Monday, July 20, 2026

OWASP Global AppSec EU 2026 - Achievement Unlocked

When Mireia Cano and I received the confirmation that our paired talk "Security Champions: Lessons from Opposite Trenches" was accepted at one of the largest OWASP events, the OWASP Global AppSec EU conference, we were speechless. This was too good to be true! We knew the journey there would be very stressful, given the short time left from getting accepted to the conference taking place, and given our lives already had super busy plans for us. And yet, we simply couldn't resist. We fought our way through and overcame every hurdle on the way. We knew why we did it and it was worth it in the end. And Mireia, I'm truly grateful you pulled through together with me! Would we repeat this very stressful experience? Most likely not! But this time, it worked out even better than we hoped for. Here's how the conference went overall.

 


Welcome to Vienna

Vienna was this year's location for the conference which used to move across Europe, and it seems OWASP will stay there for a few years. For me it was a great opportunity to visit the city which isn't that far away from home yet I've never been there.

So I've visited Vienna for the first time, exactly during a period Europe faced an extreme heat wave. The city was burning hot and I was extremely happy that the hotel I chose had working air conditioning and was in walking distance from the conference venue.

Mireia arrived a bit later, and once settled in, we used the time for practicing our talk. I mean, how else could it be. Paired talks are extremely tricky to get right and done well if you don't want to simply patch two half-talks done by two different people in two different styles together and hope for the best. (Nope, that's definitely not how we wanted to do this.) This was our first time to practice in person, and we really needed that opportunity.

Once the duty was done, we enjoyed the rest of the (still very hot) evening over a nice dinner and then called it a day. We knew we would need the energy for what was to come.


First Conference Day

Good thing our talk was scheduled for the second day only, which meant I could fully dive into the experience and check things out on day one. 

That day started with a special breakfast for me. Now, if you know me, I'm neither the breakfast type of person nor am I fully awake at that time of day. This one, however, was too good not to opt in for. It was the "Women in AppSec Breakfast" co-hosted by Tanya Janca, Juliane Reimann, Kim Wyuts, and Marisa Fagan. I mean, how could I miss this chance not only meeting those folks I only knew from social media but also meeting a bunch of other women in my area? I usually love seeing a smaller group of folks first before encountering the whole crowd at a conference, and this one promised to create a safe enough space to make real connections. Turns out, it really did! I met lots of amazing women this morning and we happened to bump into each other again and again during the event. Many thanks to Michelle Mariam Philip, Margot Schepens, Eden Yardeni, Liel and Tina! This pre-conference session truly made me feel welcome from the start and it seems the others were happy about this opportunity just as well.

Here are the sessions I've joined during the rest of the day.

  • Keynote: "The Reinvention of Software Engineering" by Hannah Foxwell. Hannah presented her view on how the software world is changing due to latest AI tooling. She stated that with agentic development, speed of development is outpacing speed of decisions - and yet we really shouldn't just build anything because we can, but something that is worth building. We also need to have the means to ensure safety as things are speeding up. People do and will always matter, so invest in them and broaden their skills.
  • "Why AppSec Fails at Scale (and How to Fix It)" by Eduard Thamm. As Eduard shared, AppSec fails at scale when you keep managing findings instead of designing systems that make secure behavior the easiest path. Preach! Lots of gems in this talk. Like: Security advice that ignores delivery pressure will be routed around - the system rewards shipping fast and often. Haven't we seen that over and over again? Not only with security but all kinds of aspects that make good quality software? Eduard asked everyone to move from findings to mechanisms to make the secure behavior the default. Hear, hear.
  • "Authorization Is Where Your App Goes to Lie" by Eden Yardeni. Eden rightfully pointed out that broken access control issues just keep showing up and stick around among the most common vulnerabilities. Why? Because they're often bound to business logic and hence depend a lot on the underlying intentions of features. It's not straightforward for any application to tell who should be allowed to do what - rather the opposite. Eden's answer to this? Use policy engines so "your product owner's intention compiles into policy as code". Helpful for threat modeling, too!
  • "Retiring CVE Chasing: Defending Against Application Exploit Techniques" by Idan Elor. Idan appealed to the audience that we need to start defending against the underlying techniques instead of just running after getting vulnerabilities fixed (have I already shared how often we're seeing this one?). If we build technique-level controls and detect exploitation attempts, we can cover whole classes at once. Idan presented the application attack matrix to help - a community-driven framework mapping tactics, techniques and procedures against modern applications, which can be used for threat modeling and in architecture reviews.
  • "This Build can Break You - Evil Runners and eBPF for Detection" by Reinhard Kugler. Reinhard shared how different CI/CD runners handle things differently and hence show different attack vectors - yet usually they are highly privileged and a valuable target. How to see what happens in the Kernel space? The answer is eBPF code running in a virtual machine in the Kernel. You can attach functions to a trigger like a syscall, trace event or network call and hence detect malicious activities. As Reinhard said, observability is the first step of defense!
  • Book Signing: Alice and Bob Learn Application Security Tanya Janca. Well, I simply had to seize this opportunity. Tanya had been the most influential person in my security career so far, and by far. I've literally only seen my way into security because of her. Knowing she would be at the conference, I kept looking for an opportunity to talk with her, at least shortly to thank her for her work. At breakfast, this opportunity did not show up and I didn't want to impose. Then, at one of the earlier talks that day, I happened to sit front row (as usual) and prepare my sketchnote for the following talk. I was talking with another person next to me, when someone suddenly turned around to us. It was Tanya! We happened to have a quick chat where I blurted out I was in security because of her making security accessible, and also nervously revealed we'll also have a talk the next day. I was super happy this happened and happened naturally. I still wanted to go to her book signing, now even more (I obviously had her book of course already, yet a physical signed copy is just something truly special). And Tanya remembered me and wished us good luck for the talk. Honestly a true fan-girling moment. Stay tuned, this story continues!
  • "The Devil is in the Defaults - what to do about XSS" by Frederik Braun. Cross-site scripting has been the number one CWE for over 10 years. The measures we have to defend against it still aren't as widely used as they should. Like the Content Security Policy - it's shocking how few websites actually make good use of it. Trusted types are great as they treat all HTML parsing as harmful unless proven otherwise - but they also need to be enabled through a CSP directive (which we know only few even use), and, very unfortunately, they ignore context during HTML parsing. Here comes the HTML sanitizer API to the rescue! It will never allow XSS - guaranteed by the browser and as part of HTML standard. I love that Frederik left with a hope-instilling note: we indeed can fix XSS.

During the day, it was really pleasant to run into some folks I already knew from other conferences! Like Clemens Hübner who Mireia and I met at the Open Security Conference 2025. Or Irfan Qadoos whom I met at both BSides Munich and security meetups. Just loved catching up with both again. The world is small and you never know where you'll meet again.

The official program ended already by 16:15 CEST which I was absolutely not used to from other conferences. Of course, networking events are super crucial and lots of stuff was planned on that end, not only socializing at the venue but also dinners and sightseeing offered by various sponsors. Well, not for Mireia and me this time, because obviously we had to use this last opportunity to practice our talk and make it work for the next day. Lucky us, we could still use the venue for the first dry run so we had a "close to real" practice environment. As things closed down at the venue, we had to move out and do the second run at our accommodation. Once we had a good enough feeling, we called it a day. I took the remaining time of the evening to enjoy a really lovely dinner at a Chinese restaurant offering as authentic as one can get Sichuan food. It was absolutely delicious and just good for the soul after a long stressful period of months. Especially as the very next day, it was on.

 

Second Conference Day

The second day, how else could it be, I was rather late for the first session yet made it just in time. I knew ahead of time I most likely won't be able to join many things next to our own talk, yet in the end I managed to catch a few sessions still. 

  • Keynote: "We Live in the Future: The Death and Rebirth of Application Security" by Gadi Evron. Gadi reminded us that things keep changing and we have to keep changing with them. For example, we cannot trust security configurations anymore when agents can just change them. The perimeter shifted to the endpoint agent, yet security controls don't cover them yet. Gadi raised a big question: English is the new programming language - yet how do we secure English?
  • Book Signing: Threats: What Every Engineer Should Learn From Star Wars with Adam Shostack. Yes, I just had to go to this book signing as well. Of course I had Adam's book as well already. But remember, a signed physical copy is a special thing! Also, you never know what will happen. I just loved that Adam noticed my Star Trek shirt and complimented me on it. Well, that's one of the many reasons I love wearing such shirts. They are a great way to find your kin and have lovely conversations. Just like with Adam this time. Thanks a bunch for that!
  • "Keep It Between Us: Manipulating Humans for Better AppSec (Ethically)" by Nariman Aga-Tagiyev. Nariman focused this talk on human motivation - what makes us do things? What are we actually driven by, how much does this reason come from the outside, and how sustainable is it? He reminded us that with some reinforcement, behavior will become a habit, and we can make use of this in our AppSec programs. Make it obvious, make it attractive, make it easy, make it satisfying. Or: Invert all of the above. The invisible side of AppSec and the secret plan is to convert activities into habits. We can start with writing down what the current good and bad habits are around a problematic behavior we observe.
  • "Security Champions: Lessons from Opposite Trenches" by Mireia Cano and me. It was time. We went on stage. The show was on. Have I said paired talks are a special kind of a challenge? This time, we attempted role plays on stage to convey our messages and have a red thread throughout the talk. Well, it was risky - these role plays could have come across as very cringe and over the top. You can't imagine how happy we were when we received lots of amazing feedback afterwards exactly on those theatrical role plays! Seems we hit just the right note and they indeed helped make the topics tangible and relatable with folks. We pulled through, it was our best version of the talk, and you don't know how happy I am that this was recorded! The relief was real afterwards. We really did it! Time to celebrate. That being said, what did we talk about? Well, Mireia came from the security side, having gathered plenty of experience with designing and running security champions programs with everything that could go wrong and what helps to make them go well and evolve. And I lived that champions experience myself for three years before going fully into security, now running a security champions program myself! We've found four key aspects that truly made the difference for such programs. The slides are already out, yet to get the full experience, you'll have to wait a couple of months until the recording is released.
  • "Using CTFs as a Community of Practice Content Machine" by Marco Macala, Florian Schier, and Christian Buchinger. In this talk, they described the security community they built, what worked and what didn't. Very fitting talk to come just after ours! Marco, Florian and Christian advised to keep the monthly sessions light, comedic and consistent. To make them engaging for different backgrounds. To have open discussions, give people free rein for content. And, what I especially love: there should be no grandstanding from security. So much this, seen this way too often as well! All this made them discover CTFs as a perfect opportunity to increase awareness and skills. They encouraged folks to keep them very basic and limiting the effort to set them up. Especially: education over competition, approachable for everyone! That really resonated with me and my current approaches to CTFs, especially when giving such sessions during open space conferences.
  • "Insecurity as Code: How Modern Software Scaled the Attack Surface" by Igor Stepansky. Igor explained how applications aren't the only attack surface anymore - it's everything around them as well, while everyone is already drowning in findings. Due to AI tooling, alerts are exploding - yet are they even valid? Igor reminded us: You're not behind, you're buried! It's about reliably finding the 1% truly critical. To triage on reachability and business impact and then patch those fast, focusing on what matters. And instead of fixing more findings, we should remove the attacker's leverage. This!

During the day, even though the excitement of the upcoming talk was there, I once again had opportunity to meet folks. Like Frederik Braun whom I was connected with via social media yet we never had a chance to talk before. Or Lars Hermerschmidt whom I heard about through a friend working at the same company. Or Ali Kabiri who was immensely kind helping me out with my (super cool) OWASP badge by getting me an extension for it. Also meeting folks I met before, like Michael Helwig. Really enjoyed all those conversations.

The conference approached its closing, and with that came a very special moment for me. Remember that Tanya Jana wished me good luck for our talk? Well. It happened to turn out that she was attending the same last talk as I was. As I was finishing up my sketchnote, she was coming to the front, chatting with the speaker. While I collected all my stuff, she saw me and asked how our talk went. We started to talk and, as it happens, went to the conference closing together. She was going to sit front row - as I usually do the same, I had no problem joining her. Sitting next to her, chatting, and really enjoying our conversation. This way, I also found out that the conference provided slim-fit conference t-shirts for the first time this year - and I have to thank Tanya for relentlessly trying to make the offering more diverse (no, unisex is not the solution here).

The closing was done. The room emptied. I looked around, and found Clemens with a few folks and joined them. I met Mariia Denysenko this way, realizing we're from the same location - a lovely encounter! It was also a pleasure to meet Michael Koppmann who enabled this whole conference by leading the team of volunteers and relentlessly working behind the scenes.

Then it was time to say goodbye and close this chapter. I had a nice dinner in the area. Calmed down a bit. Prepared for the next day - I was adamant to go sightseeing despite the heat. I thoroughly enjoyed doing exactly that after sleeping in the next day (I love art and art galleries are a great air-conditioned place by nature). The day afterwards, it was time to go home.

My first proper OWASP event was as big as they get. It was a good one in itself. It was a really great one because of the people. And it was definitely a huge achievement unlocked moment for Mireia and me!

Thursday, July 16, 2026

SoCraTes UK 2026 - Instant Connection

My heart is full of gratitude for finding such instant and easy connection. That's probably the best summary I can provide after my very first SoCraTes UK. I would have loved to be able to write this post right after the conference while memories and emotions were fresh, yet life happened and right now is the next best time for it. So let's start at the beginning.


Arrival

As for most conferences, it takes me a while to get to their location so I plan with a travel day back and forth. It reduces most travel worries due to hiccups, makes everything so much more relaxed, and also gives a chance to connect with the first set of people before the event starts. Also in this case, arriving the day before was well worth it. The lovely venue is located in the countryside, surrounded by nature. I had some time to settle in and just breathe. So far so good.

But then there was the heat. Well, that full-blown heat wave was not sparing the region and it presented a challenge throughout the conference. Especially given my hotel room was right under the roof, only had limited capacity to open windows and offered no air conditioning - not even any air circulation in the bathroom. Let's say it was tough, but I survived. 

Having settled in and rested for a bit, it was time for meeting people and then having dinner together. It was great to see people like Amélie CornélisEmily Bache, Simon Görtzen, Alexander Alemayhu, Michel Grootjans, or Raimo Radczewski again. At the same time I loved connecting with folks I haven't met before, like Clare SudberyJames BelClaudia Görtzen or Chris Jenkins.


Training Day

SoCraTes UK offered a bunch of trainings this year before the official start of the conference. I really appreciate these short pre-scheduled workshops that bring people together on practicing things hands-on and also provide some topics already to take further into the following open space.

  • TDD Game with Cyber-Dojo by Jon Jagger. If you haven't come across Cyber-Dojo yet, it's a great practice playground for coding katas across all kinds of programming languages. And Jon is its creator! In this session, we split into groups and tried to predict every outcome of our changes, working on a kata. And not only that, we played against an LLM model who tried to predict as well - so our goal was to trick it into false assumptions. Well. The sad news: Nearly no group succeeded. A rather sobering insight. I guess this might change once the domain would become more unique and specialized, yet who knows.
  • Secure Development Lifecycle Applied - How to Make Things a Bit More Secure than Yesterday Every Day by me. I've given this workshop plenty of times already and every time it's fun for me to notice how the groups engage with the material, what kinds of ideas they surface, which ones they try first. As usual, I hope it's also fun for the participants to practice together hands-on on tangible things they can do to make software more secure. I really appreciated the folks that joined, many of them gave detailed feedback - invaluable! - and people seemed to find value in it to take with them.
  • Using TDD to Get Better Results From LLMs/AI by Clare Sudbery. We worked together in pairs to build an app using only an agent, based on a set of requirements provided by Clare. Half of the groups had to use TDD, the other half was obliged not to even mention any kind of testing to the LLM. Curiously, the key insight for me from this workshop was not related to the question "TDD or not TDD" at all. It was that no matter how we implement things, we still need to work with humans first to gain insights on the domain and problem space to gain understanding on what they actually want to have us build. Classic lesson, learned once again.
  • Value Stream Mapping by Tim Ottinger. This was a really cool workshop for me. I've learned about the approach and key concepts from various sources for years and spread it further in one way or the other. This workshop felt super validating that what I've been sharing with my teams and outside was indeed going in the right direction. We all put on paper what the value of our product for a customer is, what they desire and require. Then we mapped out all the steps that need to happen to deliver this value. We annotated that stream to identify value-adding and non-value-adding work, including pure waste. We documented cycle times for each step, as well as waiting times in between the steps. Because one of the main points here is that speeding up a non-bottleneck process produces deeper queues and longer waits - you make the bottleneck worse. We analyzed several example situations and what we could do to make things flow. Well, as a longstanding advocate for pairing and ensembling, the answer how to increase flow was right there for me.

The training day was over, and the main conference started in the evening. It was a true pleasure to have Romeu Moura as a facilitator for the open space. He did a splendid job to get people to not only break ice, but also deeply engage with the values of the conference, really think about what everyone of us, starting with ourselves, can contribute to make this a safe space. This kind of foundation really showed the next days and I believe we took it with us even after the conference had ended.

Dinner time! Had lovely conversations with the folks at our table. Topics didn't stay shallow either, with the round addressing big societal problems as well as generational change. Afterwards, I was already pretty tired and close to call it a day, yet I wanted to check out what people were up to. The board game round intrigued me so much in the end that I stayed for way longer than originally planned. I just love games and the one people tried had a really cool concept, was not easy at all and truly required collaboration of players. You know, those lessons for life games. 


Open Space Day 1

I'm a night owl, so open space marketplaces generally start too early for me. Yet I better be there if I'd like to hear folks pitch their sessions and be ready to host one myself (and of course I do). Here's my pick of sessions for this first open space day.

  • "How can the way we work support democracy?" by Claudia Görtzen. I loved that she raised this topic already the evening before and was super happy she proposed it as a session. Because we all have our share in how we deal with things at work. Should we speak up about issues or not. Do we support unethical companies or not. Do we report misbehavior or not. Do we build this shady feature or dark pattern or not. All these big and small day to day decisions. In this session, we had a really insightful conversation and valuable exchange on tangible things we can do. The ones that stuck with me most? Join a union. Don't go alone - conspire. Learn from the book "Blueprint for Revolution". And the one I keep thinking about: start practicing anarchist calisthenics
  • "Your IDE / test suite / security scanner / design system / language server will steal your SSH key, unless ..." by Raimo Radczewski. When a security topic is proposed, I just have to attend! We all started with sharing stories about latest supply chain attacks - well, there were plenty of those happening the last years. Then we gathered ideas on what we can do to for better protection. Lots of good advice and tooling was collected. Like Little Snitch to monitor network calls on MacOS, that I already had on my list as it's been heavily recommended in the security community. As usual, there was also stuff I wasn't aware of yet that I'll definitely look into further, like nono.sh to sandbox any terminal agent, or Deno, where code executing in this Node-compatible JavaScript runtime has no access to read or write arbitrary files on the file system by default (among many more security features).
  • "Capture the flag together (beginner's edition)" by me. What can I say: I just love proposing this session at various open space conferences. So once more, I tried this out - a bunch of people joined and were captivated with capturing that flag. This highly collaborative and highly educational session just keeps giving and comes with pleasant surprises! I thoroughly enjoy doing these. It seems people did appreciate it as well: folks were staying longer, wanting more, and giving plenty of positive feedback afterwards. The one that made me the happiest is their emphasis on how accessible security and penetration testing became to them thanks to these sessions. What more could I want?
  • "How do we defend democracy and fight fascism" by Sarah Peper. I really wanted to continue this theme and engage more with this super crucial topic. Yet as my session before overran, I came to this one rather late. I was pretty tired at that moment in time so I can't really remember much from the conversation. At some point I had to walk out and cater to my needs. But that's also the beauty of open spaces - you're explicitly free, welcome and even encouraged to leave a session when you're neither contributing nor learning or just need something different at that moment in time.
  • "How the way we talk can change the way we work" by Ellen Potter. Ellen hosted an interesting session based on the book "How The Way We Talk Can Change the Way We Work" and the exercises in it. She also posted about it including a description if you want to give it a go yourself. We all started taking note of complaints we have. Then we reflected on what's important to us, basically what makes us complain in the first place. We thought about our own role in this to keep this being a problem, as well as competing commitments that contribute to us being stuck. Finally, we took a deep introspection into which assumptions we base this all on and what experiments we can run to find out what's actually the case. This was such a thought-provoking session! Lots to unravel and try out.

The day was closed, the evening marketplace was opened. I couldn't resist and, after a lovely relaxed dinner, I offered the follow-up to my previous session: "Capture the flag together (adventurer's edition)". Once again, lots of people joined in! And as it usually happens... the evening got longer and longer. We had fun feeling all the rollercoaster emotions of going through frustration and hope and trying ideas and failing and sometimes succeeding by finding a new insight and circling back and wondering what we missed and... You get the picture. In the end, we spent four wonderful hours and managed to capture the flag together. 

 

Open Space Day 2

The longer the conference, the more tired I grow. Which is nothing new. The good thing about open space conferences is that I don't have to feel bad about not going to sessions. Okay, I usually do feel bad at first. Then I realize it's the perfect thing to do right now to not stress myself, follow my needs, and recharge batteries so I can fully enjoy the rest of the day. So I chose a very slow morning without sessions. There were also quite a few personal tasks to do, given this was a period when a lot was going on in my life on top of many travels in a row. So I took the liberty to just miss sessions, although there were really good ones on offer. Instead, I could lift a burden from my shoulders and that was a true relief. In hindsight, giving myself grace that morning was absolutely the best thing I could have done.

Then came lunch time and afterwards I wanted to join sessions again. But things happened differently. A new session was born over lunch, as it happens. So I stayed at my table and our group continued talking about all the things: personal differences, neurodiversity, weird and even surreal situations, academics, health conditions, and so much more. It was just lovely. 

Way sooner than not it was time for the session I pitched myself that day, so I better had to be there! I had called it "Interactions with security folks - gone well and gone badly" and it aimed for an experience exchange. Once again, lots of folks turned up! I started with preparing a flip chart. I set the room so more people than just dominant voices would share. Then I asked for people's experiences and insights - and lots of stories were brought to the table. At some point I asked more specific questions that elicited further insights. The outcome? The "Nay" side of my flip chart filled up rather quickly - something I observe and hear way too often, all the bad experiences people make with security folks. The "Yay" side lagged behind for a long time. Good news: in the end, it was showing a lot more points. There's hope! This session provided lots of food for thought. Not only for my contribution at work, but also for what I want to share in my next talk that I'll soon start to craft.

For the last session slot during the day I picked the "TDD Game" by Ted M. Young. He brought the board game he designed and I was eager to give it a try. Even though we were on a tough time constraint, this game was truly a great experience! The game play and different tactics triggered insightful conversations and at the same time validated what our group knew already based on their own experiences. It would have been really interesting to do this together with people who are not aware of TDD, value stream mapping and flow, collaboration techniques, and all the good practices. Also, the game was super accessible, I felt very safe with my own knowledge and skills - and yet it forced decision making and practicing it. Another interesting thing was that Ted included the concept of exchanging a card as "thinking time", and also that you always have to hold back two (yes, two!) playing cards, otherwise you run out of energy. Really neat. If you have a chance to try this game out yourself, I can only recommend you to give it a go.

A lovely dinner followed, and, how else could it be, I offered once again an evening capture the flag session. I really enjoy them way too much not to. This time, something really cool happened. First, Michel Grootjans went all in and started a whole setup for himself and we could already use it for our session. Second, the group decided to experiment with different ways to collaborate and become more effective together in capturing the flag. Third, it didn't end that night at SoCraTesUK (spending up to six hours and absolutely capturing flags)! The next day at breakfast (that I obviously skipped), people kept talking about these sessions and expressed their eagerness to continue beyond the conference as a SoCraTesUK CTF round. Ellen Potter kindly offered to drive this, and can you imagine, the first session already took place and the second is scheduled! I'm a bit sad I couldn't join any of these (yet), and I'm overjoyed this just happens without me. Just beautiful.


Departure

It was time to leave. My heart was full, the newly found connections were strong. I absolutely appreciate the organizers to craft this space so intentionally. It seemed to be a smaller event this year compared to the previous ones, yet it did not matter at all. I absolutely recommend checking this one out. I'm certain I'm not the only one who got a lot out of it this year.

As a bonus, I opted for a longer stay at the airport so I could meet my dear community friend Tabitha Ncooro for the first time in person. We got to know each other a few years ago during the time I seeked connections into the security community and found her trying the same. Ever since we check in with each other regularly and I've found her to be one of the kindest and wisest people I've ever met in life. It was a true pleasure to meet her in person just after such a wonderful event.

I'm back home. It's been a few weeks since SoCraTes UK. And yet: I still think about this event, how people made me feel, and all the inspiration taken with me from it. This conference brought instant connection and keeps resonating.