logo
AppSec Challenges and How We Do It

Wait, first - what’s AppSec?

AppSec is the shorthand for Application Security. Which means to make sure that the monday.com platform is running secure software so that our customers’ data that is stored on monday.com is safe.

 

That doesn’t sound too difficult - what are the challenges?

Well, there are a whole bunch of challenges here. One of which is the fact that while developers do a fantastic job - sometimes there are bugs, and sometimes these bugs can become vulnerabilities that can lead to things going wrong.

Another challenge is running security at scale - how to make sure security is implemented all around when we’re a super-fast paced company in constant growth.

 

So, how do you do it?

First, like many companies, we’ve implemented an S-SDLC (Secure Software Development Life Cycle). 

Our S-SDLC includes, but is not limited to:

  • Training developers
  • Security design review (aka threat modeling)
  • Peer review for every piece of software written in monday.com
  • Security tools running on our PRs, such as (but not limited to):
    • Dangeroid (looks for dangerous patterns or cases that require more attention)
    • SAST (static code analysis)
    • Secret scanner (search for passwords or tokens in our code)
    • SCA (check for vulnerable open source dependencies)

 

While we still have much more to improve in the scaling landscape, we automate as much of our process as possible. Also, the monday.com way is that even the newest developer takes responsibility for the code they write. So, while we have training for all developers - it’s their responsibility to attend and implement what they’ve learnt. The AppSec team is in daily contact with all R&D domains - but we expect (and they do) the teams to come to us for a review and to discuss the most secure way to implement their project.

 

Also, by running the tools in the pipeline - the developers get immediate feedback and can fix their code/dependencies before reaching the peer review, and thus saving 🕜 and 💰.

 

What else does AppSec do in monday.com?

Well, as the guardians of our platform, we handle a few more super interesting tasks that keep us on edge. These include:

 

Bug Bounty

monday.com maintains a private bug bounty program  where we allow hackers to try and find vulnerabilities in our software. The AppSec team is the one that manages the program (putting out campaigns for specific vulnerabilities or features, hacker engagement, and more), reviews the findings (understand, reproduce, prioritize, etc), and take the vulnerabilities from end-to-end with the development teams to get it fixed and pay the hackers for their valuable findings and improvement of our platform.

 

Penetration Testing

In addition to the automatic testing and bug bounty on our platform, we also engage with a professional team of pen-testers who dig deep into our platform, sometimes with some gray-box testing where we give them some pointers on how we’ve implemented our features. This allows skipping some of the reconnaissance required during an attack and allowing deeper and more focused testing.

 

Anomaly & Abuse Detection

Together with our Data Security team, we identify the misuses of our amazing platform by malicious actors. These include opening accounts to send out spam utilizing our notification system, phishing attempts with our WorkForms, and more. We can identify where things go differently than we expected and catch bugs/vulnerabilities early on.

 

Incident Response Team

Unfortunately, we have software bugs and vulnerabilities. Sometimes, these vulnerabilities actually caused some security measures to fail and maybe a user was able to perform an action they shouldn’t have or see data they don’t have access to. These are referred to as security or privacy incidents.

The AppSec team leads the Incident Response Team for such incidents on our platform. This includes coordinating with R&D for investigation and fixing, working with the Privacy team and CX to communicate with the affected cust

עוד תוכן בנושא
Personal Lessons on Maximizing Impact with Minimal Resources

בלוג

4 דק'

Personal Lessons on Maximizing Impact with Minimal Resources

Basics
Entrepreneurship
Product
Enter Card קריאת הבלוג

בלוג

4 דק'

The Art of Lean Team Building: Practical Strategies for Startups

Basics
HR
Enter Card קריאת הבלוג
The Art of Lean Team Building: Practical Strategies for Startups

בלוג

4 דק'

Building a Security Department - Values, Culture and Thoughts

Basics
Data & Security
Enter Card קריאת הבלוג
Building a Security Department - Values, Culture and Thoughts
Unveiling the Secrets of the IT Security World

בלוג

4 דק'

Unveiling the Secrets of the IT Security World

Basics
Data & Security
Enter Card קריאת הבלוג

פודקאסט

70 דק'

Jason Lemkin (SaaStr), Eran Zinman & Roy Mann (monday.com) - Measuring SaaS companies in 2023

Jason Lemkin (SaaStr), Eran Zinman & Roy Man (monday.com) sit down to discuss how should we measure SaaS companies in 2023

Data & Security
Finance
Growth
Enter Card האזנה לפרק
Jason Lemkin (SaaStr), Eran Zinman & Roy Mann (monday.com) - Measuring SaaS companies in 2023

בלוג

5 דק'

Why is Security Compliance Important?

Basics
Data & Security
Enter Card קריאת הבלוג
Why is Security Compliance Important?
Why SOC 2 might be critical for your Round A

בלוג

4 דק'

Why SOC 2 might be critical for your Round A

Basics
Data & Security
Enter Card קריאת הבלוג

בלוג

5 דק'

Why did we change our team from DBA, and what is DBRE anyway?

Basics
Data & Security
Enter Card קריאת הבלוג
Why did we change our team from DBA, and what is DBRE anyway?

בלוג

5 דק'

Entrepreneurship and Meaning: A Personal Journey in Finding Purpose

Basics
Entrepreneurship
Inspirational
Enter Card קריאת הבלוג
Entrepreneurship and Meaning: A Personal Journey in Finding Purpose
Product-market fit: What it is and how to find it

בלוג

4 דק'

Product-market fit: What it is and how to find it

Basics
Entrepreneurship
Product
Enter Card קריאת הבלוג

בלוג

4 דק'

How To Build a Team From Scratch

Basics
Entrepreneurship
HR
Enter Card קריאת הבלוג
How To Build a Team From Scratch

בלוג

5 דק'

The seven principles that guide our managers‘ communications

Basics
Entrepreneurship
Enter Card קריאת הבלוג
The seven principles that guide our managers‘ communications
How to create a privacy compliance strategy

בלוג

2 דק'

How to create a privacy compliance strategy

Data & Security
Enter Card קריאת הבלוג

בלוג

7 דק'

How to Produce Content that People will Want to Consume

The content we consume has changed drastically in recent years. It’s much more visual, much shorter, and much more direct. The product that most exemplifies the way we’ve grown accustomed to consuming content is the Story: short, precise, and once we’ve exhausted it, an easy tap of the finger will skip to the next one. …

AppSec Challenges and How We Do It Read More »

Basics
Marketing
Enter Card קריאת הבלוג
How to Produce Content that People will Want to Consume

בלוג

4 דק'

Four Insights into Performance Marketing We Learned Along the Way

These days, Performance Marketing is the most basic tool for reaching customers for your product. However, it is also a relatively new tool – our paradigms are constantly changing, and there are things you have to learn the hard way before mastering it. Here are several insights we’ve reached after making quite a few mistakes …

AppSec Challenges and How We Do It Read More »

Basics
Marketing
Enter Card קריאת הבלוג
Four Insights into Performance Marketing We Learned Along the Way
Recap: Starting a Partnership Program

פודקאסט

07 דק'

Recap: Starting a Partnership Program

Asaf Fradkin and Barak Zigdon share the most important things to know when starting a partnership program, and best practices for building the first relationships.

Basics
Partnerships
Enter Card האזנה לפרק

בלוג

5 דק'

Five steps to developing a data-driven culture in your organization

1. Assessing the current state Any cultural change should begin with an understanding of the existing culture or belief even before attempting the change. A key component in developing a data-driven culture is changing the way people think about data. In many organizations the data collection process is complicated and ineffective. Many times it’s about …

AppSec Challenges and How We Do It Read More »

Data & Security
Enter Card קריאת הבלוג
Five steps to developing a data-driven culture in your organization

פודקאסט

50 דק'

S4S Talks: Turning 30k Support Tickets a Month Into Actionable Insights

Effie Arman, Head of Customer Success Israel at monday.com, walked us through what we call ”Voice of Customer”.

Customer success
Data & Security
Product
Enter Card האזנה לפרק
S4S Talks: Turning 30k Support Tickets a Month Into Actionable Insights
The ABC’s of A/B Testing

בלוג

14 דק'

The ABC’s of A/B Testing

Imagine you have a product that you want to tweak and improve. That being said, you’re not sure...

Basics
Data & Security
Product
+1
Enter Card קריאת הבלוג
Personal Lessons on Maximizing Impact with Minimal Resources

בלוג

4 דק'

Personal Lessons on Maximizing Impact with Minimal Resources

Basics
Entrepreneurship
Product
Enter Card קריאת הבלוג
The Art of Lean Team Building: Practical Strategies for Startups

בלוג

4 דק'

The Art of Lean Team Building: Practical Strategies for Startups

Basics
HR
Enter Card קריאת הבלוג
Building a Security Department - Values, Culture and Thoughts

בלוג

4 דק'

Building a Security Department - Values, Culture and Thoughts

Basics
Data & Security
Enter Card קריאת הבלוג
Unveiling the Secrets of the IT Security World

בלוג

4 דק'

Unveiling the Secrets of the IT Security World

Basics
Data & Security
Enter Card קריאת הבלוג
Jason Lemkin (SaaStr), Eran Zinman & Roy Mann (monday.com) - Measuring SaaS companies in 2023

פודקאסט

70 דק'

Jason Lemkin (SaaStr), Eran Zinman & Roy Mann (monday.com) - Measuring SaaS companies in 2023

Jason Lemkin (SaaStr), Eran Zinman & Roy Man (monday.com) sit down to discuss how should we measure SaaS companies in 2023

Data & Security
Finance
Growth
Enter Card האזנה לפרק
Why is Security Compliance Important?

בלוג

5 דק'

Why is Security Compliance Important?

Basics
Data & Security
Enter Card קריאת הבלוג
Why SOC 2 might be critical for your Round A

בלוג

4 דק'

Why SOC 2 might be critical for your Round A

Basics
Data & Security
Enter Card קריאת הבלוג
Why did we change our team from DBA, and what is DBRE anyway?

בלוג

5 דק'

Why did we change our team from DBA, and what is DBRE anyway?

Basics
Data & Security
Enter Card קריאת הבלוג
Entrepreneurship and Meaning: A Personal Journey in Finding Purpose

בלוג

5 דק'

Entrepreneurship and Meaning: A Personal Journey in Finding Purpose

Basics
Entrepreneurship
Inspirational
Enter Card קריאת הבלוג
Product-market fit: What it is and how to find it

בלוג

4 דק'

Product-market fit: What it is and how to find it

Basics
Entrepreneurship
Product
Enter Card קריאת הבלוג
How To Build a Team From Scratch

בלוג

4 דק'

How To Build a Team From Scratch

Basics
Entrepreneurship
HR
Enter Card קריאת הבלוג
The seven principles that guide our managers‘ communications

בלוג

5 דק'

The seven principles that guide our managers‘ communications

Basics
Entrepreneurship
Enter Card קריאת הבלוג
How to create a privacy compliance strategy

בלוג

2 דק'

How to create a privacy compliance strategy

Data & Security
Enter Card קריאת הבלוג
How to Produce Content that People will Want to Consume

בלוג

7 דק'

How to Produce Content that People will Want to Consume

The content we consume has changed drastically in recent years. It’s much more visual, much shorter, and much more direct. The product that most exemplifies the way we’ve grown accustomed to consuming content is the Story: short, precise, and once we’ve exhausted it, an easy tap of the finger will skip to the next one. …

How to Produce Content that People will Want to Consume Read More »

Basics
Marketing
Enter Card קריאת הבלוג
Four Insights into Performance Marketing We Learned Along the Way

בלוג

4 דק'

Four Insights into Performance Marketing We Learned Along the Way

These days, Performance Marketing is the most basic tool for reaching customers for your product. However, it is also a relatively new tool – our paradigms are constantly changing, and there are things you have to learn the hard way before mastering it. Here are several insights we’ve reached after making quite a few mistakes …

Four Insights into Performance Marketing We Learned Along the Way Read More »

Basics
Marketing
Enter Card קריאת הבלוג
Recap: Starting a Partnership Program

פודקאסט

07 דק'

Recap: Starting a Partnership Program

Asaf Fradkin and Barak Zigdon share the most important things to know when starting a partnership program, and best practices for building the first relationships.

Basics
Partnerships
Enter Card האזנה לפרק
Five steps to developing a data-driven culture in your organization

בלוג

5 דק'

Five steps to developing a data-driven culture in your organization

1. Assessing the current state Any cultural change should begin with an understanding of the existing culture or belief even before attempting the change. A key component in developing a data-driven culture is changing the way people think about data. In many organizations the data collection process is complicated and ineffective. Many times it’s about …

Five steps to developing a data-driven culture in your organization Read More »

Data & Security
Enter Card קריאת הבלוג
S4S Talks: Turning 30k Support Tickets a Month Into Actionable Insights

פודקאסט

50 דק'

S4S Talks: Turning 30k Support Tickets a Month Into Actionable Insights

Effie Arman, Head of Customer Success Israel at monday.com, walked us through what we call ”Voice of Customer”.

Customer success
Data & Security
Product
Enter Card האזנה לפרק
The ABC’s of A/B Testing

בלוג

14 דק'

The ABC’s of A/B Testing

Imagine you have a product that you want to tweak and improve. That being said, you’re not sure...

Basics
Data & Security
Product
+1
Enter Card קריאת הבלוג
רוצים לקחת חלק בשיתוף ידע?
אם גם אתם רוצים להצטרף למשימה שלנו להעשיר את האקוסיסטם בידע ותובנות, אם אתם רוצים לשאול אותנו משהו, אם אתם מרגישים שיש משהו שעזר לכם וכולם צריכים לדעת, נשמח לשמוע. 
כתבו לנו
icon
המייל נשלח!
נותרו: 0 מיילים לחודש. מתחדש ב-1 לחודש
סגור
icon
הפגישה נקבעה!
נותרו: 0 פגישות לחודש. מתחדש ב-1 לחודש
סגור
סגור
icon
הבקשה שלך התקבלה, תודה :)
אנחנו עוברים על כל הפרטים, ובקרוב ניצור איתך קשר בנוגע לשולחן העגול.
סגור
icon
קיבלנו את בקשתך לפתיחת שולחן עגול!
נעבור על הבקשה ובימים הקרובים ישלח אליך מייל אישור והשולחן יופיע ברשימת השולחנות העגולים.
סגור

שליחת מייל

שליחת מייל למשקיע/ה