Call for Papers!

Announcing the call for papers (CFP) for the next annual FIRST Technical Colloquium (TC) in Amsterdam, Netherlands: March 2–4, 2027.

The CFP opens on October 1, 2026, and we will close it on January 10, 2027.

Our theme: AI in incident response — attack and defense

For years our theme has been incident response. This year we turn that lens on AI: the same intelligence that breaks a defense can rebuild it. We want technical talks on both edges of that blade — how attackers are weaponizing AI, and how defenders are using it and securing it.

The call for papers is now open! Note this will be an in-person event. There will be no virtual talks — only send an abstract if you can be there in-person.

To submit your presentation abstract for review:

Submit Presentation

Registration is free and always fills up quickly — note you must commit to attending, as we pay the venue per seat and want to make sure we don’t end up with any empty seats. Registration details will be announced on the event website.

The TC will be a plenary-style conference held on the 3rd and 4th of March 2027 at a venue in downtown Amsterdam, Netherlands. In addition, we will host one optional, free training workshop day on Tuesday, March 2nd.

The idea behind the TC is to encourage security teams and talented researchers to share their technical work in a friendly environment. We encourage anyone who has not spoken at a conference before to submit a proposal. We can help new presenters review their materials in preparation for submission. Local talent is welcome from anywhere (although travel and other expenses are not covered by FIRST, we cannot sponsor visas or invitation letters).

We are interested in new ideas and presenters. Any novel idea, technique, case study, or piece of research where AI meets incident and threat response is welcome — including how teams walk through actual security incidents. Suggested topics, split across two tracks:

Track A — AI in Attack Track B — AI in Defense
How AI attacks How AI defends
  • LLM-assisted malware, exploit generation, and autonomous attack chains
  • Prompt injection, jailbreaks, and abuse of agentic / tool-using AI
  • Model and data poisoning, backdoors, and training-supply-chain attacks
  • Deepfakes and AI-scaled social engineering, phishing, and fraud
  • Adversarial ML: evasion of detection and classification models
  • Attacks on AI pipelines, MLOps, model registries, and inference APIs
  • Criminal underground and state-backed actors adopting AI
  • Real-world security incidents involving AI-enabled threat actors
  • AI in incident detection and response that actually ships
  • LLMs for alert enrichment, triage, and incident summarization
  • Operationalizing AI for threat hunting and TI ingestion / alerting
  • AI red-teaming, model evaluation, and guardrail engineering
  • Securing the AI supply chain: model provenance, signing, and policy
  • Detecting AI-generated content, deepfakes, and synthetic identity
  • Digital forensics and IR playbooks for AI-enabled environments
  • Lessons from defending production AI systems under attack

Submission requirements

All talks must be 45 mins (including time for Q&A). For your submission to be reviewed, you must submit using the EasyChair form and provide ALL of the following information:

Our goal is to have the program on the event website as soon as possible. To that end, please have all submissions completed by January 10, 2027.

Speaker Privileges

This is a free conference; we cannot sponsor travel or other honorarium support.

Important Notes

FIRST does not allow presentations to gain the audience's interest in any commercial application, solution or product. In other words: NO MARKETING PRESENTATIONS. Any commercial product demo, sales pitch, or marketing presentation will be rejected. Likewise, talks that veer into product/marketing will be stopped.

Program Committee