Every talk runs 45–60 minutes as a conference session or
breakout, or expands into a half-day workshop. I also offer 20-minute
lightning talks on request. Happy to tailor to your audience.
TALK 01
Compliant and Compromised: Mapping the Gap Between Your Audit and Your Attacker
Passing an audit and getting breached in the same quarter happens more
often than people think, and it's not a contradiction. It just means your
evidence measured something different than what the attacker actually
exploited. I walk through three control patterns that satisfy assessors
while leaving a real path open, map each to the specific MITRE ATT&CK
technique it fails to stop, and leave you with a threat-informed validation
plan a small team can run, regardless of which regulation is generating the
paperwork.
GRC, Compliance & Blue Team
TALK 02
Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills
Cybersecurity has spent a decade investing in tools, frameworks, and
controls. Yet the outcome of a real incident still turns on whether the
humans in the room trust each other enough to speak plainly and decide
under pressure. This talk reframes the human side of cyber, communication,
mentorship, trust, and psychological safety, as load-bearing infrastructure
rather than a support function. When that layer is weak, technical
excellence cannot compensate; when it's strong, ordinary teams produce
extraordinary outcomes.
Leadership and Strategy
TALK 03
Rage Bait: Why Women in Cyber Are Tired of Being "Women in Cyber"
The way we do "women in cyber" is broken, and a lot of the people it's
supposed to help are done pretending it isn't. The work came with a second
job attached: be the gender on the panel, in the mentorship track, at
nearly every event that will have you, while the men who should be part of
the conversation get told it isn't their room. I make the operational case
instead, tracing the metric we got wrong back to what the Women, Peace and
Security framework actually asked for. Not headcount. Meaningful
participation.
Culture, Diversity & Team Performance
TALK 04
The Logic Looked Fine: Reversing Safety-System Bypass in Critical Infrastructure PLCs
In 2026, Iranian-affiliated actors disrupted PLC operations across US
water, energy, and local-government infrastructure without a single
zero-day. They reached misconfigured, internet-facing controllers through
the manufacturers' own programming software, then modified the safety
logic itself: shutdown and alarm routines disabled, HMI displays reading
normal while nothing underneath was. I walk through the public advisory
this campaign is documented in, then spend the second half on defense that
works on a normal budget, from known-good logic validation to monitored
gateways in front of controllers that can't defend themselves.
ICS/OT, Threat Intel & Blue Team