Loading…
Attending this event?
26 June 2024
London, England
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source in Finance Forum London 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in British Summer Time. To see the schedule in your preferred timezone, please select from the drop-down menu to the right above "Filter by Date."


Security [clear filter]
Wednesday, June 26
 

13:05 BST

EU's Cyber Resilience Act Repercussions in Open Source - Nick Peacock, Cloudsmith
The EU's Cyber Resilience Act (CRA) proposes stringent cybersecurity requirements for digital products, aiming to bolster security against cyberattacks. While it promises safer hardware and software, it also raises questions for Open Source contributors and organizations. Will they be liable for vulnerabilities in their code? Could this legislation stifle innovation or foster it? The final draft of the CRA removed the burdensome requirements on OSS contributors- a very near land mine for the OSS community. Join me in exploring these questions to understand how the CRA underscores the imperative for open source organizations to advocate for their interests in policymaking.

Speakers
avatar for Nick Peacock

Nick Peacock

Senior Director Customer Success, Cloudsmith
Nick has worked with software organisations across different industries to optimise and get the most out of their software. He currently heads up Customer Success at Cloudsmith, the only cloud native universal artifact management platform.


Wednesday June 26, 2024 13:05 - 13:19 BST
Plaza Suite 10

13:21 BST

Supply Chain Security for Financial Services - Rhyddian Olds, Citi
Join this panel to find out how defining a standard and conformance framework around supply chain security may help enterprises evidence that they are meeting supply chain risk and support vendors with rollout and adoption of security products and services.

Speakers
avatar for Rhyddian Olds

Rhyddian Olds

Director, Open Source Program Office, Citi


Wednesday June 26, 2024 13:21 - 13:35 BST
Plaza Suite 10

15:25 BST

Open Source Software Supply Chain Security - Cephas Paul Edward, Goldman Sachs
Choosing between Open source vs proprietary for enterprise solutions has always been a battle of pros and cons of both the paradigms. Though open source promises to generally boost flexibility, agility and happens to be cost-effective as well, there are increased concerns around the trust worthiness of Open source components. Due to the nature of open source components, the surface area of potential attacks are also relatively high especially when these are employed by financial firms. These become hotspots for attackers to gain access to sensitive data. Thus, the problem statement reduces to a "supply chain" problem. This presentation provides an insight into exploitation methods employed by attackers specifically in the context of Open source components (with specific focus on Supply Chain attack), risk identification and mitigation strategies (Secure SDLC practices with focus on Supply chain security). In order to effectively identify relevant risk(s), it is important to defend the OSS components through out the lifecycle.The presentation also focusses on best practices which includes a novel approach to ensure OSS maturity via a checklist and appropriate control gates.

Speakers
avatar for Cephas Paul Edward

Cephas Paul Edward

Vice President, Goldman Sachs
Vice President, Goldman Sachs


Wednesday June 26, 2024 15:25 - 15:39 BST
Plaza Suite 10

15:41 BST

OpenSSF Security Insights: Empower Your GovOps - Luigi Gubello, Pitch
Discover the OpenSSF Security Insights specification, redefining open-source project security standards and compliance through automation and measurement. This specification provides a concise, machine-readable overview of project security, simplifying both human interpretation and automated processing. The specification helps security engineers and developers to have a project overview, standardizes attestation related to policies and licenses, and makes enables measurable information collection for open-source artifacts. This missing capability is essential for anyone creating software for highly regulated industries. Come explore the value of this open specification and the ecosystem that is quickly growing around it.

Speakers
avatar for Luigi Gubello

Luigi Gubello

Senior Security Engineer, Pitch
Security Engineer. Sometimes I try to hack stuff. Investigated by the authorities due to an SQL injection, financed by the powers that be, someone said.


Wednesday June 26, 2024 15:41 - 15:55 BST
Plaza Suite 10
 
  • Timezone
  • Filter By Venue London, UK
  • Filter By Type
  • AI/Emerging Tech
  • FDC3/Frontend
  • Featured Sessions
  • Hot Topics/Sustainibility/RegTech
  • Keynote Sessions
  • Open Source Readiness
  • Registration/Breaks/Solutions Showcase/Special Events
  • Security

Filter sessions
Apply filters to sessions.