Tracy Bannon

It's the humans that matter...

Podcast Series:It's 505!

I am proud to be a contrbuting journalist and podcaster for It’s 5:05. This briefing airs daily at 5:05 ET US focused on Open Source and Cybersecurity News. You can check out all my contributions below. Also head over to It’s 505 Updates Website and subscribe! Loading…

Trust, Trustworthiness, and the Trust Equation

Trust is not something you just ask for or earn. Rather you need to exude trustworthiness and others examine that and decide for themselves if they can or will extend trust. Charles Green published a 'trust equation' that I have adopted for years and can say it is wonderfully helpful.

#NoHobbyists - Cybersecurity Cannot Depend on Hobbyists

We have a talent and knowledge deficit with cybersecurity. The pace of technical innovation is ever increasing as is the need to constantly upskill. Often, the most successful and sought after talent spend many many hours on their own to keep pace; this is not sustainable.

Shift Left Acadermy: Builders and Breakers

Builders and Breakers Our best way forward towards cyber secure software is teaching builders to think like breakers and breakers to understand builders. Excellent discussion by Tracy Bannon, Casey Ellis, facilitated by Deb Radcliff

Cyber Ops needs love too!

“Cyber Ops needs love too! We spend much time focused on DEV and often ignoring OPS. I am guilty of this too. I work with the MITRE now; I never realized their emphasis on world class cybersecurity. We work on behalf of the public good."

The only thing that matters is working code in production!

“'The only thing that matters is working code in production! This was a shocking statement by friend and colleague, David Sisk. We worked side by side focused on application architecture and software engineering at Deloitte. David, managed to anger an entire set of senior leaders plus a highly visible methods and tools organization by saying the most important outcome is not documents and decks. Ultimately all that matters is working software.."

DevSecOps Misinformation Is Real!

“DevSecOps Misformation is real. Ok, ok, maybe we should say misconceptions? Joan Goodchild wrote a brief blog myth-busting her top 5 DevSecOps fallacies."

Faux Script Kiddie!

Why is it so easly to learn to hack?

A few weeks ago I dusted off my dog-eared copy of ”The Web Application Hacker’s Handbook” by Studdard and Pinto (Yes,I still prefer printed books though I now spring for a second e-version for when I’m traveling.). I’ve installed the most recent version of Burp Suite community edition and OWASP’s ZAP and decided to freshen up my ethical hacking/cyber-student skills. Of course, I am not probing public sites, but rather, using the ethical learning sites: