Program Overview

Agenda is subject to change. Agenda timing reflects local time, CET +1.

Tuesday, January 14th

Track 1
Atlantique E
Track 2
Atlantique M
Track 3
Atlantique W
Track 4
Zephyr
09:00 – 10:30
 LV

Building OpenShield - Personal DNS Threat Intelligence with DNS Firewall

Armīns Palms, Dana Ludviga (CERT.LV, LV)

TLP:CLEAR
 US

KPIs for CSIRTs

Logan Wilkins (Cisco, US)

TLP:CLEAR
 AR ES

Effective Design of TTX Exercises for Incident Response

Federico Pacheco (BASE4 Security, AR); Sliafertas Matias (BASE4 Security, ES)

TLP:CLEAR
 GR

Joint Incident Response in the Face of Cross-Country Threat Actors

Manos Athanatos (Technical University of Crete, GR)

TLP:GREEN
10:30 – 11:00

Coffee Break

11:00 – 12:30
 LV

Building OpenShield - Personal DNS Threat Intelligence with DNS Firewall

Armīns Palms, Dana Ludviga (CERT.LV, LV)

TLP:CLEAR
 US

KPIs for CSIRTs

Logan Wilkins (Cisco, US)

TLP:CLEAR
 AR ES

Effective Design of TTX Exercises for Incident Response

Federico Pacheco (BASE4 Security, AR); Sliafertas Matias (BASE4 Security, ES)

TLP:CLEAR
 GR

Joint Incident Response in the Face of Cross-Country Threat Actors

Manos Athanatos (Technical University of Crete, GR)

TLP:GREEN
12:30 – 13:30

Lunch

13:30 – 15:00
 LV

Building OpenShield - Personal DNS Threat Intelligence with DNS Firewall

Armīns Palms, Dana Ludviga (CERT.LV, LV)

TLP:CLEAR

SIM3 Training

Don Stikvoort (Open CSIRT Foundation)

TLP:GREEN
 US

Advanced Threat Hunting in Cloud Environments: Detection and Response Across Hybrid Architectures

Matt Bromiley (LimaCharlie, US)

TLP:GREEN
 LU

Kickstart Training in Computer Forensics

Michael Hamm (CIRCL, LU)

TLP:CLEAR
15:00 – 15:30

Coffee Break

15:30 – 17:30
 LV

Building OpenShield - Personal DNS Threat Intelligence with DNS Firewall

Armīns Palms, Dana Ludviga (CERT.LV, LV)

TLP:CLEAR

SIM3 Training

Don Stikvoort (Open CSIRT Foundation)

TLP:GREEN
 US

Advanced Threat Hunting in Cloud Environments: Detection and Response Across Hybrid Architectures

Matt Bromiley (LimaCharlie, US)

TLP:GREEN
 LU

Kickstart Training in Computer Forensics

Michael Hamm (CIRCL, LU)

TLP:CLEAR

Wednesday, January 15th

January 15
TF-CSIRT Meeting & Joint Plenary Day 1
09:15 – 09:30

Welcome Remarks TF-CSIRT

09:30 – 10:00
 US

The Human Factor: Psychological Safety in Cybersecurity Frontlines

Cristiana Brafman Kittner (Google Cloud, US)

TLP:AMBER
10:00 – 10:30
 FR

Building an IR-ready SOC

Stefan Thibault (Defenso, FR)

TLP:GREEN
10:30 – 10:45

Coffee Break

10:45 – 11:30
 US

Investigating Triad Nexus and Pivoting from a Pig Butchering Investment Scam Website into an Entire Malicious Network

Zach Edwards (Silent Push, US)

TLP:CLEAR
11:30 – 12:15
 GB

Evaluating Detection Accuracy: A Practical Guide to Benchmarking Malware Sandboxes

Michael Bourton (VMRay, GB)

TLP:CLEAR
12:15 – 12:20
 FR

A Comprehensive Intelligence Platform for Tracking and Analyzing Ransomware Activities

Marc-Frédéric Gomez (TF-CSIRT / FIRST, FR)

TLP:CLEAR
12:20 – 12:25
 LT

Cybersecurity Ecosystem from National CSIRT View

Paulius Dauksas (NRD Cyber Security, LT)

TLP:CLEAR
12:25 – 13:30

Lunch

13:30 – 14:00
 DE

Quantum Computers: Should We Worry?

Morton Swimmer (Trend Micro, Inc, DE)

TLP:CLEAR
14:00 – 14:30
 JE

Never mind the Pollocks: Aligning Incident Response with Emergency Response Using JESIP

James McLaren (Jersey Cyber Security Centre, JE)

TLP:GREEN
14:30 – 15:00
 LT

The Development of CSIRTs: Challenges for Small (Developing) States

Dr. Tadas Jakštas, (NRD Cyber Security, LT)

TLP:CLEAR
15:00 – 15:30

Coffee Break

15:30 – 16:00
 LT

Incident Response: How to Make Other in the Organisation Care?

Živilė Nečejauskaitė (NRD Cyber Security, LT)

TLP:CLEAR
16:00 – 16:45
 NL

Enhancing Incident Response: Harnessing LLM AI, RAG, and RegEx for Next-Generation Data Analysis

Patrick van Looy (Northwave Cybersecurity, NL)

TLP:CLEAR
16:45 – 16:50
 LU

LUKS Full Disk Encryption Upside-Down

Michael Hamm (CIRCL, LU)

TLP:CLEAR
16:50 – 16:55
 RS SE

Localization of Transits I Course in the Republic of Serbia

Marko Krstić (SRB-CERT (RATEL), RS); Vladimir Bobor (SIRT Officer Swedbank CDC, SE)

TLP:CLEAR
17:00 – 19:00

Networking Reception at le Meridien

Thursday, January 16th

January 16
Joint Plenary Day 2
09:15 – 09:30

Welcome Remarks FIRST

09:30 – 10:15
 FR

Post-Incident Remediation at ANSSI: A Full Scale Effort

Christophe Renard (Agence Nationale de la Sécurité des Systèmes d'Information, FR)

TLP:GREEN
10:15 – 10:45
 CZ

Fighting Phishing in Czech Constituency

Martin Kunc (CSIRT.CZ and CZ.NIC-CSIRT, CZ)

TLP:GREEN
10:45 – 11:15

Coffee Break

11:15 – 12:00
 BE

Modern n-Day Perimeter Backdoors

Maxime Thiebaut (NVISO, BE)

TLP:GREEN
12:00 – 12:30
 MY

Threat Analysis on Emerging Data Breach in Malaysia with Causes, Challenges, Preventions, and Moving Forward

Kilausuria Abdullah (CyberSecurity Malaysia, MY)

TLP:GREEN
12:30 – 13:30

Lunch

13:30 – 14:15
 NO

Incident Response Beyond the Technical Level

Mona Østvang (mnemonic AS, NO)

TLP:AMBER
14:15 – 15:00
 CH

Exercises in Cyber Peacekeeping

Dr. Serge Droz (FIRST / FDFA, CH)

TLP:GREEN
15:00 – 15:30

Coffee Break

15:30 – 16:15
 BE

The CVD, the EUVD, and the CRA SRP

Johannes Clos (ENISA, BE)

TLP:GREEN
16:15 – 17:00
 LT

Building Resilience - A Practical Guide to Cyber Crisis Management

Dr. Tadas Jakštas,, Živilė Nečejauskaitė (NRD Cyber Security, LT)

TLP:CLEAR