Rebâtir votre stratégie DevSecOps à l’ère de l’IA
Download resourcesAbout this session
Simon Harvey, application security domain lead at Desjardins, argues that AI agents have removed the last real barrier to finding vulnerabilities: skill. Anyone with a credit card can now rent an aggressive model to scan code and write exploits, while frontier AI vendors sell the fix for a problem their own models accelerate. He contrasts Anthropic's 271 findings in the well-funded Firefox codebase against only five or six in curl, a volunteer project with far less technical debt, to show AI mostly exposes years of underfunded remediation rather than new bugs. He proposes six readiness questions (fast SBOM generation, vulnerability ownership, repository-wide scanning, blocking pipelines on findings, meeting SLEs, handling external disclosures) and a five-pillar rebuild: solid processes and training, deterministic scanning tools bought for repeatability, dependency and SBOM hygiene with zero-trust artifact registries, automated remediation via agentic parallelism, and detect/remediate metrics. His close: fund the unglamorous middle, buy AI for remediation not detection, and start today.
Automated AI pentesting platform are accelerating new security findings and zero-day. This will increase the
pressure and cadence requirement on the devs teams to quickly provide response and remediation.
In this talk, we will discuss how your organization should build its DevSecOps architecture and platform to be
ready to sustain the upcoming intensification of application security vulnerabilities.
Starting by looking at today's best practices, how to avoid anti-pattern and prioritze the right solution.
Key takeaways
- Measure whether you can generate a software bill of materials within ten minutes of a new critical CVE; if it takes days, attackers with the same AI tools will find your vulnerable dependencies first.
- Give every vulnerability a named owner and move CI pipelines from informational to blocking on security findings; without ownership and gates, known issues sit unaddressed for months.
- Buy deterministic SAST/SCA/secret-scanning tools even though an AI agent could try the same job, because you need a repeatable, gateable result and AI scans are non-deterministic by design.
- Put a zero-trust proxy between public package registries (npm, PyPI, GitHub) and your build systems, and actually enforce the blocking policy instead of leaving it informational.
- Spend AI budget on remediation, not detection: use agentic workflows to parallelize fixing years of backlog CVEs across teams, since discovering vulnerabilities was never the real bottleneck.
Speakers

Conseiller principal en DevSecOps, Sécurité Applicative chez Desjardins Fort d’une carrière de plus de 17 ans dans les secteurs hautement réglementés de l'aéronautique et de la défense, Simon a acquis une expertise internationale en travaillant au… Read moreRead less
Conseiller principal en DevSecOps, Sécurité Applicative chez Desjardins
Fort d’une carrière de plus de 17 ans dans les secteurs hautement réglementés de l'aéronautique et de la défense,
Simon a acquis une expertise internationale en travaillant au Canada, aux États-Unis, au Mexique.
No Profes. Pic

