Join us at the inaugural London Secure Software and AppSec Summit. A fast-moving, peer-led day for AppSec professionals, senior developers, and security leaders on real-world risks, from AI-generated code to supply chain exposure, and how teams are solving them without slowing delivery. Free-to-attend.
Small groups, real problems, peers in your seat. Ten to twelve practitioners around one table, chaired by someone who does the job, working through something the whole room is dealing with.

Practitioners sharing what worked, not vendor theory. What they built, what it cost, what broke, and what they would do differently.

Live debate. Vote and contribute from your phone. Three or four people who genuinely disagree, a chair willing to push, and the room's answers on screen as it runs.

Matched to your challenges. Short meetings with solution providers based on what you flag at registration, scheduled around the rest of your day at the summit.

2 keynotes · 3 panels · 4 "How I Solved" case studies · 1 live audience simulation · roundtables · drinks.
AI-generated code is becoming a bigger part of software development, but it is also creating new security challenges. The UK's National Cyber Security Centre (NCSC) has highlighted the risks of AI-generated and "vibe coded" software, raising important questions about how organisations review and secure code created with AI. This opening keynote explores how AI-generated code is changing application security, where traditional approaches may fall short, and how organisations can manage these risks at scale.
A hands-on, interactive session working through a real software security scenario as a room. Details announced soon.
Small-group, discussion-based sessions where you'll work through real software security challenges with peers in similar roles. Roundtable topics will be announced soon.
Automation has transformed security testing coverage and speed, but not every risk can be caught by a scanner, and over-reliance on automation has its own failure modes. This session puts the trade-off directly to the room with live voting, then debates where the balance should actually sit.
Beat the rush and join us early for complimentary barista-made coffee and breakfast.
AI-generated code is becoming a bigger part of software development, but it is also creating new security challenges. The UK's National Cyber Security Centre (NCSC) has highlighted the risks of AI-generated and "vibe coded" software, raising important questions about how organisations review and secure code created with AI. This opening keynote explores how AI-generated code is changing application security, where traditional approaches may fall short, and how organisations can manage these risks at scale.
As AI becomes a bigger part of software development, organisations need to rethink how that software is governed. In the UK, AI is being addressed through existing regulators and evolving guidance, meaning organisations need to build their own approach rather than wait for a single set of rules. This keynote explores how governance needs to change as more code is created with AI, and how organisations can put the right oversight, processes, and accountability in place.
Shift-left security has been the industry mantra for years, yet most organisations still find security bolted on late, and security champions programs often stall without real developer buy-in. This panel examines what's actually working to embed security from the first line of code, rather than as a gate before release, and what's needed to make shift-left more than a slogan.
Many organisations rely heavily on open source software but don't always have a clear picture of what is inside their applications or where the risks are. With software supply chain requirements increasing in the UK and EU, having greater visibility is becoming more important. This case study explores how one team introduced a Software Bill of Materials (SBOM) and built a practical approach to managing open source and supply chain risk.
A hands-on, interactive session working through a real software security scenario as a room. Details announced soon.
Cyberattacks are moving faster, putting greater pressure on organisations to detect and respond to application breaches quickly. Even with an incident response plan in place, the reality of managing a live breach can expose unexpected gaps. This case study explores how one organisation responded to an application breach, what didn't work as planned, and how they improved their approach afterwards.
Containerised and microservice architectures have multiplied the number of things that need securing while often reducing visibility into what's actually running. This case study details how one organisation closed critical gaps in container image security, runtime protection, and microservice-to-microservice access control, without slowing their deployment pipeline.
While AI creates new risk in how code is written, as the NCSC's own guidance acknowledges, it's also becoming a genuine tool for defenders, powering automated penetration testing, faster triage, and security review at a scale human teams can't match alone. This panel examines where AI is actually proving useful in AppSec today, and where it's still overhyped.
Small-group, discussion-based sessions where you'll work through real software security challenges with peers in similar roles. Roundtable topics will be announced soon.
Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.
With exploited vulnerabilities and attack timelines both accelerating, thanks in part to attackers using AI to weaponise flaws faster, incident response plans built for a slower era are being tested and found wanting. This case study walks through a real application breach, what the existing response plan got wrong in the moment, and what was rebuilt afterward.
Tools and automation only get an AppSec program so far; the organisations with genuinely strong security postures tend to have a culture where security is a shared responsibility, not a separate team's problem. This closing keynote covers what it actually takes to build that culture, and why so many DevSecOps transformations stall at the tooling stage.
Automation has transformed security testing coverage and speed, but not every risk can be caught by a scanner, and over-reliance on automation has its own failure modes. This session puts the trade-off directly to the room with live voting, then debates where the balance should actually sit.
Unwind with your peers for a couple of drinks on us!
Beat the rush and join us early for complimentary barista-made coffee and breakfast.
AI-generated code is becoming a bigger part of software development, but it is also creating new security challenges. The UK's National Cyber Security Centre (NCSC) has highlighted the risks of AI-generated and "vibe coded" software, raising important questions about how organisations review and secure code created with AI. This opening keynote explores how AI-generated code is changing application security, where traditional approaches may fall short, and how organisations can manage these risks at scale.
As AI becomes a bigger part of software development, organisations need to rethink how that software is governed. In the UK, AI is being addressed through existing regulators and evolving guidance, meaning organisations need to build their own approach rather than wait for a single set of rules. This keynote explores how governance needs to change as more code is created with AI, and how organisations can put the right oversight, processes, and accountability in place.
Shift-left security has been the industry mantra for years, yet most organisations still find security bolted on late, and security champions programs often stall without real developer buy-in. This panel examines what's actually working to embed security from the first line of code, rather than as a gate before release, and what's needed to make shift-left more than a slogan.
Many organisations rely heavily on open source software but don't always have a clear picture of what is inside their applications or where the risks are. With software supply chain requirements increasing in the UK and EU, having greater visibility is becoming more important. This case study explores how one team introduced a Software Bill of Materials (SBOM) and built a practical approach to managing open source and supply chain risk.
A hands-on, interactive session working through a real software security scenario as a room. Details announced soon.
Cyberattacks are moving faster, putting greater pressure on organisations to detect and respond to application breaches quickly. Even with an incident response plan in place, the reality of managing a live breach can expose unexpected gaps. This case study explores how one organisation responded to an application breach, what didn't work as planned, and how they improved their approach afterwards.
Containerised and microservice architectures have multiplied the number of things that need securing while often reducing visibility into what's actually running. This case study details how one organisation closed critical gaps in container image security, runtime protection, and microservice-to-microservice access control, without slowing their deployment pipeline.
While AI creates new risk in how code is written, as the NCSC's own guidance acknowledges, it's also becoming a genuine tool for defenders, powering automated penetration testing, faster triage, and security review at a scale human teams can't match alone. This panel examines where AI is actually proving useful in AppSec today, and where it's still overhyped.
Small-group, discussion-based sessions where you'll work through real software security challenges with peers in similar roles. Roundtable topics will be announced soon.
Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.
With exploited vulnerabilities and attack timelines both accelerating, thanks in part to attackers using AI to weaponise flaws faster, incident response plans built for a slower era are being tested and found wanting. This case study walks through a real application breach, what the existing response plan got wrong in the moment, and what was rebuilt afterward.
Tools and automation only get an AppSec program so far; the organisations with genuinely strong security postures tend to have a culture where security is a shared responsibility, not a separate team's problem. This closing keynote covers what it actually takes to build that culture, and why so many DevSecOps transformations stall at the tooling stage.
Automation has transformed security testing coverage and speed, but not every risk can be caught by a scanner, and over-reliance on automation has its own failure modes. This session puts the trade-off directly to the room with live voting, then debates where the balance should actually sit.
Unwind with your peers for a couple of drinks on us!

Just bring yourself, your laptop or a notebook and get ready to collaborate!
No. You'll have to be there to enjoy the sessions.
Yes, absolutely! Stay connected at the event with complimentary wifi - we'll share the details at the event.
Yes, morning tea, lunch, and afternoon refreshments will be provided. Please indicate any dietary requirements during registration.
Absolutely! No media, recordings, or live streaming... what happens in the room, stays in the room.
Smart casual or business casual is recommended, no need for a suit and tie! Keep it comfortable.
Nope! The conference is completely free for industry professionals. Contact us if you are not sure whether you qualify.
Be the engineering leader in the room — not the one reading the LinkedIn recap.



