CodeSecCon Brings Developers and Security Teams Together to Fix a Growing Blind Spot
A virtual conference focused on building safer software is drawing both coders and cybersecurity professionals to the same table, a pairing that rarely happens and badly needs to.

Key points
- CodeSecCon is a free virtual event aimed at closing the gap between software developers and cybersecurity professionals.
- The conference focuses on application security, meaning the practice of finding and fixing weaknesses in software before attackers can use them.
- SecurityWeek highlighted the event as part of broader industry efforts to push security earlier into the software-building process.
- Developers and security teams historically work in separate silos, a split that leaves software riddled with preventable flaws.
Most software is written with speed in mind, not safety. Deadlines come first. Security checks, when they happen at all, get bolted on at the end, and by then fixing problems costs far more time and money than catching them early would have.
CodeSecCon is a virtual conference designed to break that habit.
What is this event actually about?
The conference gathers software developers and cybersecurity professionals in the same online space to work through application security, which is the discipline of spotting and closing weaknesses in software before criminals find them. The goal is practical: give developers the thinking they need to write safer code from the first line rather than the last.
It's relevant to ordinary people because the apps they rely on daily run on that code. A flaw can expose passwords or payment details to whoever finds it first. Our coverage of AI coding assistants found an average of 15 security flaws per project across 16 major tools, and the problem has only grown sharper as those same tools get better at finding and exploiting the flaws they leave behind.
Why does the developer-security split cause problems?
Developers are trained to build features. Security teams are trained to break things. Both groups are usually under pressure, and they rarely share what they know until it's too late.
When security arrives late, fixing a single flaw can require rewriting large chunks of code. Research from the National Institute of Standards and Technology has long shown that flaws caught during design cost roughly thirty times less to fix than those caught after release. AI tools compounding the pace of code output make that cost gap worse, not better.
Conferences like CodeSecCon exist to put both groups in conversation before the damage is done.
Should you worry about this?
You don't need to write code to care about it. Every app you trust with personal information depends on decisions made by developers, often under time pressure, often without security training.
If you work in an organisation that builds software, asking your development team how security is handled during the build process is a reasonable question. The answer will tell you a lot.
The gap between developers and security professionals is well-documented and genuinely costly. What's less clear is whether a single virtual event moves the needle, or whether it mostly draws an audience already convinced. Watch whether the conversation produces changed practices, not just shared slides.



