Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud

Security Journey: Train Like Your Org Depends on It (Because It Does)

Truth in IT
05/05/2025
45
1 (100%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hi, Mike Matchett with Small World Big Data and we're here at RSAC 2025 looking at cybersecurity companies all across the landscape. We're talking to Security Journey right now. Who's got an innovative way to teach security, educate, do security education with people who develop applications? Michael Birch welcome. Awesome. Thank you. Yeah. You can hold this if you want. I can hand. It to you. There you go. Awesome. Perfect. Yeah. Um, yeah. So we do application security training. We teach secure coding and security development design. Very gamified, hands on approach. Something to really keep people engaged because I think that's the biggest part we have with training is keeping people engaged and actually caring about the training. So they walk away like they feel like they learned something. So do you think that that's really a big problem with most people's security regimes and one of their bigger vulnerabilities, people not knowing what to do when they're writing code or not knowing how to approach security. Yeah. I think one of the biggest things, the biggest part is awareness, right? It's understanding what the right answer is. And it comes from the fact that security isn't really a requirement. When we think about teaching development or DevSecOps or any of those other things, what happens is in the universities, it might be an elective that someone might pick up when they're graduating. So when they get to their companies, they know how to produce code. But security is not in any part of their education. Right. Tell me a little bit then about security journeys. You sort of unique value proposition. What do you tell people just to get their attention about how you guys approach security training? We approach it from a very developer first mentality, right. There's a lot of companies out there that I think they're really focused on the program. We're thinking about the end learner every time along the way. We want to make sure that you feel rewarded, engaged. You're having fun and you're getting value. So we're giving you the most appropriate training for your business role. Like a one time test you take online. This is something that you engage with on an ongoing basis with the app. And it really ties into our name. It's a journey for us. It's a nonstop journey where you're going to start at this foundational level, and we're going to build you up over the years continuously enhancing your security knowledge. If you look out at the crowd here so far, and I know we're early in RSAC, what would you say is the biggest thing you'd like to tell everyone that's walking by? One of the biggest things I would like to say is, um, understanding that security is a fundamental thing and the decisions that most people are making. I'm going to bring the AI part in here because that's one of the hottest. You have to say it. You got to say the AI, because I got to say almost every booth, that's one thing they found is a way to put AI sticker on their booth. Right. And the big important part to that is my big word of caution. There is a AI is amazing. It can do some great stuff, but it doubles, triples, quadruples your threat landscape. If you don't know what you're doing with appropriately and not all problems need an AI solution. So choose AI when you need it. And when you make that decision, understand the impact it's going to have in your organization. Just to close up that, so do you have some AI relevant security training in your materials? We have a deep dive. We have a bunch of sandbox stuff where you actually interact with real AI systems, and we teach you how to do it. All right. Thank you so much, Michael, I appreciate it. If you're here at the show, check out our check out Security journey. If not, look for you guys online soon. You got a website? Yes we do. Security journey.com. Take care folks.
Security Journey blends education and engagement to build lasting security awareness across dev teams. Their platform combines lessons, scenarios, and gamified content to shift security left—and make it stick. At RSAC, they emphasized measurable culture change, not just checkbox compliance. Want fewer bugs? Start with smarter devs.
Categories:
  • » Small World Big Data
  • » Cybersecurity Webinars
Channels:
  • Mike Matchett: Small World Big Data
News:
Events:
Tags:
  • rsac2025
  • cybersecurity
  • matchett
  • security
  • journey
  • security
  • training
  • developer
  • education
  • devsecops
  • culture
  • appsec
  • awareness
  • secure
  • coding
  • gamified
  • training
  • employee
  • security
  • engagement
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated

            Video's comments: Security Journey: Train Like Your Org Depends on It (Because It Does)

            Upcoming Spotlight Events

            • Sep
              11

              Cyera: An Executive’s Guide to Secure AI Adoption

              09/11/202501:00 PM ET
              • Sep
                16

                KnowBe4: Beyond DMARC: Closing Critical Gaps in Your Email Security Shield

                09/16/202501:00 PM ET
                More events

                Upcoming 360 View Events

                • Sep
                  25

                  360View: Email Security & Social Engineering Defense

                  09/25/202512:00 PM ET
                  • Oct
                    23

                    360View: Preventing Data Exfiltration: Keeping Enterprise Data Secure

                    10/23/202512:00 PM ET
                    • Nov
                      20

                      360View: Budget Optimization: Doing More with Less

                      11/20/202512:00 PM ET
                      More events

                      Upcoming Industry Events

                      • Sep
                        16

                        SOC 2 for Startups: Strategies to Reduce Costs, Enhance Efficiency, and Achieve Compliance

                        09/16/202512:00 PM ET
                        • Sep
                          16

                          HUMAN Security: CISO to CISO: A HUMAN conversation about Artificial Intelligence

                          09/16/202501:00 PM ET
                          • Sep
                            18

                            Trend Micro Webinar: Risk in Real Time: Agentic SIEM

                            09/18/202511:00 AM ET
                            More events

                            Recent Industry Events

                            • Aug
                              26

                              Renown Health Secures 10K Mailboxes & Stops $1M+ in Email Threats (Abnormal Security Webinar)

                              08/26/202501:00 PM ET
                              • Aug
                                25

                                Cyera: Harnessing AI to Transform the Landscape of Data Security

                                08/25/202510:55 AM ET
                                • Aug
                                  19

                                  Secureframe: CMMC 2.0 Insights: Understanding Compliance from an Expert Auditor's Perspective

                                  08/19/202512:00 PM ET
                                  More events

                                  Upcoming Events Calendar

                                  • 09/11/2025
                                    01:00 PM
                                    09/11/2025
                                    Cyera: An Executive’s Guide to Secure AI Adoption
                                    https://www.truthinit.com/index.php/channel/1374/an-executives-guide-to-secure-ai-adoption/
                                  • 09/16/2025
                                    12:00 PM
                                    09/16/2025
                                    SOC 2 for Startups: Strategies to Reduce Costs, Enhance Efficiency, and Achieve Compliance
                                    https://www.truthinit.com/index.php/channel/1410/soc-2-for-startups-strategies-to-reduce-costs-enhance-efficiency-and-achieve-compliance/
                                  • 09/16/2025
                                    01:00 PM
                                    09/16/2025
                                    KnowBe4: Beyond DMARC: Closing Critical Gaps in Your Email Security Shield
                                    https://www.truthinit.com/index.php/channel/1403/beyond-dmarc-closing-critical-gaps-in-your-email-security-shield/
                                  • 09/16/2025
                                    01:00 PM
                                    09/16/2025
                                    HUMAN Security: CISO to CISO: A HUMAN conversation about Artificial Intelligence
                                    https://www.truthinit.com/index.php/channel/1411/ciso-to-ciso-a-human-conversation-about-artificial-intelligence/
                                  • 09/18/2025
                                    11:00 AM
                                    09/18/2025
                                    Trend Micro Webinar: Risk in Real Time: Agentic SIEM
                                    https://www.truthinit.com/index.php/channel/1372/risk-real-time-agentic-siem/
                                  • 09/25/2025
                                    12:00 PM
                                    09/25/2025
                                    360View: Email Security & Social Engineering Defense
                                    https://www.truthinit.com/index.php/channel/930/360view-email-security-social-engineering-defense/
                                  • 10/23/2025
                                    12:00 PM
                                    10/23/2025
                                    360View: Preventing Data Exfiltration: Keeping Enterprise Data Secure
                                    https://www.truthinit.com/index.php/channel/931/360view-preventing-data-exfiltration-keeping-enterprise-data-secure/
                                  • 11/20/2025
                                    12:00 PM
                                    11/20/2025
                                    360View: Budget Optimization: Doing More with Less
                                    https://www.truthinit.com/index.php/channel/932/360view-budget-optimization-doing-more-with-less/
                                  • 12/18/2025
                                    12:00 PM
                                    12/18/2025
                                    360View: 2026 IT Predictions & Emerging Trends
                                    https://www.truthinit.com/index.php/channel/933/360view-2026-it-predictions-emerging-trends/
                                  Truth in IT
                                  • Sponsor
                                  • About Us
                                  • Terms of Service
                                  • Privacy Policy
                                  • Contact Us
                                  • Preference Management
                                  Desktop version
                                  Standard version