DevSecOps: Secure Every Stage of Your CI/CD Pipeline

Build security into DevOps from the first commit to production. This DevSecOps track shows you how to automate security across the CI/CD pipeline by integrating SAST, SCA, and secret scanning, generating a software bill of materials (SBOM), and defending the software supply chain. You'll apply threat modeling (STRIDE, PASTA), enforce zero trust with service meshes like Istio, meet the EU Cyber Resilience Act (CRA), and use AI to ship secure code faster.

DevSecOps

What you can learn:

  • Secure CI/CD pipelines: integrate SAST, SCA, DAST and secret scanning into GitHub and beyond
  • Software supply chain security: build and manage SBOMs and stop supply chain attacks
  • EU Cyber Resilience Act (CRA): meet the new compliance requirements across your SDLC
  • Threat modeling: apply STRIDE and PASTA to find risks before attackers do
  • Zero trust & service mesh: enforce mTLS and authorization with Istio Ambient
  • AI in DevSecOps: use AI for threat modeling, secure code, and continuous testing
  • DevSecOps Maturity Model (DSOMM): benchmark and level up your practices

Track Speakers Munich 2026

Track Speakers Berlin 2026

Track Program Berlin 2026

Track Program Munich 2026

Track Sessions Berlin 2026

Track Sessions Berlin 2026

View all sessions

Track Sessions Munich 2026

Track Sessions Munich 2026

View all sessions

FAQ

What is DevSecOps?

DevSecOps integrates security into every stage of DevOps: planning, coding, building, testing, and operations. That way, security is automated and continuous rather than a final gate.

What's the difference between DevOps and DevSecOps?

DevOps optimizes for fast, reliable delivery; DevSecOps adds automated security (scanning, policy, compliance) into that same pipeline so speed doesn't come at the cost of risk.

What is an SBOM and why does it matter?

A Software Bill of Materials is a complete inventory of the components in your software. It's central to supply chain security and increasingly required by regulations like the EU Cyber Resilience Act.

What is shift-left security?

Shift-left means moving security testing earlier in the development process (into the IDE and pipeline). That way, issues are caught when they're cheapest to fix.

Who should attend the DevSecOps track?

Developers, DevOps and platform engineers, and security professionals who want hands-on, tool-level techniques for securing modern delivery.

Enjoying the content?

Get the most out of IT Security Summit by becoming a free community member — curated resources, weekly newsletter, and member-only perks.

Weekly
Articles + tutorials

The reads you'd find if you had time

2× / mo
Live webinars

Experts you can actually ask

Monthly
Magazine + whitepapers

Deep dives worth your weekend

On-demand
Recordings + courses

Past conferences, ready when you are

AI-Powered Security
Harness AI for security automation, threat detection, and integrating AI-driven solutions into DevSecOps.

Cloud, API Security & Identity
Safeguard your cloud environments, APIs, and identities with advanced strategies.

DevSecOps
Integrate security into your DevOps processes with precision.

Pentesting, Vulnerability Management & Forensics
Advance your offensive security skills with cutting-edge penetration testing techniques.

Secure Coding & Software Development Lifecycle
Create secure software from the ground up by mastering secure coding practices and embedding security throughout the Software Development Lifecycle (SDLC).