Uploaded May 2026 | Updated September 2026, 3 hours ago
Tracy Ragan (DeployHub.com, US)
Traditional vulnerability management has been rooted in the pre-deployment world, utilizing CI/CD scans, SCA tools, and secure-by-design controls. But attackers have already moved on. With daily CVE surges, rapid open-source package churn, and software spread across clouds, edge devices, and even space systems, production has become the new attack surface. Vulnerabilities that matter most now appear after deployment, when software is already running in the wild and exposed. This talk explains why organizations must pivot to post-deployment endpoint detection and how the open-source community, through projects like Ortelius.io, a Continuous Delivery Foundation initiative, has built the foundational architecture to make it possible. Ortelius introduced the industry’s first deployment-centric SBOM catalog and digital-twin model, enabling teams to understand exactly which live endpoints are impacted by newly reported vulnerabilities without scanning or instrumenting production environments. Attendees will learn how digital-twin mapping, SBOM-driven intelligence, and deployment lineage tracking reveal the true attack surface of new CVEs across containers, clusters, edge devices, satellites, ground systems, and distributed infrastructures. We will show why pre-deployment tools alone cannot determine real risk, and how a post-deployment detection layer closes the gap that attackers are actively exploiting.
---
Tracy Ragan is a well-known speaker in open source security, DevOps, and the software supply chain. She has provided keynotes for Open Source Summit and CDCon. She is a regular analyst for TechStrong Gang (Futurum Group) where various topics in security are discussed. Tracy serves as the CEO and Co-Founder of DeployHub. She sits in leadership roles across the OpenSSF and Continuous Delivery Foundation Tracy and has contributed significantly to the CI/CD Cybersecurity SIG and Ortelius.io. Ortelius is the open-source CDF project delivering deployment-centric SBOM intelligence and digital-twin-based post-deployment detection. She advocates for modernizing how organizations secure live, mission-critical systems across cloud, edge, and space environments, hardening software assets after pre-deployment scans.
Tracy Ragan (DeployHub.com, US)
Traditional vulnerability management has been rooted in the pre-deployment world, utilizing CI/CD scans, SCA tools, and secure-by-design controls. But attackers have already moved on. With daily CVE surges, rapid open-source package churn, and software spread across clouds, edge devices, and even space systems, production has become the new attack surface. Vulnerabilities that matter most now appear after deployment, when software is already running in the wild and exposed. This talk explains why organizations must pivot to post-deployment endpoint detection and how the open-source community, through projects like Ortelius.io, a Continuous Delivery Foundation initiative, has built the foundational architecture to make it possible. Ortelius introduced the industry’s first deployment-centric SBOM catalog and digital-twin model, enabling teams to understand exactly which live endpoints are impacted by newly reported vulnerabilities without scanning or instrumenting production environments. Attendees will learn how digital-twin mapping, SBOM-driven intelligence, and deployment lineage tracking reveal the true attack surface of new CVEs across containers, clusters, edge devices, satellites, ground systems, and distributed infrastructures. We will show why pre-deployment tools alone cannot determine real risk, and how a post-deployment detection layer closes the gap that attackers are actively exploiting.
---
Tracy Ragan is a well-known speaker in open source security, DevOps, and the software supply chain. She has provided keynotes for Open Source Summit and CDCon. She is a regular analyst for TechStrong Gang (Futurum Group) where various topics in security are discussed. Tracy serves as the CEO and Co-Founder of DeployHub. She sits in leadership roles across the OpenSSF and Continuous Delivery Foundation Tracy and has contributed significantly to the CI/CD Cybersecurity SIG and Ortelius.io. Ortelius is the open-source CDF project delivering deployment-centric SBOM intelligence and digital-twin-based post-deployment detection. She advocates for modernizing how organizations secure live, mission-critical systems across cloud, edge, and space environments, hardening software assets after pre-deployment scans.










