Skip to content

Details

20 minutes of in-person meet-and-greet, 10 minutes of Chapter information, then the Presentation!
Note: if attending in person, sign up at https://owasp-austin-2026-september.eventbrite.com)

Presentation:
Is Annual Compliance Dead?
Description:
For two decades, we've treated a passed audit as evidence of a secure company. But a point-in-time audit is a photograph: one frame, captured on one day. Your attack surface, meanwhile, is a film running every minute of the year. Adversaries do not attack on audit day; they attack on day 200, when nobody is looking.
This talk argues that annual, point-in-time compliance is no longer sufficient on its own. As organizations adopt cloud platforms, CI/CD pipelines, and modern security frameworks that increasingly emphasize continuous control operation, the assumptions underlying traditional audit models are rapidly eroding. The ground has already shifted beneath us.
We'll explore what continuous compliance looks like in practice. Not as a massive transformation program or an expensive new platform, but as a discipline of incremental improvement: identifying a control you dread proving, automating part of its evidence collection, and building from there. Over time, a collection of honest, continuously validated controls creates assurance that neither an auditor nor an attacker can easily dispute.

Presenter:
Akash Rajeev Bhatia is a Senior Cybersecurity Analyst specializing in governance, risk, compliance, and application security. With experience spanning security operations and cybersecurity governance, he focuses on practical approaches to improving security and compliance outcomes. Akash also completed a postgraduate program in Artificial Intelligence and Machine Learning in partnership with UT Austin and has a strong interest in applying automation and emerging technologies to cybersecurity challenges

Related topics

Application Security
OWASP
Software Security
Risk Management
Risk Governance and Compliance

You may also like