Leveraging Product Management to Shift Left in Small SaaS Teams

sirris_be 45 views 17 slides Oct 17, 2024
Slide 1
Slide 1 of 17
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17

About This Presentation

Leveraging Product Management to Shift Left in Small SaaS Teams

Sirris | Nick Boucart


Slide Content

NICK BOUCART Leveraging Product Management to Shift Left in Small SaaS Teams SIRRIS 5:30 AM ET

Hi, I’m Nick Software Engineer turned Advisor Work @ SIRRIS not-for-profit technological innovation co-pilot in Belgium Focus on software startups and scaleups CoderDojo volunteer This talk is made possible thanks to support of

CyberSecurity Problem

CyberSecurity Problem Product Management Problem

This got us thinking….

This got us thinking…. A lot

Some Context on Belgian startups/scaleups Pre 2018: founder-led sales – trust in the team and the solution T hen came GDPR, NIS2, DORA, AI ACT, … and serious incidents CS much earlier on the table

Reality of many SaaS teams Small team Many of our customers have dev teams < 10 Lots of to do’s it is all about getting the right features out Little security knowledge Most teams are relatively ok, they just don’t know it, or cannot prove it (*) . ( *) as long as they don’t invent their own crypto

We thought we helped them with… OWASP ASVS, DSOMM, SAMM – find your security related requirements there(*) Group coaching – learning and growing with peers Threat modelling (*) ginormous amount of respect for the work of OWAPS

Maybe understanding security related concerns of the customers, is a part of a product managers job…

As yourselves…. (doomsday edition) What if we go offline for a day? How do we think that would impact our customers? What if customer data shows up on the internet? Have a brainstorm with product and dev and create a common mental model

Document and use this mental model Demonstrate you understand the concerns of customers before they bring them up themselves Prioritize your investements in CS, balancing out with feature development Will help you with SLA and contract negotiations

Build a Persona Would this feature trigger questions? How would we deal with them?

Closing words This won’t replace certifications, nor make you be secure by itself It does increase awareness of how customers look at you from a CS perspective
Tags