Loading…
24 June 2025 | London, England
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source in Finance Forum London 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in British Summer Time. To see the schedule in your preferred timezone, please select from the drop-down at the bottom of the menu to the right.
Venue: Gielgud clear filter
arrow_back View All Dates
Tuesday, June 24
 

11:00 BST

DORA: How To Balance Compliance With Innovation - Monica Sasso, Red Hat
Tuesday June 24, 2025 11:00 - 11:30 BST
The Digital Operational Resilience Act (DORA) is a game-changer for the EU financial services industry, establishing uniform ICT risk management, incident reporting, and third-party risk regulations. Unlike previous sector-specific frameworks, DORA mandates a horizontal implementation across entire firms, ensuring a ‘Minimum Viable Bank’—continuity of critical services amid disruption.
DORA aligns with the financial sector’s shift toward decentralised technology models, where hybrid cloud adoption has introduced operational complexity. While regulatory compliance may seem burdensome, DORA presents an opportunity: fostering a tech-first mindset, enhancing resilience, and driving strategic modernization. However, challenges remain—smaller firms may struggle with costly penetration testing, while managing fourth- and fifth-party risks requires increased supply chain visibility.
A successful DORA implementation hinges on open hybrid cloud platforms, enabling interoperability, scalability, and AI-driven innovation. Rather than a regulatory checkbox, DORA should be seen as an industry-wide resilience strategy, securing financial services for the future.
Speakers
avatar for Monica Sasso

Monica Sasso

Global Financial Services Digital Transformation Lead, Red Hat
Monica supports customers in adopting open source & hybrid cloud for business transformation, focusing on digital transformation, operational resilience, and compliant infrastructure. As the Asset & Wealth Management business lead, she brings experience from top global firms like... Read More →
Tuesday June 24, 2025 11:00 - 11:30 BST
Gielgud

11:40 BST

K8s vs. Agent Smith: Exploding GPUs and the AI Readiness Governance Framework - Andrew Martin, ControlPlane
Tuesday June 24, 2025 11:40 - 12:10 BST
In a broad and detailed appraisal of end-to-end AI security for FINOS members we examine how to run LLM agent workloads on Kubernetes using the AI Readiness Governance Framework — without getting lost in the Matrix.

GPU megaclusters, operationalising LLM agnents at scale, and securely deploying GPU-bound workloads are covered, with real-world experience in some of the world's most complex deployments with the industry's latest, bleeding-edge offensive and defensive tooling.

In this talk we:
- enumerate the threats and controls in the AI Readiness Governance Framework with real infrastructure and examples, and examine how they fix FSI concerns
- investigate how to attack and defend against a range of historical and current AI CVEs, both with the FINOS AI Readiness and FINOS CCC/CFI projects
- analyse where misconfigurations and advanced threats are at the greatest risk and impact to your AI systems
- introduce AI Red Teaming and our work in the OpenAI Red Teaming Network
- look at the future growth and ambitions of the governance framework, and at how other critical FINOS projects intersect to support the mission
Speakers
avatar for Andrew Martin

Andrew Martin

CEO, ControlPlane
Andrew has an incisive security engineering ethos gained building and destroying high-traffic web applications. Proficient in systems development, testing, and operations, he is at his happiest profiling and securing every tier of a cloud native system, and has battle-hardened experience... Read More →
Tuesday June 24, 2025 11:40 - 12:10 BST
Gielgud

12:20 BST

Cloud Compliance vs. Cost Efficiency: Can Fintech Have Both? - Kate Obiidykhata, Percona
Tuesday June 24, 2025 12:20 - 12:35 BST
Regulated fintech organizations must ensure compliance with stringent data regulations while maintaining cost efficiency in the cloud. However, compliance-driven choices—such as data residency requirements, encryption mandates, and audit logging—can lead to hidden costs, especially in cloud storage and database management. This talk breaks down how cloud adoption impacts database architectures in fintech, why public cloud pricing models often penalize compliance-heavy workloads, and how open-source database solutions can help financial organizations regain control over performance, security, and cost.
Speakers
avatar for Kate Obiidykhata

Kate Obiidykhata

Senior Product Manager, Percona
Senior Product Manager with 9 years of experience in the open-source technology industry, leading projects such as AlmaLinux, Kubernetes Operators, and Everest - a cloud-native database management platform.
Tuesday June 24, 2025 12:20 - 12:35 BST
Gielgud

12:35 BST

Taming Multi-Cloud Security: Progress on Common Cloud Controls - Michael Lysaght, Citi & Sonali Mendis, Scott Logic
Tuesday June 24, 2025 12:35 - 12:50 BST
For highly regulated firms, aligning security and compliance in the cloud is a persistent challenge. The FINOS community has been tackling this issue head-on, defining technology-specific control catalogs informed by security frameworks and regulations, while enabling automated compliance validation and compliant delivery mechanisms.

Join two project maintainers of the Common Cloud Controls (CCC) project as they showcase how it streamlines the creation of threat-informed controls and integrates them into reusable assets via the Compliant Financial Infrastructure (CFI) project. This session will provide insights into building scalable, open-source security controls that help financial institutions accelerate cloud adoption while maintaining regulatory compliance.

Who should attend? Leaders and individual contributors in compliance, security, and cloud infrastructure who are looking to bridge the gap between governance requirements and real-world cloud implementations.
Speakers
avatar for Michael Lysaght

Michael Lysaght

Head of Global Threat-Informed Defense Engineering, Citi
Michael is the Head of Citi's Global Threat-Informed Defense Engineering team, where he leads a global team of engineers focused on delivering protective, detective, and responsive security controls across Citi's cloud environments. Passionate about bridging the gap between security... Read More →
avatar for Sonali Mendis

Sonali Mendis

Senior Software Developer, Scott Logic
Sonali is a Senior Developer at Scott Logic, where she leverages 14 years of experience across cloud, backend, mobile, and enterprise applications to deliver high-impact solutions for clients. Passionate about open-source contributions, she actively engages in community-driven projects... Read More →
Tuesday June 24, 2025 12:35 - 12:50 BST
Gielgud

14:05 BST

CALM - Architecture Lifecycle Management - Konadu Appiah & Joseph Brown-Pobee, Turntabl.io
Tuesday June 24, 2025 14:05 - 14:20 BST
Lightening talk showcasing an architects persona using CALM (Common Architecture Language Model).

CALM enables software architects to define, validate, and visualize system architectures in a standardized, machine-readable format, bridging the gap between architectural intent and implementation.

CALM aims to move architecture beyond static diagrams by providing a common language that both humans and machines can understand, ensuring that architectural decisions are consistently applied and easily auditable.

Speakers
avatar for Konadu Appiah

Konadu Appiah

Software Engineer, Turntabl.io
TBD.
avatar for Joseph Brown-Pobee

Joseph Brown-Pobee

Software Engineer, Turntabl.io
TBD.
Tuesday June 24, 2025 14:05 - 14:20 BST
Gielgud

14:30 BST

Platforms for Secure API Connectivity With Architecture as Code - James Gough, Morgan Stanley
Tuesday June 24, 2025 14:30 - 15:00 BST
As microservices and complex platforms become the standard, ensuring secure connectivity while maintaining a smooth developer experience is a significant challenge. Traditional security models often introduce friction, slowing down innovation and deployment. Regulated industries must balance stringent security controls with the need for agility.

In this session, you will learn how Architecture as Code with CALM, an open-source initiative from FINOS, provides a structured approach to defining Patterns and Architectures that incorporate security and resilience from the start. You will see how CALM CLI can generate and validate architectures against predefined patterns, ensuring security compliance without compromising developer experience.

Through a live demo, you will observe how an initial deployment lacks security and how a threat model can be applied to highlight vulnerabilities. You will then learn how controls enforce security requirements, including Zero Trust principles to lock down the cluster. Finally, you will discover CalmHub and the Visualizer, tools that help review and maintain architectures over time.
Speakers
avatar for James Gough

James Gough

Distinguished Engineer/Executive Director, Morgan Stanley
API Platform Lead Architect at Morgan Stanley working on APIs, security, and developer experience. A Java Champion, author, and conference speaker, Jim has contributed to the Java Community Process, co-authored Mastering API Architecture and Optimizing Cloud Native Java (O’Reilly... Read More →
Tuesday June 24, 2025 14:30 - 15:00 BST
Gielgud

15:15 BST

Learning To Trust Again: How Open Source Can Be Leveraged in Highly Regulated Industries - Liam Follin, KPMG
Tuesday June 24, 2025 15:15 - 15:45 BST
In the highly regulated world of financial services, trust is paramount. This talk explores how internal teams can trust open-source software (OSS) to provide a compliant financial infrastructure, using romantic comedies as analogies. Just as trust in relationships is built over time, so too is trust in technology, especially where compliance, security, and risk management are critical. We'll cover the basics of OSS, its transparency, and community-driven development, likening it to the openness seen in films like 'You've Got Mail.' We'll address the trust deficit in regulated industries, highlighting cybersecurity risks and compliance with regulations like GDPR. By adopting OSS, financial institutions can gain greater visibility into their software, allowing for more rigorous security audits and compliance checks. The talk will explore building trust through visible code and peer reviews, and leveraging OSS in industries like healthcare and finance. We'll discuss overcoming adoption barriers, emphasising data privacy, incident response, and community support. Looking to the future, we'll explore how AI and blockchain can enhance OSS security.
Speakers
avatar for Liam Follin

Liam Follin

Lead Penetration Tester, KPMG
Liam is a Lead Penetration Tester and Dual CHECK Team Leader in KPMG's Cyber Defence Services Team. He is also a Chartered Cyber Security Professional under the UK Cyber Security Council. He loves all things pentesting and hacking.
Tuesday June 24, 2025 15:15 - 15:45 BST
Gielgud

15:55 BST

The Rise of Internal Forks: How AI Is Reshaping Code Integration and Its Risks To the Financial Serv - Daniel Forsgren, FossID
Tuesday June 24, 2025 15:55 - 16:25 BST
As financial institutions accelerate their digital transformation, the integration of third-party code has become a necessity—but also a hidden risk. The rise of AI-assisted development is increasing the prevalence of internal forks, where modified external code becomes unmanaged and invisible to traditional security and compliance processes. In a highly regulated industry like financial services, these forks pose significant challenges, including security vulnerabilities, compliance gaps, and technical debt that can impact operational resilience. This session will explore how AI is reshaping software integration, why financial firms must proactively address internal forks, and how modern Software Composition Analysis (SCA) tools can provide much-needed visibility and control. Learn how to leverage AI-driven development while maintaining the highest standards of security, compliance, and risk management.
Speakers
avatar for Daniel Forsgren

Daniel Forsgren

Chief Technology Officer, FossID
Daniel Forsgren drives the technological vision and innovation strategy at FossID. With over two decades of experience in software engineering, product management, and corporate development, he is passionate about advancing open source software management and security. Before joining... Read More →
Tuesday June 24, 2025 15:55 - 16:25 BST
Gielgud
 
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -