Security Exception Management: Balancing Risk with Reality at Enterprise Scale @OWASPGLOBAL
Security Exception Management: Balancing Risk with Reality at Enterprise Scale  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 1 week ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/53/Global_AppSec_DC_Security_Exceptions.pptx

Engineering teams often find themselves drowning in vulnerabilities. In such situations, how do they distinguish real threats from noise — and when is it okay to defer remediation in favour of other critical business priorities? Join us as we explore how Adobe runs a scalable exception management program across 500+ product teams, balancing development agility with security work, while minimising the organisation’s risk exposure.

We’ll explore the different types of exceptions granted at Adobe and how our review process is designed to be thorough, yet efficient. I’ll share details of the risk assessment framework we’ve developed, which helps us carefully evaluate the potential impact of each exception. We'll talk about how active exceptions are continuously monitored and finally, I'll share how we're trying to leverage large language models (LLMs) to accelerate the exception review process.

This talk includes practical, real-world strategies for responsible risk acceptance and attendees will walk away with a playbook for building (or scaling) an exception management program at their own organisations.

Gurneet Kaur
Adobe
Senior Software Engineer

Gurneet Kaur is a Senior Software Engineer at Adobe with seven years of experience in Security Engineering. She has led the development of multiple tools that assess, report, and mitigate security risk across Adobe’s global infrastructure. Her current area of interest is leveraging large language models (LLMs) to drive efficiency and scale security operations.
linkedin.com/in/gurneet-kaur-6b9a19123

Managed by the OWASP® Foundation
owasp.org
Security Exception Management: Balancing Risk with Reality at Enterprise ScaleThe Past, Present, and Future of Automated RemediationInstall Once, Exploit Forever: The MCP Plugin Supply Chain Attack Surface - Track 1Web Security Experts: Are you overlooking WebRTC vulnerabilities? - Sandro GauciOWASP AppSec Day France HighlightOWASP Board of Directors - February 2026I Know What You Did Last Summer: Lessons Learned from Privacy Breaches and Scandals - Dr. Kim WuytsAI Under the Hood: Unmasking Hidden Threats - Dr. Nitish M. UplavikarOWASP Nettacker - Arkadii Yakovets, Sam StepanyanMillions Of Public Certificates Are Reusing Old Private Keys - Dylan Ayrey, Joseph LeonIt’s Giving Insecure Vibes: Secure Coding Literacy for Vibe Coders Track 1Who Hurt You? Earning the trust of developers - Tanya Janca
OWASP Foundation |

Security Exception Management: Balancing Risk with Reality at Enterprise Scale

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER