Dr. Dag Flachet, Dr. Aram Hovsepyan

The AppSec Management Podcast

This podcast is about application security, OWASP and security first compliance. It is targeted at those involved with application security programmes and anyone interested in the frontier of cybersecurity in applications.

Author

Dr. Dag Flachet, Dr. Aram Hovsepyan

Category

Technology

Podcast website

podcasters.spotify.com

Latest episode

Jun 16, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

PRC, Product Risk and Compliance 16.06.2026

Traditional GRC tools were built for corporate IT, not for modern software development. As regulations like the EU Cyber Resilience Act raise the bar for product-level security, a new discipline is emerging: Product Risk and Compliance (PRC).

CRA Sessions: Risk Assessment 09.06.2026

Risk assessments are the starting point of your application security program and as it turns out your Cyber Resilience Act compliance strategy. If you think about it, it makes absolute sense. If there is no risk, you don't really need security. Unfortunately, that's not the world we are living in and creating a crystal clear understanding of the risk profile for each of your products is essential....

What is CRA and why do we care? 02.06.2026

Lara and I kick off our new series on the EU Cyber Resilience Act (CRA), where we'll go deep on what the regulation actually means for product security teams and how to translate it into concrete application security practice. In this first episode, we cover the foundations:What the CRA is and why it existsWhich products fall under its scope, and which don'tHow compliance requirements diff...

Is security becoming prompt-driven? The future of AppSec in the age of AI 26.05.2026

AI is changing everything - including how attackers think. But is the security industry keeping up? This webinar, hosted jointly with Toreon, tackles one of the biggest questions in AppSec right now: as AI agents, LLMs, and prompt-driven development become the norm, what does application security even look like?📌 Follow us on LinkedIn: https://www.linkedin.com/company/9420309/🌐 Or visit our webs...

AppSec at SMEs, how are your peers doing? 19.05.2026

In this chapter we have the research team of PXL University of Applied Sciences that did an in depth analysis of the state of AppSec processes at SMEs. They report on their outcomes and findings.

Operational Security With SAMMY 12.05.2026

You can use SAMMY for free on sammy.codific.com

Appsec Management With SAMMY 05.05.2026

You can use sammy for free on sammy.codific.com

AI in AppSec, May 2026 Update 28.04.2026

This episode looks at the latest developments around AI tools in Application Security. Guidance and best practices in the new context.

Introduction to EU DORA 21.04.2026

This is deep dive into DORA the EU Digital Operational Resilience Act. For more details refer to the Codific website: https://codific.com/summary-of-dora/

CRA Standards 14.04.2026

This episode covers the EN-40000 standards that serve as a provisional basis for CRA Horizontal Standards. This is the summary of resources collected on complycra.eu for the full story and presentation please refer to the website: https://complycra.eu/cra-standards/

Introduction to Secure Control Frameworks 07.04.2026

This content is a summary of a deep dive by the Codific team. For the full coverage refer to the article on the Codific Website: https://codific.com/secure-controls-framework-a-comprehensive-overview/

How to build and manage your appsec program. 31.03.2026

This is a summary of interviews in the Codific website. For the full stories please refer to the Codific website: https://codific.com/codifics-customers-success-stories/

NIS2 Directive: Everything you need to know 24.03.2026

This is a summary of a deep dive by the Codific team. For the full article please refer to the Codific website: https://codific.com/nis-2-directive-compliance-guide-fines-scope/

NIST SSDF 1.2: an introduction 17.03.2026

This is a summary of a deep dive by Aram Hovsepyan. For the full article refer to the Codific website: https://codific.com/nist-ssdf-1-2-explained/

Women in cybersecurity, what it really looks like, and where you can fit 09.03.2026

In this International Women’s Day interview, we speak with Kim Wuyts, a privacy engineer and privacy by design advocate with 15+ years across security and privacy. Kim helped develop LINDDUN, a privacy threat modeling framework, and regularly speaks at international security and privacy conferences. This conversation is for women who are considering cybersecurity or privacy, women already in tech...

Can we do Application Security with AI? An analysis of Claude Code Security. 03.03.2026

This episode is based on analysis by Aram Hovsepyan. For the full story refer to his blog post here: https://codific.com/claude-code-security-will-ai-disrupt-application-security/

Understanding the Cyber Resilience Act (CRA): What Software and Product Companies Need to Know 03.02.2026

In this episode, Viktor Lukachyk, Security Manager at Sigma Software, joins Nicolas and Dag from Codific to break down the Cyber Resilience Act (CRA) and what it means for software and digital product companies operating in the EU.We discuss how CRA fits alongside regulations like NIS 2 and DORA, which products fall into scope, and why CRA is focused on secure by design principles rather than comp...

Frameworks and maturity models explained 07.01.2026

ISO 27001, NIST CSF, NIST SSDF, CIS Critical Security Controls Framework. All these things are called frameworks. But what are they really? Why do we need them? And are they only relevant for GRC teams in large organizations? If all your tools show green dashboards, isn’t that enough to claim your software product is secure? In this episode of AppSec Science I explain why frameworks are essential...

The Reality of AppSec Risk Management using CVEs and CVSS scores 18.12.2025

Many organizations treat Common Vulnerability Enumerations or CVEs as first class citizens. Some even enforce strict SLAs on CVE remediation times depending on their severity scores expressed with the CVSS metric. The numbers make sense as they are built on top of real and hard data. Moreover, attackers also have access to this data, so building your complete strategy around vulnerability dashboar...

The science of security metrics 11.12.2025

" If you can’t measure it you can’t improve it. ". It is hard to argue with that. But here is the catch, what are we measuring and what are we improving.  Measuring the right things right is not a rocket science, but it is a science. Common sense might get you so far, but in my experience common sense is failing us. Organizations are focusing on metrics that are readily produced by tooli...

What is the cost of a Data Breach? 11.12.2025

This episode is based on the the IBM cost of a Data Breach report, for full data refer to the report. https://www.ibm.com/reports/data-breach

How to comply with CRA 05.12.2025

This episode is based on content from the the Codific website. Voices and narrative are AI generated. For full factual acurracy refer to the Codific website. https://codific.com/application-security-insights-and-other-exciting-stories/

OWASP ASVS, an introduction 27.11.2025

This content is based on an article written by Nicolas Montauban. Voices and narrative are AI generated, for full factual accuracy refer to the underlying article. https://codific.com/owasp-asvs-a-comprehensive-overview/

The New OWASP TOP 10, what has changed and why. 20.11.2025

This podcast is based on the presentations and press releases of the OWASP and Codific team. For the latest insights check the Codific website.

Top Application Security Failures at Fortune 500 Companies 13.11.2025

This podcast is based on in depth analysis by Dr. Aram Hovsepyan. Voices and narrative are AI generated. For full factual accuracy refer to underlying article. https://codific.com/top-application-security-failures-in-fortune-500-companies/

Listen to the The AppSec Management Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.