Cybersecurity Insights with Chris Wysopal | RSAC Conference 2025
Chris Wysopal highlights the growing complexity of the attack surface and a positive trend in software security, with fewer vulnerabilities noted. DevSecOps is emphasized for better collaboration between developers and security teams. The role of generative AI in coding efficiency and the importance of security testing are discussed, along with Veracode’s Risk Manager tool and the concept of ‘Secure by Design.’
Transcript
Welcome back to Tech Tech on TV guys and Lisa Martin. Great to be with you. We are live at RSAC in San Francisco at Moscone West, having great conversations with leading cybersecurity experts across industries.
For the next four days of live coverage, Alan Shimmel and Mitch Ashley will join me in the next couple of days, so be sure to keep tuning in. My next guest is Chris Weal, chief security evangelist at Veracode. Chris, great to have you on text on Hi.
It's great to be here. You are an OG cybersecurity expert. You've been in cybersecurity space for probably, you said, you mentioned like at least 20 RSAs.
That's Right. Talk to me about the evolution you've seen because as technology advances, the good guys have access to it. Yeah.
The bad actors have access to it. We've got, we're in this AI era now, which just spreads that attack surface even more amorphously. Absolutely.
What have you seen that struck you over the last 20 years? Well, I mean, I think we keep making the problem harder and harder for ourselves, Uhhuh, because we keep making more software. We keep expanding our attack attack surface.
Someone was telling me today that, um, there's risky plugins for teams Now. I'm like, really? There's plugins for teams.
So like, there's just more and more software coming at us constantly being deployed and all of that software has risk. Yeah. And now we have AI generating code Yes.
Which means more software faster. Yes. Um, so I, you know, that's, that's what we have to do as a cybersecurity industry, is protect this evolving attack surface.
Yeah. Which the technology changes and, you know, the developers build new stuff. They change technology's on us, and I always feel like security's always catching up.
Okay. But I do think we're making good progress. Yeah.
Good. When I, when I, when I, when I spoke earlier today, my talk was secure by design. Are we winning?
Yeah. And what I wanted to show was there are some, there is some good news, there are some good indicators. And we derive this data from Veracode's customers, we call the state of software security report.
Yep. And in that data, it actually shows that over the last 15 years, there's less vulnerabilities in the software that vendors are producing. That's good.
And it actually was slow, very slow incremental progress for the first 10 years of the report. One, 1% a year improvements in apps that didn't have one of these au top 10 vulnerabilities in them. Okay.
But in the last five years, we had 4% a year improvement. So what Account for that acceleration? Yeah.
Well that's what I want figure out. Right. Okay.
Right. Right. I mean, it's, it's great to see the outcome.
Yeah. And then you try to figure out like what are the practices people are doing? What are the motivations that is causing them to make better software?
Right. And then, you know, I would say like, let's have more companies do that. Do you think that's a DevSecOps Absolutely.
Evolution. Absolutely. And developers and security folks finally coming together to collaborate A Absolutely.
I think the DevSecOps process gets that security more closely embedded into the actual development workflow and the whole shift left. Yeah. And it's not the only answer, but it is definitely one of the things that you need to do to make improvements.
And that has been a process change that's really taken hold in the last five years. Oh yeah. Well, it's cultural too, right?
I think that is one of them. Yeah. Developers are very aware of the security tools that are running now, where 10, 15 years ago it was something that someone else did.
And, you know, they, they pressured me to maybe fix a few flaws and I didn't really understand it. Now with DevSecOps, the improvement is, it's part of their job and, you know, we're, we're getting there. It isn't absolutely part of every developer's job.
Sure. But, um, I like to say it's part of the definition of done software is Yeah. The features are in there.
They've been tested and they work and it's been security tested and the security bugs fixed. Yes. Now it's done.
And so that process improvement is what's making one of the big improvements in, in this outcome. That's good. It's, I'm sure you were pleasantly surprised to see that increase after 10 years of, of very small incremental Right.
Improvements as you Jump 1% a year. I was like, and we were starting at, uh, I think it was 23% passing rate and we got to 32% after 10 years. I was like, I'm gonna be long retired.
Yeah. Before we get to over 50%. Yeah.
But then we had this acceleration in the last five years and I feel like we can actually improve things a lot over the next five. Yeah. Well, the, the challenge, it's kind of like a, it's a flywheel, right?
I mean, we're, you talked about we have so much more software now. Right. But that phenomenon is only accelerating.
It's not gonna slow down. So how does Veracode help get control for the developers? So from a business perspective, nobody wants to be the next headline.
Right. Is it possible to gain control over this? Yeah.
So yes. But it isn't something that happens overnight. And one of the big reasons is when you first test your software, you have years and years of security debt, all that time.
You weren't testing the software. You had vulnerabilities that you were completely ignoring. You didn't even know they existed.
Right. And then you, you sort of have to slowly drive down that security debt. You have to take, allocate a percentage of time.
'cause you can't do it all at once. You can't, like, um, I know Microsoft said they did this back in like 2003 with their trustworthy computing memo. Bill Gates said, we're gonna stop writing software.
Everyone's gonna learn how to write secure software. We're gonna fix all the bugs. Mm-hmm.
It's like, you just can't stop your company for a year, let alone a month. Right. You have to weave it in.
Yeah. And you have to, you have to have to slowly drive, drive that debt down. So that's what we do when we start engaging with a customer, is we put these tools in place, but we say you can't, you still have to keep shipping your software.
Yeah. And unfortunately, you're gonna be shipping software, whether it's to the cloud or to your mobile device or to your customers. OnPrem that has that has security bugs in it.
Yeah. 'cause you can't fix them all right away. Right.
But the the, what you want to get to is have enough capacity to fix at least the bugs that you're, the new bugs you're creating. So you sort of stop the bleeding Yeah. And you're not getting worse.
Yeah. And then you incrementally make, make pro process. So it, it typically takes a company a few years Okay.
To go from no process to being best in class. Okay. I would say like four or five years.
Oh, okay. So that's a journey. Yeah.
Cool. It's a journey As the, the evangelist. Where are you having conversations within customers?
Is it at the CSO level? Is it at the ELT level? Is it the developers?
All the Above. It's mostly with the developers. Okay.
Um, and that's great because like all the security people already know who I am. They know who Veracode is. They know what we do.
Yeah. Yeah. Um, but the developers have no idea.
Right. So like a company will have a developer day where they'll fly all their developers to one location and they'll have talks throughout the day. I love speaking at those talks.
Yeah. 'cause I get to engage Yeah. Directly with, it might not be the developers, it might be sort of the development managers.
Okay. But it would be developers and architects too. But That's your audience.
And that would, that would be the audience that I really like to like, to talk to Talk a little bit about. You mentioned the Secure by Design campaign. CISA launched that what, a couple of years ago?
Yes. It's been a couple years now. Yeah.
It's been a couple years. They launched their, uh, secure by Design Pledge Two years ago. What's the, what's the conceptually?
So Secure Philosophical by Design has been around for a long time in, in my talk. Um, and my co-presenter, actually Jason Healy, he's from Columbia. He's the security researcher.
He talks about, uh, a paper written by the Air Force in 1972 that actually said, we have no hope to build secure software unless we start from the beginning and build it secure by design. Oh, okay. So the concept isn't new.
Got it. It's just that people haven't been practicing it. Why do You think that is?
Is it behavioral? Because when you start building software, that's the time where time is the most precious. Mm-hmm.
Right. You're like trying to see if you can get the software to market. Yeah.
It might be a competitive situation where you're doing catch up with your competitor. I mean, the competitive pressures is the big reason Sure. That people aren't fixing flaws 'cause they need that feature.
Right. Or they have a customer complaining about something. So when you have those scenarios, the fixing a security bug becomes deprioritized.
Right. And I, and I think the Secure by Design is deprioritized because it's in the beginning of when you're building software, but unless you do it, you kind of have no hope over the lifetime of that software of having it be really secure. Right.
It's really hard to bolt stuff back. Right on. Like, if you look at what Adobe did with Flash, I dunno if you remember, but there was years after years of critical bugs in Adobe Flash.
This was really old software. Adobe Flash was created in the late nineties. Yeah.
And it persisted until, I don't know, like 2015 or something like that. And they finally said, we can't keep up with the bugs. Wow.
We're gonna, we're gonna, we're gonna, we're gonna terminate this software. Oh, wow. And, and we're gonna shut it down and end of life it.
Yeah. Um, and that's an extreme case. Yeah.
But it, it, it, it sort of shows the point because they didn't build it securely in the beginning and it was very popular, very critical piece of software and all kinds of websites. Yeah. Um, it was constantly attacked and they could never, couldn't catch up.
So that's sort of the worst case scenario. Um, but, but that's, that's, that's what can happen if you don't start secure by design. Well, it needs to be baked in from the beginning.
Application security. Where does that belong in production? It can't be a bolt on afterthought because we've companies time and again, have proved that doesn't work.
Right. Like the worst, the worst place to put it is like, well, maybe just scanning stuff after you put it in production. Yeah.
That would be the worst. But people, most people realize that, that that gives no time to fix anything that you find. So, uh, a lot of companies scan the code or test the code just before production.
Okay. But the problem is with DevSecOps, with so many quick iterations where you might be pushing code on a daily basis, there's no time to both test it and fix it and fix it. So you gotta, this is where the whole shift left comes in.
Ideally in the cust in the, in the developer's IDE or at pull request time when that code is changing, test it and you have the opportunity to fix it. Yeah. Then, then too.
But I think that that also is a little shortsighted just to shift left, because so we say you have to shift right too. Like you have to understand what's going on in production. Sure.
Because there's stuff in production that doesn't exist on a developer's desktop. It's interacting with the cloud environment that might be configured differently. There might be other software deployed in, in that, in production that it's interacting with.
So you need to test there too. Sure. So we say shift left and right.
Okay. Both as early as you can and in and, and in production to give you that complete continuous Picture. Yeah.
And that's one of the things that we're driving to at Veracode. We have this product called Veracode Risk Manager, which connects results found in production back with the results of your testing. Okay.
Back with the code and the root cause of the problem to, to, to make one coherent picture of risk and where to fix it. The best place to fix issues. So instead of fixing a hundred individual issues, if you can determine it's really just one issue.
Yeah. You want to do that. Yeah.
Go upstream. So that, and, and so that's, that's our drive is to constantly make things more efficient for the developers. Yeah.
'cause we know their time is so limited. Yes. Yes.
So we want the context point them Right. To the fix. And now we're introducing ai, generative AI based fixing.
Okay. So have the AI fix it. Yeah.
And if you think about, like we, we talked about velocities are getting quicker and quicker. Yeah. There's more code.
Generative AI is just making that go faster. Exactly. Right.
So I've seen data to say each developer can write 50% more code, um, using generative ai. Yeah. So now you have 50% more code per developer who's gonna fix the flaws.
Right. 'cause we can't, we can't just Expect it's gonna Be Secure. So you need to Right.
You can't assume that the generative AI stuff is secure. So we gotta test that just the same. But then you need something that can fix it.
Yeah. And so we are focused on automating the fixing process using jitter of AI as much as possible and make things that are reliable and built in that just maybe every time vulnerabilities are found in a pull request, automatically fix them. Yeah.
It sounds like what you're giving the developers is visibility. Yep. Way more visibility than they had before to really understand where things are, where the vulnerabilities are, how to fix them, allowing them to, to use gen AI to be more productive.
Which is what they want. They wanna write code EE Exactly. They wanna generate, they Wanna vibe code.
Yeah. They want a vibe code. Yes.
Who wants to look up for what this API's I know are, I know that's so hard. He already knows it. Yeah.
Just say, I wanna make a database call. Yep. Yep.
Yep. What's your favorite customer story of Erica that you think really shines a light on the true value you are delivering so that organizations can really become cyber resilient? Yeah.
That's a journey in and of itself. Yeah. So I, I think the way I like to look at it is, if we look at our state of software security report, which we came out in 2025, um, we, we, we look through the data and we have, you know, we have a lot of averages.
The average application, the average bug takes this long to fix. The average application has this many percent of OAS top 10. But then we split it into quartiles and we said, what are the organizations that are leading, what are the ones that are doing the best?
Yeah. And so it, it shows you what you as a organization, you can benchmark yourself against this data and say, I, I want to improve. I want to be like that.
So that's, that's sort of the story I like to tell is, you know, the, the best organizations are fixing 10% of all the security bugs they know about Okay. On a monthly basis. And is that acceptable?
10%? Yes. That will keep you your head above water.
Got it. That'll keep your head, that'll keep your head above water. Um, so, so we look at those metrics of the leading organizations, like how fast are they fixing flaws?
Is it taking them six months a year, or is it taking them 30 days? And then it shows you like, well it's, this is possible. Yeah.
This is possible to do. Yeah. I would love to add in survey data Yeah.
To say like, exactly how are you getting to these outcomes? Sure. Because we just see the outcome in the data.
Okay. We don't know what they're actually doing. That would be nice insight to have.
Yeah. So I, I would love, love to do that to tell a better story. So a a a customer or just any company can, can look at our, our report and say, if I do these things, I'm gonna get an outcome like this.
Right. And I don't have to just like, listen to something as a best practice. This is what companies that are getting these good results are actually cheating, are actually doing.
Yes. And I think that's con connecting practices with outcomes Absolutely. Is super important.
'cause we, everyone here speaking in all these halls is talking about what's the best way to do this? Yeah. What's the best way that, but they have to show that the actual outcomes are real world companies.
Yes. Or it's just a pipe dream. It's all about outcomes.
Yes. Last question for you as we're living in this AI era, you know, it's funny, AI's been around for decades, but chat GPT was born and then everybody is talking about AI and it's, there's a lot of AI washing going on. You can't go to a conference without hearing tons about ai.
But how in this AI era, you know, organizations, I talk to CMOs a lot, or everybody's embracing gen, ai, agent ai. How do you help organizations defend this digital frontier and the age of AI when the frontier is just continuingly changing? Right.
One of the challenges is just knowing where the AI is. Yeah. Right?
Like a lot of it is like it's creeping into all these different products. And like sometimes CISO are completely surprised that something has been transcribing all of their employee video conferencing calls. Yep.
Right. Oh, 'cause anybody can shadow it. Anybody can.
Yeah. You can just use order or zoom every, everything's got note takers. Totally.
So it's again, this AI attack surface Yeah. Is percolating through, through everything. And, and if say you're using a SaaS service and you're sending your data out of your enterprise somewhere else to be processed, right.
Are are they training on my data? Mm-hmm. Right.
Is there a chance that my, my, my secrets end up in, in the answer to someone else's support question. Yeah. Right.
So that's, those are the things you need to ask or CISO need to ask is where is all this AI activity happening? Because a, all AI has to learn from something, right? And there's so much value in AI learning from proprietary data sets.
'cause everyone can train on the open source code or all the, you know, published books out there. There's a lot of stuff they're not supposed to be training on, but they are. But there are, because it's because it's available.
Right. But if you have a proprietary data set you that gives you a competitive advantage. Okay.
And what's a great one? Like the data my, my customers are creating, right? So this is, this is one big thing that people need to be aware of.
The other one is, where is AI being built into my own software? Right? Like if I'm building a chat bot for my website is, is they hooking in Yeah.
Chat G-P-T-A-P-I into that thing and they're having it, it, it, it talked, you know, that's a risk. Now I can have things like prompt injection, right. Maybe attackers can get into my proprietary data through the chatbot Yeah.
My website. 'cause it has access to my customer records or something like that. So there's a risk of losing your proprietary data and there's a risk of, um, you know, by people training on it, but there's also this risk of attackers Yeah.
Using the AI you're building in to steal your data. Wow. So it's, it's a new it.
I I feel like it's the cloud era all over again. Okay. Where cloud changed everything.
Sure. I think AI is changing everything again. Yeah.
What's the one positive that you can share with the audience that, that you've seen from this evolution that we talked about at the beginning of cybersecurity? What's the golden nugget? We're going in the right direction here.
I think we are going in the right direction. Um, and, and, and the, so the big picture is like as this technology constantly changes, is it helping defenders more or is it helping offense Right. More?
Yeah. Right. And we have to constantly think like, how does, how, how, how does, how does defense constantly, how constantly get better.
Right? And one of those things is, is secure by design. Yeah.
Right? That is, that is something that, that helps the defense get better because you have more defendable software, less vulnerabilities, less patching, less incidents to respond to. Right.
So, um, I, I think the, the secure by design is definitely the biggest thing that I'm seeing as a, as a, as a, as a potential game changer. Excellent. Um, but I also think that this connecting the dots of, um, the technology with the root cause of the problems.
Yeah. So this attack surface management discovering vulnerabilities, but then connecting it back to the root, the root problem. This is giving us much better visibility.
Exactly. I was just Yes. Into risk.
So the visibility into risk is, is getting, getting better, better getting, but we have to act on it. Yeah. Right.
Like that's, that's that, that's, that's a Yeah. But you then you have to make improvements based on the information you have. You can't just get this great information then do nothing with it.
Right. It's a never ending story. Yeah.
Chris, thank you so much for joining me on Techstrong TV today. I learned so much from you. What you're doing at Veracode, what you're enabling developers to achieve.
That visibility, those blinders are coming off and that's so important as cybersecurity will just continue to evolve in good ways and not so good ways. Gotta stay a step ahead. We appreciate your insights.
Thank you for joining me. Thank You so much for having Me. Oh, my pleasure.
For Chris Wise Sopel, I'm Lisa Martin. You're watching Textron TV live from RSAC. This is day one of four days of coverage from techron.
Keep it on this channel. We've got more great content coming up. Thanks for watching.