Conference Description
Key Takeaways
- Two-day application security conference in Porto, Portugal, attracting over 400 attendees
- Focus on defending against AI-powered attacks, cloud vulnerabilities, and evolving threat landscapes
- Technical programme includes workshops, keynotes, hands-on sessions, and a Capture The Flag competition
- Covers secure software engineering, DevSecOps, API security, threat modelling, and governance
- Designed for security professionals, developers, architects, and technology leaders
Introduction
OWASP AppSec Days Portugal 2026 returns to Porto as the country’s principal gathering for application security practitioners. The two-day conference addresses the technical and strategic challenges facing organisations as they secure software against increasingly sophisticated threats, including those leveraging artificial intelligence. With cloud adoption accelerating and development pipelines becoming more complex, the event provides a timely forum for examining defensive strategies that span code, infrastructure, and governance.
About This Event
Organised under the OWASP banner, AppSec Days Portugal brings together more than 400 security professionals, software developers, architects, researchers, and technology leaders. The programme combines hands-on workshops with keynote presentations from international experts, technical breakout sessions, and a Capture The Flag competition that allows participants to test offensive and defensive skills in a controlled environment. Social events throughout the conference encourage informal knowledge exchange and community building within the Portuguese and broader European AppSec ecosystem.
Securing Software in an Era of AI-Driven Threats
A central theme of the 2026 edition is the emergence of AI-powered attack techniques. Adversaries are increasingly using machine learning to automate vulnerability discovery, craft convincing phishing campaigns, and evade traditional detection mechanisms. Sessions examine how security teams can adapt their tooling and processes to counter these capabilities while also exploring the secure integration of AI components into their own applications. The discussion extends to cloud environments, where misconfigurations and identity management weaknesses remain persistent sources of compromise.
Core Technical Topics
The conference agenda spans the full application security lifecycle. Secure software engineering sessions address coding practices, dependency management, and the integration of security checks into continuous integration and delivery pipelines—commonly referred to as DevSecOps. Dedicated tracks cover API security, mobile application hardening, and threat modelling methodologies that help teams identify risks early in the design phase. Governance and risk management content provides guidance on building security programmes that align technical controls with business objectives and regulatory requirements.
Industry Context
Application security has moved from a specialist concern to a board-level priority as organisations face mounting regulatory scrutiny and reputational risk from breaches. The European Union’s evolving cybersecurity directives place greater accountability on software producers and operators, making secure development practices a compliance imperative as well as a technical one. At the same time, the shift toward cloud-native architectures and microservices has expanded the attack surface, requiring security teams to rethink traditional perimeter-based defences in favour of identity-centric and zero-trust models.
Who Should Attend
The event is designed for practitioners who build, test, or govern software security. Security engineers and application security specialists will find deep technical content, while software developers and DevOps engineers can learn how to embed security into their workflows without sacrificing velocity. Architects benefit from sessions on secure design patterns and threat modelling, and technology leaders—including CISOs, CTOs, and IT managers—gain strategic insight into programme development and risk prioritisation. Researchers and academics contribute to and benefit from the exchange of emerging techniques and empirical findings.
Supporting Organisations
The conference draws sponsorship from a cross-section of the security industry. Participants include Devoteam Cyber Trust, Integrity, NOS, Cloudflare, Palo Alto Networks, Snyk, Thales Cyber, Checkmarx, Blaze Information Security, Kuehne+Nagel, Siemens Energy, Xygeni, Celfocus, Infineon, Jscrambler, DM Advisory, Porto Business School, and Claranet, alongside several community sponsors. Their involvement reflects the breadth of stakeholders invested in advancing secure software development, from cloud infrastructure providers and application security tooling vendors to consultancies and academic institutions.
Conclusion
OWASP AppSec Days Portugal 2026 offers a concentrated opportunity to engage with the techniques, tools, and strategic thinking required to defend modern software. For professionals navigating the intersection of rapid development, cloud complexity, and AI-augmented threats, the conference provides both practical guidance and a community of peers facing similar challenges.

