03 Jun 2027
Melbourne
97d 17h 34m
until doors open
Third Edition

Melbourne Secure Software and AppSec Summit 2027

AppSec

Join us at the Melbourne Secure Software and AppSec Summit. A fast-moving, peer-led day for AppSec professionals, senior developers, and security leaders on real-world risks, from AI-driven threats to supply chain exposure, and how teams are solving them without slowing delivery. Free-to-attend.

June 3, 2027
Thursday
8:30am - 4:45pm
AEST
Collins Square Events Centre
Level 5, Tower 2/727 Collins St, Docklands VIC 3008
Free to attend
Industry practitioners

The security playbook for teams shipping secure software at speed.

Free to attend
60-second registration
Instant confirmation
What you'll walk out with

Concrete deliverables, not just notes.

1

Roundtable Discussions

Small groups, real problems, peers in your seat.

2

Keynote Presentations

Practitioners sharing what worked, not vendor theory.

3

Panel Discussions

Live debate. Vote and contribute from your phone.

4

1-2-1 Meetings

Matched to your challenges. Optional, never a pitch.

agenda preview

A day designed for momentum.

2 keynotes · 3 panels · 4 "How I Solved" case studies · 1 live audience simulation · roundtables · drinks.

9:20 am

Opening Keynote: Managing and Securing AI-Generated Code

How AI-generated code is changing application security, and where old approaches fall short.

AI-generated code is becoming a bigger part of software development, but it is also creating new security challenges. The risks of AI-generated and vibe coded software are drawing growing scrutiny, raising important questions about how organisations review and secure code created with AI.

This opening keynote explores how AI-generated code is changing application security, where traditional approaches may fall short, and how organisations can manage these risks at scale.

  • Why AI-generated code is creating new security risks
  • How AppSec, code review, and testing practices need to adapt to AI-generated code
  • How organisations can manage the risk through stronger tools, processes, and accountability
Collapse
Read more
Keynote
11:25 am

Audience Activity

Tackle a real software security scenario together with your peers.

A hands-on, interactive session working through a real software security scenario as a room. Details announced soon.

Collapse
Read more
12:40 pm

Peer Roundtables

Small-group problem-solving with people in similar roles — topics announced soon.

Small-group, discussion-based sessions where you'll work through real software security challenges with peers in similar roles. Roundtable topics will be announced soon.

Collapse
Read more
3:10 pm

Think Tank: Finding the Right Balance Between Automated and Manual Security Testing

Live voting on where automation ends and manual testing still earns its place.

Automation is helping security teams test software faster and at greater scale, but not every security risk can be identified automatically. Human expertise and manual testing still have an important role to play.

This interactive think tank will use live audience voting to explore how organisations are balancing automated and manual security testing, where gaps remain, and how AI could change that balance.

  1. How much of your security testing is currently automated?
  2. Where has automated testing missed risks that manual testing could have identified?
  3. Is AI-generated code tested to the same standard as human-written code?
  4. Who decides when automated testing is enough and when manual review is needed?
  5. Where will you invest next: automation, manual testing, or AI-assisted security tools?
Collapse
Read more
8:30 am

Registration Opens & Networking Breakfast

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Collapse
Read more
SOCIAL
9:15 am

Welcome & Opening Remarks

Kick off the day with a welcome from your MC and a look at what's ahead.
Collapse
Read more
9:20 am

Opening Keynote: Managing and Securing AI-Generated Code

How AI-generated code is changing application security, and where old approaches fall short.

AI-generated code is becoming a bigger part of software development, but it is also creating new security challenges. The risks of AI-generated and vibe coded software are drawing growing scrutiny, raising important questions about how organisations review and secure code created with AI.

This opening keynote explores how AI-generated code is changing application security, where traditional approaches may fall short, and how organisations can manage these risks at scale.

  • Why AI-generated code is creating new security risks
  • How AppSec, code review, and testing practices need to adapt to AI-generated code
  • How organisations can manage the risk through stronger tools, processes, and accountability
Collapse
Read more
Keynote
9:40 am

Keynote: Closing Governance Gaps as AI Becomes Part of Software Development

Updating governance and accountability as AI writes more of the codebase.

As AI takes on a bigger role in writing, reviewing, and deploying code, traditional software governance needs to evolve. Many existing processes were designed around human developers and may not provide the right oversight for AI-generated work.

This keynote explores how organisations can update their governance, processes, and accountability as AI becomes a bigger part of software development.

  • Where existing software governance may fall short when AI is involved
  • What approval and accountability should look like for AI-generated code
  • Practical steps to strengthen governance and reduce security and compliance risks
Collapse
Read more
Keynote
10:10 am

Panel Discussion: Building Security Into the Development Process From the Start

Making shift-left security work without slowing developers down.

Building security into software early can help teams identify and fix issues before they become bigger problems. But many organisations still struggle to make security a natural part of the development process without slowing developers down.

This panel explores how teams can make security part of everyday development, improve collaboration between developers and security teams, and make shift-left security work in practice.

  • What makes shift-left security work effectively
  • How security champions can help build stronger security practices across development teams
  • How to give developers the right security guidance without slowing down delivery
Collapse
Read more
Panel
10:40 am

How I Solved… Getting Open Source and Supply Chain Security Under Control With SBOMs

Getting visibility over open source dependencies and supply chain risk.

Many organisations rely on open source software but don't always have a clear view of what is inside their applications or where the risks are. As software supply chain security becomes more important, organisations need better visibility over their software and dependencies.

This case study explores how one team introduced a Software Bill of Materials (SBOM) and built a practical approach to managing open source and supply chain risk.

  • What their first SBOM revealed about hidden dependencies and security risks
  • How they built an ongoing process to identify, track, and address open source risks
  • How they made SBOM data useful for security teams, rather than just a compliance requirement
Collapse
Read more
case study
10:55 am

Morning Tea & Networking

Recharge with refreshments and structured networking with your peers.
Collapse
Read more
SOCIAL
11:25 am

Audience Activity

Tackle a real software security scenario together with your peers.

A hands-on, interactive session working through a real software security scenario as a room. Details announced soon.

Collapse
Read more
11:40 am

How I Solved… Automating Security Testing Without Slowing Teams Down

Automating security testing across the pipeline without creating delays.

Security testing needs to keep up with faster software releases. If testing takes too long or creates too many delays, development teams may find ways around it.

This case study explores how one team automated security testing across its development pipeline, what they chose to automate, and where human testing was still needed.

  • Which security tests they automated first and why
  • How automation helped improve security without slowing down development
  • Where automated testing still had gaps and required human oversight
Collapse
Read more
case study
11:55 am

How I Solved… Securing Containers and Microservices at Scale

Improving container and microservices security without slowing deployments.

As organisations use more containers and microservices, managing security across these environments can become more complex. Teams need to protect applications and services without creating delays in development and deployment.

This case study explores how one organisation improved container and microservices security while maintaining the speed of its deployment pipeline.

  • Where they identified the biggest security gaps across containers and microservices
  • How they improved image scanning, runtime protection, and access between services
  • How they strengthened security without slowing down deployments
Collapse
Read more
case study
12:10 pm

Panel Discussion: Using AI and AI Agents to Strengthen Software Security

Where AI agents deliver real AppSec value, and where human expertise still matters.

AI is creating new security risks, but it is also giving security teams new ways to find and respond to vulnerabilities faster. From automated testing to reviewing and prioritising security issues, AI is becoming a growing part of AppSec.

This panel explores where AI and AI agents are delivering real value, where their limitations remain, and when human expertise is still needed.

  • Where AI is helping AppSec teams improve testing and identify security risks faster
  • Where AI-powered security tools still require human review and oversight
  • What teams should consider before using AI agents to make security decisions
Collapse
Read more
Panel
12:40 pm

Peer Roundtables

Small-group problem-solving with people in similar roles — topics announced soon.

Small-group, discussion-based sessions where you'll work through real software security challenges with peers in similar roles. Roundtable topics will be announced soon.

Collapse
Read more
1:30 pm

Lunch & Networking

Enjoy a complimentary lunch while connecting with fellow attendees.
Collapse
Read more
SOCIAL
2:20 pm

QuickFire Quiz: Test Your Knowledge Against Your Peers

Test your knowledge in a fast-paced quiz — the top scorer takes the crown.

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.

Collapse
Read more
SOCIAL
2:35 pm

How I Solved… Preparing for and Responding to an Application Breach

What a real application breach exposed in the incident response plan.

Cyberattacks are moving faster, making it more important for organisations to detect and respond to application breaches quickly. Even with an incident response plan in place, a real attack can expose gaps that weren't expected.

This case study explores how one organisation responded to an application breach, what didn't work as planned, and how they improved their approach afterwards.

  • What happened during the breach and where the response plan fell short
  • What the team learned about responding to an incident under pressure
  • How they improved their tools, processes, and communication for future incidents
Collapse
Read more
case study
2:50 pm

Keynote: Building a Strong DevSecOps Culture

Why DevSecOps stalls at the tooling stage, and what culture change requires.

Technology and automation are important, but strong software security also depends on culture. Security works best when developers, security teams, and leaders see it as a shared responsibility.

This closing keynote explores how organisations can build a stronger DevSecOps culture, improve collaboration between teams, and make security part of everyday software development.

  • Why DevSecOps can struggle when the focus is only on tools and technology
  • How developers and security teams can share responsibility for security
  • How leaders can help build and support a strong security culture
Collapse
Read more
Keynote
3:10 pm

Think Tank: Finding the Right Balance Between Automated and Manual Security Testing

Live voting on where automation ends and manual testing still earns its place.

Automation is helping security teams test software faster and at greater scale, but not every security risk can be identified automatically. Human expertise and manual testing still have an important role to play.

This interactive think tank will use live audience voting to explore how organisations are balancing automated and manual security testing, where gaps remain, and how AI could change that balance.

  1. How much of your security testing is currently automated?
  2. Where has automated testing missed risks that manual testing could have identified?
  3. Is AI-generated code tested to the same standard as human-written code?
  4. Who decides when automated testing is enough and when manual review is needed?
  5. Where will you invest next: automation, manual testing, or AI-assisted security tools?
Collapse
Read more
3:40 pm

Closing Remarks & Prize Draw

Wrap-up of the day's key takeaways — and your chance to win some epic prizes.
Collapse
Read more
3:45 pm

Networking Drinks Hour

Unwind with your peers for a couple of drinks on us!

Unwind with your peers for a couple of drinks on us!

Collapse
Read more
SOCIAL
4:45 pm

Event Closed

Collapse
Read more
8:30 am

Registration Opens & Networking Breakfast

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Collapse
Read more
SOCIAL
9:15 am

Welcome & Opening Remarks

Kick off the day with a welcome from your MC and a look at what's ahead.
Collapse
Read more
9:20 am

Opening Keynote: Managing and Securing AI-Generated Code

How AI-generated code is changing application security, and where old approaches fall short.

AI-generated code is becoming a bigger part of software development, but it is also creating new security challenges. The risks of AI-generated and vibe coded software are drawing growing scrutiny, raising important questions about how organisations review and secure code created with AI.

This opening keynote explores how AI-generated code is changing application security, where traditional approaches may fall short, and how organisations can manage these risks at scale.

  • Why AI-generated code is creating new security risks
  • How AppSec, code review, and testing practices need to adapt to AI-generated code
  • How organisations can manage the risk through stronger tools, processes, and accountability
Collapse
Read more
Keynote
9:40 am

Keynote: Closing Governance Gaps as AI Becomes Part of Software Development

Updating governance and accountability as AI writes more of the codebase.

As AI takes on a bigger role in writing, reviewing, and deploying code, traditional software governance needs to evolve. Many existing processes were designed around human developers and may not provide the right oversight for AI-generated work.

This keynote explores how organisations can update their governance, processes, and accountability as AI becomes a bigger part of software development.

  • Where existing software governance may fall short when AI is involved
  • What approval and accountability should look like for AI-generated code
  • Practical steps to strengthen governance and reduce security and compliance risks
Collapse
Read more
Keynote
10:10 am

Panel Discussion: Building Security Into the Development Process From the Start

Making shift-left security work without slowing developers down.

Building security into software early can help teams identify and fix issues before they become bigger problems. But many organisations still struggle to make security a natural part of the development process without slowing developers down.

This panel explores how teams can make security part of everyday development, improve collaboration between developers and security teams, and make shift-left security work in practice.

  • What makes shift-left security work effectively
  • How security champions can help build stronger security practices across development teams
  • How to give developers the right security guidance without slowing down delivery
Collapse
Read more
Panel
10:40 am

How I Solved… Getting Open Source and Supply Chain Security Under Control With SBOMs

Getting visibility over open source dependencies and supply chain risk.

Many organisations rely on open source software but don't always have a clear view of what is inside their applications or where the risks are. As software supply chain security becomes more important, organisations need better visibility over their software and dependencies.

This case study explores how one team introduced a Software Bill of Materials (SBOM) and built a practical approach to managing open source and supply chain risk.

  • What their first SBOM revealed about hidden dependencies and security risks
  • How they built an ongoing process to identify, track, and address open source risks
  • How they made SBOM data useful for security teams, rather than just a compliance requirement
Collapse
Read more
case study
10:55 am

Morning Tea & Networking

Recharge with refreshments and structured networking with your peers.
Collapse
Read more
SOCIAL
11:25 am

Audience Activity

Tackle a real software security scenario together with your peers.

A hands-on, interactive session working through a real software security scenario as a room. Details announced soon.

Collapse
Read more
11:40 am

How I Solved… Automating Security Testing Without Slowing Teams Down

Automating security testing across the pipeline without creating delays.

Security testing needs to keep up with faster software releases. If testing takes too long or creates too many delays, development teams may find ways around it.

This case study explores how one team automated security testing across its development pipeline, what they chose to automate, and where human testing was still needed.

  • Which security tests they automated first and why
  • How automation helped improve security without slowing down development
  • Where automated testing still had gaps and required human oversight
Collapse
Read more
case study
11:55 am

How I Solved… Securing Containers and Microservices at Scale

Improving container and microservices security without slowing deployments.

As organisations use more containers and microservices, managing security across these environments can become more complex. Teams need to protect applications and services without creating delays in development and deployment.

This case study explores how one organisation improved container and microservices security while maintaining the speed of its deployment pipeline.

  • Where they identified the biggest security gaps across containers and microservices
  • How they improved image scanning, runtime protection, and access between services
  • How they strengthened security without slowing down deployments
Collapse
Read more
case study
12:10 pm

Panel Discussion: Using AI and AI Agents to Strengthen Software Security

Where AI agents deliver real AppSec value, and where human expertise still matters.

AI is creating new security risks, but it is also giving security teams new ways to find and respond to vulnerabilities faster. From automated testing to reviewing and prioritising security issues, AI is becoming a growing part of AppSec.

This panel explores where AI and AI agents are delivering real value, where their limitations remain, and when human expertise is still needed.

  • Where AI is helping AppSec teams improve testing and identify security risks faster
  • Where AI-powered security tools still require human review and oversight
  • What teams should consider before using AI agents to make security decisions
Collapse
Read more
Panel
12:40 pm

Peer Roundtables

Small-group problem-solving with people in similar roles — topics announced soon.

Small-group, discussion-based sessions where you'll work through real software security challenges with peers in similar roles. Roundtable topics will be announced soon.

Collapse
Read more
1:30 pm

Lunch & Networking

Enjoy a complimentary lunch while connecting with fellow attendees.
Collapse
Read more
SOCIAL
2:20 pm

QuickFire Quiz: Test Your Knowledge Against Your Peers

Test your knowledge in a fast-paced quiz — the top scorer takes the crown.

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.

Collapse
Read more
SOCIAL
2:35 pm

How I Solved… Preparing for and Responding to an Application Breach

What a real application breach exposed in the incident response plan.

Cyberattacks are moving faster, making it more important for organisations to detect and respond to application breaches quickly. Even with an incident response plan in place, a real attack can expose gaps that weren't expected.

This case study explores how one organisation responded to an application breach, what didn't work as planned, and how they improved their approach afterwards.

  • What happened during the breach and where the response plan fell short
  • What the team learned about responding to an incident under pressure
  • How they improved their tools, processes, and communication for future incidents
Collapse
Read more
case study
2:50 pm

Keynote: Building a Strong DevSecOps Culture

Why DevSecOps stalls at the tooling stage, and what culture change requires.

Technology and automation are important, but strong software security also depends on culture. Security works best when developers, security teams, and leaders see it as a shared responsibility.

This closing keynote explores how organisations can build a stronger DevSecOps culture, improve collaboration between teams, and make security part of everyday software development.

  • Why DevSecOps can struggle when the focus is only on tools and technology
  • How developers and security teams can share responsibility for security
  • How leaders can help build and support a strong security culture
Collapse
Read more
Keynote
3:10 pm

Think Tank: Finding the Right Balance Between Automated and Manual Security Testing

Live voting on where automation ends and manual testing still earns its place.

Automation is helping security teams test software faster and at greater scale, but not every security risk can be identified automatically. Human expertise and manual testing still have an important role to play.

This interactive think tank will use live audience voting to explore how organisations are balancing automated and manual security testing, where gaps remain, and how AI could change that balance.

  1. How much of your security testing is currently automated?
  2. Where has automated testing missed risks that manual testing could have identified?
  3. Is AI-generated code tested to the same standard as human-written code?
  4. Who decides when automated testing is enough and when manual review is needed?
  5. Where will you invest next: automation, manual testing, or AI-assisted security tools?
Collapse
Read more
3:40 pm

Closing Remarks & Prize Draw

Wrap-up of the day's key takeaways — and your chance to win some epic prizes.
Collapse
Read more
3:45 pm

Networking Drinks Hour

Unwind with your peers for a couple of drinks on us!

Unwind with your peers for a couple of drinks on us!

Collapse
Read more
SOCIAL
4:45 pm

Event Closed

Collapse
Read more
What attendees say

Why engineering leaders return year after year.

4.7 / 5
Average attendee rating
Across all 2025 events
94%
Rate our content extremely relevant
Keynotes
panels
case studies
100%
Would recommend us to a colleague
2025 post-event survey
I recently attended Clutch Events Melbourne Secure Software and AppSec Summit, and it was a solid reality check on where software security is heading as AI adoption explodes. There was honestly way too much value packed into the event to cover in a single post. Huge credit to all the speakers on providing such an informative packed morning.
Kenneth H.
Founder, Praxis Cyber
This was a great event with very relevant topics and knowledgeable speakers. The audience was engaged throughout. Kudos to Mike for being such a great host and moderator.
Rob Schluensen
Talent Acquisition, Peregrine
Thanks, enjoyed the event today. It was well run and there were some great takeaways from a couple of the speakers.
Dion Maber
Cloud Engineer, ANZ
Past Speakers
Robert Whelan

Security Architect, Australian Signals Directorate

Cole Cornford

Chief Executive Officer, Galah Cyber

Will Sharpe

Chief Information Security Officer, Telstra Health

Edwin Kwan

Head of Product Security, Domain Group

Simon Ellis

Head of Cybersecurity, Lendi Group

Girish Darda

Head of Security, Littlepay

Past Sponsors
Partners

Backed by the platforms your team actually runs on

Looking to partner? Get in touch
Reach Danny Perry, Director of Sales
Get the partner pack
Register

Register in under 60 seconds.

Complimentary Full-day access to keynotes, panels & case studies

Includes catering & post-event drinks.
Opens a 60-second form
no payment details
Instant confirmation
FAQ's

Common questions.

What do I need to bring?

Just bring yourself, your laptop or a notebook and get ready to collaborate!

Will sessions be recorded or live-streamed?

No. You'll have to be there to enjoy the sessions.

Will there be WiFi?

Yes, absolutely! Stay connected at the event with complimentary wifi - we'll share the details at the event.

Will food and drinks be provided?

Yes, morning tea, lunch, and afternoon refreshments will be provided. Please indicate any dietary requirements during registration.

Are Chatham House Rules in effect?

Absolutely! No media, recordings, or live streaming... what happens in the room, stays in the room.

What is the dress code?

Smart casual or business casual is recommended, no need for a suit and tie! Keep it comfortable.

Are there any fees to attend?

Nope! The conference is completely free for industry professionals. Contact us if you are not sure whether you qualify.

Venue

Getting there.

Melbourne
Collins Square Events Centre
Level 5, Tower 2/727 Collins St, Docklands VIC 3008
Melbourne
·
June 3, 2027

97 days left.
Register free today.

Be the engineering leader in the room — not the one reading the LinkedIn recap.

Free to attend
60-second registration
Instant confirmation

Contact our event team for any enquiry

Director of Sales
Danny Perry
For sponsorship opportunities.
danny@clutchgroup.co
Director of Client Relations
Lili Munar
For guest and attendee enquiries.
lilibeth@clutchgroup.co
Director of Conference Production
Steph Tolmie
For speaking opportunities & content enquiries.
stephanie@clutchevents.co
Director of Operations
Taylor Stanyon
For event-related enquiries.
taylor@clutchgroup.co