I'll be speaking at DevOpsDays Austin, May 1st and 2nd! My presentation is "Give up! Just stop patching vulnerabilities!". I'll be talking about taking a proactive approach to vulnerability remediation and not focusing on reactive measures.
In today’s fast-paced development environments, vulnerability management often feels like a reactive game of whack-a-mole. Developers spend countless hours patching flaws as they emerge, but this approach only treats the symptoms of a deeper issue. In this talk, we’ll explore how to break the cycle by focusing on prevention rather than endless remediation. Instead of chasing down individual vulnerabilities, we’ll discuss how to eliminate entire classes of vulnerabilities, such as cross-site scripting (XSS) and SQL injection, through secure-by-default frameworks, libraries, and targeted development practices.
Cultural shifts are at the heart of this transformation. We’ll talk about how to empower developers to take ownership of security by integrating lightweight threat modeling into their workflows and fostering a mindset that prioritizes prevention. This isn’t about adding more steps to your process—it’s about making security an intrinsic part of how you build software.
Finally, we’ll examine practical strategies for managing third-party vulnerabilities, including smart patching cycles and automation, and introduce modern approaches like ephemeral infrastructure. By adopting a "burn-and-replace" mindset for containers and serverless functions, you can minimize your reliance on traditional patching altogether. If you’re ready to move beyond the reactive and start building secure systems by design, this talk is for you.
https://devopsdays.org/events/2025-austin/welcome/
#DevOps #DevOpsDays #Security #SecurityTalks #DevelopersFirst #ConferenceTalks