Agentic Coding: The Earthquake That Topples the Software Factory

Agentic Coding: The Earthquake That Topples the Software Factory

Abstract

The tectonic plates beneath software development are shifting. They are moving too fast to predict what the landscape will look like when the earthquake hits. Still, we are sure that the coming earthquake will be on a scale that not only brings down the software factory but also changes the landscape so much that few landmarks on the current map will be identifiable afterwards.

In particular, as AI systems plan, generate, test, deploy, and operate software, roles that were redefined by agile will be entirely replaced by new ones. Domain experts and managers can now create and deploy systems without technical expertise.

This talk will help you identify if you or your organization is standing on any of these precarious fault lines:

  • Roles that will emerge/disappear as builders move beyond factory walls
  • Team and feedback boundaries failing under autonomous AI loops
  • Governance and security models that no longer apply to who and how software is built

About the Presenter 

Larry Maccherone is a pioneer in agile, security, and agentic AI development. At Comcast, Larry launched and scaled the DevSecOps Transformation program over five years, safely empowering 600 agile and DevOps teams to take ownership of their products’ security.

Larry was a founding Director at Carnegie Mellon’s CyLab, researching cybersecurity and software engineering. While there, he co-led the launch of the DHS-funded Build-Security-In initiative. Larry has also served as principal investigator for the NSA’s Code Assessment Methodology project, which wrote the book on evaluating application security tools, and received the Department of Energy’s Los Alamos National Labs Fellow award.

Larry firmly believes in learning by doing, so in his spare time, he is the author of a dozen open-source projects, one of which gets a million downloads per month.

Most recently, he launched Lumenize, a back-end-as-a-service for vibe coding enterprise and B2B apps. He currently serves on the Model Context Protocol (MCP) transports working group and is the author of the WebSocket transport proposal for MCP.

Contact Larry on his LinkedIn page: https://LinkedIn.com/in/LarryMaccherone

Why Program Increment Estimates Miss: Hidden Variables for Planning

Why Program Increment Estimates Miss: Hidden Variables for Planning

The February 2026 Tech Talk was presented by Dr. Bill Nichols and Dr. Tapajit Dey

Abstract

What is a credible range of dates for when the work in a product increment might finish? Software development work includes many sources of uncertainty, including the size of the work product, developer work effort, complexity, and waits that are sometimes predictable. We found that story point counts often don’t add information that is useful for projecting durations to completion, and wanted to understand whether the problem was in estimation or execution. To investigate, we compared data to determine the correlation between estimates of stories, the actual story direct time, and the calendar durations for story completion, in the hope that this would help to better predict credible completion ranges.

Our research analyzed real data (TSP) from 39 enterprise software projects, including 7,400+ work items. We used the TSP data, with detailed accruals and plans, as ground truth and compared with that same data synthesized into Jira-like data set (lossy compression). We proceeded to quantify sources of variability and bias. We found the following:

  • Real stories often spend significant time in wait states that appear only indirectly through measures such as work in progress.
  • Story points capture an estimate for the effort that a piece of work might require, but they don’t correlate with the actual effort, nor do they predict the actual duration of stories. Without story level measures, there is no meaningful feedback which may explain the persistently weak correlations. 
  • Cycle time (the calendar duration it takes to complete a work item) fails to adequately measure effort, due to embedded wait time from task switching and nonwork time.
  • Ironically, wait states created the most noise on the shortest stories. Shorter sprints are becoming an industry standard, but they may lead to larger swings in velocity when work items are short or straddle sprint boundaries.

This talk presents a straightforward, data-driven approach to understanding these effects and improving measurements; and how both estimation and measurement can include these effects to make better plans and better projections for commitments.

About the Presenters

Dr. Bill Nichols is a Principal Engineer in the Software Solutions Division of the Software Engineering Institute at Carnegie Mellon University, where he leads the Software Measurement and Analysis team. Before joining the SEI, Dr. Nichols earned a doctorate in physics from Carnegie Mellon University, after completing graduate work in particle physics. He later led a software development team at the Bettis Laboratory near Pittsburgh, Pennsylvania, where he developed and maintained nuclear engineering and scientific software for 14 years. He has more than 30 years of technical and management experience in the software engineering industry and has published in Nuclear Instruments and Methods, IEEE Transactions on Nuclear Science, IEEE Computer, and Physical Review Letters.  He is currently the Principal Researcher for the Automated Continuous Estimation of DevSecOps Pipelines  project that measures software processes for project and program management.

Dr. Tapajit Dey is a Member of Technical Staff (MTS) Researcher at the Software Engineering Institute, Carnegie Mellon University, where he works in the Software Solutions Division. His research focuses on empirical software engineering, AI-augmented software engineering, and mining software repositories. He earned his Ph.D. in computer science from the University of Tennessee, Knoxville. Prior to joining SEI, he was a postdoctoral researcher and later a research fellow at Lero, the Science Foundation Ireland Research Centre for Software at the University of Limerick, where he worked on inner-source and open-source software development and helped to found the Lero Open Source Program Office.

Lessons from Using LLMs to Check Software Security

Lessons from Using LLMs to Check Software Security

Abstract

Large language models (LLMs) like ChatGPT are transforming the landscape of software development and evaluation, although claims of AI replacing programmers are often overstated. This session delves into the core technologies of LLMs and their role in software generation and assessment, emphasizing the influence of training data that includes insecure coding practices. We share insights from historical analyses of over 100 million lines of code in languages such as C, C++, and Java to drive our analysis of ChatGPT 3.4, ChatGPT 4, and Copilot performance. Participants will gain a comprehensive understanding of the advantages and potential pitfalls of LLMs, strategies for mitigating associated risks, and foresight into the future of secure AI-driven software development.

About the Presenter 

Dr. Mark Sherman is the Technical Director of the Cybersecurity Foundations directorate in the CERT division of the Carnegie Mellon University Software Engineering Institute (CMU SEI).

Dr. Sherman leads a diverse team of researchers and engineers on projects that focus on foundational research on the lifecycle for building secure software, data-driven analysis of cybersecurity, cybersecurity of quantum computers, cybersecurity for and enabled by machine learning applications, and digital media authenticity. Dr. Sherman was at IBM and various startups, working on mobile systems, integrated hardware-software appliances, transaction processing, languages and compilers, virtualization, network protocols, and database.

Beyond the Peak: Sustaining World-Class Performance in High-Performing Organizations

Beyond the Peak: Sustaining World-Class Performance in High-Performing Organizations

The December Tech Talk panelists were Brian Gallagher, Steve Moulder, and Lynn Penn

Abstract

Achieving a high level of performance is challenging—but sustaining it year after year is even harder. Like keeping off those same 10 pounds, it’s much easier to focus on attaining a goal than to sustain it. So how do organizations maintain that intensity once they’ve “met their goal?”

This session features a panel of experts who have been directly involved in shaping high-maturity practices and who continue to advise organizations seeking to achieve and sustain excellence. They will respond to a set of prepared questions that highlight insights from across industries, addressing topics such as:

  • How high-maturity organizations handle disruptions—such as leadership changes, reorganizations, or shifting priorities—without losing the ground they’ve gained
  • Practices that make it easier to weather setbacks without derailing performance
  • The most important advice for organizations that want to sustain high maturity for the long haul

The discussion will be guided by these focused questions, with a brief opportunity for additional input from participants. Attendees will gain practical strategies for avoiding backsliding, keeping leaders and teams engaged, navigating disruptions, and using data and culture to maintain world-class performance.

About the Presenters

Brian Gallagher is an ISACA Certified High Maturity Lead Appraiser with over 30 years of experience applying advanced systems, software engineering, and program management methodologies to help organizations solve their most challenging problems and achieve business and mission success. Brian is the owner and principal consultant at BG Solutions and Services LLC, a veteran-owned small business, and is an adjunct professor at the University of Arkansas and the University of Maryland Global Campus. Brian earned a PhD in Systems Engineering through Colorado State University and an MS in Computer Science/ Software Engineering through Florida Institute of Technology. He is a retired Air Force officer and served as Senior Vice President of Operational Excellence at CACI; Executive Director of Engineering and Mission Assurance at Northrop Grumman; and Executive Director at the Software Engineering Institute, Carnegie Mellon University.

Steve Moulder is a program analyst and CMMI subject matter expert, as well as a CMMI Process Engineer Advisor. He has 47 years of experience in the information technology industry with multiple major corporations, and approximately 25 years of experience with CMMI. Steve has helped multiple development organizations to achieve CMMI-DEV Maturity Levels 4 and 5, the highest process maturity level possible in the industry, as well as two services organizations to achieve CMMI-SVC Maturity Level 4. In addition, Steve consults with IT infrastructure organizations, helping them to improve processes and performance using the ITIL framework. Steve is an ASQ Certified Six Sigma Black Belt, ASQ Certified Manager of Quality/Organizational Excellence, Professional Scrum Master 1, Certified SAFe 6 Practitioner, and is certified in ITIL foundations in IT service management. Steve has also served as an adjunct instructor of math at Ivy Tech State College.

Lynn Penn is president of Performance and Methods (P&M) Consulting, LLC, where she consults with organizations, focusing on enhancement, institutionalization, and optimization of business operations.

As a director at Lockheed Martin Corporation, Information Systems & Global Solutions (IS&GS), Lynn oversaw policies and process command media, process compliance via audits, and process improvement activities. She developed and managed compliance to multiple process methodologies including CMMI-DEV, CMMI-SVC, RMM, Lean Six Sigma, Agile, ISO 9001/AS9100, ISO 20000, and ISO 27001.

Capability Maturity Model (CMM) involvement began with SW-CMM and progressed to the current CMMI version 3.0. She has participated in multiple formal SPAs, CBA IPIs, assessments using the Acquisition Model, risk evaluations, and supported multiple software capability evaluations per versions 1, 2, and 3. She has supported multiple assessments using People CMM, RMM, previous versions of CMMI-DEV, CMMI-SVC, DMM, and current CMMI V3.0. She was a member of the CMMI V2.0 Core Team and continues to lead CMMI reviews and pilots. She is currently a Lead Appraiser with the Medical Device Discovery Appraisal Program.

Lynn has a BS in mathematics from Villanova University, and has done graduate studies in computer science and management information systems. She is a certified ISO 9000 internal auditor at Lockheed Martin. She is also a Certified Green Belt and Black Belt in Six Sigma and Lean techniques.

She has published the book CMMI and Six Sigma: Partners in Process Improvement.

Process Isn’t a Four-Letter Word

Process Isn’t a Four-Letter Word

Abstract

Agile methods emerged as a direct rebellion against the heavyweight processes of the 1990s. And the Team Software Process (TSP) did too, by brilliantly reimagining process in a lightweight, agile way that empowers self-directed teams to achieve remarkable performance.

People who are familiar with both know how powerfully they work together. But those with only an agile background often see a process definition and reflexively think, “Waterfall!”

This session will explore ways we can reshape the conversation to clarify why good processes amplify agility, rather than constrain it. It will also share process modernization ideas that high-maturity teams can use to take performance to the next level.

This collaborative session will encourage dialogue: we’d love to learn from you! Bring your ideas and let’s advance the state of the practice.

About the Presenter 

David Tuma is a graduate of MIT, with a passion for exceptional software development. He has contributed to the success of numerous projects in roles ranging from architecture to coding, security assessment to causal analysis, and project management to coaching. 

In his support for exceptional practices, he created (and continues to evolve) an open-source toolset called the Process Dashboard, which has been used by tens of thousands of developers worldwide.

David is an active member of the SEA Executive Team and the SEA Data Warehouse Working Group.

The Cyber Success Vector™: Building Mission-Ready Cyber Talent for Life-Critical and Defense Systems

The Cyber Success Vector™: Building Mission-Ready Cyber Talent for Life-Critical and Defense Systems

Abstract

Cybersecurity mandates across defense, aerospace, and life-critical systems are growing in urgency and complexity. Whether facing CMMC compliance, Agile integration, or zero-failure system demands, organizations increasingly depend on more than just secure code — they need people who are capable, aligned, and ready for what’s next.

This talk introduces the Cyber Success Vector™, a leadership and workforce development model designed to grow mission-ready cyber professionals. Fully compatible with the DoD Cyber Workforce Framework (DCWF), this model enables organizations to:

  • Build and sustain DCWF-aligned competencies across diverse roles
  • Integrate cyber readiness into Agile and DevSecOps environments
  • Align people capabilities with mission risk and system assurance needs
  • Develop leadership at every level—from practitioners to program managers
  • Prepare not only today’s workforce, but also shape the future force in cybersecurity

Attendees will walk away with actionable tools to assess, grow, and retain cyber talent in high-stakes environments — where operational resilience and human readiness are critical to mission success.

About the Presenter 

Doug Gray is a cybersecurity and strategic risk leader with over 20 years of experience spanning federal civilian, defense, intelligence, and commercial sectors. His career has focused on advancing operational resilience, maturing cybersecurity governance, and leading high-impact teams through transformational change.

Doug began his cyber journey as a senior Army officer, leading the 10th Mountain Division’s cybersecurity operations during combat and later guiding the U.S. Army Command and Control Support Agency to runner-up for the NSA’s prestigious Rowlett Award for organizational excellence in cybersecurity. These experiences laid the foundation for a career built on mission alignment, innovation, and measurable outcomes.

Since transitioning from uniformed service, Doug has held executive roles in government and industry, serving as a senior cybersecurity leader for a financial regulator, leading information assurance for the U.S. Senate, and managing global cybersecurity and ITSM efforts for a member of the Intelligence Community. He has developed enterprise risk programs, modernized ITSM platforms, and created frameworks such as the Software Engineering Institute, Carnegie Mellon University’s Intelligence Preparation for Operational Resilience (IPOR). His credentials include the CISSP-ISSMP, CRISC, and the CISO certificate from the National Defense University.

Doug is the creator of the Cyber Success Vector™, a comprehensive leadership and workforce development model that aligns cyber talent with mission-critical needs, fostering the skills, resilience, and leadership required to succeed in high-stakes environments.