BSides Joburg 2026

SocVel Live : The CISO's Gambit
2026-07-25 , Track 1

I don't sign off on risk waivers and I don't set the budgets. But, more often than not, I am the one who tells the CISO why their weekend plans are about to get ruined.

The CISO's Gambit is a live strategy simulation where Threat Intelligence sets the scene and the audience drives the response. Drawing on the cyber roller coaster of the past 12 months, you get put in the hot seat of the one whose weekend is now also ruined. When a critical vendor is compromised, do you halt production or do "heightened monitoring" and pray. When the geopolitical mess spills over into cyber, do you change vendors or duck and cover.

Through live audience voting, we track the real-world impact of your choices across key metrics. No slides. No safe paths. Just trade-offs, facepalms and high-fives through a collective decision-making experiment.


This isn't a talk about security leadership. But a look at how those decisions are made collectively. Decisions that need to get taken because someone, probably someone in this room, found something. Flagged something. Wrote the email that landed in the wrong inbox at the wrong time and suddenly it's everyone's problem.

The CISO's Gambit is the next evolution of SocVel Live, the interactive tabletop format that took home Best Speaker at BSides JHB 2025. This time, we're not hunting the threat. We're managing what comes after.

Working through scenarios grounded in real threat intelligence from the past year: each one a moment where a technical finding collides with a business reality — and someone has to make a call with incomplete information, an impatient board, and a vendor on hold. Sound familiar?

The scenarios cover the kind of things that have been quietly ruining people's Fridays since 2025. ClickFix campaigns, the AI apocalypse, geopolitical shenanigans, supply chain compromises and malicious dev tooling that handed your build pipeline over to someone called Vlad.

The audience votes on what to do at each decision point. Consequences unfold in real time. And we track the impact across three metrics: Board Confidence, Reputation, and Threat Exposure.

This session is built for techies. Because the best leadership decisions in security are only as good as the technical insight behind them. The techies are the ones who assess the new tool that is supposed to be the silver bullet, give feedback on what the blast radius of a change will be, or flag the dodgy process the entire business is running on. This simulation puts that work in context — and shows what happens when it hits the decision layer.

No single right answer. No fixed path. Just trade-offs, pressure, and the collective weight of a room that knows exactly what's at stake.

Hope you like awkward board meetings.

Jaco Swanepoel is a cybersecurity professional with over 15 years of experience in digital forensics, incident response, and threat intelligence. He’s worked on high-profile investigations, supported law enforcement operations, and testified as an expert witness in court. Having obtained multiple SANS certifications, he has led forensic engagements across several continents. Today, he heads a threat hunting and intelligence team within one of South Africa’s leading financial institutions, tracking threat actors and uncovering malicious activity. Passionate about sharing knowledge, Jaco actively works on projects designed to spark curiosity and inspire others to explore the world of cybersecurity.