Roundtable: what to do with fourteen thousand vulnerabilities
A closed-door discussion among security and platform leaders about the vulnerability backlog problem, under Chatham House rules.
- 22 October 2026 · 17:30–20:30 BST (UTC+1)
- Central London (venue confirmed on registration), London
- 2 speakers
What this event covers
Almost every organisation past a certain size has a vulnerability backlog that produces very little completed remediation. This roundtable is a structured discussion of why, and what has actually worked.
Attendance is limited to around eighteen people so the conversation stays a conversation. There are no presentations and no slides.
Held under Chatham House rules: participants may use what they hear, but not attribute it.
What is Roundtable: what to do with fourteen thousand vulnerabilities?
A closed-door discussion among security and platform leaders about the vulnerability backlog problem, under Chatham House rules.
What happens, and when
Informal, food provided.
A ten-minute framing, then open discussion.
What proportion of your backlog is the same finding repeated, and what happened when you fixed the shared cause.
What context actually changed the order, and what engineering teams accepted.
How participants handle the findings they are not going to fix.
Informal continuation for those who want it.
Who is talking
DevOpsArk Security
Security engineering
DevOpsArk
Chair to be announced
Independent chair
Independent
Who should attend
- Heads of security engineering and application security
- Platform leaders who own remediation capacity
- CISOs at organisations with a large service estate
Event questions
Because a roundtable stops being one past about eighteen people. Requests are reviewed to keep a mix of sectors and organisation sizes.
No. The session runs under Chatham House rules and nothing is recorded or attributed.
No. DevOpsArk hosts and participates, but the session is a peer discussion with an independent chair.
Before or after the event
Related modules
Vulnerability Management
From finding to fix, with ownership
Scanners
Image, code, IaC and secret scanning
Security
Posture, policy and continuous verification
Related reading
Vulnerability management: turning a report into a work queue
How to make a twelve-thousand-row vulnerability report actionable: deduplication, exposure-based ranking, ownership and verified closure.
What is DevSecOps? Beyond "shift left"
What DevSecOps means in practice, why shifting left fails when the feedback is not actionable, and the practices that actually change security outcomes.
Container security: the practices that actually reduce risk
Build-time hardening, runtime restriction and supply chain controls for containers, ordered by how much risk each one removes rather than by how often it is mentioned.
Request an invitation
Places are limited. Registration is a short form and we will confirm by email.