Software supply chains, composed of diverse tools, dependencies, and collaborative workflows, have become critical targets for malicious actors. Attackers exploit vulnerabilities in open-source components, CI/CD pipelines, and automated engineering processes, exposing organizations to significant risks. Resilience in this context demands a shift from reactive defenses to proactive strategies that integrate security directly into engineering workflows, ensuring vulnerabilities are addressed before they can be exploited.
From this track
Secure by Design: Building Security into Engineering Workflows and Teams
Tuesday Apr 8 / 10:35AM BST
Security doesn't have to be a blocker- it can be an enabler. In this session, we’ll explore how to seamlessly integrate secure development practices into engineering workflows while fostering a culture of collaboration and shared ownership.

Stefania Chaplin
Founder & CEO @DevStefOps, Previously Solutions Architect @GitLab, AWS Certified Security - Speciality
Empower Your Developers: How Open Source Dependencies Risk Management Can Unlock Innovation
Tuesday Apr 8 / 11:45AM BST
As security practitioners, we face the challenge of driving innovation whilst needing to balance security risks.

Celine Pypaert
Vulnerability Manager @Johnson Matthey, Women in CyberSecurity UK Volunteer, Book Contributor, Ex-Microsoft
Trust No One: Securing the Modern Software Supply Chain with Zero Trust
Tuesday Apr 8 / 01:35PM BST
Can you truly trust your software supply chain? As cloud-native software development surges, threat actors increasingly target the supply chain, exploiting vulnerabilities in CI/CD pipelines, dependencies, and container images.

Emma Yuan Fang
Senior Cloud Security Architect @EPAM, DevSecOps, Cloud Security Advocate, Strategist and Public Speaker, Ex-Microsoft, CISSP
Panel: Security Against Modern Threats
Tuesday Apr 8 / 02:45PM BST
Details coming soon.
Securing AI Assistants: Strategies and Practices for Protecting Data
Tuesday Apr 8 / 03:55PM BST
The data behind AI copilots is not only their most critical asset but also a key strategic consideration for enterprises and SMBs alike.

Andra Lezza
OWASP London Chapter Leader, 10+ Years of Experience Building AppSec Program
Unconference: Resilient Engineering Practices for Security Against Modern Threats
Tuesday Apr 8 / 05:05PM BST
Track Host

Sonya Moisset
Staff Security Advocate @Snyk