Dr. Dag Flachet, Dr. Aram Hovsepyan
The AppSec Management Podcast
This podcast is about application security, OWASP and security first compliance. It is targeted at those involved with application security programmes and anyone interested in the frontier of cybersecurity in applications.
Author
Dr. Dag Flachet, Dr. Aram Hovsepyan
Category
Podcast website
Latest episode
Jun 16, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
PRC, Product Risk and Compliance 16.06.2026 4:41
Traditional GRC tools were built for corporate IT, not for modern software development. As regulations like the EU Cyber Resilience Act raise the bar for product-level security, a new discipline is emerging: Product Risk and Compliance (PRC).
CRA Sessions: Risk Assessment 09.06.2026 26:06
Risk assessments are the starting point of your application security program and as it turns out your Cyber Resilience Act compliance strategy. If you think about it, it makes absolute sense. If there is no risk, you don't really need security. Unfortunately, that's not the world we are living in and creating a crystal clear understanding of the risk profile for each of your products is essential....
What is CRA and why do we care? 02.06.2026 23:55
Lara and I kick off our new series on the EU Cyber Resilience Act (CRA), where we'll go deep on what the regulation actually means for product security teams and how to translate it into concrete application security practice. In this first episode, we cover the foundations:What the CRA is and why it existsWhich products fall under its scope, and which don'tHow compliance requirements diff...
Is security becoming prompt-driven? The future of AppSec in the age of AI 26.05.2026 47:16
AI is changing everything - including how attackers think. But is the security industry keeping up? This webinar, hosted jointly with Toreon, tackles one of the biggest questions in AppSec right now: as AI agents, LLMs, and prompt-driven development become the norm, what does application security even look like?📌 Follow us on LinkedIn: https://www.linkedin.com/company/9420309/🌐 Or visit our webs...
AppSec at SMEs, how are your peers doing? 19.05.2026 42:41
In this chapter we have the research team of PXL University of Applied Sciences that did an in depth analysis of the state of AppSec processes at SMEs. They report on their outcomes and findings.
Operational Security With SAMMY 12.05.2026 10:12
You can use SAMMY for free on sammy.codific.com
Appsec Management With SAMMY 05.05.2026 23:08
You can use sammy for free on sammy.codific.com
AI in AppSec, May 2026 Update 28.04.2026 21:41
This episode looks at the latest developments around AI tools in Application Security. Guidance and best practices in the new context.
Introduction to EU DORA 21.04.2026 21:52
This is deep dive into DORA the EU Digital Operational Resilience Act. For more details refer to the Codific website: https://codific.com/summary-of-dora/
CRA Standards 14.04.2026 22:31
This episode covers the EN-40000 standards that serve as a provisional basis for CRA Horizontal Standards. This is the summary of resources collected on complycra.eu for the full story and presentation please refer to the website: https://complycra.eu/cra-standards/
Introduction to Secure Control Frameworks 07.04.2026 21:13
This content is a summary of a deep dive by the Codific team. For the full coverage refer to the article on the Codific Website: https://codific.com/secure-controls-framework-a-comprehensive-overview/
How to build and manage your appsec program. 31.03.2026 23:36
This is a summary of interviews in the Codific website. For the full stories please refer to the Codific website: https://codific.com/codifics-customers-success-stories/
NIS2 Directive: Everything you need to know 24.03.2026 22:47
This is a summary of a deep dive by the Codific team. For the full article please refer to the Codific website: https://codific.com/nis-2-directive-compliance-guide-fines-scope/
NIST SSDF 1.2: an introduction 17.03.2026 22:33
This is a summary of a deep dive by Aram Hovsepyan. For the full article refer to the Codific website: https://codific.com/nist-ssdf-1-2-explained/
Women in cybersecurity, what it really looks like, and where you can fit 09.03.2026 28:15
In this International Women’s Day interview, we speak with Kim Wuyts, a privacy engineer and privacy by design advocate with 15+ years across security and privacy. Kim helped develop LINDDUN, a privacy threat modeling framework, and regularly speaks at international security and privacy conferences. This conversation is for women who are considering cybersecurity or privacy, women already in tech...
Can we do Application Security with AI? An analysis of Claude Code Security. 03.03.2026 19:44
This episode is based on analysis by Aram Hovsepyan. For the full story refer to his blog post here: https://codific.com/claude-code-security-will-ai-disrupt-application-security/
Understanding the Cyber Resilience Act (CRA): What Software and Product Companies Need to Know 03.02.2026 47:26
In this episode, Viktor Lukachyk, Security Manager at Sigma Software, joins Nicolas and Dag from Codific to break down the Cyber Resilience Act (CRA) and what it means for software and digital product companies operating in the EU.We discuss how CRA fits alongside regulations like NIS 2 and DORA, which products fall into scope, and why CRA is focused on secure by design principles rather than comp...
Frameworks and maturity models explained 07.01.2026 21:55
ISO 27001, NIST CSF, NIST SSDF, CIS Critical Security Controls Framework. All these things are called frameworks. But what are they really? Why do we need them? And are they only relevant for GRC teams in large organizations? If all your tools show green dashboards, isn’t that enough to claim your software product is secure? In this episode of AppSec Science I explain why frameworks are essential...
The Reality of AppSec Risk Management using CVEs and CVSS scores 18.12.2025 35:16
Many organizations treat Common Vulnerability Enumerations or CVEs as first class citizens. Some even enforce strict SLAs on CVE remediation times depending on their severity scores expressed with the CVSS metric. The numbers make sense as they are built on top of real and hard data. Moreover, attackers also have access to this data, so building your complete strategy around vulnerability dashboar...
The science of security metrics 11.12.2025 41:07
" If you can’t measure it you can’t improve it. ". It is hard to argue with that. But here is the catch, what are we measuring and what are we improving. Measuring the right things right is not a rocket science, but it is a science. Common sense might get you so far, but in my experience common sense is failing us. Organizations are focusing on metrics that are readily produced by tooli...
What is the cost of a Data Breach? 11.12.2025 16:36
This episode is based on the the IBM cost of a Data Breach report, for full data refer to the report. https://www.ibm.com/reports/data-breach
How to comply with CRA 05.12.2025 14:21
This episode is based on content from the the Codific website. Voices and narrative are AI generated. For full factual acurracy refer to the Codific website. https://codific.com/application-security-insights-and-other-exciting-stories/
OWASP ASVS, an introduction 27.11.2025 12:45
This content is based on an article written by Nicolas Montauban. Voices and narrative are AI generated, for full factual accuracy refer to the underlying article. https://codific.com/owasp-asvs-a-comprehensive-overview/
The New OWASP TOP 10, what has changed and why. 20.11.2025 14:09
This podcast is based on the presentations and press releases of the OWASP and Codific team. For the latest insights check the Codific website.
Top Application Security Failures at Fortune 500 Companies 13.11.2025 21:32
This podcast is based on in depth analysis by Dr. Aram Hovsepyan. Voices and narrative are AI generated. For full factual accuracy refer to underlying article. https://codific.com/top-application-security-failures-in-fortune-500-companies/
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.