Breaking News: Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP
Read the Report
OX Security is recognized as a Leader in the 2026 Gartner® Magic Quadrant™
Read the full report
OX Security Named a Sample Vendor Across 3 Categories in the Gartner® Hype Cycle™ for Application Security
Read More

Mastering the Secure Software Development Life Cycle and Third Party Risks

Beyond the Basics Resource Tile

In this OX Security panel, host Boaz Barzel leads six security leaders, Nuno Teodoro (Solaris), Jag Singh (Ted Baker), Tomer Weinberger (Microsoft), Conor Mancone (Cimpress), David Cross (Oracle), and Luca Lanziani (Nearform), through a wide-ranging discussion on mastering the secure software development lifecycle and third party risk. They explain why secure SDLC has shifted from a methodology to a necessity, how cloud transformation reshaped both the security boundary and incident response, and why traditional practices like once-a-quarter pen testing no longer hold. Drawing on real breaches such as the Okta support-system compromise, they map third party risks that reach well beyond software dependencies into containers, base images, and identity. The conversation turns to prioritization through context (reachability, attack paths, and business criticality), the central role of culture and accountability, and how AI and automation can help, with the recurring advice to automate first and apply AI only where it adds value.

Key Takeaways

  • Secure SDLC is now a necessity, not an option. Security has moved from a final-stage checkbox to something embedded across the whole lifecycle, driven by cloud transformation and increasingly sophisticated attacks.
  • Third party risk extends far beyond software dependencies. It includes container base images, marketplace images, the operating system itself, and identity providers, as the Okta breach showed; an SBOM is a starting point, not the finish line.
  • The cloud changed both the boundary and the response. Security boundaries now extend to external vendors and services, and cloud incident response remains immature because of shared-responsibility access limits and transient resources.
  • Context beats raw severity for prioritization. Reachability, internet exposure, attack-path analysis, and business criticality should reclassify vulnerabilities; EPSS and risk-based scoring help, but only with the right culture and an audit-ready process.
  • Culture and accountability are the real differentiator. Given the same tools, the team that is empowered, trained, and shares responsibility (with top-down CISO support) wins, because security should be everyone's job rather than someone else's.
  • Automate first, then apply AI. Panelists favored fine-tuning automation before adding AI, using AI to consolidate signals, cut alert fatigue, and summarize context, while staying wary of hallucinations, added complexity, and regulatory load.

Video Transcript

Speakers

boaz li image

Boaz Barzel

View on LinkedIn

Director of Product Marketing, OX Security (host)

Hosts the panel and frames the discussion on securing the software development lifecycle and third party risk at OX Security.

Nuno Martins

Nuno Teodoro

View on LinkedIn

VP, Group Cyber Security, Solaris

Leads cyber security for Solaris, a German tech company with a banking license, where his remit includes product and application security.

Jagjot Singh

CISO, Ted Baker

Heads cyber security for retailer Ted Baker, including its global supply chain and the risks behind it.

Tomer Weinberger

Tomer Weinberger

View on LinkedIn

Senior Manager, Microsoft

A senior manager at Microsoft focused on cloud threat protection, helping build the detection and response capabilities of Microsoft Defender for Cloud.

Conor Mancone

Conor Mancone

View on LinkedIn

Principal Application Security Engineer, Cimpress

A trained research scientist (PhD in astronomy) turned application security leader at Cimpress (Vista), where he helps implement the secure SDLC.

David B. Cross

David Cross

View on LinkedIn

SVP and CISO, Oracle SaaS Cloud

SVP and CISO for Oracle's SaaS Cloud and a venture partner at Rain Capital, with 20 years building cloud security teams at Microsoft, Google, and Oracle.

Luca Lanziani

Luca Lanziani

View on LinkedIn

Head of DevOps and Platform Engineering, Nearform

Leads DevOps and platform engineering at Nearform, a remote-first services company, helping clients across the DevSecOps lifecycle.

FAQ

A panel of security leaders on mastering the secure software development lifecycle (SSDLC) and managing third party risk, covering market context, risks and challenges, and solutions and approaches.

Because nearly every service relies on software, and cloud transformation plus more sophisticated attacks mean security must be built in across the lifecycle rather than bolted on at the end.

Software dependencies and fourth-party libraries, container base images and marketplace images, the operating system, and identity providers, illustrated by the Okta support-system breach.

With context: reachability, internet exposure, attack-path analysis, and business criticality, using risk-based and EPSS-style scoring, backed by an audit-ready process and the right culture.

Culture, empowerment, training, and shared accountability; tools provide data, but the team that best understands its systems and owns security moves faster.

They can consolidate signals, reduce alert fatigue, and summarize context, but the panel advised automating first and adding AI only where needed, while watching for hallucinations, complexity, and compliance overhead.

Frame 2085669014
Group 1261154229