
Short, sharp and interactive: keynotes and case studies from practitioners, live panels you vote in, peer roundtables on the problems you name, and two hours of structured networking by design.

Speakers are announced on a rolling basis. Sign up for updates to hear each announcement first.
All times PDT. Sessions are announced and updated on a rolling basis.
Beat the rush and join us early for complimentary barista-made coffee and breakfast.
Kick off the day with a welcome from your MC and a look at what's ahead.
Secure by design is now an expectation from regulators, customers and boards. Turning it from a principle into something engineering teams actually do is the hard part.
This opening keynote is a practitioner's account of embedding security into how software gets designed and built: which decisions moved earlier, what secure defaults were made non-optional, how the case was made to product and engineering leadership, and what measurably changed in the vulnerabilities that reached production.
AI coding assistants now write a meaningful share of enterprise code, and they introduce risks that look nothing like the ones AppSec programs were built to catch.
This keynote works through what actually goes wrong: insecure patterns reproduced at scale, dependencies hallucinated into existence, secrets and context leaking through prompts, and agents with far more access to source and infrastructure than anyone intended — and what controls hold up against each.
The software supply chain keeps getting attacked where teams have the least visibility: build pipelines, package registries, CI credentials and the maintainers of dependencies nobody has looked at in years.
This panel brings together leaders defending real pipelines to compare what they actually do — how they verify what they consume, what SBOMs are and are not good for, how they respond when a dependency is compromised, and where they think the next wave hits.
Once AI is writing and reviewing code, the audit question changes: who wrote this, what reviewed it, and can you show that to an auditor?
In this case study, a practitioner walks through the governance they put around an AI-assisted development lifecycle — what they log, how AI-generated changes are reviewed differently, which gates stayed human, and how they produced compliance evidence without slowing delivery to a crawl.
Recharge with refreshments and structured networking with your peers.
Attendees are faced with a series of scenarios they may meet in their own roles, discussing the possible courses of action with peers before logging their own decision. Results are tallied live and shape how the room moves through the activity.
Most AppSec programs do not have a detection problem. They have a triage problem: five tools, tens of thousands of findings, and no agreed answer to which ones matter.
This session details how one team connected their testing and posture data, worked out what was genuinely exploitable and reachable, and produced a prioritized list engineering was willing to act on — plus what they stopped reporting altogether.
Every organization has more APIs than its inventory says, and the undocumented ones are where the incidents come from.
A practitioner shares how they built a real picture of their API estate across cloud and cloud-native environments — how they discovered what was actually exposed, which authorisation flaws they found, how they tested for them continuously as services changed, and how they kept the inventory accurate afterwards.
Every AppSec leader says security and speed are not in conflict. Every engineering leader has a story about a release gate that says otherwise.
This panel gets honest about the trade-off: where security genuinely slows delivery, which controls are worth that cost, how teams decide what blocks a release and what does not, and what it takes for engineering to treat AppSec as help rather than tax.
Small-group, discussion-based sessions where you'll work through real application and product security challenges with peers in similar roles. Roundtable topics announced soon.
Enjoy a complimentary lunch while connecting with fellow attendees.
Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts and emerging trends. Compete for bragging rights — and a travel voucher — as the top scorer takes the crown.
AppSec that starts at the pull request has already missed most of the decisions that matter. Product security starts at architecture and stays involved through production.
This keynote sets out what that shift actually requires: threat modelling that engineers will do, security owning outcomes rather than findings, how the function is staffed and where it reports, and what changes in the relationship with product and engineering leadership.
The fastest way to reduce risk is for the person who wrote the code to fix it before it ships. Most programs never get there, because the feedback arrives late, in the wrong tool, with no clear fix.
This case study covers how one team moved security feedback into the developer's workflow, provided secure defaults and paved paths instead of policy documents, and got remediation happening in days rather than quarters.
Centralised or embedded, gatekeeper or enabler, tooling-led or people-led: every AppSec team is running one of these models and quietly wondering whether it picked the right one.
This interactive session puts the strategic trade-offs directly to the room, using live voting to surface where the audience really stands versus where the market says they should be, then debating the gaps.
Wrap-up of the day's key takeaways — and your chance to win some epic prizes.
Unwind with your peers for a couple of drinks on us!
See you at AppSec World Melbourne on 3 June 2027.
