The AppSec Poverty Line

▶ Watch (3:02)

Most teams are not Microsoft or Google. Tanya surveyed 60 companies in 2024 and realized the industry is not doing well. The poverty line is the minimum threshold of security investment below which common threats cannot be blocked. Minimal Viable Security (MVS) is the smallest set of controls to reduce risk without stopping core delivery. Every public app needs at least MVS.

The MVS Checklist

▶ Watch (7:22)

Input validation rejects bad data. Parameterized queries prevent SQL injection. Use modern tools and buy authentication rather than building it. Encrypt with HTTPS. Pass a free DAST scanner like ZAP or Burp. Log everything and monitor uptime. Do a basic threat model using Adam Shostack’s four questions: What are we building? What could go wrong? What are we doing about it? Did we do a good job? Assess each app with the same four‑point scale.

What Small Teams Can Ignore

▶ Watch (15:53)

Don’t obsess over TLS version unless you use SSL. Skip zero days unless they are actively exploited. Do not write custom crypto or PKI. Avoid complex RBAC for eight users. Security through obscurity is not the priority. Pentesting can wait until you pass a DAST scan. Skip advanced tooling, strict governance, and 100 percent code coverage. Focus on critical flows first.

Free DAST fixes more bugs than a pentest at this stage.

Free Training and Culture

▶ Watch (20:33)

OWASP provides 37 Top‑10 lists, secure coding dojos, and intentionally vulnerable apps all free. Books cost $40 and libraries will buy them. Create a Slack channel for security questions. Embed security in code reviews with a checklist and rotate reviewers. Celebrate small wins like a clean DAST scan. Invite developers to OWASP chapters. Security culture is built on praise and repeated behavior, not posters in the lobby.

When Minimal Is Not Enough

▶ Watch (28:49)

Handling sensitive user data, payment flows, or high‑profile exposures requires more than MVS. Signs you need to level up: your team cannot handle incidents, the company is growing fast, security cannot keep up, or your threat model changed after a merger. Scale with automation, pentests, better training, intent monitoring, and a dedicated appsec hire. Do not stay at MVS when attackers are actively looking at your app every day.

Q&A

How should a professional services team integrate MVS into client environments? Train the developers on secure coding and code review before they deploy. Clients now require proof of training. ▶ 36:02

Does MVS change for a non‑online app? It depends on the threat model. A medical device on a body needs far more than MVS. A harmless fidget spinner with code is fine at MVS. Use the four‑point safety check. ▶ 38:20

Any low‑cost alerting or monitoring recommendations? Build a custom logging with the ELK stack; you pay with time. Write a small service that emails your dev team on errors. There is no cheap turnkey solution for small teams. ▶ 39:39

Notable Quotes

if you have no logs and no evidence and you don’t know what happened and your data is on the internet that’s way more expensive Tanya Janca · ▶ 9:21

Microsoft’s one of the oldest companies, like IT companies in the world, and they made Active Directory, and they measure their profit in trillions, and they’ve been working on it like what, 30 years, and there’s still bugs in it. I’m sorry. You can’t do better. Tanya Janca · ▶ 10:07

you are already getting a pentest every day. You are just not getting the report. Tanya Janca · ▶ 34:39

Key Takeaways

  • Run a free DAST scanner against every public app and fix every exploitable bug it finds.
  • Buy authentication and payment systems; do not build them from scratch.
  • Free OWASP resources and code review checklists provide all the training a small team needs.

About the Speaker(s)

Tanya Janca, known online as SheHacksPurple, is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the founder of DevSec Station, a modern learning platform and community built to help software developers master secure coding.