Threat Modeling CI/CD: Systems for Improving Developer Experience and Achieving Security by Design

May 31, 2025
10:00 AM
Room Barcelona (1st floor)
🎤 Expert talk

About this session

Applications and systems today often follow an automated and repeatable flow from the developers to the infrastructure where they run. This allows organizations to scale their development velocity and innovation. When done right this ensures that all applications are secure and verifiable, but if done insecurely the only thing that's been scaled is our attack surface. In this talk we will discuss how to apply threat modeling to CI/CD to achieve better developer satisfaction and security.

About the speaker

Karim is a seasoned and renowned thought leader within cloud security. At O3 Cyber, he conducts research and development and works with our clients, primarily in Financial Industry. Karim has a background in building and operating platform services for security on private and public clouds, developing and executing a cyber security strategy for the world’s largest sovereign wealth fund.

Speaker

Speakers

Karim El-Melhaoui
Principal Security Architect, O3 Cyber / Microsoft Security MVP
Håkon Nikolai Stange Sørum
Principal Security Architect and Partner, O3 Cyber