Break things, but not security: CI/CD done right

Gijs Van Laer
Gijs Van Laer
CTO, XFA
Abstract

This session explores how to build fast, secure CI/CD pipelines without compromising on velocity. We dive into the dangers of over-automation, like supply chain attacks and secret leaks, and show how embedding security early mitigates these risks. Supported by real-world attack examples, we learn which tools are must-haves and which can wait. We will also examine the economics of security tooling: comparing built-in, open-source, and vendor solutions, so you can make smart, secure choices at scale.