Sandy Carielli,

Sandy Carielli

VP, Principal Analyst

Sandy advises security and risk professionals on application and product security, with a particular emphasis on the collaboration among security and risk, product management, application development, operations, and business teams. Her research covers topics such as application threat modeling, quantum security, protecting modern and emerging application architectures, protecting applications in production environments, and embedding security throughout the product lifecycle.

Research Coverage

Planned Research

What research can you expect from Forrester in the next 12 months? Updated biweekly, our publishing plan will keep you current with market and technology trends. Use the link below to download a list of our upcoming research.

Download Planned Research
April 8th, 2026 5:00 PM - 5:40 PM Webinar

Top Recommendations For Your Security Program, 2026

As we move further into 2026, the security landscape continues to evolve in parallel with ongoing global uncertainty. Our latest report, “Top Recommendations For Your Security Program, 2026,” provides timely guidance for security leaders as they navigate another precarious year for their roles, programs, and organizations. Join us in this webinar to go over highlights from our 2026 recommendations and hear directly from the analysts making these calls.Key takeaways: Learn the most important recommendations for your security strategy in 2026 and our rationale behind them.Leverage our research and insights to guide your security program strategy.Understand how to prioritize changes in areas including AI and data governance, security budgets and staffing, post-quantum security, and critical infrastructure in the coming year.Target audience level: intermediate
April 30th, 2026 3:00 PM - 4:00 PM Webinar

Lessons Learned From The World’s Biggest Data Breaches And Privacy Abuses, 2025

Forrester analyzed the top global breaches and worst privacy abuses of 2025 and identified key trends and lessons learned. With more than 10.6 billion records exposed in the top 35 breaches alone and almost $2.8 billion in fines levied on the top 35 violators, lessons abound for security teams. Join us as we review some of the most important breaches of 2025 and discuss ways your security team can protect against them.Key takeaways: Understand the key breaches and lessons from the past year.Learn how to augment your security and privacy strategies accordingly.Target audience level: all levels