Trust No One: Securing the Modern Software Supply Chain with Zero Trust

QCon London 2025

Session software supply chain

Trust No One: Securing the Modern Software Supply Chain with Zero Trust

Tuesday Apr 8 / 01:35PM BST, Mountbatten (6th Fl.)

Abstract

Can you truly trust your software supply chain? As cloud-native software development surges, threat actors increasingly target the supply chain, exploiting vulnerabilities in CI/CD pipelines, dependencies, and container images. These risks can be further amplified by human factors such as misconfigurations and flawed access control policies.

In this talk, we will explore how seemingly trusted entities within your DevOps pipelines can be exploited by threat actors. We will discuss the critical need for a proactive approach to defend against upstream threats by verifying each interaction within the system. Learn how to decipher Zero Trust principles and translate them into security controls to protect your software supply chain.

Key Objectives:

  • Understand the threat landscapes and security challenges in the software supply chain.
  • Discuss the key principles of the Zero Trust and the advantages of applying this approach to enhance the security posture of your DevOps environment and CI/CD Pipelines.
  • Lean practical guidance to defend against supply chain attacks by implementing Zero Trust Security. 

Topics

software supply chain cloud security zero trust
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon London 2025 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Tuesday 8 April

10:35 Mountbatten (6th Fl.) Session Secure by Design: Building Security into Engineering Workflows and Teams Stefania Chaplin Founder & CEO @DevStefOps, Previously Solutions Architect @GitLab, AWS Certified Security - Speciality 11:45 Mountbatten (6th Fl.) Session open source Empower Your Developers: How Open Source Dependencies Risk Management Can Unlock Innovation Celine Pypaert Vulnerability Manager @Johnson Matthey, Women in CyberSecurity UK Volunteer, Book Contributor, Ex-Microsoft 13:35 Mountbatten (6th Fl.) Session software supply chain Trust No One: Securing the Modern Software Supply Chain with Zero Trust Emma Yuan Fang Senior Cloud Security Architect @EPAM, DevSecOps, Cloud Security Advocate, Strategist and Public Speaker, Ex-Microsoft, CISSP 14:45 Windsor (5th Fl.) Session Panel: Security Against Modern Threats 15:55 Windsor (5th Fl.) Session security Securing AI Assistants: Strategies and Practices for Protecting Data Andra Lezza OWASP London Chapter Leader, 10+ Years of Experience Building AppSec Program 17:05 Rutherford (4th Fl.) Unconference Unconference: Resilient Engineering Practices for Security Against Modern Threats