In this talk on Cloud Native Security, we dive deep into how organizations can leverage CNCF best practices to secure modern, cloud-native environments. We cover the full security lifecycle—from integrating security into development, through artifact integrity in distribution, to robust pre-deployment checks and runtime protection. Learn about essential strategies like Zero Trust, defense-in-depth, and shift-left security, and discover how automation, observability, and continuous improvement play a pivotal role. We also highlight key CNCF projects such as Falco for runtime threat detection, Notary and Sigstore for artifact signing, SPIFFE/SPIRE for identity management, and OPA/Gatekeeper for policy enforcement.