Join the Open Cloud Security Community

8 April, 2025 9:00 am - 1:00 pm (PT)

The Open Cloud Security movement is not just about protecting systems and data, it's about building a foundation of trust and resilience that spans across enterprises, public organizations, small businesses, cloud security community of practitioners and individual users globally.

  • Trust & Resilience

  • Global Community

  • Collaborative Security

Empowering a Secure and Trustworthy Cloud Ecosystem

We are dedicated to fostering a secure and trustworthy cloud ecosystem for enterprises, public organizations, small businesses, and individual users globally. Our mission is to promote collaboration and knowledge sharing to enhance cloud security and resilience.

Agenda

All Timings are in PT

Agenda

time icon04/08/2025 09:00 am to
09:05 am

Welcome & Opening Remarks

speaker headshot

Toni de la Fuente
Prowler

A brief introduction to the conference, the mission of Open Cloud Security, and what to expect from today’s sessions.

time icon04/08/2025 09:05 am to
09:25 am

The Future of Open Security

speaker headshot

Gabriele Columbro
Linux Foundation Europe

Open-source security is evolving—what does that mean for defenders? Gab Columbro will share insights on the state of open-source security, its impact on cloud security practitioners, and how we can build more resilient security ecosystems together.

time icon04/08/2025 09:25 am to
09:45 am

Server Side Chat: Open Source & Cloud Security

speaker headshot

Shay Banon
Elastic

speaker headshot

Toni de la Fuente
Prowler

A Server Side Chat on where we are, where we’re headed, and what really matters in open cloud security. Expect real talk about security challenges, open-source innovation, and the future of cloud security.

time icon04/08/2025 09:45 am to
10:05 am

A Pentester's Guide to Finding Misconfigurations at Scale

speaker headshot

Sandeep Singh
ProjectDiscovery

Cloud misconfigurations are among the most exploited attack vectors today. In this session, Sandeep Singh from ProjectDiscovery shows how open source tools like Nuclei and Subfinder can automate and scale cloud pentesting across AWS and multi-cloud environments. Learn how to uncover misconfigurations, identify weak IAM roles, and embrace open methodologies for more transparent and effective cloud defense.

time icon04/08/2025 10:05 am to
10:25 am

Survey Says: Open Wins

speaker headshot

Rajiv Taori
Prowler

speaker headshot

Laura Franzese

Based on new survey data from over 650 security practitioners, this session explores how teams are adopting open cloud security tools to improve visibility, reduce breaches, and lower costs. Rajiv and Laura will share insights on where organizations are thriving—and where they’re still struggling—with automation, compliance, and cloud complexity.

time icon04/08/2025 10:25 am to
10:45 am

How We Saved $70,000 Per Year with Our Open-Source Private Cloud CA

speaker headshot

Paul Schwarzenberger
Q-Solution

Faced with high costs from AWS Private CA, Q-Solution—providers of managed services to the UK government—built an open-source, serverless certificate authority for under $5/month per environment. This session covers the technical design, a live demo of the CA in action, and lessons from deploying it for a secure, accredited UK government community. Learn how you can use this lightweight solution to enable mTLS for cloud-native applications.

time icon04/08/2025 10:45 am to
11:05 am

DockSec: AI-Powered Docker Security for Cloud-Native Environments

speaker headshot

Advait Patel
Broadcom

As container adoption grows, so do the risks—misconfigurations, vulnerabilities, and supply chain threats. In this session, you’ll learn how DockSec, an open-source AI-powered Docker Security Analyzer, helps detect issues, enforce best practices, and integrate real-time remediation into CI/CD pipelines. See how GPT-powered analysis enhances traditional tools like Trivy, Hadolint, and Docker Scout. Ideal for DevSecOps engineers, SREs, and cloud security teams. Includes a live demo and practical tips for integrating DockSec into GitHub Actions, Jenkins, and VS Code.

time icon04/08/2025 11:05 am to
11:35 am

NETWORKING BREAK

time icon04/08/2025 11:35 am to
11:55 am

Open Sourcing Cloud SOC - Security is for Everyone!

speaker headshot

Urvesh Thakkar
Circles.Life

Learn how to set up a full-featured cloud Security Operations Center (SOC) using open source tools—covering SIEM, CSPM, EDR, and SOAR—with little to no cost. This session walks through practical integrations and architecture patterns for small teams looking to monitor threats in the cloud without the price tag of traditional SOC solutions.

time icon04/08/2025 11:55 am to
12:15 pm

The Power of Composability: Building Security through Open Source Ecosystems

speaker headshot

Nathan Wallace
Turbot

Security tools are stronger when we build together. This talk explores how composable architectures—like those behind Steampipe, Powerpipe, Tailpipe, and Flowpipe—enable sharing of queries, detections, and controls across teams and tools. Learn practical patterns for assembling open source building blocks to solve complex multi-cloud security challenges and create a more collaborative, scalable security ecosystem.

time icon04/08/2025 12:15 pm to
12:35 pm

Incorporating End to End Integration Testing into your Detection Engineering Workflow

speaker headshot

Ariel Ropek
Panther Labs

This session explores how modern detection teams are moving beyond unit tests to adopt end-to-end testing strategies. Learn how to simulate attacks, capture real telemetry, and validate full detection pipelines to improve reliability and reduce false confidence. A must-attend for detection engineers looking to level up their testing practices.

time icon04/08/2025 12:35 pm to
12:55 pm

Securing Multi-Cloud in the Open with Prowler

speaker headshot

Toni de la Fuente
Prowler

At the heart of the Open Cloud Security movement, Prowler is helping teams secure AWS, Azure, GCP, and Kubernetes using fully open-source tooling. In this session, Prowler engineers will dive into how the tool scales across complex environments, supports compliance-as-code, and integrates into DevSecOps pipelines. You’ll also get a first look at the upcoming roadmap—and how the community is shaping the future of open cloud security.

time icon04/08/2025 12:55 pm to
01:00 pm

Closing Remarks

speaker headshot

Toni de la Fuente
Prowler

Frequently Asked Questions


Yes, you’ll need to fill out our registration form to gain access to the event. Please fill in the registration form with some basic information to get started.
The information you provide upon registration will only be used to establish you as a user on the platform and to create your login credentials. It will not be used for any other purposes.
Yes, the vFairs platform is compatible with any computer or mobile device and any browser.
Yes, this event is completely free to attend.
The event will be on demand till 8 May 2025, however we may make updates and changes to the platform periodically. Make sure to keep checking back in to see our newest features in action!