Edwin Kwan

AppSec Unlocked

AppSec Unlocked is your key to understanding the complex world of application security. Whether you're a seasoned security professional, a curious developer, or somewhere in between, join us as we demystifies application security one episode at a time.

Author

Edwin Kwan

Category

Technology

Podcast website

appsecUnlocked.substack.com

Latest episode

Jun 23, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android almost 10M downloads · 4.8 rating iOS soon

Episodes

S2E12 -The Future of Security Training 23.06.2025

Season 2: Training & Awareness Episode 12: The Future of Security Training We're at the season finale on the theme of Training & Awareness. We're going to finish off the season by looking ahead to the future of security training and awareness. Over the past eleven episodes, we've covered everything from Security Champions to cloud security. Now it's time to explore what&#39...

S2E11 - Security Training for Remote Teams 09.06.2025

Season 2: Training & Awareness Episode 11: Security Training for Remote Teams In this episode, we're looking at a challenge that's become increasingly critical: security training for remote teams. We'll explore how to build and maintain a strong security culture when your team is distributed across different locations, time zones, and even continents.

S2E10 - Cloud Security Awareness 26.05.2025

Season 2: Training & Awareness Episode 10: Cloud Security Awareness In this episode, we'll be talking about cloud security awareness and exploring why traditional security thinking falls apart in the cloud, and how to build a new security mindset for the cloud era.

S2E9 - Secure Development Lifecycle Training 12.05.2025

Season 2: Training & Awareness Episode 9: Secure Development Lifecycle Training In this episode, we’ll look into Secure Development Lifecycle training, or SDL. We're going to explore how to build security into every phase of your development process—from initial planning through deployment and beyond.

S2E8 - The Human Factor - Social Engineering Defense 28.04.2025

Season 2: Training & Awareness Episode 8: The Human Factor - Social Engineering Defense In this episode, we'll be diving deep into what many consider the most persistent security threat: social engineering. We'll explore why humans are often called the weakest link in security – and more importantly, what we can do about it.

S2E7 - Crisis Response Training: Preparing for the Inevitable 14.04.2025

Season 2: Training & Awareness Episode 7: Crisis Response Training: Preparing for the Inevitable In this episode we're diving deep into crisis response training. Because in security, it's not if a crisis will happen, but when. Every organization will face security incidents—that's simply the reality of our digital landscape today.

S2E6 - Executive Security Awareness - Speaking the Board's Language 31.03.2025

Season 2: Training & Awareness Episode 6: Executive Security Awareness - Speaking the Board's Language In this episode, we learn from special guest and seasoned CISO Mangaraja Saut Martua on how to communicate security risks to executives, board-level security awareness program and how to translate technical risks into business impact.

S2E5 - Secure Coding Bootcamps - From Theory to Practice 17.03.2025

Season 2: Training & Awareness Episode 5: Secure Coding Bootcamps - From Theory to Practice Last episode, we discussed building a security culture. Today, we're getting hands-on with one of the most effective ways to improve security: secure coding bootcamps

S2E4 - Security Culture by Design 03.03.2025

Season 2: Training & Awareness Episode 4: Security Culture by Design In our previous episode, we dove into measuring security awareness. Today, we're tackling something more fundamental: how to build security into your organization's DNA. We're talking about creating a security culture by design.

S2E3 - Measuring Security Awareness - Metrics That Matter 18.02.2025

Season 2: Training & Awareness Episode 3: Measuring Security Awareness - Metrics That Matter In our previous episodes, we explored building Security Champions programs and effective developer training. Today, we're tackling a challenge that keeps many CISOs up at night: How do you actually measure if your security awareness programs are working?

S2E2: Developer Security Training - Beyond Annual Compliance 03.02.2025

Season 2: Training & Awareness Episode 2: Developer Security Training - Beyond Annual Compliance In our last episode, we talked about building an effective Security Champions program. Today, we're tackling something even bigger: How to make security training actually work for developers.

S2E1: Building a Security Champions Program That Actually Works 20.01.2025

Season 2: Training & Awareness Episode 1: Building a Security Champions Program That Actually Works In this episode we'll talk about the most important security program you're not running correctly: The Security Champions program.

Season 2 Intro: Training and Awareness 20.01.2025

Intro to Season 2 of AppSec Unlocked Welcome to Season 2 where we're diving into something critical that often gets overlooked in the world of cybersecurity: Training and Awareness.

Help! There’s too many Vulnerabilities! A Practical Guide to Tackling Open-Source Security 02.12.2024

Season 1: Open Source Security Episode 11: Help! There’s too many Vulnerabilities! A Practical Guide to Tackling Open-Source Security

S1E10 - A FAIR Approach to Vulnerability Patch Prioritization 18.11.2024

Season 1: Open Source Security Episode 10: A FAIR Approach to Vulnerability Patch Prioritization In this episode of AppSec Unlocked, we dive into the fascinating topic of using a FAIR approach to Vulnerability Patch prioritization, where we explore how organizations can better prioritize vulnerabilities in their open-source software using the FAIR model and EPSS. And we have Denny Wan, an expert o...

S1E9 - Open-Source Vulnerability Management Policy: A Balanced Approach 11.11.2024

Season 1: Open Source Security Episode 9: Open-Source Vulnerability Management Policy: A Balanced Approach In today's rapidly evolving cybersecurity landscape, managing vulnerabilities in open-source components has become increasingly complex. While traditional approaches relying solely on CVSS scores have their merits, they may not be sufficient to address the exponential growth in discovered vul...

S1S8 - A Cautionary Tale on Supply Chain Attacks: My Recent Encounter with a Compromised NPM Library 04.11.2024

Season 1: Open Source Security Episode 8: A Cautionary Tale on Supply Chain Attacks: My Recent Encounter with a Compromised NPM Library This is a rebroadcast from the CyberBites podcast as it is related to application security and open source supply chain.

S1E7 - Introduction to SSVC 21.10.2024

Season 1: Open Source Security Episode 7: Introduction to StakeholderSpecific Vulnerability Categorization (SSVC) Introduction to a transformative risk-based approach to vulnerability management Why SSVC, especially when we already have CVSS How SSVC works and how to use it Challenges and considerations Real-world example

S1E6 - Software Composition Analysis Selection Criteria 07.10.2024

Season 1: Open Source Security Episode 6: Software Composition Analysis Selection Criteria The Language of Love (and Code) Accuracy: The Goldilocks Zone Speed: Because Time is Money (and Sanity) Remediation: The Path of Least Resistance User-Friendly: No Computer Science Degree Required Timing is Everything The Never-Ending Story

S1E5 - Embarking on the Open Source Security Journey 23.09.2024

Season 1: Open Source Security Episode 5: Embarking on the Open Source Security Journey. When Organisations Take the Leap The Crucial Role of Awareness and Buy-in The First Steps: Gaining Visibility Key Takeaways for a Successful Program Practical Steps and Resources

S1E4 - 5 Steps for Securing Your Open Source Supply Chain 09.09.2024

Season 1: Open Source Security Episode 4: 5 Steps for Securing Your Open Source Supply Chain Most modern applications are assembled from open-source components with developers typically writing less than 15% of the code for their application. Here are the 5 Steps for securing your open source supply chain. Step 1: Maintain a Software Bill of Materials (SBOM) Step 2: Perform Due Diligence - Scan fo...

S1E3 - How Secure Is Open Source Software 26.08.2024

Series 1: Open-Source Security Episode 3: How Secure Are Your Open Source Software Get ready for an eye-opening episode that could change the way you think about the building blocks of modern applications. The Open-Source Paradox The Security Controls Gap The Open-Source Enigma The Due Diligence Disparity The Cost of Insecure Open Source: A Walk Down Memory Lane Best Practices for Secure Open-Sour...

S1E2 - Do Your Applications Have A Software Bill of Materials? 12.08.2024

Season 1: Open Source Security Episode 2: Do Your Applications Have A Software Bill of Materials? “Oh, I didn’t realise we were exposed to as I didn’t think that application was using .”  I often heard such comments during the initial stages of our application security uplift. There was a lack of visibility on what open-source components applications relied on. Developers were often surprised, and...

S1E1 - You're Using More Open-Source Than You Realize 29.07.2024

Season 1: Open Source Security Episode 1: You're Using More Open-Source Than You Realise We're diving into a topic that might surprise you: "You're Using More Open-Source Than You Realize." Get ready for an eye-opening episode that could change the way you think about your applications. • The Open-Source Reality Check • Real-World Example: The Log4j Wake-Up Call • The Rise of AI in Development • T...

Introduction 29.07.2024

Welcome to AppSec Unlocked, the podcast that's all about demystifying application security and empowering developers and security professionals alike. I'm your host, Edwin Kwan, and I'm thrilled to kick off this exciting journey with you. What is AppSec Unlocked? AppSec Unlocked is your key to understanding the complex world of application security. Whether you're a seasoned securi...

Listen to the AppSec Unlocked podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.