Loading…
or to bookmark your favorites and sync them to your phone or calendar.
strong>CloudX [clear filter]
arrow_back View All Dates
Thursday, November 14
 

9:30am PST

[Virtual] OPEN SESSION (CloudX): Surging Supply Chain Attacks: Risks and Defenses
Thursday November 14, 2024 9:30am - 9:55am PST
Richard Clark, JFrog, Senior Solutions Architect

As supply chain attacks continue to evolve and proliferate, there is a critical need for organizations to fortify their defenses. Especially with the ever growing usage of open source technology in today’s software landscape, open source vulnerabilities have become a prime target for attackers seeking widespread impact. In this session, Richard Clark, Senior Solutions Architect at JFrog will emphasize the importance of proactive measures, including educating developers to use reputable tools, and adopting software composition analysis to safeguard against the growing menace of supply chain vulnerabilities.

In this session, Richard will also discuss:
How software bills of materials or SBOM standards, such as CycloneDX and SPDX, enhance visibility into software dependencies;
The rapid adoption of faster release cycles in business operations and how it heightens vulnerabilities in supply chain management;
The importance of collaboration between security teams and developers.
Speakers
avatar for Richard Clark

Richard Clark

Senior Solutions Architect, JFrog
Richard is a Senior Solutions Architect with JFrog. He is also an entrepreneur/inventor, having previously run a startup in the Internet of Things space, where he holds technology patents and has been a key member of several M&A startups. In his spare time, he enjoys cooking and traveling... Read More →
Thursday November 14, 2024 9:30am - 9:55am PST
VIRTUAL CloudX -- Main Stage

10:00am PST

[Virtual] Sponsor Spotlight: mogenius (Live Demo)
Thursday November 14, 2024 10:00am - 10:15am PST
Overwhelmed by Kubernetes support requests?

Empower your developers to self-serve on Kubernetes and take control.

Accelerate project delivery, reduce errors, and cut costs by enabling developers to manage Kubernetes deployments independently.

In our live demo, discover how mogenius can help your team tackle cloud-native challenges and ensure consistent delivery with customized workflows for independent lifecycle management – all while maintaining compliance and reducing DevOps reliance.

Our team is happy to answer your questions.
Sponsors
Thursday November 14, 2024 10:00am - 10:15am PST
Virtual Expo Hall
  OPEN SESSIONS, CloudX

10:00am PST

[Virtual] OPEN SESSION (API): Unlocking Live Data Access for AI
Thursday November 14, 2024 10:00am - 10:25am PST
Anushrut Gupta, Hasura, Senior Product Manager, Generative AI

“Over the last 3 months, summarize the top billing issues faced by my enterprise customers within the first 30 days of their onboarding.”

On the surface, building an internal AI customer intelligence application that can answer questions like this is a perfect use-case for Gen AI.
However, building a production ready app that retrieves the data (RAG) before hauling it off to your favorite LLM for summarization soon becomes a terrible engineering experience.

The data is spread across 3 places: a tickets database (eg: elastic), a CRM (eg: salesforce) and your user-accounts transactional database (eg: postgres).
In production, your app can’t access the data from these databases directly. Given security & privacy concerns, your app won’t have direct access to these databases.
Making independent retrieval requests to each of these sources and then joining them in memory might be prohibitively expensive and needs a level of query planning to do efficiently.
Moving all data into one location is expensive to build, maintain and govern
Predictable quality is further made hard because underlying data formats and storage interfaces are continuously changing.
Different types of user queries might require additional filtering and joining of data, which becomes hard to generalize.

APIs solve almost all of these very well known challenges. APIs offer standardization and security. APIs can provide a stable contract to interact with underlying data.

And in all likelihood, you already have APIs on these internal and external data sources.

Ironically, while APIs have become a necessity for other parts of the stack, they are clearly not the first thing that AI engineers building RAG reach for.

In this talk, we’ll discuss:
Why API based retrieval doesn’t work well for RAG
What we need from our existing internal and external APIs to make them RAG ready
How we can get existing APIs to become RAG ready without needing to rebuild the APIs

This talk will be technical, with code demos (possibly with some live coding!) and end with key resources (reference architectures, API best practices, tools/technologies) that attendees can take back to their work.
Speakers
avatar for Anushrut Gupta

Anushrut Gupta

Senior Product Manager, Generative AI, Hasura
Thursday November 14, 2024 10:00am - 10:25am PST
VIRTUAL API World -- OPEN Workshop Stage

10:30am PST

[Virtual] PRO SESSION (CloudX): Type-Safe, Polyglot Messaging and Eventing: Stream/Queue/Topic “Of T”
Thursday November 14, 2024 10:30am - 10:55am PST
Clemens Vasters, Microsoft, Chief Messenger
Speakers
avatar for Clemens Vasters

Clemens Vasters

Chief Messenger, Microsoft
Clemens Vasters is Lead Architect in Microsoft’s Azure Messaging team that builds and operates a fleet of hyper-scale messaging services, including Event Grid, Service Bus, and Event Hubs. Clemens represents Microsoft in messaging standardisation in OASIS (AMQP) and CNCF (CloudEvents... Read More →
Thursday November 14, 2024 10:30am - 10:55am PST
VIRTUAL CloudX -- Stage 1

10:30am PST

[Virtual] OPEN SESSION (CloudX):: Managing Data Security in Multi-Cloud Environments
Thursday November 14, 2024 10:30am - 10:55am PST
Kevin Hunt, Cloud Storage Security, CTO

Ransomware attacks, breaches, data exfiltration, and insider disclosures are occurring every day around the world. Legacy thinking on providing data security has been focused on the application and platform or operating system. This leads to a somewhat chaotic data security landscape that is likely to have holes and missed handoffs. Modern enterprise systems use and store data using the most effective platform that delivers the convenience and performance required. This open-ended approach to data handling should be addressed through an equally open and flexible approach to securing data regardless of where it is stored or how and when it is used.
Businesses should take a holistic view of their data security to ensure that unintended gaps and inconsistencies that may open the door for threat propagation are detected and mitigated. Enacting multiple layers of data management practices ensures that both stored and inflight data is clean.
This keynote will draw on the Data Security Maturity Model (DSMM) to illustrate the challenges developers and users face in the open landscape of current application deployments. Placing a strong focus on a layered framework that provides consistent and robust security for data as it is used, this approach incorporates seamless malware scanning and detection that provides a constant watch for irregularities and threats.
Speakers
avatar for Kevin Hunt

Kevin Hunt

Chief Technology Officer, Cloud Storage Security (CSS)
As chief technology officer for CSS, Kevin leads the company’s product development, engineering, and customer experience groups in delivering unparalleled cloud storage security solutions that address current and future customer storage security needs. Kevin brings CSS a wealth... Read More →
Thursday November 14, 2024 10:30am - 10:55am PST
VIRTUAL API World -- Main Stage

11:00am PST

[Virtual] Sponsor Spotlight: mogenius (Live Demo, Live Q&A (post speaking session))
Thursday November 14, 2024 11:00am - 11:15am PST
Overwhelmed by Kubernetes support requests? Empower your developers to self-serve on Kubernetes and take control.

Accelerate project delivery, reduce errors, and cut costs by enabling developers to manage Kubernetes deployments independently.

In our live demo, discover how mogenius can help your team tackle cloud-native challenges and ensure consistent delivery with customized workflows for independent lifecycle management, all while maintaining compliance and reducing DevOps reliance.

Our team is ready to answer your questions.
Sponsors
Thursday November 14, 2024 11:00am - 11:15am PST
Virtual Expo Hall
  OPEN SESSIONS, CloudX

11:00am PST

[Virtual] OPEN SESSION (CloudX): Responsible AI and Security in the Generative Era: Science and Practice
Thursday November 14, 2024 11:00am - 11:25am PST
Ishneet Dua, Amazon Web Services, Senior Generative AI Solutions Architect
Parth Girish Patel, Amazon Web Services, Sr AI/ML Architect

The rapid growth of generative AI brings promising innovation and, at the same time, raises new challenges around its security, safe, and responsible development and use. These challenges include some that were common before generative AI, such as bias and explainability, and new ones unique to generative models, including hallucinations, toxicity, and intellectual property protection. During this session, participants will gain an overview of the challenges that generative AI presents, survey the emerging science surrounding these challenges, and engage in a discussion about the hands-on, security, and Responsible AI work currently being conducted on AWS.
Speakers
avatar for Ishneet Dua

Ishneet Dua

Senior Generative AI Solutions Architect, Amazon Web Services
Ishneet Dua (Isha) is a recognized expert in leveraging AI and machine learning for sustainability solutions. She has established herself as a go-to authority on combating climate change, pollution, and other environmental challenges through cutting-edge technologies.Dua has authored... Read More →
avatar for Parth Girish Patel

Parth Girish Patel

Sr AI/ML Architect, AWS
Parth Girish Patel is a seasoned architect with a wealth of experience spanning over 17 years, encompassing management consulting and cloud computing. Currently, at Amazon Web Services (AWS), he specializes in Artificial Intelligence/Machine Learning, generative AI, sustainability... Read More →
Thursday November 14, 2024 11:00am - 11:25am PST
VIRTUAL CloudX -- Main Stage

11:00am PST

[Virtual Exclusive] OPEN SESSION (CloudX): A Developer Self-Service Experience for Edge and IoT Come True
Thursday November 14, 2024 11:00am - 11:50am PST
Carl Moberg, Avassa, CTO and co-founder
Amy Simonson, Avassa, Marketing Manager


Enough manual actions. Enough slow handovers. And enough K8mplexity.

For many innovative enterprises today, the journey to the centralized cloud has shaped the way of working when it comes to container orchestration and observability. Now, developers and IT teams are increasingly also managing containers at the distributed on-site edge and in IoT environments, which risk becoming a mind-boggling task due to the resource-constrained, distant nature of IoT and edge.

In this session, we address the challenges related to deploying, monitoring, observing, and securing container applications at the edge. We also present hands-on examples of what a self-service developer experience can look like for the container applications at the distributed edge and IoT infrastructure. It's automated, it's application-centric and it's astonishingly easy.
Speakers
avatar for Carl Moberg

Carl Moberg

CTO and co-founder, Avassa
Carl has spent many years solving for automation and orchestration. He started building customer service platforms for ISPs back when people used dial-up for their online activities. He then moved on to focus on making multi-vendor networks programmable through model-driven architectures... Read More →
avatar for Amy Simonson

Amy Simonson

Marketing Manager, Avassa
Amy is an experienced marketing professional who thrives right in the intersection between deep tech and marketing. She is currently the marketing manager of Swedish Edge Platform provider Avassa, who are set out to make the distributed on-site edge delightfully easy to manage.
Thursday November 14, 2024 11:00am - 11:50am PST
VIRTUAL CloudX -- Expo Innovation Stage

11:30am PST

[Virtual] PRO SESSION (CloudX): Infrastructure in a Flash: Deploy via Code in Under 30 Minutes!
Thursday November 14, 2024 11:30am - 11:55am PST
Jagrut Sharma, Adobe, Senior Software Engineer

Unlock the power of managing infrastructure through code in this dynamic session! You'll dive into the fundamentals of infrastructure as code (IaC) with a focus on AWS CloudFormation. Step-by-step, you'll learn how to write your first template to efficiently create, update, and delete cloud resources.

By the end of this hands-on workshop, you'll have added a valuable skill to your repertoire and be equipped with the knowledge to further explore the vast possibilities of infrastructure as code. Join to enhance your technical skillset and embark on a journey of continuous innovation in cloud infrastructure management.
Speakers
avatar for Jagrut Sharma

Jagrut Sharma

Senior Software Engineer, Adobe
Jagrut Sharma is a senior software engineer at Adobe, where he leads the architecture and development of services enabling innovative machine-learning solutions and use cases. With over 20 years of experience in technology, Jagrut has contributed to a wide variety of projects across... Read More →
Thursday November 14, 2024 11:30am - 11:55am PST
VIRTUAL CloudX -- Stage 1

11:30am PST

[Virtual Exclusive] OPEN SESSION (CloudX): Azure OpenAI in Action
Thursday November 14, 2024 11:30am - 11:55am PST
Jannik Reinhard, BASF, Senior Solution Architect

In this session I will guide you from how to start with a CoPilot to deploy and own Azure Open AI instance to use cases which brings benefit to your company. We will also have a look how to build custom solution with the power of Azure.

- Takeaways:
- What is a copilot and how you can use it in your daily business
- How to setup Azure Open AI
- How can you build a custom solution with help of Azure.
Speakers
avatar for Jannik Reinhard

Jannik Reinhard

Senior Solution Architect, basf
My name is Jannik Reinhard and I'm 25 years old and I am work in the internal IT department of the largest chemical company in the world. I am a senior solution architect in the area of modern device management and technical lead of AIOPS (AI of IT Operation).
Thursday November 14, 2024 11:30am - 11:55am PST
VIRTUAL CloudX -- Main Stage

12:00pm PST

[Virtual Exclusive] PRO SESSION (CloudX): Building Guardrails for Generative AI: Security, Compliance, and Responsible Innovation
Thursday November 14, 2024 12:00pm - 12:25pm PST
Ken Huang, DistributedApps, CEO and Chief AI Officer

This presentation introduces a comprehensive framework for testing and validating the security of generative AI applications, particularly those built on large language models (LLMs). Developed by Ken Huang (the Speaker) and World Digital Technology Academy's AI Safety, Trust, and Responsibility (STR) working group, the framework addresses the new attack surfaces and risks introduced by generative AI.

The standard covers the entire AI application stack, including base model selection, embedding and vector databases, prompt execution/inference, agentic behaviors, fine-tuning, response handling, and runtime security. For each layer, it outlines specific testing methods and expected outcomes to ensure AI applications behave securely and as designed throughout their lifecycle.

Key areas of focus include model compliance, data usage checks, API security, prompt injection testing, output validation, and privacy protection. The framework also addresses emerging challenges like agentic behaviors, where AI agents autonomously perform tasks based on predefined objectives.
Speakers
avatar for Ken Huang

Ken Huang

CEO and Chief AI Officer, DistributedApps
Ken Huang is a prolific author and renowned expert in AI and Web3, with numerous published books spanning AI and Web3 business and technical guides and cutting-edge research. As Co-Chair of the AI Safety Working Groups at the Cloud Security Alliance, and Co-Chair of AI STR Working... Read More →
Thursday November 14, 2024 12:00pm - 12:25pm PST
VIRTUAL API World -- Workshop Stage A

12:00pm PST

[Virtual Exclusive] OPEN SESSION (CloudX): Adding Generative AI to Real-Time Streaming Pipelines
Thursday November 14, 2024 12:00pm - 12:25pm PST
Timothy Spann, Zilliz, Principal Developer Advocate

In this talk I walk through various use cases where bringing real-time data to LLM solves some interesting problems.

In one case we use Apache NiFi to provide a live chat between a person in Slack and several LLM models all orchestrated via NiFi and Kafka. In another case NiFi ingests live travel data and feeds it to HuggingFace and OLLAMA LLM models for summarization. I also do live chatbot. We also augment LLM prompts and results with live data streams. All with ASF projects. I call this pattern FLaNK AI.
Speakers
avatar for Timothy Spann

Timothy Spann

Principal Developer Advocate, Zilliz
Tim Spann is the Principal Developer Advocate for Data in Motion @ Zilliz. Tim has over a decade of experience with the IoT, big data, distributed computing, streaming technologies, and Java programming. Previously, he was a Developer Advocate at StreamNative, Principal Field Engineer... Read More →
Thursday November 14, 2024 12:00pm - 12:25pm PST
VIRTUAL CloudX -- Main Stage

12:00pm PST

[Virtual Exclusive] OPEN SESSION (CloudX):Architecting platform services for mission-critical software systems
Thursday November 14, 2024 12:00pm - 12:25pm PST
Aman Sardana, Discover Financial Services, Senior Principal Application Architect

Have you ever wondered what it takes to create resilient and highly available platform services that support mission-critical software systems? Please join me to find out how you can set the right strategy and foundational architecture for building platform services that businesses can trust for their most critical workloads.

Payment systems that support real-time transaction processing are expected to be highly available and highly responsive 24/7/365. These systems must be fault-tolerant and resilient to any failures that might happen during payment transaction processing.
Mission-critical payment systems with distributed architecture often depend on platform services like distributed caching, messaging, event streaming, databases, etc. that should be independently designed for high availability and fault tolerance.
In this talk, I’ll share the approach we took for architecting and designing platform services within the payments domain that can be applied to any domain that supports business-critical processes. This methodological approach starts with establishing a capability view for platform services and then defining the implementation and physical views. You’ll also gain an understanding of other aspects of platform services like provisioning, security, observability, testing, and automation that are important for creating a well-rounded platform strategy supporting business-critical systems.
Speakers
avatar for Aman Sardana

Aman Sardana

Senior Principal Application Architect, Discover Financial Services
I am a technology professional working in the financial services and payments domain. I’m a hands-on technology leader, enabling business capabilities by implementing cutting-edge, modernized technology solutions. I am skilled in designing, developing, and implementing innovative... Read More →
Thursday November 14, 2024 12:00pm - 12:25pm PST
VIRTUAL API World -- Expo Discovery Stage

12:30pm PST

[Virtual Exclusive] OPEN SESSION (CloudX): Green DevOps: Building Sustainable Software
Thursday November 14, 2024 12:30pm - 12:55pm PST
Neel Shah, Internauts Infotech, Devops Community

In today's world, where environmental concerns are at the forefront of our minds, it's crucial to consider the impact of our actions, including those within the tech industry. Software development, while driving innovation and progress, also contributes to a significant carbon footprint. This is where Green DevOps steps in, offering a powerful solution for building software that is both efficient and environmentally friendly.

Green DevOps refers to the practice of integrating sustainable practices into your software development lifecycle. This means implementing tools, techniques, and methodologies that minimize the environmental impact of software development and delivery. By adopting Green DevOps, you can achieve significant benefits, including:

Reduced energy consumption: Green DevOps practices help optimize resource utilization, leading to lower energy consumption throughout your development process. This not only translates to cost savings but also minimizes the carbon footprint of your software.

Improved resource efficiency: Green DevOps encourages developers to utilize resources wisely, minimizing waste and maximizing efficiency. This can involve practices like code optimization, infrastructure right-sizing, and efficient testing processes.

Enhanced software quality: Green DevOps principles encourage a focus on quality from the very beginning of the development process. This leads to fewer bugs and defects, resulting in software that is more reliable and requires fewer resources to maintain.

I would cover most of this topics in my talk.
Speakers
avatar for Neel Shah

Neel Shah

Devops Community Guy, Internauts Infotech
Mentored more than 10 hackathons and open source programs and mentored more than 2000 peers to contribute to open source programsCo-organiser of HUG Ahmedabad,Gandhinagar , CNCF Gandhinagar ,GDG Cloud Gandhinagar
Thursday November 14, 2024 12:30pm - 12:55pm PST
VIRTUAL CloudX -- Expo Innovation Stage

1:00pm PST

[Virtual] OPEN SESSION (CloudX): The Critical Role of Observability in Cloud Native Applications: Ensuring Reliability and Minimizing Downtime
Thursday November 14, 2024 1:00pm - 1:25pm PST
Greg Leffler, Splunk, Director of Developer Evangelism - Observability

As organizations have moved to the cloud and increased their pace of innovation to ship software more often, it becomes harder to validate the impact of changes – both to their business and to their customers’ experience. That’s where Observability comes into play. Observability has emerged as a critical aspect of cloud native applications due to its ability to provide comprehensive insights into the complex and dynamic environments these applications operate within. By enabling real-time monitoring, tracing, and logging, observability allows users to proactively identify and resolve performance issues, improve reliability and build better digital experiences. This is crucial in helping organizations lower the cost of unplanned downtime and be more resilient.

Downtime not only results in direct financial losses, often quantified in thousands of dollars per minute for large enterprises, but also incurs indirect costs such as reduced customer satisfaction, loss of trust, and potential long-term reputational damage. To illustrate these benefits, we will demonstrate a troubleshooting scenario in a microservice environment using an advanced observability tool, showcasing how timely insights can present and resolve issues efficiently. As a result, investing in robust observability tools and practices is essential for maintaining the reliability and efficiency of cloud native applications, ultimately supporting business continuity and growth.
Speakers
avatar for Greg Leffler

Greg Leffler

Director of Developer Evangelism - Observability, Splunk
Greg Leffler heads the Observability Developer Evangelism team at Splunk and is on a mission to spread the good word of Observability to the world. Greg's career has taken him from the NOC to SRE, from SRE to management, with side stops in security and editorial functions. In addition... Read More →
Thursday November 14, 2024 1:00pm - 1:25pm PST
VIRTUAL CloudX -- Main Stage

1:00pm PST

[Virtual Exclusive] OPEN SESSION (CloudX): Unleashing DevSecOps Mastery: The 5 Secrets Every Cloud Innovator Must Know!
Thursday November 14, 2024 1:00pm - 1:25pm PST
Gursimar Singh, freeCodeCamp, Author

In the dynamic realm of cloud infrastructure, security remains a paramount concern. As organizations strive to fortify their digital assets against evolving threats, integrating security seamlessly into infrastructure development processes becomes imperative. DevSecOps offers a compelling framework for achieving this synergy between security and infrastructure operations.

This anticipated session at CloudX 2024 will provide actionable insights tailored to infrastructure professionals. The session will provide expert insights on establishing and sustaining a highly effective DevSecOps framework, anchored in five foundational tenets that prioritize people, tools, and processes.
Speakers
avatar for Gursimar Singh

Gursimar Singh

Author, freeCodeCamp
Gursimar is trying to empower individuals via Education, Mentorship, and Open-Source. He was invited to Paris and presented at the HAProxy Conf 2022 in November 2022. He's a moderator and CFP review committee member for ContainerDays 2023 & 2024 and Staff Member & CFP review committee... Read More →
Thursday November 14, 2024 1:00pm - 1:25pm PST
VIRTUAL CloudX -- Expo Innovation Stage

1:30pm PST

[Virtual] OPEN SESSION (CloudX): Unlocking the Promise of AIOps: Leveraging AI to Realize Full-Context Operations
Thursday November 14, 2024 1:30pm - 1:55pm PST
Fred Koopmans, BigPanda, Chief Product Officer

Context is fundamental to well-run tech operations: With the right context, IT teams can better understand their systems, interpret real-time data quickly, and facilitate better incident management to achieve operational efficiency. But too often, gathering the necessary context is a lengthy, inconsistent, and elusive process. IT teams are forced to grapple with fragmented tools, siloed workflows, and inconsistent manual processes, which have turned context collection into a definitive pain point for the ITOps industry. Teams are losing out on precious time, money, and attention that should be directed towards digital transformation and innovation.

The tech industry has recently transformed thanks to the AI boom: ITOps is at a critical juncture where AI can enable faster, more efficient ITOps as well as deliver Full-Context Operations. Fred Koopmans, Chief Product Officer of AIOps platform BigPanda, will speak to the promise of Full-Context Operations – the process of unifying IT teams’ tools and processes with AI to provide the institutional knowledge needed to address every incident immediately. He’ll dive deep into the ways that teams can tangibly benefit from having the right context, outlining how the IT industry can leverage AI to collect comprehensive and contextual data to help operators achieve better incident resolution. Fred can share detailed proof points from developing BigPanda’s AI-powered assistant that was purpose-built for delivering full context in IT operations. With Full-Context Operations, the IT industry can finally fulfill the long-sought-after promise of AIOps, putting AI into practice to deliver unprecedented operational efficiency.
Speakers
avatar for Fred Koopmans

Fred Koopmans

Chief Product Officer, BigPanda
Fred Koopmans, BigPanda's Chief Product Officer, is dedicated to driving innovation and collaboration, building trusted partnerships with customers, creating product roadmaps, and empowering individuals to achieve the extraordinary. He leads product strategy, product management, product... Read More →
Thursday November 14, 2024 1:30pm - 1:55pm PST
VIRTUAL CloudX -- Main Stage

2:00pm PST

[Virtual] PRO SESSION (CloudX): Building Robust Networks: The Power of CI/CD in Network Validation
Thursday November 14, 2024 2:00pm - 2:25pm PST
Naveen Achyuta, Roblox, Network Reliability Engineer

While CI/CD practices are well-established in software development, the networking field is still adapting to these methodologies. This presentation demonstrates a method for validating network configurations in a lab environment, both pre- and post-deployment, to build confidence before implementing changes in production networks. Using open-source tools, custom scripts, and containerlab, we'll walk through each step of implementing a CI/CD pipeline. This approach not only enhances confidence in network deployments but also bridges the gap between traditional networking practices and modern DevOps methodologies. 
Speakers
avatar for Naveen Achyuta

Naveen Achyuta

Network Reliability Engineer, Roblox
Naveen works as a Network Reliability Engineer at Roblox and lives in the Bay Area. After graduating with his master's degree, he initially worked as a network engineer at Comcast. He then transitioned to network software engineering to build network automation systems that streamline... Read More →
Thursday November 14, 2024 2:00pm - 2:25pm PST
VIRTUAL CloudX -- Stage 1

2:00pm PST

[Virtual] OPEN SESSION (CloudX): Shifting the Perspective on Security: Putting Security Back in the Design Process
Thursday November 14, 2024 2:00pm - 2:25pm PST
Celina Stewart, Neuvik Solutions, Cyber Risk Lead

Although many organizations incorporate security into the Software Development Life Cycle, it is often treated as a compliance requirement rather than a purpose-built feature. Not treating security as a feature during the design process can lead to rework, extra complexity, or investment in functionality that does not actually address risk effectively. Further, poor integration of security can have a negative impact on otherwise well-designed applications and cause friction in user experience.

This talk encourages attendees to go beyond traditional threat modeling and defense-in-depth techniques to incorporate security as a purpose-built feature in applications. Attendees will receive tactical guidance on how to incorporate security proactively in the design process. Techniques discussed will include: how to use the organization’s risk outlook to prioritize security features; how to avoid unnecessary development costs by proactively anticipating friction in user experience; how to evaluate tradeoffs and invest in the security features needed to prevent the greatest risks.
Speakers
avatar for Celina Stewart

Celina Stewart

Cyber Risk Lead, Neuvik
Celina Stewart is an expert in cyber risk management at Neuvik, a cybersecurity services company. In her current role, she leads Neuvik’s Integrated Risk Management service line, translating technical findings from Red Team Assessments to cogent, tactical strategies to buy-down... Read More →
Thursday November 14, 2024 2:00pm - 2:25pm PST
VIRTUAL CloudX -- Main Stage

2:30pm PST

[Virtual] KEYNOTE (CLOUDX): Fairwinds -- K8s Is a Big Hammer - Is Everything a Nail?
Thursday November 14, 2024 2:30pm - 2:55pm PST
Andy Suderman, Fairwinds, CTO

It's been 10 years since Kubernetes came on the scene and became synonymous with running containers at scale. Suddenly everyone needed to run their apps in Kubernetes.

Or did they?

I'll discuss the different real-world scenarios where Kubernetes makes sense, and where it doesn't. We'll talk about how the hype of technology can get you into trouble, and how to evaluate when Kubernetes is the right call for your business. Don't walk down the dark alley....unless you need to.
Speakers
avatar for Andy Suderman

Andy Suderman

CTO, Fairwinds
Andy Suderman is CTO at Fairwinds, a managed Kubernetes-as-a-Service provider. Andy has worked with cloud native technologies for the last eight years helping organizations adopt and manage Kubernetes. Andy is the creator and primary developer of Goldilocks—an open source tool that... Read More →
Thursday November 14, 2024 2:30pm - 2:55pm PST
VIRTUAL API World -- Main Stage

3:00pm PST

[Virtual] KEYNOTE (CLOUDX): Trend Micro -- Utilizing a New Threat Model for Software Supply Chain in Cloud-native Systems
Thursday November 14, 2024 3:00pm - 3:25pm PST
Mike Milner, Trend Micro, VP Cloud Technology

As cloud native environments become more secure, attackers are shifting their focus to infiltrate the software supply chain. Securing the software supply chain starts at the beginning of the development process and continues throughout the application’s development lifecycle, but the complexity means that it is easy to miss links in this chain.

This session will construct a threat model that includes everything from the developer work stations, the code and open source libraries that make up an application, to the entire pipeline of building and deploying an app and the teams that maintain it.

Attendees of this session will:
• Understand the steps needed to manage and ensure the security of a broader software supply chain considering quickly evolving tech innovations.
• Learn how to determine the best tools for tracking the software development lifecycle in cloud-native settings.
• Discover how new generative AI tools can help automate some of the monotonous tasks such as fixing or updating older or broken code.
Speakers
avatar for Mike Milner

Mike Milner

VP Cloud Technology, Trend Micro
Mike Milner is the VP Cloud Technology at Trend Micro. Between fighting cybercrime for the Canadian government and working for security agencies overseas, Mike has developed a deep understanding of the global security landscape and how the underground economy dictates hacks and drives... Read More →
Thursday November 14, 2024 3:00pm - 3:25pm PST
VIRTUAL CloudX -- Main Stage
 

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date - 
  • Talk Type
  • OPEN Session
  • PRO Session
  • PRO Workshop
  • Track or Conference
  • AI & ML (CloudX)
  • API Case Studies & Success Stories (API World)
  • API Design / Architecture (API World)
  • API Leadership Summit (API World)
  • API Ops & Scalability & Usability (DX) & Testing (API World)
  • API Program Management (API World)
  • API Security / Compliance (API World)
  • API World
  • API World: API Innovation
  • API World: API Lifecycle
  • API World: API Strategy
  • API World: Microservices World
  • API-First Development (API World)
  • APIs (Dev Innovation)
  • Automated Testing & Monitoring & Reporting (CloudX)
  • CI/CD (CloudX)
  • CI/CD / Deployment (API World)
  • Cloud Development Technologies (CloudX)
  • Cloud Development Technologies (Dev Innovation)
  • Cloud Infrastructure (CloudX)
  • Cloud Innovation (AI & Edge & etc) (CloudX)
  • Cloud Security (CloudX)
  • Cloud Talent & Skills (CloudX)
  • CloudX
  • CloudX: Cloud Architecture & Infrastructure
  • CloudX: Cloud Strategy Conference
  • CloudX: Cloud-Native Development
  • CloudX: DevOps Summit
  • Containers & Kubernetes (CloudX)
  • Deployment Strategies (CloudX)
  • Dev Innovation (CloudX)
  • Dev Innovation Summit
  • Developer Tools (Dev Innovation)
  • DevSecOps (CloudX)
  • Digital Acceleration (CloudX)
  • Edge Computing (CloudX)
  • Emerging APIs: AI & IoT & Blockchain & Web3 & XR (API World)
  • Expo Challenge
  • Future of Cloud-Native Computing (CloudX)
  • Hybrid & Multi-Cloud (CloudX)
  • Hybrid APIs & Low Code APIs (API World)
  • Industries: Open Banking & Healthcare & Retail (API World)
  • Infrastructure-as-Code (CloudX)
  • Integration Management (API World)
  • Leadership Lounge
  • Microservices Design & Architecture (API World)
  • Microservices Design (CloudX)
  • Microservices Management (CloudX)
  • Observability (CloudX)
  • OPEN Session
  • Platform Engineering (API World)
  • Programming Languages (Dev Innovation)
  • Roundtables
  • Service Mesh & Containers & Kubernetes (API World)
  • Sponsor Spotlight
  • Virtual
  • In-Person/Virtual
  • In Person
  • Virtual
  • Virtual Exclusive