Application security, MSSP, MSP

Don’t Fix. Forecast.

COMMENTARY: AppSec too often feels like a rerun - same tools, same dashboards, same cycle of scanning, patching, and replacing. There's an entire industry around fixing what’s already broken instead of predicting what’s likely to fail. The goal isn’t more tools or faster scanners; it’s smarter anticipation. Predictive AppSec isn’t about reacting to alerts - it’s about understanding the behaviors, patterns, and contexts that create them. When you can forecast where risk will emerge, you stop firefighting and start actually securing. That’s where the shift has to happen.


I was recently on a product demo listening to a vendor walk through their AppSec platform - slides about vulnerability scanning, remediation workflows, and integration capabilities.

And all I could think was: this is the same presentation I’ve heard from three other vendors this month. Same architecture. Same promises about finding vulnerabilities faster. The only differences they could point to were surface-level - better UI, more intuitive dashboards, easier integration.

Meanwhile, their customers are still stuck in the same cycle: buy the tool, scan for vulnerabilities, attempt to patch, slow down development, frustrate the dev team, get fed up, replace the tool two years later. The market's oversaturated. We keep treating the symptoms instead of the disease.

Stuck on a Treadmill

Traditional AppSec is reactive. You point a scanner at your code, find vulnerabilities, patch what you can, deploy, and move to the next cycle. Everyone talks about “shift left” - catching problems earlier in development. Great. You find 2,000 vulnerabilities before production instead of after.
Now what?

You still don’t know which five of those 2,000 actually threaten your business. You still slow down your developers. You still end up hunting for a different tool 18 months later because this one didn’t solve the fundamental problem.

The issue isn’t bad technology. The guidelines work. The scanning tools find real vulnerabilities. But organizations approach AppSec as a fix-it operation: find the problem, patch it, move on. We’re fixers when we need to be forecasters.

Prediction Requires Knowing When to Look

The shift to predictive AppSec means applying intelligence at every stage of development—before you write code, while you’re writing it, and after you deploy.

Before you start coding: we know from past projects that certain types of functions introduce specific vulnerabilities. Building authentication with OAuth? You’ll probably hit token management issues at a particular stage. Predict that risk upfront and design around it.

During development: developers are human. I’ve seen patterns where certain team members consistently push code with more vulnerabilities than others. Maybe they’re tired. Maybe they’re moving too fast. Maybe they haven’t been trained on secure coding practices. Track those patterns. That’s a predictable risk you can address through training, pairing, or additional review layers.

Throughout the lifecycle: every decision about architecture, dependencies, and deployment creates future risk. How much contextual intelligence can you gather about what you’re building, who’s building it, and where it’s going? Risk isn’t just technological. Behavior, environment, process - all of it feeds prediction.

You move from “we found the problem, now fix it” to “we see where problems will likely emerge - let’s address them now.”

Volume Without Context Is Noise

Here’s what happens today: you run a scan, get back 2,000 vulnerabilities, and stare at a list of severity ratings - low, medium, high, critical. No business context. No revenue impact. No actual prioritization beyond generic risk scores.

What you need to know: which three to five vulnerabilities would genuinely damage the business if exploited? Which ones could cause a 15% revenue drop if breached? Which ones expose customer data in ways that violate compliance requirements?

One client I worked with had a critical vulnerability in a legacy system that processed financial transactions. They also had 47 medium-severity findings in an internal testing environment that three people accessed. Guess which one got fixed first? The testing environment—because the legacy system was “too hard to patch.”

Predictive AppSec uses behavioral analytics and business context to identify which flaws actually threaten what matters. Then you allocate resources accordingly. Everything else is just alert fatigue.

Service Providers Need to Stop Being Transactional

If you’re an MSSP or reseller, you can’t just sell tools and disappear. That keeps customers on the treadmill.

Leading customers from reactive to predictive requires three stages:

Crawl: help them handle current issues better. Improve their incident response. Give them visibility into what’s actually happening in their environment. You can’t predict risks you can’t see.

Walk: deploy tools that enable prediction - behavioral analytics, contextual scanning, risk quantification. Give them the capability to forecast where vulnerabilities will emerge based on code patterns, developer behavior, and deployment context.

Run: shift the entire mindset. Predictive AppSec requires full lifecycle coverage - implementation, operation, configuration management, and ongoing maintenance post-production. You’re not securing code; you’re enabling innovation with appropriate guardrails. That means staying engaged after deployment, providing continuous vigilance, not handing off at launch, and moving to the next deal.

Service providers that position themselves as partners in this evolution will shape how their customers approach security. The transactional ones will keep replacing tools every 18 months without solving anything.

Nobody Gets to Sit This Out

I talked to a hospital last month - over 100 years in business, major regional player. When I brought up AppSec, they said they don’t really do software development. Meanwhile, the urgent care clinic down the street has apps for blood results, appointment scheduling, and telehealth visits.

Even businesses that seem purely physical run on software. The fryers at KFC have computers that control cooking times. Home thermostats use AI to predict when to turn on based on occupancy patterns. I worked with an entertainment company on their security posture - they’ve got archaic animation systems running on code nobody’s examined in years. Their CISO told me directly, “We don’t know what we don’t know.”

Your competitors are evolving. Some hospital systems in your region are already offering better digital experiences because they invested in secure application development. As applications become more ambitious - more automated, more interconnected, more dependent on AI - the consequences of insecurity grow exponentially.

AI won’t replace security professionals. Security professionals who know how to leverage predictive AppSec will replace those who don’t. The same principle applies to organizations. Evolve or get left behind.

Prediction Doesn’t Stop at Deployment

Everyone focuses on “shift left.” Find vulnerabilities before production. Absolutely critical. But then what?

You secure the code, fix the vulnerabilities, launch the application, and move on to the next project. Meanwhile, threats evolve. Configurations drift. New attack vectors emerge. Dependencies get updated with their own vulnerabilities. The application you secured six months ago is exposed in ways you never scanned for.

Predictive AppSec requires ongoing vigilance post-production and at runtime - continuously forecasting risk across the entire lifecycle of the application. That’s where most organizations fail. They treat security as a gate you pass through, not a practice you maintain.

Service providers either prove their value here, or prove they’re just another vendor selling point solutions. The future belongs to forecasters who understand that prediction is continuous, not a one-time event before launch.


MSSP Alert Perspectives columns are written by trusted members of the managed security services, value-added reseller and solution provider channels or MSSP Alert's staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].

Jeremy Ventura

Currently, as the Field CISO at global systems integrator Myriad360, Jeremy Ventura is a seasoned cybersecurity professional and advisor, specializing in information security best practices, driving defense strategies, and safeguarding organizations against evolving threats. With extensive experience in vulnerability management, API security, email security, incident response, and security center operations, he has honed his expertise through roles at premier security vendors and internal security teams. Follow Jeremy on LinkedIn.

You can skip this ad in 5 seconds