Skip to content
  • Solutions
  • Markets
  • Resources
  • About
Set Up A Call
Back

Solutions

The PCI Platform

New

A secure, reliable, high-performance, cloud-native foundation that powers our full-spectrum suite of solutions and natively integrates AI-enabled enterprise analytics

View the platform

AI

New

Insights

Hot

Security

Hot

Technology

Hot

Solutions

Energy Trading

ETRM

PCI ETRM

End-to-end energy trading, risk, and scheduling in one system

  • ETRM
  • Front Office: Gas & Fuels
  • Front Office: Power
  • Middle Office
  • Back Office
  • ETRM
  • Front Office: Gas & Fuels
  • Front Office: Power
  • Middle Office
  • Back Office

Bid-to-Bill

GenManager®

Complete market participation workflow from forecast to final bill

  • Bid-to-Bill
  • Forecasting
  • Market Participation
  • Scheduling & ISO Integration
  • e-Tagging
  • Meter Data Management
  • Settlements and Billing
  • Bid-to-Bill
  • Forecasting
  • Market Participation
  • Scheduling & ISO Integration
  • e-Tagging
  • Meter Data Management
  • Settlements and Billing

Portfolio Optimization

GenTrader®

Maximize portfolio value with integrated optimization

  • Portfolio Optimization
  • Energy Trading Optimization
  • Energy Storage Optimization
  • Forecaster
  • Long-Term Planning
  • Mid-Term Planning
  • Sustainable Energy
  • Portfolio Optimization
  • Energy Trading Optimization
  • Energy Storage Optimization
  • Forecaster
  • Long-Term Planning
  • Mid-Term Planning
  • Sustainable Energy

Transmission & Reliability

Transmission

New
Manage transmission rights, congestion, and settlements
  • Transmission
  • Transmission Scheduling
  • e-Tagging
  • Transmission Portfolio Opt.
  • BA Operations
  • Energy Accounting
  • Transmission
  • Transmission Scheduling
  • e-Tagging
  • Transmission Portfolio Opt.
  • BA Operations
  • Energy Accounting

Outage Management

New

Plan and coordinate outages with built-in compliance

  • Outage Management
  • Operator Logging
  • Gen. Outage Management
  • Trans. Outage Management
  • Line Rating Management
  • Outage Management
  • Operator Logging
  • Gen. Outage Management
  • Trans. Outage Management
  • Line Rating Management
Back

Markets

PCI Clients Map

Markets We Serve

A Global Footprint

PCI Energy Solutions serves utility companies, independent power producers, and wholesale power traders. We support customers in every organized market in North America and maintain a global presence across five continents.

Markets

Markets

North America

50%+ of North American power is optimized using the PCI Platform

Latinoamerica

PCI da soporte al 90% de la capacidad de generación eléctrica en México

Europe

HOT

PCI has a foothold in Europe with a growing presence

Australia

HOT

Modern outage management  tailored to Australia’s NEM and WEM utilities

Market Chatbots

ISO Bot

Popular

Ask energy market questions of an AI trained on ISO/RTO manuals

M+ Bot

New

AI assistant dedicated to up-to-date SPP Markets+ documentation

CEN Bot

New

Chatbot de IA sobre el mercado eléctrico CENACE

Back

Resources

INFOCUS Customer Conference

Discover why hundreds attend each year

April 14-16 2026

Learn More

Resources

Thought Leadership

Blog

New

Our industry thought leadership

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Newsletter

Subscribe

Updates on product launches &more 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Webinars & Events

HOT

Live & on-demand discussions 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Case Studies

HOT

Real-world customer results

 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Customer Portal

INFOCUS Conference

Apr

Connect, learn, and shape our future

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Product Trainings

New

Hands-on remote training

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Issue Tracker

New

Track, manage, and resolve issues 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Product Documentation

New

Guides, references, and release notes

 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
Back

About

A trusted partner since 1992

Our Values

Customer Success

Central

We succeed by creating happy customers

Continuous Improvement

New

We continually grow, adapt, and get better

Enlightened Awareness

New

Our character is revealed through our actions

Connectedness

New

Our genuine connections drive shared success

About Us

About

People

Careers

Hiring

Build the future of energy software

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Leadership

HOT

Meet the leaders driving our vision

 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Connect

Contact Us

New

Talk with our experts today

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Newsroom

New

Company news & announcements

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • Blog
  • Secure Code Development Training: How to Reduce Risk & Build Secure Software
Share this post
Picture of Peter Samoray

Peter Samoray

Abstract image to help portray "secure code development training"

Secure Code Development Training: How to Reduce Risk & Build Secure Software

February 5, 2025
/
Cybersecurity

Many of today’s most devastating data breaches share a common root cause: a lack of secure code development training. Despite advances in cybersecurity, insecure coding practices continue to expose organizations to unnecessary risk. 

Under tight deadlines, developers often prioritize speed over security, introducing vulnerabilities that cybercriminals can exploit. Without proper secure code development training, teams may unknowingly create weaknesses that lead to costly breaches. 

The best way to reduce this risk is to build a security-first development culture. By implementing structured training programs, leveraging industry frameworks, and motivating developers to follow secure coding best practices, organizations can significantly improve software security while maintaining efficiency. 

This blog post explores: 

  • Why secure code development training is essential 
  • Industry-leading frameworks and resources for training developers 
  • Strategies to balance speed, quality, and security in development 
  • How to motivate developers to adopt secure coding best practices 

The importance of secure code development training  

The projects that gain business value need to have focus to move the business and customers forward, however, there needs to be a balance, to ensure we are training, motivating, and governing secure coding practices so we are not sabotaging our goals. 

In the past, developers were evaluated on Lines Of Code (LOC) that they produced and speed to market to gain customer favor and gain market share. As speed was the primary focus, it also introduced risk of actually missing requirements or introducing inefficiencies.  

Methodologies changed to include speed, efficiency, and quality (Software Quality Assurance – SQA) which moved development toward a focus on the software process and realization that quality coding practices needed to be baked into the entire Software Development Lifecycle (SDLC). 

Based on the major data breaches involving insecure code, which is often preventable, a number of standards and processes have been developed to help organizations train developers on secure coding practices.  

We’ll start by looking at some key resources to help your developers master secure coding. 

Secure code development training and education 

Begin with a policy on application development to create a baseline of expectations for development activities within your organization. 

Training and education should be in alignment with your policy, which could include: 

  • Methodologies such as Secure Development Operations (DevSecOps) to improve automation, monitoring, and application of security at every phase of the software development lifecycle (see the U.S. Department of Defense DevSecOps Fundamentals Guidebook to learn more.)  
  • Frameworks such as NIST Secure Software Development Framework (SSDF) SP 800-218 specifically address software in detail.  
  • Organizational alignment such as: 
    • SANS point out the top 25 most dangerous software errors and how to avoid and remediate them 
    • SAFECode, an organization designed as a community for developers to seek training, guidance on secure coding practices, and developer community discussion groups
    • OWASP, a community project that provides a dynamic list of the top 10 application security risks along with recommendations for secure coding methods to mitigate them
    • Cloud Security Alliance – CSA, an organization that provides awareness and tips toward secure cloud development that recently included secure AI development; they also offer a Star Program for company certification on cloud security posture levels 

How to balance speed, quality, and security in code development 

An organization needs to determine the prioritization on code development. 

Priorities could be broken down into three categories: 

  • Speed: Develop code and complete fixes in the fastest amount of time possible 
  • Quality: Ensure the code not only meets expectations/specifications, but it is also easy to maintain and understand, is efficient, and is sustainable 
  • Security: Align actions with secure coding practices 

 

Ideally, all three are a priority. With code repositories and AI code assistants, speed can be achieved relatively easily while providing time to ensure quality and security. 

If we spend the appropriate amount of time upfront and throughout the development process to ensure the code meets or ideally exceeds quality and security standards, we will end up with less time and resources needed to fix bugs and remediate insecure code while reducing our overall risk. 

This process and prioritization needs to transfer to customer understanding and expectations to receive secure quality code rather than really fast insecure code that doesn’t quite meet requirements. 

  

What motivates developers to prioritize secure code? 

Regardless of what we put in a policy or training we provide to our developers, being a previous developer myself, there are a few main areas that should be considered to help actually motivate secure code development as a practice. 

Rewards: 

  • Are we providing the appropriate rewards for developers that produce fast, high-quality code that has the least amount of code vulnerabilities when scanned and/or pen tested? 
  • Is this reflected in their raises, bonuses, evaluations? 

  

Penalties: 

  •  Are we enforcing appropriate penalties for developers who produce fast code but lack high quality and have the highest number of vulnerabilities when scanned or pen tested? 
  • Is this reflected in their raises, bonuses, evaluations? 

 

Having read this blog post, you may be several steps closer to protecting your organization from the high risk of developing insecure code and the introduction of a potential data breach as a result than you were 10 minutes ago before you read it. 

However, there’s more. 

One of the best ways to ensure secure code development is to train and educate, make it a priority, and properly motivate developers to follow policy and actually apply what they have been trained on. With this shift toward a more secure minded culture, the rewards will far outweigh the costs. 

At PCI Energy Solutions, we’re committed to fostering secure development practices that protect businesses and their customers. I’ll be sharing my expertise on this topic at SecureWorld Boston 2025, offering actionable insights to help organizations build a security-first culture. Ready to strengthen your secure coding practices? Visit our Cybersecurity page to learn how we help our clients implement secure development practices and reduce risk. 

Picture of Peter Samoray

Peter Samoray

Peter has over 18 years of cybersecurity experience within multiple sectors, from automotive, defense, telecommunications, retail, consulting, and software development. Peter holds a BA in psychology from Wayne State University, an MS in information systems from the University of Detroit-Mercy, and a certificate in change leadership from Cornell University. Of late, his focus has been on improving the human factor of cybersecurity. Peter maintains the following certifications: CISSP, CISM, CISA, CIPP/US, CIPP/EU, and PMP.

Related blog posts

Loading...
Dec 09
About Us,Cybersecurity

PCI Achieves SOC 2 Type II Attestation, Reinforcing Security for 2026 & Beyond

open laptop
Feb 18
About Us,Cybersecurity

PCI Successfully Completes SOC/FISMA Examinations for 2024

AI graphic to portray "How Can Generative AI Be Used in Cybersecurity?"
Apr 10
Cybersecurity

How Can Generative AI Be Used in Cybersecurity?

Related press

Loading...
tuscon arizona sky
Feb 17
SPP,SPP Markets Plus,US ISO/RTO Markets

Tucson Electric Power Selects PCI Energy Solutions for Its Transition into SPP Markets+ Ahead of 2027 Launch

Dec 09
About Us,Our Technology

PCI Energy Solutions Named a 2025 Geo & Global AWS Partner Award Finalist

Dec 09
About Us,Cybersecurity

PCI Achieves SOC 2 Type II Attestation, Reinforcing Security for 2026 & Beyond

PCI Energy Solutions

PCI Energy Solutions

Also known as Power Costs, Inc.

Connect with us

U.S. 1+ 405.447.6933

Sales 1+ 405.701.7301

301 David L. Boren Blvd., Suite 2000
Norman, OK 73072

Contact us

We’re Hiring! 

Linkedin Twitter
  • Platform
  • PCI AI
  • PCI Insights
  • Our Technology
  • Cybersecurity
  • AWS Partnership
  • Solutions
  • ETRM
  • Bid-to-Bill
  • Portfolio Optimization
  • Transmission
  • Outage Management
  • Customer Portal
  • INFOCUS Conference
  • Product Trainings
  • Product Documentation
  • Issue Tracker
  • About
  • Careers
  • About Us
  • Leadership
  • Newsroom

Subscribe to our newsletter

Subscribe

© Power Costs, Inc. 2026 | All Rights Reserved.

  • Privacy Policy
  • Sitemap
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}

Request More Information

  • This field is for validation purposes and should be left unchanged.

Name
I am not a robot 🤖

Solutions

Energy Trading and Optimization

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Transmission and Reliability

  • Transmission Outage Management
  • Transmission Scheduling
  • e-Tagging
  • Balancing Authority Operations
  • Energy Accounting and Meter Data Management
  • Transmission Outage Management
  • Transmission Scheduling
  • e-Tagging
  • Balancing Authority Operations
  • Energy Accounting and Meter Data Management

Sustainable Energy

  • Energy Trading Optimization
  • Energy Storage Optimization & Trading
  • Hydrogen
  • Hydropower
  • Carbon Intensity
  • Forecasting
  • Energy Trading Optimization
  • Energy Storage Optimization & Trading
  • Hydrogen
  • Hydropower
  • Carbon Intensity
  • Forecasting

Platform

  • PCI AI
  • PCI Insights
  • Our Technology
  • Cybersecurity
  • AWS Partnership
  • PCI AI
  • PCI Insights
  • Our Technology
  • Cybersecurity
  • AWS Partnership

Markets

  • North America
  • Latinoamerica
  • Europe
  • Australia
  • North America
  • Latinoamerica
  • Europe
  • Australia

Energy Market AI Chatbots

  • ISO Bot (North American Markets)
  • M+ Bot (New Market)
  • CEN Bot (Mexico)
  • ISO Bot (North American Markets)
  • M+ Bot (New Market)
  • CEN Bot (Mexico)

Resources

Thought Leadership

  • Blog
  • Newsletter
  • Webinars & Events
  • Case Studies
  • Blog
  • Newsletter
  • Webinars & Events
  • Case Studies

Customer Portal

  • INFOCUS User Conference
  • Product Trainings
  • Product Documentation
  • Issue Tracker
  • INFOCUS User Conference
  • Product Trainings
  • Product Documentation
  • Issue Tracker

About Us

  • About
  • Leadership
  • Newsroom
  • Contact Us
  • About
  • Leadership
  • Newsroom
  • Contact Us

Careers