A dynamic leader and passionate coach, Stacy is known for his creativity, authenticity, and people first leadership style. He thrives on unlocking potential - both within teams and individuals - and is deeply energized by helping others succeed. A natural storyteller, Stacy believes great stories don’t just inform; they inspire, motivate, and create lasting momentum.
Join us as Stacy Betts takes the stage to share insights, stories, and practical strategies that will inspire and empower our community.
Social Engineering CTF!
Session 1 · 10:00 AM – 11:45 AM
Angle
Oak
Secret!
Do you have what it takes to elicit information during a high stakes, pressure sensitive interview?
Could you do it in 10 minutes?
Could you do it with fake information you memorized for 3 minutes?
Come join us and find out!
Sneaking Malicious Hardware into a Keyboard
Session 1 · 10:00 AM – 10:45 AM
neko
Redbud A
Rubber Ducky's are pretty well known so you might hope a user won't just plug in a random parking lot flash drive, but do you think they might plug in a random keyboard that looks exactly like the keyboard they already have? Especially if they are told it is a magical keyboard that will make their computer much faster?
This talk is all about designing and building a malicious keyboard and then what you can do with it and how you might go about defending from something like this.
Parks and Re-Creation "The Attack Surface Is 17,000 Acres"
Session 1 · 10:00 AM – 10:45 AM
Anthony G George
Redbud C
Most security professionals think of an attack surface as a network, a data center, or maybe a factory. What happens when the attack surface is an entire industrial park?
Over the past year, I've had the opportunity to help shape the technology strategy for a next-generation industrial campus that's bringing together AI, digital twins, smart infrastructure, advanced manufacturing, energy, industrial networking, and operational technology. It quickly became clear that this wasn't just another Industry 4.0 project—it was the convergence of physical infrastructure and cybersecurity at a scale I hadn't experienced before.
This talk walks through the architectural decisions, integration challenges, and security considerations involved in building an intelligent industrial ecosystem. We'll explore how technologies like digital twins, AI, industrial networking, asset tracking, edge computing, and OT systems can be integrated into a single operational platform without creating a security nightmare.
This isn't a vendor presentation or a product demo. It's an engineering case study from the trenches about connecting technologies that were never designed to work together and securing them before they become tomorrow's critical infrastructure.
Whether you're interested in OT security, AI, infrastructure, networking, or simply where our industry is heading, you'll leave with a different perspective on what "cybersecurity" looks like when the attack surface is measured in acres instead of IP addresses.
Everything Is a Flow: Using the OSI Model Beyond Networking
Session 1 · 10:00 AM – 10:45 AM
Mitch Roberson
Trail Rooms
For decades, the OSI model has been taught as a networking concept, often reduced to a memorization exercise for certification exams. Unfortunately, that approach misses its true value.
The OSI Model is one of the foundations of modern computing. Not because it explains networking but because it teaches us how to think. It demonstrates that flow of data as it moves from one computer to another. This flow is key to Trouble shooting. Weather you work in CyberSecurity, Cloud, Infrastructure, Software Development, databases, Identity or networking, every outage, slow down breach and user complaint comes down to how information is flowing and where it is breaking.
This session will look at the OSI model through a different lens. Instead of treating it as something to memorize for a test. We'll use it as a practical methodology for trouble shooting. And help the attendee understand the flow of data is key to trouble shooting.
Using real-world examples from security incidents, authentication failures, application outages, cloud services, database connectivity problems, and network disruptions, we'll explore how a framework created decades ago remains one of the most effective troubleshooting tools available today.
The goal is simple: stop memorizing the OSI model and start using it to think.
Managing AI Risk
Session 1 · 10:00 AM – 10:45 AM
Mike Mahurin
Walnut
For organizations looking to embrace Artificial Intelligence while maintaining strong governance and risk controls, this presentation provides a practical roadmap for developing an AI Risk Management Program aligned to the NIST AI Risk Management Framework (AI RMF). Attendees will learn how to establish an enterprise-wide approach to identifying, assessing, mitigating, and monitoring AI-related risks while enabling innovation and business value. The session outlines the key components of an effective AI governance structure, including risk management processes, roles and responsibilities, policy development, regulatory and compliance considerations, security controls, data governance requirements, and ongoing monitoring practices.
Privacy ScALPRs - A Discussion on ALPRs, Implications, and How to Engage Your Community
Session 2 · 11:00 AM – 11:45 AM
Daniel Rosendale
Osage
As one of the hot topics currently in the news both nationally and locally, this discussion aims to educate attendees on the basics of Flock or ALPRs in general, ways in which some of this tech can be used, legal cases in the past and currently ongoing that are challenging these technologies, and then how to engage your community on this matter, regardless of which side of the argument you may land on, at a Local, State, and Federal Level
Good Intentions, Bad Outcomes: How Security Culture Turns Human Behavior Into Defense
Session 2 · 11:00 AM – 11:45 AM
Nicki Swart
Redbud A
Cybersecurity often treats people as the weakest link, but what if we're looking at the problem backwards?
Employees rarely intend to create security incidents. They're trying to help a customer, meet a deadline, solve a technical problem, follow instructions, or simply get their job done. Yet reasonable decisions can still produce unreasonable security outcomes.
This session explores how organizations can build a healthy security culture that turns human behavior from a source of risk into an additional layer of defense. We'll examine what happens when employees bypass controls to get their jobs done, hesitate to report mistakes, or place too much trust in technology—including exploring examples of people acting on AI recommendations without fully understanding the consequences.
The goal isn't to create employees who never make mistakes. It's to create an environment where people feel empowered to pause, question, verify, and report—and where security is viewed not as an obstacle to the business, but as something everyone participates in.
Don't Trust the Agent: Enforcing Security Boundaries in AI Systems
Session 2 · 11:00 AM – 11:45 AM
Travis Lowe
Redbud C
AI agents are increasingly being given the ability to execute commands, access infrastructure, modify code, and interact with real-world systems. But instructions, system prompts, and skills are not security boundaries they influence what an agent **should** do, not what it is actually **allowed** to do. This talk explores harness engineering as a means of enforcing those boundaries through capability control, tool authorization, validation, isolation, approvals, and auditing. We’ll also examine the limitations and new attack surface introduced by harnesses themselves, and why the harness should ultimately control what an AI agent can do.
The Security Journey: Breaking into Cybersecurity
Session 2 · 11:00 AM – 11:45 AM
John Dobbin
Trail Rooms
A Cybersecurity Solutions Architect and CISSP with nearly 30 years in IT shares the unfiltered version of a career in security: which education paths actually pay off, how to survive being thrown in over your head, why rejection is a signal worth listening to, and how experience gets built before it gets credentialed. The session ends with a candid look at AI's role in the field today, where it helps, where it doesn't, and how to use it without letting it think for you. Built for students and early-career professionals who want the real story, not the recruiting pitch.
You Can’t Secure What You Keep Changing: Why Change Management Is a Cybersecurity Control
Session 2 · 11:00 AM – 11:45 AM
Linda Lenox
Walnut
Technology environments don't sit still. Applications are upgraded. Configurations change. Access is modified. Infrastructure is replaced. Integrations are added. And when something breaks, an emergency change can go from idea to production pretty darned fast.
Meanwhile, organizations continue to invest in increasingly sophisticated security technology to detect, prevent, and respond to threats.
But here's the problem: technology doesn't manage change.
Effective Change Management does.
A strong change process makes risk assessment part of the conversation before the change happens. It establishes an approval chain that makes it clear who reviewed the change and accepted the risk. And it creates an audit trail that can answer the questions everyone starts asking when something goes wrong: What changed? Why? Who approved it? When did it happen? And what happened next?
This session takes a practical look at Change Management as part of an organization's cybersecurity posture. We'll explore how effective risk assessment, appropriate authorization, and an auditable record of change can give security teams something their tools can't provide on their own: context.
Because having a great security stack doesn't mean much if you don't have a handle on the changes happening in the environment it's protecting.
Don't Be the Low Hanging Fruit
Session 3 · 1:30 PM – 2:15 PM
James Smith
Osage
Cybercriminals don’t always need to defeat the best security—they just need to find an easier target. Don’t Be the Low Hanging Fruit challenges IT leaders to take a hard look at the assumptions behind their security strategy. We’ll examine how attackers are getting around MFA, exploiting legitimate credentials, targeting privileged access and vendors, attacking backups, and using AI to make social engineering more convincing than ever. Using real-world breaches and lessons from nearly 30 years of working with computers and the Internet, we’ll ask the questions that matter: If an attacker already had a valid credential, what would stop them? Would you know they were there? And is your organization harder to attack than the one next door?
NIST Cybersecurity Framework 2.0 Demystified: Mastering the Power of Governance
Session 3 · 1:30 PM – 2:15 PM
Christopher Gregg
Redbud A
In today’s landscape, Information Security professionals are battling the "Blinking Box Problem". For a long time, our industry has been focused on buying purpose built tools to address risks within our environment. However, we are now seeing that we have tool/vendor sprawl, bloated costs, and more tools than we know how to manage. Case in point: A blinking box isn't going to solve any of our problems without appropriate governance and strategic implementation of our tools.
To successfully approach tool and vendor consolidation, we need to go back to the basics. By leveraging the NIST Cybersecurity Framework (CSF) 2.0, we can realign with our core principles.
We’ll do an overview of the NIST CSF Framework, discuss profiling your business, explain the CSF Cores and Tiers, and then do a deep dive into the central Govern (GV) Function and its key categories.
Conagotchi: From Concept to Completion
Session 3 · 1:30 PM – 2:15 PM
Jason, Chief Pixel Chef, Angle, Daniel
Redbud B
A joint talk on the process of bringing the Conagotchi badge to life, from concept to completion.
Your vuln program is working perfectly. For the attackers.
Session 3 · 1:30 PM – 2:15 PM
Brad Liggett
Redbud C
Most vulnerability programs do exactly what they were built to do. They scan everything, ticket the 9.8s and report a shrinking critical count to the board. Attackers still walk in through the CVSS 6.2 on the public VPN. This talk explains why severity scores were never meant to measure risk, and how free signals like CISA KEV and EPSS can cut the list down to what attackers actually use. It also covers how reachability, compensating controls and asset value decide what really matters in your environment, and what CISA's new BOD 26-04 means now that CVSS is out of the federal decision model. Attendees leave with a practical way to move from "fix 150,000" to "fix the 40 that will breach you," plus one question to ask their team on Monday.
Takeaways:
- Why CVSS measures severity, not risk
- How to use KEV and EPSS together to prioritize
- How compensating controls change exposure, and what BOD 26-04 means for that
- A simple maturity path from scanning to exposure management
From Classroom to Cyber Incident: Building Job-Ready Defenders in WSU Tech’s Cyber Range
Session 3 · 1:30 PM – 2:15 PM
Matthew Lewis, Jacob Buck, Adam Shah
Trail Rooms
Technical knowledge alone does not make someone ready to defend an organization. Cybersecurity professionals must interpret incomplete information, correlate evidence from multiple systems, make decisions under pressure, and explain why their response is justified.
WSU Tech’s Cyber Range provides learners with a broad collection of realistic simulations modeled on real-world threats and security incidents. Working through varied scenarios allows a learner to practice responding to different attack methods while developing the investigative reasoning and technical judgment required in the workplace.
This session demonstrates that process using a simulated FIN7 intrusion as a case study. The investigation begins when law enforcement reports finding an organization’s financial information in a threat actor’s possession. Learners must determine what happened, identify the affected systems, establish the scope of the compromise, and recommend an appropriate response.
Learners correlate SIEM alerts, firewall traffic, Windows events, and system artifacts to uncover a phishing-enabled compromise, lateral movement, persistence, financial-data staging, and exfiltration. Observable performance criteria evaluates ability to identify the initial compromise, reconstruct the attack, confirm data loss, and propose defensible containment and recovery actions.
FIN7 represents one of the many scenarios available in the Cyber Range. Exposure to multiple incidents helps a learner develop transferable capabilities rather than memorize a single investigative process. Structured debriefing then turns missed evidence and incomplete conclusions into targeted opportunities for additional practice.
Attendees will leave with a practical understanding of how they and their teams can use WSU Tech’s Cyber Range to develop, refine, and evaluate job-ready cybersecurity competencies through realistic, scenario-based practice.
So, You've Inherited OT Security
Session 3 · 1:30 PM – 2:15 PM
Joe Lobdell
Walnut
OT (Operational Technology) security is frequently handed to an IT security team with little to no training in how or why it's different.
Come learn:
- What is OT?
- Why can't I just use IT security tools?
- What is the right way to secure them?
Scaffolding Over Scale: Unauthenticated Account Takeover in Blazor with a Local LLM
Session 4 · 2:30 PM – 3:15 PM
Ryan Chaplin
Redbud A
This talk covers a real unauthenticated account takeover found against a mature enterprise client's .NET Blazor WebAssembly application. We will discuss how hardcoded encryption keys slip into client-side .NET assemblies and how that can compound with other common vulnerabilities into a full arbitrary account takeover from an unauthenticated threat actor.
These vulnerabilities were partially discovered by a frontier model (Claude Sonnet 4.5, tested Mar 2026) with refusal behavior bypassed. However, it couldn't put the full exploitation chain together. This talk demonstrates that a much smaller local large language model (LLM) with the right scaffolding achieves full account takeover and, in some cases, appears to surpass the frontier cloud model’s capabilities.
This talk also covers how to defend against this class of vulnerabilities, advantages of local LLMs, and the tooling and resources to help you do the same.
Note: The finding was reported to the client, remediated, and their information has been redacted and anonymized. The target is described generically and all demonstrations run against a purpose-built replica.
AI Governance: Move Fast Without Losing Control
Session 4 · 2:30 PM – 3:15 PM
Chrissie Collins
Redbud B
Type: Discussion Panel
Moderator: Chrissie Collins
Panel: Jeff Buss, Cory Brasel, Shawn Evans, Nikita Belikov
As organizations rapidly adopt artificial intelligence, governance has become critical to protecting not only their own information, but also the data entrusted to them by customers and partners. The challenge is balancing the productivity and innovation that AI provides with emerging risks involving data leakage, privacy, security, regulatory requirements, and responsible use.
This panel will bring together cybersecurity professionals for a practical discussion of the real-world challenges organizations are encountering as they develop and implement AI governance programs. Panelists will share examples, lessons learned, and approaches for establishing policies, managing risk, educating employees, and maintaining appropriate oversight without unnecessarily restricting innovation.
Attendees will leave with practical considerations and recommendations they can apply when evaluating or strengthening AI governance within their own organizations.
eMMC Firmware Extraction
Session 4 · 2:30 PM – 3:15 PM
neko
Redbud C
Firmware extraction is a critical first step in hardware security assessments, and eMMC storage is one of the most commonly encountered targets across "higher-end" embedded AI and IoT devices. This talk covers two practical approaches to extracting firmware from eMMC chips: in-circuit lead tapping and full chip-off removal. We walk through identifying eMMC pinouts, soldering to exposed test points, and interfacing with affordable readers for in-circuit extraction, then cover hot air desoldering, BGA reballing, and reading bare chips via socket adapters for chip-off. For each method, we discuss tooling, trade-offs, failure modes, and when to choose one approach over the other based on board layout, risk tolerance, and common obstacles like epoxy potting and locked partitions.
IT on a Shoestring
Session 4 · 2:30 PM – 3:15 PM
Logan Rhamy
Trail Rooms
Most small businesses don't have an IT department, they have one overworked person wearing five hats, or nobody at all. This talk is a practical playbook for small business owners and the accidental IT people tasked with keeping things running: documentation, backups and disaster recovery, automation, compliance basics, and, just as important, knowing when it's time to call in outside help.
Cyber Monitoring: From Vulnerability to SIEM
Session 4 · 2:30 PM – 3:15 PM
Martin Yarborough
Walnut
Cybersecurity monitoring is often treated as a collection of separate activities—vulnerability scanning, endpoint monitoring, log collection, SIEM alerting, and security assessments. The result can be an abundance of security data without a clear understanding of what actually represents risk.
This session presents a practical approach to building an integrated cybersecurity monitoring program that connects vulnerability discovery with endpoint visibility and SIEM monitoring. We will examine how external and internal vulnerability scanning, endpoint vulnerability detection, security-event collection, and SIEM analysis complement one another—and, equally important, where each technology has visibility gaps.
Attendees will learn how to move beyond periodic vulnerability reports and isolated security alerts toward a continuous monitoring model that answers three fundamental questions: What is vulnerable? What is happening now? And what requires action?
Using practical examples and lessons learned from real-world monitoring environments, the session will demonstrate how organizations of varying sizes can develop meaningful security visibility without creating an unmanageable volume of alerts, reports, and data.