Join us at the Sydney Secure Software and AppSec Summit. A fast-moving, peer-led day for AppSec professionals, senior developers, and security leaders on real-world risks, from AI-driven threats to supply chain exposure, and how teams are solving them without slowing delivery. Free-to-attend.
Small groups, real problems, peers in your seat.
Practitioners sharing what worked, not vendor theory.
Live debate. Vote and contribute from your phone.
Matched to your challenges. Optional, never a pitch.
2 keynotes · 3 panels · 4 "How I Solved" case studies · 1 live audience simulation · roundtables · drinks.
AI-generated code is becoming a bigger part of software development, but it is also creating new security challenges. The risks of AI-generated and vibe coded software are drawing growing scrutiny, raising important questions about how organisations review and secure code created with AI.
This opening keynote explores how AI-generated code is changing application security, where traditional approaches may fall short, and how organisations can manage these risks at scale.
A hands-on, interactive session working through a real software security scenario as a room. Details announced soon.
Small-group, discussion-based sessions where you'll work through real software security challenges with peers in similar roles. Roundtable topics will be announced soon.
Automation is helping security teams test software faster and at greater scale, but not every security risk can be identified automatically. Human expertise and manual testing still have an important role to play.
This interactive think tank will use live audience voting to explore how organisations are balancing automated and manual security testing, where gaps remain, and how AI could change that balance.
Beat the rush and join us early for complimentary barista-made coffee and breakfast.
AI-generated code is becoming a bigger part of software development, but it is also creating new security challenges. The risks of AI-generated and vibe coded software are drawing growing scrutiny, raising important questions about how organisations review and secure code created with AI.
This opening keynote explores how AI-generated code is changing application security, where traditional approaches may fall short, and how organisations can manage these risks at scale.
As AI takes on a bigger role in writing, reviewing, and deploying code, traditional software governance needs to evolve. Many existing processes were designed around human developers and may not provide the right oversight for AI-generated work.
This keynote explores how organisations can update their governance, processes, and accountability as AI becomes a bigger part of software development.
Building security into software early can help teams identify and fix issues before they become bigger problems. But many organisations still struggle to make security a natural part of the development process without slowing developers down.
This panel explores how teams can make security part of everyday development, improve collaboration between developers and security teams, and make shift-left security work in practice.
Many organisations rely on open source software but don't always have a clear view of what is inside their applications or where the risks are. As software supply chain security becomes more important, organisations need better visibility over their software and dependencies.
This case study explores how one team introduced a Software Bill of Materials (SBOM) and built a practical approach to managing open source and supply chain risk.
A hands-on, interactive session working through a real software security scenario as a room. Details announced soon.
Security testing needs to keep up with faster software releases. If testing takes too long or creates too many delays, development teams may find ways around it.
This case study explores how one team automated security testing across its development pipeline, what they chose to automate, and where human testing was still needed.
As organisations use more containers and microservices, managing security across these environments can become more complex. Teams need to protect applications and services without creating delays in development and deployment.
This case study explores how one organisation improved container and microservices security while maintaining the speed of its deployment pipeline.
AI is creating new security risks, but it is also giving security teams new ways to find and respond to vulnerabilities faster. From automated testing to reviewing and prioritising security issues, AI is becoming a growing part of AppSec.
This panel explores where AI and AI agents are delivering real value, where their limitations remain, and when human expertise is still needed.
Small-group, discussion-based sessions where you'll work through real software security challenges with peers in similar roles. Roundtable topics will be announced soon.
Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.
Cyberattacks are moving faster, making it more important for organisations to detect and respond to application breaches quickly. Even with an incident response plan in place, a real attack can expose gaps that weren't expected.
This case study explores how one organisation responded to an application breach, what didn't work as planned, and how they improved their approach afterwards.
Technology and automation are important, but strong software security also depends on culture. Security works best when developers, security teams, and leaders see it as a shared responsibility.
This closing keynote explores how organisations can build a stronger DevSecOps culture, improve collaboration between teams, and make security part of everyday software development.
Automation is helping security teams test software faster and at greater scale, but not every security risk can be identified automatically. Human expertise and manual testing still have an important role to play.
This interactive think tank will use live audience voting to explore how organisations are balancing automated and manual security testing, where gaps remain, and how AI could change that balance.
Unwind with your peers for a couple of drinks on us!
Beat the rush and join us early for complimentary barista-made coffee and breakfast.
AI-generated code is becoming a bigger part of software development, but it is also creating new security challenges. The risks of AI-generated and vibe coded software are drawing growing scrutiny, raising important questions about how organisations review and secure code created with AI.
This opening keynote explores how AI-generated code is changing application security, where traditional approaches may fall short, and how organisations can manage these risks at scale.
As AI takes on a bigger role in writing, reviewing, and deploying code, traditional software governance needs to evolve. Many existing processes were designed around human developers and may not provide the right oversight for AI-generated work.
This keynote explores how organisations can update their governance, processes, and accountability as AI becomes a bigger part of software development.
Building security into software early can help teams identify and fix issues before they become bigger problems. But many organisations still struggle to make security a natural part of the development process without slowing developers down.
This panel explores how teams can make security part of everyday development, improve collaboration between developers and security teams, and make shift-left security work in practice.
Many organisations rely on open source software but don't always have a clear view of what is inside their applications or where the risks are. As software supply chain security becomes more important, organisations need better visibility over their software and dependencies.
This case study explores how one team introduced a Software Bill of Materials (SBOM) and built a practical approach to managing open source and supply chain risk.
A hands-on, interactive session working through a real software security scenario as a room. Details announced soon.
Security testing needs to keep up with faster software releases. If testing takes too long or creates too many delays, development teams may find ways around it.
This case study explores how one team automated security testing across its development pipeline, what they chose to automate, and where human testing was still needed.
As organisations use more containers and microservices, managing security across these environments can become more complex. Teams need to protect applications and services without creating delays in development and deployment.
This case study explores how one organisation improved container and microservices security while maintaining the speed of its deployment pipeline.
AI is creating new security risks, but it is also giving security teams new ways to find and respond to vulnerabilities faster. From automated testing to reviewing and prioritising security issues, AI is becoming a growing part of AppSec.
This panel explores where AI and AI agents are delivering real value, where their limitations remain, and when human expertise is still needed.
Small-group, discussion-based sessions where you'll work through real software security challenges with peers in similar roles. Roundtable topics will be announced soon.
Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.
Cyberattacks are moving faster, making it more important for organisations to detect and respond to application breaches quickly. Even with an incident response plan in place, a real attack can expose gaps that weren't expected.
This case study explores how one organisation responded to an application breach, what didn't work as planned, and how they improved their approach afterwards.
Technology and automation are important, but strong software security also depends on culture. Security works best when developers, security teams, and leaders see it as a shared responsibility.
This closing keynote explores how organisations can build a stronger DevSecOps culture, improve collaboration between teams, and make security part of everyday software development.
Automation is helping security teams test software faster and at greater scale, but not every security risk can be identified automatically. Human expertise and manual testing still have an important role to play.
This interactive think tank will use live audience voting to explore how organisations are balancing automated and manual security testing, where gaps remain, and how AI could change that balance.
Unwind with your peers for a couple of drinks on us!

Former - Head of Technology

Just bring yourself, your laptop or a notebook and get ready to collaborate!
No. You'll have to be there to enjoy the sessions.
Yes, absolutely! Stay connected at the event with complimentary wifi - we'll share the details at the event.
Yes, morning tea, lunch, and afternoon refreshments will be provided. Please indicate any dietary requirements during registration.
Absolutely! No media, recordings, or live streaming... what happens in the room, stays in the room.
Smart casual or business casual is recommended, no need for a suit and tie! Keep it comfortable.
Nope! The conference is completely free for industry professionals. Contact us if you are not sure whether you qualify.
Be the engineering leader in the room — not the one reading the LinkedIn recap.



