AI in the kill chAIn: a new frontier of digital threats?
This talk will provide an insight in how artificial intelligence is influencing the digital threat landscape. It will examine real-life cases of how threat actors utilize AI in different parts of the cyber kill chain. The examples show how certain parts of the kill chain are being automated, run more efficiently and sometimes even replaced […]
Human resilience when truth is hackable
Artificial intelligence is forcing the next step in the human risk side of cybersecurity. As voice cloning and synthetic media erode trust in what people see, hear and read, the challenge of human risk is shifting from detecting malicious content to making decisions under ambiguity. Drawing on cyberpsychology and applied work, this session introduces Responsible […]
Beneath Arrakis:Unmasking Hydra Saiga’s Covert Operation
On a desert world, Hydra Saiga mines “spicetelligence” from government, defense, and infrastructure targets across Central Asia, the Middle East, and Eastern Europe. This APT aligns with its sponsor’s geopolitical interests—specifically water and gas strategy—while largely evading Western scrutiny. We will explore their TTPs and targets using a custom tool that intercepts the actor’s Telegram-as-a-C2 […]
Storage Spoofing – where digital and physical crime meet
This presentation is hosted by a chemical company and a team of the Dutch police. We showcase an ongoing crime where cybersecurity and physical crime blend, in the world of Rotterdam’s oil and chemical storage. It starts with the tracking of a very persistent threat actor who uses domain typosquatting and near perfect BEC fraud […]
The security innovation lab for OT: call for champions!
The Security Innovation LAB for OT (SILO) brings the critical infrastructure in the Netherlands two major innovation shifts. Namely shaping the innovation agenda within the critical sectors of the OT domain and it provides a solution for a programmatic approach to cyber innovation. This calls for cooperation. In this session the NCSC, TNO and the […]
How to build a world-class Cyber Defense Center
This talk explains how DICTU built a Cyber Defense Center (CDC), basically a next-generation SOC, combining proactive, threat intel-driven defense and offensive capabilities. We will explain this using a medievil theme, so that you can follow along regardless of your background and technical level of expertise. It covers the motivation for building a CDC, its […]
Unravel Cybercrime: Anti-Phishing and -Ransomware Agenda
Phishing remains the primary entry point for many cyberattacks, enabling access to interconnected criminal ecosystems where no cybercrime occurs in isolation. This session examines how attackers exploit trust layers like DNS, use anonymization technologies, and leverage crypto assets to obscure operations. It highlights the need for a technology agenda that links fragmented signals and rapidly […]
Flatline vs. Recovery: Responding to Ransomware Attacks on Healthcare
Few word combinations are more dreadful than “ransomware” and “healthcare.” Despite countless hours and substantial investment, we see it more and more — not less. News outlets and cybersecurity blogs offer tips to “prevent,” “detect,” and “recover”; warn that “it’s not a matter of if, but when”; yet many still struggle to turn that guidance […]
Collaborating in the Cyber Resilience Network &Cyclotron
The Netherlands is taking a major step forward in public–private cyber resilience through the development of the Cyber Resilience Network (Cyberweerbaarheidsnetwerk/CWN) and the Cyclotron collaboration. Through these initiatives, we are jointly building a new, trusted ecosystem that structurally strengthens public–private cooperation. This session presents practical examples of types of collaboration, the results thereof, and lessons […]
The good, the bad, and STIX/TAXII
Standards are essential; without them, the internet would not exist. In open source, organisations like the Linux Foundation drive such standards, as seen with OpenTelemetry, now widely adopted despite early scepticism. In cybersecurity, STIX/TAXII plays a similar role. Though often criticised, it remains vital, particularly for cyber threat intelligence and detection rule sharing. Its value […]