Learning to build an effective security design review program - Felix Matenaar, Ari Fay @OWASPGLOBAL
Learning to build an effective security design review program - Felix Matenaar, Ari Fay  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 1 week ago
Learning from "edge of tomorrow" to build an effective security design review program

Security design reviews are an essential part of any modern application security program. While technical frameworks to identify security defects in software are well documented and standardized among the industry, little guidance can be found on how to bootstrap, manage and grow an overarching process and program that developers happily engage in and that is measurably effective at finding critical security flaws before they launch to production.


300 reviews later and with an absolute NPS of 52 we are ready to share our data, stories, experiments, failures and accomplishments collected during our journey to build an effective security design review program from scratch for an organization of 500 software developers.


We will present and release all material needed to replicate the program 1-to-1 in your organization.


-

Managed by the OWASP® Foundation
owasp.org
Learning to build an effective security design review program - Felix Matenaar, Ari FayOWASP Foundation - December 2025 Financials
OWASP Foundation |

Learning to build an effective security design review program - Felix Matenaar, Ari Fay

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER