Call for Speakers

What We Are Looking For…

We are seeking new ideas, actionable insights, innovative research, compelling case studies, and practical experiences that advance the practice of security and incident response.

We especially welcome:

Ideas that can be shared and applied by other teams without requiring proprietary information or software are particularly welcome.

We encourage you to share what you have learned, what has worked—or failed—and what others in the community can take away from your experience.

No Sales or Marketing Presentations: Presentations must provide meaningful technical or operational value and must not be primarily intended to promote or sell a commercial product, solution, or service.

Important Dates

Suggested Topics

We invite submissions guided by the following broad topics:

1. AI-Enabled Adversaries and Adaptive Defense

Potential submissions: autonomous attack chains, AI-generated malware, AI-enabled phishing and social engineering, machine-speed exploitation, AI-assisted reconnaissance, adversary adaptation, AI-driven deception, adaptive defense, AI-enabled vulnerability exploitation, and real-world AI-enabled attacks.

2. Incident Response in Intelligent and Connected Environments

Potential submissions: cloud and SaaS incidents, IoT, ICS/CPS, APIs, connected infrastructure, network and endpoint incidents, multi-environment investigations, modern enterprise IR, incident containment, response orchestration, and complex incident coordination.

3. Digital Forensics, Investigation and Attack Analysis

Potential submissions: digital forensics, memory and endpoint forensics, malware analysis, reverse engineering, evidence collection and preservation, attack-chain reconstruction, threat actor infrastructure analysis, attribution, forensic tooling, investigation methodologies, cloud forensics, and real-world investigation case studies.

4. Detection, Threat Intelligence and Adversary Analysis

Potential submissions: detection engineering, threat hunting, behavioral analytics, threat intelligence, adversary intelligence, threat actor tracking, detection methodologies, intelligence analysis, indicators of compromise, campaign analysis, and measurable improvements in detection.

5. Human-Machine Incident Response

Potential submissions: AI-assisted triage, investigation support, security copilots, response automation, automated containment, analyst decision support, human oversight, AI reliability and validation, human-machine decision frameworks, responsible automation, and measuring AI-assisted response effectiveness.

6. Defending the Defenders

Potential submissions: manipulation of security tooling, attacks against security operations platforms, malicious RAG data, security-control evasion, deceptive indicators, compromised detection systems, attacks against automated response mechanisms, and defensive infrastructure compromise.

7. Identity Beyond the Human

Potential submissions: AI agents, service accounts, workloads, machine identities, tokens, API keys, agent-to-agent access, credential compromise, privilege escalation, identity-based attacks, access-path analysis, containment, and accountability.

8. Response Across Organizational Boundaries

Potential submissions: third-party compromise, supplier incidents, software and hardware dependencies, software supply chains, open-source ecosystems, cloud-provider incidents, shared responsibility, collective cyber defense, coordinated vulnerability response, information sharing, and ecosystem-level response.

9. Engineering for Response-Ready Products and Systemic Resilience

Potential submissions: secure-by-design, DevSecOps, product security, PSIRT, vulnerability discovery and disclosure, rapid vulnerability response, exploitability assessment, security testing, software provenance, observability, root-cause analysis, systemic weaknesses, durable remediation, recovery validation, resilience engineering, and lessons from product security incidents.

10. Operating Models, Crisis Leadership and Responsible Security

Potential submissions: SOC/CSIRT/PSIRT operating models, organizational maturity, incident command, security leadership, decision-making under uncertainty, crisis coordination, executive communication, workforce evolution, governance, privacy, ethics, standards, regulations, accountability, responsible security practices, and balancing automation with human oversight.

Presentation Styles and Formats

We welcome technical presentations that share research, real-world experiences, case studies, practical approaches, tools, methodologies, or lessons learned relevant to the security and incident response community.

The Review Process, Tips, and Guidelines

All submissions are reviewed by the program committee, composed of experts and practitioners representing a diverse set of teams and organizations. They are responsible for selecting the best and most relevant talks to make up the conference program. FIRST does not require you to submit a formal paper for consideration. However, your submission must at least let the reviewers understand:

You must provide a detailed outline (recommended 300-500 words) and an abstract (no more than 250 words, though we recommend 100-150 words) to explain what the talk is about in a way that makes people interested in hearing it. You are welcome to include additional materials to support any of these points. Submissions must be received by the closing date by November 21, 2026 (UTC+14:00) or they will be rejected.

Speaker Privileges

There is no fee for speakers to attend the event. Accepted speakers will be required to complete the online event registration form for badging purposes.

Speakers provide consent for FIRST to record their presentations in audio and/or visual form and grant FIRST a royalty-free license to use, reproduce, and distribute the recordings and accompanying materials. Speakers also understand that while they retain the rights to their presentation materials (handouts, slides, etc.) and the content of the presentation, FIRST is the sole copyright owner of any recording and can distribute the recording, along with any supporting materials in any way, with the appropriate attribution of the speakers. Submitters can indicate an opt-out for recording their presentation.

The FIRST Technical Colloquium conference is open to the public and welcomes non-members, press, and social media coverage. After the conference, presentation materials will be made available on the public area of the FIRST website. If your presentation will be sensitive in nature and will require special handling, you must indicate your TLP level during your CFS submission. Submitters may be asked to explain the reason for the chosen TLP level. TLP definitions can be found at www.first.org/tlp.

Professional photographs, audio, and video will be captured during the Conference. Conference Attendees wearing lanyards indicating their approval to be photographed/recorded, grant FIRST and its representative’s permission to photograph and/or record them during Conference activities and to use such recordings in support of FIRST’s mission. Uses of records may include but are not limited to, electronic broadcasting on FIRST’s YouTube Channel, educational initiatives, post-conference reporting, and FIRST’s social media activities.

FORMS FOR SUBMISSION