I am a Resilience Analyst at National Grid Ventures, with a background in Computer Science and a strong interest in Operational Technology security. My experience in the energy sector has developed my interest in how cyber incidents can create real-world physical consequences. I have also competed in the Cyber 9/12 Strategy Challenge and Cyber Leaders Challenge, working through simulated crisis scenarios affecting the UK. I am particularly interested in the intersection of cyber resilience, operational technology and the systems that keep society running.
- Beyond the Air Gap: How IT/OT Convergence Changes the Attack Surface
I'm a BSc Computer Science student at the University of Glasgow, entering my fourth and final year of study. Initially interning at BT as a software developer, I have since interned twice at Microsoft, with my primary area of interest being Windows kernel vulnerability research.
I have recently began researching topics in aviation security, specifically vulnerabilities in digital communication protocols used in commercial aviation.
- Ghosts in the Sky: Creating Phantom Aircraft with Mode-S Transponder Spoofing
Andy is currently a Vulnerability Researcher with CoreTech Security based in Cheltenham. With over 20 years of experience working in various hands-on roles, including IT manager, penetration tester, software engineer and vulnerability researcher, Andy has a fair bit of experience fighting working with technology. He is a firm believer in paying it forward, and would like to share that knowledge with anyone who is interested in learning.
- Getting started in embedded device research
Aurelia is a multi-award winning early-careers advocate in cyber security. Her work spans chairing the UK Cyber Security Council's Youth Advisory Panel and supporting several tech community groups across the UK. Her past experience is in IT and Cyber Security, in both retail and banking environments.
- Love You! Now Please Buy Me Gift Cards
Becky is a final-year Computer Science student at the University of Birmingham, currently completing a year-long placement with the West Midlands Regional Cyber Crime Unit. There, she supports front-line cybercrime investigations and delivers cyber security training to businesses, charities, and schools across the region. She is an executive member of CyberWomen@Birmingham and STEM ambassador, and is passionate about using education to encourage more women and girls into cyber security.
- How Efficiency Can Lead to Disruption: The Evolution of Phishing Emails
Chris has worked in a range of industries, most notable of which are Critical National Infrastructure (CNI), and leading edge design and manufacturing (Dyson).
Doing so has given Chris a very varied array of knowledge, from penetration testing robot vacuum cleaners, to designing and testing secure ICS/OT networks.
During Chris’ time at Dyson, he was involved in developing the global security team and performing internal penetration testing. Chris was also heavily involved with securing the design of Dyson’s current and future internet connected appliances, and corresponding smartphone applications.
Chris is an Red Team Lead at Accenture which involves him acting and thinking like a genuine attacker to compromise client networks.
Chris’ skill set also includes Social Engineering, and he has successfully gained access into CNI, Airports and Casinos, which are regarded are some of the most secure facilities in the industry.
Chris has been lucky enough to have spoken at DefCon twice (Social Engineering 101 & How to hack an oil rig) , and many different BSides across the country.
- So You Want To Get Into Red Teaming: Skills, Mindset, and Myths
I am a cybersecurity and cloud infrastructure professional specialising in securing and optimising enterprise IT environments across multinational organisations.
My work focuses on cloud security, virtualisation, risk management and resilient infrastructure, supporting organisations in building scalable and secure digital systems. I have contributed to enterprise technology initiatives that improve operational efficiency, strengthen security posture and enable business growth.
Alongside my industry work, I actively contribute to the global technology ecosystem through research, public speaking and knowledge sharing. I have delivered an industry talk at a recognised international VMUG community event and regularly publish peer-reviewed cybersecurity research, with multiple journal articles currently under review and additional publications planned.
I collaborate closely with senior business and technology leaders, enabling me to bridge the gap between technical strategy and business outcomes. This experience has strengthened my ability to lead initiatives, share expertise and support the development of emerging professionals in the field.
My long-term goal is to contribute to the advancement of secure and innovative technology at an international level while supporting the growth of the wider tech community.
- Why Cybersecurity Awareness Alone Doesn't Stop Phishing: Lessons from a Human-Centred Study of 200 Users
David Rushmer is a technology leader, product strategist, and security researcher specialising in areas of artificial intelligence, reverse engineering, malware analysis, and threat intelligence. With a career spanning offensive and defensive security disciplines, he has built and operated threat research and intelligence teams, developed security products, and helped organisations better understand and defend against emerging cyber threats.
As a Tech Evangelist at Hex-Rays, David focuses on bridging the gap between cutting-edge reverse engineering technology and the practitioners who rely on it every day. His expertise spans binary analysis, vulnerability research, malware investigation, threat intelligence generation, and the application of AI to complex cybersecurity challenges.
- They Hacked Me. I Took Their Source Code.
Dumisani Masimini is a penetration tester and consultant at Worknest (former Pentest People), where he helps organisations understand and reduce their security risk through meaningful, action-focused assessments. With experience across internal infrastructure, web apps, and Active Directory environments, Dumisani is passionate about making technical findings accessible and impactful for every level of an organisation.
- The Next Internal Network: Why Your Old Playbook Doesn't Work
Endurance Imasuen is a cybersecurity professional with a background in Computer Science and an MSc in Cyber Security with Human Factors from Bournemouth University. He has experience spanning software engineering, IT support, and cybersecurity education, with a focus on translating technical security concepts into practical, user-centred understanding.
His work and research interests centre on human factors in cybersecurity, particularly phishing behaviour, security awareness effectiveness, and the design of systems that better reflect real human decision-making. He is currently developing a phishing-awareness platform aimed at improving how individuals and organisations recognise and respond to social engineering threats.
Endurance is passionate about bridging academic research and real-world cybersecurity practice, with a focus on security culture, behavioral change, and more realistic approaches to organizational security.
- The Human Firewall Is a Myth: Designing Security for Actual Human Behavior
George-Octavian Vieru is an early-career cybersecurity professional who has packed a lot into his first seven months in the industry. With a focus on red teaming, social engineering, OSINT, and physical penetration testing, he has quickly developed a hands-on understanding of how attackers think and operate in the real world.
Driven by a genuine curiosity for offensive security, George approaches each engagement by stepping into the mindset of the adversary, whether that means researching a target, manipulating human behaviour, or walking through a front door that wasn’t meant to be opened.
- Your Daily Routine, Their Daily Recon
An undergraduate researcher with special focus on the vulnerabilities in vocal biometric security. Delivered multiple conference talks regarding this research, including Bristol and Bath Cybercon 2025, and recently released a threat report on the increase of risk and erosion of trust in vocal biometric security with the Bloomsbury Intelligence and Security Institute in March 2026.
- The Illusion of the cloud: From orbit to ocean floor
James Boorman is a security consultant specialising in mainframe security. Over the past several years, James has spent his time untangling the web that is mainframe security within large, international organisations, delivering assessments and training to identify the hidden risks within these overlooked but undoubtedly critical platforms driving global economies.
- NonStop Looting: How to Steal from the Mainframe You’ve (likely) Never Heard Of
James Elliott builds security that ships, not security that says no. As a DevSecOps Engineering Manager, he spent his formative years breaking and fixing production pipelines as a developer and sysadmin. Having seen both sides of the friction between security teams and engineering, he now focuses on the human element of DevSecOps: tuning out the noise, separating visibility from enforcement, and proving that a 70% control a team actually runs beats a 100% control they route around. When he isn't untangling legacy monoliths, he can usually be found touring far and wide on his motorcycle.
- How Not to Roll Out a Security Tool: A Tale of Broken PRs and Regret
James McQuiggan brings over 25 years of experience to the cybersecurity field and is the founder and Advisory CISO of Apparent Security, a consulting practice to help organizations deal with Human Risk Management, Artificial Intelligence, and social engineering, as well as vCISO for various organizations.
His extensive background includes CISO Advisory at Knowbe4, providing thought leadership on various cybersecurity topics. McQuiggan was a senior cybersecurity roles at Siemens (Energy and Wind Divisions), where he developed expertise in industry standards, incident response, and industrial control system (ICS) security. In addition to his corporate work, James serves as part-time faculty at Full Sail University, teaching Cyber Threat Intelligence.
A dedicated community leader, he currently volunteers with ISC2 as Co-chair of the North American Region Advisory Council and Chair of the Southeast Chapter Regional Management Committee, following an eight-year tenure as President of the ISC2 Central Florida Chapter.
- Fake It Till You Detect It: Live Deepfakes, Detection Gaps, and the Human Risk Management Response
Jemma Davis is the co-founder of DECID:R and author of Access Denied. She has led post-incident recovery, rebuilt security functions from scratch, and delivered cyber awareness programmes at scale across government, healthcare, and global organisations. Her work sits between strategy and operations, focusing on the human behaviours that frameworks alone cannot fix.
Lucy Smith is the co-founder of DECID:R and Inclusive Change. She has lived experience of neurodiversity and has been working in the area of neurodiversity for 6 years. Lucy combines a career in change management in internationally renowned organisations with experience in education to create thoughtful and inspiring training and consultancy services.
- Decision Making Under Pressure
Dr Joe Gardiner is co-founder and co-director of Hacktonics Ltd, a start-up providing hands-on training in security of industrial control systems and operational technology security. He is also a lecturer in cyber physical systems security as part of the Bristol Cyber Security Group at the University of Bristol. His research focusses on the security of industrial control system (ICS). He has been involved in cyber security teaching and research for more than 10 years.
- ICS Village
UK-based cyber security leader and currently a Principal Cloud Security Operations Centre Manager at Microsoft. For more than a decade, I’ve built, led, and mentored SOC teams operating in high-pressure environments.
- Metrics that lie
Luiz leads the Offensive Security practice at Bridewell and has 2 decades of experience as a penetration tester, red team manager and leader.
He is a Chartered Cyber Security Professional (ChCSP), holds an MSc in Information Security from Royal Holloway along with various industry certifications.
Luiz has a particular interest in user-driven attacks, and leveraging social engineering to bypass technical controls.
- You’ve Been Ph0wned: How Attackers Compromise Organisations Via Telephone Social Engineering
Martin Clarke has been a Cyber Security Specialist working in Aviva's perimeter security team specialising in Domain Management and Protection for the past 5 years. He has been involved in introducing tools that allow us to understand who or when our brand is being infringed for malicious or fraudulent proposes and taking appropriate action to prevent or stop such activity. Prior to working at Aviva, Martin worked for Lloyds Banking Group for over 30 years with 20 years in IT Service Management.
- Domain Protection - How We Protect Our Customers
I am an undergraduate student going into my final year at UWE Bristol who loves CTFs and giving students opportunities to learn outside the classroom. I lead The CTF Falcons, UWE's cybersecurity society, where we bring in industry speakers and run learning sessions on topics that interest us. I served as president in my second year and am moving into the vice-president role this coming year.
- Still Supported Isn't the Same as Still Safe: Legacy Assets and the Enforcement Gap
I am a Digital Forensics and Incident Response Analyst working in the Defence Sector. Last year I completed my BSc in Cyber Security as an apprentice where I discovered an interest in detecting honeypots. I enjoy blue team CTFs and in my life outside of cyber (if that exists!) love the outdoors and animals.
- Honeypot detection through machine wear and tear
Matt has more than 25 years experience in the IT industry, primarily focussed on public sector organisations. He spent more than 8 years working for AWS in their Public Sector organisation, and was AWS' Chief Technologist in their UK National Security & Defence team. Whilst there he was involved in the UK (London) region launch, and was the initial technical lead for Project Sunflower, AWS's technical response to the invasion of Ukraine. He is currently Group CTO at UBDS, a UK-based SME providing digital consultancy cyber-security expertise, and managed services to a range of public sector organisations.
- The biggest digital sovereignty risk isn’t what you think...
Oliver is a 3rd year cyber security degree apprentice, splitting his time between Leonardo's Cyber & Security division and the Univeristy of Gloucestershire. He has a particular interest in product development and research, designing and building the latest defensive security solutions.
- ADS-B and Aviation Security
Peter Jones is a Cyber Security and Digital Forensics professional working as a CISO with a
career covering auditing, digital forensic investigations and incident response. Peter has coauthored a number of CREST-accredited courses and co-founded the South West Cyber
Security Cluster.
- Managing The Minefield of Management Cyber Explosions - Understanding what to say and when to say it
Poulomi Dwibedi is a Senior Cyber Security Engineer in Aviva working across threat modelling, cloud security, and detection engineering in large enterprise environments. Her work focuses on understanding how security practices operate beyond theory — especially when they meet real-world complexity, time pressure, and constantly evolving systems.
While relatively new to public speaking, Poulomi brings a practical and honest perspective shaped by hands-on experience, including where things don’t go as planned. She is particularly interested in bridging the gap between security design and operational reality, making processes like threat modelling more usable, relevant, and connected to everyday security work.
She is passionate about sharing real lessons, not perfect stories — especially for others navigating similar challenges early in their journey.
- Threat Modelling in the Real World: Lessons from a First-Time Practitioner
I'm Prithika Gopinath, a BSc Computer Science (Hons) student at London South Bank University. I'm the Assistant Technical Lead of LSBUZeroDay, a student-led cybersecurity society, and I'm currently founding CyberWomen@LondonSouthBank — the first CyberWomen branch in London. I'm also a National Cyber & Forensics Alliance (NCFA) Ambassador and working towards my Certified Associate in Project Management (CAPM) certification. I'm passionate about digital privacy and security awareness, and this is my first conference talk!
- Hooked: Investigating the Phishing Attack That Targeted Me at University
Richard Dosumu is a cybersecurity practitioner, independent researcher, Product Lead and founder of OctaTech, a UK-based digital product company building accessible tools for cybersecurity development, learning, and productivity. He holds an MSc in Cyber Security and Human Factors from Bournemouth University and writes on cybersecurity, AI, digital resilience, and human-centred security. Through CyberYearn and OctaTech’s wider product work, Richard is focused on improving cybersecurity literacy by making security guidance clearer, more practical, and more accessible to learners, early-career professionals, and real-world teams.
- Ghost in the Kernel: Hunting BYOVD After Microsoft’s 2026 Driver Trust Shift
Richard Tweed is the security, compliance and infrastructure person at Tessl. He's the OWASP Project Lead for Github-Workflow-Updater-Extension and the lead maintainer of kube-audit-rest.
Mastodon https://infosec.exchange/@RichardoC
LinkedIn https://www.linkedin.com/in/richardftweed/
- Using local models and agents, and customising them for your needs
With over 5 years of industry experience, Shammas began his career through a degree apprenticeship, gaining experience across IT, Sales, Customer Experience, and Marketing.
He joined Cisco as a degree apprentice and was later selected for its fast-tracked CX Incubator programme, specialisng as a Security Consultant.
Shammas currently works as a Security Consultant within Cisco’s Security Advisory practice, delivering projects across GRC, Security Architecture, Threat Modelling, Security Awareness Training, and Penetration Testing.
He is also an advocate for those early in their careers within the cybersecurity space. Shammas has written several blogs sharing his experiences and runs a podcast aimed at guding and inspiring others pursuing careers in cybersecurity. In addition, he serves on the UK Cyber Security Council’s Youth Advisory Panel.
- How Resilient is your MFA?
Simon Wilks is Technical Director at Emerald IT, a UK-based Managed Service Provider specialising in Microsoft 365, Azure and cyber security for small and medium-sized businesses.
With over 30 years' experience in IT, Simon spends most of his time investigating security incidents, designing layered security solutions and helping organisations improve their cyber resilience.
This is his first conference talk.
LinkedIn: https://www.linkedin.com/in/wilmerism/
- We Didn't Have a Patch: How Defence in Depth Saved Our Customers from Log4Shell
Susanne BITTER is a dynamic cyber security leader and sought-after international speaker, known for turning complex security challenges into clear and actionable strategies.
She currently serves as Head of Regional Strategic Alliances (UK) at the Cyber Security Forum Initiative (CSFI) and as Teaching Cyber Consultant for the UK’s National Cyber Security Centre (NCSC) amongst other roles.
Susanne combines academic depth and global industry expertise: she holds an MBA in Strategic Management from Nottingham Trent University and is currently a PhD candidate in Information Security at Royal Holloway, University of London.
With over 15 years of experience, Susanne has led and delivered cyber security and data privacy initiatives across a uniquely diverse range of sectors, from Samsung’s to BP’s global operations, defence suppliers, international SW corporations, family office, pharmaceutical manufacturers and local authorities. This breadth of experience gives her a rare, 360° perspective on today’s security challenges. She excels at shaping Governance, Risk & Compliance (GRC) frameworks, building resilient security strategies, and translating complex risks into practical solutions that work across industries.
Susanne also holds leading certifications, including CISM, ISO27001 Lead Auditor & Implementer etc.
When she’s not shaping cyber strategy, Susanne is literally building strength: she is a multi-time Czech National Powerlifting Champion (IPF) and national record holder, proudly representing her country internationally. She draws on the discipline and resilience of powerlifting as a metaphor for career growth, balance, and overcoming challenges - a theme that runs through her talks.
A passionate advocate for cyber security education and awareness, Susanne frequently speaks at global conferences and panels, inspiring audiences to take action, embrace authenticity, and thrive in an increasingly digital world.
- **Keynote** Saturday
Tasha is a Security Analyst at Police Digital Services with more than 20 years of intelligence and forensics experience.
Her career spans a range of disciplines including breaking into secure environments through physical security engagements, protecting critical national infrastructure, tracking APTs with law enforcement on multi-billion dollar networks, and being flown across oceans for emergency response engagements, all while proving that security can be both serious business and a little bit fun.
Now working at the intersection of policing and digital security, Tasha brings a unique perspective on threat intelligence, investigative rigour, and enterprise defence drawing in from her experience from her previous roles..
When not keeping bad actors on their toes, she can be found supporting women in Cyber, and stem, speaking at conferences, or swapping threat actors for stage actors in support of local amateur dramatics.
- The Silence of the LAMs: Detecting Rogue Language Models
Viola Lykova is a senior software engineer and SRE focused on authentication reliability, access control, and production security. She is an experienced speaker and panelist who has presented across security, testing, cloud, and DevSecOps communities, including Cypress, Community Stack, AWS user groups, Ministry of Testing London, London DevSecOps, and IOActive Hack Soho.
She is an AWS Community Builder in the Security category and a Cypress Ambassador. Outside of her day-to-day engineering work, Viola runs weekly hands-on open-source workshops with contributors through Snappycart, volunteers with Code Your Future, and creates educational content on software engineering, reliability, and security.
- Who Can Become Root? An SRE Guide to Access Drift and Privilege Escalation
I am a Red Team Operator and Physical Penetration Tester with over 20 years experience. I started my career as a Unix DB Admin before lured to world of Enterprise Solutions. I spent many years working for Blue Chip companies in IT before discovering my true passion, security. I continued to work for those Blue Chip companies but also working in Formula 1, Industrial Control Systems, Telcos and Pharmaceutical companies. I now focus on Physical Security!
- Breaching The Perimeter: The Forgotten Attack Vector That Always Works