Evan OslickApr 26, 20223 minAPPSEC ADVICEFalse Positives VS. False Negatives in Application Security DAST vs. SAST: Is It Better to Know Too Much or Too Little? “In our new application security program, do we implement static analysis...
Brook S.E. SchoenfieldApr 21, 20225 minAPPSEC ADVICERisk-based AppSec, But How?Risk. Everyone in AppSec or software security talks about it. Pundits advise that we base our decisions on it. AppSec manuals demand that...
Brian PavicicApr 21, 20222 minNEWSEvan Oslick Joins True Positives’ Leadership TeamThe consultancy gains a deep skillset in enterprise application security assurance and automation. We’re excited to announce that Evan...
Brian PavicicMar 29, 20225 minAPPSEC VAR SOLUTIONSAppSec Shared Security Model: It Really Is Everyone’s ResponsibilityGood AppSec really is everyone’s responsibility, from server side to users, cloud owners and platforms. Explore the shared security model he
-Dec 8, 20211 minNEWSTrue Positives, LLC, Announces Key Additions to its Leadership TeamThe consultancy gains a deep skillset in enterprise application security assurance and automation. Press Release FOR IMMEDIATE RELEASE:...
Brian PavicicNov 23, 20212 minNEWSIntroducing AppSec Assurance Strategy Led by Brook S.E. SchoenfieldWe’re excited to announce the launch of our AppSec Assurance Strategy services. This offering rounds out our existing tooling and managed...
Brook S.E. SchoenfieldJul 13, 20215 minT+ TEAMGrowing Up AppSecTrue Positives is excited to announce that Brook S.E. Schoenfield has joined the firm to lead our AppSec Assurance Strategy service. His...
Brian PavicicNov 29, 20203 minAPPSEC ADVICESemgrep Puts Real Time Vulnerability Scans in Developers’ HandsDiscover how our partner r2c is reducing cost, time, and headaches in static testing The State of Static Application Security Testing...
The HUB at True Positives Nov 6, 20204 minAPPSEC ADVICEApplication Security: Shift Left isn’t EnoughIn Application Security the focus is always on Shift Left. The theory goes that the sooner the teams can identify vulnerable code, the quick