- 22-27 June 2008 - Ken will be
presenting a talk on Security Testing of software while
at the annual FIRST
conference in Vancouver, British Columbia, Canada.
The paper and slides will shortly be available in our
reading room, so stop back
and check it out.

- 15-19 September 2008 - Ken will be a Distinguished Lecturer at the European Network and Information Security Agency’s (ENISA) summer school on network and information security, in Heraklion, Crete, Greece. More details to come...
- 14 October 2008 - Ken will be presenting a session on Secure SDLCs Compared at the 6th Annual Software Process Symposium in Edison, New Jersey, USA.
- 3-5 November 2008 - Ken will be presenting a 3-day hands-on workshop on building secure J2EE web applications for Technology Transfer in Rome, Italy. This event is open to the public, so check out their web site for details on how to register.
If you would like to contact us regarding a speaking or training engagement, please contact us directly.
Announcements
- 5 July 2007 - Ken re-elected onto FIRST Steering Committee: KRvW's founder, Ken van Wyk, has been re-elected to serve on the Steering Committee and Board of Directors of the Forum of Incident Response and Security Teams (FIRST), an organization he's been involved with for nearly 20 years. FIRST is a non-profit professional organization made up of security teams that are truly on today's information security front lines.
- 3 May 2007 - Rick and Bruce Schneier jointly publish an opinion column on c|net News. The column is on the dangers and shortcomings of the new U.S. National ID card system.
- 7 June 2004 - Ken's first monthly column hits eSecurityPlanet. This innaugural column is about the dangers of relying too heavily on the reactive product solutions that have become so pervasive and popular in the IT Security industry. Note that an archive of Ken's monthly columns is being maintained here in the reading room of KRvW Associates' web site.
- 28 May 2004 - On 2 June 2004, IT Security news portal eSecurityPlanet will be launching their new web site. Ken will be among the small group of monthly columnists for the site, with his first column appearing on 7 June 2004. Keep an eye out on the eSecurityPlanet site for the new columns.
- 20 April 2004 - Announcing the availability of a Japanese translation of Secure Coding. Information is available via O'Reilly Japan. (Kanji browser required.)
- 16 February 2004 - Those of you that follow KRvW's Secure Coding mailing list, SC-L, can now get to the list via RSS feed. The RSS feed is provided as a free service by the good folks at Mail-Archive.com. Just point your RSS aggregator at http://www.mail-archive.com/sc-l@securecoding.org/maillist.rdf.
Recent Events
- 1-3 April 2008 - Rick presented a talk entitled "An Empirical Look at the Vulnerability Debate" at the "Terrorism: Training, Threats, Tactics and Technology" conference, sponsored by Sandia National Laboratories and the Terrorism Research Center.
- 7-9 May and 12-14 May 2008 - Ken teamed up with AdAstra to present two hands-on, 3-day workshops on web application security issues, in Singapore.
- 4 March 2008 - While in town for the SecAppDev class, Ken spoke at the OWASP chapter meeting held at the Katholieke Universiteit. His talk was a quick comparison of several secure software development methodologies including Microsoft's SDL, Cigital's "Touchpoints", and OWASP's own CLASP. After the talk, asserted the identity of various members' CAcert.org X.509 certificates.
- 3-7 March 2008 - Ken again taught several modules for the Secure Application Development ("SecAppDev") seminar, sponsored by the Solvay Business School in Brussels, Belgium and the Katholieke Universiteit, Leuven.
- 10-11 December 2007 -- Ken was in Singapore to teach a hands-on 2-day class on web application security.
- 16 July 2007 - Ken presented a keynote presentation and short tutorial on software security at the Congreso Internacional en Ingeneria de Software y Sus Aplicaciones in Guadalajara, Mexico. Conference information can be found on the conference website.
- 17-22 June 2007 - As a long-time supporter of the Forum of Incident Response and Security Teams (FIRST), Ken was a speaker at the organization's 19th annual conference in Seville, Spain. Hope to see you there.
- 16-17 April 2007 - For the third year in a row, Ken was a speaker at the Software Security Summit.
- 26 March 2007 - Ken presented a 1-day tutorial on Software Security at the annual Software Engineering Process Group meeting in Austin, TX. Information on SEPG can be found here.
- 26 February thru 2 March 2007 - Ken once again taught several modules for the Secure Application Development seminar, sponsored by the Solvay Business School in Brussels, Belgium and the Katholieke Universiteit, Leuven. Keep an eye on the site above for information on next year's sessions.