When Mireia Cano and I received the confirmation that our paired talk "Security Champions: Lessons from Opposite Trenches" was accepted at one of the largest OWASP events, the OWASP Global AppSec EU conference, we were speechless. This was too good to be true! We knew the journey there would be very stressful, given the short time left from getting accepted to the conference taking place, and given our lives already had super busy plans for us. And yet, we simply couldn't resist. We fought our way through and overcame every hurdle on the way. We knew why we did it and it was worth it in the end. And Mireia, I'm truly grateful you pulled through together with me! Would we repeat this very stressful experience? Most likely not! But this time, it worked out even better than we hoped for. Here's how the conference went overall.
Welcome to Vienna
Vienna was this year's location for the conference which used to move across Europe, and it seems OWASP will stay there for a few years. For me it was a great opportunity to visit the city which isn't that far away from home yet I've never been there.
So I've visited Vienna for the first time, exactly during a period Europe faced an extreme heat wave. The city was burning hot and I was extremely happy that the hotel I chose had working air conditioning and was in walking distance from the conference venue.
Mireia arrived a bit later, and once settled in, we used the time for practicing our talk. I mean, how else could it be. Paired talks are extremely tricky to get right and done well if you don't want to simply patch two half-talks done by two different people in two different styles together and hope for the best. (Nope, that's definitely not how we wanted to do this.) This was our first time to practice in person, and we really needed that opportunity.
Once the duty was done, we enjoyed the rest of the (still very hot) evening over a nice dinner and then called it a day. We knew we would need the energy for what was to come.
First Conference Day
Good thing our talk was scheduled for the second day only, which meant I could fully dive into the experience and check things out on day one.
That day started with a special breakfast for me. Now, if you know me, I'm neither the breakfast type of person nor am I fully awake at that time of day. This one, however, was too good not to opt in for. It was the "Women in AppSec Breakfast" co-hosted by Tanya Janca, Juliane Reimann, Kim Wyuts, and Marisa Fagan. I mean, how could I miss this chance not only meeting those folks I only knew from social media but also meeting a bunch of other women in my area? I usually love seeing a smaller group of folks first before encountering the whole crowd at a conference, and this one promised to create a safe enough space to make real connections. Turns out, it really did! I met lots of amazing women this morning and we happened to bump into each other again and again during the event. Many thanks to Michelle Mariam Philip, Margot Schepens, Eden Yardeni, Liel and Tina! This pre-conference session truly made me feel welcome from the start and it seems the others were happy about this opportunity just as well.
Here are the sessions I've joined during the rest of the day.
-
Keynote: "The Reinvention of Software Engineering" by
Hannah Foxwell. Hannah presented her view on how the software world is changing due to latest AI tooling. She stated that with agentic development, speed of development is outpacing speed of decisions - and yet we really shouldn't just build anything because we can, but something that is worth building. We also need to have the means to ensure safety as things are speeding up. People do and will always matter, so invest in them and broaden their skills.
-
"Why AppSec Fails at Scale (and How to Fix It)" by
Eduard Thamm. As Eduard shared, AppSec fails at scale when you keep managing findings instead of designing systems that make secure behavior the easiest path. Preach! Lots of gems in this talk. Like: Security advice that ignores delivery pressure will be routed around - the system rewards shipping fast and often. Haven't we seen that over and over again? Not only with security but all kinds of aspects that make good quality software? Eduard asked everyone to move from findings to mechanisms to make the secure behavior the default. Hear, hear.
-
"Authorization Is Where Your App Goes to Lie" by Eden Yardeni. Eden rightfully pointed out that broken access control issues just keep showing up and stick around among the most common vulnerabilities. Why? Because they're often bound to business logic and hence depend a lot on the underlying intentions of features. It's not straightforward for any application to tell who should be allowed to do what - rather the opposite. Eden's answer to this? Use policy engines so "your product owner's intention compiles into policy as code". Helpful for threat modeling, too!
-
"Retiring CVE Chasing: Defending Against Application Exploit Techniques" by
Idan Elor. Idan appealed to the audience that we need to start defending against the underlying techniques instead of just running after getting vulnerabilities fixed (have I already shared how often we're seeing this one?). If we build technique-level controls and detect exploitation attempts, we can cover whole classes at once. Idan presented the application attack matrix to help - a community-driven framework mapping tactics, techniques and procedures against modern applications, which can be used for threat modeling and in architecture reviews.
-
"This Build can Break You - Evil Runners and eBPF for Detection" by Reinhard Kugler. Reinhard shared how different CI/CD runners handle things differently and hence show different attack vectors - yet usually they are highly privileged and a valuable target. How to see what happens in the Kernel space? The answer is eBPF code running in a virtual machine in the Kernel. You can attach functions to a trigger like a syscall, trace event or network call and hence detect malicious activities. As Reinhard said, observability is the first step of defense!
- Book Signing: Alice and Bob Learn Application Security Tanya Janca. Well, I simply had to seize this opportunity. Tanya had been the most influential person in my security career so far, and by far. I've literally only seen my way into security because of her. Knowing she would be at the conference, I kept looking for an opportunity to talk with her, at least shortly to thank her for her work. At breakfast, this opportunity did not show up and I didn't want to impose. Then, at one of the earlier talks that day, I happened to sit front row (as usual) and prepare my sketchnote for the following talk. I was talking with another person next to me, when someone suddenly turned around to us. It was Tanya! We happened to have a quick chat where I blurted out I was in security because of her making security accessible, and also nervously revealed we'll also have a talk the next day. I was super happy this happened and happened naturally. I still wanted to go to her book signing, now even more (I obviously had her book of course already, yet a physical signed copy is just something truly special). And Tanya remembered me and wished us good luck for the talk. Honestly a true fan-girling moment. Stay tuned, this story continues!
-
"The Devil is in the Defaults - what to do about XSS" by
Frederik Braun. Cross-site scripting has been the number one CWE for over 10 years. The measures we have to defend against it still aren't as widely used as they should. Like the Content Security Policy - it's shocking how few websites actually make good use of it. Trusted types are great as they treat all HTML parsing as harmful unless proven otherwise - but they also need to be enabled through a CSP directive (which we know only few even use), and, very unfortunately, they ignore context during HTML parsing. Here comes the HTML sanitizer API to the rescue! It will never allow XSS - guaranteed by the browser and as part of HTML standard. I love that Frederik left with a hope-instilling note: we indeed can fix XSS.
During the day, it was really pleasant to run into some folks I already knew from other conferences! Like Clemens Hübner who Mireia and I met at the Open Security Conference 2025. Or Irfan Qadoos whom I met at both BSides Munich and security meetups. Just loved catching up with both again. The world is small and you never know where you'll meet again.
The official program ended already by 16:15 CEST which I was absolutely not used to from other conferences. Of course, networking events are super crucial and lots of stuff was planned on that end, not only socializing at the venue but also dinners and sightseeing offered by various sponsors. Well, not for Mireia and me this time, because obviously we had to use this last opportunity to practice our talk and make it work for the next day. Lucky us, we could still use the venue for the first dry run so we had a "close to real" practice environment. As things closed down at the venue, we had to move out and do the second run at our accommodation. Once we had a good enough feeling, we called it a day. I took the remaining time of the evening to enjoy a really lovely dinner at a Chinese restaurant offering as authentic as one can get Sichuan food. It was absolutely delicious and just good for the soul after a long stressful period of months. Especially as the very next day, it was on.
Second Conference Day
The second day, how else could it be, I was rather late for the first session yet made it just in time. I knew ahead of time I most likely won't be able to join many things next to our own talk, yet in the end I managed to catch a few sessions still.
-
Keynote: "We Live in the Future: The Death and Rebirth of Application Security" by
Gadi Evron. Gadi reminded us that things keep changing and we have to keep changing with them. For example, we cannot trust security configurations anymore when agents can just change them. The perimeter shifted to the endpoint agent, yet security controls don't cover them yet. Gadi raised a big question: English is the new programming language - yet how do we secure English?
- Book Signing: Threats: What Every Engineer Should Learn From Star Wars with Adam Shostack. Yes, I just had to go to this book signing as well. Of course I had Adam's book as well already. But remember, a signed physical copy is a special thing! Also, you never know what will happen. I just loved that Adam noticed my Star Trek shirt and complimented me on it. Well, that's one of the many reasons I love wearing such shirts. They are a great way to find your kin and have lovely conversations. Just like with Adam this time. Thanks a bunch for that!
-
"Keep It Between Us: Manipulating Humans for Better AppSec (Ethically)" by
Nariman Aga-Tagiyev. Nariman focused this talk on human motivation - what makes us do things? What are we actually driven by, how much does this reason come from the outside, and how sustainable is it? He reminded us that with some reinforcement, behavior will become a habit, and we can make use of this in our AppSec programs. Make it obvious, make it attractive, make it easy, make it satisfying. Or: Invert all of the above. The invisible side of AppSec and the secret plan is to convert activities into habits. We can start with writing down what the current good and bad habits are around a problematic behavior we observe.
-
"Security Champions: Lessons from Opposite Trenches" by Mireia Cano and me. It was time. We went on stage. The show was on. Have I said paired talks are a special kind of a challenge? This time, we attempted role plays on stage to convey our messages and have a red thread throughout the talk. Well, it was risky - these role plays could have come across as very cringe and over the top. You can't imagine how happy we were when we received lots of amazing feedback afterwards exactly on those theatrical role plays! Seems we hit just the right note and they indeed helped make the topics tangible and relatable with folks. We pulled through, it was our best version of the talk, and you don't know how happy I am that this was recorded! The relief was real afterwards. We really did it! Time to celebrate. That being said, what did we talk about? Well, Mireia came from the security side, having gathered plenty of experience with designing and running security champions programs with everything that could go wrong and what helps to make them go well and evolve. And I lived that champions experience myself for three years before going fully into security, now running a security champions program myself! We've found four key aspects that truly made the difference for such programs. The slides are already out, yet to get the full experience, you'll have to wait a couple of months until the recording is released.
-
"Using CTFs as a Community of Practice Content Machine" by
Marco Macala,
Florian Schier, and
Christian Buchinger. In this talk, they described the security community they built, what worked and what didn't. Very fitting talk to come just after ours! Marco, Florian and Christian advised to keep the monthly sessions light, comedic and consistent. To make them engaging for different backgrounds. To have open discussions, give people free rein for content. And, what I especially love: there should be no grandstanding from security. So much this, seen this way too often as well! All this made them discover CTFs as a perfect opportunity to increase awareness and skills. They encouraged folks to keep them very basic and limiting the effort to set them up. Especially: education over competition, approachable for everyone! That really resonated with me and my current approaches to CTFs, especially when giving such sessions during open space conferences.
-
"Insecurity as Code: How Modern Software Scaled the Attack Surface" by Igor Stepansky. Igor explained how applications aren't the only attack surface anymore - it's everything around them as well, while everyone is already drowning in findings. Due to AI tooling, alerts are exploding - yet are they even valid? Igor reminded us: You're not behind, you're buried! It's about reliably finding the 1% truly critical. To triage on reachability and business impact and then patch those fast, focusing on what matters. And instead of fixing more findings, we should remove the attacker's leverage. This!
During the day, even though the excitement of the upcoming talk was there, I once again had opportunity to meet folks. Like Frederik Braun whom I was connected with via social media yet we never had a chance to talk before. Or Lars Hermerschmidt whom I heard about through a friend working at the same company. Or Ali Kabiri who was immensely kind helping me out with my (super cool) OWASP badge by getting me an extension for it. Also meeting folks I met before, like Michael Helwig. Really enjoyed all those conversations.
The conference approached its closing, and with that came a very special moment for me. Remember that Tanya Jana wished me good luck for our talk? Well. It happened to turn out that she was attending the same last talk as I was. As I was finishing up my sketchnote, she was coming to the front, chatting with the speaker. While I collected all my stuff, she saw me and asked how our talk went. We started to talk and, as it happens, went to the conference closing together. She was going to sit front row - as I usually do the same, I had no problem joining her. Sitting next to her, chatting, and really enjoying our conversation. This way, I also found out that the conference provided slim-fit conference t-shirts for the first time this year - and I have to thank Tanya for relentlessly trying to make the offering more diverse (no, unisex is not the solution here).
The closing was done. The room emptied. I looked around, and found Clemens with a few folks and joined them. I met Mariia Denysenko this way, realizing we're from the same location - a lovely encounter! It was also a pleasure to meet Michael Koppmann who enabled this whole conference by leading the team of volunteers and relentlessly working behind the scenes.
Then it was time to say goodbye and close this chapter. I had a nice dinner in the area. Calmed down a bit. Prepared for the next day - I was adamant to go sightseeing despite the heat. I thoroughly enjoyed doing exactly that after sleeping in the next day (I love art and art galleries are a great air-conditioned place by nature). The day afterwards, it was time to go home.
My first proper OWASP event was as big as they get. It was a good one in itself. It was a really great one because of the people. And it was definitely a huge achievement unlocked moment for Mireia and me!
No comments:
Post a Comment