We’ll peel back the covers on how we secure the 1000+ microservices and 1500+ deployments per month at HMRC Digital, part of the UK’s tax agency. Security incidents such as Log4Shell and news reports of data leaks are always a risk to digital services. At HMRC Digital we need to take proactive steps to ensure we’re protected from known vulnerabilities and that we’re in a position to react quickly and confidently to incidents as they occur.
We’ll share security insights and lessons learned over the years, including:
- why we created an application security team to proactively search for problems
- how we identify vulnerabilities prior to live deployments
- how we increase buy-in from teams to shift security left
- why leaning on an opinionated tech stack boosts our security position
- how a service catalogue can power security collaboration