Live webinar · Wednesday, October 14 · 9:00am PT / 12:00pm ET

Welcome to the Island of Misfit Stacks

A live supply chain compromise on the stacks regulated industries run.

Andrew Martin
Presenter
Andrew Martin
Tim Miller
Host
Tim Miller
Andrew Martin, CEO, ControlPlane, and Tim Miller, Co-Founder & CEO, Kusari

Your build runs on Nix, or Haskell, or Pants, or a monorepo nobody outside the company understands, or the R and MATLAB the research desk refuses to give up.

You've likely sat through the scanner vendor's demo. It works on the sample repo, but then you send them your build and they stop replying.

On October 14, Andrew Martin, CEO of ControlPlane and author of Hacking Kubernetes, compromises a running application live, through a package installed the ordinary way, in a cluster configured like a regulated institution's.

Andy and Tim Miller go through what a build like yours costs you:

  • Days to say whether you have a vulnerability and where, because the scanner never ran on the repo that matters
  • Evaluations that stall before the first scan finishes
  • An audit where the evidence is a spreadsheet
  • A scanner your best engineer wrote because nothing else would run, and now maintains

Tim finds every artifact carrying Andy's package on a Pants monorepo, from source, live. He shows what he'd hand an auditor, opens the fix while you watch, and leaves the merge to your team.

Bring your sticky questions and misfit stacks for the Q&A.

You leave with

  • The recording, whether or not you make it live
  • Three questions to take to your CISO or CTO
  • A one-page summary to hand to your leadership

Speakers

Andrew Martin, CEO, ControlPlane. Author of Hacking Kubernetes.

Tim Miller, Co-Founder & CEO, Kusari. Twenty years running engineering and security for trading systems inside regulated institutions, on builds like yours.

Details

  • Wednesday, October 14, 2026 · 9:00am PT / 12:00pm ET
  • 60 minutes: 45 of walkthrough and discussion, 15 of questions
  • Hosted on Zoom

Who it's for

Written for the people who own product security and know their stack cold: heads of InfoSec, directors of engineering who own AppSec, and security engineering leads at banks, asset managers, insurers, payers, and the SaaS companies that sell to them. Your CISO or CTO is welcome. The walkthrough is for you.