Loading…

Type: Talk Track 1 clear filter
Saturday, September 12
 

9:30am CDT

Keynote Address: We Keep Us Safe
Saturday September 12, 2026 9:30am - 10:20am CDT
Who keeps us safe? We keep us safe.

It’s a rallying cry for community defenders, and for blue teams, it’s the job description. All of us are fighting uphill battles with short resources and long odds, and we have a lot to learn from each other.



How can we do our work most effectively when we can’t count on institutions to have our backs?

This talk takes lessons from neighborhood organizing and applies them to envision security that is rooted in a different kind of trust, with a shared responsibility model built on relationships and care. Attendees will leave with practical advice about what they can do to help get us there together.
Speakers
avatar for Ian Coldwater

Ian Coldwater

Security Consultant, Independent
Ian Coldwater is SIG Security Co-Chair for the Kubernetes project, a longtime community organizer, and a globally recognized expert in container and Kubernetes security. They have presented their research on hacking and hardening cloud native infrastructure at conferences such as... Read More →
Saturday September 12, 2026 9:30am - 10:20am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

11:00am CDT

How We've Gone Completely Phishing-resistant (And So Can You!)
Saturday September 12, 2026 11:00am - 11:50am CDT
Phishing-resistant authentication is shifting from optional to mandatory. Not only are attackers using phishing as the primary mechanism to evade traditional forms of MFA, but they are also evolving their attacks to find ways around implementations where phishing-resistant auth is only preferred and not enforced. The road to deploying passkeys, Windows Hello for Business and Mac Platform SSO looks easy enough in the Microsoft docs, but what does it look like to implement them as mandatory across a workforce?

In this session we’ll cover how we went from a handful of FIDO2 keys to phishing-resistant authentication across our enterprise in Entra ID at breakneck speeds. We’ll explore the ins-and-outs from a technical and organizational perspective of the implementation, the gotchas we hit along the way, and how we overcame them. We’ll cover edge case scenarios, and how deploying passkeys is just part of the bigger equation to going phishing-resistant. We’ll also examine phishing attack trends we were seeing, which helped inform and shape policy so that phishing-resistant authentication isn’t an option – it’s the only option.
Speakers
avatar for Eric Woodruff

Eric Woodruff

Chief Identity Architect, Semperis
Throughout his 26-year career in the IT field, Eric has sought out and held a diverse range of roles. Currently the Chief Identity Architect for Semperis; Eric previously was a member of the Security Research and Product teams. Prior to Semperis, Eric worked as a Security and Identity... Read More →
Saturday September 12, 2026 11:00am - 11:50am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 1

12:00pm CDT

Breaking Identity at Scale: From DPAPI & TBAL Secrets to Full Domain Compromise
Saturday September 12, 2026 12:00pm - 12:50pm CDT
Modern enterprise environments continue to rely on implicit trust within identity and credential protection mechanisms such as DPAPI, DPAPI-NG, and token-based authentication layers. While these technologies are designed to safeguard secrets, they also introduce powerful attack surfaces when combined with misconfigurations, weak privilege boundaries, and overlooked trust relationships.


This session presents a deep technical exploration of how attackers extract and abuse protected credentials at scale, moving from local access to full domain compromise. We demonstrate novel techniques for decrypting DPAPI-protected data, abusing TBAL-related key material, and chaining these with authentication protocol weaknesses such as NTLM and Kerberos to achieve lateral movement and privilege escalation.


Unlike traditional approaches that focus on single techniques, this research connects multiple layers of identity abuse into a cohesive attack path observed in real-world environments. Attendees will see how seemingly isolated weaknesses: credential storage, token handling, and protocol trust, combine into high-impact attack chains.


The session also provides defensive strategies, including detection opportunities, hardening approaches, and architectural changes to reduce reliance on implicit trust. The goal is to shift defenders from reactive detection to proactive identity security design.
Speakers
avatar for Paula Januszkiewicz

Paula Januszkiewicz

CEO and Founder, Cybersecurity Expert, CQURE
Paula Januszkiewicz is the Founder and CEO of CQURE and CQURE Academy, globally recognized organizations delivering cutting-edge cybersecurity consulting and advanced training since 2008. She is an Enterprise Security MVP, Microsoft Regional Director, and one of the world’s leading... Read More →
Saturday September 12, 2026 12:00pm - 12:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 1

1:00pm CDT

Defending the Hypervisor: Using Offensive Tooling to Validate vSphere Security
Saturday September 12, 2026 1:00pm - 1:50pm CDT
VMWare (Broadcom) represents the most commonly used enterprise Hypervisors.  This means a compromised vCenter or ESXi host gives attackers access to every virtual machine and credential in your my environment. Defenders often lack visibility into what a post-exploitation attack against the hypervisor layer looks like. So, I built a tool to find out.
  In this session, I'll walk through the real-world attack chains that threat actors use against VMware vSphere environments: extracting Kerberos keytabs and credential caches from ESXi  hosts, decrypting stored VPX database passwords to pivot across every managed host, dumping JVM heap memory from vCenter to harvest SAML tokens, and forging certificates using stolen VMCA private keys. These are the techniques behind campaigns and APT operations targeting virtualization infrastructure today.
The core of this talk is a live demo of VEXED (vSphere EXploitation Extraction and Detection), an open-source tool I developed to automate these attack chains against vCenter and ESXi. Starting from a single SSH session, I'll show how VEXED chains credential extraction through VPX password decryption to automatically pivot across an entire vSphere cluster — mirroring the lateral movement patterns we as defenders need to detect and prevent.
But I didn't build this as a red team tool. I built it to answer a blue team question: what should I be looking for? For each attack chain I demonstrate, I'll map the corresponding detection opportunities: what logs are generated, what telemetry to forward to your SIEM, and what hardening controls actually break the chain. I'll cover VEXED's built-in hardening audit module, which checks over 20 security configurations across ESXi and vCenter, giving you a repeatable way to validate vSphere security posture. I'll also walk through the interactive attack graph output that visualizes the relationships between compromised credentials, certificates, and pivot paths… something I've found quite useful when communicating to leadership.
 Attendees will leave with:
  - A clear understanding of the most critical vSphere post-exploitation attack chains and how to detect them
  - Practical SIEM detection logic for credential extraction, memory dumping, and lateral movement across vSphere infrastructure
  - A hardening checklist validated against real attack tooling, not just vendor best practices
  - An open-source tool you can run in your own lab to validate defenses before an attacker does
 
  This session is for SOC analysts, infrastructure security teams, and anyone responsible for defending virtualized environments. No prior vSphere security experience is required. Just a desire to understand what happens when the hypervisor layer is compromised and how to stop it.
Speakers
avatar for Darryl Baker (DFIRDeferred)

Darryl Baker (DFIRDeferred)

Senior Staff Security Researcher, Netwrix
Darryl Baker is a Senior Staff Security Researcher at Netwrix, where he focuses on identity security and emerging attack techniques targeting enterprise authentication systems. With a background spanning security research, consulting, and adversary simulation, he specializes in uncovering... Read More →
Saturday September 12, 2026 1:00pm - 1:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

2:00pm CDT

The Second Front: Detecting LOTL Off the Endpoint
Saturday September 12, 2026 2:00pm - 2:50pm CDT
Living-off-the-land (LOTL) isn't what it used to be. Blue teams have spent years tuning detections for the classic playbook - LOLBins, malicious macros, WMI abuse, PowerShell, etc. - and endpoint tooling has gotten pretty good at catching it. So, attackers moved.
LOTL is now operating across a second front: the identity and management plane, which spans hundreds (if not thousands) of SaaS apps and authorizations in an enterprise. Stolen session tokens, abused OAuth flows, device code phishing, and browser-native credential harvesting let adversaries operate entirely within sanctioned tools and legitimate traffic. 
Scattered Spider, and more recent evolutions like Scattered Lapsus$ Hunters, operate inside victim environments using legitimate SaaS APIs and identity tooling: SSO, MFA bypass via social engineering and post-auth attacks, and direct access to cloud management planes. In every case, the attackers aren’t hiding from EDR; they’re operating in the browser context where EDR doesn't see.
This “missing middle” is a structural gap: EDR owns the endpoint, and the IdP owns authentication events. But the space in between - the authenticated browser session, the OAuth token, the SaaS API call from a legitimate identity - belongs to no tool and appears on no dashboard. It’s a second front for LOTL, and most blue teams don't have a strategy for it because they don't have visibility into it.
This talk maps the evolution of LOTL techniques from endpoint to identities and SaaS, walks through the attack patterns that define the second front (AitM session hijacking, OAuth abuse, infostealer-to-IAB pipelines, MFA-resilient phishing infrastructure), and describes a practical detection framework that addresses both fronts simultaneously. We'll look at what telemetry sources actually exist for in-browser and identity-plane activity, how to build detection logic when you're pattern-matching against legitimate behavior rather than malicious binaries, and how SOC teams can prioritize coverage across two active fronts without exponentially increasing analyst workload.
Attendees will leave with a mental model for how these two LOTL fronts interact, a framework for evaluating their own detection coverage gaps, and concrete starting points for building detection programs that account for the full attack surface - not just the stuff that shows up in endpoint logs!
Speakers
avatar for Mark Orlando

Mark Orlando

Field CTO, Push Security
Mark is the Field CTO at Push Security, where he advances detection and response for in-browser threats. With 25 years of experience building and leading security operations teams at the White House, the Pentagon, the Department of Energy, and Fortune 500 companies, Mark has investigated... Read More →
Saturday September 12, 2026 2:00pm - 2:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

3:00pm CDT

Entra the Dragon: Entra ID Red vs Blue
Saturday September 12, 2026 3:00pm - 3:50pm CDT
Entra ID is the identity & access management system for the Microsoft cloud. Microsoft continues to add new features to Entra ID and many of these features provide attack capability. There are many moving parts and regular updates that requires attention to stay secure. This talk covers the latest attacks against the Microsoft cloud from phishing to account take-over to persistence as well as the best ways to defend against them. So go beyond Secure Score and level up your cloud security!
Speakers
avatar for Sean Metcalf

Sean Metcalf

Identity Security Architect, TrustedSec
Sean Metcalf  (@PyroTek3) is an Identity Security Architect with TrustedSec. He is one of about 100 people in the world who holds the Microsoft Certified Master Directory Services (MCM) Active Directory certification and is a former Microsoft MVP. Sean has presented on Active Directory... Read More →
Saturday September 12, 2026 3:00pm - 3:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

4:00pm CDT

Trusted, But Dangerous: Identity Abuse Through First-Party Apps in Entra
Saturday September 12, 2026 4:00pm - 4:50pm CDT
Microsoft Entra environments rely heavily on implicit trust in Microsoft first-party applications, yet most defenders have limited visibility into how expansive that trust boundary truly is. With more than 4,000 Microsoft first-party app IDs, many operate as “ghost” applications: active in authentication and token issuance, but not clearly represented in enterprise application views or routinely monitored by defenders. This creates a significant blind spot in identity security.
This session explores how these trusted applications can be abused through Resource Owner Password Credentials (ROPC), Family of Client IDs (FOCI), and token issuance behaviors that extend access beyond what defenders typically expect. Rather than focusing on generic anomalous sign-ins, the talk centers on capability: the delegated scopes these applications request, the permissions they inherit, and how those access paths can be leveraged to persist and expand access within a tenant. These behaviors can be executed through standard Graph API interactions and demonstrate how ROPC can be leveraged to obtain tokens without interactive authentication and, in many real-world environments aligned with historical Microsoft guidance, results in effective MFA bypass conditions.
Attendees will learn how ROPC remains relevant in modern identity attacks, how first-party application trust complicates Conditional Access enforcement, and why policy evaluation differs between interactive and non-interactive authentication paths. The session also examines token lifecycle in depth, including how refresh tokens can persist for extended periods, how Continuous Access Evaluation (CAE) impacts enforcement, and why resetting user credentials does not necessarily revoke active access without additional token invalidation steps.
From a defensive perspective, this talk provides practical, immediately usable guidance. It includes KQL queries specifically designed to identify ROPC authentication activity, enumerate first-party application usage, and help defenders understand which client applications are requesting access and with what scope. It also covers Conditional Access policy considerations, validation techniques, and response actions to take during identity incidents involving token abuse.
A companion GitHub repository is included with ready-to-use KQL queries, detection logic, and example configurations. Attendees will leave with a concrete understanding of how first-party application trust can be abused, where visibility and enforcement gaps exist, and how to build effective identity-focused detection and response workflows in Microsoft Entra.
Speakers
avatar for Jon Haas

Jon Haas

Threat Hunter, Nationwide
Jon Haas is a Threat Hunter at Nationwide specializing in identity security, cloud detection engineering, and adversary tradecraft in modern SaaS environments. His work focuses on uncovering gaps in authentication controls, including OAuth abuse, first party application behavior... Read More →
avatar for Joe Morrissey

Joe Morrissey

Director & Incident Commander, Nationwide
Joe Morrissey is a Director of the CSIRT at Nationwide, specializing in intrusion detection, network forensics, and incident response. His work focuses on strengthening security operations, improving detection and investigative capabilities, and preparing teams to respond effectively... Read More →
Saturday September 12, 2026 4:00pm - 4:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

5:00pm CDT

Behaviour-Driven Detection for Software Supply Chain Exploitation
Saturday September 12, 2026 5:00pm - 5:50pm CDT
Abstract
Modern software development depends on an intricate ecosystem of open‑source libraries, third‑party services, CI/CD workflows, container registries, package repositories, and cloud‑native infrastructure. As organizations accelerate development velocity, their applications increasingly rely on components they neither wrote nor control. This creates a supply chain environment where the weakest external link becomes the attacker’s easiest entry point. While Application Security (AppSec) teams focus on code reviews, SAST/DAST, SCA results, and secure SDLC controls, many of the most dangerous threats originate outside their visibility. These include malicious dependency updates, compromised package maintainers, poisoned CI/CD pipelines, hijacked SDKs, and third‑party API breaches—risks that traditional AppSec tooling isn’t designed to detect.
At the same time, Cyber defence teams track adversary activity, ecosystem‑level manipulation, suspicious code commits, dark‑web chatter, targeted campaigns against popular libraries, and exploitation of software supply chain dependencies. They see indicators and emerging threats far earlier than any automated scanner—but this intelligence rarely makes its way into AppSec decision‑making. As a result, AppSec teams continue to approve dependencies with no CVEs, unaware that the maintainer was compromised; security testing pipelines approve builds even though TI has already flagged one of the upstream components; and organizations ship production code containing malicious logic that no scanner will ever detect because the code behaves "as designed"—just not by your design.
This talk presents a unified model for bridging these gaps—delivering a strategic approach through supply chain defence. Attendees will learn how real‑world supply chain attacks unfold, why they bypass traditional AppSec controls, and how integrating cyber defence changes the defender’s perspective. We break down practical detection methods for ecosystem‑level anomalies, maintainer compromise signals, malicious package patterns, CI/CD infiltration attempts, and signs of upstream component manipulation. Through real attack examples and defensive case studies, we show how organizations can fuse AppSec findings (SCA results, dependency mapping, SBOM data) with cyber defence to build an adaptive, intelligence‑driven supply chain protection strategy.
Key Takeaways
  • Why AppSec alone cannot detect supply chain compromise — and the specific blind spots hidden inside package ecosystems, CI/CD pipelines, and third‑party integrations.
  • A practical integration model where AppSec and Cyber defence team jointly monitor, validate, and block risky dependencies or services before they reach production.
  • Field-tested workflows for real-time supply chain monitoring using SBOM enrichment, threat feeds, dependency risk correlation, and behaviour-based anomaly detection.
  • A blueprint for building an enterprise supply chain defence program that continuously adapts to attacker evolution, ecosystem shifts, and vendor risks.
Why This Talk Is Important
Supply chain attacks are now a preferred strategy for both state-sponsored and financially motivated threat actors. They exploit trust relationships between developers, automation systems, and ecosystem maintainers—areas where AppSec with cyber defence team lacks visibility with limited operational influence. This session provides a practical, actionable roadmap for bringing both teams together to defend the modern software supply chain—before adversaries weaponize it.
Speakers
avatar for Niladri Sekhar Hore

Niladri Sekhar Hore

Lead Engineer - Threat Detection and Automation, StoneX
Niladri Sekhar Hore is a Lead Engineer at StoneX Group in Threat Detection and Automation. He builds data-driven detection systems and security automation frameworks across cloud and hybrid environments, focusing on operationalizing  security intelligence into measurable runtime... Read More →
Saturday September 12, 2026 5:00pm - 5:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 1
 
Sunday, September 13
 

10:00am CDT

The Malware Is Coming from Inside the Repo
Sunday September 13, 2026 10:00am - 10:50am CDT
GitHub isn't just where developers work. It's where adversaries stage, obfuscate, and deliver malicious code. Every minute, thousands of commits hit public repositories, and buried inside that firehose are credential stealers, reverse shells, crypto drainers, and the occasional nation-state lure dressed up as a coding challenge. The platform's openness, trust, and sheer volume are exactly what make it useful to attackers: free hosting, free CDN, a developer-friendly domain in every allowlist, and a culture where running npm install or cloning a stranger's repo is just Tuesday.

This talk is about what happens when you actually try to watch all of it.

We'll walk through github-threat-scanner, a pipeline that consumes the GitHub public event stream in near real time, pulls down the code behind every push, and runs it through a stack of decoders and detection rules looking for anything that smells wrong. The interesting problems aren't where you'd expect. Ingesting the stream is easy. Storing it is a solved problem. The hard parts are everything in between: peeling back the layers of obfuscation attackers use to hide payloads, deciding what "malicious" even means when half the internet's legitimate code looks suspicious, and keeping false positives low enough that a human analyst can still trust the queue.

We'll dig into the deobfuscation engine (CyberSaucier), a library of CyberChef recipes that chain together XOR bruteforcing, base64 and hex decoding, packed-JavaScript unwrapping, PowerShell de-munging, and the other tricks that turn a wall of gibberish back into something a detection rule can match on. You'll see which recipes earn their keep, which ones we retired because they were pure theatre, and the surprisingly mundane reasons some decoders fail in production that never show up in a blog post.

Then we'll get to the fun part: who's actually out there. Commodity and Nation State actors treat GitHub Pages as disposable infrastructure. And threading through all of it are the targeted operations: DPRK-aligned clusters running fake job interviews and "technical assessments" that ship trojanized projects to developers at crypto firms and long-running personas that maintain plausible commit histories for months before turning hostile.

You'll leave with a concrete picture of how to build this kind of visibility yourself, what the detection surface actually looks like once you're watching it, and why GitHub deserves a seat in your threat model next to email and the browser. If you run a security team, you'll walk out with questions to take back to your developers. If you write detections, you'll have new ideas for where to point them. And if you just like watching adversaries do dumb things at scale, there will be plenty of that too.


The best part of all of this? Most of this data was initially triaged and analyzed by an autonomous AI analyst running in a throwaway VM in dangerous mode, unafraid of touching actual adversary infrastructure.

No prior knowledge of GitHub internals required. Bring opinions about regex.
Speakers
avatar for Justin Borland

Justin Borland

Director of Threat Engineering, Abstract
A proven technical leader in the security industry, Justin started his career with a Canadian Secret clearance while still in College. After graduating, he spent the next decade building custom packet capture systems, intrusion detection systems, logging systems, and DFIR tooling... Read More →
Sunday September 13, 2026 10:00am - 10:50am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 1

11:00am CDT

Fortress in a Box: Enterprise-Grade Kubernetes Security for the Organizations That Can't Afford It
Sunday September 13, 2026 11:00am - 11:50am CDT
In 2022, the Red Cross was breached and data from 515,000 vulnerable people was exposed. Amnesty International was surveilled by state-sponsored attackers. Bellingcat, the group that documents war crimes, is a constant target of state actors trying to destroy evidence.
These organizations protect the most vulnerable, and have zero security budget to defend themselves.
This talk presents Fortress in a Box, an open-source, one-command Kubernetes security platform built specifically for NGOs, journalists, and human rights organizations. It implements four layers of defense-in-depth: CI/CD scanning with Trivy, admission control with Kyverno, real-time runtime threat detection with Falco, and GitOps self-healing with ArgoCD — fully configured, zero Kubernetes expertise required.
Attendees will see a live demo where Kyverno blocks an insecure deployment and Falco catches unauthorized container access in seconds, routing alerts directly to Discord — no SIEM required.
Takeaways: a clear understanding of how defense-in-depth works in Kubernetes, the specific policies that block the most common attack vectors, and how to deploy Fortress in their own infrastructure that same day.
Speakers
avatar for José Lorenzana

José Lorenzana

DevSecOps Student & Open Source Developer
A computer science student and DevSecOps practitioner focused on making enterprise-grade security infrastructure accessible to organizations that need it most. With hands-on experience in Kubernetes, containers, and cloud security, their work sits at the intersection of technical... Read More →
Sunday September 13, 2026 11:00am - 11:50am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

12:00pm CDT

Reconstructing Reality: Advanced USN Journal Extraction and Full-Fidelity Correlation with MFT
Sunday September 13, 2026 12:00pm - 12:50pm CDT
The NTFS USN Journal remains one of the most underutilized yet powerful forensic artifacts in Windows environments. While widely known, its practical use is often limited by incomplete parsing, lack of context, and the inability to correlate it effectively with other filesystem structures such as the Master File Table.
This session challenges long standing forensic assumptions about how filesystem evidence should be interpreted. Traditional approaches treat artifacts such as the USN Journal and the Master File Table as separate and partially reliable sources of truth. Our research demonstrates that this model is fundamentally flawed.
Many widely used forensic tools silently ignore critical fields, leading to incomplete or misleading conclusions. As a result, investigators often rely on partial visibility when reconstructing attacker activity.
We introduce a comprehensive approach to extracting, parsing, and operationalizing USN Journal data at scale, using full field analysis to reconstruct detailed file system activity. A key contribution of this work is a novel correlation model between USN Journal entries and Master File Table records, enabling investigators to rebuild complete timelines with significantly higher accuracy.
By combining these artifacts and analyzing all available metadata, we show that it is possible to detect inconsistencies, uncover hidden attacker activity, and validate events that would otherwise remain ambiguous or invisible.
This approach redefines how filesystem forensics should be performed, transforming fragmented artifacts into a unified and reliable representation of system activity. The techniques presented are actively used in real world incident response and threat hunting engagements, where precision and speed are critical.
Speakers
avatar for Paula Januszkiewicz

Paula Januszkiewicz

CEO and Founder, Cybersecurity Expert, CQURE
Paula Januszkiewicz is the Founder and CEO of CQURE and CQURE Academy, globally recognized organizations delivering cutting-edge cybersecurity consulting and advanced training since 2008. She is an Enterprise Security MVP, Microsoft Regional Director, and one of the world’s leading... Read More →
Sunday September 13, 2026 12:00pm - 12:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 1

1:00pm CDT

The Only Way to Win Is by Learning: Deception Design, Read Through a Comedy Game Show
Sunday September 13, 2026 1:00pm - 1:50pm CDT
Most deception technology fails the same way a bad magic trick fails: the audience can see the strings. A pristine honeypot, a too-obvious credential, a decoy environment without any of the messy human fingerprints of a real network — these tip off skilled attackers in the first thirty seconds of contact and then sit unused, generating no intelligence and no value.
This talk argues that the people who have already solved this design problem are, improbably, the writers of Dropout's Game Changer — a comedy game show where contestants don't know the rules, and where the host's entire job is to design environments that intelligent, adaptive people will inhabit fully while being watched. The parallels to defensive cyber deception turn out to be precise and useful.
Working through concepts including verisimilitude and "coherent imperfection," choice architecture and the path of least resistance, flow-state engineering for sustained engagement past the initial probe, nested observation layers modeled on the show's "Bingo" episode, and the counterintuitive Tularosa finding that announcing deception makes it more effective, this session translates game-design craft into practical honeypot, honeytoken, and deception-fabric architecture any defender can deploy.
Attendees will leave with a design checklist for building deceptive environments that sustain coherence under adversarial pressure, a vocabulary for evaluating commercial deception platforms against actual attacker psychology, and an argument for why the best deception operators are, in a real sense, game designers.
The talk is interactive. The audience is already playing.
Speakers
avatar for Dylan Shroll

Dylan Shroll

Security Engineer, Bankers Trust
Dylan is a cybersecurity engineer with six-plus years across healthcare, financial services, lottery, and logistics — everywhere the stakes are high and the regulations are higher still. She specializes in LLM-powered cyber deception operations and behavior-science-driven security... Read More →
Sunday September 13, 2026 1:00pm - 1:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 1

2:00pm CDT

Strength in Diversity: Building an Inclusive Cybersecurity Workforce
Sunday September 13, 2026 2:00pm - 2:50pm CDT
The presentation “Strength in Diversity: Building an Inclusive Cybersecurity Workforce” explores how diversity across race, gender, sexual orientation, and neurodiversity strengthens cybersecurity by fostering innovation, resilience, and more adaptive defenses. It argues that cybersecurity is as much about people and perspectives as it is about technology, and that inclusion drives strategic advantage in addressing complex, evolving cyber threats.
The introduction sets the tone by positioning diversity not just as a social ideal but as a core element of operational effectiveness. It emphasizes that a broad range of lived experiences improves problem-solving and enhances anticipation of attacker behavior. A personal story titled “A Gay Man’s Journey Through Change and Resilience” illustrates this principle through a cybersecurity professional who endured discrimination and living through the AIDS crisis, eventually turning adversity into empowerment, mentorship, and advocacy for diversity in tech.
Data presented from 2023 industry studies—including (ISC)², CyberSeek, and ISACA—reveals progress and persistent gaps. Women comprise about 26% of the U.S. cybersecurity workforce, while approximately 62% of professionals identify as White. Black, Hispanic/Latino, and Asian professionals represent roughly 9–10%, 8%, and 17–18% respectively. Around 7–8% of cybersecurity professionals identify as LGBTQ+, and 5–10% are estimated to be neurodivergent. Leadership, however, remains disproportionately White and male.
Subsequent sections examine how specific forms of diversity enhance cybersecurity effectiveness. Racial diversity introduces broader cultural understanding and region-specific threat identification. LGBTQ+ inclusion fosters authenticity, psychological safety, and creativity—core elements of innovative problem-solving. Gender diversity improves usability, ethical awareness, and understanding of human vulnerabilities in security systems. Neurodiversity, though only briefly mentioned, provides unique cognitive strengths like pattern recognition and sustained focus, valuable in security analysis.
The presentation warns against “groupthink,” which arises in homogeneous teams and can blind organizations to unseen threats. Diverse teams, by contrast, challenge assumptions and expand awareness. The business case follows: data show that organizations with diverse teams outperform peers in innovation, responsiveness, and decision-making. In cybersecurity—where agility is essential—diverse perspectives directly translate into better incident response and threat intelligence.
Practical guidance focuses on dismantling systemic barriers such as implicit bias, inequitable advancement, and limited mentorship. Recommendations include inclusive hiring, employee resource groups (ERGs), leadership training on unconscious bias, and structured mentorship for underrepresented professionals. Building an inclusive culture requires active allyship, where leaders champion belonging and empower all employees to participate fully.
Looking toward the future, the presentation notes that global cyber threats demand culturally intelligent solutions and that younger, more diverse generations will reshape the field. The call to action urges professionals to recruit widely, support consistently, and lead inclusively. The final message encapsulates the presentation’s core thesis: diversity of people produces diversity of thought—creating stronger, more resilient cybersecurity defenses for all.
Speakers
avatar for Rick Hudson

Rick Hudson

CTO, Critical Path Security
Rick Hudson is currently the CTO (Chief Technology Officer) for Critical Path Security. Rick is a member of the InfraGard (InfraGard is a partnership between the Federal Bureau of Investigation (FBI) and members of the private sector for the protection of U.S. Critical Infrastructure... Read More →
Sunday September 13, 2026 2:00pm - 2:50pm CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk Track 1
 
Blue Team Con 2026
From $0.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.