| Time | Track 1 | Track 2 | Workshop |
|---|---|---|---|
| 9:30-10:00 | Arrivals and check-in at The Tavern | ||
| 10:00-10:10 | Welcome - Committee | ||
| 10:10-10:55 | * Keynote: Secure Delivery Over Untrusted Networks - Holly Grace Williams | ||
| 11:00-11:25 | * Opsec Lessons from Ukraine - Vic Harkness | * Supply Chain Attacks: You Can’t Depend on Anyone - Zoheb Ainapore | Backdoors and Breaches - Antisyphon Training |
| 11:30-11:55 | Patriotism for Hire: An OSINT Investigation - Peter Neve | Accessible Security for 1.3 Billion Disabled People - Aliyu G. Yisa | Backdoors and Breaches - Antisyphon Training |
| 12:00-12:25 | * The misinformation economy - Aidan Lynch | Backdoors and Breaches - Antisyphon Training | |
| 12:25-13:20 | Lunch - The Tavern | ||
| 13:20-13:45 | Unlocked and Leaked - Darren McDonald & Craig Blackie | * Ocean data is existentially important! How were working towards security strategies for Marine Autonomous Science - Owain Jones | AI in Security Operations: From Hype to Hands-On - Jymit Singh |
| 13:50-14:15 | Custom built NFC/RFID blinky hexagon - Bryan Watkins von Schuh | ||
| 14:20-14:45 | When Blue Team Tools Become Red - Michael Mullen | Beacon Butty & Raspberry Pi: A Meal Deal for C2 Detection - Dave Marsh | |
| 14:50-15:15 | |||
| 15:15-15:30 | Break | ||
| 15:30-15:55 | Threat Modelling OpenSource - Kyverno and the Kubernetes Kraken - Tom Cope | The metrics that lied to leadership - Luigi Ritacca | Backdoors and breaches |
| 16:00-16:25 | Risk Under the Microscope - James Bore | Phishing Education is Broken: Training Humans to Spot Attacks That Actually Work - Endurance Imasuen | Backdoors and breaches - Antisyphon Training |
| 16:30-17:00 | Resilience Is Not a PDF: Proving Recovery Before the Incident - Richard Dosumu | Backdoors and breaches - Antisyphon Training | |
| 17:05-17:30 | Closing remarks - Commitee | ||
| 17:30-??:?? | Drinks! Bar Tab sponsored by Interrupt Labs - The Tavern | ||
Schedule
Will not be recorded = *
Talk Summaries
-
Talk:
Hardening Distributed Edge Systems for Secure Package Delivery Over Untrusted Networks
This talk will cover lessons learned from securing latency-sensitive edge platforms operating over untrusted networks; with a focus on command integrity and reliable task execution in contested environments.
We'll cover building the system, from the ground up with threat modelling considerations and practical mitigations against interception, spoofing, and system disruption.
The talk walks through building operator-controlled systems that maintain trust, enforce intent, and ensures deliveries arrived exactly where they're meant to.Speaker:
Holly has worked in cybersecurity for nearly 20 years. Her early career was spent in the military working in roles such as Site Security Officer, although she now works with a wide range of organisations delivering penetration testing. She is always interested in working on novel and nerdy side quests, which often lead to unconventional conference talks and odd blog posts.
-
Talk:
TW: This talk is about an active warzone, and will contain discussions of serious injury and death.
When you hear the sirens, what do you do? Run for the nearest air-raid shelter that you’ve previously located? Hide in the bathroom? Down your pint because there’s no point in dying sober? Opsec as a humanitarian volunteer in Ukraine very much depends upon your personal risk appetite. In this talk I will discuss what I have learned during my time in Ukraine, discuss the factors that go into the opsec decision making process, and give my opinion on what actually matters.
Speaker:
Vic crossed the border into Ukraine a little over a week after the start of the full-scale invasion. She has now crossed in and out of that border over 20 times. She has worked on a large range of humanitarian projects from Lviv to Kharkiv. In addition to this she has worked on projects interviewing Ukrainians to collect the stories of Ukrainian people and international volunteers during the war.
-
Talk:
Modern applications depend on a growing web of open-source packages, build tools, CI/CD systems, SaaS integrations, and cloud services. That dependency chain creates a wide attack surface and if one trusted component is compromised, the impact can reach far beyond the original target.
In this talk, we’ll break down real-world supply chain attacks, including compromised npm packages, CI/CD takeovers, SaaS breaches, and cloud credential theft. We’ll look at how attackers turn trusted components into entry points, what the blast radius looks like in practice, and why these incidents are so effective.
Through practical examples, we’ll explore how these attacks work, what impact they have in real environments, and how to defend against them with actionable, developer-friendly controls. Attendees will leave with a clearer mental model of supply chain risk and concrete steps to reduce it.Speaker:
Zoheb is a Principal Security Engineer based in the UK, specialising in pragmatic, risk-driven approaches to application and cloud security. With a background in software development and years of hands-on cybersecurity experience, he focuses on helping organisations build security that actually works in the real world.
He is an active contributor to the security community, regularly speaking at industry events, mentoring aspiring professionals, and supporting initiatives that introduce young people to cybersecurity. He has also guest lectured at universities and reviewed multiple technical publications. -
Talk:
An OSINT investigation into the people behind the flags that appeared on lamposts around the country over the last year. This is a 101 introduction into setting up sock accounts and protecting your identity for OSINT and HUMINT investigations, and what I found when investigating these groups.
Speaker:
Pete Neve is a mediocre hacker with a strong background in information security. Currently serving as the Director of Information Security at Synamedia in the United Kingdom, Pete holds multiple certifications including CISSP, CEH, and SABSA Chartered Business Security Architect. With over a decade of experience, he has held key leadership positions, including Information Security Manager at Synamedia and Information Security Consultant at Arqiva. Pete's experience includes collaborating with the NCSC as part of the NSIE group protecting Critical National Infrastructure, and working with prominent organizations such as Cisco, Vodafone, and BT. His technical proficiency spans various domains, including system architecture, network security, ethical hacking, and data protection.
-
Talk:
Over 1.3 billion people worldwide live with a disability. That is 16% of the global population. These people face the same cyber threats as everyone else, but the security controls, training, and tools designed to protect them often exclude them entirely. In some cases, they even face more threats than non-disabled people. From password managers to authentication systems, security tools and security awareness, barriers exist that harm the security of people and organisations. On the other hand, assistive technologies also need to be protected from cyber attacks.
Speaker:
Aliyu G Yisa is an inclusive security advocate. He has a background in software and security engineering with almost a decade of experience. He co-founded Fezzant, which focuses on the intersection of digital accessibility and cybersecurity. He also volunteers as Head of Accessibility at The Cyber Helpline, a charity supporting victims of cybercrime. Aliyu is passionate about making cybersecurity more inclusive and speaks regularly at events on the intersection of accessibility and security. He co-authored "Secure by Design, Accessible by Default: Building Cybersecurity Ethics That Include Everyone" in the book Digital Accessibility Ethics: Disability Inclusion in All Things Tech.
-
Talk:
A quick and non-technical dive into the world of online misinformation operations and the Freakonomics that encourage them. From Government funded election interference to online clout chasing, misinformation now makes up a substantial portion of the online ecosystem and its negative impact are spilling over into the real world in more and more dramatic ways.
Speaker:
Aidan Lynch is a first year PhD student at the University of Oxford studying pharmaceutical chemistry. He became interested in the use of information warfare by state actors after conducting volunteer work in Ukraine and seeing how false narratives online effect the conditions on the ground through the restriction of international aid.
-
Talk:
Modern Dell systems claim a locked BIOS protects against physical attackers, password screen, Secure Boot enforcement, IOMMU-protected DMA, signed firmware updates. We'll show two reasons it doesn't. First: disabling preboot DMA protection by flipping a single NVRAM byte; the BIOS setup screen still cheerfully reports DMA enabled. Second: a bug that lets us pull BIOS passwords out in cleartext. Both attacks reduce to read-modify-write of the SPI flash with a SOIC clip and a cheap programmer. The talk covers the bugs, the tooling, and what it means for deployed Dell hardware. You may see this referenced as CVE-2026-40639.
Speaker:
Craig is an experienced network and physical security professional at MDSec. He enjoys breaking into things from ATMs, buildings, and encrypted laptops. Hacker of all things, bringer of root.
Darren McDonald is a cybersecurity consultant at AmberWolf specialising in offensive security, red team operations, and hardware hacking. When not hacking he enjoys coding Rust and RISC-V. -
Talk:
The National Oceanography Centre hosts the largest collection of Autonomous Underwater Vehicles (AUVs) in Europe. The data these gather is invaluable to some really high-impact science, from coast to deep ocean.
Their Information Security is key, but thinking "nobody is going to hack the scientists!" often leaves it forgotten or de-prioritised.
This talk will introduce you to Boaty, the current state of infosec in our niche of maritime robotics for environmental science, our vision for keeping the scientific data supply chain trustworthy, and the first steps we’ve been taking towards it.Speaker:
Owain is a software engineer working in NOC's Marine Autonomous Robotics Systems (MARS) group. He was the first developer to start on the AUV 'command & control' project (yep, we named it C2), and has been doing it for roughly 10 years. For the past year, he’s been leading a project to improve encryption of AUV data transmissions over satellites and underwater acoustics. An “Honorary Goon”, he has no idea what he's doing but is happy to be here.
-
Talk:
Showing off a custom-built implant, maybe bringing along a musical actuator, who knows
Speaker:
Bryan likes to tinker and pick up skills, but mainly a hardware enjoyer.
-
Talk:
This talk explores a growing pattern: attackers increasingly re-purpose defensive tools such as backup, monitoring, and incident-response software defenders deploy. We’ll break down real world examples such as using Veeam infrastructure for data staging/exfiltration preparation, leveraging network monitoring platforms for reconnaissance and persistence, then connecting these to wider industry trends like full memory capture for lsass dumping workflows and the malicious use of DFIR/endpoint tooling (e.g., Velociraptor). Attendees will leave with practical detection ideas, architectural hardening guidance, and a threat-model for the defensive stack itself.
Speaker:
Michael is a incident response practitioner with over 8 years experience in the field; day to day work life for Michael is assisting clients with security incidents, ranging from a typical single mailbox business email compromise through to nation state espionage.
-
Talk:
C2 attacks are rising — and most home and small-business networks have essentially zero chance of detecting one. How did we get here, and what can we actually do about it? Beacon Butty is a Raspberry Pi-powered detection stack that can identify C2 beacons on your LAN using similar techniques to enterprise SOCs — but is both open-source and inexpensive.
Speaker:
Dave Marsh has spent 30 years breaking and securing things — from hardware control systems for chemical plants, to VMS at Digital, to cryptography and digital funds transfer protection for HSBC, BP and ABN-AMRO. He now works as a QSA, where professional scepticism about network security comes with the job. Beacon Butty started as a weekend project to see whether enterprise-grade C2 detection could run effectively on a Raspberry Pi. It can.
-
Talk:
We all use open source software every day, but do we take the time to validate the security assumptions made by these projects? In this talk, we will discuss threat modelling processes, why they are important, and how to perform them effectively. We will walk through our Kyverno threat model, discuss discoveries (and CVEs!) made along the way, including how to best secure your Kyverno deployments.
Speaker:
Tom Cope is a experienced Security Architect and Systems Engineer with a passion for designing, building and maintaining secure systems, processes, and teams. With 12 years in the Cyber Security space he describes himself as a "Blue Team by day and Red team by night". Currently working at ControlPlane helping secure opensource and highly regulated companies.
-
Talk:
Why metrics matter, common pitfalls of security operations metrics. (Mean Vs median, false positive Vs benign positive, and other pitfalls), why many SOC metrics unintentionally distort operational reality, and how measurement changes analyst behaviour, often negatively
the difference between measuring alerts, investigations, and actual security outcomesSpeaker:
Luigi Ritacca is a UK-based cyber security leader and Principal Security Operations Manager at Microsoft. For more than a decade, he has built and led high-performance SOC
-
Talk:
Risk scores give us a number and pretend we're thinking. Multiply likelihood by impact, stick a colour on it, get a signature, and call it done.
Alternatively, go down the quantitative analysis route with Monte Carlo simulations so that we can properly dress up our assumptions as authority.
If you're fed up of heat maps and want to really pull risk apart, this one's probably for you. Includes a game, with prizes available (this is not a bribe to attend).Speaker:
James thinks too much about security and sometimes builds games about it. He has over twenty years in the industry, and has spent too much time arguing that risk management is broken and we should fix it.
-
Talk:
Phishing is still quite effective despite years of security awareness training, revealing a disconnect between people's knowledge and their behavior under duress. The failure of traditional, compliance-driven training to alter actual behavior is examined in this talk. It demonstrates how users react to actual attack scenarios based on experience creating a phishing awareness application. In order to improve decision-making, the session emphasizes behavioral design and experience learning. Attendees will witness how training through experience, rather than teaching, helps create more self-assured, security-aware people through a live simulation demonstration.
Speaker:
Endurance Imasuen is a cybersecurity expert with experience in software development, and business analysis. He earned an MSc in Cyber Security with a Human Factor from Bournemouth University.
He has designed and developed user-focused security solutions, such as a phishing awareness app for students, people, and corporate users across the United Kingdom. His work focuses on bridging the gap between technological security measures and human behavior, assisting organizations to establish more effective and realistic security awareness initiatives. -
Talk:
The CrowdStrike outage showed how one trusted supplier can disrupt critical services globally. Advanced’s ransomware incident affected NHS 111, while the British Library’s cyber-attack caused a long and painful recovery. The lesson is clear: resilience is not a PDF, and recovery plans only matter if they survive reality. This talk shows how security teams can map critical services, expose hidden dependencies, test severe-but-plausible scenarios safely, and build evidence that recovery actually works before an incident, auditor, customer, or regulator asks the uncomfortable question.
Speaker:
Richard Dosumu is a cybersecurity practitioner, independent researcher, Product Lead and founder of OctaTech, a UK-based digital product company building accessible tools for cybersecurity development, learning, and productivity. He holds an MSc in Cyber Security and Human Factors from Bournemouth University and writes on cybersecurity, AI, digital resilience, and human-centred security. Through CyberYearn and OctaTech’s wider product work, Richard is focused on improving cybersecurity literacy by making security guidance clearer, more practical, and more accessible to learners, early-career professionals, and real-world teams.
Workshop Summaries
-
Each session is around 20 minutes and does not require pre-booking
Backdoors & Breaches takes traditional tabletop exercises and turns them into a structured, fun, & educational card game.The original CORE Deck contains 52 unique cards that all represent different aspects of Incident response.
Whether those are commonly seen attacks, or even defensive tools or methods you could purchase or learn about…
Tabletop Exercises Have Never Been Easier!
-
The security industry is drowning in AI promises. This workshop cuts through the noise. Drawing on real-world experience building AI-assisted security operations at scale, this hands-on session gives practitioners a grounded, no-hype introduction to where AI actually moves the needle in a SOC, and where it introduces new risk if deployed carelessly. Participants will work through practitioner-focused use cases: threat detection engineering, alert triage, incident response acceleration, and log analysis. Labs are built around Anthropic's Claude Model Context Protocol, and their Agent Skills and Subagents curriculum, giving attendees direct, transferable experience with tooling they can use from day one.
The session covers not just capability, but responsibility: how to architect AI pipelines that are auditable and controlled, the evidence integrity challenges AI introduces to security workflows, the real threat of prompt injection in analyst pipelines, and how to design human-in-the-loop systems that don't collapse under operational pressure. Attendees will leave with reusable patterns, a critical framework for evaluating AI security tooling, and hands-on exposure to techniques they can apply in their own environments immediately — no prior AI experience required.