Mental Preparation and the Marathon Mindset
AppSec programs share one underappreciated trait with marathon training: both are measured in years, not sprints. Michael Shin, FactSet’s interim CISO and a Boston Marathon qualifier with 18 years in AppSec, frames the parallel directly. Confidence in security comes from the same place as confidence on race day: training, small wins, and not flinching at early failure. His wife started by running one minute and walking four. After years of training, she qualified for Boston 2025. AppSec teams start the same way.
Short-Term Wins, Long-Term Direction
Goal structure matters as much as the goal itself. Long-term targets, like reaching SOC 2 compliance or building a mature security organization, set the direction. Short-term targets, like passing an upcoming audit or fixing a specific product’s vulnerabilities, keep the team moving. Without short-term milestones, long-term goals feel unreachable and demotivating. FactSet’s team acknowledges short-term wins through blog posts, awards, and gamified targets. OWASP resources provide a starting point for calibrating where your program stands against industry benchmarks.
Selecting Tools Without Overbuying
Fang’s first assumption about marathon running was that you just needed running shoes. Shin corrected him: serious runners maintain separate shoes for race day and training, some discarded after one or two races. The same logic applies to AppSec tooling. The most feature-rich tool may not fit your budget or your team’s workflow. Start by identifying what your organization actually needs, then match tools to budget. Open source options and OWASP’s reference lists reduce the pressure to buy an enterprise suite from day one.
Continuous Monitoring and Adaptation
Wearables give marathon runners real-time heart rate, pace, and oxygen data mid-race. AppSec has the equivalent: SAST, SCA, and CI/CD pipelines that produce vulnerability density, time-to-remediate, and SLA ratios. Those metrics guide short-term goal adjustments and also give security teams a story to tell management. Adaptation matters too. Race conditions change mid-run; AppSec programs face new malware, zero-days, and GDPR-style regulatory shifts. Incident response plans prevent teams from scrambling when a breach hits. Having the plan before the incident is the point.
Collaboration as Force Multiplier
Shin runs weekly with a 20-person group in San Antonio. Newer runners learn from veterans; peer accountability fills gaps that personal discipline misses. AppSec teams get the same benefit from security champion programs, OWASP chapter participation, and cross-team developer relationships. When security reports a vulnerability, framing it as a teaching moment, explaining why something is exploitable rather than just flagging it, shifts developers from treating security as a blocker to thinking about impact proactively. That culture change is harder than any tool selection.
Q&A
What is the biggest personal challenge in the AppSec marathon? Fang identifies collaboration with developers: both groups have distinct roles and priorities, and bridging that gap is difficult but rewarding when it pays off. ▶ Watch (34:25)
Notable Quotes
life is a marathon not a Sprint I’m sure Derek Fang · ▶ Watch (2:01)
having that uh trust both ways and that Derek Fang · ▶ Watch (30:05)
see the fruits of that labor Derek Fang · ▶ Watch (35:05)
Key Takeaways
- AppSec programs mature over years; early teams should set realistic short-term goals and celebrate wins.
- SAST, SCA, and CI/CD metrics give AppSec teams the same feedback wearables give marathon runners.
- Security champions and developer relationships shift teams from reactive blockers to proactive program builders.
About the Speaker(s)
Derek Fang is part of the Product and Application Security Team at FactSet, a global team dedicated to ensuring the security of FactSet’s products and applications. In his role, he collaborates with FactSet’s developers and product teams to align the organization’s security posture.