Farshad Abasi
Founder | Application & Pipeline Security Architect | OWASP SPVS Co-Author
Vancouver, Canada
Actions
Farshad Abasi has been building and breaking software systems for nearly three decades, starting in the 80s on a Sinclair ZX Spectrum and never quite losing the curiosity that came with it.
He began his career as a software engineer at Motorola and later as a Senior Software Engineer at Intel before transitioning into security architecture. Farshad spent almost nine years at HSBC Global as a Software Security Architect, gaining deep experience in enterprise architecture, large-scale systems, and regulated environments.
Today, he is the Founder of Forward Security and co-founder of Eureka DevSecOps, where he focuses on application security, cloud security, and securing modern software delivery pipelines. He is also the co-author of the OWASP Secure Pipeline Verification Standard (SPVS) and has taught network and application security for over 20 years.
Farshad has spoken at ISC², LASCON (multiple times), DeveloperWeek, FinTech DevCon, OWASP AppSec events, and several BSides conferences including Vancouver, Calgary, and Toronto.
He remains interested in one persistent question: where security intent diverges from what systems actually become.
Area of Expertise
Topics
Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026
Threat modeling was created for a time when the intended design closely matched what shipped. That is no longer true. Most teams still model what they plan to build, including user flows, design decisions, and evil user stories, but they rarely re-evaluate the model against what is actually deployed. Pipelines continuously uncover real risks through SAST, SCA, DAST, IaC scans, and cloud configuration checks, yet those signals are not fed back into the threat model. This creates a growing blind spot where decisions are based on assumptions instead of production truth.
This session shows how to extend threat modeling beyond design and incorporate evidence from the built system. You will learn how to treat discovered vulnerabilities as inputs that evolve the model and how to update the model continuously without waiting for new platforms. The approach is practical and can be adopted with tools most teams already have.
Securing Software Delivery Pipelines in the Age of AI: Introducing OWASP SPVS
Software delivery pipelines have become one of the most important and most attacked parts of the modern software ecosystem. From source control and build systems to artifact repositories, deployment workflows, and runtime operations, weaknesses in the pipeline can undermine the security of everything that follows.
In this session, Farshad Abasi and Cameron Walters will introduce the OWASP Secure Pipeline Verification Standard (SPVS), a practical framework for assessing and improving the security of software delivery pipelines across the full lifecycle. SPVS helps organizations evaluate pipeline security in a structured way across Plan, Develop, Integrate, Release, and Operate.
The talk will show why pipeline security has to be treated as more than CI/CD hardening. Modern delivery environments now include cloud-native build infrastructure, deployment automation, software supply chain dependencies, and increasingly, AI-assisted and agentic tooling that can influence how software is written, reviewed, built, and shipped. SPVS gives teams a practical model for evaluating governance, trust boundaries, permissions, verification, and operational controls across that entire system.
Attendees will leave with a clear understanding of where SPVS fits in a modern AppSec and DevSecOps program, why pipeline security deserves to be treated as a first-class discipline, and how to use SPVS as a roadmap for improving delivery security maturity in real-world environments.
Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026
Most teams threat model what they intended to build, not what is actually deployed. This talk exposes that blind spot and shows how to extend threat modeling beyond design by incorporating real SAST, SCA, DAST, IaC, and cloud findings.
OWASP LASCON 2026 Sessionize Event Upcoming
WeAreDevelopers World Congress 2026 - North America Sessionize Event Upcoming
Farshad Abasi
Founder | Application & Pipeline Security Architect | OWASP SPVS Co-Author
Vancouver, Canada
Actions
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top