• Home

matthiasrohr's blog

Latest Articles

Is Shift Left Dead?

Posted on April 27, 2025May 10, 2025

What You Should Consider Before Choosing a New AppSec Tool

Posted on December 29, 2024January 4, 2025

Solving the AppSec Governance Disconnect

Posted on October 29, 2024October 31, 2024

Shift-Up Strategies for Elevating Product Security as a Management Priority

Posted on June 3, 2024June 13, 2024
Posted inSecure Software Development

Is Shift Left Dead?

Matthias Rohr Posted on April 27, 2025May 10, 2025
Recently, the term “Shift Left” has faced much criticism in the security community, with some suggesting “it’s time to stop shift left“, “shift left starts to rust”, or even calling it a “dirty word“. This raises an obvious question: does…
Posted inSecurity Test Automation

What You Should Consider Before Choosing a New AppSec Tool

Matthias Rohr Posted on December 29, 2024January 4, 2025
Tools play an important role in an effective AppSec strategy. However, tools alone can only…
Posted inGeneral, Secure Software Development

Solving the AppSec Governance Disconnect

Matthias Rohr Posted on October 29, 2024October 31, 2024
An often-seen anti-pattern in software architecture is the Ivory Tower Architect. It describes architects who…
Posted inSecure Software Development

Shift-Up Strategies for Elevating Product Security as a Management Priority

Matthias Rohr Posted on June 3, 2024June 13, 2024
Since “shift-left”, and also and “shift-right”, have increasingly been taken over as marketing terms, I…
Posted inSecure Software Development

A Guide to Organizational AppSec Functions

Matthias Rohr Posted on March 31, 2024April 3, 2024
With OWASP SAMM, BSIMM, and NIST SSDF, there have been excellent resources for some time…
Posted inSecure Software Development

Positive Security Culture in Software Development

Matthias Rohr Posted on January 2, 2024June 5, 2024
The significance of a positive security culture is more crucial than ever in times of the increasing complexity of business applications and threats. But what does this practically mean? Here are some indicators for a product-oriented development organization that I…
Posted inSecure Software Development, Security Test Automation

Implementing Smart Security Gates in Modern Software Development

Matthias Rohr Posted on November 24, 2023April 1, 2024
In modern software development, there is a strong emphasis on aspects like speed and productivity.…
Posted inSecure Software Development

Why Security Champions Are Not the Silver Bullet

Matthias Rohr Posted on September 13, 2023November 13, 2023
Security Champions have been a proven and popular security practice over the years. We’ve learned…
Posted inSecure Software Development

Secure Software Lifecycle Management (SSLM)

Matthias Rohr Posted on February 10, 2023June 4, 2024
The concept of integrating security into the software development process is not new. While I…
Posted inSecure Software Development

Shifting Security Left by Sharing Ownership & Responsibilities

Matthias Rohr Posted on January 30, 2023September 25, 2023
Many discussions on how to shift security left in the SDLC, or about implementing DevSecOps…

Posts pagination

1 2 3

My latest posts

  • Is Shift Left Dead?
    1 year ago

    Is Shift Left Dead?

  • What You Should Consider Before Choosing a New AppSec Tool
    2 years ago

    What You Should Consider Before Choosing a New AppSec Tool

  • Solving the AppSec Governance Disconnect
    2 years ago

    Solving the AppSec Governance Disconnect

  • Shift-Up Strategies for Elevating Product Security as a Management Priority
    2 years ago

    Shift-Up Strategies for Elevating Product Security as a Management Priority

matthiasrohr's blog

Seamless Theme René, made by Altervista

Create a website and earn with Altervista - Disclaimer - Report Abuse

  • Home