Chair
Patrick Grau is a Senior Manager at the Bosch Group and is responsible with his team for Cyber Threat Intelligence, Threat Hunting and Threat Control Management (including Detection Engineering). Prior to that, he was the Cyber Threat Intelligence Lead and part of the Bosch CERT as an incident manager with a preference for analysis and digital forensics. In addition, he graduated somewhere, holds a degree in something, has some expired certificates, and owns more than one computer.

DE
Chair
Dr. Thomas Schreck is a Professor for IT-Security at the Munich University of Applied Sciences. Prior he was a Principal Engineer for IT-Security at Siemens and the Head of Siemens CERT. He served between 2015 and 2021 on the Board of Directors of FIRST.org and was the Chairman from 2017 to 2019.
He holds a PhD in Computer Engineering from the Friedrich Alexander University Erlangen-Nuremberg and a Diploma in Computer Science for the University of Applied Sciences Landshut.

FIRST Liaison Member, MX
I have 16 years of experience in cybersecurity, including 10 years in incident response and CTI. Since 2015, I have held leadership and management roles in the aforementioned areas.

Google, DE
Alexander Jäger is a Senior Security Engineer at Google and doing Incident Response and Digital Forensics. At Google, he leads large-scale security incidents and is a core maintainer of Timesketch, the open-source forensic timeline analysis tool. With over a decade of frontline experience defending major enterprises, Alex is deeply committed to strengthening the global security community. He previously served on the board of FIRST, including as CFO and continues to contribute to various open-source projects and community events.

Booking.com, NL
Since the early 2000s Anastasios has been involved with cyber security starting from the offensive side of vulnerability research and exploit development and gradually moving to the defender’s side in the area of incident response, digital forensics, and security engineering. In the process he acquired several industry accreditations along with a M.Sc. in Secure Computing Systems. The last few years Anastasios has been focusing on intelligence and he is currently working as Senior Manager for Enterprise Security Engineering at Booking.com. Anastasios has presented his research to various industry conferences and events organised by BSides, Google, RecordedFuture, FIRST, DeepINTEL, x33fcon, SEC-T, ENISA, and others.

Mnemonic, NO
Andreas is a seasoned Cyber Threat Intelligence (CTI) analyst and Threat Hunter (TH) with over 15 years in cybersecurity. He currently specializes in the analysis of adversary tradecraft, providing actionable intelligence for strategic and tactical use, and leading and supporting hunting programs and various intelligence initiatives for mission success.
Throughout his career, Andreas has led multiple teams in threat intelligence, detection engineering, and incident investigation. He strongly advocates for intelligence-driven defense to mitigate complex cyber threats and collaborates with other CTI researchers for investigation, profiling and tracking. He is dedicated to improving detection- and hunting capabilities by deeply understanding adversary tactics and techniques, as well as refining methods for operationalizing intelligence.

Swisscom, CH
Andreas Muehlemann has been working over 15 years in IT security. He has worked for different industries like Finance, Industry, Logicstic, Electricity, Research and has a broad background in Cyber Security, Network Security and Linux Security. His current role in the CTI Team of Swisscom includes Cyber Threat Intelligence, IOC sharing, malware analysis and network security. He's actively contributing in FIRST SIGs and passionate about open source software.

ThreatIntel.EU, GR
Andreas Sfakianakis is a Cyber Threat Intelligence professional with over fifteen years of experience in cyber security. He focuses on applying threat intelligence and helping organizations manage threats mostly within the Energy, Technology, and Financial sectors as well as in European Union’s Agencies and Institutions. Andreas has been contributing to the CTI community since 2012 via public reports and presentations, his blog, newsletter, and instructing. His utmost goals are the maturing of threat management programs within organizations as well as the embedding CTI in policy making. Andreas Twitter handle is @asfakian and his website is threatintel.eu.

Infocomm Media Development Authority Singapore, SG
I have over 20 years of information security & technology experience from banks, technology companies and government agency, based out of Singapore. I have experience evaluating cybersecurity risk, having practitioner experience conducting threat analysis and assessment and leading cyber incident investigation. My responsibilities include evaluating risk and impact to the organisation and preparing advisories recommending mitigations solutions to detect and prevent attacks, to the executive committee with regards to cyber threats that impact the sector/organisation.
CERT-India, IN
Arpit Raj is a cybersecurity professional with over 12 years of experience in the domains of electronics, information technology, and telecom, including nearly 6 years specializing in cybersecurity. He is currently working at CERT-In (Indian Computer Emergency Response Team), where he is part of the Malware Analysis and Threat Intelligence team. In his current role, he focuses on malware analysis, with a special interest in nation-state Advanced Persistent Threat (APT) groups targeting India. Additionally, he is actively involved in threat hunting, digital forensics, and supporting incident response activities.

Silobreaker, CA
Brian lives and breathes collaboration and threat Intelligence. A German living in Canada's Capital Ottawa (via Laguna Beach, California) who has spent years conducting advanced threat research at HP's Office of the CTO and HP Security Research as well as at Flashpoint Intelligence. Brian also explored cyber threat intelligence at DTAG, one of the world’s largest carriers. After a year supporting Canadian initiatives, he joined Silobreaker, who have supported Brian’s mission for over a decade. Brian has co-authored several books and helped develop a couple of patents. Recently Brian was appointed liaison member to First.org the Forum of Incident Response and Security Teams. Brian also influences/leads various gatherings of OSINT/TI practitioners that constantly collaborate to improve tooling as well as collaborative defenses.

DCSO Deutsche Cyber-Sicherheitsorganisation GmbH, DE
Christoph Lobmeyer is Lead Threat Researcher at DCSO where he focusses on providing actionable intelligence for customers and for internal purposes. Prior to that, he primarily worked in DFIR, as an analyst, incident manager and leadership positions. His passion lies in automating painstaking manual processes and navigating the interface between geo-political developments and technological reality.

Siemens, DE
Former head of Cyber Threat Intelligence at Siemens CERT. Hired and trained by the best on the market. Served in every FIRSTcon and FIRSTCTIcon PC of the past few years.
Agnostic Intelligence AG, CH
Florian Klaus Kaiser is a senior consultant with Agnostic Intelligence AG, Zug, Switzerland with a focus on Cyber Threat Intelligence. He received his Dr.-Ing. from Karlsruhe Institute of Technology (KIT), Karlsruhe, Germany. He worked at the National Competence Centre for Applied Security Technology and Institute of Information Security and Dependability (KASTEL) and associated with Cyber@Ben Gurion University (CBG), Beer Sheva, Israel.

GreyNoise Intelligence , US
Glenn Thorpe is the Sr. Director of Security Research and Detection Engineering at GreyNoise Intelligence. His journey in the cybersecurity industry began when he fell victim to a phishing scam; this ignited his interest in protecting digital assets and infrastructure and kicked off his career of 20+ years. His passion for digital forensics, incident response, and security communications led him to consult with organizations to detect and respond to high-priority threats. When not at work, Glenn enjoys studying weather patterns and planning his next shark diving expedition.

Birkenstock, DE
Jamila Wilson is an IT Security Officer at Birkenstock, where she is responsible for leading Security Operations and driving strategic cyber resilience for the global enterprise. Prior to Birkenstock, Jamila served as an IT Security Engineer at FTI Group, focusing on Cyber Threat Intelligence (CTI), Vulnerability Management, and Security Awareness. She holds a Master of Science in Information Science from North Carolina Central University and is a CISSP and ITILv3 certified professional.

Google, US
I've been doing CTI since about 2005 when at Arbor Networks and investigating various DDoS attacks, botnets, and techniques. I have worked on a variety of CTI aspects including malware analysis techniques, geopolitical attack analysis, and for the past five years darkweb CTI. I have also trained analysts in CTI techniques and structured analysis approaches.
BCP, PE
Leonardo Francia is a cybersecurity professional with a real passion for the field and over five years of experience in the financial sector, plus additional work in government, identity management, and vehicle systems. As a threat detection specialist, he applies frameworks like DEBMM and M3TID, turning detection into a strategic process aimed at reducing impact and strengthening organizations’ cyber defense capabilities.
He’s currently involved in threat intelligence programs and initiatives based on CMM-CTI frameworks, helping generate high-value information that supports decision-making across the organization. Leonardo also has solid experience with standards such as ISO/IEC 27001 and ISO 20000, leading audits and implementations for companies in different industries and countries. He holds certifications including CEH, CTIA, ECIH, and MITRE ATT&CK, among others.
In his free time, he enjoys family lunches and traveling, both domestically and internationally, by plane or road.

Security Research Labs, DE
Lisa Lobmeyer works as a Lead Security Consultant at Security Research Labs. She is an experienced DFIR-Specialist, leading and building teams that help organizations affected by IT security incidents while at the same time trying to minimize the impact by improving organizations' Cyber Defense capabilities.

BASF Digital Solutions GmbH, DE
Rainer has been involved in cyber threat intelligence at BASF since 2016. In 2022, he took over the leadership role of a newly established cyber threat intelligence team. Prior to that, he held various manager and individual contributor positions in cyber security, including in incident response, security engineering, vulnerability management, and firewall administration.

JPMC, GB
Ryan Kovar is a globally recognised cybersecurity executive with over two decades of experience transforming chaos into strategy and duct-taped infrastructure into defensible architecture, all while losing battles with office printers. He’s gone from pulling CAT5 on an aircraft carrier to advising Fortune 100 boards who wish their security posture looked half as good as their earnings reports. From DARPA to Splunk and now his new role at JPMC, he has helped build elite security programs that start small and end up shifting the ecosystems they inhabit. Known for bridging silos, driving inclusive talent acquisition, and thriving in entropy, Ryan is equally at home briefing boards, threat intel standups, mentoring emerging talent, or gently explaining for the hundredth time why you don’t actually need PCAP if you have wire data.
Sri Lanka CERT, LK
Thilina is a seasoned Cybersecurity Specialist and Digital Transformation Leader with over a decade of progressive experience in managing and executing national level cybersecurity and ICT initiatives. Currently serving as Manager – Cyber Security Capacity Building (Research, Policies & Projects) at Sri Lanka CERT. Thilina leads mission critical projects that strengthen the country’s cybersecurity posture, particularly in the protection of Critical National Information Infrastructure (CNII).
He has played a pivotal role in the formulation and implementation of cybersecurity strategies, policies, and capacity building programs for government institutions and critical sectors. His work includes conducting risk assessments, gap analyses, capacity building and the development of policy frameworks aligned with global best practices. Under his leadership, over 5,000 key government officials and stakeholders have been trained in cybersecurity awareness, secure coding, systems & infrastructure , incident response, regulatory compliance, information technology, policy adoption and project management . He is also a key contributor to cybersecurity research, focusing on policy adoption, skills development frameworks, internet governance, and emerging cyber threats.
Prior to joining Sri Lanka CERT, he held multiple roles at the Information and Communication Technology Agency (ICTA) of Sri Lanka, where he managed national digital initiatives and large scale e-Government projects. He also brings experience from the private sector in marketing, strategic planning, project management and public communications.
Known for his ability to align strategic vision with practical execution, Thilina is committed to advancing Sri Lanka’s cyber resilience and digital maturity through policy-driven, research-based, capacity-developed, and technology-enabled solutions.
