BSides Joburg 2026

The speaker's profile picture
Aaron Van Den Berg

I break into networks, applications, and infrastructure to find the critical flaws that automated scanners miss. By simulating real-world adversary tactics, I help organizations see their environment through an attacker's eyes, demonstrating actual risk and providing the blueprint to fix it.

  • Lighting the Way to the Server Room
The speaker's profile picture
Christo Goosen

DevSecOps Lead, AI/ML. Hacker, tinkerer, builder, breaker.

BSIDES Cape Town organiser.

  • Turning Roadkill into braAI-VibeSDLC
The speaker's profile picture
Christoff Jacobs

Software Developer | Mobile Security Enthusiast

  • Shedding Light on Mobile Trust: Rethinking SSL Pinning
The speaker's profile picture
Dietmar Marggraff

Dietmar Marggraff is a cybersecurity consultant at blueflare Consulting, specialising in Operational Technology (OT) cybersecurity. He focuses on delivering pragmatic, real‑world solutions that organisations can implement today. He has authored several practical guides on airport and OT cybersecurity, as well as penetration testing, and brings a grounded, actionable perspective to cybersecurity.

  • A journey through Cybersecurity Regulation in practice
The speaker's profile picture
Drystan Govender

Drystan Govender serves as the Chief Technology Officer at Cyber Retaliator Solutions (CRS), where he is responsible for defining the company's technology vision and ensuring the delivery of secure, scalable cybersecurity solutions.

Drawing on a robust background in pre-sales engineering and extensive hands-on field experience, Drystan excels at translating complex client challenges into practical, strategic technology solutions. He works intimately with a diverse network of partners, resellers, Managed Service Providers (MSPs), and customers to implement tailored solutions that meet their unique operational needs.

Drystan is passionate about building resilient security architectures, optimizing processes, and supporting sustainable growth. His overarching goal is to make technology work seamlessly for clients while aggressively advancing CRS’s mission to deliver trusted, highly effective cybersecurity defenses.

  • Illuminating the Underground : How Infostealers are Bypassing MFA
The speaker's profile picture
Ivan Burke

I currently serve as the Head of Research, Development, and Innovation at BlueVision ITM, where I lead initiatives in cyber security innovation and capability development. I specifically focus on bridges the gap between theoretical research and practical application, particularly in areas like cryptography, network security, and cyber resilience.

I am passionate about fostering the next generation of cyber security talent through mentorship and community engagement. As such, I contribute to various cyber security events, community gatherings and cyber security challenges throughout South Africa.

  • Using CSC to build future cyber workforce
The speaker's profile picture
Jaco Swanepoel

Jaco Swanepoel is a cybersecurity professional with over 15 years of experience in digital forensics, incident response, and threat intelligence. He’s worked on high-profile investigations, supported law enforcement operations, and testified as an expert witness in court. Having obtained multiple SANS certifications, he has led forensic engagements across several continents. Today, he heads a threat hunting and intelligence team within one of South Africa’s leading financial institutions, tracking threat actors and uncovering malicious activity. Passionate about sharing knowledge, Jaco actively works on projects designed to spark curiosity and inspire others to explore the world of cybersecurity.

  • SocVel Live : The CISO's Gambit
The speaker's profile picture
Jared Naude

Jared is the Head of Security at Synthesis, where he specializes in enterprise cloud architecture. Jared is passionate and deeply committed to guiding large organizations through the complexities of architecting, securing and operationalizing enterprise cloud environments. Beyond Jared’s professional responsibilities, Jared is an enthusiastic advocate for community building, serving as the organizer of several local security events, including 0xcon, BSides Cape Town, and BSides Joburg. Jared’s research focuses on cybersecurity topics that intersect with national security and foreign policy issues such as encryption, privacy, surveillance, disinformation, and nation-state activity.

  • The Black Box Problem: Detection Engineering in the Age of AI Agents
The speaker's profile picture
Jason Jordaan

Jason Jordaan is the Principal Forensic Scientist and Founder of DFIRLABS. As a recognised polymath, he is considered by his peers internationally to be a leading specialist in the fields of digital forensics, incident response, cybercrime investigations, and cybersecurity forensic engineering. He was one of the early pioneers in digital forensics in South Africa with his interest and activities in the field beginning in the mid 1990’s. Not only does Jason lead DFIRLABS, but he remains actively involved as a practitioner in these fields and regularly testifies as an expert witness in them.

He founded DFIRLABS in 2014 after leaving the Special Investigating Unit, where he was the national head of the Cyber Forensic Laboratory. In this role, he was responsible for the development and implementation of the digital forensics capacity of the Special Investigating Unit, and in conducting digital forensics engagements on several high-profile cybercrime, fraud, and corruption cases in the South Africa public sector. Prior to joining the Special Investigating Unit in 1998, Jason served as a Detective in the South African Police Service Commercial Branch from 1992, where he conducted numerous white-collar crime investigations, with a focus on organised crime.

Jason is an active researcher, academic, trainer, advisor and assessor in the international digital forensics and cybersecurity communities. He is a Principal Instructor with the internationally renowned SANS Institute. In this capacity he teaches digital forensics around the world, including to some of the leading international law enforcement, intelligence, and miliary units such as the Federal Bureau of Investigations, the US Secret Service, US Special Operations Command, Scotland Yard, the UK National Crime Agency, and many others. He also has provided digital forensics and incident response training to numerous companies in the Fortune 500 list. He is also as Assistant Professor at the SANS Technology Institute. He has also taught digital forensics at the University of Cape Town, the University of Pretoria, and Rhodes University.

He currently serves on the SANS Advisory Board and on the Advisory Board of the Department of Computer Science of the University of Pretoria. He also served on the expert advisory panel for the South African Deputy Minister of Justice for cybercrime legislation and has advised the South African Police Service on the South African National Cybercrime Strategy.

Jason is an assessor for the Netherlands Register of Court Experts and is responsible for the assessing the competency of digital forensics practitioners testifying in court in the Netherlands. He is a Director of the Institute of Commercial Forensic Practitioners of South Africa. He has previously served as a Director of the South African Academy of Forensic Sciences, and the South African Chapter of the Association of Certified Fraud Examiners. His digital forensics, cybersecurity, and cyberlaw research has been published in textbooks and international peer-reviewed journals, and he is a frequent speaker at professional, scientific, and technical conferences internationally. He also sits on several international and local conference advisory boards.

  • The Missing Drive: Proving a Hidden Linux HDD Through Windows Registry Forensics
The speaker's profile picture
Jonathon Everatt

I'm a Senior CyberSecurity consultant at MWR CyberSec. I've spoken a BSides Cape Town a few times before and some other conferences. I'm an organsior of the MWR Virtual Internship and Internship.

Come say hi

  • Stop Waiting for Unicorns: Bulding SA's Security Pipeline with 3,300 Interns
The speaker's profile picture
Keith Makan

Keith Makan is an experienced cybersecurity consultant and researcher with a strong history of helping clients around the world manage information security risks. He founded Keith Makan Security Consulting (KMSEC) (Pty) Ltd, a locally owned consultancy specialized in secure code review, penetration testing, training, and engineering support to help clients achieve an industry-best standard in security engineering and performance.

Keith is also a published author, having written "The Android Application Security Cookbook" and "Penetration Testing with the Bash Shell." His security research contributions include identifying vulnerabilities in widely used software like Google Chrome, and he recently presented his concolic execution framework, Zorya-Volos, at the Black Hat Asia 2026 Arsenal in Singapore. He holds an MSc in Computer Science, focusing on automated vulnerability analysis in binary formats, and is currently advancing this research as a PhD candidate at the University of the Western Cape.

  • Lighting the Way in the Dark: Binary-Only Race Detection in Go with Zorya-Volos
The speaker's profile picture
Kitso Moema

I'm a Cyber Threat Intelligence professional who spends my days tracking scams, cybercrime, fraud, and other emerging threats. I'm particularly interested in understanding how criminals think, adapt, and exploit both technology and human behaviour.

  • Should've, Could've, Would've: How Organisations Drift Into Breach
The speaker's profile picture
Latasha Friend

Latasha Friend is a cybersecurity consultant at Integrity 360, where she serves as technical lead of the incident response team. Having begun her career in penetration testing, she transitioned into incident response driven by a passion for digital forensics and active threat management.

Malware analysis quickly stood out as a fascinating and essential piece of the incident response puzzle. Since then, she has been building her knowledge in this space, driven by a genuine curiosity about how malware works and a desire to turn that understanding into faster, sharper triage decisions. As a certified incident responder working directly in client environments, Latasha sees firsthand how critical it is to quickly make sense of a threat before it does real damage.

The excitement of untangling complex problems is what drew her to this topic and what this talk is built around.

  • From Unknown to Understood: Malware Triage in Minutes
The speaker's profile picture
Logan Kroeger

I am a computer engineer who is a self-motivated and disciplined individual impassioned by cybersecurity and technology. I'm a hard worker and willing to go the extra mile because I am ambitious, eager to succeed and always enthusiastic to learn. I take pride in what I do and see myself as being conscientious and diligent, with a good work ethic. I am proactive, innovative and "think outside the box".

I have a passion for performing red team exercises, namely simulating real-world advanced cyberattacks where I can employ the latest tactics, techniques and procedures to execute on attacker goals whilst remaining undetected; with the aim of identifying security weaknesses and areas where change can be implemented to enhance security practices.

  • Gimme! Gimme! Your Creds After Midnight: Weaponising Veeam Credential Extraction
The speaker's profile picture
Marinus van Aswegen

Marinus is a Cyber Security professional with over 25 years of experience consulting to startups, multinationals, government, and law enforcement. He has extensive experience in building banks from the ground up and is currently focusing on AI engineering.

Marinus has a background in architecture, risk management, security assessments, testing, audit, forensics, penetration testing, and development. He holds numerous international security certifications including CISSP, ISSMP, ISSAP, and CSSLP, and is a certified TOGAF 10 Enterprise Architecture Practitioner.

In 2006 he founded Telic, a specialist consulting practice that helps customers bring products and services to market by managing their security design, engineering, and implementation concerns.

Before Telic, he was a Principal Consultant at Deloitte, working with clients across Europe, Africa, Japan, and Australia.

  • Cells and Claws: A Mental Model for Autonomous AI Agents
The speaker's profile picture
Mohammed Anas

A seasoned security practitioner with over a decade of experience building and managing Security Operations Centres across the Middle East, Africa, and Europe. Having started on the offensive side — understanding how attackers think, move, and hide the transition to defence brought a sharper eye for what most blue teams miss. That attacker's perspective is what drives this talk: DNS isn't just a log source, it's the trail adversaries leave behind, and most defenders aren't following it yet.

  • 1 LogSource to rule them all: What DNS Is Telling You(That You're Not Listening)
The speaker's profile picture
Roelof Temmingh

Roelof Temmingh has worked in cybersecurity and Open-Source Intelligence (OSINT) for more than 25 years. Trained as an engineer (B.Eng, 1995), he began his career in IT security and penetration testing, co-founding SensePost, one of the early security consultancies, which later became part of Orange Cyberdefense.

He went on to start Paterva, the company that created Maltego, widely used for data visualization and relationship mapping in OSINT investigations. More recently, he founded Vortimo and is currently building Ubikron.

Over the years, Roelof has given talks and training in many countries, sharing practical approaches to security and OSINT. He is known for creating tools that emphasize usability and real-world application rather than hype.

  • "Goedkoop koop is duur koop" - the price of cheap thinking
The speaker's profile picture
Rogan Dawes

Rogan Dawes is a senior researcher at SensePost and has been hacking since 1998, which, coincidentally, is also the time he settled on a final wardrobe. He used the time he saved on choosing outfits to live up to his colleague’s frequent joke that he has an offline copy of the Internet in his head. Rogan spent many years building web application assessment tools, and is credited as having built one of the first and most widely used intercepting proxies; WebScarab. In recent years, Rogan has turned his attentions towards hardware hacking; and these days many suspect him to be at least part cyborg. A good conversation starter is to ask him where he keeps his JTAG header.

  • Rooting the Wink Hub 2 (finally)
The speaker's profile picture
Stephen

I am a Principal Consultant and Red Team Lead at MWR CyberSec, specialising in offensive security and adversary simulations.

  • Gimme! Gimme! Your Creds After Midnight: Weaponising Veeam Credential Extraction
The speaker's profile picture
Tinus Green

Passionate about cybersecurity, helping upskill others, and generally getting involved in the cybersecurity community!

  • Stop Waiting for Unicorns: Bulding SA's Security Pipeline with 3,300 Interns
The speaker's profile picture
Travis More

Travis More is a penetration tester at Bitcrack Cyber Security, where his work covers traditional pentesting. On the side, he digs into hardware hacking, reverse engineering, and password attacks, and has previously spoken at BSides Las Vegas.

  • The Device Doesn't Take No for an Answer
The speaker's profile picture
Tyron Kemp

Tyron Kemp is a cybersecurity professional with with a background spanning network engineering, penetration testing, and deception technology. He is perhaps best known for his Black Hat USA 2020 briefing, Routopsy: Modern Routing Protocol Vulnerability Analysis and Exploitation, co-presented with Szymon Ziolkowski at SensePost, where he exposed how misconfigured dynamic routing and first-hop redundancy protocols can be weaponised for person-in-the-middle attacks, releasing an open-source toolkit alongside the research.

In recent years, Tyron has worked where offensive tradecraft, detection engineering, and deception technologies overlap, helping organisations understand how attackers operate and how to reduce risk in ways that matter.

In his BSides Joburg 2026 talk, Pipe Dreams, he turns his attention to the endpoint by walking through how he escalated privileges to SYSTEM via Cooler Master's MasterPlus software, because sometimes the most dangerous vulnerabilities are hiding in the software you least expect.

  • Pipe Dreams: Escalating to SYSTEM via Cooler Master MasterPlus