Why Coverage Throughout the SDLC is Critical to Your Security Posture

Logo
Presented by

Joe Nicastro, Field CTO at Legit Security & Liam McCamley, Senior Solutions Architect at Legit Security

About this talk

Did you know that once a secret makes it into a Git commit history, it stays there forever and can be left undiscovered for months or years? Recent attacks like Uber and Toyota underscore the risks. Once hackers gain access to critical systems via an exposed secret, they can move laterally across an organization to orchestrate dangerous supply chain attacks. Join us as we walk through the problem of secrets in the modern development environment and what it takes to detect and prevent secrets in even the most complex organizations. You will learn: - How to detect different types of secrets across your entire SDLC, not just in source code, but also pipelines and even Confluence. - Best practices for preventing secrets from being inadvertently pushed to production. - The value of prioritization and context when it comes to secret scanning, and how this can help you remediate faster. - How innovative tools like AI can reduce the noise and false positives associated with secrets scanning.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (11)
Subscribers (958)
Legit is a new way to manage your application security posture for security, product and compliance teams. With Legit, enterprises get a cleaner, easier way to manage and scale application security and address risks from code to cloud. Built for the modern SDLC, Legit tackles the toughest problems facing security teams, including GenAI usage, proliferation of secrets and an uncontrolled dev environment. Fast to implement and easy to use, Legit lets security teams protect their software factory from end to end, gives developers guardrails that let them do their best work safely, and proves the success of the security program. This new approach means teams can control risk across the business – and prove it.