SESSION + Live Q&A
The Evolving Practice of Security
As technology has evolved from on-premise data centres to cloud native systems, the practices of managing that technology has evolved giving us benefits like continuous integration and deployment and configuration as code and cloud orchestration platforms. But security practices have generally not evolved to match, we find security practitioners are still fighting the wars of yesterday, fighting firewalls and network configurations that simply don’t exist today.
In this talk, you’ll learn what practices that are evolving in the security space, and how developers and security can collaborate more with new and modern practices.
Speaker
Michael Brunton-Spall
Independent Security Consultant, previously Deputy Director for Technology and Operation, & Head of CyberSecurity of Government Digital Service
Michael Brunton-Spall is an independent Cybersecurity consultant, working for the UK Government. Michael is a former Deputy Director with the Cabinet Office, where he headed up Technology and Operations for the Government Digital Service as well as being head of Cybersecurity. Michael...
Read moreFind Michael Brunton-Spall at:
From the same track
A Continuation of Devops: Policy as Code
Organisations large and small are embracing devops and agile practices and transforming themselves into software companies. As part of that movement many organisations have embraced infrastructure as code, the idea that rather than systems administrators managing...
Gareth Rushgrove
Product Manager @Docker
Speed The Right Way: Design and Security in Agile
“Blame the programmer” was an emerging theme in the security breaches of the last year placing coders and “their bugs” squarely in the security spotlight. But what is upstream of implementation bugs of causing these security issues? Application architecture and design. Effective...
Kevin Gilpin
Enterprise Software Engineer
Securing Services Using SSO
As BuzzFeed transitioned to microservices it needed to secure a growing number of internal tools. Our first solution was an open source auth service deployed in front of each app, but this approach had a number of scaling issues. The talk will discuss sso, our open-source, homegrown, centralized...
Shraya Ramani
Software Engineer @BuzzFeed
The Three Faces of DevSecOps
DevSecOps is the buzzword du jour in the world of security. Organisations increasingly understand that if you transform development and embrace DevOps, you must transform security as well. Failing to do so would either leave you insecure, or make your security controls negate the speed you aimed...
Guy Podjarny
Co-founder @SnykSec, previously CTO @Akamai