World Congress 2025

Simple Steps to Kill DevSec without Giving Up on Security

July 11, 2025 12:20 – 12:50 · 30 min Stage 4
automation cybersecurity devops ci/cd

What this session covers

The “shift left” movement in code security, intended to shift security responsibilities to developers, has largely failed. Instead of easing burdens, it has inundated developers with noisy alerts, straining the relationship between development and security teams, and ultimately putting the burden back on security. This session will provide examples of how successful teams have addressed this issue and highlight the concept of using secure guardrails that notify (but don’t block) developers in their native workflow and promote the use of secure defaults. Find out how to effectively mature your application security program and steps you could take immediately to improve your security posture.

Related talks at this congress

Open session

World Congress 2025

July 11, 2025 · 14:20–14:50

Stage 3 - Microsoft

Real-World Security for Busy Developers

Kevin Lewis

Senior Developer Advocate at GitHub

Kevin Lewis
Open session

World Congress 2025

July 11, 2025 · 13:40–14:10

Stage 4

Why Security-First Development Helps You Ship Better Software Faster

Michael Wildpaner

Maw Wildpaner, VP of Engineering, Security at GitLab

Michael Wildpaner
Open session

World Congress 2025

July 10, 2025 · 10:30–12:30

M7 (18 Seats)

Code Red: When Your Tools Turn Against You

Aaron Bray, Julian Totzek-Hallhuber

Aaron Bray
Julian Totzek-Hallhuber
Open session

World Congress 2025

July 10, 2025 · 12:55–13:00

Stage 8

Get security done: streamlining application security with Aikido

Mia Neethling

Aikido Security, Founding Account Executive

Mia Neethling
All sessions at this congress