
Sign up to save your podcasts
Or


Send a text
In this episode of Secure Insights, James is joined by Chris Hertz, co-founder and CEO of Heeler to unpack one of the biggest and most underestimated risks in modern software development: open-source security.
The conversation looks at why traditional approaches to managing open-source libraries often create more noise than clarity, leaving teams buried in alerts while real risk goes unresolved. Chris shares how combining static analysis, runtime context, and automated remediation changes the way organisations think about open-source vulnerabilities shifting the focus from volume to what’s actually exploitable and worth fixing.
Chris also draws on his experience founding and scaling multiple venture-backed technology companies, including leadership roles at DivvyCloud and New Signature, to discuss how security teams and developers can work more effectively together as organisations grow. This episode is a practical listen for engineering leaders, security teams and founders who want a more realistic way to manage risk without slowing development down.
By NDK CyberSend a text
In this episode of Secure Insights, James is joined by Chris Hertz, co-founder and CEO of Heeler to unpack one of the biggest and most underestimated risks in modern software development: open-source security.
The conversation looks at why traditional approaches to managing open-source libraries often create more noise than clarity, leaving teams buried in alerts while real risk goes unresolved. Chris shares how combining static analysis, runtime context, and automated remediation changes the way organisations think about open-source vulnerabilities shifting the focus from volume to what’s actually exploitable and worth fixing.
Chris also draws on his experience founding and scaling multiple venture-backed technology companies, including leadership roles at DivvyCloud and New Signature, to discuss how security teams and developers can work more effectively together as organisations grow. This episode is a practical listen for engineering leaders, security teams and founders who want a more realistic way to manage risk without slowing development down.