BSides Tallinn 2026

Ago Ambur

Ago is the Co-founder and Chief Operating Officer at Glazer, bringing deep technical expertise in cybercrime and cyber investigations. Ago joined Estonia's National Criminal Police at the age of 19 and went on to lead the Cybercrime Bureau, overseeing advanced technical and intelligence operations. His expertise spans low-level systems engineering, cyber investigations, and applied intelligence, having contributed to several of Estonia's landmark cybercrime investigations.

  • Identifying 100 Cybercriminals In 1 Hour
Alvar Soome

IT relict, from ancient ages. From Assembly to Python, from developer to CIO. From village to city. From books to AI ... Alvar Intelligence.

  • KEYNOTE by Alvar Soome "How to eat a wooden carrot"
Andres Jõgi

Product Security Manager @ Bolt
Applies Chekhov’s Gun to cybersecurity: "If an alert or a tool doesn't serve a clear purpose, it’s just noise, use it or cut it."

  • We have Mythos at home
Anton Sokolov

Anton Sokolov is a researcher at Tyche Institute in Tallinn, Estonia, and works as a Public Key Infrastructure engineer. His research focuses on verifiable evidence for AI governance, cryptographic provenance, public-source audit trails, and open infrastructure for accountable AI-agent workflows.

  • Who Said the Agent Could Do That? Catching the Correctly-Signed, Out-of-Mandate Action
Dadash

Product Security Engineer @ Bolt. Interested in web, mobile and API security, with a growing interest in AI-assisted vulnerability discovery. Building tooling to make security faster, reliable and available to everyone.

  • We have Mythos at home
Evgen Blohm

Evgen Blohm is an experienced DFIR expert who has been involved in responding to a large number of cyber incidents. He is based in Hamburg, Germany and is currently working for InfoGuard AG, where he is also supporting customers with compromise assessments and dark web monitoring.

  • Iranopasmigirim - Unmasking an ever-evolving GitHub-Hosted Espionage Campaign Against Iranian Dissidents
Iuliia Laaneots

Iuliia is a Cloud Security Manager at Bolt. Official title: keeps the infrastructure safe. Unofficial title: professional worst-case-scenario imaginer.

  • Nobody monitors the monitor: Chaos engineering for the security team's own infrastructure
Jarkko Kinnunen

Jarkko Kinnunen is a Security Solution Engineer at Microsoft and Co-Founder of KuoSec community. A passionate advocate for the Blue Team, he specializes in developing continuous security services and enhancing SOC operations. By day, he advises companies and partners on designing and implementing solutions built on Microsoft security technologies. After working hours, he loves helping the community to do stuff...

  • Every Path Counts: When Defenders Learn to Think in Graphs
Kirils Solovjovs

Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist, known for uncovering and responsibly disclosing critical security vulnerabilities in national and international systems. An expert in penetration testing, network flow analysis, and reverse engineering, he is also a lifelong command-line enthusiast. Kirils started programming at age 7 and by grade 9 was spending his lunch breaks writing machine code directly in a hex editor. He uses bash daily for hacking, automation, and large-scale data processing and is sometimes contracted by major online education providers to proofread their bash certification exams. He currently is the lead researcher at Possible Security.

  • Mastering Bash for Hackers: Extreme Command-Line Power
Klaus Agnoletti

Klaus Agnoletti has been an all-round infosec professional since 2004. As a long-time active member of the infosec community in Copenhagen, Denmark, he co-founded BSides København in 2019.

Currently he's a freelance storytelling cyber security advisor specializing in security transformation and community focused marketing, employer branding, playing security games and other fun assignments and ideas coming his way.

Lately he has also become a neurodiversity advocate speaking about ADHD to educate and break down taboos in an industry with a vast overrepresentation of neurodiversity and not very many talking about it.

  • Gotta Contain 'Em All: Collaborative Incident Response Training Through Gaming
Lyra Rebane

I like to play around with the web and browsers for fun. Sometimes I find bugs. 13 CVEs in Chrome.
https://lyra.horse/blog/

  • Reporting vulnerabilities to Estonian companies - 2026 edition
Mait Peekma

If you are reading this, you probably get paid to build or protect stuff. Mait does the opposite — but has somehow avoided handcuffs so far.

  • PLC unplugged (09:30, 11:15)
Marvin Ngoma

Marvin is a seasoned consultant and security architect. He has a strong passion for helping nordic and baltic organizations succeed in their cybersecurity programs. He has led many projects in both the private and public sectors, architecting and building Security Operations and Intelligence capabilities; unifying tools, processes, and people. Prior to joining Elastic, Marvin worked as a security consultant at IBM and was the primary SME for QRadar in the nordics and baltics.

In addition to his work with clients, Marvin frequently speaks at conferences, summits, and meetups on the latest security topics, making him a dedicated security evangelist. He holds a masters in Computer Science & Engineering from Chalmers University of Technology in Sweden, and is a very proactive member of ISC2, among other security bodies.

  • Inside Scattered Spider: A Red vs. Blue Breach & Attack Simulation
Oskar Gross

Oskar Gross is the CEO of Glazer Technologies and a former criminal police officer. He joined the National Criminal Police in late 2015 to establish the Cybercrime Bureau, focusing on cybercrime intelligence and investigations. The unit investigated several major cross-border cases, including the €577 million HashFlare fraud case. In 2023, Oskar was appointed Head of the Estonian National Criminal Police, leaving the role in 2024 when he relocated to Brussels. He holds a PhD in computer science from the University of Helsinki.

  • Beyond the Narrative: Mapping the Hidden Infrastructure of Information Warfare
Peeter Marvet

Estonian Radio Amateurs Union https://erau.ee/en/ has been active since 1935, with members taking part in contests and organizing field days. Workshop and village are created by ERAÜ's Radio Networks Committee, tasked to build and maintain repeaters, IP and radio networks, digital systems, and taking care of related cybersecurity.

Our goal is simple: more airtime, more coverage, more radio amateurs on the air every day.

  • HAM radio workshop and exam (ALL SPOTS FULL)
Siret Schutting

Siret is an information security and strategic communication expert and researcher, focusing on cognitive security, frontier technologies, defence and space (particularly LEO). She teaches information security and risk management at Tartu University, trains teams and organisations in cyberhygiene and resilience and consults companies on implementing infosec management systems. She is the founder & CEO of Digital Round Table, a think tank focused on security research, international infosec collaboration and technology education.

  • Language Matters
Stephan Berger

Stephan Berger has over a decade of experience in cybersecurity. Currently working with the Swiss-based company InfoGuard, Stephan investigates breaches and hacked networks as Head of Investigation of the Incident Response team. An avid Twitter user under the handle @malmoeb, he actively shares insights on cybersecurity trends and developments. Stephan also authors the blog DFIR.ch, where he provides in-depth analysis and commentary on digital forensics and incident response. Stephan has spoken at numerous conferences, sharing his expertise with audiences worldwide.

  • Deconstructing Modern macOS Initial Access Vectors
  • Anti-Forensics (and Anti-Anti-Forensics) Techniques for Incident Responders (ALL SPOTS FULL)
Toomas Lepik

A well-seasoned Cyber Security Analyst with 20+ years of experience across the IT industry, specialising in network forensics, malware analysis, and incident handling. Blends hands-on technical investigation with critical thinking—and a healthy appreciation for laziness, meaning efficient solutions that avoid unnecessary work. Passionate about secure software practices and turning messy incidents into clear, actionable answers. Away from the keyboard, likes sauna and happily pets dogs and most other domestic animals

  • Wifi Discovery and monitoring 101 primarily with Kismet
Vladyslava Shekula

Hi, my name is Vladyslava. I work as a Cyber Physical Security Consultant in WOTOS. I moved to Estonia about five years ago from Ukraine to study Cyber Security Engineering at TalTech and later continued with the Master's in Cybersecurity, which I completed this year. During my Bachelor's, I worked for more than two years as a DevOps engineer at Playtech. After my Bachelor's, I became interested in OT security and joined my current position. Today, I work with risk assessments, disaster recovery planning, tabletop exercises, business impact assessment, procurement, compliance and I’m also involved in other security projects.

  • Hidden Risks in Industrial Communications: Real Findings from a Manufacturing OT Environment
Zafer Balkan

Zafer Balkan is a cybersecurity, compliance, and IT operations professional based in Tallinn, Estonia. His work spans security governance, infrastructure security, business continuity, risk management, defensive operations, and practical security engineering. He currently works as Security and Compliance Manager at Nets Estonia, part of Nexi Group, where he supports IT security and compliance decision-making, risk assessment, business impact analysis, business continuity and disaster recovery planning, internal audits, security control implementation, vulnerability analysis, and pentesting coordination in the finance/payment-services sector.

Before moving into finance-sector security and compliance, Zafer built a substantial technical and operational background in NATO and defense environments. His earlier roles covered IT management, communication and information systems security, systems and network administration, blue-team operations, IAM across internet-connected and air-gapped networks, SIEM/EDR environments, security appliances, virtualization, backup, disaster recovery, and secure software practices.

  • Detection in Technicolour: Finding the Gaps Your Dashboard Cannot See