About the summit
Now in its fourth year, the AppSec World is Australia’s dedicated event built specifically around application security, product security and secure software, with events in Sydney and Melbourne. Software is being built and released faster than security teams can review it. Cloud-native development, open-source dependencies, APIs, AI-generated code and now coding agents have expanded the attack surface, while AppSec teams are still expected to reduce risk without slowing engineering. Until this summit, application security was a stream inside broader cybersecurity or developer conferences, never the room itself. The AppSec World is that room. CISOs, Heads of AppSec and Product Security, DevSecOps leaders, security architects, engineering managers and the practitioners responsible for securing software come together to compare programs directly with their peers. Make sure you are part of the discussion at Australia’s dedicated event for the teams building and securing modern software.
Who attends
- CISO
- Head of AppSec
- Director of Product Security
- VP Engineering
- Head of Platform / Cloud
- Principal Security Engineer
What the programme covers
- Application Security at ScaleBuilding security into the software lifecycle without turning AppSec into a release gate.
- Product Security and Secure by DesignOwning security from architecture and design through development and production.
- AI-Generated Code and Coding AgentsSecuring the code, tools and permissions introduced by AI-assisted and agentic development.
- Software Supply Chain SecurityProtecting open-source dependencies, build pipelines, artifacts and the systems software teams rely on.
- Application Security Testing and ASPMConnecting testing and posture data so teams can focus on the vulnerabilities that matter.
- API and Cloud-Native SecurityFinding and securing APIs, containers, Kubernetes and cloud-native applications as they change.
- Vulnerability Prioritisation and RemediationMoving from vulnerability volume to what is exploitable, exposed and actually fixable.
- Developer Security and Secure CodingGiving engineers the guardrails, training and secure defaults to fix risk before production.