06 Jan 2026
50m

Why Most Security Advice Fails and What Actually Reduces Risk | Bob Lord

Podcast cover

The TPRM Podcast

Software security currently relies on unsafe components, practices, and configurations, creating brittle systems that unfairly burden users. Bob Lord, a veteran security leader, argues that the industry must move beyond "Hack Lore"—outdated or ineffective security myths—to focus on "Secure by Design" principles. Rather than blaming users for phishing or human error, organizations should treat security as a fundamental product quality issue. Meaningful progress requires aligning economic incentives, where customers collectively demand higher standards and vendors take ownership of security outcomes. Drawing parallels to the automotive industry’s shift toward safety, the discussion highlights that systemic change is possible when developers are empowered with "paved roads" and when security is treated as a core business requirement rather than an afterthought. Ultimately, shifting responsibility upstream and simplifying security for the end-user remains the most effective path toward a more resilient digital economy.

Outlines

Sign in to continue reading, translating and more.

Open full episode in Podwise