Secure Coding: Build Safe Software Across the SDLC

Write software that resists attacks efficiently. This Secure Coding & SDLC track puts the OWASP Top 10 into practice: preventing cross-site scripting (XSS and mutation XSS/mXSS), SQL injection, CSRF, and SSRF, and hardening apps with the right security headers. You'll embed security into every stage of the software development lifecycle: threat modeling, SAST/SCA in the pipeline, and SBOMs. Additionally, you’ll prepare for post-quantum cryptography and the EU Cyber Resilience Act.

Secure Coding & Software Development Lifecycle

What you can learn:

  • OWASP Top 10: understand and mitigate today’s most critical web application risks
  • Prevent common vulnerabilities: XSS, mutation XSS (mXSS), SQL injection, CSRF, SSRF
  • Security headers & hardening: strengthen web apps and APIs by default
  • Threat modeling: build secure-by-design software with STRIDE and PASTA
  • Secure SDLC & pipelines: add SAST, SCA and SBOMs to your lifecycle
  • Application security hands-on: learn by hacking deliberately vulnerable apps (e.g. WebGoat)
  • Future-proofing: post-quantum cryptography and the EU Cyber Resilience Act

Track Speakers Berlin 2026

Track Speakers Munich 2026

Track Program Munich 2026

Track Program Berlin 2026

Track Sessions Berlin 2026

Track Sessions Berlin 2026

View all sessions

Track Sessions Munich 2026

Track Sessions Munich 2026

View all sessions

FAQ

What is secure coding?

Secure coding is the practice of writing software that resists attacks by design validating input, encoding output, managing secrets safely, and following standards like the OWASP Top 10.

What is the OWASP Top 10?

The OWASP Top 10 is the industry-standard list of the most critical web application security risks, updated by the Open Worldwide Application Security Project and used as a baseline for secure development.

How do you prevent cross-site scripting (XSS)?

Encode output for its context, validate input, apply a Content Security Policy, and use framework protections. Besides that, watch for mutation XSS (mXSS), which slips past naive sanitizers.

What is a secure SDLC?

A secure Software Development Lifecycle embeds security into every phase of the development process (design, coding, testing, and release) instead of testing only at the end.

What is WebGoat?

WebGoat is a deliberately insecure application from OWASP used to learn and practice web application security hands-on.

Enjoying the content?

Get the most out of IT Security Summit by becoming a free community member — curated resources, weekly newsletter, and member-only perks.

Weekly
Articles + tutorials

The reads you'd find if you had time

2× / mo
Live webinars

Experts you can actually ask

Monthly
Magazine + whitepapers

Deep dives worth your weekend

On-demand
Recordings + courses

Past conferences, ready when you are

AI-Powered Security
Harness AI for security automation, threat detection, and integrating AI-driven solutions into DevSecOps.

Cloud, API Security & Identity
Safeguard your cloud environments, APIs, and identities with advanced strategies.

DevSecOps
Integrate security into your DevOps processes with precision.

Pentesting, Vulnerability Management & Forensics
Advance your offensive security skills with cutting-edge penetration testing techniques.

Secure Coding & Software Development Lifecycle
Create secure software from the ground up by mastering secure coding practices and embedding security throughout the Software Development Lifecycle (SDLC).