ASPM Mastery: Elevating Application Security Beyond the Basics

with time

In this OX Security webinar, moderator Boaz Barzel is joined by Maxym Shapoval (uklon), Artem Ryabov (SOFTSWISS), and Colin Bell (AppScan) to explore what it means to master ASPM and move application security beyond the basics. The panel covers the core challenges of scaling AppSec across many products, why automation and a centralized ecosystem are essential, and how ASPM shifts risk management from reactive to a proactive, continuous-security model. They share practical strategies for scaling without dropping quality (EPSS, reachability, security champions, starting small), KPIs centered on stopping repeat vulnerabilities, the value of collaboration and gamification, and the trends, attack-surface management, reachability, and AI, shaping the future of the field.

Key Takeaways

  • ASPM is about an ecosystem, not separate tools. With 130+ products, automation that discovers projects, runs scans, and creates and tracks tickets is essential; the goal is one centralized security ecosystem.
  • Move from reactive to “continuous security,” shift everywhere. ASPM’s value is centralized visibility and metrics that let risk managers act proactively, built on governance, standards, and audit, not just shift-left.
  • Scale without losing quality by prioritizing exploitability. Automate scanning in CI/CD, use EPSS and reachability to fix what’s most likely exploited, and build security champions so dev and security work closely.
  • Start small, prove it, then scale horizontally. Use the Pareto rule for quick wins, validate a practice on a small scope, then roll it out across teams and improve its quality over time.
  • Measure what isn’t fixed, and stop repeat vulnerabilities. A strong KPI is zero high or critical vulnerabilities carried over from previous sprints; catching issues before release keeps fixes cheap.
  • Collaboration beats enforcement. Treat security tooling as an internal product, use gamification like internal CTFs and leaderboards, and give developers trustworthy, consolidated findings so they fix less and solve more.

Video Transcript

Speakers

boaz li image

Boaz Barzel

View on LinkedIn

OX Security (host/moderator)

Leads technology evangelism and enablement at OX Security and moderates the session.

Maksym Shapoval (1)

Maksym Shapoval

View on LinkedIn

Head of Information Security, uklon

Head of information security and business continuity at uklon, a Ukrainian ride-hailing and delivery company, with over 13 years in information security.

artem

Artem Bychkov

View on LinkedIn

Head of AppSec and Product Security, SOFTSWISS

Head of product security at SOFTSWISS, with over 15 years in security including eight in application and product security across offensive and defensive roles.

Colin Bell

CTO, AppScan

CTO for the AppScan application security testing product, a former pentester and developer who has worked on AppScan since 2007, including years at IBM.

FAQ

Build genuine attack-surface awareness, scale both technical and process practices, and get engineering working in concert with security. The mindset shift is to treat security as one connected ecosystem rather than a set of point tools.

At 130+ products you can’t manually run scanners, maintain dashboards, and manage tickets. Automation discovers new projects, sets up and runs scans, creates and tracks tickets, and re-scans to verify fixes, which is the only way to manage security posture at that scale.

It adds centralized, continuous visibility and metrics, enabling a proactive “continuous security” model with governance, standards, and audit, rather than the reactive, siloed testing security has relied on for years.

Automate scanning in the CI/CD pipeline, prioritize with EPSS and reachability so you fix what matters, set realistic goals (start small, then scale), and build a core of security champions to keep development and security aligned.

Track total vulnerabilities and, crucially, vulnerabilities carried over from previous sprints, targeting zero for high and critical. Finding new issues is normal; repeating old ones is not. Catching them before release keeps fixes cheap.

Frame it by attack surface, not tool type: external-facing exposure first, then internal findings by CVSS. Correlating SAST, DAST, SCA, and IAST results into one place (the ASPM approach) gives richer, fix-oriented insight than any single scanner.