BoFs, SIGs, & Scheduled Side Meetings

Schedule is subject to change. Please be sure to refer to the conference mobile app during conference week for the latest and most accurate times.

Tuesday, June 16th

BoFs & Sides (Gov Sq 10)
11:00 – 12:00
 CH

From Alert Fatigue to Autonomy: Redefining CSIRT Operations

Jose Vazquez (NesCERT, CH)

TLP:CLEAR
14:35 – 15:35
 PL

Analyzing Internet Background Radiation

Paweł Pawliński (CERT.PL / NASK, PL)

TLP:GREEN

Wednesday, June 17th

BoFs & Sides (Gov Sq 10)
09:00 – 10:00
 US

Bangalore TC Planning Meetup

Logan Wilkins (Cisco, US)

TLP:CLEAR
11:30 – 12:10
 IL

Agentic Campaign Inteligence

Uri Segman & Elhay Efrat (Dream Security, IL)

TLP:AMBER
13:30 – 14:30
 GB US

Preparing for Frontier AI Models

Chris Gibson (FIRST Executive Director – FIRST.org, GB); Maarten Van Horenbeeck (Zendesk, US)

TLP:CLEAR

Thursday, June 18th

BoFs & Sides (Gov Sq 10)
12:30 – 13:30

2027 PC Lunch & Learn Session

TLP:CLEAR
  •  ILTLP:AMBER

    Agentic Campaign Inteligence

    A single threat report names an intrusion set. An analyst's job is to answer: "So what? Does this affect us?" That question takes hours of manual pivoting, matching aliases, tracing infrastructure, cross-referencing CVEs against your own exposure. We automated it. Our agentic pipeline ingests published CTI articles, parses STIX entities, performs multi-hop pivots across attack group infrastructure, and scores each campaign against your organization's real external attack surface. Fuzzy matching handles the messy reality of threat actor naming. Graph traversal expands a single report into a mapped network of compromised assets. Multi-stage LLM classification with rule-based floors ensures nothing critical slips through. The result: campaign intelligence that is personal, prioritized, and actionable, delivered in minutes, not days.

    June 17, 2026 11:30-12:10

  •  PLTLP:GREEN

    Analyzing Internet Background Radiation

    We would like to bring together researchers, operators and CSIRTs to discuss practical approaches for analyzing unsolicited Internet traffic ("Internet Background Radiation") and converting it into actionable cyber intelligence. The session will focus on observations from network telescopes (passive monitoring of traffic sent to globally routed but unused IP space) and other types of large-scale, low-interaction sensors that reveal Internet-wide scanning, misconfigurations, worm propagation signals, and DDoS backscatter. The BoF is designed as an informal, participant-driven discussion about data capture, pipeline design (packet/flow processing, enrichment, clustering, and alerting), and analytic techniques suitable for identification of events of interest. A key outcome will be enabling practical collaboration among participants, in particular building trusted connections and facilitating sharing of selected datasets, indicators, and methods.

    June 16, 2026 14:35-15:35

  •  USTLP:CLEAR

    Bangalore TC Planning Meetup

    In February, the FIRST Bangalore 2026 Technical Colloquium brought together professionals from across the region to share insights, build connections, and strengthen our collective response to emerging threats.

    This meeting is to plan the next meetup for the area. Feel free to attend to learn more!

    June 17, 2026 09:00-10:00

  •  CHTLP:CLEAR

    From Alert Fatigue to Autonomy: Redefining CSIRT Operations

    José Vázquez is a Senior Cyber Security Specialist within the Cyber Security Incident Response Team (CSIRT), focused on transforming traditional security operations into scalable, automation-driven ecosystems. He has led initiatives to redesign incident response workflows by integrating SIEM and SOAR capabilities with autonomous L0 agents, significantly reducing manual triage efforts and operational backlog at scale. His work centers on bridging the gap between detection engineering, automation, and real-world incident response. José is particularly interested in challenging conventional SOC models and driving the evolution towards autonomous, intelligence-led cyber defense strategies.

    Traditional CSIRT and SOC operating models are breaking under the weight of alert fatigue, manual triage, and ever-increasing attack surface complexity. Throwing more analysts at the problem is no longer a sustainable solution. This Bird of a Feather session challenges the status quo: what if Tier-1 no longer existed? We will explore a real-world transformation where SIEM and SOAR platforms were re-engineered to support an autonomous Level 0 (L0) agent capable of triaging, enriching, and in many cases resolving security alerts without human intervention. Rather than focusing on tools, this session opens a discussion on:

    Eliminating repetitive analyst work through autonomous decision-making Designing trust in machine-driven triage and response Reducing backlog and scaling globally without linear headcount growth Shifting CSIRT roles from reactive responders to strategic threat hunters

    We will share key challenges, resistance points, and lessons learned during this transition, including where automation fails and where human expertise remains critical. This is not a presentation. This is an open discussion for teams who believe the current SOC model is unsustainable and are actively exploring what comes next.

    June 16, 2026 11:00-12:00

  •  GB USTLP:CLEAR

    Preparing for Frontier AI Models

    Chris brings a wealth of relevant and up-to-date experience in setting up and managing CERTs at the very highest levels of the worldwide Information and Cyber Security community.

    Chris spent over 12 years working in the Computer Emergency Response Team (CERT) whilst at Citigroup and, for 10 years, was part of the leadership of the Forum of Incident Response and Security Teams (FIRST); 2 as Chair. Within FIRST he implemented the Fellowship program. This was created to fund CERTs from UN-designated “Least Developed Nations” (LDCs) allowing them both to join FIRST and attend conferences and training.

    Chris joined the UK Government's CERT-UK team in November 2013 to build and launch the UK’s first formally chartered national CERT, joined Close Brothers as Chief Information Security Officer in November 2016, moved to Orwell Group as CISO in Jul 2018 and joined FIRST as it’s Executive Director in May 2019.

    Chris’ experience has allowed him to work with colleagues from both inside some of the world’s largest global financial institutions with the complexities that brings and also with colleagues from the incident response community, with members ranging from Microsoft and Oracle through to the national CERTs of Azerbaijan and Indonesia.

    Maarten Van Horenbeeck is a Board member, and former Chairman, of the Forum of Incident Response and Security Teams (FIRST. Maarten is also Chief Information Security Officer with Zendesk. Prior to this role, he was Vice President, Security Engineering at edge cloud network Fastly and managed the Threat Intelligence team at Amazon. Maarten has a master's degree in Information Security from Edith Cowan University, and a Masters degree in International Relations from the Freie Universitat Berlin. He is also Lead Expert to the Internet Governance Forum’s Best Practices Forum on Cybersecurity.

    June 17, 2026 13:30-14:30