Engineer Led Security - Dan Abel - AotB 2026
Dan
Being secure by design: Deep dives and follow-ups

(Title Photo by Peter Conrad on Unsplash)
Dan’s deep dives
Three impossible things before breakfast - Chartering a Security Team
Navigating security challenges: the art of risk register creation
'With Great Power...' Making security documentation that matters
Want secure products? Start your engineers thinking like hackers
Talk References
real life exposures
- Scam alert: why you can’t trust that ‘Booking.com’ message
- What happened in the DoorDash data breach?
- DoorDash scam used fake drivers, phantom deliveries to bilk $2.59M
- M&S warns of £300M dent in profits from cyberattack
- Co-op Cyber Incident
Security Primers
Web security beginner? Start here: OWASP top 10
Integrating Security
GOTO 2015: The Road To Being Rugged (Shannon Lietz) [Slides] [Video]
BSidesSF 2022: Why Security Engineers and Product Managers should be working together [Slides] [Video]
Github: How empowering developers helps teams ship secure software faster
Forbes: Why Organisations Need A Developer-Centric Security Approach
Snowflake: Keeping [security] all together at scale
Organisational Change Backgrounders
(for managing change and team operation)
Use the Team Onion for silo awareness and team boundary understanding
Use the Lippitt-Knoster Model for Managing Complex Change to spot weaknesses in your planning
Operate over People, Process, Technology (and Culture)
Respect and build the invisible-infrastructure that PPT misses