The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Dag Flachet -- Kaizen for your Appsec Program
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Dag Flachet joins us to discuss the concept of Kaizen and its application in improving application security. Dag shares his journey into the world of security, emphasizing the importance of iterative, small-step improvements. The conversation delves into how organizations can effectively implement maturity models to enhance their security programs, the limitations of compliance-focused frameworks like ISO 27,000 and SOC 2, and the practical application of Kaizen principles. They also explore the evolution and future updates of OWASP SAM, and the importance of empowering development teams through a bottom-up approach in security enhancement. Dag is the co-founder of Codific, a professor and board member at the Geneva Business School, and an active member of the OWASP Barcelona Chapter and the OWASP SAMM community.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.
→ Learn more about Security Journey
Connect with Dag Flachet:
→ Codific
→ OWASP SAMM
Mentioned in this episode:
→ Codific
→ OWASP SAMM
→ OWASP SAMM
→ OWASP DevSecOps Maturity Model (DSOMM)
→ openCRE.org
→ EU Cyber Resilience Act
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Dag Flachet: Kaizen for your Appsec Program
01:39 The thing that we love. Well, uh, we're joined by Dag
06:54 That'd be funny if she sent a message yet. Like, hey
13:20 Yeah, very cool. Well, as we mentioned, we're going to be
17:08 Which is, is DSOM part of SAM now or are they
22:08 This is an interesting thing, but maturity models have also evolved
24:44 Let's wrap this whole thing together now. We introduced Kaizen. We've
27:00 If we were to kind of dive a little bit deeper
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo