> Markdown version of [/videos/357-climate-vs-weather-how-do-we-sustainably-make-software-more-secure](https://www.wearedevelopers.com/videos/357-climate-vs-weather-how-do-we-sustainably-make-software-more-secure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Climate vs. Weather: How Do We Sustainably Make Software More Secure? Code isn't regulated like physical infrastructure, but should it be? Learn how early threat modeling and high-confidence automation can secure your applications without killing delivery velocity. - **Speakers:** - **Event:** WeAreDevelopers LIVE - **Published:** February 24, 2022 - **Duration:** 51:41 - **URL:** https://www.wearedevelopers.com/videos/357-climate-vs-weather-how-do-we-sustainably-make-software-more-secure ## Summary The panel discussion explores the systemic challenges of integrating security sustainably into modern software development. A critical obstacle to producing reliable applications is the persistent tension between initial delivery velocity and long-term sustained velocity. Unlike the construction industry, which enforces rigorous safety and architectural regulations, software engineering often lacks standardized compliance checks. As developers rush to stack new frameworks and libraries, security frequently takes a backseat to deadlines and budgets, largely because foundational secure system design is rarely prioritized in academia or coding bootcamps. To shift from reactive patching to proactive defense, the panel advocates heavily for introducing secure design practices early in the development lifecycle. One of the most effective, yet frequently misunderstood, methodologies is threat modeling. Rather than relying on rigid compliance checklists, teams can leverage simple, conversational whiteboarding sessions or attack trees to visualize an application's architecture and identify potential risks before a line of code is written. Additionally, implementing secure code reviews allows developers to learn through immediate feedback without needing to instantly master complex security paradigms. While static analysis and automated scanning tools—both red and blue team variants—are essential for establishing a scalable security baseline, they cannot replace deep architectural understanding. The continuous issue of tool-generated false positives often creates friction, causing developers to ignore security alerts completely. Instead, organizations should prioritize integrating automation that delivers limited but high-confidence alerting, alongside robust unit testing and safe code abstractions. Balancing these technical guardrails with a frictionless developer experience ensures teams can sustainably secure their systems without compromising agility. **Keywords:** secure system development lifecycle, threat modeling, attack trees, secure code reviews, static analysis tools, false positive reduction, red team tools, blue team tools, automated unit testing, scalable security baseline, owasp top 10, vulnerability management, application security posture, secure software architecture ## Chapters 1. **Primary obstacles to achieving high software quality** (01:28) — Balancing initial development velocity against project budgets and deadlines frequently compromises structural security and testing. 1. **Addressing the lack of security in academic education** (05:07) — Integrating secure system development lifecycles into standard computer science curricula helps build foundational industry skills. 1. **Building multidisciplinary teams and integrating secure code reviews** (08:37) — Leveraging specialized team members and interactive code reviews offers a sustainable alternative to expecting uniform security expertise. 1. **Mandating software engineering regulations and security standards** (18:58) — Implementing government regulations and official industry standards could establish necessary accountability for software stability. 1. **Defining fundamental starting points for software application security** (23:05) — Commencing projects with strict security requirements and creative threat modeling prevents architectural flaws early. 1. **Implementing pragmatic security automation and analysis tools** (30:51) — Configuring linters and static analysis tools with custom rules reduces noise and builds maintainable testing pipelines. 1. **Envisioning idealistic improvements for software development workflows** (41:26) — Experts suggest mandatory security phases, reduced dependencies, and centralized knowledge bases as ideal industry transformations. 1. **Finding personal fulfillment in the cybersecurity industry** (47:39) — Protecting organizations and continuously exchanging innovative engineering solutions creates a highly rewarding professional environment. ## Related Moments - [Making security a foundational feature in software development](https://www.wearedevelopers.com/videos/100358-always-on-the-right-track-with-rails-with-eileen-uchitelle-senior-system-engineer-at-github) (from "Always on the Right Track with Rails with Eileen Uchitelle, Senior System Engineer at GitHub") - [Identifying bottlenecks in traditional software security approaches](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) (from "Organizational Change Through The Power Of Why - DevSecOps Enablement") - [Addressing developer adoption and future software security risks](https://www.wearedevelopers.com/videos/900-from-syntax-to-singularity-ai-s-impact-on-developer-roles) (from "From Syntax to Singularity: AI’s Impact on Developer Roles") - [Balancing engineering scale with limited application security resources](https://www.wearedevelopers.com/videos/1568-why-security-first-development-helps-you-ship-better-software-faster) (from "Why Security-First Development Helps You Ship Better Software Faster") - [Scaling security teams through developer advocates](https://www.wearedevelopers.com/videos/193-building-security-champions) (from "Building Security Champions") - [Bridging the gap between developers and security tools](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") ## Related Articles - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Staff Engineer, Security Engineering Partners](https://www.wearedevelopers.com/jobs/ext/1187268-staff-engineer-security-engineering-partners) at **Twilio** - [Senior Software Engineer](https://www.wearedevelopers.com/jobs/ext/15942-senior-software-engineer) at **GitHub** - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Senior Software Engineer, Enterprise Products](https://www.wearedevelopers.com/jobs/ext/1841248-senior-software-engineer-enterprise-products) at **GitHub**