OWASP 2025 Global AppSec Conference – Day 2

CyberRisk TV is proud to partner with the OWASP Foundation for on-site coverage of the 2025 Global AppSec USA conference in Washington, D.C. Join us as we capture candid moments with leading technologists, thought-leaders and vendors shaping the future of application security — from software reform to hardware transparency and AI-driven disruption.

This episode is sponsored by
Full Show Notes
Segment One

The future of CycloneDX and software transparency – Steve Springett – OWSP25 #2

Guest
Vice Chair, Global Board of Directors at OWASP Foundation

Steve guides teams in both the strategy and execution of secure software development. He integrates security throughout the entire development lifecycle, leading efforts in threat modeling, secure architecture and design, static, dynamic, and component analysis, offensive research, and defensive programming.

Steve’s passionate about helping organizations identify and reduce risk from the software supply chain. He is an open source advocate and leads the OWASP Dependency-Track project, OWASP Software Component Verification Standard (SCVS), and Chairs the OWASP CycloneDX Core Working Group and Ecma International TC54.

Steve serves as Vice Chair on the Board of Directors of the OWASP Foundation where he helps drive the continued growth of the foundation and the pursuit of its mission to make secure software a reality through open collaboration, education, and innovation.

Segment Two

From Transparency to Trust: Shaping AI Security with OWASP AIBOM & AI Exchange – Aruneesh Salhotra – OWASP25 #2

Guest
CEO, CISO, SNM Consulting Inc. + OWASP Project Lead/Co-Lead at SNM Consulting Inc

I’m a seasoned technologist and servant leader with extensive expertise across cybersecurity, DevSecOps, AI, Business Continuity, Audit, and Sales. My impactful presence as an industry thought leader is underscored by my contributions as a speaker and panelist at leading industry events including RSA, CactusCon, Harvard, QA Forum, ADDO, Palo Alto Ignite, ISACA, OWASP, Open Source Congress, IAPP, InfoSec World, and Machines Can See (Dubai). My engagement with key security bodies like OWASP, IEEE, CFF, PBC, and IAPP significantly shapes security policies and promotes better cybersecurity practices.

I serve in leadership roles across multiple OWASP initiatives including AI Exchange, AIBOM (AI Bill of Materials), Serverless Top Ten Project, CRA, GenAI Lead Author as well as IEEE Next Gen Cyber Security. As a distinguished board advisor across many security and AI companies, Angel Investor and limited partner in several venture capital firms specializing in cybersecurity, I provide strategic direction to startups and established organizations navigating the complex intersection of security and AI. I’m also an active member of InfraGard in the NY Metro Chapter.

I leverage my credentials—including CISSP, C-CISO, GCISO, AWS, and Kubernetes—to bridge technical excellence with business strategy. I have a proven record of building communities around topics relevant to Cyber Security and AI, believing deeply in making security accessible and actionable for all.

Segment Three

AIVSS: Do we need a new Risk Management Approach in the era of Agentic AI? – Ken Huang – OWASP25 #2

Guest
CEO at DistributedApps.ai

Ken Huang is a prolific author and renowned expert in AI and Web3, with numerous published books spanning business and technical guides as well as cutting-edge research. He is a Research Fellow and Co-Chair of the AI Safety Working Groups at the Cloud Security Alliance, Co-Chair of the OWASP AIVSS project, and Co-Chair of the AI STR Working Group at the World Digital Technology Academy. He is also an Adjunct Professor at the University of San Francisco, where he teaches a graduate course on Generative AI for Data Security.

Huang serves as CEO and Chief AI Officer (CAIO) of DistributedApps.ai, a firm specializing in generative AI-related training and consulting. His technical leadership is further reflected in his role as a core contributor to OWASP’s Top 10 Risks for LLM Applications and his participation in the NIST Generative AI Public Working Group.

Key Books:

– Securing AI Agents: Foundations, Frameworks, and Real-World Deployment , Springer, October, 2025

– Agentic AI: Theories and Practices – Springer, July 2025

– LLM Design Patterns – Packt, May 2025

– Beyond AI: ChatGPT, Web3, and the Business Landscape of Tomorrow -Springer, 2023

– Generative AI Security: Theories and Practices -Springer, 2024)

– Practical Guide for AI Engineers (Volumes 1 and 2 by DistributedApps.ai, 2024)

– The Handbook for Chief AI Officers: Leading the AI Revolution in Business -DistributedApps.ai, 2024

– Web3: Blockchain, the New Economy, and the Self-Sovereign Internet – Cambridge University Press, 2024)

– Web3 Applications Security and New Security Landscape: Theories and Practices -Springer, 2024

– Blockchain and Web3: Building the Cryptocurrency, Privacy, and Security Foundations of the Metaverse (Wiley, 2023)

A globally sought-after speaker, Ken has presented at events hosted by RSA, OWASP, ISC2, Davos WEF, ACM, IEEE, Consensus, the CSA AI Summit, the Depository Trust & Clearing Corporation, and the World Bank.

Segment Four

OWASP 2025 Wrap-Up: Community, AI Security, and the Future of AppSec – Avi Douglen – OWSP25 #2

Guest
Founder and CEO at Bounce Security

AviD is a prominent security architect and software developer, with decades of experience leading development teams in building secure products and protecting complex systems. He has enjoys researching efficient security engineering, usable security, and scaling enterprise security systems. He founded Bounce Security to focus on bringing his own brand of efficient software security to a wider range of technology companies and software developers. Mr. Douglen is a frequent trainer and speaker at industry conferences, such as OWASP, RSA, BSides, and InfoSec, as well as developer conferences such as O’Reilly, DevSecCon, PyCon, and DevOpsDays.

Stay in the Know, No Smoke and Mirrors – Join Our Newsletter

You can skip this ad in 5 seconds