A tale: 3 Spammy boxes – technical deep dive

This session is a technical deepdive of the talk ”Set-top boxes: your personal unwanted proxy”. This talk will dive into our analysis methodology and technical findings from our extensive investigation into shady Android devices flooding the market. In this technical deep dive, we’ll walk you through the entire infection chain of x96mini Android TV boxes […]

From awareness to action: SME Cyber Security

Despite their economic importance Dutch SMEs lag behind in implementing cybersecurity. To strengthen cyber resilience of SMEs in the region, THUAS, Connect2Trust, and the municipality of The Hague launched a platform in 2025 to facilitate collaboration between SMEs from various sectors. A cyber maturity survey was conducted to serve as a baseline measurement, showing three […]

The Threats of High Power IoT on the Power Grid

More and more devices are being connected to the electricity grid, including High Power IoT. Examples are solar inverters, electric cars, and heat pumps. This presents opportunities, but also many dangers. What are these dangers? What laws and regulations apply to this High Power IoT on the power grid? And what would be possible solutions […]

Geopolitical Liminality in Cyberspace

“The old world is dying, and the new world struggles to be born: now is the time of monsters.” — Antonio Gramsci Writing from prison, Antonio Gramsci described the world he lived in as liminal and unstable – seeing an old order fade and a new yet to emerge. He called these “times of monsters”: […]

Human resilience when truth is hackable

Artificial intelligence is forcing the next step in the human risk side of cybersecurity. As voice cloning and synthetic media erode trust in what people see, hear and read, the challenge of human risk is shifting from detecting malicious content to making decisions under ambiguity. Drawing on cyberpsychology and applied work, this session introduces Responsible […]

Set-top boxes: your personal unwanted proxy

Residential proxies are increasingly used not only for legitimate purposes—such as AI training and secure browsing—but also by cybercriminals and state actors to obscure indicators of compromise and launch large-scale DDoS attacks. The NCSC-NL has observed a sharp rise in such abuse, making attacks harder to detect and mitigate. This presentation first explores NCSC’s research […]

Cyber Operations and Critical Infrastructure in Conflict

This session provides an intelligence‐based assessment of state actor cyber operations against critical infrastructure before and during armed conflict. Using the Venezuelan energy case and lessons from Russian operations in Ukraine, it examines what cyber tools actually achieved, their limits, and why the Venezuelan case is not directly comparable to Europe. The talk offers a […]

How we accidentally built a nation-scale tracking system

What if tracking someone’s real-time location didn’t require malware or exploits, but just a phone call? In 2026, a critical misconfiguration in a European telco network allowed callers to determine a person’s location without the call being answered, and without leaving meaningful traces. Affecting a large portion of a national subscriber base, this issue exposed […]

Power, Trust, Responsibility in Fragmented Digital World

Cybersecurity has evolved into a strategic domain at the intersection of geopolitics, economic stability, and societal resilience. Rising global tensions are shaping cyber threats with real-world impacts, while collective defense through international and public–private cooperation becomes essential. The digital space faces a growing tension between anonymity and accountability, as misuse fuels cybercrime and erodes trust. […]