SBN

Cybersecurity Insights with Contrast CISO David Lindner | 5/27

Skip to content

Cybersecurity Insights with Contrast CISO David Lindner | 5/27

Cybersecurity Insights with Contrast CISO David Lindner | 5/27

Insight #1

“A recent survey shows developers are struggling to write secure code and often times publish code with known security vulnerabilities due to juggling priorities and demands. The only way to solve this is to provide your developers with all the information they need, in process, and in real-time, and allow them to fix vulnerabilities as they write code. Out of band tests, pdf reports, and false positives all lead to ignoring and deprioritizing.”
 

Insight #2

“Struggling with retention on your security teams? Three things that may help. First, provide weekly research time as part of their normal job. Second, send them to conferences. Third, pay them well and continually review the market.”
 

Insight #3

“When was the last time you did a Github search for common secrets, keys, or configuration files used in your environments? Try it today as I guarantee you find something.”
 
 
 

David Lindner, Chief Information Security Officer

David Lindner, Chief Information Security Officer

David is an experienced application security professional with over 20 years in cybersecurity. In addition to serving as the chief information security officer, David leads the Contrast Labs team that is focused on analyzing threat intelligence to help enterprise clients develop more proactive approaches to their application security programs. Throughout his career, David has worked within multiple disciplines in the security field—from application development, to network architecture design and support, to IT security and consulting, to security training, to application security. Over the past decade, David has specialized in all things related to mobile applications and securing them. He has worked with many clients across industry sectors, including financial, government, automobile, healthcare, and retail. David is an active participant in numerous bug bounty programs.

*** This is a Security Bloggers Network syndicated blog from AppSec Observer authored by David Lindner, Director, Application Security. Read the original post at: https://www.contrastsecurity.com/security-influencers/cybersecurity-insights-with-contrast-ciso-david-lindner-5/27