Software Security & Risk Management

QCon London 2026

Track

Software Security & Risk Management

Tuesday 17 March · 6 sessions, 50 minutes each

About the track

Implement secure development lifecycle practices, from threat modeling and static analysis to vulnerability management and compliance, to effectively mitigate software-related business risk.

Sessions in this track

Tuesday 17 March. 6 sessions per track, chosen and introduced by the Track Host.

10:35 Mountbatten (6th Fl.) Session security Why Governance Matters: The Key to Reducing Risk Without Slowing Down Sarah Wells Independent Consultant and Author 11:45 Mountbatten (6th Fl.) Session Kernel Building on Bedrock: A Security Philosophy from Bootloader to Runtime Alex Zenla Founder & CTO @Edera 13:35 Mountbatten (6th Fl.) Session SBOMs From Chaos to Clarity: Modern SBOM Practices That Actually Work Viktor Petersson Founder of sbomify, Co-founder & CEO of Screenly, Host of Nerding Out with Viktor 14:45 Rutherford (4th Fl.) Unconference Unconference: Software Security & Risk Management 15:55 Windsor (5th Fl.) Session security Exploding GPUs Andrew Martin Founder and CEO @ControlPlane, CISO OpenUK, CNCF Security Advisory Group 17:05 Windsor (5th Fl.) Session security Adopting Memory-Safety and Fine-Grained Compartmentalisation With CHERI David Chisnall Director of System Architecture @SCI Semiconductor, OS, Compiler, and Computer-Architecture Expert, Maintainer of the CHERIoT Platform
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon London 2026 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share