As the world marches forward into 2024, the ever-evolving realm of application and cloud security presents both pioneering prospects and intricate complexities. This May, the Sydney AppSec and DevSecOps Summit stands as your indispensable gateway to navigate, negotiate, and nurture strategies in this ever-vital domain.
This paramount event congregates Australia’s top-tier software and security experts, offering profound insights into themes that mould the current application and cloud security panorama:
- Software Supply Chain Risk: Delving into the risks associated with software sourcing and managing them proficiently.
- Developer Training and Engagement: Cultivating an environment where developers are equipped, involved, and inspired.
- Continuous Threat Modelling: Up-to-the-minute strategies for persistently evaluating and mitigating threats.
- AI-Driven Software Assurance: Leveraging artificial intelligence for proactive software security.
- Software Delivery Governance: Ensuring systematic and secure processes in software delivery pipelines.
- App, Cloud, and Product Security: Comprehensive strategies for safeguarding today's digital assets.
Featuring a line-up of esteemed professionals and visionaries from the security sphere, the summit guarantees illuminating dialogues and unparalleled networking occasions. The insights and experiences shared will enable you to hone your security postures, fostering resilience and excellence in your establishment.
Unravel, unite, and uplift your security strategies at the Sydney AppSec and DevSecOps Summit 2024. Boost your security prowess and be at the forefront of the application and cloud security revolution.
Fortify your security stance with precision. Register today!
Event MC.
9:00am |
Arrival & Registration |
9:10am |
Welcome & Ice-Breaker Exercise |
9:30am |
Opening Keynote: In this keynote, we dive into Cole's decade of AppSec experiences, highlighting the pivotal lessons learned and strategies developed to counter evolving cyber threats. The session will explore the transformation of AppSec practices in response to changing technologies and threat landscapes, emphasizing the importance of an integrated, proactive security approach.
Speaker: |
9:55am |
Keynote: The evolution of industry has seen the rise of platform engineering. Explore how Platform Engineering co-exists with DevSecOps bringing it all together to enable and empower modern engineering with a focus on what is being delivered over the how. Key items to be covered include:
Speaker: |
10:20am |
Morning Tea & Networking |
10:50am |
Keynote: Policy as Code in DevSecOps is about treating security and compliance policies with the same level of automation, integration, and version control as application code. This approach helps organizations ensure that security and compliance requirements are consistently met throughout the software development and deployment lifecycle, reducing the risk of security misconfigurations and compliance violations for your applications. Topics that will be covered include:
Speaker: |
11:20am |
Panel: The evolution of software supply chains, increasingly reliant on third-party and open-source components, has brought about significant security challenges. This discussion will navigate through the complexities of securing these supply chains, highlighting the critical need for robust strategies to mitigate risks, ensure compliance, and maintain trust. Attendees will be exposed to the latest approaches in addressing the vulnerabilities inherent in software supply chains, with a focus on implementing effective governance and risk management practices. The aim is to equip participants with the knowledge to develop a resilient and secure software supply chain, capable of withstanding the dynamic threats in today’s digital landscape.
Speakers: |
11:50pm |
Roundtable Discussions:
|
12:50pm |
Lunch & Networking |
1:50pm |
Panel:
Speakers: |
2:20pm |
Keynote: In this keynote, we will explore the critical role of the threat modelling process in shaping the cybersecurity strategies of organisations. As the digital landscape becomes increasingly complex and interconnected, the ability to proactively identify, assess, and mitigate potential threats has never been more crucial. This session will delve into the fundamentals of threat modelling, illustrating how it serves as the backbone of effective cybersecurity architecture, particularly within the realms of AppSec and DevSecOps. The discussion will cover the systematic approach to threat modelling, highlighting its importance in early detection and prevention of security vulnerabilities. Attendees will gain insights into the latest methodologies and tools that enhance the threat modelling process, enabling organizations to better understand their security posture and make informed decisions to protect their assets. Key points to be covered include:
Speaker: |
2:45pm |
Panel: This panel will delve into the critical aspects of cloud and container security within the AppSec and DevSecOps frameworks. As cloud and container technologies become central to modern application development, their security implications have grown increasingly complex. The session will explore the unique challenges these technologies pose and the strategies needed to secure them effectively, aligning with AppSec and DevSecOps principles. Through discussions with leading experts, the panel will address how to navigate the security landscape of cloud-based and containerised environments, ensuring that security is integrated throughout the development and deployment pipeline. Attendees will learn about the latest trends, tools, and methodologies for securing cloud and container infrastructures in a way that supports rapid development and maintains strong security postures. Key points to be covered include:
Speakers: |
3:15pm |
Afternoon Tea & Networking |
3:35pm |
Keynote: This keynote addresses the critical challenge of communicating AppSec risks to internal stakeholders, focusing on the need for clear, impactful, and actionable dialogue. In the complex ecosystem of cybersecurity, effectively conveying the significance of AppSec risks and the necessary mitigation strategies to non-security personnel is essential for fostering an organisation-wide culture of security awareness and proactive defense. The session will explore the best practices for translating technical AppSec concepts into business-centric language that resonates with executives, product managers, and other non-technical stakeholders. Attendees will learn how to articulate the potential impacts of AppSec risks on the organization's objectives and operations, facilitating informed decision-making and strategic investment in cybersecurity measures. Key points to be covered include:
Speaker: |
4:00pm |
Keynote: This session will unravel the often-underestimated realm of shadow IT, specifically focusing on the high-level risks associated with vendor software. Shadow IT, particularly through third-party and vendor-supplied applications, presents a significant and complex challenge for organisations, as it can introduce unaccounted vulnerabilities and compliance issues. The discussion will start with a high-level overview of the shadow IT problem, highlighting how vendor software can become a weak link in the cybersecurity chain. Following the initial overview, the session will transition into technical deep dives, examining specific vulnerabilities that have been discovered in vendor software. These case studies will shed light on the nature of these vulnerabilities, their impact on organisational security, and how they were identified and mitigated. Attendees will gain a comprehensive understanding of the risks associated with vendor software and the importance of rigorous vetting, continuous monitoring, and effective management of these external components within their IT ecosystems. Key points to be covered include:
Speakers: |
4:30pm |
Event Closed |
- Chief Information Security Officer
- Heads of Application Security
- DevSecOps Leaders
- Application Security and DevSecOps Architects and Engineers
- Cybersecurity Engineering Leaders
- Cloud Security Directors
- Heads of DevOps and Engineering
- Security Product Managers
- Senior AppSec Manager
- Senior DevSecOps Manager
- Senior Cybersecurity Manager
- Senior DevOps Manager
- Senior Cloud Security Manager
- Senior Engineering Manager
- Senior Product Security Manager
Are you interested in sponsoring the AppSec & DevSecOps Summit Sydney 2024?
Find out more here or get in touch with Danny Perry to secure your spot now, as each of our events is highly limited to 8 sponsors.
Swissôtel
Recently renovated and centrally located in the CBD, the Swissôtel is a great place to meet & share with 200+ of your peers.