Hi [[ session.user.profile.firstName ]]

How To Determine What Your Open-Source Risks Look Like

38% of open-source libraries are active and only 12% of classes within them are actually invoked in applications.

Discover key findings recently published in Contrast Security's “2021 State of Open-Source Security Report.” Attendees will learn ...
• The average number of libraries in individual applications
• The average age of library versions and how this dramatically ratchets up risk
• The total number of vulnerabilities found in libraries
• The presence of potential licensing issues in open source used in applications
• Strategies and tactics organizations can employ to mitigate open-source risks
• And more …
Recorded Aug 18 2021 63 mins
Your place is confirmed,
we'll send you email reminders
Presented by
Contrast: Jeff Williams, Damian Horner, Katharine Watson
Presentation preview: How To Determine What Your Open-Source Risks Look Like

Network with like-minded attendees

  • [[ session.user.profile.displayName ]]
    Add a photo
    • [[ session.user.profile.displayName ]]
    • [[ session.user.profile.jobTitle ]]
    • [[ session.user.profile.companyName ]]
    • [[ userProfileTemplateHelper.getLocation(session.user.profile) ]]
  • [[ card.displayName ]]
    • [[ card.displayName ]]
    • [[ card.jobTitle ]]
    • [[ card.companyName ]]
    • [[ userProfileTemplateHelper.getLocation(card) ]]
  • Channel
  • Channel profile
  • Co-founders Discuss Key Takeaways from the 2021 OWASP Top Ten Oct 26 2021 5:00 pm UTC 69 mins
    OWASP CO-FOUNDERS: Jeff Williams and Dave Wichers
    The average enterprise uses 765 web applications to run their business, and many of these have serious vulnerabilities.

    Organizations around the world evaluate their application risk using the OWASP Top Ten. On September 24, the OWASP Foundation released the OWASP Top 10 2021. It’s been four years since the last release, and there are some notable additions, changes, and combinations.

    Organizations are recalibrating how they measure application risk and reevaluate strategies based on these changes. The co-founders of OWASP address the latest changes to the Top Ten and provide their perspectives on each one. Topics covered during the moderated webinar include:

    ● New entrants, deletions, and combinations to the Top Ten
    ● Risks—in terms of prevalence and likelihood to exploit—posed by each of the Top Ten
    ● How to use the OWASP Top Ten to evaluate risk and existing application security programs
    ● Potential application security gaps not covered by the OWASP Top Ten
    ● How to assess application security coverage based on the OWASP Top Ten
    ● Future trajectories for application cyber threats
  • Key Insights and Benchmarks from Contrast’s 2021 AppSec Observability Report Recorded: Sep 14 2021 60 mins
    Contrast Security: Jeff Williams, David Lindner, and Larry Maccherone
    The second annual 2021 Application Security Observability Report provides key insights and industry benchmarks on an array of different application security areas.

    This moderated webinar features three subject-matter experts from Contrast who will speak to some of the findings in the just-published report, including:

    • Discussion of the newly formulated vulnerability escape rate and how it demonstrates how well—or how poorly—developers are doing when it comes to writing and releasing secure code
    • The percentage of active application code is custom versus open source and what this means when it comes to risk
    • The median time to remediate resolved vulnerabilities—for Contrast versus other application security tools
    • Which vulnerability types are up, the ones that are down, and the ones that pose the highest risk in terms of likelihood and impact
    • And much more …

    This is truly a “can’t miss” webinar for the year.
  • Five Key Concepts for DevSecOps Transformation Recorded: Aug 31 2021 42 mins
    Larry Maccherone, DevSecOps Evangelist -Contrast Security; Jimmy Xu, Director of DevSecOps/Cloud Security - Trace3
    Larry Maccherone launched and for five years scaled the DevSecOps Transformation program across the hundreds of development teams at Comcast. Along the way, he and his team found through experimentation a number of high-leverage approaches. Similarly, Jimmy Xu has seen what works well at a variety of very different organizations in his current and previous consulting roles. Jimmy and Larry put their heads together to present this short list of key concepts that are critical in making your DevSecOps transformation more actionable and successful.
  • Why Interactive Security Analysis for Go Applications Is Needed Recorded: Aug 25 2021 42 mins
    Contrast Security Presenters: Erik Costlow, Sourabh Katti, Benji Vesterby
    Learn how Contrast can help application security teams improve the security of Go applications with the industry’s first interactive application security analyzer for the Go language.

    The addition of the Contrast Go agent to the Contrast Application Security Platform provides an automated method of detecting critical security vulnerabilities in Go-based code—without false positives that cause workflow bottlenecks.

    This webinar looks at how Contrast can help organizations improve testing and protection of their Golang projects. Watch the on-demand webinar to learn …
    • Where Go fits into software and why development teams choose it
    • How security analyzers focus on simplifying any gaps or discussions between software teams
    • The difference between composition analysis (dependencies) and integrated analysis (custom vulnerabilities)
    • How to use interactive application security testing (IAST) in the software development life cycle
    • How integrated analyzers work in different software languages
    • And more …
  • How DevOps in Financial Services Is Creating Application Risks Recorded: Aug 24 2021 62 mins
    David Lindner CISO & Erik Costlow, Director, Contrast, & Patrick Crabtree, Application Security Engineer, GuidePoint Security
    Almost ¾ of financial services firms are traveling at DevOps speed—releasing code multiple times per day or with every change. But only 25% of security teams are able to review and pass all alerts back to their development teams—a big security gap that must be closed.

    Contrast’s 2021 State of Application Security in Financial Services Report highlights these and other trends that application security and development leaders and practitioners need to know to effectively and securely embrace Agile and DevOps.

    Attend this webinar to learn:

    • How well application security and development teams are collaborating
    • What percentage of application vulnerabilities are prioritized for remediation
    • How compliance and risk are shaping financial services and DevSecOps
    • How much time is spent running security scans and triaging and diagnosing alerts
    • How often financial services firms’ applications are successfully exploited
    • If DevSecOps outcomes are affected by company size, number of applications in development, who is responsible for AppSec, etc.
    • And more!
  • How To Determine What Your Open-Source Risks Look Like Recorded: Aug 18 2021 63 mins
    Contrast: Jeff Williams, Damian Horner, Katharine Watson
    38% of open-source libraries are active and only 12% of classes within them are actually invoked in applications.

    Discover key findings recently published in Contrast Security's “2021 State of Open-Source Security Report.” Attendees will learn ...
    • The average number of libraries in individual applications
    • The average age of library versions and how this dramatically ratchets up risk
    • The total number of vulnerabilities found in libraries
    • The presence of potential licensing issues in open source used in applications
    • Strategies and tactics organizations can employ to mitigate open-source risks
    • And more …
  • How To Stop SQL Injection and Other Common Application Attacks in Their Tracks Recorded: Jul 28 2021 42 mins
    Arshan Dabirsiaghi, Blake Connell, and Johnathan Gilday
    98% of organizations reported 3+ successful application exploits in the past year.

    In response to the cascade of successful cyber exploits, President Biden issued an executive order that mandates the need for strengthening cybersecurity. Contrast Protect does just that for production applications. Unlike perimeter defenses, protection from the inside delivers unparalleled insights and remediation capabilities.

    Attend this webinar to learn:

    • Where your production applications are vulnerable today
    • Why existing application security solutions are ineffective for critical security use cases
    • How Contrast Protect delivers application security from inside application code to block actual exploits—both known and unknown
    • How application security teams can support developers with precise attack information
    • And more …
  • The SAST of the Future: Pipeline-native Static Analysis Recorded: Jul 14 2021 45 mins
    Ethan Wilder, Allstate Insurance, Brian Chess, Fortify Software & Arshan Dabirsiaghi, Steve Wilson, Surag Patel from Contrast
    History is being made. Don’t get left behind.

    Slow, inefficient, and inaccurate legacy static analysis is history. Contrast Scan is pipeline native and revolutionizes 15-year-old SAST technology to produce results that include …

    ● 10x faster scan times
    ● 45x faster remediation times
    ● 30% improvement in application security efficiency

    Attend this webinar to learn …

    ● The journey with SAST from the view of a founder
    ● The benefits and pains of SAST for the enterprise from the view of a customer
    ● What the future needs to look like for SAST to thrive and serve the market
    ● Why SAST must be pipeline native to be focused, actionable, and fast
  • How to Modernize Your Azure Journey with DevSecOps Princples Recorded: Dec 9 2020 50 mins
    Surag Patel Chief Strategy Officer at Contrast Security, Steven Murawski
    Whether you have been on the cloud journey for 5 months or 5 years, over 75% of enterprises are still encountering a variety of architectural and security challenges when migrating legacy applications to the cloud, developing and delivering cloud-native applications, or managing hybrid and multi-cloud environments.

    Some of these hurdles include understanding dependencies between applications and application components, refactoring application security infrastructure for cloud hosting, and securing the API proliferation.

    During this fireside chat, Contrast Security and Microsoft will discuss how CIOs, CTOs, CISOs, and Chief Cloud Architects can overcome many of these obstacles and maximize cloud efficiencies by implementing DevSecOps principles.

    Specifically, they will cover how using DevSecOps can help you better:

    · Understand risk in your applications as you migrate to the cloud

    · Rebuild/refactor applications for cloud hosting

    · Secure production workloads once applications are deployed in the cloud

    · Manage application workloads across hybrid and multi-cloud environments
  • Managing Open-Source Security for Modern-Day DevOps Recorded: Oct 27 2020 46 mins
    Joe Coletta & Pauline Logan
    Joe Coletta, Product Marketing Manager at Contrast Security
    Pauline Logan, Product Manager of Contrast OSS at Contrast Security

    Tackle open-source risks without grinding DevOps to a halt.

    Is managing open-source software (OSS) with legacy tools causing more harm than good? This is often the case when it comes to outdated software composition analysis (SCA) tools that bury teams with false positives and require a series of tedious manual processes that waste valuable time.

    Tune in for a webinar that will explain how these SCA tools fall short when it comes to managing OSS risk, as well as how to untangle the confusion and find a security strategy that doesn’t stop DevOps in its tracks. You’ll come away understanding:

    - The rising rate of OSS vulnerabilities
    - Different layers of risk that come with OSS
    - Specific steps DevOps can take to managing an OSS security strategy
    - How instrumentation can help streamline OSS security

    Join us to discover a new way to protect OSS that doesn’t burden security or DevOps teams, but actually integrates into DevOps workflows for seamless, proactive protection.
  • Lessons from Top Echelon Development Teams: Higher Quality Code & Productivity Recorded: Oct 1 2020 63 mins
    Francis Cianfrocca, Luke Hinds, Erik Costlow, Patrick Spencer
    Francis Cianfrocca, CEO, InsightCyber Group
    Luke Hinds, Security Engineering Lead, Office of the CTO, Red Hat
    Erik Costlow, Director of Developer Relations at Contrast Security
    Patrick Spencer, Editor-in-Chief of Inside AppSec Podcast

    Over 60% of leading development teams deploy code to production every day or with every release. This demands a completely different security approach.

    Attend this webinar to learn how the “cream of the crop” are accelerating their release cycles and transforming their businesses by launching new applications and evolving existing ones. Attendees will learn:

    - Best practices from top development teams
    - What security tools and approaches they use
    - How they leverage open-source frameworks and libraries
    - What tools must be integrated into the IDE and CI/CD pipeline
    - How application security must change

    The digital age completely changes DevSecOps, and only those in the top echelon of practitioners are likely to succeed.
  • Application Security Jumps to the Top of the CISO's List of Priorities Recorded: Aug 27 2020 61 mins
    Sean Walls CISO & VP - Visionworks of America, Andre Tehrani Ptr. - Recrewmint, Patrick Spencer, EIC of Inside AppSec Podcast

    Sean Walls, CISO and VP at Visionworks of America
    Andre Tehrani, Partner at Recrewmint
    Patrick Spencer, Editor-in-Chief of Inside AppSec Podcast

    Strategies for implementing effective application security

    As the modern-day CISOs role continues to expand, CISOs must mitigate both business risk and execute successful cybersecurity strategies. This is especially true when it comes to the risk of application development vulnerabilities that can result in dire financial consequences—ranging from diminished brand reputation to severe financial loss.

    Tune in for a special moderated webinar that will feature insights from a seasoned executive recruiter and CISO practitioner about what it takes to manage an effective application security strategy. You’ll come away understanding:

    -Why application security is a highly sought-after skill for CISOs
    - What types of skills and experience help CISOs mitigate application risks
    - How to prioritize application security resources and budget
    - How CISOs can showcase application security skills and experience throughout the interview process.

    Join us to discover how to up-level your application security strategy as well as how to translate application security concerns and plans to the rest of the C-suite and your board of directors.
  • Security in a DevOps World: Unlocking Velocity and Innovation Recorded: Jul 16 2020 62 mins
    Jeff Williams CTO and CoFounder Contrast Security, Sam Guckenheimer Product Owner Azure DevOps, MC Reid Sr Solutions Architec
    Cloud technologies, new architecture stacks, DevOps tools, and agile methodologies have all contributed to productivity, software velocity, and business innovation. But what about security? Can security be an accelerator to innovation?

    Join CTO and Co-Founder of Contrast Security Jeff Williams, Sam Guckenheimer, Product Owner of AzureDevOps at Microsoft, and MC Reid, Senior Solutions Architect at Contrast Security as they demo how Contrast Security's embedded application security model integrates into the Microsoft AzureDevOps Pipeline. This talk will cover how to leverage application security instrumentation techniques in DevSec and SecOps (DevSecOps) to increase both developer and security productivity. By changing culture through advanced automation, we will cover the following 6 topics and how to apply them in real workflow environments:

    Shifting left starts with vulnerability visibility for developers

    Treating vulnerabilities for what they are, software bugs

    Enforcing application security policies into your CI/CD pipelines

    Enhancing threat intelligence with application threat and attack telemetry

    Aligning Development, Security, and Operations teams with real-time unified insights

    Deploying DevSecOps at scale

    Register today to understand how the combined benefits of Microsoft and Contrast Security can help you accelerate innovation with Security in a DevOps world.
  • Evaluating RASP - A discussion of Runtime AppSec Platforms and how they are used Recorded: Nov 19 2019 42 mins
    Securosis analyst, Adrian Lane & Contrast Application Security Specialist Erik Costlow
    Runtime Application Security Platforms, in light of disruptive trends like cloud computing, containers, continuous deployment and DevOps, is a key application security technology. In this webcast we are going to examine several facets of how to evaluate RASP solutions, including the threats they address, how they compare to WAF & static analysis solutions, and how they are integrated into build and production environments.

    Join Securosis analyst, Adrian Lane and Contrast Application Security Specialist Erik Costlow on how RASP works, how the solutions are architected, and then discuss common questions we have received over the last several years from customers of RASP solutions. We hope this webcast will help guide you in your evaluation and selection process.
  • Comment accélérer le cycle développement de vos applications? Recorded: Oct 2 2019 35 mins
    Chardy N’diki (Regional Manager, EMEA) & Laurent Levi (Sales Engineer, EMEA) at Contrast Security
    Une transformation digitale réussi dépend de l’agilité sa Software Factory. Comment la sécurité peut tenir le rythme et avoir une emprunte minimal sur les cycles développement ? Nous vous montrerons comment Contrast utilise les technologies d’instrumentations pour renforcer la sécurité des applications avant leur déploiement, de les protéger en production et offrir une visibilité sur les vulnérabilités tout au long du cycle de vie des applications. Enfin nous montrerons comment améliorer l’adoption auprès des développeurs et d’optimiser les ressources liées à la sécurité dans vos projets.
  • What the WAF? Understanding and augmenting what the WAF cannot see Recorded: May 29 2019 52 mins
    Erik Costlow, Principal Product Evangelist, Contrast Security
    In this webinar we will uncover why WAFs exist and go through architectures of a WAF, Cloud Native vs. On-Premise and of Self-Defending Applications. We’ll highlight what WAF’s can and cannot see and why they require augmentation to function to their fullest. We’ll also investigate into the three types of WAFs and highlight their similarities and differences:

    - Traditional WAF
    - “Next-Gen” WAF
    - Cloud WAF

    We will also discuss the commonalities and disparities of Cloud and on-premise WAF’s and present some best practices, deployment strategies and management for each. Additionally we’ll highlight WAF augmentation and underscore why you need to secure within the application instead of just in front and how Contrast’s platform can see things that are “invisible” to WAFs and comparing the different approaches to application protection.

    The webinar will illustrate how Runtime Application Self-Protection (RASP) works from within the application via instrumentation in production environments and show how easy it is to deploy in for DevOps, Cloud and Container environments. We will also illustrate why RASP is more accurate than a WAF, so you can block attacks out-of-the-box quickly, economically and effectively.
  • Key Application Security Strategies for your Cloud Migration Recorded: Mar 19 2019 52 mins
    Rohit Gupta, Global Segment Leader; Surag Patel, Chief Strategy Officer
    Cloud computing is one of the major shifts in technology that is gaining rapid traction and is helping fuel the growth in today’s digital transformation. As leading organizations modernize their hardware and software environments, they are demanding flexibility, business agility and operational efficiencies. This ultimately equates to tangible cost savings, loyal customers and higher profits, as organizations leverage the cloud to compete more effectively and differentiate their digital service and product offerings.

    As a real-world example, you will hear from Chris Perkins, Senior Security Architect at a major Fortune 500 medical technology and solutions company on:

    - Key drivers and use cases in migrating from traditional legacy technologies and embracing modern hybrid cloud computing approaches.
    - Application Security threat landscape, testing pipelines and native integrations.
    - Major hurdles and lessons learned (organizationally, culturally, technology) and how to reduce friction and increase collaboration between Dev & Ops teams
    in order to optimize resources and ensure a secure Cloud migration.
    - The cost curve for remediation of defects enabling a safer speed to market and growth

    You’ll also hear from Rohit Gupta, Global Segment Leader, Security: Amazon Web Services (AWS) highlighting key tenets for security for AWS and the framework required to help their customers meet compliance, regulation and security objectives and Surag Patel, Chief Strategy Officer, Contrast Security, underscoring modern approaches to automate, integrate and scale Application Security.

    As a result of this webinar, you will hear about the major benefits in migrating to a secure, compliant cloud environment and learn from a customer’s experience on how to successfully automate and secure your applications. There will also be a Q&A session at the end of the webinar.
  • Cloud-Native Security: Processes and Tools for Real-World Transformation Recorded: Feb 20 2019 59 mins
    Jeff Williams, co-founder and Chief Technology Officer of Contrast Security and David M. Zendzian, Pivotal Global CTO
    Can your organization support developer self-service across 11,000 workloads with certainty that 100% of the workloads are security-approved across the entire stack? The answer is yes with a cloud-native approach.

    Cloud-native platforms not only make it easier to support the kind of cultural shift necessary for continuously shipping software, they make it easier to practice good security and reduce the available attack surface. But an attack on the application itself can undermine all platform controls.

    In this webinar, Jeff and David will discuss application development code security in pre-production as well as runtime security at scale for cloud-native production applications. This session will cover the following:

    ● Tools that work well with rapid-cycle CI/CD pipelines
    ● Baking audit and compliance into pipelines
    ● Achieving zero downtime CVE patching and updates
    ● Vulnerability discovery, and blocking of application threats and attacks in the runtime
    ● Demonstration of threat discovery and blocking

    This is the second webinar in a series presented by Pivotal and Contrast Security on cloud-native security best practices. The previous webinar in this series is available in the attachment section.

    Pivotal Privacy Statement: 

    Contrast Privacy Statement: 

    This webinar:
  • Cloud-Native Security: Understanding the Why and How Recorded: Feb 14 2019 63 mins
    David M. Zendzian, CTO, at Pivotal and Jeff Williams, Co-founder and CTO at Contrast Security
    The latest Verizon Data Breach Investigations Report continues to confirm that top sources of data breaches continue to be at the application layer. DevOps and security teams are adopting modern, fully automated software delivery platforms to release apps to production environments multiple times a week or even daily. This has forced security teams to rethink the traditional processes and practices to make security a key component of their cloud-native transformation.

    Join Jeff and David to learn how enterprises are addressing cloud native application security at speed and scale. This session will cover:

    - Common security anti-patterns
    - What is Cloud-Native Security?
    - People: How to align Dev, Security and Ops teams to achieve Cloud Native Security
    - Process: How does Cloud Native change security processes to support the modern agile business?
    - Technology: Introducing Cloud Native Security tools to achieve continuous application security
    - Q&A

    This is the first webinar in a series presented by Pivotal and Contrast Security on Cloud-native Security best practices
  • Under the hood with Static Analysis – What is actually happening Recorded: Nov 29 2018 41 mins
    ERIK COSTLOW, Principal Product Evangelist, Contrast Security
    Do you use static analysis and want a better understanding of how it works? This technical webinar will walk through the basics that support the static analysis field, such as semantic analysis and how dataflow works between source and sink. We will walk through the model structure that is built, how it is queried, and how it is impacted by different development techniques.

    At the end of this webinar, attendees will be able to better understand what factors in to the quality of results.

    Questions this webinar will answer:

    What is the impact of microservices on analysis quality?
    As analysis traces data from source to sink, what exactly does it watch?
    How are frameworks and different architectures scoped and analyzed?
    What are techniques like inversion of control, dependency injection, and static/dynamic typing,
    and what impact do they have on code analysis?
DevOps-Native AppSec Platform
Contrast Security is the leader in next-generation application security, embedding code vulnerability analysis and attack prevention directly into software through instrumentation. Contrast’s patented deep security instrumentation completely disrupts traditional application security approaches with integrated, comprehensive security observability that delivers highly accurate assessment and continuous protection of an entire application portfolio. This eliminates the need for disruptive scanning, expensive infrastructure workloads, and specialized security experts. The Contrast Application Security Platform accelerates development cycles, improving efficiencies and cost, and enabling rapid scale while protecting applications from known and unknown threats.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: How To Determine What Your Open-Source Risks Look Like
  • Live at: Aug 18 2021 5:00 pm
  • Presented by: Contrast: Jeff Williams, Damian Horner, Katharine Watson
  • From:
Your email has been sent.
or close