BSidesLuxembourg 2026

Ondrej Nekovar

Ondrej Nekovar is an experienced executive manager responsible for the cyber security of critical information infrastructure and the state. His areas of expertise include research into the use of advanced technologies for active cyber defense, deception, detection engineering and cyber counterintelligence.

LinkedIn profile:
https://www.linkedin.com/in/onekovar/


Sessions

05-07
13:30
40min
CT(C)I-Driven detection against internal and external threats
Ondrej Nekovar

Threat intelligence is often reduced to reactive IOC lists or superficial color-coded reports. This talk dismantles that paradigm. We will explore the application of Cyber Threat (Counter) Intelligence - CT(C)I - in a geopolitical context, demonstrating how to engineer detections that actively hunt sophisticated adversaries operating both outside and inside your perimeter. Moving beyond standard threats, we dissect the rising trend of APT-backed "remote workers" infiltrating organizations using deepfakes and fabricated histories. We will show you how to weaponize cyber counterintelligence and deploy deceptive defenses to expose the threat, transforming your internal environment into your primary intelligence sensor - detection. Finally, we will outline a modern, graph-based "Detection-as-Code" methodology that replaces static documentation with visual, automated defense logic.

Actionable CTI and detection engineering village
IFEN room 1, Workshops and Detection Engineering village (Building D)
05-08
13:30
40min
Panel Discussion: The future of Detection Engineering
Diana Waithanji, Ondrej Nekovar, Remi Seguy, Andrii Bezverkhyi

The purpose of this panel is discuss where the participants see the still-young, still-emergent discipline of Detection Engineering going.

The tools and know-how presented over the last 2 days in the village will be pitted against ideas from Diana (moderator) and the audience.
The panelists will try to explore together how the detection engineering landscape might evolve over the next few years,

Actionable CTI and detection engineering village
IFEN room 1, Workshops and Detection Engineering village (Building D)
05-08
13:50
5min
Building a safe harbor for cybersecurity professionals
Ondrej Nekovar

This lightning talk will present positive and negative examples related to workplace well-being. It will emphasise the importance of mental health for operational teams such as SOCs and CSIRTs, and explore the pressures CISOs face today. The talk will explore the importance of creating a safe and open environment for cybersecurity professionals. It will also explain how to build a safe harbor for cybersecurity professionals. Furthermore, it will explain how this approach will be reciprocated by these individuals and contribute to a positive workplace culture.

Main Stage