Lessons Learned From the CrowdStrike Incident: InfoQ Dev Summit Munich 2024 Preview
03 Sep 2024 (4 months ago)
DevSecOps Professionals
- Danielle is the Security Operations Manager at Liver and has been working in DevSecOps for the last decade. (2m14s)
- Santos is a Senior Software Engineer at Sane, based near Hamburg, and works primarily with monorepos. (2m52s)
- M. Brki is a Principal Software Architect in Munich working in fintech, focusing on architecture strategy and cloud platform migration. (4m0s)
Importance of System Reliability
- A passenger at Frankfurt station was unable to purchase food due to their card not working, highlighting how even small mistakes can have significant consequences. (6m47s)
- The incident emphasized the importance of ensuring critical paths in systems are robust and reliable, as they can impact millions of people. (7m18s)
- The deployment and testing approaches within the fintech industry should be significantly improved to prevent similar situations from occurring. (11m2s)
Managing Third-Party Risks
- Organizations need to have a plan to deal with third and fourth-party technical issues and threats. (13m15s)
- It is important to understand the infrastructure of third-party solutions, ask detailed questions, and validate vendor promises. (14m2s)
Cloud Security and Investment
- Determining the critical paths for investment and safety in cloud environments is crucial, considering the balance between reliability and cost. (16m55s)
- Daniel's session at InfoQ Dev Summit Munich will focus on misconfigurations in cloud infrastructure and how to gain visibility into them. The session will cover topics such as cloud security posture management (CSPM) and cloud workload protection platforms (CWPP). (22m35s)
Software Development and Risk Mitigation
- Sonos ships updates to over 40 applications every week. Sonos uses feature flags and a rollback strategy to mitigate risk. (19m35s)
- Human error is a known factor in software development. Education and awareness are crucial to minimize risk. Developers should strive to understand the potential impact of their actions, such as misconfigurations in code, documentation, or deployments. (21m21s)
- Danielle will present a talk about managing the complexities of deploying over 40 applications per week across a collaborative environment of over 40 teams. (24m10s)
Software Supply Chain Security in Fintech
- SM will discuss a comprehensive approach to software supply chain security within the highly regulated fintech industry, emphasizing the importance of navigating regulations and understanding the broader environment. (24m56s)
- SM will also provide real-world examples and architectural insights to illustrate how to make faster and more effective architectural decisions. (26m5s)