Crash Override

Hooray! Security Teams May Still Be Accountable for Secure Software, but Developers Are Now Taking Responsibility for It and Here Is Why

Developers are finally taking real responsibility for secure code while security teams shift into trusted advisor roles. Here's why it matters.
By Mark Curphey
June 3, 2025

Featured

How to Uncover Potential Shadow Engineering Situations

The product walkthrough helps surface shadow engineering issues across your cloud infrastructure and explains what they mean for your team.
By Sean Clarke
April 30, 2025

The Curious Case of Shadow Engineering

By Mark Curphey
April 28, 2025

Code Ownership and Code Owners Files

This article explains why code ownership matters, what is needed in a code ownership system, and where code owners files falls short.
By Mark Curphey
April 15, 2025

Opengrep - The Security Industry Deserves Better

Opengrep, a fork of Semgrep, raises concerns in open-source security. This blog investigates the motivations behind Opengrep, defends Semgrep’s open-core model, and calls for industry accountability.
By Mark Curphey
January 29, 2025

Are there too many bubbles of similar security efforts?

Why we shouldn't work together for the greater good of the security industry
By Mark Curphey
March 26, 2024

SBOMs for Production Incident Response Maybe a Killer Trojan Use Case for Security

SBOMs are more valuable for platform engineers than they are to security engineers today, and why this will help security in the long run.
By Mark Curphey
November 14, 2023

Build System or Bust and Wrapping Security Tools Using Docker

Build System or Bust and Wrapping Security Tools Using Docker
By Mark Curphey
November 13, 2023

Security Quackery

The Dangerous Rise of the Security Influencers Who Shouldn't Be, and the Oxygen Sucking Echo Chamber It Creates
By Mark Curphey
October 26, 2023

The curse of AI in the security industry

What happens if everyone thinks AI is table stakes? It become a checkbox feature.
By Mark Curphey
October 5, 2023

Five Questionable Things About Top Ten Security Lists

Five Questionable Things About Top Ten Security Lists
By Mark Curphey
October 3, 2023

Building Security Tools is the Wrong Approach

Building security tools is the wrong approach
By Mark Curphey
June 13, 2023