A few months ago, Jess Kerr facilitated (and illustrated!) a fireside chat with myself and the fine folks at Code Sync about the question:
What makes a code base “risky?”
Within seven minutes, we already had this exciting topic network on the board:

As Jess brings up early on, the risk associated with a code base covers a much broader range of problems than security ones. Throughout this discussion we name a bunch, talk about how to analyze them, and touch on how to address them.

Bonus footage: My stuffed animal collection, Jess’s cat.
Enjoy!
If you liked this piece, you might also like:
The rest of the talks category (if you’re into seeing what else I’ve said for audiences)
The technical debt series (for digging deeper into this subject matter)
This piece about the pitfalls of data-driven innovation (because people seem to be into this piece)