The Salt Conference 2018 brought cloud, security, and infrastructure leaders together to explore real-world threats and scalable defenses. This gathering highlighted operational best practices and emerging research across network security, identity, and cloud platforms.
Attendees reviewed practical case studies, tooling demonstrations, and policy discussions that shaped how teams approach risk and resilience in modern environments.
| Topic | Details | Speaker | Session Type | Key Takeaway |
|---|---|---|---|---|
| Threat Landscape 2018 | Cloud workloads, identity compromise, and container risks | Security Researchers | Keynote | Shared frameworks for detection and response |
| Cloud Security | AWS, Azure, GCP controls and logging | Cloud Architects | Workshop | Policy as code for scalable governance |
| Identity & Access | SSO, federation, and credential hygiene | IAM Practitioners | Talk | Least privilege with continuous verification |
| Incident Response | Playbooks, automation, and forensics | IR Leaders | Panel | Accelerate detection to remediation |
| DevOps Security | CI/CD pipelines, secrets, and testing | Engineering Leaders | Hands-on Lab | Shift-left without slowing delivery |
Networking and Infrastructure Security
Modern network segmentation
Sessions explored zero trust models, micro-segmentation, and secure service meshes tailored for dynamic cloud environments. Teams reviewed traffic visibility, east-west threat detection, and integration with existing tooling.
Observability and detection
Presenters shared telemetry pipelines, log normalization strategies, and correlation playbooks that improve signal quality. Attendees discussed balancing overhead with actionable alerts to reduce noise and improve response times.
Identity and Access Management
Centralized identity strategies
The conference emphasized converged identity platforms, federation standards, and phishing-resistant authentication. Real-world scenarios illustrated how governance, lifecycle automation, and conditional access reduce exposure.
Privileged access and secrets
Content covered vault architectures, just-in-time access, and secure developer workflows. Participants evaluated trade-offs between convenience, compliance, and operational resilience across hybrid infrastructures.
Cloud Security and Compliance
Shared responsibility and controls mapping
Guided discussions clarified responsibilities across SaaS, PaaS, and IaaS models. Teams compared frameworks such as CIS, NIST, and ISO to map controls efficiently across multi-cloud estates.
Audit readiness and policy as code
Use cases demonstrated automated evidence collection, continuous monitoring dashboards, and policy-as-code pipelines. These practices helped organizations streamline audits while maintaining flexible, repeatable deployments.
Threat Intelligence and Incident Response
Threat hunting methodologies
Analysts presented hypothesis-driven hunting, use of threat frameworks, and integration with detection engineering. The sessions linked intelligence to detection rules, improving prioritization and coverage.
Playbooks and automation
Incident commanders shared runbooks, communication templates, and post-incident review practices. Attendees examined orchestration tools that speed containment while preserving forensic integrity and legal considerations.
Operationalizing Salt Conference 2018 Insights
- Review and update detection playbooks based on shared incident response patterns
- Assess identity coverage and enforce least privilege with conditional access policies
- Map cloud workloads to shared responsibility models and control frameworks
- Introduce policy as code into CI/CD pipelines to automate compliance checks
- Establish telemetry baselines and observability metrics for continuous improvement
FAQ
Reader questions
What were the main themes of Salt Conference 2018?
The key themes included cloud security, identity and access management, threat intelligence, incident response, and DevOps security, with a strong focus on practical tooling and policy implementation.
Which organizations were represented at the event?
The audience included security researchers, cloud architects, identity specialists, incident responders, and engineering leaders from technology firms, enterprises, and startups.
How were technical topics delivered during the conference?
Sessions combined keynotes, workshops, hands-on labs, panels, and talks to provide both strategic overviews and detailed implementation guidance.
What outcomes did attendees expect from participating?
Participants sought improved detection and response strategies, clearer policy frameworks, and actionable insights to strengthen their cloud and identity security programs.