Suzanne Ciccone

Suzanne Ciccone

Suzanne is part of the content team at Veracode, working to create resources that shed light on AppSec problems and solutions. 

Stay up to date on Application Security

Posts by Suzanne Ciccone
  • Podcast: AppSec's Effect on the…
    | By Suzanne Ciccone

    Traditionally, most executives have thought of security as a necessary evil – an investment that was needed solely to avoid a bad outcome, but not something that would bring in new customers or boost revenue. But that seems to be changing. Veracode recently surveyed IT and business leaders to find…

    Read Article
     
  • Do IT Pros Consider Security When…
    | By Suzanne Ciccone

    Traditionally, security was about cost avoidance. It was thought of like insurance – something you have to have in case something bad happens, but not something that would boost the bottom line or attract customers. But in today’s environment, we are increasingly seeing that security is about more…

    Read Article
     
  • Security: Create a Development Champion
    | By Suzanne Ciccone

    We talk a lot about the need for development teams to create security champions. With the shift to DevOps – and the intersecting of development, security, and operations teams – development and security teams can no longer operate in their traditional silos. Each team needs to not only work closely…

    Read Article
     
  • 5 Essential Steps to Shift Security…
    | By Suzanne Ciccone

    Speed rules in software development today. The DevOps model means getting newer, better, faster into the hands of customers as quickly as possible is the name of the game. But where does that leave security? If it’s not done right -- overlooked or worked around. Done right -- it’s embedded into the…

    Read Article
     
  • Security: Here’s What You Need to Know…
    | By Suzanne Ciccone

    The days of security and development working in separate and isolated silos are over. Security is now a task shared by the development and security teams throughout the software lifecycle – from inception to production. Security testing has become primarily the responsibility of developers, with…

    Read Article
     
  • Podcast: 2017 OWASP Top 10 – What’s New
    | By Suzanne Ciccone

    For the first time in four years, we have a new OWASP Top 10 list of the most critical application security risks. Cross-site request forgery (CSRF) and unvalidated redirects and forwards have been bumped off the list. XML external entities, insecure deserialization and insufficient logging and…

    Read Article