SecuritySecurity
Conference50min
INTERMEDIATE

Proactive or Reactive Security? How to shift away from Incident-Driven Design

The talk explains “Secure by Design” before coding begins, showing how early requirements and planning shape later risks. It argues that proactive security can be built into system design with small changes, helping teams prevent incident-driven weaknesses without slowing delivery.

talk.summaryAiDisclaimer

Bárbara Teruggi
Bárbara TeruggiIndependent
talks.description
Most systems aren’t intentionally designed to be insecure… They’re designed to ship.
When time-to-market sets the pace, systems tend to evolve by reacting to incidents: something breaks, we fix it, and move on. Over time, this becomes incident-driven design when systems aren’t shaped early to avoid facing the consequences of pre-installed weaknesses.
This talk focuses on what “Secure by Design” means before code is written. We’ll look at how requirements, planning, and design phases of the SDLC define what can go wrong later, and how small changes at this stage help build security into the design without slowing teams down.
By the end of the talk, you’ll leave with practical advice on how to integrate proactive security into system design.
sdlc
proactive security
secure by design
system design
talks.speakers
Bárbara Teruggi

Bárbara Teruggi

Independent

Spain

Originally from Argentina, I've been living in the Barcelona area for +20 years. Started in the IT world in 2006, building my career within the Finance and Insurance business. My path started as a developer in different areas (business oriented and also more technical tasks). I have also been working on development support and a brief DevOps period, until my current position as a Security Architect.
In my free time I enjoy music, reading, climbing, pilates, traveling and socializing.