-level risk, as focus shifts from network, endpoint, and cloud to the code.
  • The biggest challenge is manual AppSec. Manual analysis, ownership, and triage are the bottleneck; automating them lets teams leapfrog straight to response instead of crawling through every tooling stage.
  • AppSec is different because remediation sits with developers. Security can’t fix the code, so it must deliver real-time, prioritized, evidence-backed findings (and even gamify) to win developer traction without slowing releases.

Video Transcript

Speakers

Mandy Logan

Mandy Logan

View on LinkedIn

Security Weekly / Cyber Risk Alliance (host)

Host with Security Weekly and Cyber Risk Alliance, covering Black Hat 2024 on CyberRisk TV.

boaz li image

Boaz Barzel

View on LinkedIn

Technical Evangelist and Director of Enablement, OX Security

Technical evangelist and director of enablement at OX Security.

FAQ

From a focus on discovery and scanning toward generating context: automated prioritization and consolidation to root-cause fixes. With code shipping weekly or daily, simply listing vulnerabilities no longer scales.

Yes. Frameworks like secure by design, SLSA, NIST, and OSC&R help in the long run, but because backlogs are already huge, the immediate focus should be understanding current posture and fixing today’s real risks.

The Open Software Supply Chain Attack Reference, a framework that takes maturity further by converging application detection and response, application security testing, software supply chain security, and ASPM, revealing exposure and the attacker’s perspective.

Almost every company develops software (maybe only ~5% don’t), so AppSec is now broad: more than 90% of organizations have an AppSec position, and more than 50% treat it as a top-five board-level risk.

Manual practices: analysis, determining ownership, triage, and gathering context all done by hand. Automating that work lets teams skip ahead to response and leapfrog years of tooling evolution.

Remediation sits with developers, not the security team, so it needs a continuous, real-time, evidence-backed approach. OX eliminates manual AppSec across the pipeline, uses OSC&R and ADR to surface the few critical issues with guided remediation, and frees teams to work strategically without slowing development.