This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Why a Proactive Security Approach is Linked to a Constant Cyber Transformation and what are the Benefits for Companies?

Download resources

About this session

Thomas Veynachter, CEO of Neotrust and formerly a cloud and product lead at one of the world's 20 largest banks, walks through a security transformation he led over roughly four years, structured as three phases in a SAFe-based agile methodology. Phase one, about 18 months, built a private cloud with security-by-design baked into every feature through a tiered compliance framework, starting with authentication and secrets management. Phase two scaled the approach from a founding team of about 20 to the bank's full 120-person security organization by launching a dedicated agile release train, watching predictability climb from roughly 10% to 80% across iterations, and turning project managers into SAFe-style 'epic owners.' Phase three matured the work into six independently versioned, API-consumable security products covering incident detection, vulnerability management, secrets, identity and access, data protection and network security, extended to on-premises assets and smaller group entities. He argues the real payoff was not just delivery speed but rebuilt trust, transparency and cross-team pride. Q&A covers keeping remote project managers engaged and adapting the methodology for smaller companies.

Key takeaways

  • Build security-by-design into a platform through a tiered compliance framework (levels 0 to 3) so no feature reaches production without meeting the bar for its criticality.
  • Track sprint predictability explicitly; a team that badly over-commits early (delivering 1 of 10 planned projects) can recalibrate over a few iterations to reach roughly 80% predictability.
  • Turn project managers into SAFe-style 'epic owners' who negotiate dependencies across teams instead of running isolated project plans, which matters even more for remote teams.
  • Package mature security capabilities as versioned, API-consumable products with a public roadmap, so internal client teams can see and influence priorities instead of filing undocumented requests.
  • Pick internal champions who already know the organization to lead a methodology scale-up, rather than relying only on outside methodology experts.

Speakers

Thomas Veynachter
Thomas Veynachter
CEO · Neotrust

Resources

Tags

More from GoSec 2023

Also from Thomas Veynachter

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.