Uploaded December 2025 | Updated September 2026, 1 week ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/53/Global_AppSec_DC_Security_Exceptions.pptx
Engineering teams often find themselves drowning in vulnerabilities. In such situations, how do they distinguish real threats from noise — and when is it okay to defer remediation in favour of other critical business priorities? Join us as we explore how Adobe runs a scalable exception management program across 500+ product teams, balancing development agility with security work, while minimising the organisation’s risk exposure.
We’ll explore the different types of exceptions granted at Adobe and how our review process is designed to be thorough, yet efficient. I’ll share details of the risk assessment framework we’ve developed, which helps us carefully evaluate the potential impact of each exception. We'll talk about how active exceptions are continuously monitored and finally, I'll share how we're trying to leverage large language models (LLMs) to accelerate the exception review process.
This talk includes practical, real-world strategies for responsible risk acceptance and attendees will walk away with a playbook for building (or scaling) an exception management program at their own organisations.
Gurneet Kaur
Adobe
Senior Software Engineer
Gurneet Kaur is a Senior Software Engineer at Adobe with seven years of experience in Security Engineering. She has led the development of multiple tools that assess, report, and mitigate security risk across Adobe’s global infrastructure. Her current area of interest is leveraging large language models (LLMs) to drive efficiency and scale security operations.
linkedin.com/in/gurneet-kaur-6b9a19123
Managed by the OWASP® Foundation
owasp.org
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/53/Global_AppSec_DC_Security_Exceptions.pptx
Engineering teams often find themselves drowning in vulnerabilities. In such situations, how do they distinguish real threats from noise — and when is it okay to defer remediation in favour of other critical business priorities? Join us as we explore how Adobe runs a scalable exception management program across 500+ product teams, balancing development agility with security work, while minimising the organisation’s risk exposure.
We’ll explore the different types of exceptions granted at Adobe and how our review process is designed to be thorough, yet efficient. I’ll share details of the risk assessment framework we’ve developed, which helps us carefully evaluate the potential impact of each exception. We'll talk about how active exceptions are continuously monitored and finally, I'll share how we're trying to leverage large language models (LLMs) to accelerate the exception review process.
This talk includes practical, real-world strategies for responsible risk acceptance and attendees will walk away with a playbook for building (or scaling) an exception management program at their own organisations.
Gurneet Kaur
Adobe
Senior Software Engineer
Gurneet Kaur is a Senior Software Engineer at Adobe with seven years of experience in Security Engineering. She has led the development of multiple tools that assess, report, and mitigate security risk across Adobe’s global infrastructure. Her current area of interest is leveraging large language models (LLMs) to drive efficiency and scale security operations.
linkedin.com/in/gurneet-kaur-6b9a19123
Managed by the OWASP® Foundation
owasp.org










