What I like most about SecDim is how effectively it shifts application security from being mainly a security-team responsibility to becoming a practical capability within engineering.
We used it as part of a broader DevSecOps program. The goal wasn’t just to have developers complete security training, but to help them recognize, understand, and prevent real vulnerabilities in their day-to-day work. The hands-on approach, realistic scenarios, and emphasis on learning by doing made a noticeable difference compared with traditional awareness training.
It also fit especially well with our Security Champions model and our broader shift-left initiatives. SecDim gave developers a practical environment to build security skills, while our security team could focus on enabling teams, improving controls, and embedding security into the development lifecycle - instead of repeatedly covering the same fundamentals.
For me, the biggest value is that it treats developers as engineers rather than compliance recipients. That makes security training much easier to integrate into an engineering culture.
MF
Mazyar F.
Cybersecurity at iQ Group |
Offsec | Software Development | Security Research | Threat intel | AI | Ex-Pharmacist
SecDim is a developer-first secure-code wargame that drops you into production-grade apps packed with real-world vulnerabilities. No slides, no boring tutorials—our challenges track today’s top incidents so you can cut the crap and learn secure coding for real.