ostering.com
  • Posts
  • Talks
  • Privacy
Brett Crawley

Author: Brett Crawley (48)

Brett is a Seasoned Application Security Engineer and Thought Leader with a Proven Track Record in Software Engineering and Security Best Practices.

Brett has over 10 years of application security experience and 25 years in software engineering. He holds (ISC)² certifications including CISSP, CSSLP, and CCSP. As the author of Threat Modeling Gameplay with EoP and the project lead for the OWASP Application Security Awareness Campaigns, Brett actively contributes to the security community. He also maintains the Ostering.com blog, where he shares insights on security practices.

Brett has successfully collaborated with teams to define security best practices and integrate security by design into their software development lifecycle (SDLC). His training initiatives in threat modeling have led to significant improvements in design quality and security awareness within organizations.

In his spare time, Brett enjoys sports, gardening, cooking, and photography. He is fluent in both English and Italian and holds dual citizenship.

Key Skills: Secure by Design, Privacy by Design, Threat Modeling (STRIDE, EoP, Privacy, LinddunGO, Plot4AI), Secure Coding, Vulnerability Management, and more.

Brett welcomes connections and opportunities to collaborate on innovative security solutions.

 

 

Data Protection and Data Privacy Part 2 of 2

Data Protection and Data Privacy - Part 2 of 2

From Principle to Practice: Privacy in the Real...

June 23, 2026
Untangling the Confusion

Data Protection and Data Privacy - Part 1 of 2

Untangling the Confusion People often confuse these two...

June 9, 2026
PQC Part 2: The Plan, the Order, and the Bill

Get PQC Ready PDQ - Part 2

The Plan, the Order, and the Bill In...

May 26, 2026

Get PQC Ready PDQ - Part 1

Quantum, AI, and the Window That’s Already Closing...

May 13, 2026

Threat Modeling AI Systems: A Complete Playbook for Practitioners

The Blast Radius - Edition [4] Over the...

April 28, 2026

Sparse or Dense? Claude Mythos, Dan Geer, and Where We Should Actually Be Spending Our Effort

Last week, Anthropic announced Claude Mythos Preview and...

April 15, 2026

Software Engineering Has Regressed 50+ Years Since AI

Bear with me on this train of thought....

April 1, 2026

Dependency Pruning and Tree Shaking

Cutting the Dead Wood from Your Dependency Graph...

March 31, 2026

Threat Modeling Your Dependencies - Part 2

Mitigating Third-Party Component Risk: Swapping the Cancer for...

March 22, 2026

Threat Modeling Your Dependencies - Part 1

How One Bad Library Can Poison Your Entire...

March 18, 2026

Your SBOM Data Has Been Gathering Dust - Until Now

I’ve been talking about graphs for dependency analysis...

March 9, 2026

SAST vs Claude Code Security: A Deep Dive

SAST vs Claude Code Security: A Deep Dive...

February 23, 2026

Why SAST is Broken!

Why SAST is broken, and how it could...

February 22, 2026

Cursor as your Secure Dev Team

Cursor as your Secure Dev Team What I...

February 21, 2026
Pulling Change

Kicking Off Security Maturity

Building an AppSec Program: A Collaborative Approach Are...

October 12, 2025
AI Vulnerability Factory

Is Your AI Philosophy Broken?

AI-Generated Code: Productivity Gains, Security Pains, and the...

September 21, 2025
See the older articles

Browse all Topics

  • Accountability
  • AI
  • AI Security
  • ANTLR
  • Application Security
  • AppSec
  • Artificial Intelligence
  • Authentication
  • Authorization
  • Awareness
  • Binary
  • CAPEC
  • Centrality
  • Certificates
  • Change
  • Claude Code Security
  • Clean House
  • Compiler Compilers
  • Compliance
  • Cryptography
  • Culture
  • Cursor AI
  • Cybersecurity
  • Dark Patterns
  • Data Privacy
  • Data Protection
  • Dependency Analysis
  • Dependency Pruning
  • DevSecOps
  • Digital Signatures
  • Elevation of Privilege
  • English
  • EUAIAct
  • Framework Fixators
  • Games
  • Grammar
  • Graph Analysis
  • GSSCredential
  • Hashing
  • HttpClient
  • HttpComponents
  • Inner-Source
  • IT Extremists
  • Java
  • JavaCC
  • JavaScript
  • JBoss
  • JNDI Realm
  • Kerberos
  • Key Distribution Center
  • languages
  • LDAP
  • Leadership
  • learning
  • Legislation
  • Manners
  • Miro
  • Miroverse
  • Mitre
  • Motivation
  • Origins
  • Osteria
  • OWASP
  • Ownership
  • PageRank
  • Parser Generators
  • PicketLink
  • Post Quantum Cryptography
  • Posters
  • Precision
  • Privacy
  • Privacy by Design
  • Privacy Engineering
  • Programming Languages
  • Public Key Cryptography
  • Python
  • Quantum Computing
  • Reachability
  • Recall
  • Responsibility
  • Risk
  • Running
  • SAML
  • SAST
  • SBOM
  • SCA
  • Scrum Nazis
  • Scrum Talibans
  • Secure by Design
  • Security
  • Security by Design
  • Security Maturity
  • Social Engineering
  • Software Architecture
  • Software Composition Analysis
  • Software Design
  • Software Development
  • Software Engineering
  • Source Code
  • SSL
  • SSO
  • Strategy
  • STRIDE
  • Supply Chain Security
  • Threat Modeling
  • Threat Modelling
  • TLS
  • Tomcat
  • Top 10
  • Tree Shaking
  • TRIM
  • Trustworthyness
  • Vulnerability Management
  • Wildfly
ostering.com

{Osteria}{Running}

Copyright 2025 Brett Crawley

 

This website uses cookies
Select which cookies to opt-in to via the checkboxes below; our website uses cookies to examine site traffic and user activity while on our site, and to provide social media functionality. Privacy Policy
Cookie settings
We use cookies to enhance your browsing experience, serve content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Privacy Policy
  • Required

    These cookies are used to enhance your browsing experience, and serve content.

  • analytics

    Our site anonymizes all of its tracking data, making it fully GDPR-compliant