The Most Common AppSec Failures in Fortune 500 Companies and Beyond @OWASPGLOBAL
The Most Common AppSec Failures in Fortune 500 Companies and Beyond  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 2 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/ec/The%20Most%20Common%20AppSec%20Failures.pdf

For the past three years, I have performed over 40 hands-on security assessments of Fortune 500 companies and other organizations. Using a systematic methodology grounded in the OWASP SAMM framework, I have observed a clear pattern: regardless of size or maturity, organizations tend to make the same critical mistakes.

Security is all about risk, yet I have rarely encountered a team with a shared understanding of their application risk profile and appetite. Applications are built around requirements, but security requirements are almost never explicitly defined, even though OWASP ASVS has already laid the groundwork. Threat modeling is often reduced to a whiteboard version of a pen test, outsourced to external teams or, worse, delegated to AI. Teams place unrealistic expectations on tools: “Once we deploy our ASPM tool, things will be better.” In reality, these tools often introduce new challenges. We continue to build dashboards around security metrics we don’t understand, in pursuit of goals we never defined. Finally, the siloed nature of development, security, and operations only amplifies these issues, leading to confusion, delays, and accountability gaps.

This session will unpack these recurring pitfalls with concrete examples and provide pragmatic advice to break the cycle. Whether you’re leading an AppSec program or driving change from within, you’ll leave with a sharper understanding of what actually makes or breaks application security.

Aram Hovsepyan
Codific
Founder and CEO

For the past 15 years Aram has been involved in application security as a researcher, industry expert, and core contributor to the OWASP SAMM project.

Aram holds a PhD in application security from DistriNet KU Leuven, which gives him a broad understanding of the security landscape. His work on refining and streamlining the LINDDUN privacy engineering methodology has been incorporated into both ISO and NIST standards. Aram is the founder and CEO of Codific, a Belgian cybersecurity product firm.

At Codific, he works at the intersection of software engineering and application security, helping organizations build secure and reliable systems that protect what matters most. Aram is also a core contributing member of the OWASP SAMM project, which is the industry standard framework for managing application security programs.

Managed by the OWASP® Foundation
owasp.org
The Most Common AppSec Failures in Fortune 500 Companies and BeyondAutomatic application hardening by leveraging container runtime behavior analysis - Amit SchendelNo Admittance Except on Party Business - A Hobbits Memoir about an InfoSec JourneyOWASP Low-Code/No-Code Top 10 (LCNC) - Michael BarguryMCP Deception Incubator — Honeytraps as a Framework for Zero Trust AI Environments track 2From Maturity to Mastery: Accelerating Software Security with OWASP SAMMOWASP Global Board of Directors - May 2026 Public MeetingIn GitHub We Trust: 10 Ways You Could Get PwnedSecuring Apps Without a Budget: Minimal Viable Security Strategies track 2Kernel Alchemy: Crafting Mobile Kernel Code to Evade Modern RASP Protections - Subho HalderOWASP Global Board of Directors - June 2026 Public MeetingAPI Fuzzing in the SSDLC Problems and Possible Solutions
OWASP Foundation |

The Most Common AppSec Failures in Fortune 500 Companies and Beyond

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER