
OWASP SAMM is an excellent tool for improving an organization’s application security program, but developers often didn’t ask for it. Handed down as a scorecard, it lands as an audit, and the result is polite compliance at best and quiet resistance at worst. As software consultants and strong believers in SAMM, we set out to change how it arrives, treating the development team as the user of the model rather than its subject. We share what we learned about making maturity work accessible and empowering, and why that matters even more under the Cyber Resilience Act.
Conference partners







Organiser
