Difficulties of non-intrusive scanning as NCSC
The NCSC performs scanning to identify vulnerabile and compromised devices and warns their owners in order for them to take appropriate measures. The NIS2 directive and its implementation in the “Cyberbeveiligingswet” tasks the NCSC with “proactive non-intrusive scanning of publicly accessible network and information systems of essential and important entities”. There is however no legal […]
Strategic dependencies cryptographic products & services
In our deep dive session we will discuss the outcomes of the Analysis regarding dependencies of cryptographic products and services. Research firm Dialogic has made this analysis in 2025 for the Dutch Ministery of Economic Affairs. The outcomes of the analysis will be discussed in light of the Dutch National Cryptography Strategy, current developments and […]
Vishing At Scale: Humans vs. Voice Agents
Over the past several years, I’ve run more than a thousand human-to-human vishing calls. Now I’m conducting the same operations with fully automated voice agents, at scale, across F500 and government targets. This presentation is the before/after: humans versus voice agents in real operations. Not a controlled academic study, that’s not how internal red teams […]
PQCmigration in practice: learnings from 7 organizations
With awareness on the quantum threat to cryptography finally rising, many are looking for experience on migrating to quantum safe cryptography. In our PQC workgroup, seven wildly different companies cooperate to build this experience together. In this talk we teach you what we learned by experimenting. Specifically we talk about our inventory Proof of Concepts, […]
0 incidents, 0 sensors: governing the risks no one owns
Zero incidents. Zero sensors. That’s the official record on GPS disruption in Dutch waters – not because it doesn’t happen, but because no one measures. Zero isn’t safety; zero is blindness dressed as reassurance. This is a systemic risk: too broad for any single organisation, too operational for government, too cross-cutting for existing frameworks. Ship […]
Knight to C2; The Endgame against ransomware groups
Endgame is an ongoing law-enforcement project tackling the roots of ransomware; Botnets, RAT’s and infostealers. To combat this cybercrime, you need a broad systemic approach. In order to achieve that, we need cyber governance: the collaboration in which multiple public and private partners take their responsibilities on these topics: – Actors/suspects – Financial assets – […]
Geopolitical Resilience: A Central Bank Perspective
Geopolitical tensions increasingly materialise in the cyber domain, directly affecting financial stability, critical infrastructures and public institutions. For central banks, this creates a unique resilience challenge that spans monetary policy, financial supervision and internal operations.
Secure Apps in Mythos Era: Find Gaps Before Attackers Do
Frontier AI models are increasingly capable of discovering and exploiting software weaknesses, prompting calls for more defensive preparedness and responsible release strategies. In this session, we translate that urgency into a practical, security-first approach to LLM penetration testing for real enterprise deployments.You will learn how to scope an LLM pentest beyond the model itself, covering […]
A Room With a View
WebEx has so called ‘WebEx screens’, devices that are a combination of a screen, a camera, a microphone and speakers. These appliances are edge devices and part of the unified communications solution in both corporate and public organisations. In this deep-dive we explore how an a-symmetric approach leads to bypassing security measures using a living […]
The Rising Sun: CTI as accelerator of your stakeholders
In a short period of time, Cyber Threat Intelligence (CTI) at Dutch Railways (NS) evolved into an independent advisory function that helps stakeholders make more targeted, timely, and threat-driven decisions. Positioned as the “Rising Sun” at the center of the security ecosystem, CTI provides direction and energy to domains such as Security Operations, Risk, Architecture, […]