Turning AppSec into a Workflow, Not a Roadblock – Building Security Programs That Teams Want to Use

Channel:
Subscribers:
4,690
Published on ● Video Link: https://www.youtube.com/watch?v=tDbgqe0GQTY



Duration: 0:00
38 views
1


During the upcoming OWASP Global AppSec EU in Barcelona, Spyros Gasteratos, long-time OWASP contributor and co-founder of Smithy, to explore how automation, collaboration, and community resources are shaping the future of application security. Spyros shares the foundation of his talk at OWASP AppSec Global: building a DevSecOps program from scratch using existing community tools—blending technical guidance with a celebration of open-source achievements.

Spyros emphasizes that true progress in security stems not from an ever-growing stack of tools, but from aligning the humans behind them. According to him, security failures often stem from fragmented information and misaligned incentives across teams. His solution? Bring the teams together with a shared, streamlined flow of information and automate wherever possible to reduce wasted cycles and miscommunication.

At the core of Spyros’ philosophy is the need to turn AppSec from a blocker into a builder. Rather than overwhelming developers with endless bug reports, or security leaders with red dashboards, programs need to reflect the actual risk appetite of the business—prioritizing issues dynamically based on impact, timing, and operational goals. He challenges the one-size-fits-all approach, advocating instead for tagging systems that defer certain risks and encode organizational priorities in automation logic.

A major part of that transformation lies in Smithy, the platform he’s helping build. It’s designed to be “Zapier for security”—an automation engine rooted in open-source standards that allows for custom workflows without creating a tangle of fragile scripts. The idea is to let teams focus on what’s unique to them, while relying on battle-tested components for the rest.

Looking ahead, Spyros doesn’t buy into the doom-and-gloom narrative about AI limiting developer creativity. On the contrary, he argues that AI-enabled coding frees up cognitive space for better architecture and secure design thinking. In his view, creativity doesn’t die—it just shifts from syntax to strategy.

This episode is more than a discussion—it’s a blueprint for how teams can rally around a common goal, and how OWASP’s community can be the catalyst. Tune in to hear how open-source, automation, and human alignment are redefining AppSec from the ground up.GUEST: Spyros Gasteratos | OpenCRE co-lead and Founder of smithy.security | https://www.linkedin.com/in/spyr/

HOST:Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber] | On ITSPmagazine: https://www.itspmagazine.com/sean-martin

SPONSORS

Manicode Security: https://itspm.ag/manicode-security-7q8i

RESOURCES

Spyros' Session: A completely pluggable DevSecOps programme, for free, using community resources (https://owasp2025globalappseceu.sched.com/event/1whCB/a-completely-pluggable-devsecops-programme-for-free-using-community-resources)

Learn more and catch more stories from OWASP Global AppSec EU 2025 Conference coverage: https://www.itspmagazine.com/owasp-global-appsec-barcelona-2025-application-security-event-coverage-in-catalunya-spain

Catch all of our event coverage: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverage

Want to tell your Brand Story Briefing as part of our event coverage? Learn More 👉 https://itspm.ag/evtcovbrf

Want Sean and Marco to be part of your event or conference? Let Us Know 👉 https://www.itspmagazine.com/contact-us




Other Videos By ITSPmagazine


2025-05-28From Cassette Tapes and Phrasebooks to AI Real-Time Translations — Machines Can Now Speak for Us,...
2025-05-28Redefining What Secure Application Development Looks Like: Bringing Application Security into Foc...
2025-05-28From AppSec Training to AI Standards: Teaching AI to Code Securely | A Brand Story with Jim Manic...
2025-05-28When Simplicity Meets Strategy: Making Immutability Accessible for All | An Object First Brand Story
2025-05-28The API That Could Transform Software Transparency | An OWASP AppSec Global 2025 Conversation wit...
2025-05-28Redefining What Secure Application Development Looks Like: Bringing Application Security into Foc...
2025-05-28The API That Could Transform Software Transparency | An OWASP AppSec Global 2025 Conversation wit...
2025-05-28From AppSec Training to AI Standards: Teaching AI to Code Securely | A Brand Story with Jim Manic...
2025-05-28Redefining What Secure Application Development Looks Like: Bringing Application Security w/ ASVS v5
2025-05-28When Simplicity Meets Strategy: Making Immutability Accessible for All | A Brand Story with Sterl...
2025-05-27Turning AppSec into a Workflow, Not a Roadblock – Building Security Programs That Teams Want to Use
2025-05-26The 30s | A Conversation with Bryan Wish | After 40 Podcast with Dr. Deborah Heiser
2025-05-26The 30s | A Conversation with Bryan Wish | After 40 Podcast with Dr. Deborah Heiser
2025-05-26Agentic AI to the Rescue? From Billable Hours to Bots: The New Legal Workflow
2025-05-25Outside the Ivory Tower: Connecting Practice and Science—Why Human-Centered Cybersecurity Needs Both
2025-05-25Teaser: Measuring the Blast Radius of Tech Experimentation
2025-05-25Outside the Ivory Tower: Connecting Practice and Science — Why Human-Centered Cybersecurity Needs...
2025-05-25Agentic AI to the Rescue? From Billable Hours to Bots: The New Legal Workflow | A Conversation wi...
2025-05-25Agentic AI to the Rescue? From Billable Hours to Bots: The New Legal Workflow | A Conversation wi...
2025-05-25Outside the Ivory Tower: Connecting Practice and Science — Why Human-Centered Cybersecurity Needs...
2025-05-22What Helps You Sleep Better at Night: A Practical Take on Zero Trust | ThreatLocker Brand Story