Viola Lykova
Viola Lykova is a senior software engineer and SRE focused on authentication reliability, access control, and production security. She is an experienced speaker and panelist who has presented across security, testing, cloud, and DevSecOps communities, including Cypress, Community Stack, AWS user groups, Ministry of Testing London, London DevSecOps, and IOActive Hack Soho.
She is an AWS Community Builder in the Security category and a Cypress Ambassador. Outside of her day-to-day engineering work, Viola runs weekly hands-on open-source workshops with contributors through Snappycart, volunteers with Code Your Future, and creates educational content on software engineering, reliability, and security.
Session
Privilege escalation is not always a dramatic exploit, and in production systems it is often less about one clever trick than about a chain of ordinary operational decisions that were each made for a sensible reason, at a stressful moment, and without anyone stepping back later to ask what those decisions allowed when combined.
This blue-team SRE talk asks a simple but uncomfortable question: who can become root?
We will look at how temporary access, old service accounts, broad deploy permissions, and emergency exceptions can accumulate into hidden access paths that make people, processes, pipelines, or services more powerful than intended. Through a local, isolated demo, we will follow one flawed access path from a boring starting point to an uncomfortable ending, then reverse the story from the defender’s side to ask what evidence, containment, and guardrails would have exposed it earlier.
Attendees will leave with a practical access-path review worksheet they can use to move beyond asking "who has admin?" and start asking the more useful question: "who can become admin?"