Three DevSecOps Lessons Drawn from Conversations with 45 CISOs
Recently, I moderated round table discussions between dozens of CISOs at Evanta CISO Summits in Chicago and Atlanta. My colleague, Michelle Dufty, moderated a similar event in San Francisco ... Read More
Sonatype Nexus is Rising Above the Swamp
In case you missed it -- our rival JFrog published this blog post on Thursday. Amidst the hyperbole, JFrog made a few statements that are true, and numerous that are rooted in fear mongering, falsehoods and gimmicky marketing tactics. Please, allow me to explain ... Read More
In the Dark About Supply Chain Vulnerabilities
The software supply chain can create a seemingly endless attack surface. Here’s what you can do to better protect it. Is the “Barium” hacking collective Chinese? Russian? North Korean? It really doesn’t matter. What we know for sure is that their tactics are new, pervasive and exceptionally dangerous. Barium’s tactics ... Read More

