Production Is the New Attack Surface: Why Post-Deployment Endpoint Detection Is Now Critical @FIRSTdotorg
Production Is the New Attack Surface: Why Post-Deployment Endpoint Detection Is Now Critical  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 3 hours ago
Tracy Ragan (DeployHub.com, US)

Traditional vulnerability management has been rooted in the pre-deployment world, utilizing CI/CD scans, SCA tools, and secure-by-design controls. But attackers have already moved on. With daily CVE surges, rapid open-source package churn, and software spread across clouds, edge devices, and even space systems, production has become the new attack surface. Vulnerabilities that matter most now appear after deployment, when software is already running in the wild and exposed. This talk explains why organizations must pivot to post-deployment endpoint detection and how the open-source community, through projects like Ortelius.io, a Continuous Delivery Foundation initiative, has built the foundational architecture to make it possible. Ortelius introduced the industry’s first deployment-centric SBOM catalog and digital-twin model, enabling teams to understand exactly which live endpoints are impacted by newly reported vulnerabilities without scanning or instrumenting production environments. Attendees will learn how digital-twin mapping, SBOM-driven intelligence, and deployment lineage tracking reveal the true attack surface of new CVEs across containers, clusters, edge devices, satellites, ground systems, and distributed infrastructures. We will show why pre-deployment tools alone cannot determine real risk, and how a post-deployment detection layer closes the gap that attackers are actively exploiting.

---

Tracy Ragan is a well-known speaker in open source security, DevOps, and the software supply chain. She has provided keynotes for Open Source Summit and CDCon. She is a regular analyst for TechStrong Gang (Futurum Group) where various topics in security are discussed. Tracy serves as the CEO and Co-Founder of DeployHub. She sits in leadership roles across the OpenSSF and Continuous Delivery Foundation Tracy and has contributed significantly to the CI/CD Cybersecurity SIG and Ortelius.io. Ortelius is the open-source CDF project delivering deployment-centric SBOM intelligence and digital-twin-based post-deployment detection. She advocates for modernizing how organizations secure live, mission-critical systems across cloud, edge, and space environments, hardening software assets after pre-deployment scans.
Production Is the New Attack Surface: Why Post-Deployment Endpoint Detection Is Now CriticalOROCHIFY - An Assist to Product Developers in Manufacturing Industry to Find VulnerabilitiesRemediation-Aware Reachability: Patching Containers, Prioritizing with Agentic-CTI, and Scaling...Threat Hunting with Python & PandasEpisode 56: Mor Weinberger and Lior Kaplan, FIRSTCON26 SpeakersBuilding a Regional ISAC for West Africa that Works: Governance, Tools and Community MaturityThe EUs Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Addres ...Chaos Stack: Designing Layered Tabletop Exercises for Complex Crisis Simulation99 Bottles of Trust on the Wall: Approaches to Building Convivial CommunitiesEverything Everywhere All at Once…in 2038Understanding Scammer Threats: Detection Strategies Aligned with Thailand’s Cybersecurity Act 2562CTI-Transmute: Harmonizing Threat Intelligence in a Multi-Standard Ecosystem
FIRST |

Production Is the New Attack Surface: Why Post-Deployment Endpoint Detection Is Now Critical

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER