Strange <marquee> vectors, serious infrastructure impact
A wifi name rooting your router. A TLS certificate field taking over hosting accounts. A DNS response taking down a European network. Not your everyday injection vector, and easy to miss in security review. I spent the past year putting injection payloads into every protocol field I can control as an infrastructure operator: TLS certificates, […]
BEC Deep Dive: The New Cyclotron Technical Standard
Business Email Compromise (BEC) remains a critical threat to the Dutch economy, often bypassing traditional security measures with ease. This session provides an exclusive technical deep dive into the upcoming BEC defensive standard developed under the Cyclotron program—a high-maturity public-private partnership between the NCSC and industry experts, including Attic Security.As a co-author of this forthcoming […]
Sovereignty by Design: Europe’s SaaS Resilience Playbook
Europe’s digital sovereignty agenda is legitimate and necessary. But the market cannot deliver homegrown solutions fast enough — spreading investment too thin risks building a monoculture that makes adversaries’ jobs easier. Meanwhile, Baltic cable sabotage, service termination by decree, and an unpredictable transatlantic relationship have turned theoretical cut-off scenarios into planning realities. This session delivers […]
Difficulties of non-intrusive scanning as NCSC
The NCSC performs scanning to identify vulnerable and compromised devices and warns their owners in order for them to take appropriate measures. The NIS2 directive and its implementation in the “Cyberbeveiligingswet” tasks the NCSC with “proactive non-intrusive scanning of publicly accessible network and information systems of essential and important entities”. There is however no legal […]
PQCmigration in practice: learnings from 7 organizations
With awareness on the quantum threat to cryptography finally rising, many are looking for experience on migrating to quantum safe cryptography. In our PQC workgroup, seven wildly different companies cooperate to build this experience together. In this talk we teach you what we learned by experimenting. Specifically we talk about our inventory Proof of Concepts, […]
Under Pressure: Survive the Crisis
Imagine a massive cyberattack crippling your supply chain, amplified by the rapid deployment of malicious AI tooling. What is your next move? In this highly interactive workshop hosted by CCRC, you will step into the shoes of a crisis management team facing a high-stakes cyber incident. We will guide the audience through the painful dilemmas […]
The pre-intrusion layer
Most security teams are not blind to influence operations. They see the signals, but they see them late: content already spreading, impersonation already live, narratives amplified. By then, the early-stage indicators – cloned domains, coordinated account creation, AI-generated content being tested – have been visible for weeks on platforms their security stack doesn’t collect from. […]
Humor, The Secret Weapon for Cybersecurity Awareness
Humor can be a powerful tool in cybersecurity awareness because it makes messages more memorable and engaging, ultimately supporting real behavior change. In this presentation I’ll explain why humor works. Research shows that humor can enhance understanding and retention when applied thoughtfully. However, humor must be used carefully: it should clearly reinforce the desired behavior, […]