Track host
About the track
Software supply chains, composed of diverse tools, dependencies, and collaborative workflows, have become critical targets for malicious actors. Attackers exploit vulnerabilities in open-source components, CI/CD pipelines, and automated engineering processes, exposing organizations to significant risks. Resilience in this context demands a shift from reactive defenses to proactive strategies that integrate security directly into engineering workflows, ensuring vulnerabilities are addressed before they can be exploited.
Sessions in this track
Tuesday 8 April. 6 sessions per track, chosen and introduced by the Track Host.
10:35 Mountbatten (6th Fl.) Session Secure by Design: Building Security into Engineering Workflows and Teams Stefania Chaplin Founder & CEO @DevStefOps, Previously Solutions Architect @GitLab, AWS Certified Security - Speciality Security doesn't have to be a blocker- it can be an enabler. In this session, we’ll explore how to seamlessly integrate secure development practices into engineering workflows while fostering a culture of collaboration and shared ownership. 11:45 Mountbatten (6th Fl.) Session open source Empower Your Developers: How Open Source Dependencies Risk Management Can Unlock Innovation Celine Pypaert Vulnerability Manager @Johnson Matthey, Women in CyberSecurity UK Volunteer, Book Contributor, Ex-Microsoft As security practitioners, we face the challenge of driving innovation whilst needing to balance security risks. 13:35 Mountbatten (6th Fl.) Session software supply chain Trust No One: Securing the Modern Software Supply Chain with Zero Trust Emma Yuan Fang Senior Cloud Security Architect @EPAM, DevSecOps, Cloud Security Advocate, Strategist and Public Speaker, Ex-Microsoft, CISSP Can you truly trust your software supply chain? As cloud-native software development surges, threat actors increasingly target the supply chain, exploiting vulnerabilities in CI/CD pipelines, dependencies, and container images. 14:45 Windsor (5th Fl.) Session Panel: Security Against Modern Threats Details coming soon. 15:55 Windsor (5th Fl.) Session security Securing AI Assistants: Strategies and Practices for Protecting Data Andra Lezza OWASP London Chapter Leader, 10+ Years of Experience Building AppSec Program The data behind AI copilots is not only their most critical asset but also a key strategic consideration for enterprises and SMBs alike. 17:05 Rutherford (4th Fl.) Unconference Unconference: Resilient Engineering Practices for Security Against Modern ThreatsQCon London 2025 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.