Cover Image for The Claude Code Security Summit
Cover Image for The Claude Code Security Summit
Avatar for Packt Publishing
Presented by
Packt Publishing

The Claude Code Security Summit

Virtual
Get Tickets
Ticket Price
$149.00
Per ticket
Tickets
1
About Event

Reserve your place: Registration details will be announced shortly. Seats for the live virtual summit will be limited.

Build with coding agents. Validate like an attacker. Govern for production.

Jim Manico

Founder, Manicode Security | OWASP Standards Leader

Jim has spent more than 15 years training developers, architects and security engineers worldwide. He leads OWASP AISVS, OWASP ASVS, the OWASP Cheat Sheet Series and OWASP Proactive Controls, and is a former OWASP Global Board member, Java Champion and author of Iron-Clad Java.

Vandana Verma

Security Relations Leader, Snyk | Former OWASP Global Board Member

Vandana brings more than 19 years of cybersecurity experience and is a global AppSec speaker, trainer and community leader. She runs OWASP AppSec Days India and supports initiatives including InfosecGirls, InfosecDiversity and InfosecKids. She has trained more than 90,000 citizens in cyber awareness.

Katie Paxton-Fear

Staff Security Advocate, Semgrep | Ethical Hacker and Security Researcher

Katie is a former developer who now specializes in breaking applications. She combines practical API and application-security expertise with developer education and vendor-neutral strategy. Her session on hacking systems from the military to AI was voted a top session at RSA.

Michael Shost

Enterprise Transformation and Cybersecurity Executive

What Makes This Summit DifferentMichael has more than 25 years of experience leading enterprise transformation and created the Agentic AI-Driven Enterprise Delivery Model. He is an international best-selling author, LinkedIn Top Voice, Certified Chief Information Security Officer and Certified Ethical Hacker.

1. Build SECURITY.md and CLAUDE.md from scratch and use them to constrain generated code.

2. Compare the same feature built with and without specifications to expose the security difference.

3. Run a model-led validation loop against explicit requirements.

4. Attack an AI-generated API or application, trace the root cause and verify a secure fix.

5. Map a coding-agent workflow that uses MCP, demonstrate one abuse path and apply practical guardrails.

Speakers6. Walk through an enterprise approval flow covering vulnerability remediation, threat modeling, documentation and human sign-off.

1. Create and connect REQUIREMENTS.md, ARCHITECTURE.md, SECURITY.md and CLAUDE.md for an AI-assisted project.

2. Turn a feature request into a small, deterministic coding-agent task with testable acceptance and security criteria.

3. Define the automated test, security and human-review gates required before generated code can progress.

4. Attack an AI-generated application, trace a finding to its root cause and convert the fix into a regression requirement.

5. Map a coding-agent or MCP workflow across identities, tools, data, permissions and third-party trust boundaries.

Planned Live Demonstrations6. Draft an approval checklist that states acceptable autonomy, mandatory human decisions and minimum production evidence.

Primary audience

1. Software developers and application engineers using Claude Code or other coding agents

2. Application Security and Product Security engineers reviewing AI-generated code

3. DevSecOps and Platform Security teams implementing delivery and approval controls

4. Security engineers and ethical hackers validating AI-generated applications

5. Engineering managers and technical leads responsible for AI-assisted delivery

Also valuable for

1. AI Security engineers and coding-agent platform owners

2. CISOs, Heads of Security and technology risk leaders

3. Security consultants and technical educators

4. Governance, compliance and enterprise transformation professionals

What You Will Be Able to Do After the SummitThis is a technical, practitioner-led event built first for the people creating, testing and approving AI-assisted software. You do not need to be an expert in every standard or agent framework, but you should understand modern software delivery and be ready to examine real workflows, code and security decisions.

Most teams are already experimenting with AI coding tools. The harder transition begins when those tools can inspect a repository, generate changes across multiple files, invoke external tools, remediate findings and produce work that appears ready to ship.

At that point, prompting skill is not enough. Teams need machine-readable requirements, scoped tasks, automated tests, security checks, adversarial validation, least-privilege tool access, audit evidence and human approval at the decisions that carry real impact.

Who This Is Built ForThis summit brings those controls into one connected, vendor-neutral programme. You will see how secure AI coding works before generation, during implementation, under attack, inside coding-agent workflows and at enterprise scale.

AI is no longer just suggesting code.

It can build the feature, review the pull request, remediate the vulnerability and take the next action.
That speed is extraordinary. But when the same system can create, evaluate and act on software, one question becomes impossible to ignore: who is setting the security boundaries?

Without enforceable requirements, security gates and clear human ownership, coding agents can reproduce insecure patterns, expose sensitive tools and data, and push convincing but unverified changes toward production at machine speed.

The Claude Code Security Summit is a six-hour, multi-speaker virtual event for developers and security practitioners who want more than another AI coding demonstration or vendor pitch. Across four connected, practitioner-led sessions, attendees will move from machine-readable security requirements to adversarial testing, coding-agent and MCP controls, and enterprise-ready governance.

Why This Event Matters NowThe practical promise: Learn how to create a security-requirements stack, test AI-generated code like an attacker, map coding-agent and MCP trust boundaries, and define the evidence required before AI-assisted software reaches production

1. Independent and vendor-neutral: the programme is designed around practitioner decisions, not a product sales narrative.

2. One connected six-hour story: specify securely, build, attack and validate, control the coding agent, then govern enterprise adoption.

3. Live demonstrations that show the requirements, generated code, weakness, attack path, remediation and approval gate.

4. A practitioner-first faculty spanning secure development standards, ethical hacking, AppSec education and enterprise governance.

5. Practical outputs you can adapt immediately: requirements files, test gates, trust-boundary maps, threat models and approval checklists.

Avatar for Packt Publishing
Presented by
Packt Publishing