--- title: "Jahanzeb Farooq -- Launching and executing an AppSec program" url: https://appsecpodcast.com/jahanzeb-farooq-launching-and-executing-an-appsec-program/ date: 2024-07-02 duration_seconds: 2984 season: 11 episode: 16 guests: ["Jahanzeb Farooq"] topics: ["Threat Modeling", "Building an AppSec Program", "Security Testing", "Privacy and Compliance"] audio: https://www.buzzsprout.com/1730684/episodes/15340944-jahanzeb-farooq-launching-and-executing-an-appsec-program.mp3 video: https://www.youtube.com/watch?v=p8kOsgxgA-Q transcript: true --- # Jahanzeb Farooq -- Launching and executing an AppSec program *July 2, 2024 · 50 min · Season 11, episode 16* with [Jahanzeb Farooq](https://appsecpodcast.com/guests/jahanzeb-farooq/) on [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/), [Building an AppSec Program](https://appsecpodcast.com/topics/appsec-programs/), [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Privacy and Compliance](https://appsecpodcast.com/topics/privacy-and-compliance/) [Audio](https://www.buzzsprout.com/1730684/episodes/15340944-jahanzeb-farooq-launching-and-executing-an-appsec-program.mp3) · [Video](https://www.youtube.com/watch?v=p8kOsgxgA-Q) ## Show notes Jahanzeb Farooq discusses his journey in cybersecurity and the challenges of building AppSec programs from scratch. Jahanzeb shares his experience working in various industries, including Siemens, Novo Nordisk, and Danske Bank, highlighting the importance of understanding developer needs and implementing the right tools. The conversation covers the complexities of cybersecurity in the pharmaceutical and financial sectors, shedding light on regulatory requirements and the role of software in critical industries. Learn about prioritizing security education, threat modeling, and navigating digital transformation. Jan Zeb Farouk currently serves as the head of application security at Danske Bank, the largest bank in Denmark. Before this, he was with Novo Nordisk, where he played a key role in building their application security program from scratch and in securing their digital health solutions. Today's episode is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Jahanzeb Farooq: → [The Power of Habit by Charles Duhigg](https://www.charlesduhigg.com/the-power-of-habit) → [BSIMM](https://bsimm.com/) Mentioned in this episode: → [The Power of Habit by Charles Duhigg](https://www.charlesduhigg.com/the-power-of-habit) → [BSIMM](https://bsimm.com/) → [OWASP SAMM](https://owaspsamm.org/) Chapters: 00:00 Meet Jahanzeb Farooq: Launching and executing an AppSec program 01:57 You could have told me that you painted it. I would 07:12 From that perspective. So how do you get to AppSec then 09:08 AppSec 12:55 I have a question. I have a question about having never 15:57 There's no central, so like they don't share services or share 17:27 You're starting with these businesses that were non-IT. They made their 25:46 Do you, what are you, what's the equation you're using to 28:18 You mentioned maturity. Is that something that is based on, Are 29:20 A little question about some of the experiences that you've had 40:06 If I, if I kind of read that back to you 42:58 Yeah, I think a well-tuned SAST tool is a good assessment 45:29 Question 2, if you could display a single message on a 47:14 Yeah, I think really cool. We'll put a link to that ## Transcript *6,820 words · assemblyai* **0:00 Chris Romeo:** Jan Zeb Farouk currently serves as the head of application security at Danske Bank, the largest bank in Denmark. Before this, he was with Novo Nordisk, where he played a key role in building their application security program from scratch and in securing their digital health solutions. Prior to this, he was at Siemens, where he was responsible for the IT security architecture of major railway projects in Denmark and Norway. Jan Zeb holds a PhD in computer and information sciences from the Technical University of Denmark. a master's degree in computing science from Umeå University in Sweden, and advanced leadership training from Harvard Business School. Janza joins us to discuss prioritizing AppSec activities within a program, major milestones, and commonalities between pharma and finance in building AppSec programs. We wrap up with the biggest challenges in executing an AppSec program. **0:50 Robert Hurlbut:** Today's episode is brought to you by Security Journey. Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10. Learn more at securityjourney.com. **1:04 Chris Romeo:** Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the CEO of DaVinci, also a general partner at Curve Ventures. And also joined by my good friend Robert, who's been my co-host of the AppSec Podcast since the very first episode about 100 years ago. **1:35 Robert Hurlbut:** Seems like it, right? Hey, Chris. Yeah, Robert Hurlbut. I am a Principal Application Security Architect and Threat Modeling Lead at Acquia, and excited to be here again for a great new podcast. **1:48 Chris Romeo:** Yeah, and you got some new artwork behind you too, for those on the video feed. **1:52 Robert Hurlbut:** I do. I'm traveling and this is not mine, but it's not bad though. **1:57 Chris Romeo:** You could have told me that you painted it. I would have been like, wow, look at that. It's pretty cool. So we're joined today by Jahanzeb Farooq. And as always, we start with security origin stories. So Jahanzeb, we're just going to jump right in. We want to hear your security origin story. How'd you get into security? Yes. **2:18 Jahanzeb Farooq:** Thank you. Thank you for inviting. And it's a pleasure to be on this podcast. So yeah, my security journey. So, well, that was about, I don't know, about 3 years ago when I was working for Siemens and we were developing train control systems. **2:37 Robert Hurlbut:** Siemens. **2:38 Jahanzeb Farooq:** Siemens is a huge organization and they do everything. So I was in the Mobility Division of Siemens where they were working on train control systems and the early control. railway signaling systems. So my team, we were working on a system that operates on the train and then connects the train to the base site. So base site is the whatever temporary kitchen infrastructure you have on the base site. So these are called, these modern train control systems, they're called, for example, CBTC, This is one of the most common train control systems. CBTC stands for Communication Based Train Control. So basically you have a computer basically running inside the train, which is connecting the train using wireless communication technology. In the case of CBTC, it is just plain simple Wi-Fi actually. So yeah, so you have access points on the track side every like 500 meters or something. And then when the train is moving, it's connecting to these access points and connecting and then communicating or transmitting its location and speed and everything. And then from the way side, there is a train control center who is then sending the information back about, okay, what— What's the speed? speed to travel and where to stop and all this, right? So we're working on that. And then we thought, okay, is our software secure? Is our system secure, right? So what if there's a malicious actor who could, I don't know, try to interfere or try to listen to our communication or try to— Yeah. Change the communication in some way. So maybe what if the malicious actor made some changes to change the train speed, right? What happens in that case? So that's like a very typical scenario. So basically it's a train, it's passengers, it's human life. So for the security should be at the highest level, right? So that's how I got interested in cybersecurity. And yeah, that's what you can say. And then of course, then we, I went on to, we had a research project where we wanted to improve the network design at the base layer. Right. So anyway, so I was working on that research project and completed my PhD also during that time. And then when I was done in the research project, I also saw my manager, my then managers, when they asked me, okay, so we have this role of cybersecurity, IT security officer, person who would be responsible for the overall security of the the train control system, of course, including the software and the hardware of the train, but also the infrastructure, M&E, patching, and incident response. So I said, yes, cybersecurity was one of the new fields and very much in demand. So I said, yes, definitely. So that's my What do you think, Dave? **6:21 Chris Romeo:** Yeah, that's pretty cool. The whole train, like I didn't have that perspective on how much data was being shared back and forth off a control system for trains and access points every 500 meters or whatever. That's definitely the stakes are high when you're dealing with something like that. When, so I enjoyed your Very quick threat model of the train systems. That's the, but that's, you know, this is when you start thinking about power grid, transportation, all these types of things. It's just a whole different realm. It's not a web app where a SQL injection results in a data breach. And, uh, yes, that's terrible. Data breach is terrible, but there's no human lives in danger. When you're talking about a transportation thing, like stakes are so much higher. **7:11 Jahanzeb Farooq:** Yeah. **7:12 Chris Romeo:** From that perspective. So how do you get to AppSec then from becoming kind of a cyber— focusing on probably like being a security engineer ultimately, right, for the train solutions and whatnot? How do you then make the jump to AppSec? **7:27 Jahanzeb Farooq:** Yeah, so there was some AppSec involved also at Siemens during my role there, but it was of course the It was only a small portion of the overall value chain. But then I, after a couple of years, I moved to my next role at Novo Nordisk. I don't know if you know Novo Nordisk, but it's one of the largest pharmaceutical companies in the world based on the market cap, actually. So, Novo Nordisk is the market leader when it comes to diabetes medication care. So, and at Novo Nordisk, an AppSec program was just in the process of being launched when I joined. Actually, it was like in the process, will be in the stage of like being discussed. It was not even called an AppSec at that time. So yeah, so that's how I got involved in that. So we more or less built the program from scratch there. Actually, it's funny because at that time, AppSec was not as much in like a familiar word. It was, I think, 4 years ago I was learning, 4 and a half years ago. So actually, we were like, at some point, initially, we were like, okay, what should we call it? Secure software development, or DevSecOps, or what? **9:07 Chris Romeo:** AppSec? **9:08 Jahanzeb Farooq:** Then we Googled, and AppSec had more hits. So we said, okay, we are going to pick AppNations. So, it's just a funny recollection. So, yeah, so that's how I got involved in AppSec. **9:21 Chris Romeo:** And so that kind of sets the stage then for the conversation we're about to jump into about AppSec programs then. So you're not just somebody who has theories about AppSec, you've been in the trenches and you've created AppSec programs. And so now we're able to tap into your, I guess, your reflections on what you've seen be successful and challenging. **9:49 Jahanzeb Farooq:** Yes, of course. So, of course, there are, I mean, lots of challenges in building an AppSec program from scratch, but maybe I can just discuss a few, like the most notable challenges, at least in my world. So I would say the very first challenge that I faced or we faced was to find out our stakeholders, right? Or find out or to understand the audience. Who needs help? Who are we going to help? And why I'm saying this is because all these 3 companies that I mentioned, of course, I'm now with Danske Bank, which is the largest bank in Denmark and one of the, I think, 25 largest banks in Europe. So, all in all, all these 3 companies or 3 organizations, they are not software-focused organizations, right? So, software is a, how should I say, a supporting function or something like that, right? So, the first challenge was to find out actually who needs what, who needs our help, and who these developers are, where they are located in the organization, what is the level of awareness when it comes to security, what kind of level, what kind of education they have in security, how savvy they are in security, right? And given that, as I said, again, these are not smaller organizations, these are huge organizations. Developers could be very much, how should I say, geographically located in different locations, right? And they have varying level of familiarity with security, right? There are developers who are like self-taught developers, like so-called citizen developers, right? Who didn't start their career as developers, but then they moved to developer afterwards. So there are those. There are also all those developers who are writing scripts, I don't know, in Python or R, just collect data and process data. Then there are developers who are developing apps. There are developers who are developing web-based applications. So it's Yeah. And then of course, teams working in silos. So, I mean, there's no like one place where I can go and find, okay, how many developers we have in different locations and where they are located and what kind of education they have and all. So, I think the first challenge is to actually find these people and then of course, find them and then find out how to access them and how to reach out to them, right? **12:53 Chris Romeo:** Yeah. **12:53 Jahanzeb Farooq:** So, and then of course— **12:55 Chris Romeo:** I have a question. I have a question about having never been a part of organizations like that. I've only worked in tech companies where software is kind of the forefront of what we do. So this is something that I haven't really thought about before. And so I'm just curious, where does— so is software development in these types of organizations just distributed around the business? Every time you turn a corner, there's somebody building. So, there's no— so, IT doesn't centrally manage/control internal app development, or— I'd love to learn, just to learn a little bit more about how those organizations function when you have software sprinkled everywhere. **13:37 Jahanzeb Farooq:** Exactly, yeah. So, like, on paper, yes, there is a central IT organization, but then you always have some shadow IT here and there, right? And also, I mean, now I'm talking about 3 different product organizations. So it was different, right? In one organization, all the developers were like part of the IT organization, but in the other organization, they were like scattered all over the place. For example, Novo Nordisk, right? Novo Nordisk is a pharmaceutical company. So it's actually a company who makes or who As I said, they are the world leader in insulin, right, and selling diabetes care, right? So, it's only recently that they started to focus on software development, right? And that was, for example, as a result of digital transformation, for example, where all sort of processes should be automated. For example, they got interested in digital health solutions. They got interested in making, developing apps that could communicate with their medical devices, right? So, this is how, I mean, they like gradually from being an organization who was just producing insulin and selling insulin, they like transformed themselves into like a big— **15:11 Robert Hurlbut:** Yeah. **15:11 Jahanzeb Farooq:** a more tech-friendly, more IT-friendly company. And that also means that, okay, there is this new line of business, there is this new department, and then they want to develop their software for whatever reason, for whatever functions this department is performing. So, okay, they hire a bunch of developers and then there is software development going on there, right? So that's how it's like, okay, Oh, and then as I said, it's like, it could be people who are like just writing some Power Apps, right? Or low-code, no-code software, right? It could be, as I said, citizen developers who are self-taught and they're writing some scripts, but still it is a piece of software, it is a piece of code. **15:56 Chris Romeo:** So there's no central, so like they don't share services or share, Because I'm thinking about like centralized services in a modern engineering team, you have shared services models where we don't want everybody to build authorization, for example, or authentication. Everybody should tap into the standard that we use. So in that, in the environments that you've been in, is, are developers just figuring it out on their own for all of the things we would expect? No. **16:30 Jahanzeb Farooq:** No, I won't say that. I mean, it's because, I mean, because the pace, the pace with which these organizations, they are like growing or they are like transforming themselves digitally, that, I mean, the pace is so fast that all these processes, they cannot meet that pace. I don't know if it makes sense. So, it's at least a natural It's natural to, I mean, to have this slight lag in this process where, okay, yeah, there is a lag process here and there. Okay, then you have some freedom to introduce your own process. So, at least this is my understanding. But of course, eventually, I mean, the final goal for any organization would be to centralize the IT solutions. There is no doubt about that. **17:22 Chris Romeo:** So it's part of the, part of the maturity process then. **17:25 Jahanzeb Farooq:** Part of the maturity process. **17:27 Chris Romeo:** You're starting with these businesses that were non-IT. They made their, their fortune building something in the real world, but going through digital transformation. So phase 1 of maturity is pockets of developers sprinkled all over the place doing their own thing. And then there must be additional phases. Over some number of years where business people start to look at this and say, this doesn't make sense. We've got people everywhere doing everything. We need to bring them together into an engineering team. Now, did you ever see that happen? It doesn't matter which particular company, just in general. Did you ever see a consolidation, an engineering consolidation where they started to funnel all the people together into one shared organization? **18:12 Jahanzeb Farooq:** I've seen that. Yes, I've seen that different places. Of course, I think maybe a good example for this, Siemens, who my previous employer, who is also, they are a fusion. They are in different lines of business. As I said, I was working for mobility, but they also have, I don't know, you know, they make, they also make home appliances, they make security system. I don't know. Wherever you look, I think you find something made by Siemens. So, be it smart homes, smart cities, infrastructure, whatnot. So, the challenge that I mentioned in the context of no notice, that is also very much true in the case of Siemens. But of course, then they were trying to as you said, like, under all these, like, these activities in, like, under one umbrella, right? But I think given the size of these organizations, I think it takes some time to achieve that, I would say. **19:23 Chris Romeo:** Yeah, it makes sense. So yeah, I didn't mean to derail the challenges conversation, but I'm learning about big companies. **19:31 Jahanzeb Farooq:** Yes, yes, definitely. So, um, yes, back to the challenges. Yeah, uh, and yeah, as I was talking about, like, a level different level of awareness when it comes to security. So, I mean, I could easily find some developers who are like, oh, security or application security. Yes, we are doing security. We have risk firewalls, we have antivirus, right? So, they have very little idea what application security is, right? But then there's also In the same organization, developers who are very security savvy are very familiar with the technology, and they're maybe already using SCA tool or already, I don't know, a severe version of a SAST tool or something like that, or they're doing threat modeling and all that. So, then you have to come up with a, with the, governance and compliance for this large set of developers who are very different at— who are at very different levels, right? We have to come up with, like, guidelines and, like, a, I don't know, a secure development policy or SOP, but we have to keep in mind that it's like, okay, The level is very different from one team to the other team, right? And their challenges are different. So, that's why I think once you've found the developers, once you know who your target audience is, who these developers are, then I think the next question is to find out what sort of help they need. What is the current state of their security practices, right? So there you find already, are they using auditing? Are they following end security? Are they— do they know OWASP, for example? Do they have an AppSec tool? Do they do checkboarding? Or do they have some sort of like a direct rectification? You find that out. And then, I mean, once all this is in place, then you develop your roadmap. You like to have this and this and this, right? And then one of the Of course, one of the other, like, biggest challenges is to find out the priority or decide the priority, right? Because of course, there is always a limitation on the budget, on the security budget you have, but there is a large set of different tools and solutions that you can bring on board, right? So, Talk about these absent tools like the SAS, DAS, VS, or SCE tools. There are there is a bunch, right? And of course, then you need to you need to like decide what is the most important given the budget I have. What is the most important tool that should be brought first, right? And of course, it has become like a checklist, right? Of organizations, they look at each other, they see these, the PCM and the OpenSAM, and they see all these benchmarks and say, okay, okay, our peer banks have this tool in place, we should also have it as fast and as dense as they, right? But I think it depends very much on the attribution level of the developers. If they are If they are already educated in security, they have the basic knowledge, maybe they, I mean, maybe you don't need a SAST tool immediately, right? SAST tool is like, in my world, SAST tool is to find like basic, like low-hanging fruit, basic vulnerabilities in your code, right? And if you're not already using it, I mean, it could be an obstacle actually, because I mean, then— Yeah. Your developers, they are like, okay, oh, they're having false positives. So then they have to be educated on understanding these vulnerabilities found by these tools and then how to fix those vulnerabilities. So just getting a tool doesn't solve all the problems. I heard somewhere someone said that a tool cannot change an organization. So it's like, It's the culture, right? We should be targeting. It's not the tool. So, yeah. So, I think this other challenge is, I would say the second biggest challenge in my mind is to prioritize, come up with a priority. For example, is it worth investing in threat modeling, in a threat modeling tool? or a SaaS tool, for example, right? Or maybe a pentest tool or a bug bounty tool. So, this whole discussion, okay, what is the most important? So, yeah. And of course, then another challenge is to actually, just like finding your audience, finding the developers, there's other challenges, okay? Do we have a software asset inventory? Do we have an overview of what software we actually have in-house and what software we are like third-party software we are using? So yeah, so a number of challenges, of course. You also have your developer education program. I mean, do you want to maybe Invest in developing your developers first before like bringing in a SaaS or a PaaS tool, which, as I said, quite expensive, right? So do you want to invest in a secure developer training, security training platform, like, I don't know, SecurityJourney or Skill Provider, et cetera? **25:41 Chris Romeo:** Yeah. **25:42 Jahanzeb Farooq:** So this is my experience. **25:46 Chris Romeo:** How do you, what are you, what's the equation you're using to figure out these prior, this priority? Like, what are you, what are you looking at as input that others could potentially replicate in their, when they're starting a program? Like, are you looking at, you mentioned kind of what, if there's existing tools that are already in place and we talked about kind of inventorying, you just said asset inventory for the applications, but also kind of inventorying the developer populations. But like, what, like, how do you take that information and then make a decision about what you're going to do? **26:22 Jahanzeb Farooq:** That's a great question. So I would, I would, of course, first collect information about the current state of security, as I said before, and then based on that, I will make an assessment or about the maturity level of the organization, right? So depending on the maturity level, then I will decide, okay, we should have this and this in place. Maybe security education platform, maybe that should not be the highest priority. But if, I mean, if for example, like I see that the the developers in general are not well trained in security, right? Then maybe taking a SAST tool or an SCA tool should be the first priority, right? So that at least these tools could catch the, like, the low-hanging fruits, the basic vulnerabilities. So, and then it will also depend on the criticality or the, yeah, the utility of the application we are developing, right? So, of course, there are like, you know, also in a bank, for example, or maybe, okay, yeah, in a bank, you have all these applications, or for example, for investing, you have applications, software applications, you have like an app where you can, of course, go into your bank account and make transfers and all that. So, there are basically like quite a large number of applications, right? But some of them are like public-facing, others are like internal. So, the criticality, of course, is different from application to application. So, the 10-block also have to think about that. **28:17 Chris Romeo:** You mentioned maturity. Is that something that is based on, Are you measuring maturity based on your own experience? Are you using something like OWASP SAM or BSIMM or something else? Like, what's your, what's your guidebook, I guess, for maturity? **28:37 Jahanzeb Farooq:** Yeah, I will. Yes, I will. I will go through OpenSAM and BSIMM, basically these, all these benchmark studies to see, okay, what other organizations in the same sector, what do they have, they have in place and what is our security maturity. But of course, then I can also get some, one of these like big consultancy firms, right, to perform an assessment on us and let us know, okay, where we are on this maturity scale. I think that's very typical. And then, okay, this is one tool to find out your maturity level. So there are multiple ways, there are different ways to— **29:19 Robert Hurlbut:** So, a little question about some of the experiences that you've had, but what are some commonalities and differences in AppSec programs between pharma and financial sectors? **29:35 Jahanzeb Farooq:** Oh, yeah, yeah. I have had very interesting experience in pharma, and also now I'm in financial sector. So pharma, so it gets interesting when there is a medical device involved, right? Or maybe I should not put it like this. Okay, so pharmaceutical companies these days, they are like getting into making these digital health solutions. Like, so this could be like a harmless app that tells you your, I don't know, your, in case of non-smoking, your insulin level, glucose level, right? So, simple one, or an app that tells you, okay, cycling log, where you, it keeps a log of when you took at least your, what is it called, diabetes drug, right? So, these are like harmless, but then there are also apps that are like, there are also software that are like medical devices in themselves because they can They can they're like they can work without actually working with a medical device. So they like they can act medical device themselves. It's a bit hard to define, but anyway, so this is this is called software as a medical device, SMD we call it for short, right? So and there things become interesting. So okay, just to again rephrase. Okay, so then like there could be like three different type of software. When it comes to medical devices, right? There is software which is in the medical device. We call it like software in the medical device, right? So there is software which is not in the medical device, but which is like working together with the medical device, right? That is called software as a medical device, right? And then there is software which is used to manufacture or produce medical devices, right? That's the third category. So I work closely with the Software as a Medical Device category. This is a new world. There is a, like a sea of different standards, different regulations, different guidances, technical reports in that domain, which define everything from How you perform risk management on these type of software, how you design these software, how you make them safe and how you make them secure. So in the US, of course, you know, there is FDA. FDA is the, I can say, they are like the, how should I put it, They have to ask for on when it comes to because of course for any medical device software as a medical device, they have to get approval from FDA because before it could be placed in the market, right? So in the in in in Europe, we have equivalent authorities. Then we have something called Medical Device Coordination Group, MDCC. We have medical device regulation. So there is a number of different authorities or regulatory bodies who decide, okay, what should be, how we make a software as a medical device, how we make them secure. And there are, if I go back to standards, there is a bunch of very well-known standards. For example, these organizations have to have actually a quality management system, right? Which defines, okay, You do risk planning, you then perform threat modeling, then you look at the impact of a threat or of an attack. You look at the likelihood, then you define your risk control measures. There is a whole process of how you perform from defining requirements and perform threat modeling. Doing your security analysis and then defining your controls and all of that, right? And these, as I said, they have to have a quality management system. And there is a standard on quality management systems called ISO 13485. These quality QMS systems, they are based on this standard normally. Then there's a standard, for example, 14971 ISO, which defines how we perform risk management when it comes to medical devices. We have another standard called IEC 62304, which defines how we use software for medical devices. So then, of course, FDA, as I mentioned, they have their pre-market and post-market guidances. There is a UL 2900 standard, which also defines how you make your software-related devices secure. So, so there is a, there's, as I said, there's a sea of different regulations and all that. And then of course, over the time, these authorities like FDA, they have become more and more, I would say, they have come up with more and more stringent requirements when it comes to security. So they were like, back in the old days, of course, they were a bit lenient when it came to security. But with their new updated guidelines, now they're focusing on threat modeling. They're like making it mandatory. They are emphasizing to have an SBOM, software bill of materials. They are, of course, they would like to have an independent penetration test report, right? **35:39 Robert Hurlbut:** Yeah. **35:39 Jahanzeb Farooq:** So they are going quite, become quite stringent when it comes to security. And then of course, then they also audit you. Once you have had your device in the, or your software embedded device in the market, they come and audit you, they look at your processes and yeah. And if you have any deficiencies, then you get— **36:06 Chris Romeo:** Yeah. **36:06 Jahanzeb Farooq:** Finding that you have to your device would be or your software as medical device would be removed from the from the market. So it's a yeah, it's a quite different yeah the way this pharmaceutical market works. And then when it comes to banking, as I said, banking or financial sector is very much. Very much, how should I say, driven by regulations, right? So, for example, I don't know if you have heard about NIS2 and RoRA, but anyway, so these are 2 major, I would say, pieces of European cybersecurity legislation. NIS2 stands for Network and Information Systems, And then there is DORA. DORA stands for Digital Operational Resilience Act, right? So both these regulations or these legislations, they target like, the idea is that they target different industries. NIST 2 is like more for infrastructure companies that have infrastructure. DORA is more for the financial sector. But anyway, both emphasize or both have requirements about software. So for example, DORA, they require you to have code reviews, code analysis tools. They require you to have vulnerability testing, vulnerability management, penetration testing, of course, end-to-end testing, dynamic testing. So there is a— and this is a new regulation actually. It comes into effect now. In other words, Financial sector will have to comply to this regulation by January next year, actually 2025. So financial sector is right now working very hard on putting this in place or putting the implementation of this regulation in place. So likewise in Europe, there is something called TIBOR. TIBER, which stands for Threat Intelligence Based Ethical Red Teaming. Quite a mouthful. But so this is defined by, this is like a European framework developed by the European Central Bank, right? And the idea is that with this, the authorities, the financial sector, they come together and basically work together to improve the cybersecurity of financial sector. So there are like a full framework where there is a blue team, blue team, there is of course there's a red team, there's a white team, there is a type of all cyber team. So there's like 5, 6 different parties, they come together to perform these tests and it has to be performed by all banks. So it's actually, it's a penetration test by both parties followed by But by the— but performed by— with the help of the Central European Central Bank. And then also, also notable to mention recently, or actually is actually ongoing right now, something called a cyber stress test, again initiated by one of the central banks where I think right now it's like 110 European banks are participating in this cyber stress test. So the idea is to basically Assess, make an assessment how prepared the financial sectors is in the event of a cyberattack, right? How they can prevent it, how they can recover from it, how they can learn from it. So it's called cyber stress test. And this is something that's ongoing right now. **40:05 Robert Hurlbut:** Yeah. **40:05 Chris Romeo:** So if I, if I kind of read that back to you, then basically there's a lot of commonalities, it seems, with like regulations and standards and things that when I think about what I've experienced in the world of tech companies, yeah, there's some of that, but it's behind the scenes. There's usually departments that deal with those regulations. They're not my problem as a developer building a product. I have other people who run things through processes and run and comply with standards and all that type of stuff where, based on the descriptions here, pharma and financial, those regulations are the center of what everybody does and you, you don't operate outside of those. Everybody embraces them as a part of, of dealing with them. Is that a fair assessment? **40:53 Jahanzeb Farooq:** Yes. Yes, exactly. Very, very fair assessment. So, I mean, These sectors, financial sector and pharma sector, they are like, I would say, they're, I mean, compared to the tech industry, right? They are relatively new to IT and software and all that. But the services they provide or the products they make are so critical that, I mean, that they have to think why we input frame, number of regulations, right? So that's, yeah. And these regulations at the time, they have started to include also requirements on software development, I mean, which was not the case previously. So this is something relatively new, I would say. Yeah, yeah. **41:44 Chris Romeo:** So I wanna talk about tools, 'cause I know we've already mentioned a few different tools in the conversation. But my favorite question to ask folks such as yourself is, what's the first tool that you're looking? I know you said you do some analysis, you do some prioritization, you're assessing, but let's just say we didn't, you didn't do that. Put that off to the side. If you just went in and started a new program, in your opinion, where's the biggest value add from a technology platform? **42:18 Jahanzeb Farooq:** I would say code reviews, right? So, I mean, in old days, of course, we used to have code reviews, like manual reviews. And now, what is the equivalent of code reviews? SAST, right? So, I will, if I don't have an assessment, if I don't have like a good overview of the software development footprint in the organization, and as I said, all these in his stats, I would go for a SAST tool, which is basically a tool, an automated way of reviewing your code for security weaknesses. **42:57 Chris Romeo:** So, yeah, I think a well-tuned SAST tool is a good assessment platform for looking across an organization and trying to determine How good are each individual product from a security privacy perspective? I can see using SaaS to do that, to accomplish that. It makes sense to get that, some level of metrics. At least you've got some data. You're not just, it's not just a feeling. Well, I feel like that product over there is not very secure. That doesn't really get you anywhere in the boardroom where they're like, wait, you feel something? **43:34 Jahanzeb Farooq:** What are you talking about? **43:34 Chris Romeo:** What do the metrics show you? What's the data? What's the story the data tells you? Because data doesn't lie. At least I don't think it lies. **43:41 Jahanzeb Farooq:** Exactly. **43:44 Chris Romeo:** Well, that's helpful to think about that from kind of a tooling perspective. So we've reached that point in the show that we have now referred to as Robert's Lightning Round. **43:58 Robert Hurlbut:** All right, we've got 3 questions. First one is, what's your most controversial opinion on application security, and why do you hold this view? **44:08 Jahanzeb Farooq:** Yeah, so it's funny because my most controversial opinion would be actually opposite of what I just said about the tool, right? So, I mean, as I said before, no tool can change an organization, right? So, I mean, before going for the tool, try to like make a positive change to the culture of organization, right? So, I mean, yeah, I remember this quote from Top Gun. It goes like this, it's not the plane, it's the pilot, right? So, it's like, it's not the tool, it's the developer. So, I like that. So yeah, so, um, what's your opinion? Uh, maybe consider other controls before going for it to involve expensive. **45:09 Chris Romeo:** So, it sounds like there's a t-shirt to be had in there somewhere with Tom Cruise's picture, the jet in the background, and then your little security saying here about, it's not, it's not about, it's not the tool. It's not about the tool. It's about the developer. I could see that on a t-shirt or a sticker somewhere. **45:25 Jahanzeb Farooq:** So. Definitely. All right. **45:28 Robert Hurlbut:** And question 2, if you could display a single message on a billboard at the RSA or Black Hat conference, what would it say? **45:35 Jahanzeb Farooq:** Back to the t-shirt quote I just told. **45:41 Robert Hurlbut:** I was thinking you already got the next one. **45:43 Jahanzeb Farooq:** Exactly. All right. **45:47 Robert Hurlbut:** And then the 3rd one, what's your top book recommendation and why do you find it value? **45:54 Jahanzeb Farooq:** Oh, okay. Yeah, I mostly listen to podcasts and I mean shows. I mean, it's been a couple of years since I've last read a book, but I think the last one, the last good book, last book that I could recommend was this, the book on habits, not Atomic Habits, but another book called like, yeah, Power of Habit. Power of Habit by Charles something. Yeah, I forgot the full name. Oh yeah, Charles Duhigg. I can recommend that book. It basically discusses how habits can Shape Your Life, how you can basically create habits. It talks about like systematic approach. There is a cue, there is a like reward, there is a craving. Like these 3 elements in this framework, whatever you call it. And then how you can change this craving, you can like manipulate craving or cue to like change habits or create new habits. So I like, I like that idea. So I will. **47:13 Chris Romeo:** Yeah, I think really cool. We'll put a link to that in the show notes so people can find that book. And Jens, I would love to get a key takeaway from you, or perhaps a call to action. Is there something you want to send our audience off to do as a result of our conversation, or do you just want to provide a concluding thought? **47:38 Robert Hurlbut:** Okay. **47:38 Jahanzeb Farooq:** I think, I mean, concluding thought for me, as I said, I mean, I've worked in different sectors in the industry, so, and be it trains or pharmaceuticals or financial sector, I mean, I think our end goal should be to make our software, whatever we develop, secure, right? **48:02 Chris Romeo:** Yeah. **48:02 Jahanzeb Farooq:** So, sometimes it is a matter of patient safety or risk to life. Other times, it's someone can lose their fortune, right? If it's around the banking app. Other times, it would be a train accident or something like that. So, but I mean, all these systems or all these businesses, they have software and of course, and which makes it very critical that when we develop software, we think, okay, who is the target audience and how a security issue in the software would affect the target audience or what kind of an impact it can have. So that would be my— yeah. **48:50 Robert Hurlbut:** I think it's— **48:52 Chris Romeo:** yeah, no, it's good. It makes sense. It's a good way to conclude the conversation. So Thank you, Jahan Zeb, for being a part of the Apps to Location Security podcast with us and for sharing your expertise in building programs and providing that perspective on other verticals where security is happening. And I know I learned a lot about just those, those, some of those industries I've never played in. Like, I've never really understood why they had the challenges that they do. And it's, it was just good to hear. how digital transformation is moving things forward, but it's also, they've got some growing to do to get to the point where they're at the same level as like a tech company would be. So folks, thanks for listening to this episode of the Application Security Podcast and tune in, I don't know, in the future, listen again. **49:39 Jahanzeb Farooq:** Thank you very much. Love doing it. --- Source: https://appsecpodcast.com/jahanzeb-farooq-launching-and-executing-an-appsec-program/