People, Practices & CareerPeople, Practices & Career
Conference50min
BEGINNER

Knocking on the Wrong Door: The Six Developers You’ll Meet in Security

SECUR-E, an OWASP framework using COM-B, helps teams diagnose why secure development fails—whether due to skills, environment, or motivation—not just awareness. It identifies six developer patterns and guides tailored interventions, improving secure software practices without blame.

talk.summaryAiDisclaimer

Enrique Larios Vargas
Enrique Larios VargasOWASP

talkDetail.whenAndWhere

Thursday, October 8, 16:30-17:20
TBA 3
talks.roomOccupancytalks.noOccupancyInfo
talks.description
Secure by Design does not fail only because developers lack security awareness. It often fails because teams prescribe the wrong intervention: training when the real blocker is time, tools, motivation, or trust. In this practitioner-focused talk, we introduce SECUR-E, the OWASP Security Culture Project v2.0 framework that uses COM-B to help developers and software teams diagnose what actually blocks secure development behavior.

Through a relatable story, practical examples, and six memorable developer patterns, Skeptic, Enthusiast, Compliant, Unaware, Resistant, and Embedded, the audience will learn why one-size-fits-all security programs miss, bore, or backfire. We will show how a lightweight self-assessment maps Capability, Opportunity, and Motivation into team insights, then translates those insights into better interventions: evidence for Skeptics, support for Enthusiasts, autonomy for Resistant profiles, foundational help for Unaware developers, and amplification for Embedded security-minded builders.

Key takeaways: stop asking “why don’t developers care?”; diagnose whether the blocker is skill, environment, or motivation; choose interventions that fit the pattern; protect psychological safety; and use SECUR-E as a practical playbook for building secure software teams without blame. Audience: software developers, tech leads, security champions, and engineering managers with beginner-to-intermediate knowledge.
security culture
com-b
psychological safety
secure development
talks.speakers
Enrique Larios Vargas

Enrique Larios Vargas

OWASP

Netherlands

Enrique Larios Vargas is a Security and Learning Specialist with over 8 years of experience designing impactful learning and enablement programs across fintech, engineering, and security domains. With a background as a university lecturer in software engineering in Peru, the Netherlands, and Canada, he brings a unique blend of technical insight and behavioral science to his work. Enrique is the lead author of the research paper “DASP: A Framework for Driving the Adoption of Software Security Practices”, which explores how behavioral models like COM-B can drive secure development. He is passionate about helping developers move beyond compliance and build a meaningful, human-centered security culture.