Peter holds numerous security-related designations including the CISSP, CISA, CGEIT, CRISC, and GCFA Ensuring that the products and services we build and deliver are as threat resistant as possible is extremely important today. Meeting this challenge is not just about building secure applications since we all know that rapid development of software as well as the evolution of threats and vulnerabilities can see our applications as secure today but vulnerable tomorrow. That is why having an established product security team and response capability is extremely important. During this discussion, I will discuss, using real-world examples, including that of my own, how organizations can meet the demands of product security including: Building a culture of security within your organization beyond firewalls and anti-virus How to “sell” security to executive management and explaining what product security does and doesn’t do (i.e. staffing, budgets, etc.) Building and deploying software using the "DevOps" approach The difficulties of wearing multiple hats, with security being one of them Embedding “security” in the software development life cycle (SDLC) Establishing a proper security “response” program Product vulnerability transparency and developing a disclosure policy How to measure the success of your program Establishing a bug bounty program