SlideShare a Scribd company logo
© 2019 VERACODE INC.
How to Create a
Business Case for
Expanding Your
AppSec Program
C o l i n D o m o n e y
© 2019 VERACODE INC.
Introduction
Why are we here?
© 2019 VERACODE INC.
About the Presenter : Colin Domoney
@colindomoney
• Have run enterprise AppSec programmes
• Former Solutions Architect at Veracode
enabling customers and evangelising
AppSec
• DevSecOps consultant advising on how to
build secure, safe software in a reliable and
repeatable manner
• Technologist at heart – interested in all new
technology, particularly automation,
containers, cloud.
© 2019 VERACODE INC.
Agenda
• Expanding the AppSec Programme at Deutsche Bank
• Fighting for Budget
• Strategies for Obtaining Budget
• Programme Metrics That Matter
• Findings from Our Customers
• The Journey to a Mature Programme
• Future Proofing Your Business
© 2019 VERACODE INC.
Expanding the AppSec
Programme at
Deutsche Bank
My own story
© 2019 VERACODE INC.
AppSec Programme at Deutsche Bank
• Established as a greenfield initiative in 2012
• Scaled from 150 apps to 1,900 in 3 years
• Remediated 500,000 high severity flaws in a single year
• Heavy use of automation to reduce manual effort
• Staffed by only one AppSec expert
• Supported by a small team of analysts
© 2019 VERACODE INC.
Year One: Inception
Year
1
• Scan and triage 150 most critical applications in estate
• Reduce critical flaws in applications
• Create awareness for AppSec
PROGRAMME GOALS
• Augmented the value of the manual pen-test programmes by
removing ‘low hanging fruit’
• SaaS provided cost benefits due to low setup overheads
BUDGET JUSTIFICATION
© 2019 VERACODE INC.
Year Two: Expansion
Year
2
• Expand programme to 750 applications
• Used remediation calls to drive flaw closure
PROGRAMME GOALS
• Drive wholesale cost reduction of manual pen-test programmes
while expanding coverage scope
• Reduced developer effort by using AppSec experts as coaches
BUDGET JUSTIFICATION
© 2019 VERACODE INC.
Year Three: Remediation
Year
3
• Closed over 500,000 high severity flaws
• Deployed AppSec experts to achieve aggressive remediation
• Created ‘security champions’ to promote security capability
PROGRAMME GOALS
• Small team provided massive net risk reduction reducing
likelihood of costly breaches
• Creating internal capability led to long term savings
BUDGET JUSTIFICATION
© 2019 VERACODE INC.
Year Four: Automation
Year
4
• Expanded coverage to 2,500 applications
• Injected automated scanning into all central CI/CD systems and
artefact repositories
PROGRAMME GOALS
• Leveraged automation at all points to reduce manual labour
costs of programme execution
• Negotiated beneficial terms with Veracode based on our ability
to execute and deliver value
BUDGET JUSTIFICATION
© 2019 VERACODE INC.
Fighting for Budget
Getting more of the pie
© 2019 VERACODE INC.
Getting More of the Pie
All other security
programmes and projects
AppSec programme
© 2019 VERACODE INC.
Steal Other People’s Pie
• Show better business outcomes
• Demonstrate higher efficiencies
• Demonstrate ROI via consumption
• Be more visible than others
• Demonstrate cost savings
© 2019 VERACODE INC.
Get a Bigger Pie
• Demonstrate a vision for the future
• Attach to a ‘pet project’
• Attach to a burning problem
© 2019 VERACODE INC.
Strategies for
Obtaining Budget
It’s not just ROI
© 2019 VERACODE INC.
“CISO’s Guide to Obtaining Budget”
https://securityintelligence.com/series/a-cisos-
guide-to-obtaining-budget/
Know
Your
Audience
Know
Yourself
Cultivate
Your
Credibility
Never
Waste a
Crisis
Exploit
Pet
Projects
© 2019 VERACODE INC.
Must Do, Should Do, Could Do
https://www.risklens.com/blog/win-the-infosec-budget-
cycle-a-short-guide-for-cisos/
• Regulatory and compliance
Must Do
• Prevent negative impact on your company
Should Do
• R&D and innovation
Could Do
© 2019 VERACODE INC.
Benchmarking Against Competitors
https://www.veracode.com/state-of-software-
security-report
• Benchmark your company against
competitors in your segment
• If you’re lagging use this as a
driver to invest and close the gap
• If you’re leading use this as an
opportunity to embark on more
ambitious projects
© 2019 VERACODE INC.
Heard via the Grapevine …
“significant costs savings using a centralised solution over ad-hoc on
demand siloed testing”
“the cost of the programme is insignificant compared to the cost of losing
customers”
“we were losing customers because we couldn’t demonstrate we were
developing secure software”
© 2019 VERACODE INC.
Programme Metrics
That Matter
Numbers that count
© 2019 VERACODE INC.
How To Measure Your Programme
https://www.csoonline.com/article/3200270/cybers
ecurity-spend-roi-is-the-wrong-metric.html
https://www.fairinstitute.org/fair-book https://www.howtomeasureanyth
ing.com/cybersecurity/
© 2019 VERACODE INC.
Use Metrics to Manage Your AppSec Programme
https://www.veracode.com/sites/default/files/Resources/Whitepapers/using-
metrics-to-manage-your-application-security-program-sans-veracode.pdf
© 2019 VERACODE INC.
Veracode’s Top Five Programme Metrics
© 2019 VERACODE INC.
#1 : Your Flaw Density
• Allows appropriate focus on
expansion of developer training
activities
• Securing third-party software
• Identifying vulnerable components or
libraries
USE CASE
Reports where the most code
flaws are seen
WHAT
© 2019 VERACODE INC.
#2 : Your Fix Rate
• Allows appropriate focus on
expansion of developer training
activities
• Augment your development team
using advisors or security champions
• Redirect funds toward remediation
activities
USE CASE
How long it takes you to fix
vulnerabilities
WHAT
© 2019 VERACODE INC.
#3 : Your Rank in AppSec Maturity Models
• Identify gaps in your programme
based on the lessons learned by
others and best practices
• Expanding your programme to remain
competitive
USE CASE
How do you compare to
industry leaders and best
practices
WHAT
© 2019 VERACODE INC.
#4 : Your Compliance with Industry Regulations
• Code reviews built into the SDLC
• Both manual and automated
assessments
• Controls around 3rd party software
• Gap analysis
• Continuous verification
USE CASE
Whether you are meeting
relevant industry regulations
WHAT
© 2019 VERACODE INC.
#5 : Your Compliance with Internal Policies
• Provide additional developer training
• Gap analysis
• Continuous verification
• Augment your development team
using advisors or security champions
USE CASE
Whether you are meeting your
internal policies
WHAT
© 2019 VERACODE INC.
Metrics Used in My Deutsche Bank Programme
“What percentage of applications are covered by the
AppSec programme?
”What percentage of applications are compliant with
the AppSec policy?”
© 2019 VERACODE INC.
Findings From Our
Customers
Forrester TEI report
© 2019 VERACODE INC.
SANS AppSec ROI Report
https://www.veracode.com/blog/managing-appsec/optimizing-your-
appsec-investment-value-stream-mapping
© 2019 VERACODE INC.
Investment Decision Making
© 2019 VERACODE INC.
Simple Return on Investment Model
© 2019 VERACODE INC.
Forrester Total Economic Impact Report
https://info.veracode.com/analyst-report-forrester-the-
total-economic-impact-study.html
© 2019 VERACODE INC.
Research Methodology
© 2019 VERACODE INC.
Results Take Time
© 2019 VERACODE INC.
Analysis of Benefits
© 2019 VERACODE INC.
Doing More with a Smaller Team
© 2019 VERACODE INC.
Reduce Costs of 3rd Party Testing
© 2019 VERACODE INC.
Analysis of Costs
© 2019 VERACODE INC.
Invest in Automation Upfront
© 2019 VERACODE INC.
The Journey to a
Mature Programme
A route to maturity
© 2019 VERACODE INC.
Four Stages to a Mature Programme
Reactive
• Fire fighting mode
• Responding to emergencies
• Limited scale and scope
Baseline
• Wider coverage
• More comprehensive assessments
• Greater measure of control and KPIs
Expanded
• Fully integrated into the SDLC
• AppSec is seen as BAU
Advanced
• More nuanced in approach to tools and teams
• Highly integrated in a DevSecOps approach
© 2019 VERACODE INC.
Demonstrate a Vision for Your Programme
© 2019 VERACODE INC.
Future Proofing Your
Business
Invest for the future
© 2019 VERACODE INC.
Dev(Sec)Ops and Automation
https://dzone.com/articles/devops-
trends-2019-what-you-need-to-know
© 2019 VERACODE INC.
Security as a Competitive Advantage / Requirement
https://www.capgemini.com/2018/05/cybersecurity-the-new-
competitive-advantage-for-retailers/
© 2019 VERACODE INC.
Top Takeaways to Remember
• Fight for more of the budget pie
• Plan on expanding the budget pie
• Pick metrics that matter to your business
• Benchmark against your peers/competitors
• Pick solutions that allow automation
• Invest upfront to automate to achieve long term ROI
• Don’t expect instant gratification !
© 2019 VERACODE INC.
Get In Touch
• Follow up via the Brighttalk page
• Follow up with the point of contact in your registration email
• Please do @ me on Twitter : @colindomoney
© 2019 VERACODE INC.

More Related Content

PPTX
Business continuity & disaster recovery planning (BCP & DRP)
PDF
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
PDF
The Art of Cloud Auditing - ISACA ID
PDF
OWASP Top 10 Web Application Vulnerabilities
PPT
Chapter 01 software engineering pressman
PPT
Developing an Information Security Program
PPTX
Adaptive Enterprise Security Architecture
PDF
Scrum and Agile SDLC 101
Business continuity & disaster recovery planning (BCP & DRP)
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
The Art of Cloud Auditing - ISACA ID
OWASP Top 10 Web Application Vulnerabilities
Chapter 01 software engineering pressman
Developing an Information Security Program
Adaptive Enterprise Security Architecture
Scrum and Agile SDLC 101

What's hot (20)

PDF
Security Maturity Models.
PDF
PaloAlto Enterprise Security Solution
PDF
Security architecture
DOCX
Spm unit1
PPTX
Cybersecurity Capability Maturity Model (C2M2)
PDF
NQA ISO 27001 Implementation Guide
PPTX
Enterprise Security Architecture
PPT
Software Engineering Code Of Ethics And Professional Practice
PPTX
NIST CyberSecurity Framework: An Overview
PPTX
Business continuity
PPTX
Security Operations Center (SOC) Essentials for the SME
PDF
Cybersecurity & Project Management
ODP
Web Application Firewall
PPT
Application Security
PPT
PPTX
Security models for security architecture
PDF
Enterprise Security Architecture
PDF
Understanding the NIST Risk Management Framework: 800-37 Rev. 2
PPT
5.4 it security audit (mauritius)
Security Maturity Models.
PaloAlto Enterprise Security Solution
Security architecture
Spm unit1
Cybersecurity Capability Maturity Model (C2M2)
NQA ISO 27001 Implementation Guide
Enterprise Security Architecture
Software Engineering Code Of Ethics And Professional Practice
NIST CyberSecurity Framework: An Overview
Business continuity
Security Operations Center (SOC) Essentials for the SME
Cybersecurity & Project Management
Web Application Firewall
Application Security
Security models for security architecture
Enterprise Security Architecture
Understanding the NIST Risk Management Framework: 800-37 Rev. 2
5.4 it security audit (mauritius)
Ad

Similar to How to create a business case for expanding your AppSec program (20)

PPTX
Benefits of Developing Web Applications.pptx
PDF
Enable and Secure Business Growth in the New Application Economy
PPTX
People & Performance: How to Solve the Biggest Challenge in the Property Mana...
PDF
Transformation: Not Only the App But Also the Way We Work
PDF
T Bytes Digital customer experience
PDF
How to Choose the Right CRE Technology Partner Webinar.pdf
PDF
La Digital Transformation ha un nuovo alleato: Value Stream Management
PPTX
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
PDF
Strategies to improve the ROI on your enterprise application
PPTX
Scaling Your Software Sales: A Guide to the AppDirect Monetization Suite
PDF
Digital Strategy with Dyer & Blomfield
PDF
Mobile apps presentation - Mobile App Development Services
PDF
Application Security with NGINX
PDF
CISOSHARE's approach to designing effective cyber security programs
PPTX
Enhancing QA Strategy to Achieve Agile Quality Engineering
PPTX
Free Your Data: Accelerating Innovation by Using API's to Unlock Core Systems
PDF
Scale DevSecOps with your Continuous Integration Pipeline
PPTX
Aaron Swain at VMware Tanzu Public Sector Connect 2021
PPTX
Fixed vs. Variable Expenses: For Your Mobile App Development Project
PDF
Application Security with NGINX | APAC
Benefits of Developing Web Applications.pptx
Enable and Secure Business Growth in the New Application Economy
People & Performance: How to Solve the Biggest Challenge in the Property Mana...
Transformation: Not Only the App But Also the Way We Work
T Bytes Digital customer experience
How to Choose the Right CRE Technology Partner Webinar.pdf
La Digital Transformation ha un nuovo alleato: Value Stream Management
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
Strategies to improve the ROI on your enterprise application
Scaling Your Software Sales: A Guide to the AppDirect Monetization Suite
Digital Strategy with Dyer & Blomfield
Mobile apps presentation - Mobile App Development Services
Application Security with NGINX
CISOSHARE's approach to designing effective cyber security programs
Enhancing QA Strategy to Achieve Agile Quality Engineering
Free Your Data: Accelerating Innovation by Using API's to Unlock Core Systems
Scale DevSecOps with your Continuous Integration Pipeline
Aaron Swain at VMware Tanzu Public Sector Connect 2021
Fixed vs. Variable Expenses: For Your Mobile App Development Project
Application Security with NGINX | APAC
Ad

Recently uploaded (20)

PDF
Softaken Excel to vCard Converter Software.pdf
PPTX
Transform Your Business with a Software ERP System
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PPTX
Computer Software and OS of computer science of grade 11.pptx
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
PTS Company Brochure 2025 (1).pdf.......
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PPTX
history of c programming in notes for students .pptx
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PPTX
assetexplorer- product-overview - presentation
PPTX
ai tools demonstartion for schools and inter college
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Softaken Excel to vCard Converter Software.pdf
Transform Your Business with a Software ERP System
Wondershare Filmora 15 Crack With Activation Key [2025
Computer Software and OS of computer science of grade 11.pptx
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PTS Company Brochure 2025 (1).pdf.......
Odoo Companies in India – Driving Business Transformation.pdf
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
wealthsignaloriginal-com-DS-text-... (1).pdf
history of c programming in notes for students .pptx
VVF-Customer-Presentation2025-Ver1.9.pptx
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
How to Migrate SBCGlobal Email to Yahoo Easily
Design an Analysis of Algorithms I-SECS-1021-03
assetexplorer- product-overview - presentation
ai tools demonstartion for schools and inter college
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...

How to create a business case for expanding your AppSec program

  • 1. © 2019 VERACODE INC. How to Create a Business Case for Expanding Your AppSec Program C o l i n D o m o n e y
  • 2. © 2019 VERACODE INC. Introduction Why are we here?
  • 3. © 2019 VERACODE INC. About the Presenter : Colin Domoney @colindomoney • Have run enterprise AppSec programmes • Former Solutions Architect at Veracode enabling customers and evangelising AppSec • DevSecOps consultant advising on how to build secure, safe software in a reliable and repeatable manner • Technologist at heart – interested in all new technology, particularly automation, containers, cloud.
  • 4. © 2019 VERACODE INC. Agenda • Expanding the AppSec Programme at Deutsche Bank • Fighting for Budget • Strategies for Obtaining Budget • Programme Metrics That Matter • Findings from Our Customers • The Journey to a Mature Programme • Future Proofing Your Business
  • 5. © 2019 VERACODE INC. Expanding the AppSec Programme at Deutsche Bank My own story
  • 6. © 2019 VERACODE INC. AppSec Programme at Deutsche Bank • Established as a greenfield initiative in 2012 • Scaled from 150 apps to 1,900 in 3 years • Remediated 500,000 high severity flaws in a single year • Heavy use of automation to reduce manual effort • Staffed by only one AppSec expert • Supported by a small team of analysts
  • 7. © 2019 VERACODE INC. Year One: Inception Year 1 • Scan and triage 150 most critical applications in estate • Reduce critical flaws in applications • Create awareness for AppSec PROGRAMME GOALS • Augmented the value of the manual pen-test programmes by removing ‘low hanging fruit’ • SaaS provided cost benefits due to low setup overheads BUDGET JUSTIFICATION
  • 8. © 2019 VERACODE INC. Year Two: Expansion Year 2 • Expand programme to 750 applications • Used remediation calls to drive flaw closure PROGRAMME GOALS • Drive wholesale cost reduction of manual pen-test programmes while expanding coverage scope • Reduced developer effort by using AppSec experts as coaches BUDGET JUSTIFICATION
  • 9. © 2019 VERACODE INC. Year Three: Remediation Year 3 • Closed over 500,000 high severity flaws • Deployed AppSec experts to achieve aggressive remediation • Created ‘security champions’ to promote security capability PROGRAMME GOALS • Small team provided massive net risk reduction reducing likelihood of costly breaches • Creating internal capability led to long term savings BUDGET JUSTIFICATION
  • 10. © 2019 VERACODE INC. Year Four: Automation Year 4 • Expanded coverage to 2,500 applications • Injected automated scanning into all central CI/CD systems and artefact repositories PROGRAMME GOALS • Leveraged automation at all points to reduce manual labour costs of programme execution • Negotiated beneficial terms with Veracode based on our ability to execute and deliver value BUDGET JUSTIFICATION
  • 11. © 2019 VERACODE INC. Fighting for Budget Getting more of the pie
  • 12. © 2019 VERACODE INC. Getting More of the Pie All other security programmes and projects AppSec programme
  • 13. © 2019 VERACODE INC. Steal Other People’s Pie • Show better business outcomes • Demonstrate higher efficiencies • Demonstrate ROI via consumption • Be more visible than others • Demonstrate cost savings
  • 14. © 2019 VERACODE INC. Get a Bigger Pie • Demonstrate a vision for the future • Attach to a ‘pet project’ • Attach to a burning problem
  • 15. © 2019 VERACODE INC. Strategies for Obtaining Budget It’s not just ROI
  • 16. © 2019 VERACODE INC. “CISO’s Guide to Obtaining Budget” https://securityintelligence.com/series/a-cisos- guide-to-obtaining-budget/ Know Your Audience Know Yourself Cultivate Your Credibility Never Waste a Crisis Exploit Pet Projects
  • 17. © 2019 VERACODE INC. Must Do, Should Do, Could Do https://www.risklens.com/blog/win-the-infosec-budget- cycle-a-short-guide-for-cisos/ • Regulatory and compliance Must Do • Prevent negative impact on your company Should Do • R&D and innovation Could Do
  • 18. © 2019 VERACODE INC. Benchmarking Against Competitors https://www.veracode.com/state-of-software- security-report • Benchmark your company against competitors in your segment • If you’re lagging use this as a driver to invest and close the gap • If you’re leading use this as an opportunity to embark on more ambitious projects
  • 19. © 2019 VERACODE INC. Heard via the Grapevine … “significant costs savings using a centralised solution over ad-hoc on demand siloed testing” “the cost of the programme is insignificant compared to the cost of losing customers” “we were losing customers because we couldn’t demonstrate we were developing secure software”
  • 20. © 2019 VERACODE INC. Programme Metrics That Matter Numbers that count
  • 21. © 2019 VERACODE INC. How To Measure Your Programme https://www.csoonline.com/article/3200270/cybers ecurity-spend-roi-is-the-wrong-metric.html https://www.fairinstitute.org/fair-book https://www.howtomeasureanyth ing.com/cybersecurity/
  • 22. © 2019 VERACODE INC. Use Metrics to Manage Your AppSec Programme https://www.veracode.com/sites/default/files/Resources/Whitepapers/using- metrics-to-manage-your-application-security-program-sans-veracode.pdf
  • 23. © 2019 VERACODE INC. Veracode’s Top Five Programme Metrics
  • 24. © 2019 VERACODE INC. #1 : Your Flaw Density • Allows appropriate focus on expansion of developer training activities • Securing third-party software • Identifying vulnerable components or libraries USE CASE Reports where the most code flaws are seen WHAT
  • 25. © 2019 VERACODE INC. #2 : Your Fix Rate • Allows appropriate focus on expansion of developer training activities • Augment your development team using advisors or security champions • Redirect funds toward remediation activities USE CASE How long it takes you to fix vulnerabilities WHAT
  • 26. © 2019 VERACODE INC. #3 : Your Rank in AppSec Maturity Models • Identify gaps in your programme based on the lessons learned by others and best practices • Expanding your programme to remain competitive USE CASE How do you compare to industry leaders and best practices WHAT
  • 27. © 2019 VERACODE INC. #4 : Your Compliance with Industry Regulations • Code reviews built into the SDLC • Both manual and automated assessments • Controls around 3rd party software • Gap analysis • Continuous verification USE CASE Whether you are meeting relevant industry regulations WHAT
  • 28. © 2019 VERACODE INC. #5 : Your Compliance with Internal Policies • Provide additional developer training • Gap analysis • Continuous verification • Augment your development team using advisors or security champions USE CASE Whether you are meeting your internal policies WHAT
  • 29. © 2019 VERACODE INC. Metrics Used in My Deutsche Bank Programme “What percentage of applications are covered by the AppSec programme? ”What percentage of applications are compliant with the AppSec policy?”
  • 30. © 2019 VERACODE INC. Findings From Our Customers Forrester TEI report
  • 31. © 2019 VERACODE INC. SANS AppSec ROI Report https://www.veracode.com/blog/managing-appsec/optimizing-your- appsec-investment-value-stream-mapping
  • 32. © 2019 VERACODE INC. Investment Decision Making
  • 33. © 2019 VERACODE INC. Simple Return on Investment Model
  • 34. © 2019 VERACODE INC. Forrester Total Economic Impact Report https://info.veracode.com/analyst-report-forrester-the- total-economic-impact-study.html
  • 35. © 2019 VERACODE INC. Research Methodology
  • 36. © 2019 VERACODE INC. Results Take Time
  • 37. © 2019 VERACODE INC. Analysis of Benefits
  • 38. © 2019 VERACODE INC. Doing More with a Smaller Team
  • 39. © 2019 VERACODE INC. Reduce Costs of 3rd Party Testing
  • 40. © 2019 VERACODE INC. Analysis of Costs
  • 41. © 2019 VERACODE INC. Invest in Automation Upfront
  • 42. © 2019 VERACODE INC. The Journey to a Mature Programme A route to maturity
  • 43. © 2019 VERACODE INC. Four Stages to a Mature Programme Reactive • Fire fighting mode • Responding to emergencies • Limited scale and scope Baseline • Wider coverage • More comprehensive assessments • Greater measure of control and KPIs Expanded • Fully integrated into the SDLC • AppSec is seen as BAU Advanced • More nuanced in approach to tools and teams • Highly integrated in a DevSecOps approach
  • 44. © 2019 VERACODE INC. Demonstrate a Vision for Your Programme
  • 45. © 2019 VERACODE INC. Future Proofing Your Business Invest for the future
  • 46. © 2019 VERACODE INC. Dev(Sec)Ops and Automation https://dzone.com/articles/devops- trends-2019-what-you-need-to-know
  • 47. © 2019 VERACODE INC. Security as a Competitive Advantage / Requirement https://www.capgemini.com/2018/05/cybersecurity-the-new- competitive-advantage-for-retailers/
  • 48. © 2019 VERACODE INC. Top Takeaways to Remember • Fight for more of the budget pie • Plan on expanding the budget pie • Pick metrics that matter to your business • Benchmark against your peers/competitors • Pick solutions that allow automation • Invest upfront to automate to achieve long term ROI • Don’t expect instant gratification !
  • 49. © 2019 VERACODE INC. Get In Touch • Follow up via the Brighttalk page • Follow up with the point of contact in your registration email • Please do @ me on Twitter : @colindomoney