> Markdown version of [/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!? Tino Shock argues developers control critical infrastructure and require a professional ethical oath. Find out why fixing human flaws, not technical bugs, is the real key to cybersecurity. - **Speakers:** Tino Sokic - **Event:** World Congress 2023 - **Published:** September 27, 2023 - **Duration:** 27:36 - **URL:** https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece ## Summary **The Missing Piece in Cybersecurity.** In this discussion on software security, Tino Shock explores why cybersecurity is often the critical missing piece in modern development, arguing that developers and managers wield immense power over critical infrastructure. He draws a striking parallel between software engineering and highly regulated professions like medicine or aviation, suggesting that developers and stakeholders should adopt a formal ethical standard, akin to a professional oath. This accountability is necessary because security breaches consistently trace back to the human element rather than purely technical flaws or highly sophisticated algorithmic attacks. **Ten Non-Coding Software Vulnerabilities.** To illustrate this systemic issue, Shock outlines ten conceptual vulnerabilities that quietly erode software integrity. Critical failures such as poorly defined requirements, inadequate communication across teams, and a profound lack of proper documentation routinely compromise systems. He points specifically to technical debt where prioritizing "speed over quality" transforms temporary, insecure fixes into a new organizational normal. Furthermore, resource constraints, developer overconfidence, and a stubborn resistance to change prevent software teams from establishing an inherently secure coding culture. **The Human Software Development Life Cycle.** As a solution, organizations are encouraged to adopt the human software development lifecycle, a methodology that demands continuous user integration and rigorous evaluation across planning, design, coding, testing, and deployment phases. By actively fighting ego during user acceptance testing and investing heavily in the often-overlooked planning stages, engineering teams can systematically reduce friction. Ultimately, shifting focus toward transparent cross-team communication and human-centric design significantly mitigates the behavioral root causes of data breaches and insecure technical architecture. **Keywords:** secure software development, human element in cybersecurity, human software development lifecycle, non-coding software vulnerabilities, technical debt management, developer accountability and ethics, application security testing, secure coding culture, software project planning, user acceptance testing methodologies, cross-team communication workflows, behavioral root causes of breaches, continuous software security ## Chapters 1. **The growing power and security responsibility of developers** (00:04) — How developers and managers wield immense power over the security and stability of modern software infrastructure. 1. **Establishing an ethical oath for software engineering professionals** (04:29) — Why software engineering professionals and management teams should adopt strict ethical standards akin to medical practitioners. 1. **The fundamental human element in software security breaches** (10:13) — How human error remains the most common denominator in exposing highly sophisticated software systems to security breaches. 1. **Identifying non-coding software vulnerabilities and organizational risks** (11:21) — How systemic organizational issues like technical debt and poor communication create critical but non-technical security risks. 1. **Adapting the software development lifecycle for continuous planning** (16:51) — How integrating continuous planning, user experience design, and thorough testing improves the traditional software development process. 1. **Common cybersecurity mistakes highlighted through a musical performance** (20:49) — Common security flaws like hardcoded credentials and downgrade attacks explored creatively through a live musical performance. 1. **Clarifying the distinction between software vulnerabilities and threats** (25:39) — The critical distinction between an inherent core system weakness and the actual external threat that exploits it. ## Related Moments - [Bridging the gap between developers and security tools](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") - [Scaling security teams through developer advocates](https://www.wearedevelopers.com/videos/193-building-security-champions) (from "Building Security Champions") - [Identifying bottlenecks in traditional software security approaches](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) (from "Organizational Change Through The Power Of Why - DevSecOps Enablement") - [Engaging software developers deeply in secure engineering practices](https://www.wearedevelopers.com/videos/193-building-security-champions) (from "Building Security Champions") - [Making security a foundational feature in software development](https://www.wearedevelopers.com/videos/100358-always-on-the-right-track-with-rails-with-eileen-uchitelle-senior-system-engineer-at-github) (from "Always on the Right Track with Rails with Eileen Uchitelle, Senior System Engineer at GitHub") - [Setting the scene for real-world cybersecurity failures](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) (from "Checkmate: 5 Real Incidents That Can End a Software Company") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Exploring AI: Opportunities and Risks for Developers](https://www.wearedevelopers.com/magazine/522-exploring-ai-opportunities-and-risks-for-developers) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Staff Engineer, Security Engineering Partners](https://www.wearedevelopers.com/jobs/ext/1187268-staff-engineer-security-engineering-partners) at **Twilio** - [Senior Software Engineer](https://www.wearedevelopers.com/jobs/ext/15942-senior-software-engineer) at **GitHub** - [Tribe Lead - ( Software) Engineering Centre of Excllence](https://www.wearedevelopers.com/jobs/ext/1475530-tribe-lead-software-engineering-centre-of-excllence) at **SD Worx**