All episodes
Episode 287 June 23, 2026

Tanya Janca, CEO of SheHacksPurple Consulting

Application security, developer education, and a crusade for the world's first secure-coding law. Interviewed by Frank Victory.

Our featured guest this month is Tanya Janca, known across the industry as SheHacksPurple, CEO of SheHacksPurple Consulting and best-selling author of Alice and Bob Learn Application Security. With 25+ years in IT and software development, Tanya joins Frank Victory for a deep dive into global security policy, developer workflows, and the gap between checked compliance boxes and truly defensive software engineering.

Plus, the segment that opens every episode: a roundup of Colorado security and tech news, this month covering the state OIT restructuring, Colorado's watered-down AI law, and fresh threat-intel and AI research from community sponsors.

In this episode

  • The policy vs. security gap. Why frameworks and initiatives like the U.S. SBOM executive order often favor visibility and tooling over actual vulnerability remediation.
  • Shifting left & secure guidelines. Why the industry catches vulnerabilities late through pen testing instead of setting secure requirements at the design phase.
  • The secure-coding law crusade. Tanya's petition in the Canadian House of Commons for an accountability-driven secure-coding law that could set a global baseline.

This month in Colorado security

The news & resources segment.

From the guest

Read the transcript18345 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

You're listening to Colorado Equals Security, your local source for regional security news, events, and interviews with leaders across our community. Here are your hosts, Chelsea Weiss and Joe McCallister, with interviews by Frank Victory. Hello and welcome to episode 287 of the Colorado Equals Security podcast. My name is Joe McCallister, and I am joined by the ever lovely Chelsea Weiss. Chelsea Weiss.

Hello.

Oh, I'm hoping you can't hear my notifications because I just of course got a ding. Do not disturb everyone, it's valuable.

Rookie mistake. D&D. Yeah, you would think after how many years and how many gray hairs I'd have this figured out, but nope. Nope. Now I've become the old guy that needs help moving the PDF to a doc and back.

All right. Let's get the best of us. What have I become? What I hate. That's what.

All right, let's kick— actually, excuse me, before we get going too far, this is the Colorado Equal Security Podcast, a security podcast for Colorado-based security professionals by Colorado-based security professionals. And we encourage you, before we dive too deep today, we've got about 10 news stories to get through and a great interview at the end of this show. But we encourage you all to go to colorado-security.com to check out our events, how to sign up for the news newsletter and get show notes delivered right to your inbox, as well as join our wonderful Slack community and just be apprised of all things Colorado and security. But we can jump right into the news of the month. First up, Chelsea, unfortunately, we've got to start with a bit of a downer.

We have some news out of the Colorado Office of IT, which we're saying unfortunately goodbye to about 15%, roughly, of individuals in the Office of IT Management as part of kind of a— it's, you know, it's one of those things with the news and headlines. It's kind of, I think, a purge is how it's been described, or an overhaul and things like that. But unfortunately, with the belt tightening a bit here in Colorado, it looks like they're hoping to save about $4 million in the first year and $8 million annually in the following years. But The interesting kind of thing that they feel like they maybe felt they had to put in this story was they are not linked to artificial intelligence use or the challenges of a state budget that faced a $1.5 billion shortfall, said David Edinger, the OIT's chief information officer and executive director. Rather, heaps of negative feedback from the state auditor, which I thought is interesting.

They were hoping to move what I would call a fairly ambitious goal from a score of 31— 36 is where they got to in the last survey percent. I'm guessing this is some kind of like an NPS type thing, but they were hoping to get up to 67, which I think is pretty, pretty ambitious. How do you kind of feel about the news and the story here? Yeah, first of all, sending positive vibes to those 173 employees that were let go. I wish all of you a prosperous job search journey.

And going back to the article, The leadership folks did say that structural change was needed in order for them to be able to move forward in a healthy manner. And one of the other takeaways that all of us need to remember is making sure that we're measuring the right things. Busy doesn't always equal effective. You know, we can be closing tickets all day long, running scans, producing reports, but if our stakeholders, or in this case, you know, where they got the satisfaction scores from, if those stakeholders don't feel supported, or those those risks aren't being reduced in a visible way, your organization is still going to be perceived as underperforming. So once again, friendly reminder to the rest of us, make sure we're measuring our results, outcomes, and making sure our stakeholders are happy.

Yeah, it's a good point. And I think maybe one more thing to tack on here that I personally have benefited from is our Slack community. So yet another almost instantaneous plug for going to colorado-security.com, signing up for the Slack community. There are career discussions. There's quite a bit of chatter around jobs that are put out there.

Come out, introduce yourself, reintroduce yourself if it's been a little bit, especially if you've been affected by this or any other layoff. I again have a fun story about how I credit the Colorado Ecosecurity community and we'll get to later, but Rocky Mountain Information Security Conference has a huge part in getting my foot in the door and remaining kind of in this community and having a career. So I can vouch for the success of getting out there and meeting people and staying active. Active in this community. Absolutely.

And another hats off to both Alex and Robb for starting and keeping this wonderful community going. We will move to our second article of the day, another one from the Colorado Sun. This one's Colorado's fierce 2-year fight over AI regulation ends with watered-down law, little fanfare. So this one, if you guys remember, we had the first in the nation AI law. And per this article, it was significantly scaled back, you know, 2 years after the initial debate.

The original requirements went for companies that had to explain AI decision-making, and the watered-down part is a more simple requirement to notify customers when AI is being used in major decisions, whether it's hiring, housing, etc. The implementation of the law itself was delayed originally from, you know, June of last year, I believe, to June of this year. And then or excuse me, June of this year to June of next year so that businesses and regulators can prepare. Joe, tell me your thoughts about this one. Yeah, there's, there's quite a bit here, of course.

I mean, it's, it's, it is the tale as old as time when it comes to legislation that comes out, uh, usually fairly bold and, and gets some of those initial headlines. And then by the time it makes it into effect, uh, which this one is still— has been kind of delayed again. I think it was slated for July and now looks out to 2027 for efficacy and enforcement. But it's— it is different, definitely, than what they had put in originally. And I think what is the statement that I love from the Senate Majority Leader Robert Rodriguez was everybody lost and everybody won.

I think it is a fun peer into the politics of the intersection of politics and technology in Colorado. I also love— I shouldn't say love. Maybe it's a sickness as actually that is the commercially reasonable kind of the legality and the jargon that we get to use when we're talking about technology and discussing with my legal team of how we can define or how we can scope or how we can interpret these different things. But I am proud to be, you know, in the state that is pushing for this and had, you know, again, like you said, Chelsea, the first of its kind uh, legislation, and it, it will someday here, uh, take effect. Yes, absolutely.

And that's a good note to end on. Kudos to Colorado in that aspect. Yes. Now on to one of what I will say, uh, one of my favorite stories, which is from Westward. Denver ranks amongst the most exciting U.S. cities to drink in right now.

Uh, the local cocktail scene has actually kind of exploded in an interesting way over the past couple of years. The state's always been known as a beer state. I think it's still kind of, at least in my heart and in my mind, it remains a beer state. But the cocktail scene, as Westward puts it, may be entering its golden age with Yacht Club being named Best US Cocktail Bar by the Spirited Awards and a couple other, 3 other in the running for Best New Bar from Spirited Awards as well. So I think it's an interesting honor to be bestowed upon the city of Denver.

Chelsea, do you have a favorite establishment, especially with Armistice coming up? There's going to be more than one happy hour. Yes. So the ones that were called out, like you said, in this were Yacht Club, Lady Jane, Peach Crease Club, Semi Previous, Occidental Bar. I am in the suburbs kind of down south.

I have not been to any of those because they're downtown, but I have a good list of places to visit for those folks that are further, you know, down toward me, Castle Rock Monument, Larkspur area, Provisions in Castle Rock is absolutely phenomenal. I was just about to say yes. And not only is this the rise of the cocktail culture, but another thing that I really like about, um, what I really like about, you know, this article and just being in Denver and Colorado in general is the amount of really great non-alcoholic options as well. Yes, I love beer. Non-alcoholic beer, I have not found one that I really enjoy, but it's the opposite for non-alcoholic cocktail options.

Lots of really great stuff out there. But to your point, this is the same exact evolution that we saw with, with craft beer a decade ago. So another point for Colorado. Awesome food, awesome beverage scene. I will say, thank goodness we still have a very active populace because I know plenty of places in, say, the Midwest where I hearken from back in the days that are great drinking towns, but they're also great eating and doing nothing else towns.

So you tend to not get back out and on your bike or on your jog and, and able to burn off those excessive calories from the beverages. Yes, all in time. All right, speaking of walking and burning calories, actually that leads us to our 4th article of the day: Denver Airport plans pedestrian walkway between concourses. This one comes to us from the Denver Business Journal, and essentially DIA is building a pedestrian walkway that connects concourses A, B, and C, which is an alternative to the iconic train. The project will repurpose some of the existing underground tunnels that we have right now, which is a lot actually, and construction is expected to begin in 2027.

And the article also talked about how DIA is doing this in preparation for a future of 100 million annual passengers. Joe, question of the day: would you rather walk 15 to 20 minutes between the concourses or take the train? I think, you know, maybe this is the elder millennial in me, but I am the guy that has to get there 2+ hours early. I reserve my time at— use Denver Reserve for my, my TSA, uh, if I'm not using PreCheck. Uh, I don't have CLEAR, I'm not that fancy, but I have to walk to and see my gate, uh, and I actually use my travel days.

I'm always pretty proud at the end of the day of having a ton of steps in. So I think I would take this, uh, as an option. I think it's great. I also am fortunate enough— knock on wood, because I haven't been traveling for a little bit, but I will be shortly— uh, have not been the victim of one of the unfortunate outages of the trains. Have you had to experience this, Chelsea?

No, hard pass, thank you. Oh, Thank goodness, because the photos and the sentiment are always— I'll call— I'll say passionate on social media. But I have seen a couple of instances of those, those trains and those poor travelers. And honestly, the poor— I always want to say DIA still. I'm one of those guys too.

But I guess it's technically DEN. Those, those folks that have to fix it and then bear the brunt of the, the feedback from the public when those aren't working. Oh yes, I'm grateful that we work in cybersecurity and do not have that job. Yes, absolutely. Well, on to our next story, another one from the Colorado Sun about inflation, the hot topic of, uh, basically everybody's televisions these days.

But the headline is Denver area inflation increases to 5%, blame energy costs, period. Uh, What we're kind of seeing in the Colorado economy today is that higher prices on the cost of gas and energy, which increased at double-digit rates while food was up only about 1.8%, still, still up. What I thought was kind of interesting is some of the graphs that are included over the past 6-ish years of inflation in the Denver area. There's some interesting kind of leader and like leading data points to what the US experiences. Right now we're seeing Denver is higher than at 5% than the 4.2% of the nation.

Interesting. Or interested to get your kind of take on this, Chelsea, especially because I feel like most of this story really keys in on what is essentially the higher gas tax for us commuters that have to go to the office. Yeah. And I really interpreted this one and it won't be a surprise to many people, but we just need to buckle up and prepare for longer periods of elevated costs at this point, whether it's gas, like you said, at the 42% increase, you know, apparel 14%, transportation 11%, food 1.8%. Like, it's all, all rising faster than groceries.

So I'm going to be staying inside for a while, Joe. Yes, I, I'm not the— I own 2 gas cars and I have been shopping recently for some, an alternative Come on, International Scout. I am waiting for that car to come back. Godspeed to you. We will transition to our security-related articles of the day.

First one is from Lares. This one's on how Lares thinks about Mythos-class AI and offensive security. So this one really digs into how AI vulnerability discovery has taken a leap forward. And the Mythos-class AI models are the ones that are analyzing large code bases, uncovering subtle vulns, that, you know, the rest of us may not see and help build out proof of concepts faster than the traditional scanners that all of us currently have right now. The article does a really good job of calling out the distinction between A, discovering bugs is not the same as validating legitimate attack paths, and then B, understanding the difference between lateral movement, privilege escalation, or business impact.

And I really like how it evolved on, you know, how offensive security is continuing to grow. If you have AI that's making vulnerability discovery much cheaper and faster, offensive security needs to be able to answer, well, how on earth would an attacker actually compromise us? Which I think is a brilliant question to ask. What were your thoughts on this one, Joe? Yeah, I think about this kind of in, in the context of, uh, how I'm thinking about security, you know, at larger scale of my organization.

Of course, you know, necessary disclaimer, I'm representing my own viewpoints and so forth, not of my employer or whatever my legal team wants me to say. But it is having— we're having a lot of conversations in the industry and with peers at other organizations as well, just about what— where the emphasis, where the energy of all of our security professionals and teams needs to be. And discovery is no longer really realistic. It is a— if you focus there, you're going to go from zero to burnout in 35 seconds. You know, we're looking at record speed and speed is starting to matter even more.

But where you spend your energy and harness that speed is the interesting part, right? We talk about more context, more validation, more exploit-driven discovery as opposed to whatever. You know, we're more worried about the KEV list than we are the CVE list these days and how well your controls can kind of figure out and detect real attack paths. And you're always going to, in my opinion, always going to need a human to really get in there and say, yep, that looks realistic and no, it doesn't. But you want to make sure you're feeding those humans actionable intelligence and stuff that's not going to just get them into what would be weakness fatigue.

Yes, absolutely. And that the last thing I'll say on this one, and it's actually to me happening kind of quietly, not usually as loud as a lot of our cybersecurity buzzwords. Words are, but, um, the evolution of vulnerability management to exposure management. So essentially, you know, not getting throttled by lack of prioritization, which is like a typical vulnerability management problem, whereas exposure management puts emphasis on the attack paths like you were just talking about. So healthy transition all around.

Absolutely. Next up, we've got a Blog post from Zvelo, our friends over there talking about security risks of agent-to-agent communication. And this is a— it is a great read. It's also a common headache I see with a lot of folks that I talk to, and I'm sure we'll probably hear more about this week at RMISC, good old NHIs and those identities talking to each other. But in the particular context of agents to agent, I liked how this article kind of went down the chain of, you know, assuming that humans were in the loop along the way.

And it is funny to me how many times I run into that assumption. You know what they say about assumptions, Chelsea. What did you think of this one? Oh, I don't think we're allowed to say A-S-S on here, are we? I can spell it out, though.

Yeah. So core, core challenge on this one is, of course, visibility. It made me smile only because, you know, if you look at the articles from last month and then the month before or anything in your newsfeed, you were spending a lot of time on how to secure those models. And now we are rightfully so migrating to, oh shoot, how do we secure the relationships between our AI agents? And it's just kind of fun to sit back a little bit and hop us from one to the next.

And I look forward to where that's going to go, but also to be able to predict where it's going to go next. But I will leave that there in the interest of time so we can move on. Next one, is from Red Canary. Thank you, ladies and gentlemen. Intelligence insights from May 2026.

I love these ones. They're super neat to read. I love to play the game. Oh, this happened to them. Did it happen to us as well?

Can't speak on that, but I will tell you guys what they're seeing so far. So first one is, um, fake CAPTCHA attacks are, you know, for the month of May, according to Red Canary, the number one threat trend. So there's a campaign right now called Clearfake, and it's moving to the top spot by compromising legitimate websites and tricking users into copy and pasting malicious commands into their own computers. So here, instead of exploiting software, threat actors, bad guys and gals, are exploiting the human trust component. Second big call of the article was how credential theft is getting a lot more spicy.

There's a malware family out there called ACR Stealer that is surging in popularity because it's writing on that fake CAPTCHA scam that I was just telling you guys about. So once ACR Stealer is installed, takes the passwords, browser data, financial information, anything and everything, and it can also download additional malware. The last one this article called out is the abuse of legitimate Microsoft 365 identities and how they're seeing a rise in attacks for the login processes, which are stealing authenticated sessions. Joe, any of these stick out to you as most exciting/scary? Well, yeah, it's always— it's all scary all the time.

That's the conversation that I always have with folks that are outside of the industry. And they're like, you know, how do you— how do you keep a clear head? And, you know, it's a healthy amount of paranoia is what I tell them. And there's— there's only so much we can do trying to keep our heads on straight. When I see ones like number 9 on the ranking of the top 10 being— excuse me, tied for 9th.

The Axios npm compromise. All the stuff about npm just makes me break into a cold sweat pretty much weekly. But I thought it was also fun to see some stuff— legitimate RMM tools, Screen Connect, and I believe NetSupport is in there tied at 9th with Axios as well. But Screen Connect was up at number 2, just seeing RMM tools that I know are legitimate. However, you know, if you see them in your environment, but you're saying, oh, but we are a— be that a Kaseya or a— gosh, what are— there's a million of them out there.

Bomgar back in the day. What should be in the environment versus what should absolutely not be in the environment and how it got there is, is always a fun exercise. I'm the same. I take these articles and my detection engineering team is probably rolling their eyes because I've sent it over to them as well. And sure thing, Joe.

Yeah, we'll, we'll get to that when we get to that. But it is always fun to, to go kind of do some discovery. And the ACR stealer is definitely one of the coolest ones to— cool. Shouldn't call it cool, right? Don't give them any credit where they shouldn't get it.

Yes. Yeah. It's terrible jerks. It's terrible but fascinating. Tell me more.

There we go. Yes, exactly. I've also— I like how they highlight the legitimate ACR stealer in particular hijacking Claude installers. You know, the good old-fashioned Google something and the first result is not actually from, uh, Anthropic. Yes.

Yeah, surprise. So before we wrap that one up, just a couple of things to tell your family and friends and coworkers. A, stop copy and pasting commands from websites. B, MFA isn't always enough because they're no longer just stealing our passwords, they're taking our authenticated sessions after we've already completed the MFA. And then the third one is all of us to smile on because we spent years and years and so much training on telling people not to click suspicious links.

But now we're going to have to start teaching them don't follow suspicious instructions.

Absolutely. Well put, Chelsea. That is the best bow I could imagine for that one. So let's move right on to the Optiv blog, which gave us an advanced AI protections for CISOs, a practical punch list. Which I just stepping back for a second, I just love when we have a nice deterministic solution for a non-deterministic tool.

But this is a really nicely put, a great framing kind of up top just about the challenges. I think we're all fairly aware of this stuff and this is— it can be overwhelming when you start thinking about all of the things you need to go do. Even in this punch list, it is an 8-item punch list that I'll highlight very quickly here, which is establish AI visibility, ownership, and governance. Strengthen third-party risk management for AI and frontier models, harden core infrastructure and reduce legacy drag, implement AI-specific architectural controls, identity, access, and service account protection, monitoring, detection, and active defense for AI testing exercises and continuous validation. And finally, culture, training, and safe enablement.

All incredible concepts. That is, you know, to me reads as a 12 to 24 month roadmap just trying to get your head around some of this stuff. Chelsea, what did you think? Is there anything, especially in that list, that really jumped out as where you would spend your energy, have you the responsibility over these systems? The one that jumped out to me the most was just fix the fundamentals faster.

Like, you can't run before you learn to walk. You need to make sure that you have a really good foundation before you build anything AI-related on top of what you already have. So that's probably the one that I would say, you know, put a little star next to and bump that sucker to the top. But yeah, at the end of the day, we have to secure the model, but it's equally important to make sure that we're securing the connections around it, which I will transition into our last article of the day. Joe, drum roll please.

I can't.

Yes, all of you, wherever you're listening, on your car, on your desk, This one made me chuckle. So this article from FusionAuth, we surveyed more than 300 security leaders on AI identity. The findings are counterintuitive. So it talks about how 2 out of the 3 orgs experienced— excuse me, 2 out of 3 orgs experienced a confirmed AI identity-related security breach in the last year. So the surprise that made me laugh out loud is the orgs that were the most confident in their AI security had the highest breach rate of 84%.

There was a lot of talk in the article from the survey on how speed is what appears to be creating risk. So, you know, all of us are being pressured to aggressively deploy AI, hiring AI talent externally, rolling AI into production faster. And of course, because of that, you know, from this article, we're all seeing significantly higher incident rates. Interestingly enough, the companies that trained existing teams on AI as opposed to hiring externally, the ones that trained the existing teams only had a 33% breach rate versus 85% for orgs that are primarily hiring external AI talent. Also talked about how shadow AI is everywhere.

And nothing that really surprised me outside of this. Joe, were you surprised by any of this, or what, what made you chuckle? I, uh, that's the best way to put it. I honestly read this and was, was not sure at first kind of what I was feeling about it. And then as soon as I kind of saw the, uh, the confidence index versus breach rate, I, I did the, uh, sensible chuckle, uh, meme myself of nice.

And then there's the by revenue— what I thought was really interesting, the revenue band slash maturity doesn't necessarily mean anything really. Like, it seems to be something that is non-corollary to another data point within this necessarily. There, like, the confidence plus breach rate graphic of $1 billion plus being at 0% to me was like a real interesting, but under $10 million is 95%. So there's some really interesting data here. I would encourage everybody to go check it out because there is, as you said, confidence— like the headline from one of the subsections here being Confidence Tracks Velocity, Velocity Builds Attack Surface— hits me at my core.

Very much a well-written article as well. Like, I love the tone throughout this. It's not necessarily snarky. It's very matter of fact. But the the, the extrapolations we make from the data is, um, at the very least chuckle-worthy.

Oh yeah, I was, I was thoroughly entertained. I will— the last thing I'll say on this one is, you know, we, we, all of us are spending a shiz ton on, you know, AI governance and policies and awareness programs, but that is not what fraudsters and threat actors are attacking. They're looking at the identities, the permissions, and the access path. So if you can't answer exactly what an AI agent can access, what it did, and how quickly you can revoke it, you're probably measuring compliance, which is not helpful to the security problems you're about to have. So with that being said, Joe, that wraps up all of our articles for the day.

Oh, we did a great job, Chelsea. I think we crushed it once again. Lights out, just like champs. But I'm going to You just remind everybody here for the 3rd time. Yes.

Shameless plugs yet again for colorado-security.com, where we have multiple things for you to kind of stay plugged into the environment, the, the community. Right now we do have our salary survey going on. I am administering that and need more participants. So take your opportunity to find that in the Slack channel where we have links. And if you don't have one, you can ask me personally for one.

I'll be at RMISC this week and happy to give out some of the links to get that. It is a great way for us to get a pulse on the local salary data. But we also have the links to the Slack channel. Past shows are up there as well as our wonderful events calendar, right, Chelsea? Absolutely, which leads me into a friendly reminder for everyone because you haven't heard it 15 times this podcast.

RMISC starts tomorrow, the 23rd, and it goes through the 25th. Once again, great opportunity for networking, learning new things, and engaging with others. Joe, what else do we have going on this month? We have— I'll just tack on real quickly to RMISC being downtown Denver, there's, you know, quite a few of us being in the area. There's also going to be quite a few events and happy hours and stuff like that.

So if you have some friends in the space, make sure to tag along to those events. If you don't have friends, RMISC is the best place to make them. But ISC² Pikes Peak has their June chapter meeting on— I believe we have it June 24th, which would be Wednesday evening. And we also have a happy hour on the calendar. I won't name the vendors because there's going to be tons of them.

But like I said, there's going to be quite a few happy hours and events around the convention center. Tuesday, Wednesday, and Thursday. Yes, and then our last event of the month is going to be a beer garden at Catalyst Campus with ISSA on Thursday evening, afternoon, evening, afternoon, all day. It says all day. That can't be.

Sometime. We'll get back to you guys on this specific time. Well, hey, it's— I'll spend all day at a beer garden. You don't have to threaten me with a good time. Yes.

All right. Well, with that, that is episode 287 of the Colorado Equal Security Podcast. Chelsea, thank you so much for always being a great partner and having fun with me on this one. Everybody listening out there, tell a friend, review us on your pod catcher of choice, and we'll see you next time. Thank you so much.

Farewell, folks. Bye.

Good morning, good afternoon, and good evening. This is the Colorado Equal Security Podcast. My name is Frank, and I have a very, very special guest today with Tanya, and hopefully I say your, your name correctly here, your last name, Jan. Yeah, yeah, I should know that because Tanya was a keynote speaker at my SnowFROC conference. Very, very successful. I'd like to say, I think it's like a very, very successful conference this year.

2 days for the first time, and we have so much positive feedback. So Tanya, welcome. Thank you so much for having me. Yeah, so Tanya is the CEO of SheHacksPurple Consulting. She is a trainer as well.

She sits on the advisory board for Smithy and Catalyst, which is also run by, or at least associated, I guess, with our another local star here in Denver, Dustin Lehr. And Dustin's been on the podcast as well. And you're also a faculty member of IANS. So I used to be. I actually stopped being a faculty member of IANS last year, and now I'm a board member for the Before we get started, one of the things that I always like to do is ask you an icebreaker question.

I very specifically don't prep my interviewees for this one. Okay, so how would you change your life today if the average life expectancy was 400 years? Oh, hmm. Oh, that's such a good question because I, hmm, I'd have to save a lot more for retirement, I think. Okay.

I think maybe I would go— I think maybe I'd go slower on things and not push as hard. Okay, slower. But I mean, when you say save for retirement, would you still work for 70 years and then retire for 300 years or 330 years? Yeah, 330 years. I think that what I would see as retirement might be different, if that makes sense.

Okay. Okay. Like a lot of people, when they retire, what they do is they stop doing the career they've been doing and they, they choose a different thing. And that thing can make money or not make money. And so maybe what I would do is more things that cost, that make less money, but that still bring lots of joy.

But I'm, I'm already doing a lot of that. Like, this is the 5th podcast I was on this week. Okay. Because I love talking to people, and I, I, I, I love being able to like get a message out or talk with really smart people. And so I do a lot of things where they don't make money, but they bring me joy.

And so for instance, like the conference last week. I managed to tie a contract in there, so it paid for itself. But mostly I was like, I want to go to Denver and have a whole bunch of fun with friends. Like, yes, there's marketing involved, but like, is that the thing that's going to make me all the money? No, I just wanted to go have a really good time.

And so I think maybe I'm already doing a lot of things that are more fun than, than work, but maybe I would slow down further. Maybe. I don't know. We'll see, I guess. Okay.

Well, you know, obviously I don't know your other podcasts, but I'm going to say that this is going to be the best one that you're going to do this week. And there are lots of smart people on the podcast, or at least listening to the podcast. As cybersecurity matures, governments around the world are struggling to keep pace, not just with technology, but with enforcement regulations and defining what good security actually looks like. In this next segment, we're going to dive into the differences between privacy and cybersecurity policy, why some regulations fall short in practice, and how even well-intended initiatives like SBOMs can create visibility without necessarily improving security. It's a candid conversation about where policy helps, where it lags behind, and the unintended consequences that happen when compliance moves faster than real risk reduction.

Please listening to the podcast. All right. So, you know, we're going through your profile and you are an international traveler. And I think what you live in Canada, but you've been all over the globe. And I think one very unique perspective that you can provide is how does cybersecurity compare to other parts of the country?

You know, think about maybe your last few trips. Does any of the laws, the regulations, the attitudes affect cybersecurity over there? Oh, they absolutely do. I would say that in my opinion, Canada is behind other— so if you've heard of the Five Eyes countries, so like New Zealand, Australia, the United States, the UK, the US, we tend to be like in a group and Canada tends to be waddling along at the end usually. We're doing a great job at privacy.

We've really led the way for privacy for many, many countries with our laws that we make. However, we don't enforce them very well. So for instance, I made a privacy complaint maybe 7 years ago because I'd bought something from a pharmacy and then a pharmacy sent an email with all of us in the to field that had a specific medical condition. And guess what? One of them was a journalist.

Yeah. Okay. Yeah. And so when I, when I reported it, the Privacy Commissioner of Canada responded, well, did they apologize? And I was like, yes, they said sorry.

And they're like, well, I'm sure they're punishing themselves enough. So that's it. And I'm like, okay, there should be a fine or something. They're like, oh, they've promised not to do it again, and they're very, very sorry. They told us, so it's okay.

I'm like, are you kidding?

Well, I'm pretty sure, you know what, I'm not a lawmaker or anything like that, but I'm pretty sure here in the US that would be resulting in a lot of fines, violations of privacy, etc. Um, okay, something more than a verbal apology. Um, okay, but, but when it comes to cybersecurity So privacy and cybersecurity are similar or like maybe in the same wheelhouse sort of, but they're not the same. And I would say that Canada is far behind in my opinion. I would say that also a lot of things just aren't in law yet because cybersecurity is quite complex because we can't agree upon things because someone gets this great idea and runs with it and it's not the best idea.

Yeah, so for instance, you know, when the American government issued the executive order about S-bombs, everyone that is into S-bombs was like, this is great. And I was like, this is like spitting into a bucket one time and being like, the bucket's full. To me, S-bombs was a huge miss, and people get really upset with me. I do think they add value, but I would have much rather than say, like, because the executive order for those living under a rock is that, you know, companies must create a software bill of materials, an SBOM, and have it available to customers if they ask of what the ingredients are, essentially the third-party libraries, components, et cetera, that are included in their software. And I do think that's good.

And I do think we should have that. But my gosh, like instead it could have been, you have to do that, but you also have to scan it for vulnerabilities and you can't have like criticals and highs in there. There. Or you can't have criticals and highs that are reachable from within your code. And like, it's up to you to figure out if they're not reachable.

And if you can't figure it out, well, then you, then you can't have them. And you, you can't release to the public known super vulnerable software. And so then everyone went and bought an SBOM tool instead of a software composition analysis tool, which I feel would have added a lot more value. Like, it's nice to know that I those 47,000 things in my SBOM. I have no idea which ones have sharp edges.

Mhm. In cybersecurity, we love our frameworks, checklists, and compliance metrics because they make us feel protected. But are we actually becoming more secure, or is it just better at proving we check the box? In this next segment, we're going to dig into the uncomfortable gap between theory and reality, from OWASP guidance to secure coding practices to harsh time constraints of adversary simulation and application testing. We explore what happens when organizations confuse following the framework with truly understanding risk and why limited testing windows may leave critical vulnerabilities untouched.

It's going to be a candid conversation about tension between compliance practicality and real-world security effectiveness? Well, and I think in general, so I think in the surface, right, from what you're saying, it seems like it's a protection, but is it really protecting it? And we can apply that to other things like our frameworks. And so, for example, I was talking with someone yesterday and they said, well, we follow the OWASP Top 10. Great.

What does that Well, they recommend this. Great. Show me what you actually did. Well, we followed the recommendation. Okay.

This is becoming a very circular argument and it can— we have to break the cycle because unless you follow every recommendation in the OWASP Top 10, because I wrote that, I'm on the project team. I, me, Neil, Source, we wrote that. And so if they actually follow all the mitigation advice in the 10, plus FYI, spoiler alert, there's 3 extras in the What's Next section. So if you do the advice, like, you'll have a robust security program, like, you'll be doing pretty well, but I bet they're not. Oh, well, I mean, you can't get that test, right?

Well, well, here's a question for you, and this gets into one of my talks that I'm working on for Adversary Simulation. Is the timing part of this. They're only allowed to have so much time, and quite honestly, as both you and I know, and probably all the AppSec practitioners in the audience know this as well, you don't have enough time to test everything that you want to test. Otherwise, the test is going to be 2, 3, maybe even 5 weeks, and you get what, 1 week maybe, right? If that.

So, you know, again, How does that affect our security? Right. From a timing perspective, do you think that from, you know, a secure coding perspective as well as an offensive security, how effective are we becoming?

So those are sort of 2 questions. Yeah. So I don't like to think of the security program as just the testing part. To me, if we want to build secure software, we need to start with security requirements that are clear and precise for every single thing we build. I think that we need to have systems set up to help us build better software.

So for vibe coding, we have guardrails, secure defaults, and other things set up within the AI systems to help us make better code every time we write code. I think we need to have training so we know what secure code looks like, so we understand what we're trying to do. I think that when we do design, there needs to be assistance to make sure that design is safe and secure. And if we are doing all of those things leading up to the test, the test is going to go way better. We're going to have way better results.

There's just going to be way less to find. And so if we, for instance, are like, well, we're going to do 2 weeks of testing instead of 1, we're sacrificing a whole bunch of other things for that. And that's not where I personally would choose to make the sacrifice usually, because you're gonna find most of the juicy goodness in the first few days. I know that if we keep testing and we use different tools, especially if we have different opinions, especially if we have human and AI opinions, we will find more creative things. And, and that's cool.

Testing's important. But I feel like as an industry, we focus too much on testing. And you wanna know why, Frank? Because vendors can sell sell tests. And that is an easier thing to sell than creating a secure system development lifecycle that is adjusted for the new AI reality threat landscape.

Cough, cough, cough. But it's true. And so we, I feel, focus on that a lot more heavily than maybe we should. We focus a lot more on tooling, than on processes and actually investing in our people. And I know I sell training, so like take all of that with a grain of salt, but I, I sell it because people just kept asking me to do it.

Do you know what I mean? And because I'm trying to solve this problem and this is one of my efforts to try to solve some of these problems. Well, okay. And I'm going to launch kind of a counterpoint here with the, with the security requirements. And you knew this was coming, you know, they're not going to see the video.

This, but I can see the look on your face. However, we all talked about this, the security requirements. We need more time. But business, on the other hand, is going to say, you don't get it. You don't get that time.

You need to get this done. And everyone that's a developer, that's in the business process, or, well, let's just say everyone listening to this podcast knows that this is a reality. We don't get the time. So how do we create that equal balance? Or, you know, is there a formula?

Is there a secret formula to do this? Or, right, is this something where, you know, we have to think less of the two evils?

I have so many thoughts. So one is you have a great big breach. And then from then on, you do prioritize security because you've been burned so badly. That is a strategy a lot of companies are doing. Doing.

I just met with a big company and we're gonna do a whole lot of stuff because their competitor, their direct competitors just got popped inside and out and very publicly and very bad. And they're like, we would like to not be them. We would like to fix all the things before then. Please come on down. And I'm like, great.

Um, so, you know, don't waste a good Okay. Well, let me give again. Let me let me offer another counterpoint here to this and to that specific point. For I know companies that have been breached, and I've been with them, you know, or anything like that, and they get breached, and all of a sudden, oh well, we got to spend more money on cybersecurity. And I was actually explaining this to one of my students the other day.

I was like, oh, isn't that great? We're gonna actually get money for this. Well, what happens? We don't use that money within, let's say, 30 days because we've got to prep up, we've got to do bids, we've got to hire people, etc. And then we don't use that budget.

So on maybe day 31, they cut that budget in half because it's not as important, it's not sensationalized anymore. And then 30 days after that, that budget, that half budget gets cut in half again or goes away entirely. So again, the reality of that, and maybe, you know, in the situation that you were just speaking about, you know, how do we deal with that? What is the effects? Every security professional knows this feeling.

The risks are real, the vulnerabilities are piling up, and the answer is always the same. We don't have the time. In this next section, we dive headfirst into one of the biggest battles in cybersecurity: the collision between security requirements and business reality. How do you protect systems when deadlines are non-negotiable? Why do organizations suddenly care about security after a breach, only to lose momentum weeks later?

And is there actually a sustainable balance between speed, cost, and protection. This conversation gets brutally honest about budget cycles, breach-driven panic, executive priorities, and the uncomfortable truth that sometimes security only becomes a priority after disaster strikes. So I have an answer that I want that I don't know if anyone else will enjoy. And what— so there's a few things. So the first thing is, is I currently— and we talked about this before the podcast— so I'm a one-woman crusade against the Canadian government.

So I worked for them for 13 and a half years, then I left, and then I have been lobbying them ever since I left because I'm like, haha, screw you, I'm gonna quit and work for you for free now because I'm an idiot. And I have right now a petition in the House of Commons supported by my of Parliament, and we've been doing a letter-writing campaign. And his predecessor, we did a letter-writing campaign for a long time to all of the ministers that are appropriate and all the shadow ministers, which means the, the other political party's representative for each minister. And so the, the petition is to have the first secure coding law in the world. So the entire government and all of the Crown corporations and everyone basically related to the government, which have to follow a policy.

And of course, obviously, I wrote the policy and sent it to them as well as a suggestion based on my most recent book, like kind of boiled down into 84 items, which I share freely on the internet if you want to go get it at securecodingguideline.com. So, it's free, you can go get it. It's not written as a policy, it's written as a guideline, but that's fine.

So, the idea is, is that if the government must follow this law, that private industry would see this as a standard that they could follow. Right now, there isn't really something like that. So there's— so everyone's going to argue with me and they're going to say, but there's OWASP ASVS. And if I want to do a pen test, it is great. If I want to do verification, because guess what ASVS stands for?

The Application Security Verification Standard. And it's the things to check after that you did right. Then there's OSAM, the Software Assurance Maturity Model, and that's to check that your application security program is thorough and good and to help mature it. And it's good. These are useful things.

I'm not saying they're not great, but we don't have a, this is how you write secure code. This is what you do. We just have a, you did it wrong later. And I've always been like, why are we catching them after? Why are we telling them how much they suck later?

Why aren't we showing them this is— please do it this way? And so that's my goal with the guideline. That's my goal with this law. So there would be direct guidance and people that work in the government would be held accountable. So in, in the petition, it asks specifically that there's a governing body, and I would like the one called CSEC, the Communication Establishment Security Canada, Communication Security Establishment, CSEC.

Anyway, whatever, wherever their acronym currently is, because they change it around a lot. All right, let's zoom out, because everything we just talked about— the grind, the sacrifice, the ridiculous job requirements— that's just not an individual problem, it's a structural one. And here's the thing: Canada nor the US has figured this out. They're just failing in different ways. Canada wraps everything in frameworks, baselines, and performance indicators, but that doesn't magically produce job-ready people.

The US has its own stack of frameworks and audits, but the industry still posts unicorn job descriptions no human could ever meet. So in the next section, we're going to break down how Canada measures cybersecurity performance, how the US approaches it, and why both still leave new professionals stranded between, I have a degree and I can actually do this job. So let's get into it.

But have them verify it. And they have amazing, brilliant humans there that could definitely do some ASVS at anyone any day of the week. But if we had something like that, just like ISO 27001, like this could be a thing that people hold themselves accountable to because there is one for secure software right now. And like, I know that a lot of companies are like, oh, well, we're NIST compliant or we're this or we're that. It just touches the toe into code.

It doesn't cover secure design. It doesn't cover secure coding, most of them. It's like, you should secure your supply chain. End of discussion. And it's like, what does that mean?

How do I do it? What are the steps? I would like some clarity, please. Please. And so I, I've tried to be like, walk that line between being way, way, way too specific and writing a 450-page book and creating a checklist of things that people can go through and they know they have or have not completed each item.

And I feel like if we had that, that would be a start. Like the executive orders, like you have to make an SBOM. Well, if there's an executive order that was like, this is the secure code standard. And if you want to sell stuff to the government, you have to follow the standard. Do you think that's going to really be effective though?

I mean, you're talking about stuff to the government, but the government, right, and what's being sold to the government is probably a smaller portion that's being sold to consumers. Would that adaptation, would that law— let's say you brought that law here to the US— would that become you know, effective. We could also then turn it into a standard, turn it into some sort of compliance, like ISO 27001. That wasn't one person's crusade. It was many people working together over a long time.

But if it became a law, it'd be a lot easier to say, like, this is— I need you to know you're compliant with this or I'm not going to buy your stuff. It would be a thing that people who don't understand the details can say like, I want it, you know, I want you to be SOC 2 compliant or I'm not going to buy this thing. They don't know what SOC 2 means. They just know that that's the good checkmark that they want. And maybe that's all they need to know though.

Yeah. I mean, when I buy a car, I want to know it's not going to crash into the other car. I don't want to touch anything. I don't want things to touch my car. I don't want other cars and my car to come into contact or humans.

I want to stop when I do the brakes. And I know because of the automotive industry that it's going to pass certain tests. And we don't have that for cybersecurity. And I want us to have that. And so that would be like one thing that I would want us to start with.

Another thing that I want, and like, I'm really like throwing the gauntlet down here, is like, I think a lot of the AppSec tools are not working. And now that we're live coding, they're really not working. Well, before we get into that though, actually, before we go into that, I'd like to go back into the law portion. Just to continue on this portion here. When we talk about the law, let's say that this goes exactly the way you want and it becomes a law in Canada.

And I'm a coder, I'm living in Canada, or I'm doing something like that. And I don't follow those rules. Do I get arrested? No. Do I go to jail?

No. So the, basically then your code doesn't get to go to prod and you have to, you have to fix bugs. And that, that is your punishment. You have to fix your bugs and it'd be considered a bug if it's not following the policy. And, or maybe let's say that an organization decides to publish anyway, then CSAC censures them.

They're like, they send them a strongly worded letter and they tell them to fix those bugs. And then maybe like the 4th time it's like, well, we're going to fine you or not approve a project that you want, or there'll be some sort of governmental punishment. And like that developer, what— so I worked in the government a long time, so we have these things called PMA, Performance Management Agreements, or whatever. So it would go into their agreement that it's like, well, you know, they didn't follow this. And they pushed code to prod that they knew violated this thing.

And like, you know, instead of getting a 3 out of 5, they're going to get a 2 out of 5. So 3 out of 5 means you're good. 4 out of 5 means you're really, really, really, really good. 5 out of 5 means we have to promote you and put you through a special plan and you walk on water and you're magical. 2 out of 5 means you're like, and then 1 out of 5 is like, you need to really pull up your What Tanya is mentioning is a cybersecurity performance management plan, and it's driven by CPIs.

Those CPIs include things like mean time to patch, or MTTP, MFA enrollment rates, and incident response times. But in the US, we have something equivalent in there. We have FISMA, right? It's the Federal Information Security Modernization Act, and our metrics are MFA deployment, vulnerability vulnerability remediation speed and government's accountability. Can we measure those 2 against each other?

Are there things that we can measure against? And what do those measurements actually mean? Everyone listening to this podcast knows that these metrics are only as effective as we make them to be. So how can we actually make these meaningful to upper management And actionable by the people with hands on keyboard. So you're out of here.

Okay, well, let me go back to a point that you did earlier and kind of along the same lines here, relate this back where they sent an email to you and to all the medical conditions, and now everyone on the email knows who has this medical condition. It almost sounds, and then, you know, what was the punishment? Well, we're really, really sorry about this. It almost sounds like the same thing. Yeah, so maybe they— the enforcement won't be harsh is what you're saying.

Um, I still think that across the board we'll get way better code. I think that right now the average— so when I go in to teach secure coding, I would say like 95% of the time I am the first teacher of this topic they've ever had at that org and for every single person. So sometimes maybe if there's 30, 40, 50 people, one of them had training at a different place they worked at before, and, and that's it. So unless I'm coming back— so I do come back to clients, like some clients have me every year or every other year or whatever, but I, I've almost never— it's very, very rare that I'm not the first. And as a result that means that a lot of this is new.

So some of them are like, oh, I know injection's bad and I know I need to use an ORM. But then we start talking about like LDAP injection and command line inject or like command injection and operating system. And they're like, oh crap. And we talk about input validation and like what an allow list is and how that's not a block list. And some of them are like, well, what if we were doing that?

So at some point, every time you do training, someone puts up their hand and they're like, so I know you said we're not supposed to do this, but what if we were? And I'm like, okay, let's talk about that. Let's talk about how we can reduce risk. Let's talk about what we could do instead. And so if we had a law and it was like clear what the— there would be education on it.

They would cover it in colleges and universities, maybe. They would certainly cover it in security awareness at work or something. Then they would have guidance for the first time. Do you know what I mean? Well, I know.

Yeah. Well, you know, I think one of the things that they're trying to start teaching here in the US is to try to bring cybersecurity into the high schools and even in the middle schools so that it's not a shock to them. But the feedback that I'm getting and what I'm seeing in front of the courses honestly is not effective because they're not teaching the real stuff. They're doing very generic frameworks. Now, maybe they're targeting it towards appropriate audience.

Okay, well, here's your Instagram, here's your TikTok account, what you should, shouldn't do, etc. But they're not teaching that true awareness. And I have to tell you that some of that failure is going to be because the people that are writing the course don't really know. They're reading an article and they said, oh, well, I read an article somewhere, so I'll write a course on this. But they're not practitioners.

They don't know firsthand. And again, you know, going back to your training and what you were saying, how effective is this going to be? I mean, you know, how effective is ISO, you know, 27001? How effective is the OWASP training? I mean, obviously, as the president of the Denver chapter, you know, I think I believe I have to memorize the OWASP Top 10 and sing it every night.

But But is it really effective?

Okay, so I have a lot of thoughts. So there are a lot and a lot of brilliant people in cybersecurity that are terrible teachers. Yes, agreed. Absolutely. I took a workshop recently on AI security, and the guy teaching it, he was clearly extremely knowledgeable.

He clearly knew it inside out, but his teaching style was hard for to follow. He spoke very quietly. He let people speak over him. He did the LLM OWASP Top 10. So for those of you listening, there's 37 different top 10 lists.

And so this one was about, you know, AI. He did it in, I think it was 12 minutes. That's pretty fast for 10 extremely complex abstract concepts if you didn't already know them. Wow. 12 minutes.

Yeah, maybe 13. It was very very, very fast. And as a person that's already read it, I had trouble following. And I'd taken my Ritalin that morning and I was like excited to be there. Right.

And so, um, not everyone's a teacher. And then on top of that, we have so many people who think they're a teacher who aren't. So for instance, I was at an event recently and a person was telling me how she was going to make an app to educate women about cybersecurity and that she wanted to like target women with this app and like this was her startup idea. And then she was telling me she wasn't sure if password managers were good or not. And like, like she clearly didn't know her stuff and was planning to try to educate other women.

And I was like, so you're going to go out and harm women with your ignorance. I totally— oh, okay.

Like, and her specialty was marketing, and she's like, oh, but I'm going to be an educator like you. I'm like, oh, you're not going to be like me. And I politely excused myself because I was like, sometimes you should just shut the fuck up, Tanya, because I don't want to discourage people from starting companies and doing great things. But then the security advice she was describing was incorrect, and I was like, oh, I'm going to disagree with you on this one. Well, actually, I'm going to disagree with you on that one.

And maybe some people disagree with me and what I educate on too, right? Like sometimes people are like, you're a little strict. I'm like, yeah, that's true. But we have— and same with 2 trips ago, I had a man tell me the same thing, that he was making an app to educate. And the things he said, I did agree with his advice.

And but also like he's not a teacher and he was like, yeah, everyone's going to have this daily lesson. That they're gonna learn and just like memorize. I'm like, no, no one wants that. The average person, no one wants that crap. Like, he's like, wow, he didn't say Duolingo, but he kind of described like the idea of Duolingo.

Like, if you do it 5 to 15 minutes a day, no one gives a shit. That's a layperson that wants to have 5 to 15 minutes a day of cybersecurity dry lessons from a smart person, like, who's knowledgeable but again isn't a teacher. And yeah, so everyone thinks they're a teacher. Everyone thinks they're a content creator. And like, I think I'm one so clearly, like I'm one of those.

And so what makes me right? What makes one, one or both of them wrong? Everyone, all 3 of us definitely have the best thing in our heart to try to help. Everyone wants to help, I think. I don't think anyone's like, I'm going to educate and do a bad job on purpose.

This. But we have everyone wanting to create content and do things and making videos. And oh my gosh, Frank, like I post on LinkedIn and all these places. People started using AI to analyze my posts and then write a response. And they write a book as like a comment on my LinkedIn posts.

And they're like, what do you think? And I'm like, well, Claude, here's what I think. And I I want to be polite, but it's so very obviously that an AI wrote it. And like, usually they're— usually it's just, it's several paragraphs to say they agree with me. And yeah, Claude is not brief in any way.

But, you know, it's— yeah. The education, we need to be very careful when we take someone's time and attention. We need to be very grateful for it. We need to plan, like, it can take hours to make a 5-minute video, so you get everything you want in that 5 minutes as effective as possible. And I don't know if you know, but I used to be a professional entertainer when I was younger.

I did not know that. So, so I used to play music. I played guitar and I sang folk music, then punk rock, and then I learned drums when I was later, and then I switched to comedy because I wanted less money and less respect. And I played the Vance Warped Tour one year. I was in Rolling Stone.

I did like a whole bunch of stuff when I was younger. And so then when I teach, it's like, I guarantee we're gonna have freaking good time. And, and I learned how to learn. So I'm also dyslexic and I have ADHD. And so as an adult in Canada, I had to learn French if I wanted to progress my career in the government.

Learning to speak another language as an adult is hard, but when you have dyslexia and ADHD, let me tell you, it kind of sucked. And so I went to a special school where I learned all the different learning styles. And so when I teach, I try to teach like several different learning styles in every single lesson so I can catch as many low-hanging fruit as I can. And when I went to school, Frank, they did not do any of that. Like when I went to college, it's like, I'm gonna drone on, on this one slide for 45 minutes, or I'm gonna just talk and have no notes for Or I'm just gonna say, read the textbook, you know what to do.

Like they, they didn't care about the, I'm trying to hold your attention. They didn't care about like what value they're offering. They didn't, it, it's just, it was more like, if you can keep up, good. And if not, drop out. Like I remember a professor saying, so we had to create, we had to write our own compiler in college cuz I, I took computer science, surprise.

Um, and I remember him saying Um, 40% of you will drop out and 50% of you will fail this class. Of 100 of you, 14 will pass or something, or I can't remember what the number was. Wow. Okay, this is your textbook. I'll see you next week.

Well, okay, so I have lots of comments on that. I mean, first off, as far as the not caring part, that's my sister. And every time I try to explain my job, she tells me to shut up because she doesn't care. She doesn't understand it, doesn't want to understand it. However, However, do you understand her job and all the ins and outs of her job?

And should you have to? Okay, fair enough point. And I think I actually would say the same thing. When I drive a car, I don't want to know how the brakes work and I don't want to have to install them myself. And if I get into an accident because my brakes don't work, I don't want to hear how users are stupid.

So that's what we do. That is a very good point. But, you know, it's funny is that I was teaching at the community college levels too, on another, you know, especially on the teacher point. And, you know, there was somebody from my company that was going to actually take over my class because, you know, for certain reasons and say, oh, I've got to take the cybersecurity class. And, you know, here in the US, they're very protective on their content, right?

Especially in the community college areas. Well, you know, as you know, in our cybersecurity world, we're very giving. So I actually gave her almost over 100— almost, I think it was like 50 gigs of material, labs, systems, etc. Here's a whole lesson plan, everything else. And, you know, including things like starting off with using Nmap and what the results were, blah, blah, blah.

One of the students from our class came to me and said, here's our first lesson, to sit at Starbucks and count how many people leave their workstations unlocked. Um, what? That's the lesson? And then the next lesson was go back to the same Starbucks and see a comparative value. I'm like, how is that helping?

I mean, you know, you're not teaching anything of value in that class. And I don't understand why the college is allowing that. Of course, it was what, 2018, and they were still teaching Windows 2000. So I'm like, you know, this has been EOL and Their answer was, what's EOL? Oh, okay.

Um, yeah, so anyways, so you're right about not being teachers, and there are a certain blend of people, and they have to be able to convey their point. They also have to keep it exciting. They have to be interested. They have to be passionate about it. Because again, I know several people that know their stuff very, very well.

You know, one of my, my first mentees, absolutely brilliant, but he says, I can't teach He, he barely admits it. I can't teach. I can't talk to people. I can do it. I just can't do anything with it.

So, you know, we're in that dilemma and the people that can do it sometimes, like if we look at the SANS organization, they overcharge for it. Yeah. Yeah. I feel like, so education's very expensive, which is why I wrote the books and why I'm doing free live streams of my books. So basically, I— when I wrote my first book, I reached out to every university and college I could find contact info for and said, I really want you to teach my book.

If I make a lesson plan, will you have one of your professors teach it? And they were like, no, you can come teach it and we'll pay you less than minimum wage. And we will then own all your intellectual property after. So they offered me— each one offered me between $3,000 to $4,000 Canadian, which is about $2,500 American to maybe $3,200 American, to work for 4 months, 20 hours a week, not including marking the exams. So I would have to do— or no, it's 10 hours a week, so 2 3-hour labs and a 2-hour lecture And then assignments and like marking the assignments is going to take 2 hours, more than 2 hours.

Then I, I have to also then mark all the exams. And I was like, you measure your profit in millions, some of them hundreds of millions. You can pay me like a decent wage, but you can't pay me like I would make more if I was a Walmart greeter. And they're like, oh, well, you should do it for the love of this and that. And I'm like, oh, do you let the students students come in for the love of it, or do you charge them through the nose?

Because you charge them a lot of money, and so you could pay me a good wage. And none of them agreed. So what I did is I streamed free lectures for my first book, and I have started streaming lectures this month for my new book, Alice and Bob Learn Secure Coding. So if people want to go to that, either follow me online at SheHacksPurple everywhere, and you'll see— eventually you'll see invites, or just join my newsletter at newsletter.shehackspurple.ca, and I will just send you an invite every month. I send you one email with a silly meme, what I'm up to, free gifts, all the content I've created, and then events that I'll be at, and including these free book streams.

Because I'm like, well, if I'm going to get paid almost nothing, why don't I just do it on my terms for nothing? And then If I sell a couple extra books, that's great, but the purpose is to support the people who have bought the books in their, in their learning. Yeah, and you know, I think that's the other part within cybersecurity. I mean, we will post all those links that you just mentioned in the show notes so that everyone listening to the podcast can simply just click on the links, even though of course we're clicking on links, but we are— we will go ahead and post those. There's a moment in every cybersecurity career where the truth hits you.

The field doesn't care about your degree, your GPA, or your fancy certificate hanging on the wall. What matters is what you do when no one's watching. It's Friday night, your friends are out, the world is relaxing, and you're staring at a terminal window deciding who you want to become. In the next part of the conversation, we get brutally honest about the sacrifices, the grind, and the uncomfortable reality that most people simply won't commit. We talk about the students who show up excited and then the tiny fraction who actually follow through.

We talk about the myth of hundreds of thousands of open cybersecurity jobs and the truth behind why so many graduates still can't land an AppSec role. And we dig into the industry's obsession about impossible job requirements, like demanding 12 years of experience in a framework that's only existed for 5. This is the part where the gloves come off. This is a part where we talk about what it really takes to break into cybersecurity and why the system is failing the very people it claims to protect. I think the average person, the average person coming in, this can't be a job where you're just going to come in and say, well, I have a degree and here you go.

You're going to have to work on it, and you're going to have to make sacrifices. Today is Friday. It's Friday night. Are you going to go out and are you going to party? Are you going to study?

Are you going to hone and practice your skills? Or are you going to go out drinking with your friends? You have to make that decision and decide what's important and what you want. And I have mentored literally hundreds, you know, I, my student count is in the thousands. I personally mentored probably 50, 60.

And I'm gonna have to tell you, of those 50 and 60, maybe 5 have actually committed to it. And I find that very disappointing, but yet I keep doing it. You know what? I, I wish that our field wasn't like that. I wish that our field was you could go to college or university and you get out and you know how to do the job.

I wish that, um, we had less burnout because— so I'm not— so you are correct that if you want to succeed, you need to do those things, but I wish that wasn't the case. Does that make sense? Because I went to computer science and after— well, actually, I'd already been working as a developer. Like, I was working as a developer in high school. Like, I'm that nerd.

The moment I turned 18 years old, I got my first job and I'd already been programming for years, but I started out like my first startup at 20. I was like, let's freaking do this. But like the students that graduated in my class, they all could just get a programmer job if we hadn't graduated in the year 2000 where everyone lost their job, right?

But when you graduate from cybersecurity, you don't have the skills to be an application security professional. Don't— like, you can't just walk into a job. And there, there was someone that published an article a long time ago that many of us quoted, and I quoted, where they said there was like a million jobs or something, or 100,000 jobs with like no one qualified to do them. And it turned out all of their data was complete bullshit, and all of that was wrong, and there actually never was like hundreds of thousands of jobs with no one to do them. Um, I feel like— like, like, I, I have to disagree with I agree with you a little bit on that.

Maybe not on the number of jobs, but I do recognize that there are not enough qualified jobs. And if I go back to my own previous comment with the other teacher where we're teaching them how many people are leaving their laptops unlocked at Starbucks, that is not a skill that anybody's going to hire for. And no one cares, right? Yeah, I agree with you. I agree with you that colleges and universities are not properly preparing people to do the jobs.

Job. I also think the industry only wants to hire senior people. Like, I had someone— so I think I'm, I'm year like 12 in cybersecurity now. So it was like 3 years ago when I was like year 9. And basically someone sent me this job description for an AppSec engineer and it said 10 years hands-on AppSec experience.

And I wrote back and was like, I can't, I don't qualify for this job. And they're like, oh no, but you could have it. And I'm like, no, But I literally wrote the AppSec book. I speak at conferences worldwide. I've done this 9 years.

I feel I'm extremely competent. I don't qualify for this job. Who the hell is going to be able to qualify for this job if I don't? How many people on this planet do you think qualify for this job? Can we talk about these requirements?

Because, and so we ended up changing them and he ended up hiring a friend of mine who had 3 years experience, and she kicked ass and took names all day long there. And like, we have a lot of people saying, well, I need 12 years experience in this framework that has been around 5 years. And so that is also part of the problem of like, we don't have people that are qualified. I think another thing, Frank, is that what it means to be an AppSec engineer or even a cybersecurity professional or even any sort of IT professional right now, because AI is changing things so quickly, we don't even know what that means.

So yeah. All right, let's shift gears here. Because the next part is big. Everyone's talking about AI changing everything. But almost no one is talking about the part that actually matters.

Developers have become the new attack surface, not the code, not the pipeline, not the supply chain. The humans who touch all of it. And when you compromise the developer, you don't break just one app, you break everything they can reach. That's the real story behind the so-called supply chain attacks we've been seeing. So in this segment, we're getting into why attackers are targeting developers, how the entire ecosystem is wide open, and what it's going to take to fix it.

From secure defaults to new tools to an actual maturity model for developer security.

And yes, but you know what? And of course, AI is always a hot topic. So let's switch gears a little bit. And I'm looking at your, I think probably, I think it's your most recent blog post. And you're talking about AI literally changing everything.

But now how developers are the new attack surface. Can we talk about that a little bit more? Yeah. So I have strong opinions, which I guess is why I'm on a podcast. So I'm one of those nerds that like reads reports sometimes.

And so the Verizon breach report, the CrowdStrike report, like there's a bunch of Mandiant releases, cool stuff. About giant breaches. So I'm not talking about like, you know, this is the incident I responded to Thursday. These are big, huge breaches. If we look at the past like 3 years, they're like, oh, it's all supply chain attacks, supply chain, supply chain.

Because if you get an injection in an app, you own one app. If you're a malicious actor who's ridiculously lucky, they have not patched that SQL Server or whatever thing you injected into. And perhaps if you are extraordinarily lucky, you might be able to pivot inside the network. You might get further. But if you break part of the supply chain, then you could get to multiple apps.

But here's the thing, Frank, is if we look at these big breaches like XE Utils, the Kodak, Codev, there's like, there's a bunch of big examples and that's fine. But well, everyone's been calling them a supply chain attack, but I'm gonna politely and respectfully, because I'm Canadian, disagree and say that what was actually compromised was an individual software developer. And then it broke open multiple parts of the supply chain in one second. Because when I was a dev, I touched everything. I had, oh, I had access to everything.

And so if someone had compromised me, not only could they, you know, publish to production, they could change the code, they could turn off the SAST check or the block from the SAST, the static application security testing tool. Like, there's so many things that you could do if you compromise the developer. And so developers, in my opinion, have become the new target, and they themselves have an attack surface. And so in the workshop that I gave, I believe at SnowFROC last week, I talked about how like I've created a framework and a maturity model that I'm hoping to release this summer at Hacker Summer Camp. So I've applied to the various conferences with it and one of them is going to say yes, and then I will share the framework publicly.

But I believe that the software developer has many different parts of their attack surface, like the CI, the code repository. Most people are like, like, think about this, your CI/CD, your continuous integration and delivery you, that's their pipeline, the thing that releases the code for you. It's so powerful, Frank. It can call out to the internet, it can download things, it can execute things, it can copy things from here to there. It has secrets all stuffed inside of it.

And most, most organizations do not have that locked down almost at all. And they certainly aren't monitoring it. They're monitoring it? Well, it goes back to speed. Hey, you know, I mean, Tanya, I'm sure that you can write some great code if given a month to do it, but what if we say, okay, and you've got 3 days?

How secure, how much of an app can you write in that time frame? And, you know, even if we went in the middle, uh, again, we're watching for that developer, you know, we have to at least trust the developer. And, you know, I can tell you that I used to work for a medical insurance company, and it was kind of along the same lines of where we were trying to make things convenient for the developer, right? Or in this case, a database admin. And that was the purpose of the compromise.

So, you know, how are we going to deal with this, or is there a solution to this? Oh yeah, for sure there's a solution to this. There's, there's 2 potential solutions in my brain. I'm sure there's more. So one would be new tools.

Actually, I have 3 thoughts. New tools. So a supply chain tool that actually secures the entire developer attack surface, which will be complex because it would have to integrate with so many things. A second thing would be that the tool makers make all of the defaults secure defaults. So for instance, like when you run your CI, the thing that the service account, you know, where you check your code in and it promotes the code to different environments, you have one service account for that.

But then the service account that goes from pre-prod to prod, the one that actually is a different service account. What if we made that a default and all the CIs are like, Nope, you can't have the same service account for those 2 things. You have to separate them. So for instance, in npm, when you install a dependency, automatically the default is that post-install scripts can run. So you go install a library and all these new npm attacks, almost all of them, it's a post-install script that runs.

Well, what if the default— so I tweeted this at npm yesterday because I'm freaking jacked I was like, dear npm, will you please make the default that post-install scripts don't run? And that people then have to manually enable the post-install. So, they have to think about it. And there's this pause, this moment of friction where they're like, oh crap, I didn't know this had a post-install script. Maybe I should review it before I let arbitrary code execute in my production environment.

Like, what if all of them decided to have secure defaults? So that, that is a harder thing. And then like a, a third thing would be like what my effort is, which is like releasing a framework with a maturity model with specific steps of what to check and how to lock it down. And like, I can only do so much as one individual. So I can make a blueprint.

I'm honestly, I'm hoping that I can work with a company company that would like create a tool around my framework. So if you're listening, write me if you want to talk, because it's hard for me to say like, oh, do these 55 steps versus, oh, buy this tool that I know will do it well for you. All right, let's talk about insecure defaults because this one hits a nerve. We're doing cybersecurity for decades and somehow we keep repeating the same mistakes. Do you remember Windows in the early 2000s?

It was wide open. What about early AWS S3 buckets? They were public by default. And here we are again, acting surprised every time history repeats itself. Why?

Because technologists love shiny new toys. We get excited, we build fast, and we forget the guardrails. Not because we're careless, but because no one ever taught us the fundamentals in a way that sticks. So in this next part, we're diving into the psychology behind insecure defaults, why developers keep walking into the same traps, and how simple principles like least privilege and assume breach get lost in the moment a new technology drops. Let's get into the why we still haven't learned and what it's going to take to finally break the cycle.

You know, I've been doing this thing for, well, almost 30 years now in IT and cybersecurity. And if you remember back when Windows, I think maybe around 2005, something like that, everything was insecure because their open files was what everyone, you know, their file system was everyone, what, full read and write, full control. That was their secure default. Yeah, everything that was them, and then they made that change. When AWS first created those S3 buckets, those were, hey, everybody, anybody can look at that.

Why haven't we learned from those 2 examples?

So I have been writing about the psychology of insecure code and behavioral economics, and there's a heuristic or a bias this about this, and it's, I can't remember what it is, and I could look up what the name of it is, but basically we get so excited, so, so excited as technologists when there's a new technology. And it's normal that we would be. That's why we chose this field because we are excited by this. And so a new technology comes out and we're like, oh my God, serverless, this is so fun. And then we start building things and creating things because we are builders and we are creators and we forget about the safety measures.

And almost all of these things, Frank, it's the same couple fundamental things like the idea of least privilege, the idea of assumed breach, usable security, all of the things that I teach all the time. No one's— most people haven't been taught those. They might know the term defense in depth, but they might not know what is. I do this workshop all the time with clients where we go through each one of them and then we talk about them and how they relate to real life. So, like, give me, like, a real-life example.

Like, you go to the movies, how do you apply this? And usually they're just like, but this isn't technical, why are we doing it? I'm like, oh, because from now on you're gonna see it everywhere you frigging go. And then we'll go look at an architecture document and then it's like, now let's apply this here and, you know, talking about, you know, at your house you could have video cameras, you could have a dog, you could have this. Well, what are each one of those things?

How do we feel like one of the government agencies in Canada has a moat around it? A real moat. Like a serious moat. Like a, okay. Like a castle.

Okay. You don't wanna cross this moat and it just looks like a pretty little feature, but it's dangerous. And you don't walk through the moat. And like piranhas or anything like that in it, or shark with lasers? I don't know what's in it, but it's not, it's not safe to go in that pond that it's around.

Okay. And I, I feel like if we taught these concepts as part of computer science and computer engineering, and then we asked questions about it in their assignments, right? Like we would see it, but we're not teaching them. So how do they know to do it? Yeah.

And I fully agree because I actually just finished a 6-year stint or almost 6-year stint with multiple universities. And I was teaching what they called the higher-end classes. So I was teaching ethical hacking, DFIR, and threat hunting and intelligence. And it's so funny because they did teach in the, I guess, the more entry-level, the defense in depth. Great.

But no specifics. They didn't talk about your firewall, your IDSs, and more specifically how they interacted with each other and what happened with it, which prompted me to create the course that I'll be hopefully teaching at Hacker Summer Camp, right, with the adversary simulation and trying to really understand this more defense in depth, tying it to some of those frameworks. But is that a failure? My question to you, Is this a failure in our education system, and can we fix it?

So, I mean, I feel our education system is is not working. I mean, obviously, if I'm going around it and creating my own free education system because apparently I hate money, I I do think that. I do think it's a problem. So when, so my whole career, like, so I used to play music. I still love music so much.

I still love singing. But when I switched into cybersecurity, I just couldn't figure out how to learn the things I wanted to learn so I could do this job I really wanted to have. And so I got a professional mentor. The first one did not work out so good. If you read my books, you'll hear about the ethical issues there.

Then I got my second one. He is still a trusted advisor to this very day. I have many professional mentors. I now actually have accountability partners that are more like peers. I have someone who I'm adopting as my professional mentor, whether he knows it or not.

I just keep asking questions and then I go do it and then I close the loop and tell him what happened and I ask more advice and then I go do that. And I, I find all these different ways to learn because first of all, like attending a SANS class. I remember looking at it at the time and it was about $10,000 Canadian. And I was a software developer and I made, you know, about $106,000 per year, but we pay 50-something percent tax in Canada. So I only took home about $54,000 a year.

So I was like, so if I pay $10,000 Canadian for this class, that means I can't go to a concert for the entire year. And I, at the time, went to live music usually at least once every week. Like, I love music. And I, you know, I loved going to dinner with friends. I, like, I wouldn't say I'm a big spender, but the idea of having zero disposable income for an entire year so I could take one course, I was like, this is an unreasonable sacrifice.

And my budget was $2,250 from the government And you're not allowed to save it year after year. And I remember asking my boss and he's like, so you want to take our entire team's training budget just for you? And he just laughed and he's like, oh God, you're not kidding. And so I started speaking at conferences literally just so I could get in free. And I just, I was like, the joke's on you as if you just gave me a free ticket.

And all I had to do was hours and hours and hours and hours and hours of work for free to make this talk and do this research. And I was just like, so overjoyed to be able to see the other smart people. And then I started writing and started doing other things, and it got like basically all my hobbies completely out of hand. And now it's my job. But it's completely unrealistic to expect a person to sacrifice that much time and that much of their career just so they can learn.

It's so stupid. We need to have like a program. So one of the things that I did is I created my own academy and I sold it to Semgrep. And part of the deal— so the Semgrep folks, like the founders, they're really great. They're very likable people, the 3 of them.

And I was like, I'm only willing to do this deal if we make my academy free for the whole world. And they're like, great, we love giving shit away. We give Semgrep away for free. Like, yeah, let's do it. Um, and so you can take take my courses for free of how to become an application security engineer because I want people to be able to do that job.

And like, when I started, there were so few, and now it's like I have a path that I can show someone. Like, I'm like, buy my book, it's $27.50 if you get it through amazon.com, and then take these courses, it's free, and then, you know, find a professional mentor. And run Cyber Mentoring Monday on all my socials every Monday, and I have since 2018, to try to help people find mentors. I actually have instructions on how to get into InfoSec, the 12 steps that I suggest, on my blog, and I email that blog to people every single week. And like, I'm doing all the things I as one individual can to try to help people get into the field, but why the F am I the only one doing it?

I know Alyssa Miller wrote a book about the different jobs to try to help people figure out which job's right for them. So good job, Alyssa. And I know there's people like you that are essentially, essentially volunteering their time at the college. I'm assuming they're not paying anything close to what your day job pays. The next part's about repetition, reflection, and the one skill almost nobody teaches but every employer desperately wants: troubleshooting.

Not perfection, not memorization, the ability to hit a wall, stay calm, and figure it out. But how do we teach this? We teach them in a classroom. We teach stuff in a lab. But the problem that we have is that when we have— they do a lab, they do it one time.

And honestly, it doesn't mean a damn thing if you can't explain what you did, why it mattered, or how it reduces a risk for the company paying your salary. So let's dig into why labs need to be done 3 times, why failure is a feature, not a flaw, and why the people who refuse to give up are the ones who actually make it in the field.

In 3 different ways, if it's an abstract, complex concept. So I get doing a lot lab 3 times. I wish that you could somehow give like a small variation on the way they do the lab each time, because then they'll really learn it. Well, that was actually one of those things that I honestly, um, I, I kind of failed at, and I was trying to push with the community colleges, and I think we ultimately ended up leaving, right? Is because for one thing, we've got to teach less.

You try to, you know, there were some lesson plans, it's In a 3-hour class, you wanted me to teach 10 different subjects, right? Or 10 different concepts. No way that they are going to be able to listen to this and retain this. And I said, it's funny, is because I always told them, when we do these labs, we need to do them 3 different ways. We need to look at the results, including things like, what does this failure mean?

What did we do when it doesn't work? Because Because to me, that skill, that failure is one of the things that is a hireable skill. If you're trying to hire somebody at an entry level and you tell them to run Nmap and it doesn't work, do you want them to throw up their hands and go, well, didn't work, so now what? You know, I'm going to go play on my phone. Or do you want them to at least have some basic skills on how to troubleshoot it?

Why didn't it work? I wish that they taught taught troubleshooting in school. When I went to computer science, we had this class. So I suck at hardware. Software is my jam.

I suck at hardware. I know it. And in that class, they would bring us into this room and you had 2 hours to build a computer. So there were all the pieces in giant piles, and then you had to build a computer, turn it on, boot it, and show them that they boot. And every week we had to do it.

And guess what? A whole bunch of the parts were broken and they knew it. They're like, screw you, figure it out. And so I remember thoroughly testing a part and being like, it's broken. And the teacher was like, great.

And they threw it back in and I was so upset. I found the— so like some weeks I wouldn't get it started and some weeks I would. And like I passed the class and it was just the most frustrating class ever. And however, where it's like, you know, the time's running out, I have to have this machine booted or I'm gonna freaking fail. And so I got good at troubleshooting, and I did end up working at a computer repair store at some point after I got laid off in 2000, before I found my next software job.

But I, I feel like we don't teach that skill very much. Yeah, and then, but that is a hireable skill. And so, so, you know, right, do you show feel that you do it. Like, I used to have a different OWASP project, the DevSlop project, and we would livestream ourselves coding, building a DevSecOps pipeline. You know, we, like, we just, the 3 of us just would livestream ourselves breaking and failing and whatevering.

And I remember like this one day I just like could not get something going. And for like hours I just smashed away at something and my co-host Nancy. So the, the video was named Tanya and Nancy Fail. And Nancy was like, like 100 times I wanted to stop. And you're like, no, I have another idea.

I have another thing. Like, no, no, no. And just for hours I was just like, smash, smash, smash. And she's like, that's why you have your job, because you will not— you will not give up. And so I ended up just like trashing the whole thing.

And then redoing it from scratch and then getting it going the next episode in about an hour. And she's just like, you're just like relentless. And I was like, you have to be, or you're just not going to be a good dev. Like, we are down to the final question, the one I ask every guest before we wrap. No sugarcoating, no warm-up, just the thing that keeps you up at night.

What is the biggest security risk you are seeing right now. Not how do we fix it, not the perfect solution, just the truth. The risk that hits you in the gut when a big company calls you and says, we need your help.

Okay. What is the biggest security risk that you see today? Now, I'm not going to say solve it, but let's identify what it is. And if we can, let's try to keep it under 10 minutes. How about that?

The biggest cybersecurity risk in general or the biggest cybersecurity risk in software security? What bothers you? Like you come in and you go, hey, Tanya, I want to hire you. I'm big giant corporation. I want you to identify the biggest risk that I have.

Oh, um, yeah, I would say that the biggest risk I'm seeing, like, just quite recently is the use of AI and misuse of AI. And that, first of all, there's lots of employees using it that aren't using it effectively and efficiently, and they're just not getting their money and time worth. So there's that, and that is more like a business risk than a cybersecurity risk. And that then they are building things that are fundamentally quite insecure because there are no guardrails or there are like insufficient guardrails, insufficient defaults, etc. And so I feel like every organization needs to have AI training and policy based on how to kick butt at it and, and use this amazing new tool like a samurai sword in a samurai's hands, not in Tanya's hands, the klutz.

And then also how to make sure that they're using it safely and like whether that be a toolset, a policy training, et cetera, like all of the things so that they are enabled to do amazing, amazing things quickly and safely. Okay. Well, thank you, Tanya, for your time. You'll, of course, again, we can find Tanya on LinkedIn. We'll have the show notes there.

We have shehackspurple.ca, and please remember it is .ca, not .com. Familiar with it. It's what Black Hat, DEF CON, and BSides Las Vegas. Yeah. But there's another trip you were talking about as well.

Yes, I'm coming back to Denver, Colorado. Okay, or Aurora technically, for CppCon. So I'm going to do 2 days of training on secure C++, and then I also hopefully— I just submitted talks yesterday, and like me and the CFP, because I'm a trainer, usually your talk is accepted. And so I've actually submitted several talks, and so we'll see. So I submitted like a workshop to do threat modeling of embedded medical systems, a back-to-basics talk where it's like, let's just, all the rules of secure coding in C++, like which functions to use, which functions not to use, et cetera, memory safety, all that.

And then I submitted a talk about like how we can use the AI securely to make like really, really awesome modern C++ apps that are safe. And so hopefully one or more are accepted. And then I've been invited to do a lightning talk as well. So I'm pretty excited. So that is in September.

So if you just look up CppCon, you'll find it. And so I'm going to be in town in case anyone wants to hire me for anything else while I'm there. Because I, yeah, I tend to, when I go to conferences, I tend to also do like client contracts at the same time because why wouldn't you? Yeah. I'm looking forward to going back to Denver.

Denver has been quite lovely to me. It'll be my 3rd trip this year. So that's exciting. Um, yeah, and then I'm gonna be in Europe, in Norway. I'm doing lots of trips.

If I could promote one tiny more thing. Sure. I have a brand new podcast called DevSecStation, and it's on all the platforms. So if you just look up DevSec and then Station, and it's also on YouTube, and it is 5 to 10 minute lessons for software developers. And the first season is how to secure your supply chain.

I'll probably do secure coding in the next season. I haven't exactly decided what season 2 is yet, but if you have 5 minutes, you might want to check out DevSecStation. Yesterday we released an emergency episode about the new npm worm that's out. And basically I just begged my listeners, please, please, please, please turn off the ability to like just auto-run post-install scripts and here's how you do it. So I'm trying to help in all the ways.

So awesome. If people want to find me, if they just look up SheHacksPurple, they will find me. Frank, thank you so much for having me. Thank you for having me. Thank you, Tanya.

Thank you for having me on the podcast. Thank you. And for anyone that's following me, I'm Frank Victory up on LinkedIn, Professor Frank on YouTube. And again, hopefully we'll see— I'll be at BSides Tampa and hopefully at Hacker Summer Camp as well. Again, thank you, Tanya, for everything.

And I hope to talk to you soon and hope to see you in September. Awesome. Sounds great. Awesome. Thank you.