We ran Hackblitz 2026 yesterday, our annual secure coding tournament and this is the second year I’ve run it at Domain.
Participants picked a programming language of their choice and worked through challenges where they had to spot vulnerabilities in code and propose the fix. Points were awarded for correct answers, and hints were available if you got stuck, though taking hints cost you points. It ran for an hour and a half, with people joining both in person and virtually from across the business.
What I liked most was watching people think through the same piece of code differently depending on their language background and experience level. Spotting a vulnerability is one thing, but determining a fix in a way that addresses the root cause is a different skill, and you could see people working through that in real time.
Secure coding fundamentals do not get the attention they deserve. Most security programmes focus heavily on detection and response, but a lot of the vulnerabilities we spend time chasing later could have been avoided at the point of writing the code. Events like this are a small but useful way of keeping that muscle exercised across the business.
Congrats to the winners! Also thank you to Harisha Rameshkumar from Secure Code Warrior for taking the time to run everyone through the rules before we started and for the SCW swag. And to Daniel Bishop from AWS for the generous support in sponsoring snacks and prizes.
