BSides Tallinn 2025

Marvin Ngoma

Marvin is a seasoned consultant and security architect. He has a strong passion for helping nordic and baltic organizations succeed in their cybersecurity programs. He has led many projects in both the private and public sectors, architecting and building Security Operations and Intelligence capabilities; unifying tools, processes, and people. Prior to joining Elastic, Marvin worked as a security consultant at IBM and was the primary SME for QRadar in the nordics and baltics.

In addition to his work with clients, Marvin frequently speaks at conferences, summits, and meetups on the latest security topics, making him a dedicated security evangelist. He holds a masters in Computer Science & Engineering from Chalmers University of Technology in Sweden, and is a very proactive member of ISC2, among other security bodies.


Sessions

09-25
14:15
45min
Hype vs. Hands-On: What GenAI Actually Brings to Incident Detection & Response
Marvin Ngoma

Generative AI promises to revolutionize how security operations teams and investigators detect and respond to threats but, how much of this promise is real and how much is just hype?

In this talk, we go beyond vendor marketing to explore what practitioners and experts really think about GenAI’s place in modern detection and response workflows. Drawing from a Delphi study I conducted with global SOC leaders and AI specialists as part of my academic research with Luleå University of Technology in Sweden, we’ll uncover:

  • Where GenAI is already making an impact (and where it's not) for detection and response workflows

  • Key opportunities for GenAI in threat detection, triage, and investigation

  • Real-world challenges: hallucinations, trust issues, operational risks, and more

  • How security analyst roles and skills are evolving in the face of GenAI adoption

  • Practical considerations for integrating GenAI into existing detection and response SOC processes

Expect an honest, evidence-based discussion, free of buzzwords, and grounded in what the experts are actually experiencing on the ground.

Whether you're skeptical or optimistic about AI in detection & response workflows, this session will give you a grounded view of the path forward.

Stage 1
Stage 1
09-25
16:15
60min
Threat Hunting: develop and test a threat hypothesis
Marvin Ngoma

In this hands-on workshop, participants will walk through the core steps of a threat hunt - from forming a threat hypothesis to testing it against real-world data. You’ll learn how to frame hypotheses based on attacker behaviors, identify the right data sources, and validate your findings using structured hunting techniques. Whether you're new to threat hunting or looking to sharpen your approach, this session will give you practical skills to hunt smarter.

Workshop
Workshops