Program Agenda

2026 Cyber Threat Intelligence Conference

Agenda is subject to change. Times are reflected in UTC +2 (CEST). Workshops have limited seating and based on the registration admission purchased. Plenary sessions are open to all registered delegates.

Tuesday, April 21st

Workshops
Forum 4
Workshops
Forum 5
Workshops
Forum 6
Workshops
Forum 7
08:30 – 10:00
 NL

Workshop Cyber Scenario Planning for Cybersecurity Decision-Making

Gert-Jan Bruggink (Venation, NL)

TLP:CLEAR
 CH

Cloud Forensics with Open Source: Building Your Own OSDFIR Lab on GCP

Alexander Jäger, Janosch Köpper (Google, CH)

TLP:GREEN
 NO US GB

Intelligence Collection Planning Workshop: Maturing your Threat Intelligence Program through Targeted Stakeholder Engagement and Advanced Analytic Techniques

Freddy Murstad (Nordic Financial CERT, NO); Garrett Carstens (Intel471, US); Kevin Williams (Intel471, GB)

TLP:GREEN
 DE

Detection Engineering with Sigma

Thomas Patzke (Evonik Industries AG, DE)

TLP:CLEAR
10:00 – 10:15

Networking Break

10:15 – 12:30
 NL

Workshop Cyber Scenario Planning for Cybersecurity Decision-Making

Gert-Jan Bruggink (Venation, NL)

TLP:CLEAR
 CH

Cloud Forensics with Open Source: Building Your Own OSDFIR Lab on GCP

Alexander Jäger, Janosch Köpper (Google, CH)

TLP:GREEN
 NO US GB

Intelligence Collection Planning Workshop: Maturing your Threat Intelligence Program through Targeted Stakeholder Engagement and Advanced Analytic Techniques

Freddy Murstad (Nordic Financial CERT, NO); Garrett Carstens (Intel471, US); Kevin Williams (Intel471, GB)

TLP:GREEN
 DE

Detection Engineering with Sigma

Thomas Patzke (Evonik Industries AG, DE)

TLP:CLEAR
12:30 – 13:30

Lunch

13:30 – 15:30
 US

Structured Analytic Techniques for Cyber Threat Intelligence

Scott Roberts (Remitly, US)

TLP:CLEAR
 LU

Drone Threat Intelligence Workshop

Christian Studer (CIRCL, LU); Paul Jung (He/Him) (CIRCL, LU)

TLP:CLEAR
 NO US GB

Intelligence Collection Planning Workshop: Maturing your Threat Intelligence Program through Targeted Stakeholder Engagement and Advanced Analytic Techniques

Freddy Murstad (Nordic Financial CERT, NO); Garrett Carstens (Intel471, US); Kevin Williams (Intel471, GB)

TLP:GREEN
 LU

Collaborative Detection Engineering with Rulezet

Théo Geffe (CIRCL, LU)

TLP:CLEAR
15:30 – 15:45

Networking Break

15:45 – 17:30
 US

Structured Analytic Techniques for Cyber Threat Intelligence

Scott Roberts (Remitly, US)

TLP:CLEAR
 LU

Drone Threat Intelligence Workshop

Christian Studer (CIRCL, LU); Paul Jung (He/Him) (CIRCL, LU)

TLP:CLEAR
 NO US GB

Intelligence Collection Planning Workshop: Maturing your Threat Intelligence Program through Targeted Stakeholder Engagement and Advanced Analytic Techniques

Freddy Murstad (Nordic Financial CERT, NO); Garrett Carstens (Intel471, US); Kevin Williams (Intel471, GB)

TLP:GREEN

Wednesday, April 22nd

Plenary Sessions Day 1
Forum 8
09:00 – 09:15
 DE

Welcome Remarks

Prof. Dr. Thomas Schreck (Munich University of Applied Sciences, DE)

09:15 – 09:45
 US

Evaluating Threat Intelligence Through Velocity

Joe Slowik (Paralus, US)

TLP:CLEAR
09:45 – 10:15
 NL

Dealing With Uncertainty: Scenario Planning for Cybersecurity Decision-Making

Gert-Jan Bruggink (Venation, NL)

TLP:CLEAR
10:15 – 10:45

Networking Break

10:45 – 11:15
 NO

Who Did It? Getting Started with Threat Actor Profiling

Marthe Raaheim Rogndokken (Sopra Steria, NO)

TLP:CLEAR
11:15 – 11:45
 AU

TBD

Chris Horsley (Cosive, AU)

TLP:CLEAR
11:45 – 12:15
 US

Filtering the Noise: Crafting an Actionable Threat Feed from Community-Shared Standards

JJ Josing (Retail & Hospitality ISAC, US)

TLP:CLEAR
12:15 – 13:30

Lunch

12:35 – 13:15

CTI SIG Meeting (12:35-13:15) - Room Forum 8

13:30 – 14:00

Keep Calm and ETL On: CTI 101

Jamila Boutemeur

TLP:AMBER
14:00 – 14:30
 LU

Building Intelligence with What You Have: Lessons from the Field

Casey Knerr (LU); Jean-Louis Huynen (ICRC, LU)

TLP:AMBER
14:30 – 15:00
 JP

From Grassroots to Governance: Getting CTI on Track Against All Odds

Yu Hirata (Recruit, JP)

TLP:GREEN
15:00 – 15:30

Networking Break

15:30 – 16:00
 DK

Big Game Hunting: Tracking APT's Within Covert Networks

Jonathan Andersen (Webscout, DK)

TLP:RED
16:00 – 16:30
 NL

Hunting Cyber Threat Intelligence on Telegram

Emmanuele Zambon, Luca Allodi, Roy Ricaldi, Victor Asanache (Eindhoven University of Technology, NL)

TLP:CLEAR
16:30 – 17:00

Lightning Talks

17:00 – 17:10

Day 1 Wrap Up

17:30 – 19:30

Thursday, April 23rd

Plenary Sessions Day 2
Forum 8
08:50 – 09:00

Opening Remarks: Day 2

09:00 – 09:30
 TW

One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?

Sian-Yao Huang, Yen-Shan Chen (CyCraft Technology, TW)

TLP:CLEAR
09:30 – 10:00
 GB

Operational Efficiency in CTI: A Blueprint for SME's Using Open-Source AI and Cognitive Automation

Omar Saenz, Raquel Guzman (Google, GB)

TLP:CLEAR
10:00 – 10:30
 US

Beyond Human Scale: AI and Automation as Force Multipliers in Cyber Threat Intelligence

Cydney Stude, Steve de Vera (Amazon/AWS, US); Vamshi Krishna Edamadaka (Amazon Web Services, US)

TLP:CLEAR
10:30 – 11:00

Networking Break

11:00 – 11:30
 ES

Forecasting to Stay Clear of Blizzards, Typhoons, Sandstorms, Tempests and more.

Clara Bayón González, Elena Casado González (Deloitte, ES)

TLP:GREEN
11:30 – 12:00
 LU FR

Forecasting Vulnerability Sightings Under Data Scarcity: Modeling Sparse and Bursty Cyber Threat Signals

Alexandre Dulaunoy (CIRCL, LU); Cédric Bonhomme (CIRCL, FR)

TLP:CLEAR
12:00 – 13:15

Lunch

13:15 – 13:45
 CA US

How NOT to be Your Adversary's Best Friend - Doing What Matters...

Brian Hein (Silobreaker, CA); James Shank (Expel, US)

TLP:CLEAR
13:45 – 14:15
 IN

The Integrated CERT Communication Framework (ICCF): A Behavioral Model for Effective CERT Communication, CTI Sharing, and Advisory Dissemination

Rakesh Kumar Singh, Yudhishthira Sapru (CERT-In (Indian Computer Emergency Response Team), IN); Sanjeev Kumar (C-DAC, IN)

TLP:CLEAR
14:15 – 14:45

Networking Break

14:45 – 15:15
 NL LU

OpenTide: From Raw Intelligence to Structured Threat-Informed Detections

Amine Besson (European Commission CSOC, NL); Remi Seguy (European Commission CSOC, LU)

TLP:CLEAR
15:15 – 15:45
 CZ

Signals in the Noise: Real-world Fingerprinting Stories

Vlad Iliushin (ELLIO / AMTSO , CZ)

TLP:CLEAR
15:45 – 16:15
 BR

Billions of Indicators, Zero Action: How We Fixed That

Daniel Lima, Gabriel Testoni (NTT DATA, BR)

TLP:CLEAR
16:15 – 16:30

Closing Remarks