Skip to main content
šŸš€ Taking AI from prototype to production? Find the architecture, GPU, security and governance gaps before they become incidents. Get a Production AI Readiness Assessment
Luca Berton pointing at the TechEx Join us in 2025 wall at the RAI Amsterdam
DevOps

TechEx Europe 2024: Puppet on DORA, NIS2 and Desired State

Puppet's Confidence as Code keynote at TechEx Europe 2024 in Amsterdam: DORA, NIS2, XZ Utils, CrowdStrike, configuration drift and the Interhyp case study.

LB
Luca Berton
Ā· 6 min read

On Tuesday 1 October 2024, the first day of TechEx Europe at the RAI in Amsterdam, I went to the Cyber Security & Cloud Expo stage. The banner at Entrance C listed the expos sharing the halls that year: IoT Tech, AI & Big Data, Digital Transformation, Cyber Security & Cloud, Edge Computing, Intelligent Automation, Unified Communications and Data Centre.

The session this post is about was Puppet’s keynote on DORA and NIS2. The timing made it relevant. According to the EUR-Lex texts, member states had to transpose NIS2 (Directive (EU) 2022/2555) by 17 October 2024, with the measures applying from 18 October. DORA (Regulation (EU) 2022/2554) applied from 17 January 2025. So the keynote landed about two weeks before the NIS2 deadline and three and a half months before DORA applied.

The Cyber Security & Cloud Expo stage at the RAI with an audience in headphones, Day 1 track Hybrid Cloud, DevOps, Cloud Infrastructure & Cloud Security

A morning session at the Cyber Security & Cloud Expo. Most of the audience wore headphones to follow the talk.

ā€Confidence as Codeā€

The table card at the stage gave the full title: ā€œConfidence as Code: DORA, NIS2, and a New Vision for Desired State & DevOps Data Managementā€, a keynote from 12:20 to 12:50 by Tzvika Shahaf, Vice President of Product Management at Puppet by Perforce. The card’s tagline summed up the pitch: ā€œRisk is growing. Security is shifting left. Agility remains essential.ā€

He started from the regulations. The slide ā€œEnforcement of Evolving Compliance Regulationsā€ put NIS2, DORA and GDPR in the foreground, with CIS Benchmarks, the NIST Cybersecurity Framework, ISO 27001 and PCI DSS behind them. The two problems underneath were:

  • complying with more than one regulation at once and implementing a secure configuration baseline;
  • automatically enforcing configurations that comply with security standards.

Slide: Enforcement of Evolving Compliance Regulations, with NIS2, DORA and GDPR badges and CIS, NIST, ISO 27001 and PCI DSS logos

NIS2, DORA and GDPR on one slide, with the frameworks that turn them into concrete settings below.

The point is that none of these regulations tells you which sshd_config line to change. The frameworks below them do. A desired-state tool earns its place by turning that baseline into code and applying it everywhere, continuously.

Three incidents from 2024

The middle of the talk used three recent events to show why ā€œconfigure onceā€ isn’t enough.

XZ Utils. The slide ā€œVulnerabilities Often Demand Rapid Responseā€ showed the XZ Utils backdoor, CVE-2024-3094, and listed three steps: scanning for exposure across all systems to evaluate risk, automatically remediating to a secure configuration, and monitoring for future exposure.

Slide: Vulnerabilities Often Demand Rapid Response, with the XZ Utils Backdoor CVE-2024-3094 graphic and the speaker at the lectern

Scan, remediate, monitor: the XZ Utils example.

CrowdStrike. ā€œManage Software Releases and Patches at Scaleā€ put a photo of a blue-screened airport display next to CrowdStrike’s tech alert of 19 July 2024 about Windows hosts crashing because of the Falcon sensor. The alert’s workaround was manual: boot each host into Safe Mode or the Windows Recovery Environment, go to the CrowdStrike driver directory, and delete the file matching C-00000291*.sys. The slide’s title put the emphasis on releases as much as on the fix. If you can’t control how fast a change reaches your whole estate, you can’t control how fast a bad change does either.

Slide: Manage Software Releases and Patches at Scale, with an airport display showing a blue screen and the CrowdStrike tech alert workaround steps

The July 2024 CrowdStrike outage as a patch-management case.

Log4Shell coming back. ā€œBeware! Vulnerabilities Often Reappearā€ was the slide I found most useful. It said configuration drift and manual changes reintroduce previous vulnerabilities, so you have to constantly check for and remediate drift. The supporting number, credited on the slide to Cybersecurity Dive: 29% of assets showed recurrences of Log4Shell despite previously achieving full remediation.

Slide: Beware! Vulnerabilities Often Reappear, saying configuration drift reintroduces vulnerabilities and 29% of assets showed recurrences of Log4Shell

Drift brings vulnerabilities back. That’s the argument for continuous enforcement.

Interhyp: compliance with a click

The customer story was Interhyp, which the slide described as the largest broker of residential mortgages in Germany, so a business in a highly regulated sector. Its three outcomes were one-click change details with continuous delivery and configuration management, self-service documentation replacing manually written records, and strict compliance met in financial services. Puppet’s Interhyp case study adds the details: 20 to 30 changes a day, Puppet Enterprise Continuous Delivery connected to ServiceNow so change records are generated automatically, and a migration from open source Puppet to Puppet Enterprise.

For DORA, that ServiceNow link matters more than the configuration language. An auditor wants to see what changed, on which system, and who approved it. Generating that record from the pipeline means it’s complete by default.

Infrastructure and data in one pipeline

The second half explained the ā€œDevOps Data Managementā€ part of the title. The ā€œFull Stack DevOps Pipelinesā€ slide had two branches. Infrastructure led to automatic desired state, vulnerability management and observable infrastructure. Data led to virtualisation, data masking and automatic real data.

Slide: Full Stack DevOps Pipelines, with infrastructure and data branches, and the speaker at the lectern

Desired state for servers and masked, virtualised data for test environments in the same pipeline.

A ā€œSecure by Design (Shift Left)ā€ slide followed, with the DevSecOps loop and two goals: ensure data and infrastructure follow security best practices, and integrate security practices into development and operations. The summary slide listed six capabilities: automation of security configuration and patch management, on-demand test data management, DevSecOps practices for integrated security, compliance across diverse systems, rapidly repaving infrastructure and refreshing data, and continuous monitoring and remediation of security risk.

My take: I work mostly with Ansible, so I came to this talk with a different tool in mind, and the argument still held. The regulation doesn’t care whether an agent enforces the baseline every 30 minutes or a scheduled job runs a playbook. It cares that you can show the baseline, show it’s enforced, and show what changed. I covered the Ansible side of that in DORA Compliance Automation with Ansible. The drift slide is the one I’d show a CISO, because it explains why a one-off hardening project doesn’t count as compliance.

Before the keynote I recorded a short conversation at the Couchbase stand in the AI & Big Data Expo with someone from the Couchbase team who said he’d been with the company for nine years. He described Couchbase as a scalable database platform that also covers mobile, and argued that AI applications need that kind of scalable, high-performance data layer. When I asked about retrieval-augmented generation, he confirmed that vector search was now part of the product and described it as a recent addition, with customers already testing it for AI use cases. He also pointed to a free trial of Capella, Couchbase’s database-as-a-service. Couchbase’s vector search announcement from February 2024 covers Capella, Couchbase Server 7.6 and Couchbase Lite.

A year later

Early that morning I took a selfie at the ā€œThank you for attending! Join us in 2025ā€ wall, which listed the next editions: London on 5 and 6 February 2025 at Olympia, California on 4 and 5 June 2025 at the Santa Clara Convention Center, and Amsterdam on 24 and 25 September 2025 back at the RAI.

Luca Berton pointing at the TechEx Join us in 2025 wall listing London, California and Amsterdam dates

The 2025 dates. I took the hint.

I did go back a year later, and spent the second day of TechEx Europe 2025 recording interviews at the booths. They’re in TechEx Europe 2025: Eight Booth Interviews in Amsterdam.

Free 30-min Production AI consultation

Book Now