WeAreDevelopers LIVE • Oct 12, 2020

You can’t hack what you can’t see

Reto Kaeser

Traditional boundary firewalls are obsolete. Since 80% of cloud traffic is internal, perimeter breaches are devastating. Harness microsegmentation and zero trust to make workloads invisible to attackers.

Pause
Mute Enter Fullscreen
#1 about 3 min

Evolving from siloed operations to DevOps culture

Culture plays a massive role in successful DevOps adoption beyond tooling.

#2 about 2 min

Integrating security into the DevOps lifecycle

Left-shifting security creates DevSecOps to protect modern remote workloads.

#3 about 4 min

Identifying abuse cases during requirements gathering

Addressing potential attack vectors early hardens architecture before design begins.

#4 about 2 min

Security challenges of workload abstraction in cloud environments

Containerizing and moving workloads introduces fine-grained connection risks.

#5 about 3 min

Classifying and anonymizing data during system design

Treating restricted data carefully and avoiding unnecessary context reduces exposure risk.

#6 about 4 min

Managing vulnerabilities in open-source libraries early

Catching vulnerable component versions using pre-commit hooks saves downstream remediation time.

#7 about 2 min

Leveraging continuous penetration testing via red teams

Feeding abuse cases directly to testers improves ongoing security posture.

#8 about 3 min

Protecting internal east-west traffic within networks

Shifting focus from external firewalls to safeguarding internal communications between services.

#9 about 2 min

Securing individual workloads systematically at the application layer

Moving security policies away from infrastructure to surround the data directly.

#10 about 2 min

Implementing logical firewalls to enforce microsegmentation

Defining communication restrictions workload-by-workload limits the radius of potential breaches.

#11 about 2 min

Adopting zero-trust principles and whitelisting intentions

Only allowing explicitly approved workloads to access specific services hardens environments.

#12 about 2 min

Automating firewall policies using security as code

Tagging workloads natively in code speeds up policy generation and enforcement.

#13 about 3 min

Reaping the benefits of embedded cloud workload security

Letting protection follow workloads automatically unlocks true agility and scalability.

#14 about 2 min

Staying paranoid to ensure continuous software security

Maintaining a healthy skepticism helps prioritize secure delivery in an increasingly dangerous computing landscape.

Matching moments

6:32 min

Embracing DevSecOps and automating the software development lifecycle

Mathias Tausig · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE