
Risk-First: Stars of Software
Claim This Podcastby Risk-First
Podcast Overview
<p>Risk-First is about understanding how to manage risks in software development.<br />But there are a million jobs in technology besides coding, testing, and releasing.</p><p>How does risk inform those jobs?<br />And could it be that being good at <i>any</i> job in tech really means being good at risk management?</p><p><br />Is all work… risk management?</p><p></p><p>I’m Rob Moffat, and in each episode I sit down with leaders, builders, and thinkers from across the software industry to understand what they do, the risks they navigate every day, and the lessons they’ve learned along the way.</p><p></p><p>Because behind every successful system, career, and company…<br />there’s someone making smart decisions about risk.</p><p></p><p>And if you want to be great in your chosen field, you need to be great at managing risk.</p><p><br />So who better to learn from… than the stars?</p><p></p><p>Welcome to <b>Risk-First: Stars of Software</b>.</p><p></p>
Language
🇺🇲
Publishing Since
2/14/2026
1 verified contact email on file for Risk-First: Stars of Software
Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.
Recent Episodes

May 30, 2026
Risk-First: Stars of Software #9 - Dave Thomas
<p><b>Dave Thomas: Pragmatism, Feedback Loops, and Why AI Doesn’t Change the Fundamentals</b></p><p></p><p>In this episode of Risk-First: Stars of Software, Rob Moffat talks with Dave Thomas, co-author of The Pragmatic Programmer, original signatory of the Agile Manifesto, founder of The Pragmatic Bookshelf, and long-time thinker on software simplicity, agility, and feedback-driven development. </p><p></p><p>Dave has spent decades shaping how software developers think about programming — from pragmatism and feedback loops, through Agile, Ruby, and testing, to his more recent work on simplicity and AI-assisted software development.</p><p></p><p>Along the way, Rob and Dave dive into:</p><ul><li>Why nearly every idea in <i>The Pragmatic Programmer</i> still applies in the age of AI </li><li>The role of feedback loops in software development</li><li>Why Agile was originally about values and adaptability</li><li>The origins of the Agile Manifesto and how it unexpectedly “went viral” after Snowbird</li><li>How military concepts like “commander’s intent” parallel modern agile software teams</li><li>Why organisations built around top-down command structures struggle to be genuinely adaptive</li><li>How delighting users requires empathy, not just technical competence</li><li>Why empathy matters not only for people, but for machines, systems, and software design itself</li><li>The possibility that future AI-generated software may eventually become unreadable to humans</li><li>Why AI may ultimately reinforce good software design practices like small modules, meaningful names, and readable structure</li><li>The ongoing “CVE apocalypse”</li><li>Why writing books — and software — is fundamentally about synthesising and refining ideas from reality into reusable forms</li><li>Dave’s belief that the best way to navigate an increasingly complex world is to live “agilely”: taking small reversible steps guided by feedback</li></ul><hr /><h2>Links</h2><p><b>The Pragmatic Programmer</b><br /><a rel="noopener noreferrer nofollow" href="https://pragprog.com/titles/tpp20/the-pragmatic-programmer-20th-anniversary-edition/" target="_blank">https://pragprog.com/titles/tpp20/the-pragmatic-programmer-20th-anniversary-edition/</a><br />Classic software engineering book introducing concepts like pragmatism, tracer bullets, orthogonality, and feedback-driven development.</p><p></p><p><b>The Pragmatic Bookshelf</b><br /><a rel="noopener noreferrer nofollow" href="https://pragprog.com" target="_blank">https://pragprog.com</a><br />Technical publishing company focused on practical software development books across programming, AI, testing, and engineering.</p><p></p><p><b>Agile Manifesto</b><br /><a rel="noopener noreferrer nofollow" href="https://agilemanifesto.org" target="_blank">https://agilemanifesto.org</a><br />The original Agile Manifesto and principles created at Snowbird in 2001.</p><p></p><p><b>Simplicity</b><br /><a rel="noopener noreferrer nofollow" href="https://pragprog.com/titles/dtlang/simplicity/" target="_blank">https://pragprog.com/titles/dtlang/simplicity/</a><br />Dave Thomas’ recent book exploring simplicity, empathy, systems thinking, and software design.</p><p></p><p><b>FINOS</b><br /><a rel="noopener noreferrer nofollow" href="https://www.finos.org" target="_blank">https://www.finos.org</a><br />Open source foundation discussed in relation to software supply chain security and open source sustainability.</p><p></p><p><b>Dave Thomas’ Substack</b><br /><a rel="noopener noreferrer nofollow" href="https://newsletter.pragmaticengineer.com" target="_blank">https://newsletter.pragmaticengineer.com</a><br />Dave’s writing and commentary on software, AI, and programming ideas.</p>

May 16, 2026
Risk-First: Stars of Software #8 - James Mcleod
<p><b>James McLeod: Open Source Communities, Hackathons, and Why Open Source Opens Doors</b></p><p>In this episode of Risk-First: Stars of Software, Rob Moffat talks with James McLeod, Open Source Lead at NatWest Group, FINOS board member, and organiser of London JS. </p><p>James has spent years at the intersection of enterprise technology and grassroots developer communities — helping banks engage with open source while also building one of London’s best-known JavaScript meetups. Before NatWest, he worked directly within FINOS helping financial institutions collaborate through open source, standards, and shared engineering practices.</p><p>The conversation explores how open source communities form around uncertainty, why meetups and hackathons matter far more than most organisations realise, and how the current explosion of AI tooling mirrors the chaos and creativity of the early JavaScript ecosystem.</p><p>Along the way, Rob and James dive into:</p><ul><li>How the rise of React, Node.js, npm, and frontend frameworks created a “primordial soup” developers had to collectively figure out together </li><li>Why London JS was created to help developers learn collaboratively rather than depend on individual experts </li><li>The importance of creating communities where people can safely experiment, fail, and learn in public </li><li>Why meetups act as “distilled serendipity” — compressing useful collisions between people and ideas</li><li>How open source communities help reduce dependency on proprietary ecosystems and centralized knowledge</li><li>Why hackathons are valuable not just for innovation, but for exposing firms to external thinking and new technologies </li><li>The challenge of maintaining momentum after hackathons end and preventing ideas from “rotting in a repo” </li><li>How open source participation helps organisations avoid becoming technologically entrenched </li><li>Why enterprises often misunderstand open source as purely an IP issue instead of a collaborative engineering model </li><li>James’ experiences moving from highly proprietary Microsoft ecosystems into open source development cultures </li><li>How AI today feels similar to the early React ecosystem: lots of tools, rapid change, and nobody really knowing the “correct” answers yet </li><li>Why AI communities need openness, shared learning, and emotional intelligence — especially when many developers are anxious about the future of work </li><li>The idea that “open source opens doors” — creating careers, friendships, startups, and opportunities far beyond code itself</li></ul><hr /><h2>Links</h2><p><b>London JS</b><br /><a rel="noopener noreferrer nofollow" href="https://www.meetup.com/london-js/" target="_blank">https://www.meetup.com/london-js/</a><br />London-based JavaScript and frontend development community bringing together developers, speakers, and technology enthusiasts.</p><p><b>FINOS (Fintech Open Source Foundation)</b><br /><a rel="noopener noreferrer nofollow" href="https://www.finos.org" target="_blank">https://www.finos.org</a><br />Foundation enabling collaboration on open source projects and standards across financial services.</p><p><b>NatWest Group</b><br /><a rel="noopener noreferrer nofollow" href="https://www.natwestgroup.com" target="_blank">https://www.natwestgroup.com</a><br />UK banking group active in open source collaboration and FINOS initiatives.</p><p></p>

April 25, 2026
Risk-First: Stars of Software #7 - Viktor Petersson
<p><b>Viktor Petersson: SBOMs, Supply Chains, and the Reality of Software Transparency</b></p><p>In this episode of Risk-First: Stars of Software, Rob Moffat talks with Viktor Petersson, founder of SBOMify and co-founder and CEO of Screenly.</p><p></p><p>Viktor has spent years building real-world systems at the intersection of hardware, cloud, and security—from early Raspberry Pi-based digital signage through to globally deployed platforms used by organisations like NASA and Capital One. More recently, he’s focused on one of the most talked-about—and misunderstood—areas in modern software: Software Bills of Materials (SBOMs).</p><p></p><p>The conversation explores why SBOMs have suddenly become a regulatory and industry focus, whether they actually solve the problems they claim to, and what it really means to understand what’s inside the software we run.</p><p></p><p>Along the way, Rob and Viktor dive into:</p><ul><li>What an SBOM actually is—and why it’s often misunderstood as just “a file”</li><li>Why software supply chain transparency is much harder than it sounds</li><li>The gap between regulatory intent and engineering reality</li><li>Why generating SBOMs is easy—but making them useful is not</li><li>The problem of incomplete, inaccurate, or outdated dependency data</li><li>How transitive dependencies create hidden and compounding risk</li><li>Why most organisations don’t actually know what’s in their software</li><li>The difference between compliance-driven SBOMs and operationally useful ones</li><li>Why “perfect visibility” is probably unattainable—and what to do instead</li><li>How SBOMs intersect with vulnerability management and incident response</li><li>The role of tooling, automation, and standards in making SBOMs usable</li><li>Whether SBOMs reduce risk—or just make it more visible</li><li>How supply chain security is evolving alongside AI-generated code</li></ul><hr /><h2>Links</h2><p><b>sbomify</b><br /><a rel="noopener noreferrer nofollow" href="https://sbomify.com" target="_blank">https://sbomify.com</a><br />Platform focused on generating, managing, and operationalising Software Bills of Materials.</p><p><b>Screenly</b><br /><a rel="noopener noreferrer nofollow" href="https://www.screenly.io" target="_blank">https://www.screenly.io</a><br />Digital signage platform originally built on Raspberry Pi, now deployed globally across enterprise environments.</p><p></p><hr /><h2>Topics and concepts discussed</h2><p><b>Software Bill of Materials (SBOM)</b><br />A structured representation of the components, libraries, and dependencies that make up a piece of software.</p><p><b>Software Supply Chain Risk</b><br />Risks arising from dependencies on external code, including vulnerabilities, maintainership gaps, and compromised packages.</p><p><b>Transitive Dependencies</b><br />Dependencies of dependencies, which often introduce hidden complexity and risk.</p><p><b>SBOM Accuracy & Freshness Problem</b><br />The challenge of keeping SBOMs up to date and reflective of real-world deployed systems.</p><p><b>Compliance vs Operational Security</b><br />The difference between producing artefacts to satisfy regulators and actually improving security posture.</p><p><b>Vulnerability Management Integration</b><br />Using SBOMs as input into processes that identify, prioritise, and remediate security vulnerabilities.</p><p><b>AI-Generated Code Risk</b><br />The increasing difficulty of understanding software composition as AI accelerates code generation and reuse.</p>
9 total episodes available
Deep-dive analytics for Risk-First: Stars of Software
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is Risk-First: Stars of Software?
<p>Risk-First is about understanding how to manage risks in software development.<br />But there are a million jobs in technology besides coding, testing, and releasing.</p><p>How does risk inform those jobs?<br />And could it be that being good at <i>any</i> job in tech really means being good at risk management?</p><p><br />Is all work… risk management?</p><p></p><p>I’m Rob Moffat, and in each episode I sit down with leaders, builders, and thinkers from across the software industry to understand what they do, the risks they navigate every day, and the lessons they’ve learned along the way.</p><p></p><p>Because behind every successful system, career, and company…<br />there’s someone making smart decisions about risk.</p><p></p><p>And if you want to be great in your chosen field, you need to be great at managing risk.</p><p><br />So who better to learn from… than the stars?</p><p></p><p>Welcome to <b>Risk-First: Stars of Software</b>.</p><p></p> - How often does this podcast release new episodes?
This podcast updates daily.
- Where can I listen to this podcast?
This podcast is available on 4 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
Yes, this podcast regularly features guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.
