From Policy to Practice: Making Security and Architecture Land on the Work Floor
Aanmelden
From Policy to Practice: Making Security and Architecture Land on the Work Floor
A KNVI Interest Group Architecture session with Martin Knobloch
Date: 27th of October Time: 17:30 – [end time] (walk-in and networking from [time]) Location: [venue / online] Language: English Costs: Free for KNVI members | fee for non-members
About this session
Every organisation has them: architecture principles, security policies, design guidelines. Carefully written, formally approved, and quietly ignored the moment a deadline looms. The gap between what we prescribe and what teams actually do is rarely a knowledge problem. It's a human one.
In this session, Martin Knobloch explores how architecture and security rules actually land on the work floor. Why do well-intended guardrails get bypassed? What makes developers and teams embrace security practices instead of working around them? And what can architects and security professionals do differently, in how they write, communicate, and embed their rules, so that compliance becomes a by-product of good engineering rather than a box-ticking exercise?
The focus is squarely on the human aspect: culture, incentives, trust between security and delivery teams, and meeting engineers where they are. Expect war stories from decades in application security, practical patterns for building security champions and ownership within teams, and a candid look at where the security profession itself gets in its own way.
What you'll take away
Concrete approaches for turning paper policies into lived practice: how to frame rules so teams adopt them, how to build security ownership inside delivery teams, and how to position the architecture and security function as an enabler rather than a gatekeeper. We close with a moderated discussion on experiences from your own organisations.
No security background required, this session is for anyone whose rules need other people to follow them.
About the speaker
Martin Knobloch is VP Security Engineering at Valtech and a long-standing figure in the application security community, with more than 25 years of experience in IT and over 15 in cybersecurity. With a background in Java development, he understands the reality of enterprise software delivery, agile teams, continuous delivery, and deadline pressure, and has spent his career bridging the gap between security ambitions and engineering practice, from awareness to implementation.
Martin has been involved in OWASP since 2006: he served on the OWASP Netherlands chapter board, co-organised the OWASP BeNeLux Day conference, chaired OWASP's Global Education Committee, and served as Chairman of the OWASP Global Foundation Board of Directors. Before joining Valtech he was Global AppSec Strategist at Fortify (OpenText). He is a frequent international speaker on making security work in practice, not on paper.
Programme (TBD)
| Time | Item |
|---|---|
| [time] | Walk-in & networking |
| [time] | Welcome by KNVI Interest Group Architecture |
| [time] | Session: From Policy to Practice |
| [time] | Moderated discussion |
| [time] | Drinks & networking |
For whom
Enterprise, solution, and security architects; CISOs and security officers; engineering leaders; and anyone responsible for making governance, architecture, or security standards work in day-to-day delivery.
This session is organised by the KNVI Interest Group Architecture.