WeAreDevelopers LIVE Oct 12, 2020

You can’t hack what you can’t see

Reto Kaeser

Traditional boundary firewalls are obsolete. Since 80% of cloud traffic is internal, perimeter breaches are devastating. Harness microsegmentation and zero trust to make workloads invisible to attackers.

Pause
Mute Enter Fullscreen
#1 about 3 min

Evolving from siloed operations to DevOps culture

Culture plays a massive role in successful DevOps adoption beyond tooling.

#2 about 2 min

Integrating security into the DevOps lifecycle

Left-shifting security creates DevSecOps to protect modern remote workloads.

#3 about 4 min

Identifying abuse cases during requirements gathering

Addressing potential attack vectors early hardens architecture before design begins.

#4 about 2 min

Security challenges of workload abstraction in cloud environments

Containerizing and moving workloads introduces fine-grained connection risks.

#5 about 3 min

Classifying and anonymizing data during system design

Treating restricted data carefully and avoiding unnecessary context reduces exposure risk.

#6 about 4 min

Managing vulnerabilities in open-source libraries early

Catching vulnerable component versions using pre-commit hooks saves downstream remediation time.

#7 about 2 min

Leveraging continuous penetration testing via red teams

Feeding abuse cases directly to testers improves ongoing security posture.

#8 about 3 min

Protecting internal east-west traffic within networks

Shifting focus from external firewalls to safeguarding internal communications between services.

#9 about 2 min

Securing individual workloads systematically at the application layer

Moving security policies away from infrastructure to surround the data directly.

#10 about 2 min

Implementing logical firewalls to enforce microsegmentation

Defining communication restrictions workload-by-workload limits the radius of potential breaches.

#11 about 2 min

Adopting zero-trust principles and whitelisting intentions

Only allowing explicitly approved workloads to access specific services hardens environments.

#12 about 2 min

Automating firewall policies using security as code

Tagging workloads natively in code speeds up policy generation and enforcement.

#13 about 3 min

Reaping the benefits of embedded cloud workload security

Letting protection follow workloads automatically unlocks true agility and scalability.

#14 about 2 min

Staying paranoid to ensure continuous software security

Maintaining a healthy skepticism helps prioritize secure delivery in an increasingly dangerous computing landscape.

Matching moments

6:32 min

Embracing DevSecOps and automating the software development lifecycle

Mathias Tausig · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026

Farshad Abasi

CEO/Founder, Eureka DevSecOps + Forward Security

Farshad Abasi
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey