Web Banner
Back to Pre-Conference Training Page

Back to Conference Home Page

Assess and Improve Your AppSec Programme using OWASP SAMM

One-Day Interactive (Classroom) Training - OWASP New Zealand Day 2026

Abstract

Incorporating a mix of lectures and workshops, this training delivers an in-depth view of and practical implementation of the OWASP Software Assurance Maturity Model (SAMM). SAMM provides an effective and measurable way for organisations to analyze and improve their software security posture.

Course Details

Dates: Tuesday, 1 September 2026

Time: 8:45 a.m. to 5:30 p.m. (NZDT)

Instructor: John DiLeo, Application Security Lead, Gallagher Security

Course Fee: NZ $450.00 (plus GST and ticketing fees)

Registration Site: https://events.humanitix.com/owaspnz2026-training

Course Description

Building security into the software development and management practices of an organisation can be a daunting task. There are many elements to the equation: organisation structure, different stakeholders, technology stacks, tools and processes, and so forth. Implementing software assurance can have a significant impact on the organization. Yet, trying to achieve this without a good framework is most likely leading to just marginal and unsustainable improvements. OWASP SAMM gives you a structural and measurable framework to do just that. It enables you to formulate and implement a strategy for software security that is tailored to the risk profile of your organisation.

The goal of this one-day training, which is conceived as a mix of presentations and interactive workshops, is for the participants to get a more in-depth view of, and practical feel for, the OWASP SAMM model. The training is set up in three parts:

In case you haven’t started a secure software initiative in your organisation yet, this training should provide you with the necessary foundations and ideas to do so. Be prepared for the highly effective and applicable treatment of this large domain!

And, in case you would be concerned about confidentiality issues, we adhere to the Chatham House Rule.

Course Topics

Part One: SDLC Overview and OWASP SAMM Introduction

Part Two: Applying OWASP SAMM

Part Three: OWASP SAMM Tools

Part Four: OWASP SAMM Best Practices

Your Instructor

Photo of John DiLeo

Dr. John DiLeo leads the OWASP New Zealand Chapter. In his day job, John is the Application Security Lead at Gallagher Security in Hamilton. Before joining Gallagher, John led the Application Security Services team at Datacom, providing support and guidance to clients in launching, managing, and maturing their enterprise software assurance programs.

Before turning to full-time roles in security, John was active as a Java enterprise architect and Web application developer. In earlier lives, John has been a full-time professor and had specialized in developing discrete-event simulations of large distributed systems. Twitter: @gr4ybeard