Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Application security learning: what actually helps people retain it?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A personal AppSec learning guide argues that effective upskilling depends on matching format to learning style, using communities and mentors, and practising recall through short, repeatable sessions, based on Semgrep’s published essay. The governance lesson is that security training works best when it is accessible, contextual, and reinforced, not treated as a one-off event.

NHIMG editorial — based on content published by Semgrep: a practical essay on learning application security over time

Questions worth separating out

Q: How should security teams design training so people actually retain it?

A: Use a mix of formats, then force retrieval.

Q: Why does mentorship quality matter in security training?

A: Because bad mentoring can train fear, confusion, or unsafe habits, while good mentoring builds confidence and sound judgment.

Q: What do organisations get wrong about personalised security training?

A: They often assume personalisation means better outcomes by default.

Practitioner guidance

  • Build role-specific learning paths Create separate learning tracks for developers, security analysts, and IAM practitioners so each group gets the concepts, tooling, and exercises most relevant to its decisions.
  • Use short recall cycles Add low-stakes quizzes, flash reviews, and short hands-on exercises after each training block so people must retrieve the information rather than just recognise it.
  • Pair training with active community support Encourage staff to join communities of practice, internal discussion groups, or external chapters where they can ask questions and compare approaches.

What's in the full article

Semgrep's full article covers the practical learning methods this post intentionally leaves at a higher level:

  • Personal background on career switching, dyslexia, and limited training budgets that shaped the author’s approach to learning
  • Specific community and mentoring experiences, including OWASP chapter involvement and public speaking as a learning method
  • Detailed examples of free and low-cost AppSec learning resources, including community courses and project-based study
  • Practical suggestions for choosing formats, pacing study, and building a self-directed learning routine

👉 Read Semgrep's article on practical application security learning methods →

Application security learning: what actually helps people retain it?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Security capability is a retention problem before it is a training problem. Organisations often assume that publishing guidance or buying courses creates capability, but the article shows that people need repetition, context, and confidence before knowledge becomes useful. That is especially true in IAM and NHI programmes, where control intent is easy to describe and harder to execute consistently. Teams that want durable outcomes should treat learning design as part of the control environment, not an optional add-on.

A question worth separating out:

Q: How do you know if identity security training is actually working?

A: Look for faster and cleaner governance outcomes, such as fewer review errors, better exception decisions, and lower support burden when policies change. Completion rates alone are weak evidence. Effective training changes how people apply controls under real conditions, especially when identity scope expands across humans, machines, and automation.

👉 Read our full editorial: Continuous learning in appsec depends on format, community and recall



   
ReplyQuote
Share: