Program Sikkerhetsfestivalen 2026

Cloud & Security Architecture

Infrastructure as Code Is Still Infrastructure

Tirsdag 10 · HeartBox, Byscenen

EnglishHigh-level 40 min

Kristoffer Hatland

Kristoffer Hatland

Security Architect - mnemonic AS

Kristoffer has worked as a security architect for several years. The last seven years he has focused mainly on cloud security and application security. From his many engagements he has worked with companies helping them secure their cloud infrastructure and their applications.

Human error is not increasing because people are worse.

It is increasing because we deploy things we no longer understand.

The calendar reads 2026 and many organisations are cloud-first, with strict Infrastructure-as-Code policies and a “you build it, you run it” mindset. Standardised landing zones, reusable templates, and pre-built modules allow teams to move fast and scale consistently. Whether these templates come from internal teams, hyperscalers, the community, or major cloud enablers, this approach often works very well. In many cases, things run exactly as intended.

The challenge appears when layers of abstraction accumulate. As systems grow more complex, flawed designs and security-relevant assumptions become harder to spot and harder to reason about. Teams deploy Infrastructure-as-Code they do not fully understand. A configuration that appears safe in a test environment may become insecure once it is promoted to production and exposed to real traffic and real threat actors.

To reduce this risk, organisations introduce policies, guardrails, and verified modules. These controls are necessary, but they have limits. When complex distributed systems are assembled from many interacting modules across cloud services, platforms, and runtimes, guardrails alone are not enough. If we do not understand the resulting infrastructure we are deploying, securing it becomes largely guesswork.

Infrastructure as Code is a powerful abstraction, but it does not remove responsibility. The architecture and the infrastructure are still real, even when hidden behind templates, Kubernetes, containers, or managed services. Working code is not the same as safe infrastructure.

This talk argues that templates and IaC are not a replacement for understanding and skilling. Just because a module works, or can be made to work, does not mean it should be deployed. In an environment where speed is rewarded and abstraction is the norm, rebuilding technical understanding must be treated as a core security control, not an optional nice-to-have.

  1. Sikring i sanntid av sanntidsteknologi for web 1 · Frimurerlosjen, rom 1
  2. OIDC: (In)security by obscurity 1 · Frimurerlosjen, rom 2
  3. Balancing Security, Usability and Performance in Real-World E-Voting 10 · HeartBox ,Teatersalen
  4. Når jussen møter teknologien, og begge møter virkeligheten– Sikkerhetsstyring og etterlevelse i 2026 11- Breiseth, Storlon
  5. Hva kan gå galt når ferga ligger til kai? 2 · Home hotel Hammer, moen nede
  6. Kan vi stole blindt på «smart» teknologi? 2 · Home hotel Hammer, moen oppe
  7. Jeg ble kåret til en av Norges viktigste CISO’er – av en algoritme jeg aldri har møtt 3 · Hvelvet, Gullsalen
  8. Leverandørkjedeangrep sett fra trusselaktørens perspektiv 4 · Kommunestyresalen, Lillehammer rådhus
  9. Spring Cleaning: How AI Took Out a Decade of Identity Debt? 5 · Kulturhuset Banken, Expedisjon
  10. Sikkerhetsloven – neste compliance-sjokk for norsk næringsliv? 5 · Kulturhuset Banken, Festsalen
  11. A Question of When, not If: How Cyber Threats Can Endanger Financial Stability 5 · Kulturhuset Banken, Holbøsalen
  12. Linux under angrep: Hvordan sikre kritiske systemer i møte med moderne trusler 5 · Kulturhuset Banken, Kafeen
  13. Storskala sikkerhet - hvordan verdens største selskaper jobber med IT-sikkerhet 6 · Lillehammer kino, sal 2
  14. Hva skjedde når vi tok med adferdspsykologer inn i kultur-arbeidet? 6 · Lillehammer kino, sal 4
  15. From Chatbots to Autonomous Malware: The Evolution of AI-Powered Threats 9 · Victoria Scandic, sal 1+2
  16. DataOPS - on-prem logg og analyse i stor skala 9 · Victoria Scandic, sal 3