World Congress 2023 Oct 23, 2023

DevSecOps culture

Ali Yazdani

Technology alone won’t solve your security problems. Discover how to build a DevSecOps culture that transforms isolated security bottlenecks into true development enablers.

Pause
Mute Enter Fullscreen
#1 about 3 min

Transitioning from late production testing to continuous integrated security

Testing applications exclusively in production causes operational downtime and creates friction between developers and engineers.

#2 about 2 min

Relying on collaborative culture rather than single security tools

Integrating shared responsibilities and team collaboration solves security problems better than just buying new automation software.

#3 about 2 min

Breaking organizational silos to balance delivery speed and stability

Distributing the workload equally across teams ensures faster software delivery without sacrificing application stability.

#4 about 2 min

Revising internal processes to improve transparency and team communication

Creating security champions across different departments prevents teams from secretly bypassing established test pipelines.

#5 about 3 min

Deploying automated security analysis tools directly into application pipelines

Integrating software component analysis and secret scanning prevents expensive credential leaks in public repositories.

#6 about 2 min

Using visualization and policy code to govern pipeline execution

Monitoring scan logs visually helps managers identify and address developers who skip essential run-time analysis.

#7 about 3 min

Overcoming cultural resistance to achieve international security compliance standards

Combining cross-functional communication with seamless tooling integration allows small teams to secure major regulatory certifications.

#8 about 2 min

Evaluating security culture transformation as a long-term resource investment

Catching software vulnerabilities earlier in the development cycle aggressively reduces the total cost of remediation.

#9 about 2 min

Moving security scanning into local environments via pre-commit conditions

Running automated tests locally before code is merged completely eliminates the accidental publishing of system secrets.

Matching moments

2:57 min

Securing team and management buy-in for DevSecOps adoption

Moataz Nabil Moataz Nabil · LIVE

2:34 min

Transitioning team culture from standard DevOps to DevSecOps

Moataz Nabil Moataz Nabil · LIVE

6:32 min

Embracing DevSecOps and automating the software development lifecycle

Mathias Tausig · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

4:00 min

Core principles for implementing DevSecOps in teams

Aarno Aukia · LIVE

17:55 min

Overcoming cultural friction and scaling DevOps team practices

Jacob Duijzer · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Culture Doesn't Scale Itself: Leading Engineering Teams Through Hypergrowth and the AI Transition

Thanos Baskous

VP of Engineering and Co-founder of Cogent Security

Thanos Baskous
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Agentic Drift: keeping pace with your agents

John Coghlan

Senior Director, Developer Advocacy at GitLab

John Coghlan