On Tuesday 1 October 2024, the first day of TechEx Europe at the RAI in Amsterdam, I went to the Cyber Security & Cloud Expo stage. The banner at Entrance C listed the expos sharing the halls that year: IoT Tech, AI & Big Data, Digital Transformation, Cyber Security & Cloud, Edge Computing, Intelligent Automation, Unified Communications and Data Centre.
The session this post is about was Puppetās keynote on DORA and NIS2. The timing made it relevant. According to the EUR-Lex texts, member states had to transpose NIS2 (Directive (EU) 2022/2555) by 17 October 2024, with the measures applying from 18 October. DORA (Regulation (EU) 2022/2554) applied from 17 January 2025. So the keynote landed about two weeks before the NIS2 deadline and three and a half months before DORA applied.

A morning session at the Cyber Security & Cloud Expo. Most of the audience wore headphones to follow the talk.
āConfidence as Codeā
The table card at the stage gave the full title: āConfidence as Code: DORA, NIS2, and a New Vision for Desired State & DevOps Data Managementā, a keynote from 12:20 to 12:50 by Tzvika Shahaf, Vice President of Product Management at Puppet by Perforce. The cardās tagline summed up the pitch: āRisk is growing. Security is shifting left. Agility remains essential.ā
He started from the regulations. The slide āEnforcement of Evolving Compliance Regulationsā put NIS2, DORA and GDPR in the foreground, with CIS Benchmarks, the NIST Cybersecurity Framework, ISO 27001 and PCI DSS behind them. The two problems underneath were:
- complying with more than one regulation at once and implementing a secure configuration baseline;
- automatically enforcing configurations that comply with security standards.

NIS2, DORA and GDPR on one slide, with the frameworks that turn them into concrete settings below.
The point is that none of these regulations tells you which sshd_config line to change. The frameworks below them do. A desired-state tool earns its place by turning that baseline into code and applying it everywhere, continuously.
Three incidents from 2024
The middle of the talk used three recent events to show why āconfigure onceā isnāt enough.
XZ Utils. The slide āVulnerabilities Often Demand Rapid Responseā showed the XZ Utils backdoor, CVE-2024-3094, and listed three steps: scanning for exposure across all systems to evaluate risk, automatically remediating to a secure configuration, and monitoring for future exposure.

Scan, remediate, monitor: the XZ Utils example.
CrowdStrike. āManage Software Releases and Patches at Scaleā put a photo of a blue-screened airport display next to CrowdStrikeās tech alert of 19 July 2024 about Windows hosts crashing because of the Falcon sensor. The alertās workaround was manual: boot each host into Safe Mode or the Windows Recovery Environment, go to the CrowdStrike driver directory, and delete the file matching C-00000291*.sys. The slideās title put the emphasis on releases as much as on the fix. If you canāt control how fast a change reaches your whole estate, you canāt control how fast a bad change does either.

The July 2024 CrowdStrike outage as a patch-management case.
Log4Shell coming back. āBeware! Vulnerabilities Often Reappearā was the slide I found most useful. It said configuration drift and manual changes reintroduce previous vulnerabilities, so you have to constantly check for and remediate drift. The supporting number, credited on the slide to Cybersecurity Dive: 29% of assets showed recurrences of Log4Shell despite previously achieving full remediation.

Drift brings vulnerabilities back. Thatās the argument for continuous enforcement.
Interhyp: compliance with a click
The customer story was Interhyp, which the slide described as the largest broker of residential mortgages in Germany, so a business in a highly regulated sector. Its three outcomes were one-click change details with continuous delivery and configuration management, self-service documentation replacing manually written records, and strict compliance met in financial services. Puppetās Interhyp case study adds the details: 20 to 30 changes a day, Puppet Enterprise Continuous Delivery connected to ServiceNow so change records are generated automatically, and a migration from open source Puppet to Puppet Enterprise.
For DORA, that ServiceNow link matters more than the configuration language. An auditor wants to see what changed, on which system, and who approved it. Generating that record from the pipeline means itās complete by default.
Infrastructure and data in one pipeline
The second half explained the āDevOps Data Managementā part of the title. The āFull Stack DevOps Pipelinesā slide had two branches. Infrastructure led to automatic desired state, vulnerability management and observable infrastructure. Data led to virtualisation, data masking and automatic real data.

Desired state for servers and masked, virtualised data for test environments in the same pipeline.
A āSecure by Design (Shift Left)ā slide followed, with the DevSecOps loop and two goals: ensure data and infrastructure follow security best practices, and integrate security practices into development and operations. The summary slide listed six capabilities: automation of security configuration and patch management, on-demand test data management, DevSecOps practices for integrated security, compliance across diverse systems, rapidly repaving infrastructure and refreshing data, and continuous monitoring and remediation of security risk.
My take: I work mostly with Ansible, so I came to this talk with a different tool in mind, and the argument still held. The regulation doesnāt care whether an agent enforces the baseline every 30 minutes or a scheduled job runs a playbook. It cares that you can show the baseline, show itās enforced, and show what changed. I covered the Ansible side of that in DORA Compliance Automation with Ansible. The drift slide is the one Iād show a CISO, because it explains why a one-off hardening project doesnāt count as compliance.
On the expo floor: Couchbase and vector search
Before the keynote I recorded a short conversation at the Couchbase stand in the AI & Big Data Expo with someone from the Couchbase team who said heād been with the company for nine years. He described Couchbase as a scalable database platform that also covers mobile, and argued that AI applications need that kind of scalable, high-performance data layer. When I asked about retrieval-augmented generation, he confirmed that vector search was now part of the product and described it as a recent addition, with customers already testing it for AI use cases. He also pointed to a free trial of Capella, Couchbaseās database-as-a-service. Couchbaseās vector search announcement from February 2024 covers Capella, Couchbase Server 7.6 and Couchbase Lite.
A year later
Early that morning I took a selfie at the āThank you for attending! Join us in 2025ā wall, which listed the next editions: London on 5 and 6 February 2025 at Olympia, California on 4 and 5 June 2025 at the Santa Clara Convention Center, and Amsterdam on 24 and 25 September 2025 back at the RAI.

The 2025 dates. I took the hint.
I did go back a year later, and spent the second day of TechEx Europe 2025 recording interviews at the booths. Theyāre in TechEx Europe 2025: Eight Booth Interviews in Amsterdam.