Devin Rudnicki -- Expanding AppSec
With Devin Rudnicki
Devon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role. She emphasizes the importance of collaboration, understanding the organization's business, and using metrics to drive positive change in the security program.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 14 chapters
- 00:00Meet Devin Rudnicki: Expanding AppSecAudioVideo ↗
- 03:05Very cool. So the internship, security and governance, does that leadAudioVideo ↗
- 05:03Is that What's that approval look like as far as, isAudioVideo ↗
- 07:28What's the first thing that you focus on with this programAudioVideo ↗
- 10:17You're kind of, you're learning a little bit about the personalitiesAudioVideo ↗
- 11:41Yes, I think that's an important tactical thing that we canAudioVideo ↗
- 14:54Yeah. Okay. So when we, if we break the program, thenAudioVideo ↗
- 17:54Okay. So, that's the vulnerability management side. How about developer educationAudioVideo ↗
- 20:23In the past, I would say no to that question, andAudioVideo ↗
- 21:18That's, you know, you can minimize. But yeah, I mean, penAudioVideo ↗
- 24:49Tracking the work. What metrics and KPIs did you use toAudioVideo ↗
- 27:05Yeah, and I had a similar situation in my previous timeAudioVideo ↗
- 30:03Devin, we have 3 questions that we typically ask in theAudioVideo ↗
- 32:59The gene splicing therapy. We'll find it and put it inAudioVideo ↗
About this episode
Devon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role. She emphasizes the importance of collaboration, understanding the organization’s business, and using metrics to drive positive change in the security program. Devin Rudnicki, the Chief Information Security Officer at Fitch Group, developed an application security program and advanced to the CISO role after years in security governance. She holds a BS in mathematics from DePaul University and multiple certifications, including CISSP, GSTRT, GSEC, and GCSA. Outside work, she enjoys group fitness, global travel, and mentoring in cybersecurity.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results.
→ Learn more about Security Journey
Connect with Devin Rudnicki:
→ Alice and Bob Learn Application Security
→ RSA Conference
Resources
→ Alice and Bob Learn Application Security
→ RSA Conference
→ Black Hat
→ Walter Isaacson
Actionable
From this conversation
- 7:31
Build and socialize an AppSec roadmap
First off, I built a roadmap that I could use to socialize my vision for the program and communicate with the key stakeholders what would be needed from them.
- 9:50
Tailor stakeholder discussions to their needs
Then be able to tailor your conversation to meet not only your needs, obviously, but their needs.
- 17:09
Automate vulnerability ticket workflows
We wanted to make sure that as much of the process was automated as possible.
- 25:04
Track closure and training metrics
We did try to show the value as far as showing the vulnerability closure rates and showing the trends and vulnerabilities from quarter to quarter or month to month, depending on what level of reporting you were doing.
- 33:49
Learn how your organization makes money
You need to understand how your organization makes money, and you need to understand what can you do as a security leader to help enable that.
Transcript · 36 min conversation
0:01Chris RomeoDevin Rudnicki, the Chief Information Security Officer at Fitch Group, developed an application security program and advanced to the CISO role after years in security governance. She holds a BS in mathematics from DePaul University and multiple certifications, including CISSP, GSTRT, GSEC, and GCSA. Outside work, she enjoys group fitness, global travel, and mentoring in cybersecurity. Devin joins us to explain how to build an AppSec program from scratch, what to do with that new program, how to quickly expand the program and tools, and the metrics and KPIs that you need to demonstrate success.
0:44Devin RudnickiThe Application Security Podcast is brought to you by Security Journey. Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results. Learn more at securityjourney.com.
0:59Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo, CEO of DaVinci, general partner at Curve Ventures, and also my most honorable, I think, title, co-host of the Application Security Podcast with Robert Hurlbut. Hey, Robert.
1:29Robert HurlbutHey, Chris. Yeah, Robert Hurlbut, Principal Application Security Architect and Threat Modeling Lead at Acquia, and excited to be here again for another Application Security Podcast.
1:40Chris RomeoYeah, we're going to have fun with this one because we're getting to talk to a practitioner who's built a program from the ground up. And these are always the most fascinating stories for me because I always learn something about that I can apply next time I get a chance to either build a program or help somebody build a program. So without further ado, we'd like to introduce Devin Rudnicki. And Devin, we always like to jump right into people's security origin stories, like no time to warm up. It's like dive right in. Tell us that story.
2:09Devin RudnickiYeah, well, first of all, thank you so much for having me today. I'm really excited to be here. So my security origin story is really interesting, actually. or maybe not so interesting. So when I was in college, I was a sophomore and I was looking for an internship. And at that point, at that age, I really just wanted to get an internship, to be completely honest. So I was walking around the career fair at my college, and then it just turned out that there was a company there that wanted an IT/security governance intern. So I just really impressed the hiring manager there and was able to get that internship. And that really started my entire journey in security. And I'm so extremely grateful that they decided to take that chance on me because I didn't have the education or the background necessarily coming from a mathematics degree. So then it was just a huge focal point for starting in my security journey.
3:05Chris RomeoVery cool. So the internship, security and governance, does that lead you to the first job? at that company or did you end up landing somewhere else? I know a lot of times internships kind of lead, at least as the employer, you're always trying to get interns to join the company at the end of their college career. How'd that work out for you?
3:28Devin RudnickiYeah, so it's interesting. I actually ended up having my first job at EY, Ernst Young, because I actually got to know one of the managers who was working with us at that time and then got recruited into that program, did the internship with EY, and then went on to go full-time in EY. So that was more an IT risk advisor role.
3:49Chris RomeoOkay. So, you probably got a chance to see a lot of different situations, organizations as a consultant than being in just a single organization. So, did you get to kind of sample a number of different places to see how people were doing security?
4:06Devin RudnickiSo, the funny enough story about that though is, yeah, I actually only spent about 7 months in consulting before I got lured right back into industry, actually back at that first company that I interned with.
4:19Chris RomeoOh, so it came full circle.
4:20Devin RudnickiSo I went into cybersecurity governance. It was a little boomerang action there.
4:24Chris RomeoOkay, nice.
4:25Robert HurlbutSo that works. And cool. So Devin, when building an AppSec program from scratch, just diving in here to our topic today, how did you get the charter to build the program?
4:40Devin RudnickiYeah. So it was nice because I came into the organization being hired to do that exact thing. So my manager at the time, the CISO, actually had gone before the board and everything to go ahead and get approval to build out the application security program. So that was kind of nice. I already had that, that approval and, you know, designation from when I first started at the company.
5:02Chris RomeoAnd what is that What's that approval look like as far as, is it headcount? Is it budget? What's kind of being set up that you're going to be able to go execute on now?
5:16Devin RudnickiYes, exactly. So, it was both getting the headcount and the budget for the tools and consulting services to start up the program. So, it was really nice to have both of those things already secured when I started.
5:33Robert HurlbutOkay.
5:33Chris RomeoAnd so you were the first AppSec hire then? First person in the door?
5:37Devin RudnickiYes, I was the first application security director at the company. So that was nice to be able to just start from scratch. The company already had some AppSec practices in place, which was great to kind of have that first initial awareness around the company. But that really just gave me the free license to build.
5:57Chris RomeoYeah, that's such a fun experience to have that greenfield. I can do whatever I want within reason because it's a new playground almost. And, you know, sometimes people come into existing companies and there's a program and you have to try to fit your philosophy into it. In this case, you've got to set the philosophy for what the program is going to do.
6:18Devin RudnickiYeah, no, that was really nice. And so, actually, at the last company that I'd been at before I took on this role to build the application security program from scratch, I was managing the application security team, so I got to learn a lot of good practices about AppSec and be able to really take what worked and also what didn't work well, you know, to build— actually building the program on my own.
6:43Chris RomeoYeah, it's always— it seems like we learn so much from what doesn't work. In my career, when I look back, it's like when things are successful, yes, you learn something and everybody's excited, but when things just completely fall apart, You get a perspective. So the next time when you do it, you're like, I can tell you what we're not doing. We're not doing it this way because that caused me a lot of pain and it just didn't work and everybody hated it at the end of the day. So I'm always, I always love to hear what some of those challenges are, but we'll get into that as we get, we get a little further. So you got this, you know, you're AppSec director, you're in this, this new, new opportunity. You've got budget, you've got headcount allocated.
7:26Robert HurlbutYeah.
7:27Chris RomeoWhat's the first thing that you focus on with this program?
7:31Devin RudnickiSo the very first thing that I did, well, actually, there's 2 things really. First off, I built a roadmap that I could use to socialize my vision for the program and communicate with the key stakeholders what would be needed from them.
7:47Chris RomeoOkay.
7:47Devin RudnickiSo that's the second thing is really the collaboration piece. And that's really what I think made the AppSec program build-out so successful, it was taking the time to do a roadshow, essentially, with all the key stakeholders, showing them the roadmap for the program, and then explaining why it's so important and how it would actually benefit each of them.
8:09Chris RomeoSo, when you're building this roadmap, what's your guidebook? Like, what are you using to To know what to even put on that roadmap for somebody who's, you know, I always like to think we've got some people listening to this podcast that are going to be trying to do the same thing you're doing. And so that's why I'm always diving deeper because I'm like imagining somebody listening to this going, I could do what Devin did. Oh, Devin had a, she said roadmap. Oh yeah. This is what it looks like. So, so what, where, where did you go to source the pieces of that roadmap?
8:42Devin RudnickiSo to be honest, a lot of it did come from my prior experience, which I know for someone starting out, it might be difficult if you don't have that. But then I think it's also bringing it back to the people, process, and technology pieces, right? So thinking about what do you need from each of those 3 aspects to roll out the program. And then finally, I would say it's— you can find a lot of things by Googling. I'm fully guilty of that. I Google all the time. There's some really great resources out there and some great books. Tanya Janka's application security book was really helpful. for just knowing the key components of what you need for a program.
9:20Chris RomeoYeah. And then, on the collaboration side, what would you say, what would you tell somebody who's just getting started with this? And maybe they're a little nervous about, I don't really want to talk about, talk to executive leaders. They seem like they are so important inside the company. What would be your advice for that person, like, based on your experience? Like, what would you advise them? How would you advise them? What can they do to be successful in those conversations?
9:50Devin RudnickiYeah, so I think the biggest thing is really reading the room or knowing your audience, right? So do some background, figure out what the people do at the company, and what they think about what they might be most concerned with. And then be able to really tailor your conversation to meet not only your needs, obviously, but also their needs. And I think that's, that's the biggest thing, really. Okay.
10:17Chris RomeoSo, you're kind of, you're learning a little bit about the personalities then of the people that you're going to be interacting with and some of their background and trying to profile them a little bit as far as what to expect then, right? Just so you're, it just helps you to be prepared, I guess, as you're going into those conversations.
10:36Devin RudnickiYeah. Yeah. And I think the other thing too is, like I kind of mentioned before, putting together a little roadshow presentation. with your roadmap and then really rehearsing and practicing that and feeling confident in that is also a really key thing to making your message come across clearly and also, you know, really powerfully, right, to each of those.
10:58Chris RomeoSo how many slides are you putting in that roadshow presentation?
11:02Devin RudnickiI believe I had about 5 or 6. And so the first one was really talking about you need to set the scene, right? You know, what is application security? Why is it so important? I think I also then put in a slide with some statistics from the industry just about application security risk, just to explain why it's so important.
11:27Chris RomeoOkay.
11:27Devin RudnickiAnd then I think I went into the actual roadmap with a nice little PowerPoint slide with all the colorful bars and, you know, on a little timeline there. And then talked about the benefits of the program.
11:40Chris RomeoYes, I think that's an important tactical thing that we can take away right now just from where we are in the story, right? You really, you don't want to go into that conversation with 50 slides because that room doesn't have the attention span of 50 slides. They have the attention span of 5 to 6 slides. And some people might get mad at me for saying that. I don't care. It's the truth. I'm in that category a lot of times now. And like, if you come in with me for 50 slides, I'm gonna be like, I'm sorry, but I'm gonna play on my phone now 'cause I don't have an attention span for that. But 5 slides, 5 to 6 slides where you're, I can obviously see you've got a path, you can keep me engaged in the conversation. Like, I think that's gonna be, that's a key tactic that you use there was to just minimize. And then, so what did the conversation look like? Like, did, were people, was there a lot of, was there a lot of conversation from different leaders in the company kind of supporting you in what you were doing?
12:38Devin RudnickiYeah. Yes. Yes. So essentially the conversation would really look like introducing myself, learning about the other person or the other group, right? Because it's important for you to also get that kind of information for later use, right? And help you better understand about how you can potentially help that person in that group in the future. And then it would be getting into more of, here's the vision and the roadmap that I have for the program, you know, why it's so important How did you expand the application security program and tools to the firm? Yeah, so that's, that's a great question. So we actually came up with a standardized approach. We called it the Application Security Onboarding Program. And so that was really devising, working with all the technical teams to come up with a nice template for implementing the tools within our continuous integration, continuous deployment pipelines. as well as then also teaching people the processes right around application security. So while we roll out the tools, we need to also make sure that we have the processes in place to manage the tools and actually do something about the findings that are coming out of those tools.
13:58Chris RomeoSo when you, when you were assembling your, your tool suite, did you— was there any type of prioritization? you were using as far as what categories of tools were most important to get implemented first? Or did you just have the ability to say, we're going to put out a holistic suite of tools all at one time? What— how did that work out for you?
14:23Devin RudnickiYeah, great question. So we definitely focused on getting a static scanner in place first, along with dynamic scanning, just because those are the, you know, the core tenets, I think, of application security tools. And then later, we did expand the program to include software proper composition analysis scanning tool. Thank everyone, you know, coming out of Log4j that happened now, I guess, a few years ago almost at this point. Really, you know, really the keenness of having the SCA tools.
14:53Chris RomeoYeah. Okay. So when we, if we break the program, then as you're moving forward and you're continuing to work on the program, You know, we talked about how you had the roadmap that led to the roadshow, to the collaboration. You know, you focused on SAST and DAST initially and then got to SCA. I heard somebody refer to that as SCA recently. And I was like, when did we start saying SCA? Like, that doesn't— I think of SCA music, which is like, I don't know, I don't even know how to describe that. That's the only thing that comes to mind when someone says SCA.
15:34Devin RudnickiYeah.
15:36Chris RomeoSo, what are the, I guess, what are the kind of other categories then once you get past, in building out your program here, once you get past that initial buy-in from the executive leadership team, you've got some tools that are starting to come into play. If you had to kind of bucketize the other things that your program is doing, what are some of those other buckets look like?
16:02Devin RudnickiYeah. So, the other buckets would— well, the next one would definitely be the vulnerability management piece. So, I did have to come up with an entire proposal for that and really lay it out, not only for the technical people, right, but also the product teams and more on the business side of the house, as well as the Scrum Masters. They really had to understand the deep intricacies of all of the workflows within the ticketing system. And really, you know, to know what's expected of them when a new ticket for a vulnerability comes into their backlog, right? So, that's the vulnerability management piece. And then also developer education is another big piece and penetration testing.
16:43Chris RomeoOkay. So, just to unpack these in a little more depth, vulnerability management, is this something that in your philosophy of AppSec programs, is this something that you're pushing to the individual developers? Is it something that you've got staff on your team that are, that are managing that? Like, how does, how does your philosophy play out with the program?
17:09Devin RudnickiSo we really wanted to make sure that as much of the process was automated as possible. Okay, so we did actually invest in a tool to be able to automatically create, manage, and close the tickets based on the, the tool findings. Or sorry, the tool status of each of those findings. So that's really, really helpful. And then also, we had to really focus on making sure that, again, the Scrum Masters knew what was expected. So, you know, during their backlog planning, they need to be taking a look at all of the vulnerabilities that are appearing in that backlog, and then making sure that they're slotted for an upcoming sprint, you know, within accordance of our SLAs for vulnerabilities.
17:54Chris RomeoOkay. So, that's the vulnerability management side. How about developer education? Is this something that you put— did that become like an internal project? That's something that you had resources on your team focused on delivering that? Did you go outside to try to solve that problem? What were some of your strategies there for success?
18:16Devin RudnickiYeah. So, we did get the help of a tool. I think you're probably pretty familiar with that security journey tool.
18:24Chris RomeoI've heard of that one before.
18:26Devin RudnickiGreat, great, you know, great tool.
18:27Chris RomeoI did not know that in advance. I did not know that when I asked the question. No, but I'm glad to hear it. Yeah.
18:32Devin RudnickiYeah, that was really helpful because I think it's so key for developers to be able to not only get those chats essentially right, the video pieces, but then also the hands-on keyboard training. So that was really key. And we actually had developers do a proofs of concept with different programs and to tell us which ones they really liked the most. And Security Journey definitely won out.
18:58Chris RomeoNice. Glad to hear it. So, you mentioned developer education, vulnerability management. What was the third one?
19:07Devin RudnickiPenetration testing.
19:09Chris RomeoPenetration testing. How could I forget? Because I'm such an anti-pen testing person. That's why I couldn't forget. Not anti-pen testing. I think people pen test at the wrong time. They put too much effort onto it. But our audience has heard me rant about that far too too many times, so I'll save— they'll have to go back to a previous episode for that rant. But what's your— what's your philosophy about pen testing? How does that fit into your AppSec program? Once again, are you going outside? Do you have testers on the team? What do you see as the best practice here?
19:38Devin RudnickiTo me, I think it's really helpful to have both. Both have external as well as internal because that enables you to have a variety of individuals looking at the application right at different times. And I think you also have to then adjust your penetration testing program to what the business wants and needs and has the appetite for. Right. I think we've all probably seen on a million security questionnaires, do you annually penetration test your applications? Right. So I think we definitely have, you know, some requirements in those respects. But also it's about trying to get— make sure that you're actually really assessing the security risk of your, of your applications. Right.
20:23Chris RomeoIn the past, I would say no to that question, and then I would have to get on a call to talk about the answers, and the security team would be like, how can you not do pen testing? I'm like, well, we built an application that runs in a container that has a minimal number of— the attack surface is minimized to the bare bones of what it needs. We have a runtime application self-protection solution running inside of it, so we've got We're protected from the inside out and there's just nothing there from an interface perspective. We stripped it down. And they'd be like, oh, okay. So I'm like, you can pen test it if you want. There's really not much to find. It's because it's been minimized to the point on purpose. It's been designed in that way. And that gap got me around doing pen testing for a good period of time. But it was an architecture play. And yeah, it was.
21:17Devin RudnickiIt's—
21:18Chris Romeobut that's, you know, you can minimize. But yeah, I mean, pen testing does have its— it does. I mean, I'm not anti-pen testing. the way. I just think we focus on it too much as an industry, like too many university students. And the audience has heard me say this before, but I'll say it again. You ask a university student that's studying cybersecurity, like, what do you want to do when you graduate? Oh, I want to break stuff. I want to break into things. I want to do that. I'm like, you know, we have a lot more need for people to build secure things. Like if you learn how to build secure things, you will never be unemployed for the next 30 to 40 years. That's my prediction because think about all the people we know in the AppSec community. Nobody's out of work. I mean, like everybody's, most of the people are, they move from one company to the next to launch the next program. Like Devin, like what you did in your career, you go to a new place because you want to build something from scratch and see how you can attach all the pieces together and make it work. And so that's where, but yeah, I just want to see more people focus on building. securely as their, their life goal there.
22:21Devin RudnickiYeah, no, I think it's so important. And you're totally right. I see that a lot. A lot of individuals really want to move into red team or penetration testing just because it is very attractive right from the outset. I think that the whole concept just really appeals to people, and that's what a lot of people hear on the news. So that's something that they just are really interested in. But I totally agree that it's always going to be the defenders that we need. Yeah.
22:49Chris RomeoAnd then when you— people don't realize that the life of a pentester is not as glamorous as it sounds from the outside. There is a certain amount of grind that goes into being a good pentester. It's having the knowledge, it's having the skills, which, you know, my knowledge and skills in those areas have drifted away from me decades ago. But it was, it was also a grind sometimes because there are times where you're like, I just can't, there's just doesn't appear to be anything here, but I can't send a report that says your system was better than us at defending. And so you got to keep going, you got to find a way. And, you know, I grew up in the era when security was so bad that you could pen test something. And if you didn't find a way in within an hour or two, You were probably really shaking your head going, these folks are doing something right. Because in those days, there were so many Microsoft vulns and stuff that were exposed in external services, which led to the worm culture of, you know, the late '90s and early 2000s that Robert remembers that too, because he was around at the same time. He's from the same vintage as I was. But, you know, that worm culture, what I mean is Microsoft had vulnerabilities, people wrote worms for them, and they just went through and compromised machine after machine. And then—
24:09Devin RudnickiYeah.
24:10Chris RomeoOnce the machine was compromised, it would start looking for more machines to compromise. That was the state of security, which made pen testing a whole lot easier in those days. But now it is something that can be more of a grind. It can be a tough assignment because you got to find some way in. And some people are just more built for that. Like, I find I'm not. That's not my— that's not how I'm gifted in being able to focus and do that. I can— I mean, I used to do it when I had to, but it's not Not something that, that I find myself very good at anymore. But that's not why I have the opinion that I do, just by the way. All right, Robert, what else you got here for Devin?
24:49Robert HurlbutWell, let's talk about tracking the work. What metrics and KPIs did you use to track and show value? And also, how did executive leadership receive that value?
25:04Devin RudnickiGreat question. I think this is a really hot topic and always has been in security, right? How do you show the return on investment? I think that's a really difficult question, honestly, and I've seen a lot of other people grapple with it as well because it also goes back to the whole quantification of cyber risk, right? That whole, that whole debate. But for metrics and KPIs for the application security program, We did try to show the value as far as showing the vulnerability closure rates and showing the trends and vulnerabilities from quarter to quarter or month to month, depending on what level of reporting you were doing. And then we also had some metrics around our security training, developer training, and how many— what percentage of the developers are taking the training and that sort of thing.
25:56Chris RomeoOkay. And then what was the— how did other leaders receive that? Did they believe the metrics and did those metrics cause change? Did you get any pushback from the executive leadership team as far as how they received that data?
26:10Devin RudnickiYes, I think it's really interesting because I think that I really am a proponent of using kind of the scorecard method and trying to gamify things. in a sense. So, if you really show the different business leaders across the stack of what their teams' or products' vulnerabilities are, then I think that that can really help drive vulnerability remediation because they don't want to be the product that has all the vulnerabilities compared to the other products.
26:39Chris RomeoAnd so, do you recommend showing that type of a scorecard? Is that something that everybody in the company can see?
26:49Devin RudnickiThat's a good question. So we actually just really provided them to the different business leads and technical owners. We did not publish them on our company intranet page or anything like that. But I, you know, I wouldn't be opposed to that. I think that's a cool idea.
27:05Chris RomeoYeah, and I had a similar situation in my previous time at Cisco. We used that strategy of Metrics, pitting executives against each other using metrics as a driver, because nobody wants to be at the bottom of the leaderboard. And if they see themselves at the bottom of the leaderboard, they immediately call their operations director and say, why am I at the bottom of the leaderboard? I don't care what leaderboard it is. I'm not ever at the bottom of it. And then fix it. And then somebody would go and all of a sudden that team would start to rise up the leaderboard because there was that That perception that we're the worst out of all the people, and we didn't publish it like you'd like to your point, Devin. We didn't publish it. It's not something we published where everybody in the company was looking at it, but it was published at certain levels of leadership where the other leaders could see where they stacked against each other, and it did it did cause some positive change. So that was good. Um, so then CISO, so you. Let me just recap for our audience here. You come to this company, you start the AppSec program, you put all these things in place, you build out the team, and then recently you've become the CISO of the same— in the same organization? You've able— or is it a different company?
28:22Devin RudnickiYes, the same organization. Okay.
28:25Chris RomeoSo you're able to grow the program and then go and kind of continue to grow your career into the CISO chair. As a result of the success that you had driving the AppSec program through.
28:36Devin RudnickiYes. Yes. And I really think it all goes back to what I mentioned at the beginning of the podcast. It's all about the collaboration piece. So I think it's really about getting to know your stakeholders and understanding their needs and how can you best meet their needs and the business's needs. And that's, that's really the key.
28:55Chris RomeoSo how has your relationship with those other leaders changed now? Since you've kind of risen up to, from somebody who was kind of a level below them in the organizational structure to somebody who's now kind of in that, in the conversations with them, how has that changed the way you approach influencing them and your general security approach?
29:22Devin RudnickiYeah, so I've really just tried to take a lot of the things that I learned with building the application security program and all the collaboration there and just tried to drive that forward across the entire CISO organization, just to really help enable better transparency and collaboration amongst ourselves and our stakeholders.
29:42Chris RomeoOkay. Very cool. Well, Robert, I think we've reached that time of the lightning round. This is Robert's time to shine. This is his scene in, or act in the play called the Application Security Podcast. So, Robert, take it away.
30:02Robert HurlbutOkay, Devin, we have 3 questions that we typically ask in the lightning round. The first one is more of a controversial take. So, what's your most controversial opinion on application security, and why do you hold this view?
30:15Devin RudnickiI don't have one.
30:17Robert HurlbutThat's pretty controversial.
30:22Chris RomeoYes, the most controversial answer we've ever had. And so, that will cause conference talks to be written. Did you hear this interview? Devin said there was nothing controversial in AppSec. I will show the world that there is.
30:35Devin RudnickiMaybe not. Can't wait for those. Excellent.
30:39Robert HurlbutAll right, the next one is, uh, what would it say if you could display a single message on a billboard at the RSA or Black Hat conference?
30:47Devin RudnickiCollaboration is key.
30:50Robert HurlbutLove it.
30:52Chris RomeoOh, I like that. Yeah, that's cool.
30:53Robert HurlbutAnd, uh, the final one is, um, what's your top book recommendation and why do you find it valuable? And that could be any book, really.
31:03Devin RudnickiSo I'll actually just choose— there's too many books to count that I've read in my life. So I'll pick one from somewhat recently. I actually read the new biography of Elon Musk recently. And that book was so valuable to me. So being a risk management professional, right, in this role, and then comparing it to what— how Elon Musk thinks about business and thinks about risk-taking was just really eye-opening to me. And he's truly brilliant. I mean, it was awesome to just kind of get more insight into how he thinks about things and how he addresses issues. Not going to say all that's all good necessarily, but I just think that it was an excellent book and I would highly recommend reading it if you haven't already.
31:50Chris RomeoThat is a good one. I've read that one as well, and some of his management tactics Are just like the thing that caught me, a number of things in there of his tactics caught me. I thought the book was brilliant. Like the idea that you can just add up to 10% more stuff of like parts into something you build because we're going to end up needing to cut stuff anyway. And so, just over-engineer it and we'll cut it further down the process. That being a mindset of thinking, like nobody thinks like that. Nobody thinks about, I'm just going to throw extra stuff to make it to try to make the solution work and then we'll figure out how to slice other things out further down the road. Yeah, I love that. That was a great book. That's Walter Isaacson, right? The author of that who's also written— I mean, I find everything by Isaacson is just incredible. He did others that I read. The Steve Jobs biography is very good. And then he also did one recently. I can't remember the lady's name. Jennifer, the CRISPR lady.
32:56Devin RudnickiJennifer Doudna.
32:58Chris RomeoThe gene splicing therapy. We'll find it and put it in the shownotes. But, that was the story of gene splicing and how that all works. I'm not a biology person, so I don't have that depth. But, the way Isaacson explains these things, I could understand the biology behind it at a simple level of what they're doing and whatnot and the story behind how they're curing diseases with this CRISPR machine. It's just fascinating. But yeah, that's a good recommended reading section. And, thank thank you for pointing out that Isaacson book because that's one that I love as well. So, Devin, how about a key takeaway or a call to action? Do you want to give our audience homework? I don't know how, like I said before, I don't know how they'll turn it into you, but what do you want to leave our audience with here?
33:49Devin RudnickiYeah. So, I don't think I actually really talked about this enough in the beginning of the podcast or anything, But I really think that you should take the time to go and learn your organization's business. You really need to understand how your organization makes money, and you need to understand what can you do as a security leader to help enable that.
34:13Chris RomeoYeah, that's, that is really good advice because if you don't understand where the money's coming from, it's tough to make good decisions. And I find when I understand where the money's coming from, it changes my perspective on decisions because risk has to be filtered through the lens of how we make money. Well, if we just invest all of this money in this, if you invest all that money in that, we'll be out of business. So then this doesn't really matter, the whole conversation, right? It's like we can't spend all the money on the security controls because we need to make some profit because we're a company that sells things to— that's how we run a business, right? So yeah, that's really good. Good advice. Well, Devin, thank you so much for sharing your story here, and hopefully it inspires some folks that are out there with the opportunity to do what you did and build their own programs, or maybe they're refreshing a program. Hopefully they can take some of that wisdom and apply it. And also for those folks that have that desire to get to the CISO chair, this can inspire them as well that you can begin your journey in something that's not AppSec. Get into AppSec, build a program, and you can use that to grow your career throughout the organization as they watch you making stuff happen, which I know that's what you did because you didn't get to the CISO chair unless you were making stuff happen. So hopefully that'll inspire some folks out there that think that's a path for them. So thanks for sharing that story with us.
35:40Devin RudnickiNo, thank you so much for having me. And yes, everyone, please go out there and just Just do hard work, right? Communicate, collaborate, and you'll meet great success.
35:51Chris RomeoVery good.
6,167 words · transcript by assemblyai
More on Building an AppSec Program
View all episodes →- September 28, 2019 · 38 minRonnie Flathers — Security programs big and small
- September 24, 2021 · 54 minJames Ransome and Brook Schoenfield -- trust and verify: Building in Security at Agile Speed
- February 16, 2018 · 35 minPete Chestna -- SAST, DAST, and IAST. Oh My!