Team Wabbi
March 6, 2025
Click below to listen to this episode of Kabir’s Tech Dives, where host Kabir sits down with Brittany Greenfield, founder and CEO of Wabbi, to discuss how Wabbi is revolutionizing application security, the role of cybersecurity in development, and why modern businesses must rethink their approach to risk.
This interview originally appeared on Kabir’s Tech Dives’ YouTube on March 4, 2025
The Vision Behind Wabbi
About the session
This session is an episode of Kabir’s Tech Dives podcast, where Kabir interviews Brittany Greenfield, the founder and CEO of Wabbi. The focus of the conversation is on Brittany’s background, her transition into cybersecurity, and the mission and value proposition of her company, Wabbi
Key speakers
- Brittany Greenfield: Founder and CEO of Wabbi
- Kabir: Host of the podcast
Agenda
The agenda of the session includes:
- An introduction to Brittany Greenfield and her educational background.
- A discussion on her career path and why she chose cybersecurity.
- An exploration of the concept of cybersecurity as risk management, particularly in the context of application security.
- An overview of Wabbi’s business model and how it addresses the DevSecOps gap.
- A discussion on the impact of generative AI on cybersecurity.
- A reflection on the current state of cybersecurity and the challenges faced by enterprises.
- A lightning round with quick, Jeopardy-style questions.
Takeaways
Takeaway 1: Cybersecurity is fundamentally about risk management and balancing security with usability and performance.
Cybersecurity, according to Brittany Greenfield, is not just about building impenetrable walls but about managing risks effectively. “Just because you lock up your kid doesn’t mean that the kid’s going to be safe from everything,” she explained, drawing a parallel to the idea that overly restrictive security measures can be impractical. Instead, the focus should be on a balanced approach: “it’s about saying where am I willing to take a risk and okay go ahead and put a door on this room maybe I’m even willing to put a window on this room but what mitigating controls do I have.”
Greenfield further elaborated on this concept, emphasizing that security should be integrated into the development process without creating bottlenecks. “Security got left behind in this transformation and they’re also outnumbered with a hundred developers for every one application security manager,” she noted. Wabbi’s platform addresses this gap by managing the application security development life cycle, ensuring that both developers and security teams can work efficiently without sacrificing security.
Takeaway 2: The rise of generative AI has introduced new challenges in cybersecurity, necessitating a strong focus on good hygiene and risk management processes.
The advent of generative AI has significantly impacted cybersecurity, with malicious actors quickly adopting the technology. “Just as generative AI became common use for everybody else, you know the bad guys picked it up too,” Greenfield observed. She highlighted the importance of implementing strict policies and practices to prevent security vulnerabilities. “We have a policy that says you are absolutely not to paste our code into any kind of generative AI and then take any kind of generative AI and put it back into our code,” she stated. This approach ensures that even as technology evolves, the fundamentals of security hygiene remain intact.
Takeaway 3: Wabbi’s solution is designed to integrate security seamlessly into the development process, making it accessible to a wide range of companies, from startups to large enterprises.
Wabbi’s platform is designed to help companies, regardless of size, integrate security into their development processes without disrupting their workflows. “We deal with large Market to Fortune 500 Enterprises and DOD, but our particular approach deals with the nuance very well,” Greenfield said. The platform is particularly effective in highly regulated industries like fintech and healthcare, where the complexity of security requirements can be overwhelming. “For example, in fintech, your dashboard and the menu are secured differently from your bill pay and your wire transfers,” she explained. By automating the application security development life cycle, Wabbi ensures that companies can maintain strong security practices while continuing to innovate and grow.
Takeaway 4: The lack of basic cybersecurity hygiene remains a critical issue, even in an industry that spends billions on security solutions.
Despite the significant investments in cybersecurity, many companies still struggle with basic hygiene practices, leading to vulnerabilities that can be easily exploited. “Nine out of 10 breaches begin due to defects in code,” Greenfield pointed out. She emphasized the importance of fundamental security practices and the need for continuous improvement. “Until we get the fundamentals right, it doesn’t matter how many tools we buy,” she said. This highlights the ongoing challenge of ensuring that all organizations, from startups to large enterprises, prioritize and maintain robust security practices.
Takeaway 5: The future of cybersecurity lies in dynamic, process-oriented approaches that can adapt to the constantly evolving threat landscape.
Greenfield stressed the importance of a dynamic and process-driven approach to cybersecurity, rather than relying solely on static tools and barriers. “It’s about the process of implementing security and what the right thing is to do,” she said. This approach is crucial in a world where threats are constantly evolving. “What happens when that encryption gets broken? Your 45-minute server idea right, you know what happens when that encryption is there, a second line of defense, or maybe it’s just easier that you kill that and spin something new up,” she explained. This adaptable strategy ensures that companies can respond effectively to new threats without being overly reliant on any single security measure.
Insights surfaced
- Cybersecurity is fundamentally about risk management, balancing security with usability and performance.
- The 45-minute server strategy is a proactive approach to mitigate risks by frequently destroying and recreating servers.
- The shift towards DevSecOps is necessary to integrate security into the software development lifecycle without creating bottlenecks.
- Generative AI has increased the complexity of cybersecurity, and companies need to focus on good hygiene and process management.
- The fundamentals of cybersecurity, such as code hygiene, are often overlooked, leading to vulnerabilities.
- Cybersecurity is a trillion-dollar industry, and cyber crime is a significant threat that continues to grow.
- Cyber insurance can play a role in risk management, especially for small businesses, but it should not replace good security practices.
- The encryption-breaking capabilities of quantum computers highlight the need for dynamic and layered security strategies.
Key quotes
- “Cybersecurity is about saying where am I willing to take a risk and okay go ahead and put a door on this room maybe I’m even willing to put a window on this room but what mitigating controls do I have.”
- “We are the only platform on the market that’s broken this relationship to say here’s what matters in this situation and right so that’s like 5% of vulnerabilities or potentially ignored policies whatnot 15% of it can be fixed later and then we’re just going to monitor the 80%.”
- “The decision to pay the ransomware is saying the cost to the business and the cost to our ecosystem is greater than the cost of the ransomware.”
- “First, you know, the just as generative AI became common use for everybody else you know the bad guys picked it up too you saw an immediate uptick in attacks.”
- “What keeps me up at night is actually the fact that our cyber security hygiene despite it being such a large industry and the spending constantly growing on it we are still missing a lot of fundamentals in how we’re developing in software.”
- “There are a lot of free resources, OWASP is great, etc., come up with your base processes that’s as simple as that then you can program them into Wabbi.”
- “The 45-minute server idea right you know what happens when that encryption gets broken, you kill that and spin something new up.”
- “Every company is a software company nowadays, and everybody needs to be doing good application security.”
- “Insurance can provide good structures especially when you’re looking at small businesses that may not have their first foray into cyber security.”
- “This is not a new problem and we’re still figuring out how to answer it and nobody really knows there’s not a perfect answer to it.”
Want to understand the future of application security?
Related Articles

DevSecOps in Digital Transformation
Click below to listen to this episode of Digital Shifts aka Corporate Evolution Tales, where host Mariam sits down with Brittany Greenfield, founder and CEO of Wabbi, to discuss how to align security with business goals, and why transformation is a continuous...

Building A Secure SDLC to Make DevSecOps a Daily Habit
Building a Secure SDLC to Make DevSecOps a Daily Habit In a world where security and development teams juggle countless priorities, building a secure SDLC must not take a backseat. It is not a luxury or an add-on but a fundamental practice that development...

The Hidden Risks: Internal Failures in Security by Design
The Hidden Risks: Internal Failures in Security by Design When we think about cybersecurity breaches, external attackers often come to mind—hackers, malware, and cybercriminals targeting organizations from the outside. However, breaches can also stem from within,...

Bridging Cybersecurity and Innovation
Click below to listen to this episode of Strategy Next, where host Jon Lobb sits down with Brittany Greenfield, founder and CEO of Wabbi, to discuss the critical role of foundational security practices, and how organizations can navigate the balance between innovation...

How To Overcome Common Hurdles In Adopting DevSecOps – Forbes –
This article originally appeared on Forbes on February 11, 2025 Expert Panel® Forbes Councils Member Forbes Technology Council COUNCIL POST| Membership (Fee-Based) getty Taking a more proactive and culture-based approach to security, DevSecOps stresses...

Behind Closed Doors: What AppSec Leaders Are Really Thinking About DevSecOps in 2025
Recently, I had the opportunity to sit down with a group of AppSec leaders for a closed-door conversation about their 2025 DevSecOps strategy. No vendors. No slides. Just candid discussions about the challenges they’re facing, what’s working, and what’s keeping them...

20 Tech-Related Threats We Must Not Ignore (And Solutions) – Forbes –
This article originally appeared on Forbes on December 19, 2024 Expert Panel® Forbes Councils Member Forbes Technology Council COUNCIL POST| Membership (Fee-Based) getty We rely on technology more than ever before in both our work and personal lives. It...

Secure SDLC: Turning Speed Into Efficiency to Mitigate Tech’s Greatest Vulnerability
In a world where technology drives nearly every aspect of our personal and professional lives, it’s no surprise that speed is often seen as the ultimate metric of success. Companies race to deliver new features, patch vulnerabilities, and launch products as quickly as...

Tackling Dev Sec Ops in 2025: A Practical Path Forward
The misconception of DevSecOps as a collection of tools or isolated practices has held back its true potential. In 2025, the shift will be about embedding security within every phase of development—not as an interruption, but as an enabler of efficient, secure...

Tech In 2025: Industry Leaders Detail Their Top Challenges – Forbes –
This article originally appeared on Forbes on December 3, 2024 Expert Panel® Forbes Councils Member Forbes Technology Council COUNCIL POST| Membership (Fee-Based) getty Staying on top of emerging tools and trends is all in a day’s work for tech leaders across...

Wabbi Announces General Availability of its Advanced Application Security Risk Index Enabling Risk-Management-by-Design
BOSTON / Press Release / February 21, 2024 Wabbi, the leader in Application Security Posture Management (ASPM), today announced the general availability of its Advanced Wabbi Risk Index. The Application Security Risk Index is a key component of Wabbi’s...

Wabbi Announces Phil Lawrence as New CTO to Spearhead Next Generation Application Security Posture Management Platform
BOSTON, MA, USA / November 20, 2023 /Originally Published at EINPresswire.com Industry leading ASPM provider, Wabbi, has appointed Phil Lawrence as CTO to lead product vision and growth in this high-demand cybersecurity space. Today, Wabbi (www.wabbisoft.com), the...

Wabbi Founder & CEO, Brittany Greenfield, Named 40 under 40
BOSTON, MA, USA / August 16, 2023 Brittany Greenfield, CEO & Founder of Wabbi, the leading ASPM platform, has been named to Boston Business Journal's prestigious 40 Under 40 list for 2024. This annual award honors 40 outstanding professionals under the age of 40...

Wabbi Named in Three Gartner® Reports as ASPM Sample Vendor
BOSTON, MA, USA / August 1, 2023 For more information on Wabbi's Application Security Posture Management platform, visit https://wabbisoft.com. Wabbi, a leading provider of Application Security Posture Management (ASPM) solutions, is pleased to announce that it has...

WABBI NAMED IN 2023 GARTNER® HYPE CYCLE FOR APPLICATION SECURITY REPORT AS AN ASPM SAMPLE VENDOR
BOSTON, MA, USA / July 25, 2023 / Originally Published at EINPresswire.com/ Wabbi, the leading Application Security Posture Management (ASPM) platform, today announced that it has been recognized as a Sample Vendor for Application Security Posture Management (ASPM) in...

Wabbi Named in 2023 Gartner® How to Select DevSecOps Tools for Secure Software Delivery Report as an ASPM Sample Vendor
BOSTON, MA, USA / June 14, 2023 /Originally Published at EINPresswire.com Wabbi announces its inclusion in the 2023 Gartner® How to Select DevSecOps Tools for Secure Software Delivery report as an Application Security Posture Management (ASPM) sample vendor. Gartner®...

Wabbi Unlocks the Secret to Enterprise Secrets Management
Wabbi unveils new Secrets Mangement solution as part of their leading application security posture management and orchestration platform. BOSTON, MA, USA / May 17, 2023 /Originally Published at EINPresswire.com Today, Wabbi, a leader in Application Security Posture...

Wabbi Named to CyberTech 100 for Leadership in Application Security Posture Management & Orchestration for Financial Institutions
BOSTON, MA / May 11, 2023 / EINPresswire.com Wabbi, the leading application security posture management & orchestration company, announced today that it has been named in the CyberTech100 list for 2023. Sponsored by FinTech Global and now in its fourth year, the...

Wabbi Named Winner of the Coveted Global InfoSec Awards during RSA Conference 2023
Wabbi Wins Editor’s Choice for DevSecOps in 11th Annual Global InfoSec Awards at #RSAC 2023 SAN FRANCISCO/ Press Release / April 24, 2023 Wabbi is proud to announce we have won the following award(s) from Cyber Defense Magazine (CDM), the industry’s leading electronic...

Wabbi enables Risk Management by Design with Release of Next-Gen Vulnerability Management in Release 23.1
BOSTON / Press Release / March 27, 2023 Wabbi, the leading provider of Application Security Orchestration & Correlation, announced today the launch of their next-generation vulnerability management solution. With this new offering, Wabbi is now the only tool that...

Behind Closed Doors: What AppSec Leaders Are Really Thinking About DevSecOps in 2025
Recently, I had the opportunity to sit down with a group of AppSec leaders for a closed-door conversation about their 2025 DevSecOps strategy. No vendors. No slides. Just candid discussions about the challenges they’re facing, what’s working, and what’s keeping them...

Secure SDLC: Turning Speed Into Efficiency to Mitigate Tech’s Greatest Vulnerability
In a world where technology drives nearly every aspect of our personal and professional lives, it’s no surprise that speed is often seen as the ultimate metric of success. Companies race to deliver new features, patch vulnerabilities, and launch products as quickly as...

Tackling Dev Sec Ops in 2025: A Practical Path Forward
The misconception of DevSecOps as a collection of tools or isolated practices has held back its true potential. In 2025, the shift will be about embedding security within every phase of development—not as an interruption, but as an enabler of efficient, secure...

Why AppSec Orchestration Delivers ROI for Dev, Sec & Ops Teams
Building Tangible ROI Through Dev Sec Ops Investments Historically, it has been tough to justify the ROI of cybersecurity investments because cybersecurity success often means nothing happened: no breaches, data losses, or compliance failures. This “absence of...

Building Good Application Security Hygiene
In today’s fast-evolving tech landscape, application security (AppSec) hygiene is an essential factor for every business handling data. AppSec hygiene entails establishing thorough security processes, understanding risks, and ensuring that security protocols are...

DevSecOps: Unlocking the Convergence of Security and User Experience
In today’s technology landscape, balancing robust security with an optimal user experience (UX) and high-performance standards is a delicate act. As Wabbi’s CEO, Brittany Greenfield, recently shared, no code can ever be entirely flawless, and neither can security....

Debunking the Myth: Open-Source Code Isn’t As Secure as Everybody Thinks (and what DevSecOps can do about it)
Open-source software (OSS) is everywhere, and for good reason. It’s a powerful way to accelerate innovation, reduce development costs, and maintain flexibility. But while the benefits of OSS are clear, the security implications are often misunderstood. The open nature...

Fortifying Your Defenses: How ASPM Can Combat MITM Attacks
Wabbi’s CEO, Brittany Greenfield, recently discussed with Forbes strategies organizations should adopt to strengthen their defenses and safeguard stakeholders from MITM attacks. So, we’re diving into why these types of cyberattacks are a wake-up call for improving...

Vulnerability Management Beyond Defects: Why True AppSec Requires Holistic Risk Mitigation
In a recent Forbes article, Wabbi's CEO, Brittany Greenfield, weighed in on a critical question about ransomware preparedness and response. When asked about a common mistake organizations make, Greenfield emphasized the importance of recognizing vulnerabilities not...

Understanding the Application Security Posture Management Landscape
As the importance of Application Security has grown, so has the confusion around how to successfully maintain the complete application security lifecycle– not to mention stay up to date with the alphabet soup of acronyms we must contend with. Consequently, as...