All episodes
Security, better late than never
Alejandro Vallecilla wrote that companies delay security until a merger, an incident or a law forces it. We go through the EU law that makes a security bug a product defect, and what a Security Hub score is worth without a risk assessment.
Chapters
In this episode
- The article this conversation follows: Security, better late than never, and why Alejandro Vallecilla wrote it
- The EU Product Liability Directive: software becomes a product, and a security bug that harms a person is a defect the maker pays for without proof of carelessness
- What counts as harm under that law: injury, private property, personal data destroyed or corrupted. A leak alone is a GDPR matter
- The Cyber Resilience Act: an exploited vulnerability now has to be reported to the EU within a fixed deadline, with fines scaled to global turnover
- How large a share of an open source survey had not heard of either law
- How fast the yearly count of published CVEs is growing, and how much of it is the Linux kernel alone
- Why “we are too small to be a target” stopped being true once bots and AI agents do the scanning
- Sepehr Lorestani ten years ago against Sepehr Lorestani now, and when an engineer puts a foot down with the business
- What junior engineers still have to learn when AI writes the code, and why asking AI the stupid question is the safest place to learn
- Alejandro Vallecilla on landing in an AWS account with thousands of failing Security Hub controls and no risk assessment behind them
- Ten controls that matter beat ninety that do not, and why we prefer statistics over a score
- The inventory that turns a new CVE into a one-hour check instead of a panic
- A secure environment does not mean you will not be attacked. It means the attacker works harder
- The ratio between attackers and defenders is out of balance, and why a fine is how it comes back
- Security is a range, never zero or one. What the Revolut attack shows
- Containing an attack once it is inside, the topic we left for a follow-up

