| Hackstories from the field | |
| Moderator :: Ms. Dana Ludviga | |
| 11:30 - 12:00 |
Inside the Cyberattack and Recovery of Latvian State Forests,
Mr. Māris Kuzmins (Latvian State Forests, LV),
TBC (CERT.LV, LV)
TBC
|
| 12:00 - 12:30 |
TBC,
TBC
TBC
|
| 12:30 - 13:00 |
Hacked Anyway: What Recent Incidents Really Teach Us,
Ms. Nadia Meichtry, (Oneconsult AG, CH)
Over the past years, I have responded to numerous security incidents across a wide range of industries, from ransomware attacks and exploited vulnerabilities to insider threats.
Although every incident is different, the same patterns and challenges appear again and again.
In this talk, I'll share the main lessons we can learn from these cases, looking beyond the technical details of the attacks.
Attendees will leave with a clearer understanding of where organizations struggle during incidents and what can make the difference when it matters most.
|
Agenda
13 OCT
Workshops and Trainings
Registration for the "CyberChess 2026" conference and the
workshops and trainings on October 13 is separate. Please remember that you can register for
either one full-day workshop OR one morning and one afternoon workshop. Note that seats are limited!
Registration for workshops and training sessions will be open until September 28.
Workshops and training sessions are free of charge.
Morning Workshops
| 08:30 - 09:00 | Registration |
Location | ||
| 09:00 - 12:30 | No EDRs Were Harmed During This Workshop [ENG], Mr. Jaanus Kääp (ShellDot, EE) | CERT.LV, Raina bulvaris 29 | Register | |
|
This workshop focuses on one of the most persistent challenges in modern offensive security: getting your tools past EDRs, antivirus products, and the increasingly suspicious collection of endpoint controls standing between you and a successful operation.
We will explore how existing offensive security tools can be configured and modified when their default versions are detected. Rather than changing random parts and hoping the alerts disappear, we will examine practical ways to identify what is being detected, understand why it is being detected, and determine which parts of the tool actually need to change.
The workshop is built around hands-on testing against real, currently used EDR and antivirus products in a controlled environment. Participants will compare how different products respond to the same techniques, learn why an approach that works perfectly against one product may immediately upset another, and examine how configuration changes and targeted modifications can affect detection.
We will also look at modern approaches for reducing the time required to produce a working solution, including automation and modular tooling. Tuoni will be used as a practical example of how an offensive security framework can provide configuration and modification options for adapting tooling to different environments.
By the end of the workshop, participants should have a more systematic understanding of endpoint detection evasion, the ability to diagnose likely reasons why a tool is being detected, and a practical methodology for adapting offensive tooling.
- Type of the workshop: technical
- Level: upper intermediate
- Prior knowledge necessary: Being comfortable in software development area is quite needed and some experience in red teaming or similar area helps to set things to better context.
- Personal equipment necessary: Laptop with capability to run 2+ x64 VM's.
|
||||
| 09:00 - 12:30 | CISO Challenge: Identify, Protect, Detect and Respond [ENG], Mr. Jan D’Herdt (SANS, BE) | AC Hotel Riga | Register | |
|
Step into the cybersecurity leadership team
experience! This high-energy, interactive
workshop throws your team into realistic,
high-stakes scenarios where every
decision counts. You’ll face evolving cyber
threats, manage crises under pressure, and
make strategic choices that impact your
organization’s security, reputation, and future.
Your mission? Build and sustain the strongest
Security Culture. From employee training to
incident response, every move you make will
shape your score, and prove your leadership.
Can you balance risk, budget, and impact while
staying ahead of attackers?
Will your strategy hold when the pressure
is on?
Join us and find out.
Outcomes and Learnings:
- Understand the core responsibilities of cybersecurity
leadership in high-stakes environments.
- Learn to prioritise risk and allocate resources effectively.
- Gain insights into building resilient security cultures.
- Experience real-time decision-making under pressure.
Intended Audience:
Security leaders, aspiring CISOs, and professionals who
want to sharpen their strategic cybersecurity leadership
skills.
Type of the workshop: educational
Level: intermediate
Prior knowledge necessary: No prior experience required, just a sharp mind and
a collaborative spirit.
Personal equipment necessary: A mobile device (laptop, tablet or smartphone) and a
stable internet connection is required to take part in the workshop.
|
||||
Afternoon Workshops
| 13:00 - 13:30 | Registration |
Location | |
| 13:30 - 17:00 | MISP: Kas tas ir un kā to "ēd"? [LV], Mr. Armīns Palms (CERT.LV, LV) | CERT.LV, Raina bulvaris 29 | Register |
|
MISP (Malware Information Sharing Platform) ir viena no plaši izmantotajām atvērtā pirmkoda platformām kiberdraudu informācijas apkopošanai, strukturēšanai, analīzei un apmaiņai.
Šajā praktiskajā darbnīcā dalībnieki iepazīs, kas ir MISP, kāpēc tas tiek izmantots un kā ar to efektīvi strādāt ikdienas kiberdrošības un incidentu reaģēšanas darbā. Soli pa solim apskatīsim platformas galvenās funkcijas, draudu informācijas ievadi un strukturēšanu, Events un Attributes, indikatoru (IoC) izmantošanu, informācijas korelāciju, kā arī iespējas dalīties ar draudu informāciju ar citiem uzticamiem partneriem un kopienām.
Darbnīcas laikā dalībnieki ne tikai iegūs teorētisku priekšstatu par MISP, bet arī praktiski izmēģinās darbu ar platformu, lai saprastu, kā no atsevišķiem tehniskiem indikatoriem un novērojumiem veidot vērtīgu un izmantojamu kiberdraudu izlūkošanas informāciju.
Semināra veids: izglītojošs
Līmenis: iesācējiem
Iepriekšējas zināšanas: Darbnīca galvenokārt ir domāt auditorijai, kas ir kaut ko dzirdējuši par MISP, bet vēlas uzzināt vairāk.
Nepieciešamais aprīkojums: Portatīvais dators
|
|||
Full Day Workshops
| 08:30 - 09:00 | Registration |
Location | ||
| 09:00 - 17:00 | Inside Malicious Files: A Practical Introduction to Malware Analysis [ENG], Ms. Nadia Meichtry (Oneconsult AG, CH) | CERT.LV, Raina bulvaris 29 | Register | |
|
When investigating security incidents, incident responders are often confronted with malicious files, e.g. web shells, scripts, payloads, or ransomware samples.
Understanding what these files do is critical for scoping an incident, identifying attacker capabilities, and determining the appropriate response.
This hands-on workshop provides a practical introduction to malware analysis from an incident response perspective. Participants will learn a structured approach to analysing suspicious files, extracting relevant information, and understanding attacker behavior without prior reverse engineering expertise.
Through guided exercises, we will analyze real-world malware samples using freely available tools. By the end of the workshop, participants will know how to triage malicious files efficiently and understand how malware analysis supports effective incident response.
Type of the workshop: technical
Level: beginner
Personal equipment necessary: Participants should bring a laptop capable of running virtual machines.
Before the workshop, please install:
- VMware Workstation Pro or VirtualBox
- REMnux virtual machine (https://remnux.org/)
- FlareVM (https://github.com/mandiant/flare-vm)
|
||||
| 09:00 - 17:00 | Security of Field Operations [ENG], Dr. Bernhards Blumbergs (CERT.LV, LV), Ms. Gabrielle Joni Verreault (Université de Montréal, CA) | AC Hotel Riga | (By Invitation Only) | |
|
The objective of the workshop is to prepare participants, in both mindset and practical capability, for real-world deployments in conflict zones and other contested environments. The workshop is aimed at deployable operational, diplomatic, military, and investigative experts.
This intensive and interactive full-day workshop will walk you through a scenario-based deployment mission in a hostile environment. You will work in a team to develop practical skills across the full spectrum of field readiness. Through building the operational security mindset, achieving equipment readiness, and applying OpSec discipline during in-field operations in high-risk environments, the workshop deliberately integrates the physical and cyber dimensions of operational security, reflecting the realities of operating where the two are inseparable. You will learn that survival can hinge on details as small as how you order three glasses at the pub.
You will be trained by instructors with established hands-on field experience - a military and a practical researcher, with backgrounds in active cyber operations and their security, physical operational security, and working in contested environments under modern warfare conditions.
Participants will increase their general operational readiness level by establishing and advancing an OpSec mindset, understanding the synergies between the cyber and physical aspects of operational security, and conducting risk-based assessments of the operational environment.
Level: intermediate
Prior knowledges necessary: A basic understanding of physical and cyber operational security is desirable.
Personal equipment necessary: None required, all materials are provided.
Workshop registration is primarily by invitation. Any remaining places will be made available to the public.
|
||||
14 OCT
| OMEGA HALL | |
|---|---|
| 08:00 - 09:00 | Registration and morning coffee
|
| 09:00 - 11:00 | OPENING PLENARY |
| Moderators :: Ms. Dana Ludviga & Mr. Kārlis Svilans | |
| 09:00 - 09:15 | Opening remarks, TBC |
| 09:15 - 09:25 | Opening remarks, Ms. Baiba Kaškina (CERT.LV, LV) |
| 09:25 - 09:55 |
TBC,
TBC
TBC
|
| 09:55 - 10:20 |
Navigating a Changing Cyber Landscape: Why the Global Mechanism and UN Framework Matter,
Ms. Helen Popp (Ministry of Foreign Affairs of Estonia, EE)
The keynote will look at why the UN Framework for Responsible State Behaviour and the Global Mechanism matter for building a more stable and secure cyberspace. It will share Estonia’s perspective on the importance of turning agreed principles into practical action, strengthening cooperation, and building trust among all actors. It will also reflect on how the Global Mechanism can help us keep pace with a rapidly changing cyber environment and emerging challenges.
|
| 10:20 - 10:55 |
Who you gonna call?,
Mr. Varis Teivāns (CERT.LV, LV)
TBC
|
| 10:55 - 11:00 | Moderator Remarks |
| 11:00 - 11:30 |
Coffee break
|
| HACKING | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 11:30 - 12:00 |
So, you want to write malware?,
Mr. Jaanus Kääp (ShellDot, EE)
So, you want to write malware for a cyber exercise or red-team operation (hopefully, the sentence ends there and does not continue with “for several unrelated personal reasons”).
We wanted to do the same, and for nearly three years we have been developing offensive tooling for professional red teams, security testing, and realistic cyber exercises. During that time, we have discovered that building legitimate “malware” involves considerably more than creating a payload, opening a listener, and hoping endpoint security products remain politely unaware of what is happening.
In this fast paced talk, I will explore both the technical and less technical realities of developing this unusual category of software. We will examine architectural decisions, payload design, execution methods, communication channels, modularity, and the challenges of supporting different operating systems and environments.
The talk will also cover practical problems such as payload generation, configuration, command execution and adapting techniques when previously reliable approaches become detectable. Because nothing in offensive security remains reliable for long.
Along the way, I will share lessons learned from several years of developing and maintaining offensive tooling, including decisions that worked well, ideas that worked considerably less well, and features that appeared simple until implementation proved otherwise.
The goal is to offer an honest look at what it takes to build, test, maintain, and responsibly deliver realistic offensive tooling.
|
| 12:00 - 13:00 |
[TLP: AMBER]
"Ain't my fault" will get you uncovered,
Mr. Lorenzo Nicolodi (iCounter, IT)
One thing I learned about hackers is that they like anonymity. And that they don't take things for granted.
Sure, some technologies help. To a point. But if you are serious about online anonymity while conducting operations, relying on a single solution is a very bad idea. As Rick Prado said: "In combat, two is one and one is none."
I will do my best to show you how VPN, Tor and I2P work, when each of them is the right solution and why the always cool kid stating "I am a haxx0r, I run my 3 VPS, each in a different country" just proved he really doesn't understand how things work in reality.
I will try hard also to show you what your lab should look like, at a minimum, to guarantee you some confidence that nobody is going to knock on your door. At least for a while.
|
| Opening | |
| Moderator :: Ms. Katrina Sataki | |
| 11:30 - 11:35 | Opening remarks, Ms. Katrina Sataki (.LV Registry, LV) |
| 11:35 - 11:50 |
Trends and insights from the European ccTLD market,
Mr. Patrick Myles (CENTR, EU)
A look at the latest statistics and trends from the local and wider European domain name market.
|
| 11:50 - 12:20 |
One Internet. Three Registries. Many Opportunities - Part I
Moderator :: Ms. Katrina Sataki (.LV Registry, LV) Panelists: Mr. Heiki Sibul (Estonian Internet Foundation, EE), Mr. Tomas Mackus (DOMREG, LT)
TBC
|
| 12:20 - 13:00 |
One Internet. More Registries. More opportunities - Part II
Moderator :: Ms. Katrina Sataki, (.LV Registry, LV) Panelists: Heiki Sibul (Estonian Internet Foundation, EE), Mr. Tomas Mackus (DOMREG, LT), Ms. Barbara Povše (Register .si, Arnes, SI), Mr. Roelof Meijer (.nl, SIDN, NL)
TBC
|
| 13:00 - 14:00 |
Lunch
|
| CyberCrisis | |
| Moderator :: Ms. Dana Ludviga | |
| 14:00 - 14:30 |
CyberEurope exercise,
TBC
TBC
|
| 14:30 - 15:30 |
Chain reaction: Cybercrisis management in a connected world
Moderator :: Mr. Sébastien Garnault (Paris Cyber Summit, FR) Panelists: TBC (ANSI, LU), TBC (TBC), MGen. Dave R. Yarker (CAN CAF, CA), Dr. Friederike Zedler (NATO, DE)
In today's hyperconnected environment, a cyberattack rarely affects just one organization or nation. A single compromised vendor, cloud provider, software update, or critical infrastructure component can trigger a chain reaction with far-reaching business, operational, financial, and reputational consequences. This panel will examine how organizations can strengthen resilience, improve crisis response, and coordinate effectively across national borders, partners, regulators, and stakeholders during high-impact cyber incidents.
Among these, the discussion will examine international experiences of cybersecurity crisis management mechanisms and their role in enabling and supporting coordinated action during significant cyber incidents. It will explore how these mechanisms are tested and strengthened globally through regular exercises, such as Cyber Europe 2026, which help to assess preparedness, coordination, and resilience across Member States and relevant stakeholders.
Cybersecurity experts will share lessons learned from real-world cyber crises, discuss emerging threats, and explore strategies for preparation, communication, decision-making, and recovery.
|
| Artificial Intelligence | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 14:00 - 15:00 |
Attacker pattern matching with ML,
Mr. Patrik Hammersborg (NSM, NO)
TBC
|
| 15:00 - 15:30 |
Deepfake detection,
Mr. Jānis Grīslis (Verifix, LV)
TBC
|
| 15:30 - 16:00 |
Coffee break
|
| Cyber Deterrence | |
| Moderator :: Ms. Dana Ludviga | |
| 16:00 - 16:30 |
[TLP: AMBER]
Deterring the Aggressors: Towards a Framework for Cyber Attribution,
Mr. Dāvis Baumanis, (Ministry of Foreign Affairs of Latvia, LV),
Mr. Arturs Ivanovs, (Ministry of Foreign Affairs of Latvia, LV)
Cyber threats are at an all-time high – from state sponsored cyberattacks, to proxy cyber-threat actors or pro-state hacktivists. Cyber defences and resilience are daily front lines for security of our information systems whose purpose is to deny cyber-threat actors’ openings for cyber-attacks. By reducing the anonymity and sense of impunity of cyber threat actors and creating consequences for their actions, we deter cyber-attacks and add an additional layer for our cyber security.
A structured framework for cyber attribution provides such a layer, as it exposes malicious actors and imposes reputational and diplomatic costs that signal unacceptable actions will not be tolerated and aim to deter future cyber-attacks. Collective attribution adds greatly to the deterrent effect. However, in order to pursue collective action, states require robust national systems in place to organize, implement and assess attribution.
In this segment, we will share Latvia’s experience of how we developed our framework for cyber attribution - from case-by-case early attempts at joint attribution and trial and error coordination efforts nationally to a more focused regulatory framework. We will also highlight observed differences between cyber attribution and sanctions but also how they are interlinked and mutually reinforcing.
|
| 16:30 - 17:00 |
[TLP: AMBER]
Deep dive into ecosystem of Residential Proxies: Companies, Platforms and Abuse,
TBC
TBC
|
| 17:00 - 17:30 |
[TLP: AMBER]
Cyber Fraud as a Service: Behind the Criminal Infrastructure,
Mr. Elvijs Bogdanovs (Europol, NL),
Mr. Oļegs Filatovs (State Police of the Republic of Latvia, LV)
The presentation will provide an overview of current cyber-enabled fraud trends, with a particular focus on how criminal services and infrastructure support fraud at scale.
It will begin with selected statistics and practical examples from Latvia and the broader international context, including business email compromise, fraudulent calls and messages, and other forms of cyber-enabled fraud. Particular attention will be given to the infrastructure behind these offences, including SIM-box operations and phishing-as-a-service platforms, as well as the way such services are advertised and offered to criminal users.
Two international law enforcement operations - Tycoon 2FA and SIMCARTEL - will be presented as practical case studies. These examples will demonstrate how criminal service providers can support large-scale phishing, fraudulent communications and other forms of online fraud across multiple jurisdictions.
Selected visual materials and operational video footage will be used to show how these services work, how they are disrupted, and why international cooperation is important in tackling cross-border cyber fraud.
|
| Threathunting | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 16:00 - 16:30 |
Discovering the Unseen: Accelerating Threat Hunting with AI,
Mr. Ernesto Fernández Provecho, (Trellix Advanced Research Center, ES)
As threat actors increasingly develop capabilities to bypass traditional security perimeters, the burden on SOC teams to manually sift through massive datasets has become unsustainable. This presentation introduces a modernized, proactive threat hunting methodology that combines endpoint and email telemetry with the analytical power of Artificial Intelligence (AI) to accelerate threat discovery from the initial steps to its final stages. Everything described in a way that can be reproduced by attendees in their environments.
The first half of the session establishes the practical foundations of our hunting strategy. We will highlight the necessity of creating a customer baseline to identify outliers and establishing a clear scope to avoid inefficient analysis. Moreover, we will explore how we leverage our intelligence to define the hunting hypotheses and the queries we will later use. This section also breaks down the nuances of alert-less anomaly analysis versus prioritizing alert-based hunting within the "gray zone" of newly discovered attacker techniques.
Moving from foundational theory to advanced application, we will then detail our AI-powered hunting framework, including an explanation of the process we used to teach our AI agent how to filter, discard, and understand the signs to find the most urgent campaigns in both email and endpoint telemetry. Then, we will showcase its capabilities through a demonstration, including examples of actual detections and the reasoning the AI has made to select them.
|
| 16:30 - 17:30 |
Sliding into the Enemy's DMs: Detecting SaaS-Backed Malware C2,
Mr. Patrick Staubmann (VMRay, DE)
Threat actors increasingly "live off the SaaS land" by abusing well-known collaboration and gaming platforms as covert command-and-control (C2) channels. This talk presents findings from ongoing research into e-crime malware families that use services such as Telegram, Discord, Steam, and others for C2, exfiltration, and dead-drop resolution. By leveraging a malware sandbox with full visibility into decrypted TLS traffic, we analyze how these families structure their communications, including API usage, message formats, embedded configuration data, and the delivery of second-stage payloads via legitimate services. From these patterns, we derive network-level fingerprints and YARA rules for plaintext traffic that enable robust detection, hunting, and clustering of related malware families. Finally, we discuss the role of abused SaaS applications and why legitimate domains should not be dismissed too quickly during malware analysis or incident response engagements.
|
| Is There Life Outside the Baltic Domain Space? | |
| Moderator :: Ms. Katrina Sataki | |
| 16:00 - 16:15 |
Who governs the internet?,
Mr. Jānis Kārkliņš (ICANN)
TBC
|
| 16:15 - 16:30 |
The New gTLD Program: 2026 Round updates and what is next?,
Ms. Aysegul Tekce (ICANN, TR)
The New gTLD Program: 2026 Round. Where we stand with the program and what is next in the 2026 round.
|
| 16:30 - 17:00 |
Protecting Intellectual Property in the DNS: New Trends,
Ms. Charlotte Spencer (WIPO, CH)
WIPO's recent service developments to combat cybersquatting: Emerging trends, use of AI, WIPO’s new case services (i.e., Expedited Case Processing and Early Termination), the Legal Rights Objection and String Confusion Objection for the next round of ICANN's new gTLD program, as well as the WIPO Overview 3.1. In addition, brief overview of the WIPO's ccTLD Program, including experience with .LV domain name disputes.
|
| 17:00 - 17:30 |
The "World-wide Web" of Regulations
Moderator :: Ms. Barbara Povše, (Register .si, Arnes, SI) Panelists: Mr. Jānis Kārkliņš (ICANN, LV), Ms. Charlotte Spencer (WIPO, CH), Ms. Iveta Skujiņa (.LV Registry, LV), Ms. Helen Aaremäe-Saar (Estonian Internet Foundation, EE), Mr. Tomas Mackus (DOMREG, LT)
TBC
|
| 17:30 - 21:30 | Social event (all participants) |
15 OCT
| OMEGA HALL | |
|---|---|
| 08:00 - 09:00 | Registration and morning coffee
|
| 09:00 - 11:00 | OPENING PLENARY |
| Moderators :: Ms. Dana Ludviga & Mr. Kārlis Svilans | |
| 09:00 - 09:10 | Opening remarks, Mr. Rolands Heniņš (NCSC, LV) |
| 09:10 - 09:30 |
Keynote,
MGen. Dave R. Yarker (CAN CAF, CA)
TBC
|
| 09:30 - 09:55 |
Exploring the changing European cybersecurity landscape,
Mr. Sébastien Garnault (Paris Cyber Summit, FR)
Europe’s cybersecurity landscape is entering a new phase. Cybersecurity is no longer simply a technical issue or a matter of regulation. It has become a question of power, sovereignty and national security.
Europe is facing several challenges at the same time. Russia represents an immediate and persistent threat. China raises a different, longer-term challenge around technological, industrial and economic power. And AI is accelerating everything, changing both offensive and defensive capabilities faster than our institutions can adapt.
In this context, European digital sovereignty cannot simply be about where data is stored or which rules apply. Sovereignty is ultimately the capacity to decide and act. That requires technology, industrial capabilities, resilient infrastructure, secure supply chains and the ability to protect our strategic interests.
But greater European sovereignty does not necessarily mean greater distance from the United States. Europe needs to strengthen its own capabilities while recognising that our security, technology and defence interests remain deeply interconnected across the Atlantic.
The challenge is to understand where Europe needs greater autonomy, where dependencies can be accepted, and where cooperation remains essential. This requires a much more pragmatic conversation about sovereignty, security and power.
Europe does not need to choose between sovereignty and alliances. It needs the capabilities that allow it to choose at all.
|
| 9:55 - 10:20 |
Compliance Is Not a Survival Strategy,
Mr. Patrik Fältström (NETNOD AB, SE)
Imagine an organization that complies with every cybersecurity requirement - and still cannot deliver its essential services.
How is that possible?
This presentation explores the difference between compliance and survival, why the distinction matters more than ever, and how critical infrastructure operators should think about resilience in an increasingly uncertain geopolitical environment.
|
| 10:20 - 10:55 |
Inside a celebrity cyber scam investigation: deepfakes & mind games,
Ms. Kerry Tomlinson (Ampyx News, US)
What tools and tricks are criminals using to carry out celebrity imposter fraud? Go undercover with a cyber journalist to see how a real case plays out, with the attacker deploying audio, video and image deepfakes, as well as potent social engineering techniques. See why this kind of cyber fraud is so powerful, stealing billions from victims each year, and the best strategies for defense. Plus, this session will look at undercover cyber investigation techniques, both technological and psychological.
|
| 10:55 - 11:00 | Notes from the moderators |
| 11:00 - 11:30 |
Coffee break
|
| Artificial Intelligence | |
| Moderator :: Ms. Dana Ludviga | |
| 11:30 - 12:00 |
Frontier AI,
Mr. Jesper Olsen (PaloAlto Networks, US)
TBC
|
| 12:00 - 12:30 |
TBC,
TBC
TBC
|
| 12:30 - 13:00 |
AI usage in CTI,
R.Wortmann (TrendAI)
TBC
|
| Cyber Threat Intelligence | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 11:30 - 12:30 |
How to hack a bank,
Mr. Thomas Tom Freer (Opswat, UK)
What would it take to walk into a bank, get behind the teller line, and walk out with a computer — without a weapon, without a plan, and without anyone stopping you?
Security awareness specialist Jayson E. Street did exactly that. In two minutes and twenty seconds he was behind the teller line of a Beirut bank he'd never visited, touching every machine in the branch. He stayed for thirty minutes. The manager showed up and started helping him.
Then he tried it again. And things didn't go quite to plan.
|
| 12:30 - 13:00 |
Hunting Adversaries in OT: Deception as a Proactive Detection,
Mr. Cezary Zieliński (Fortinet, PL)
Traditional security controls often detect attackers only after they have established a foothold within IT/OT networks. This technical session examines how deception technology can provide early visibility into malicious activity across OT/ICS and IT environments. We will cover the deception deployment architectures, and the design of realistic industrial decoys that emulate critical OT assets. Through a live demonstration, attendees will see how deception assets - such as PLCs, engineering workstations, and network services - can identify adversary activity while generating high-fidelity alerts with minimal false positives.
|
| A Safer and More Resilient Baltic Domain Space | |
| Moderator :: Ms. Katrina Sataki | |
| 11:30 - 12:00 |
Does NIS2 make ccTLDs more secure and resilient?,
Mr. Patrik Fältström (NETNOD AB, SE)
TBC
|
| 12:00 - 13:00 |
Verify at any cost: security solution or compliance illusion?
Moderator :: Ms. Katrina Sataki (.LV Registry, LV) Panelists: Ms. Iveta Skujiņa (.LV Registry, LV), Dr. Monika Nowikowska (.pl, NASK, PL), Mr. Timo Võhmar (Estonian Internet Foundation, EE), Mr. Tomas Simonaitis (DOMREG, LT), Mr. Christian Simmen (DENIC eG, DE)
Verifying domain registrant data in the context of the NIS 2 Directive is one of the key elements in strengthening the security and resilience of the DNS infrastructure. In practice, the biggest challenge is striking a balance between effective data verification and maintaining a simple and fast domain registration process. Problems arise especially with foreign customers and the automated registration of large numbers of domains. From a legal perspective, the main challenge is reconciling the requirements of NIS 2 with data protection regulations, particularly the GDPR.
|
| 13:00 - 14:00 |
Lunch
|
| Offensive operations | |
| Moderator :: Ms. Dana Ludviga | |
| 14:00 - 14:30 |
[TLP: AMBER]
Global Offensive Security Ops - what can go wrong?,
Mr. Piotr Borkowski (Cyber Arms, PL)
Piotr in his speech will talk about real case studies from operations done all over the world (Asia, Europe, Middle East, Africa) with some insights on how to do it properly and how to avoid mistakes. He will also deliver how to make Global Campaign targeting 5+ targets at once located in different part of the world. Some taste of physical Red Team operations will be included :)
|
| 14:30 - 15:00 |
[TLP: AMBER]
The Adaptive Pentester: Automation in Modern Offensive Operations ,
Mr. Gvido Bērziņš (Tet, LV)
Modern penetration testing and Red Team operations extend far beyond a fixed set of tools. Effective operators move between reconnaissance, infrastructure and identity analysis, attack-path discovery and validation, custom tooling, exploitation workflows, evidence collection, and reporting, selecting the most appropriate techniques for the target, scope, and operational context. This session examines how established security tools, deterministic automation, specialised data sources, and AI assisted analysis can be combined into efficient offensive-security workflows. It will also explore the value of local context in authorised testing, including Latvian public data sources, company and organisational information, national open data platforms, and other country specific resources that can turn a generic assessment into a more realistic and context aware operation. The session will also consider what supervised AI agents may realistically add to future pentests and Red Team engagements, while keeping human judgement and validation at the centre.
|
| 15:00 - 15:30 |
Agentic Intelligence: From Feeds to Decisions: Agentic AI and the Intelligence Cycle,
Dr. Daniel Gillblad (Recorded Future, SE)
The intelligence cycle has always been started by a person. Someone asks a question, an analyst tasks collection, and the work moves stage by stage until a report comes out. Attackers no longer work on that timescale. Agentic tooling lets them scan, adapt, and act without waiting for a human to decide what happens next. A defence that still begins with someone thinking to ask a question is running too slow.
Agentic AI breaks that dependency for defenders as well. When collection and processing can be delegated to machines, the cycle no longer waits: a new piece of infrastructure, a leaked credential, a shift in an actor's tooling triggers the analytical work directly. The output isn't a feed item, it's finished intelligence, already correlated and contextualised against your environment.
We will talk about what this looks like in practice: how agents perform analytical work, where they fail, and what changes about the job when the machine does the legwork. What happens when the scarce resource stops being capacity and starts being judgment?
|
| Operational Technology | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 14:00 - 14:30 |
Autonomous systems to support UAV warfare, and how to attack and defend them,
Mr. Simon-Pierre Deschênes (Tessellate Robotics, CA)
Autonomous systems rely on the continuous interaction between perception, planning, and control to understand their environment and execute missions safely. This presentation will first explain how modern robotic platforms build and leverage a Shared 3D World, transforming sensor data into a common representation used for localization, mapping, decision-making, and autonomous navigation. We will then explore how cyber attacks can target these systems by manipulating sensors, communications, software, or data, potentially degrading performance or compromising mission outcomes. Finally, in collaboration with Vendel, we will discuss modern approaches to securing autonomous systems, including resilient architectures, trusted software, secure communications, anomaly detection, and cybersecurity-by-design practices. Together, these elements are essential to ensuring that next-generation autonomous platforms remain reliable, trustworthy, and operational in demanding real-world environments.
|
| 14:30 - 15:30 |
Attack and defense in the realm of uncrewed vehicles,
Mr. Colin Stéphenne,
Mr. Bernard Lebel (Vendel, CA)
Uncrewed vehicles operate in harsh contexts and are often exposed to cyberphysical threats. This presentation aims to demistify and analyze their attack surface and propose mitigations and defense mechanisms. We take a closer look at the Robot Operating System and share a newly developped tool to assess the security of its deployment.
|
| Closing | |
| Moderator :: Ms. Katrina Sataki | |
| 14:00 - 14:20 |
See it. Share it. Stop it,
Mr. Jakob Bring Truelsen (Punktum dk, DK)
Punktum dk actively monitors the misuse of .dk domain names and notifies registrants and hosting providers whenever misuse is detected. This has led to a reduction in abuse, supporting Punktum dk’s goal of making .dk one of the safest domains on the internet.
During the talk, the methodology and results will be presented.
|
| 14:20 - 14:50 |
What will "trusted" mean in 2030?
Moderator :: Mr. Helmuts Meškonis (TBC) Panelists: Mr. Roelof Meijer (.nl, SIDN, NL), Dr. Monika Nowikowska (.pl, NASK, PL), Mr. Andriy Khvetkevych (NicNames.com & NIC.UA, UA)
TBC
|
| 14:50 - 15:20 |
Closing discussion: What's the next move?
Moderator :: Mr. Lars Forsberg, (iQ, SE) Panelists: Ms. Katrina Sataki, (.LV Registry, LV), Heiki Sibul, (Estonian Internet Foundation, EE), Mr. Tomas Mackus (DOMREG, LT),
For the closing panel of Baltic Domain Days, the leaders of Estonia’s, Latvia’s, and Lithuania’s country-code top-level domain registries come together to discuss what lies ahead for the Baltic domain-name industry.
Drawing on the themes, challenges, and ideas explored throughout the conference, the panel will reflect on how the internet landscape is changing and what those changes may mean for registries, registrars, domain holders, and the wider digital community.
What should the Baltic registries prepare for next? Where can they collaborate, and where might their paths diverge? And after two days of discussion, what is the next move?
The conversation will be moderated by Lars “LG” Forsberg, founder of Nordic Domain Days and CTO of iQ.
|
| 15:20 - 15:30 | Cosing speach, Ms. Katrina Sataki (.LV Registry, LV) |
| 15:30 - 16:00 |
Coffee break
|
| Moderators :: Ms. Dana Ludviga & Mr. Kārlis Svilans | |
| 16:00 - 16:20 |
72-hour readiness for a random blackout,
Mārtiņš Kaļķis (LMT, LV)
TBC
|
| 16:20 - 16:50 |
Physical insider threat identification and mitigation,
Mr. Clarke Jarrett (AHNA Group, UK)
TBC
|
| 16:50 - 17:20 |
How to Win Locked Shields (and Survive the Preparation)
Moderator :: Br. Bernhards 'BB' Blumbergs (CERT.LV, LV) Panelists: TBC (TET, LV), Mr. Ēriks Dobelis (TBC, LV)
TBC
|
| 17:20 - 17:30 | CTF Recap & Awards Ceremony |
| 17:30 - 17:40 | Closing speach, Ms. Baiba Kaškina, (CERT.LV, LV) |
| 17:40 - 17:45 | Closing speach by Moderators, Ms. Dana Ludviga & Mr. Kārlis Svilans & Dr. Bernhards 'BB' Blumbergs, (CERT.LV, LV) |
| 17:45 | Musical Treat |