From Foundation to Maturity: How to Build a solid AppSec Program

webinar card for li

In this OX Security webinar, Field CTO Boaz Barzel is joined by Dustin Lehr (co-founder of Katilyst) and David Kosorok (Director of Information Security Programs at Toast) to map the journey of building an application-security program from foundation to maturity. The conversation moves through three stages: how to approach the program before buying any tools (interview stakeholders, build relationships, inventory and prioritize assets), the must-have AppSec tool belt and how to justify it, and how to measure success in a way that drives real risk reduction rather than vanity metrics. Throughout, the panel stresses that AppSec is fundamentally about partnership, trust, and making the business case, and closes on the practical roles of AI and ASPM.

Key Takeaways

  • Start with relationships, not tools. Before any scanner, interview stakeholders to learn the business, its risk appetite, and who your allies are. Security is a partnership, not a dictatorship.
  • Inventory first, then prioritize. You can’t secure everything. Rank apps by public exposure, data sensitivity, business criticality, and interconnectivity, then start at the top.
  • Make the business case with real risk. Justify tools, headcount, and budget by demonstrating existing risk and past incidents, and lean on partnerships with GRC, legal, and sales.
  • Don’t overwhelm developers. Tune out false positives and send the few critical, exploitable findings that matter. Proving exploitability builds the trust that lets you expand later.
  • Treat compliance as the floor, not the goal. Use PCI, SOC 2, and NIST obligations to unlock budget, but hold yourself to the spirit of the controls and define real SLAs that leadership signs off on.
  • Measure risk reduction, not volume. Track fixes against SLAs, escape rate, and trend lines; avoid vanity metrics like lines of code or raw vuln counts. And treat AI as a co-pilot, not an autopilot.

Video Transcript

Speakers

boaz li image

Boaz Barzel

View on LinkedIn

Field CTO, OX Security (host/moderator)

Field CTO at OX Security and the session’s moderator.

DustinLehr

Dustin Lehr

View on LinkedIn

Co-founder, Katilyst

Co-founder of Katilyst, a former software engineer turned AppSec leader focused on security culture and security champions.

David Kosorok David Kosorok

David Kosorok

View on LinkedIn

Director, Information Security Programs, Toast

Director of Information Security Programs at Toast, who moved from software testing into AppSec nearly two decades ago.

FAQ

With people, not tools. Ask your hiring manager who to talk to, then ask everyone you meet the same question, building a stakeholder list that may take months to work through. Understand the business, its risk appetite, and concerns, and in parallel build a technical asset inventory of repos and deployed apps.

You can’t secure everything, so prioritize. Score apps by whether they’re public facing, the sensitivity of the data they handle, their business criticality, and how interconnected they are. Start with the one critical, public-facing, high-data, highly-depended-on app, then layer in pentesting and threat modeling over time.

Demonstrate real risk: past incidents, issues found in production, or classes of vulnerabilities that recur. Partner with GRC, legal, and sales, and use compliance drivers like PCI as the initial budgetary push to get the program moving.

Buying the bright, shiny, upper-right-quadrant tool before checking it fits your stack; over-securing an MVP that has no users yet; and dumping thousands of findings on developers. Each wastes money and the credibility you’re trying to build.

A regular pentest cadence, SAST, DAST, and SCA, threat modeling, bug bounty, plus asset inventory and prioritization tooling and a security-champions program. Match each tool to how your developers actually work and to your environment, and bring your partners into the evaluation.

Measure risk reduction, SLA adherence, and vulnerability escape rate, and show momentum with trend lines and targets rather than just a backlog of what’s left. Avoid metrics like lines of code or raw vuln counts that invite gaming or vanity.

Treat AI as a co-pilot, not an autopilot, useful for skeleton code and, increasingly, remediation, but not yet trustworthy to run unattended. ASPM (application security posture management) is one component of the broader AppSec strategy, mainly aggregating results across tools and prioritizing where to start.