OrangeCon

Brenno de Winter

Brenno de Winter has been involved in security since his early years. For 15 years he was a renowned Dutch investigative journalist. Born on December 6, 1971, in Ede, Netherlands, de Winter has made significant contributions to the field of information security and privacy. He is best known for his work in uncovering vulnerabilities in public and private sector IT systems, often bringing to light the importance of cybersecurity.

De Winter started his career as a programmer, but had several roles. In 2001 he became a journalist and quickly gained a reputation for his thorough investigative techniques and commitment to transparency and public accountability. His notable works include exposing security flaws in the Dutch public transport chip card (OV-chipkaart) and various governmental IT systems, which prompted widespread public discourse and policy changes.

In addition to his journalism, de Winter is a sought-after speaker and educator on topics related to cybersecurity, privacy, and digital rights. He has authored several articles and books, sharing his extensive knowledge and advocating for stronger security measures and better data protection practices.

Throughout his career, Brenno de Winter has received numerous accolades for his contributions to the field, cementing his status as a leading figure in cybersecurity and investigative journalism in the Netherlands and beyond.

He is the 'catfather' of the OpenKAT-project and currently leads the effort of standardizing penetration testing.


Sessions

09-05
11:00
30min
Making penetration testing auditable
Brenno de Winter

Penetration testing can vary widely in execution, sometimes providing clear insights, and other times leaving much to be desired. For clients, these tests are essential for ensuring product security and often hold significant audit value. The COVID-19 crisis revealed a powerful opportunity: enhancing client assurance through more transparent and reliable pentests, a necessity increasingly driven by evolving legislation.

This realization sparked the creation of a groundbreaking collaboration. Clients, software developers, pentesters, auditors, and information security researchers now join forces in a unique alliance. Our mission? To empower every knowledgeable professional to contribute, ensuring that every crucial aspect is thoroughly examined.

Welcome to the Methodology for Information Security Research with Audit Value – a comprehensive, participatory approach that elevates the standards of penetration testing. Embrace this innovative methodology and transform how you achieve security and compliance!

Main track
Main track
09-05
13:30
60min
Be lazy like a cat, making pentesting fun again
Brenno de Winter, Mischa van Geelen

Effective pentesting is labor-intensive, especially when it comes to validation and reporting. Standardization can help, but it may also inadvertently increase the workload. In this workshop, you will receive practical tools and strategies to reduce the workload by making standardization a part of the solution.

Join us and discover how to streamline your pentesting processes, enhance efficiency, and achieve superior results without the added stress.

Workshop track 2
Workshop track 2