VOOZH about

URL: https://thenewstack.io/why-grace-francisco-made-developers-dance-at-a-conference/

⇱ Why Grace Francisco Made Developers Dance at a Conference - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2023-10-13 07:41:06
Why Grace Francisco Made Developers Dance at a Conference
AI / Frontend Development / Security / Software Development

Why Grace Francisco Made Developers Dance at a Conference

Developer relations head says it’s time for developers to embrace the Shift Left movement and take security to heart.
Oct 13th, 2023 7:41am by Loraine Lawson
👁 Featued image for: Why Grace Francisco Made Developers Dance at a Conference
Grace Francisco at the International JavaScript conference. Photo by Loraine Lawson.

Grace Francisco, a former developer, made developers dance to drill home a point: Developers need to shift left and left again to embrace security before writing the first line of code.

“I like to incorporate emotions of concepts because it helps with setting a memory,” Francisco told the International JavaScript audience, who somewhat begrudgedly indulged the dance during her Sept. 27 keynote address. “I’m going to help you understand why we technologists have to embrace this responsibility to be part of that cultural shift. It’s super important.”

Francisco is CMO and head of developer relations at Pangea, which is a security services firm that offers security APIs for developers — so she has a vested interest in selling this point. But that doesn’t mean she’s not right: It’s too little too late to talk about security after an app is deployed. As security experts have warned time and time again, security needs to start with developers.

Plus, this is a real problem: She pointed out one survey had revealed 67% of developers “were honest enough” to admit they knowingly submitted insecure code.

Meanwhile, hackers aren’t script kiddies in basements any more — they’re organized crime and nation states: Highly funded, highly organized and extremely efficient, she added.

“Hackers are going to use AI to their advantage to exploit your code,” she said. “This is why you need to really embrace the responsibility [of] security.”

Personally Identifiable Information (PII) should be treated as the Crown Jewels of the company, she said. At an average of $146 per breach per record, attacks adds up over the course of 10,000 records, she said.

But beyond money, what Francisco wanted to emphasize is the personal impact of a breach. She shared a series of vignettes to drive home the point that when code is insecure, real people can suffer.

  • In the UK, a woman’s data was leaked in a breach involving a mobile phone. An ex-boyfriend was able to take that leaked information, take over her phone without her knowing, learn her new address, and stalk her for weeks.
  • Emergency departments Manchester Memorial and Rockville General (Connecticut) were forced to close and reroute those who needed care to a nearby medical center after a breach caused by a ransomware attack on Prospect Medical Holdings of Los Angeles. Its health care facilities also had to cancel elective surgeries and urgent care; with podiatry, wound care, women’s wellness, and gastroenterology services also suspended.
  • The Colonial Pipeline attack caused massive gas panic across 17 Eastern states and literally had people trying to pour gasoline into plastic bags, she said. Colonial ultimately paid the ransom of $5 million dollars worth of bitcoin.
  • The SolarWinds cyberattack was the largest attack on the supply chain in history involving 100 US companies and nine federal agencies. It’s estimated that at least 1,000 engineers globally were involved in the sophisticated attack, Francisco said, pointing out that, again, these aren’t script kiddies of the 1990s.
  • AI seems likely to add to the problem. Already, it’s lead to public breaches, with Samsung employees putting their code and presentations into ChatGPT, Francisco pointed out.

She compared the problem to trying to rescue drowning children — you can keep pulling them out one at a time, or you can go upstream to stop whoever is pushing them into the river in the first place. So far, developers have been pulling them out one at a time, instead of solving the real problem, she added.

“We as developers, we are doing this every single day that we ship insecure code and the people that are driving the customer journey — that’s you, that’s your friends, that’s your family, that is everyone who has to deal with your code,” Francisco said. “Software’s not regulated. There is no responsibility to the threats that we are imposing on all of our users and we don’t think about our responsibility to security to safety. For our users, it’s equivalent to no brakes, no airbags.”

TRENDING STORIES
Loraine Lawson is a veteran technology reporter who has covered technology issues from data integration to security for 25 years. Before joining The New Stack, she served as the editor of the banking technology site Bank Automation News. She has...
Read more from Loraine Lawson
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: SolarWinds.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.