SheHacksPurple: October 2025

Washington DC, Manchester UK, Online Events, StackOverflow, and more!

The SheHacksPurple Nerd-a-licious Newsletter

💜 Hit ‘reply’ to send me a message! I read every response and love hearing from you. 💜 

Hello Everyone!

I’m back from SecTor, OWASP Ottawa, appearances at several virtual events including (Wild West Hackin’ Fest!), an in-person training contract, and visiting my parents in Ontario. I also finished all the audio recording edits for Alice and Bob Learn Secure Coding while I was there (look for it on audible Oct 28th)! Now I’m at home, preparing my small farm for the winter, and I made a little video of how to winterize dahlia tubers (the roots of the plants, they hibernate over the winter) in case you’re curious. I’ve also got a lot of free webinars coming up (with Harness and Smithy!), and a brand new article in StackOverflow. Plus, travel plans for DC (OWASP Global AppSec), and the UK (NDC Security, OWASP London and potentially more events), so please check out the events section if you have time.

FYI, we (the project team) will be releasing the brand new OWASP Top Ten Risks to Web Applications, on stage, at OWASP Global AppSec, in Washington, DC, November 6th!

I should also mention that I was very honoured to receive The Rita Award at Wild West Hackin’ Fest, which is given to one individual a year for making significant contributions to the cyber security community. ☺️ It was such a surprise… I wasn’t expecting that. Especially coming from someone like John Strand who does so much. It’s probably good we couldn’t get the mic to work as I was pretty much speechless (but very happy about it). ☺️☺️☺️☺️

I’ve also hired a few students via a government program from Venture for Canada to help me plan our my new community project, DevSecStation. I have 3 of them, part time, for 7 weeks. I forgot what it was like to work with young people, oh my, so many amazing ideas already!

Tanya

My trip to SecTor in Toronto!

We Surveyed 250+ Enterprise Security Leaders on Offensive Security Strategy

Praetorian’s 2026 Offensive Security Outlook Report examines how enterprise leaders are thinking about offensive security strategy in 2026, and how offensive measures should inform defensive tactics.

The hard realities are that only 15% of enterprises are confident that they can track their IT asset inventory, and 68% report that they still have thousands of unresolved vulnerabilities. Nearly 30% can’t correlate threat data across sources, which results in material risk creation.

This free 23 page report discusses not only the current industry statistics, but measures that you can take to reduce material risk.

New Content!

Events!

Random

Remind me next time I say “I’m going to write another book” just how much work it is. And then maybe punch me for good measure?

We end with a meme.

Replace “from StackOverflow” with “from an AI” and BINGO!