How legacy AppSec is holding back Secure by Design
ID: dfa4d162-79d1-5055-8323-94cb778c022c
STIX ID: report--dfa4d162-79d1-5055-8323-94cb778c022c
Feed Name: ReversingLabs Blog
Date Published: 2023-11-22
Date Updated: 2026-04-29
Author: [email protected] (Ericka Chickowski)
This report argues that realizing Secure by Design requires moving beyond legacy AST/SCA and vulnerability-centric approaches to holistic, system-level testing and integrity checks that address software supply chain risks exemplified by SolarWinds, 3CX, Log4j, and MOVEit. Experts emphasize aligning developer incentives, embedding product security within product teams, improving secure developer experience, and adopting frameworks like NIST SSDF and OWASP SAMM, while expanding visibility and vetting for commercial off-the-shelf software. The piece contends CISA’s current guidance remains insufficient for detecting integrity and malware implant issues and calls for crash-test–like evaluations of fully assembled software before release.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
