Appsec News & Interviews from RSAC on Identity and AI – Charlotte Wylie, Rami Saas – ASW #331
Charlotte Wylie, SVP and Deputy Chief Security Officer at Okta, leads Okta’s technical cybersecurity services. This includes overseeing Okta’s global engineering teams to enhance the company’s security postures and programs that support its nearly 20,000 customers. She’s a seasoned security executive with extensive global experience across financial and technology industries in Australia and the United States. Charlotte has an extensive background in delivering security transformation programs and leading global engineering teams to create value through enhancing security posture and aligning with business goals for large corporations.
Rami Sass is co-founder and CEO of Mend.io, a company that enables organizations to accelerate the development of secure software at scale with automated tools that help bridge the security knowledge gap. Since the company’s founding in 2011, Rami has grown Mend.io from a small Israeli startup to a global business with over 300 employees across several countries and hundreds of enterprise customers including Microsoft and IBM.
- Identiverse 2025 is returning to Las Vegas, June 3-6. Hear from 250+ expert speakers and connect with 3,000+ identity security professionals across four days of keynotes, breakout sessions, and deep dives into the latest identity security trends. Plus, take part in hands-on workshops and explore the brand-new Non-Human Identity Pavilion. Register now and save 25% with code IDV25-SecurityWeekly at https://www.securityweekly.com/IDV2025
Mike Shema
- Consult the European Vulnerability Database to enhance your digital security!
Here's the EUVD. All the entries so far seem to be a mapping of CVEs to EUVDs. I'd expect these two vuln tracking sets to significantly overlap for a while. It'll be the eventual differences, specifically in the EUVD, and the nature of those differences that will be interesting to see. Such differences could be anything from preference for reporting, where EUVD becomes the favored "first notified", to showing gaps in the administration of the CVE program, to disputes on the validity or severity of an entry.
- Encourage investment and markets for secure tech – NCSC.GOV.UK
- Linux Foundation and OpenSSF Release Cybersecurity Skills Framework to Strengthen Enterprise Readiness
Check out the Cybersecurity Skills Framework. (The skill drop-downs don't work in Safari, so stop by the HTML Skills Framework first or try a different browser.)
- Secure by Design: Defining Best Practices, Enabling Developers and Benchmarking Preventative Security Outcomes
Yes, it's vendor research, but it's not stuck behind a regwall.
It's a good seed for discussing what Secure by Design either means or looks like. And it has a very interesting comment on what it observed in how companies approach threat modeling that's worth exploring more.
- Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
Also covered in The Record
There's plenty of precedence for bribery as a shortcut to hacking as well as a means of spying.
It might not seem like there's an immediate appsec angle here, but threat modeling for insider threat and designing controls for systems that have sensitive data access are surely critical tasks that fall under secure by design.











