The Broken State of DevSecOps and Its Maturity Model - Eitan Worcel, Dustin Lehr @OWASPGLOBAL
The Broken State of DevSecOps and Its Maturity Model - Eitan Worcel, Dustin Lehr  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 2 weeks ago
Despite the hype surrounding DevSecOps, the reality is starkly different: reported issues remain unresolved, SLAs are neglected, and the role of security champions is reduced to basic training sessions.


This talk examines the shortcomings of the current DevSecOps maturity model and its failure to drive substantial improvements in security practices. We will discuss the cultural shifts needed to instill a security-first mindset, emphasizing the importance of guiding teams effectively.


By empowering security champions with meaningful responsibilities and integrating advanced technologies for automated and proactive security measures, we can transform the theoretical promises of DevSecOps into a practical framework that genuinely addresses and fixes security vulnerabilities.


Join us to explore actionable solutions and strategies for bridging the gap between DevSecOps hype and reality.

-

Managed by the OWASP® Foundation
owasp.org
The Broken State of DevSecOps and Its Maturity Model - Eitan Worcel, Dustin LehrLeaking Secrets in the Age of AI: How AI Adoption is Creating New Attack VectorsBuilding Security Into Developer Velocity: How We Made Entra Identity Compliance Invisible track 1Keynote by Adam Shostack: Stop Trying to Manage RiskOWASP Board of Directors - July 2026 Public Board MeetingNo Fate But What We Make: Doing Intrusion PredictionCycloneDX 2.0 Preview: Evolving BOM Architecture for Broader ApplicabilityGuardrails First: Building AI Agents That Won’t Leak Your Secrets - Track 2Red vs. Blue: Threat Modeling Agentic AI & Securing the Unbounded Third PartySecure Financial Analytics with Homomorphic Encryption and GAN Driven Data Track 2Don’t Make This Mistake: Painful Learnings of Applying AI in Security - Eitan WorcelSelf-Healing Security Test Automation for OWASP AppSec: Adaptive Defense Against Evolving Threats
OWASP Foundation |

The Broken State of DevSecOps and Its Maturity Model - Eitan Worcel, Dustin Lehr

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER