BoFs, SIGs, & Scheduled Side Meetings
Schedule is subject to change. Please be sure to refer to the conference mobile app during conference week for the latest and most accurate times.
BoFs & Sides (Gov Sq 10)
BoFs & Sides (Gov Sq 10)
BoFs & Sides (Gov Sq 10)
Tuesday, June 16th
| BoFs & Sides (Gov Sq 10) | |
|---|---|
| 11:00 – 12:00 | CH From Alert Fatigue to Autonomy: Redefining CSIRT Operations Jose Vazquez (NesCERT, CH) TLP:CLEAR |
| 14:35 – 15:35 | PL Analyzing Internet Background Radiation Paweł Pawliński (CERT.PL / NASK, PL) TLP:GREEN |
Wednesday, June 17th
| BoFs & Sides (Gov Sq 10) | |
|---|---|
| 09:00 – 10:00 | US Logan Wilkins (Cisco, US) TLP:CLEAR |
| 11:30 – 12:10 | IL Uri Segman & Elhay Efrat (Dream Security, IL) TLP:AMBER |
| 13:30 – 14:30 | GB US Preparing for Frontier AI Models Chris Gibson (FIRST Executive Director – FIRST.org, GB); Maarten Van Horenbeeck (Zendesk, US) TLP:CLEAR |
- ILTLP:AMBER
Agentic Campaign Inteligence
Uri Segman & Elhay Efrat (Dream Security, IL)
A single threat report names an intrusion set. An analyst's job is to answer: "So what? Does this affect us?" That question takes hours of manual pivoting, matching aliases, tracing infrastructure, cross-referencing CVEs against your own exposure. We automated it. Our agentic pipeline ingests published CTI articles, parses STIX entities, performs multi-hop pivots across attack group infrastructure, and scores each campaign against your organization's real external attack surface. Fuzzy matching handles the messy reality of threat actor naming. Graph traversal expands a single report into a mapped network of compromised assets. Multi-stage LLM classification with rule-based floors ensures nothing critical slips through. The result: campaign intelligence that is personal, prioritized, and actionable, delivered in minutes, not days.
June 17, 2026 11:30-12:10
- PLTLP:GREEN
Analyzing Internet Background Radiation
Paweł Pawliński (CERT.PL / NASK, PL)
We would like to bring together researchers, operators and CSIRTs to discuss practical approaches for analyzing unsolicited Internet traffic ("Internet Background Radiation") and converting it into actionable cyber intelligence. The session will focus on observations from network telescopes (passive monitoring of traffic sent to globally routed but unused IP space) and other types of large-scale, low-interaction sensors that reveal Internet-wide scanning, misconfigurations, worm propagation signals, and DDoS backscatter. The BoF is designed as an informal, participant-driven discussion about data capture, pipeline design (packet/flow processing, enrichment, clustering, and alerting), and analytic techniques suitable for identification of events of interest. A key outcome will be enabling practical collaboration among participants, in particular building trusted connections and facilitating sharing of selected datasets, indicators, and methods.
June 16, 2026 14:35-15:35
- USTLP:CLEAR
Bangalore TC Planning Meetup
Logan WilkinsLogan Wilkins (Cisco, US)In February, the FIRST Bangalore 2026 Technical Colloquium brought together professionals from across the region to share insights, build connections, and strengthen our collective response to emerging threats.
This meeting is to plan the next meetup for the area. Feel free to attend to learn more!
June 17, 2026 09:00-10:00
- CHTLP:CLEAR
From Alert Fatigue to Autonomy: Redefining CSIRT Operations
Jose Vazquez (NesCERT, CH)
José Vázquez is a Senior Cyber Security Specialist within the Cyber Security Incident Response Team (CSIRT), focused on transforming traditional security operations into scalable, automation-driven ecosystems. He has led initiatives to redesign incident response workflows by integrating SIEM and SOAR capabilities with autonomous L0 agents, significantly reducing manual triage efforts and operational backlog at scale. His work centers on bridging the gap between detection engineering, automation, and real-world incident response. José is particularly interested in challenging conventional SOC models and driving the evolution towards autonomous, intelligence-led cyber defense strategies.
Traditional CSIRT and SOC operating models are breaking under the weight of alert fatigue, manual triage, and ever-increasing attack surface complexity. Throwing more analysts at the problem is no longer a sustainable solution. This Bird of a Feather session challenges the status quo: what if Tier-1 no longer existed? We will explore a real-world transformation where SIEM and SOAR platforms were re-engineered to support an autonomous Level 0 (L0) agent capable of triaging, enriching, and in many cases resolving security alerts without human intervention. Rather than focusing on tools, this session opens a discussion on:
Eliminating repetitive analyst work through autonomous decision-making Designing trust in machine-driven triage and response Reducing backlog and scaling globally without linear headcount growth Shifting CSIRT roles from reactive responders to strategic threat hunters
We will share key challenges, resistance points, and lessons learned during this transition, including where automation fails and where human expertise remains critical. This is not a presentation. This is an open discussion for teams who believe the current SOC model is unsustainable and are actively exploring what comes next.
June 16, 2026 11:00-12:00
- GB USTLP:CLEAR
Preparing for Frontier AI Models
Chris Gibson
Maarten Van HorenbeeckChris Gibson (FIRST.org, GB), Maarten Van Horenbeeck (Zendesk, US)Chris brings a wealth of relevant and up-to-date experience in setting up and managing CERTs at the very highest levels of the worldwide Information and Cyber Security community.
Chris spent over 12 years working in the Computer Emergency Response Team (CERT) whilst at Citigroup and, for 10 years, was part of the leadership of the Forum of Incident Response and Security Teams (FIRST); 2 as Chair. Within FIRST he implemented the Fellowship program. This was created to fund CERTs from UN-designated “Least Developed Nations” (LDCs) allowing them both to join FIRST and attend conferences and training.
Chris joined the UK Government's CERT-UK team in November 2013 to build and launch the UK’s first formally chartered national CERT, joined Close Brothers as Chief Information Security Officer in November 2016, moved to Orwell Group as CISO in Jul 2018 and joined FIRST as it’s Executive Director in May 2019.
Chris’ experience has allowed him to work with colleagues from both inside some of the world’s largest global financial institutions with the complexities that brings and also with colleagues from the incident response community, with members ranging from Microsoft and Oracle through to the national CERTs of Azerbaijan and Indonesia.
Maarten Van Horenbeeck is a Board member, and former Chairman, of the Forum of Incident Response and Security Teams (FIRST. Maarten is also Chief Information Security Officer with Zendesk. Prior to this role, he was Vice President, Security Engineering at edge cloud network Fastly and managed the Threat Intelligence team at Amazon. Maarten has a master's degree in Information Security from Edith Cowan University, and a Masters degree in International Relations from the Freie Universitat Berlin. He is also Lead Expert to the Internet Governance Forum’s Best Practices Forum on Cybersecurity.
June 17, 2026 13:30-14:30

