The Threats of High Power IoT on the Power Grid
More and more devices are being connected to the electricity grid, including High Power IoT. Examples are solar inverters, electric cars, and heat pumps. This presents opportunities, but also many dangers. What are these dangers? What laws and regulations apply to this High Power IoT on the power grid? And what would be possible solutions […]
How we accidentally built a nation-scale tracking system
What if tracking someone’s real-time location didn’t require malware or exploits, but just a phone call? In 2026, a critical misconfiguration in a European telco network allowed callers to determine a person’s location without the call being answered, and without leaving meaningful traces. Affecting a large portion of a national subscriber base, this issue exposed […]
BEC Deep Dive: The New Cyclotron Technical Standard
Business Email Compromise (BEC) remains a critical threat to the Dutch economy, often bypassing traditional security measures with ease. This session provides an exclusive technical deep dive into the upcoming BEC defensive standard developed under the Cyclotron program—a high-maturity public-private partnership between the NCSC and industry experts, including Attic Security.As a co-author of this forthcoming […]
The security innovation lab for OT: call for champions!
The Security Innovation LAB for OT (SILO) brings the critical infrastructure in the Netherlands two major innovation shifts. Namely shaping the innovation agenda within the critical sectors of the OT domain and it provides a solution for a programmatic approach to cyber innovation. This calls for cooperation. In this session the NCSC, TNO and the […]
TaHiTI, threat hunting methodology.
Discover the Power of TaHiTI at ONE Conference AI is accelerating everything—threat discovery, vulnerability disclosure, and attacker adaptation. As timelines between “known” and “exploited” keep collapsing, relying on static detection is no longer enough. In this interactive workshop, we introduce the renewed TaHiTI (Targeted Hunting integrating Threat Intelligence) framework, developed within the Dutch financial sector. […]
The Zero-Day Dilemma: Why Attacks are Increasing and How to Fight Back
The number of zero-day attacks is increasing, posing a significant challenge for organizational defense. What are the underlying drivers of this growth, and how can organizations optimize their defenses to mitigate these threats effectively?
Flatline vs. Recovery: Responding to Ransomware Attacks on Healthcare
Few word combinations are more dreadful than “ransomware” and “healthcare.” Despite countless hours and substantial investment, we see it more and more — not less. News outlets and cybersecurity blogs offer tips to “prevent,” “detect,” and “recover”; warn that “it’s not a matter of if, but when”; yet many still struggle to turn that guidance […]
Strategic dependencies cryptographic products & services
In our deep dive session we will discuss the outcomes of the Analysis regarding dependencies of cryptographic products and services. Research firm Dialogic has made this analysis in 2025 for the Dutch Ministery of Economic Affairs. The outcomes of the analysis will be discussed in light of the Dutch National Cryptography Strategy, current developments and […]
0 incidents, 0 sensors: governing the risks no one owns
Zero incidents. Zero sensors. That’s the official record on GPS disruption in Dutch waters – not because it doesn’t happen, but because no one measures. Zero isn’t safety; zero is blindness dressed as reassurance. This is a systemic risk: too broad for any single organisation, too operational for government, too cross-cutting for existing frameworks. Ship […]
0-Day SharePoint Exploitation: Responding to the unknown
This session unpacks the SharePoint Toolshell campaign as a case study in modern 0-day exploitation, walking through the tactics, techniques, and procedures observed in a real incident. From there, we broaden the lens: what does Toolshell teach us about responding to campaigns in the first 72 hours when activity is “unknown”? Attendees will leave with […]