Monday, July 20, 2026

OWASP Global AppSec EU 2026 - Achievement Unlocked

When Mireia Cano and I received the confirmation that our paired talk "Security Champions: Lessons from Opposite Trenches" was accepted at one of the largest OWASP events, the OWASP Global AppSec EU conference, we were speechless. This was too good to be true! We knew the journey there would be very stressful, given the short time left from getting accepted to the conference taking place, and given our lives already had super busy plans for us. And yet, we simply couldn't resist. We fought our way through and overcame every hurdle on the way. We knew why we did it and it was worth it in the end. And Mireia, I'm truly grateful you pulled through together with me! Would we repeat this very stressful experience? Most likely not! But this time, it worked out even better than we hoped for. Here's how the conference went overall.

 


Welcome to Vienna

Vienna was this year's location for the conference which used to move across Europe, and it seems OWASP will stay there for a few years. For me it was a great opportunity to visit the city which isn't that far away from home yet I've never been there.

So I've visited Vienna for the first time, exactly during a period Europe faced an extreme heat wave. The city was burning hot and I was extremely happy that the hotel I chose had working air conditioning and was in walking distance from the conference venue.

Mireia arrived a bit later, and once settled in, we used the time for practicing our talk. I mean, how else could it be. Paired talks are extremely tricky to get right and done well if you don't want to simply patch two half-talks done by two different people in two different styles together and hope for the best. (Nope, that's definitely not how we wanted to do this.) This was our first time to practice in person, and we really needed that opportunity.

Once the duty was done, we enjoyed the rest of the (still very hot) evening over a nice dinner and then called it a day. We knew we would need the energy for what was to come.


First Conference Day

Good thing our talk was scheduled for the second day only, which meant I could fully dive into the experience and check things out on day one. 

That day started with a special breakfast for me. Now, if you know me, I'm neither the breakfast type of person nor am I fully awake at that time of day. This one, however, was too good not to opt in for. It was the "Women in AppSec Breakfast" co-hosted by Tanya Janca, Juliane Reimann, Kim Wyuts, and Marisa Fagan. I mean, how could I miss this chance not only meeting those folks I only knew from social media but also meeting a bunch of other women in my area? I usually love seeing a smaller group of folks first before encountering the whole crowd at a conference, and this one promised to create a safe enough space to make real connections. Turns out, it really did! I met lots of amazing women this morning and we happened to bump into each other again and again during the event. Many thanks to Michelle Mariam Philip, Margot Schepens, Eden Yardeni, Liel and Tina! This pre-conference session truly made me feel welcome from the start and it seems the others were happy about this opportunity just as well.

Here are the sessions I've joined during the rest of the day.

  • Keynote: "The Reinvention of Software Engineering" by Hannah Foxwell. Hannah presented her view on how the software world is changing due to latest AI tooling. She stated that with agentic development, speed of development is outpacing speed of decisions - and yet we really shouldn't just build anything because we can, but something that is worth building. We also need to have the means to ensure safety as things are speeding up. People do and will always matter, so invest in them and broaden their skills.
  • "Why AppSec Fails at Scale (and How to Fix It)" by Eduard Thamm. As Eduard shared, AppSec fails at scale when you keep managing findings instead of designing systems that make secure behavior the easiest path. Preach! Lots of gems in this talk. Like: Security advice that ignores delivery pressure will be routed around - the system rewards shipping fast and often. Haven't we seen that over and over again? Not only with security but all kinds of aspects that make good quality software? Eduard asked everyone to move from findings to mechanisms to make the secure behavior the default. Hear, hear.
  • "Authorization Is Where Your App Goes to Lie" by Eden Yardeni. Eden rightfully pointed out that broken access control issues just keep showing up and stick around among the most common vulnerabilities. Why? Because they're often bound to business logic and hence depend a lot on the underlying intentions of features. It's not straightforward for any application to tell who should be allowed to do what - rather the opposite. Eden's answer to this? Use policy engines so "your product owner's intention compiles into policy as code". Helpful for threat modeling, too!
  • "Retiring CVE Chasing: Defending Against Application Exploit Techniques" by Idan Elor. Idan appealed to the audience that we need to start defending against the underlying techniques instead of just running after getting vulnerabilities fixed (have I already shared how often we're seeing this one?). If we build technique-level controls and detect exploitation attempts, we can cover whole classes at once. Idan presented the application attack matrix to help - a community-driven framework mapping tactics, techniques and procedures against modern applications, which can be used for threat modeling and in architecture reviews.
  • "This Build can Break You - Evil Runners and eBPF for Detection" by Reinhard Kugler. Reinhard shared how different CI/CD runners handle things differently and hence show different attack vectors - yet usually they are highly privileged and a valuable target. How to see what happens in the Kernel space? The answer is eBPF code running in a virtual machine in the Kernel. You can attach functions to a trigger like a syscall, trace event or network call and hence detect malicious activities. As Reinhard said, observability is the first step of defense!
  • Book Signing: Alice and Bob Learn Application Security Tanya Janca. Well, I simply had to seize this opportunity. Tanya had been the most influential person in my security career so far, and by far. I've literally only seen my way into security because of her. Knowing she would be at the conference, I kept looking for an opportunity to talk with her, at least shortly to thank her for her work. At breakfast, this opportunity did not show up and I didn't want to impose. Then, at one of the earlier talks that day, I happened to sit front row (as usual) and prepare my sketchnote for the following talk. I was talking with another person next to me, when someone suddenly turned around to us. It was Tanya! We happened to have a quick chat where I blurted out I was in security because of her making security accessible, and also nervously revealed we'll also have a talk the next day. I was super happy this happened and happened naturally. I still wanted to go to her book signing, now even more (I obviously had her book of course already, yet a physical signed copy is just something truly special). And Tanya remembered me and wished us good luck for the talk. Honestly a true fan-girling moment. Stay tuned, this story continues!
  • "The Devil is in the Defaults - what to do about XSS" by Frederik Braun. Cross-site scripting has been the number one CWE for over 10 years. The measures we have to defend against it still aren't as widely used as they should. Like the Content Security Policy - it's shocking how few websites actually make good use of it. Trusted types are great as they treat all HTML parsing as harmful unless proven otherwise - but they also need to be enabled through a CSP directive (which we know only few even use), and, very unfortunately, they ignore context during HTML parsing. Here comes the HTML sanitizer API to the rescue! It will never allow XSS - guaranteed by the browser and as part of HTML standard. I love that Frederik left with a hope-instilling note: we indeed can fix XSS.

During the day, it was really pleasant to run into some folks I already knew from other conferences! Like Clemens Hübner who Mireia and I met at the Open Security Conference 2025. Or Irfan Qadoos whom I met at both BSides Munich and security meetups. Just loved catching up with both again. The world is small and you never know where you'll meet again.

The official program ended already by 16:15 CEST which I was absolutely not used to from other conferences. Of course, networking events are super crucial and lots of stuff was planned on that end, not only socializing at the venue but also dinners and sightseeing offered by various sponsors. Well, not for Mireia and me this time, because obviously we had to use this last opportunity to practice our talk and make it work for the next day. Lucky us, we could still use the venue for the first dry run so we had a "close to real" practice environment. As things closed down at the venue, we had to move out and do the second run at our accommodation. Once we had a good enough feeling, we called it a day. I took the remaining time of the evening to enjoy a really lovely dinner at a Chinese restaurant offering as authentic as one can get Sichuan food. It was absolutely delicious and just good for the soul after a long stressful period of months. Especially as the very next day, it was on.

 

Second Conference Day

The second day, how else could it be, I was rather late for the first session yet made it just in time. I knew ahead of time I most likely won't be able to join many things next to our own talk, yet in the end I managed to catch a few sessions still. 

  • Keynote: "We Live in the Future: The Death and Rebirth of Application Security" by Gadi Evron. Gadi reminded us that things keep changing and we have to keep changing with them. For example, we cannot trust security configurations anymore when agents can just change them. The perimeter shifted to the endpoint agent, yet security controls don't cover them yet. Gadi raised a big question: English is the new programming language - yet how do we secure English?
  • Book Signing: Threats: What Every Engineer Should Learn From Star Wars with Adam Shostack. Yes, I just had to go to this book signing as well. Of course I had Adam's book as well already. But remember, a signed physical copy is a special thing! Also, you never know what will happen. I just loved that Adam noticed my Star Trek shirt and complimented me on it. Well, that's one of the many reasons I love wearing such shirts. They are a great way to find your kin and have lovely conversations. Just like with Adam this time. Thanks a bunch for that!
  • "Keep It Between Us: Manipulating Humans for Better AppSec (Ethically)" by Nariman Aga-Tagiyev. Nariman focused this talk on human motivation - what makes us do things? What are we actually driven by, how much does this reason come from the outside, and how sustainable is it? He reminded us that with some reinforcement, behavior will become a habit, and we can make use of this in our AppSec programs. Make it obvious, make it attractive, make it easy, make it satisfying. Or: Invert all of the above. The invisible side of AppSec and the secret plan is to convert activities into habits. We can start with writing down what the current good and bad habits are around a problematic behavior we observe.
  • "Security Champions: Lessons from Opposite Trenches" by Mireia Cano and me. It was time. We went on stage. The show was on. Have I said paired talks are a special kind of a challenge? This time, we attempted role plays on stage to convey our messages and have a red thread throughout the talk. Well, it was risky - these role plays could have come across as very cringe and over the top. You can't imagine how happy we were when we received lots of amazing feedback afterwards exactly on those theatrical role plays! Seems we hit just the right note and they indeed helped make the topics tangible and relatable with folks. We pulled through, it was our best version of the talk, and you don't know how happy I am that this was recorded! The relief was real afterwards. We really did it! Time to celebrate. That being said, what did we talk about? Well, Mireia came from the security side, having gathered plenty of experience with designing and running security champions programs with everything that could go wrong and what helps to make them go well and evolve. And I lived that champions experience myself for three years before going fully into security, now running a security champions program myself! We've found four key aspects that truly made the difference for such programs. The slides are already out, yet to get the full experience, you'll have to wait a couple of months until the recording is released.
  • "Using CTFs as a Community of Practice Content Machine" by Marco Macala, Florian Schier, and Christian Buchinger. In this talk, they described the security community they built, what worked and what didn't. Very fitting talk to come just after ours! Marco, Florian and Christian advised to keep the monthly sessions light, comedic and consistent. To make them engaging for different backgrounds. To have open discussions, give people free rein for content. And, what I especially love: there should be no grandstanding from security. So much this, seen this way too often as well! All this made them discover CTFs as a perfect opportunity to increase awareness and skills. They encouraged folks to keep them very basic and limiting the effort to set them up. Especially: education over competition, approachable for everyone! That really resonated with me and my current approaches to CTFs, especially when giving such sessions during open space conferences.
  • "Insecurity as Code: How Modern Software Scaled the Attack Surface" by Igor Stepansky. Igor explained how applications aren't the only attack surface anymore - it's everything around them as well, while everyone is already drowning in findings. Due to AI tooling, alerts are exploding - yet are they even valid? Igor reminded us: You're not behind, you're buried! It's about reliably finding the 1% truly critical. To triage on reachability and business impact and then patch those fast, focusing on what matters. And instead of fixing more findings, we should remove the attacker's leverage. This!

During the day, even though the excitement of the upcoming talk was there, I once again had opportunity to meet folks. Like Frederik Braun whom I was connected with via social media yet we never had a chance to talk before. Or Lars Hermerschmidt whom I heard about through a friend working at the same company. Or Ali Kabiri who was immensely kind helping me out with my (super cool) OWASP badge by getting me an extension for it. Also meeting folks I met before, like Michael Helwig. Really enjoyed all those conversations.

The conference approached its closing, and with that came a very special moment for me. Remember that Tanya Jana wished me good luck for our talk? Well. It happened to turn out that she was attending the same last talk as I was. As I was finishing up my sketchnote, she was coming to the front, chatting with the speaker. While I collected all my stuff, she saw me and asked how our talk went. We started to talk and, as it happens, went to the conference closing together. She was going to sit front row - as I usually do the same, I had no problem joining her. Sitting next to her, chatting, and really enjoying our conversation. This way, I also found out that the conference provided slim-fit conference t-shirts for the first time this year - and I have to thank Tanya for relentlessly trying to make the offering more diverse (no, unisex is not the solution here).

The closing was done. The room emptied. I looked around, and found Clemens with a few folks and joined them. I met Mariia Denysenko this way, realizing we're from the same location - a lovely encounter! It was also a pleasure to meet Michael Koppmann who enabled this whole conference by leading the team of volunteers and relentlessly working behind the scenes.

Then it was time to say goodbye and close this chapter. I had a nice dinner in the area. Calmed down a bit. Prepared for the next day - I was adamant to go sightseeing despite the heat. I thoroughly enjoyed doing exactly that after sleeping in the next day (I love art and art galleries are a great air-conditioned place by nature). The day afterwards, it was time to go home.

My first proper OWASP event was as big as they get. It was a good one in itself. It was a really great one because of the people. And it was definitely a huge achievement unlocked moment for Mireia and me!

Thursday, July 16, 2026

SoCraTes UK 2026 - Instant Connection

My heart is full of gratitude for finding such instant and easy connection. That's probably the best summary I can provide after my very first SoCraTes UK. I would have loved to be able to write this post right after the conference while memories and emotions were fresh, yet life happened and right now is the next best time for it. So let's start at the beginning.


Arrival

As for most conferences, it takes me a while to get to their location so I plan with a travel day back and forth. It reduces most travel worries due to hiccups, makes everything so much more relaxed, and also gives a chance to connect with the first set of people before the event starts. Also in this case, arriving the day before was well worth it. The lovely venue is located in the countryside, surrounded by nature. I had some time to settle in and just breathe. So far so good.

But then there was the heat. Well, that full-blown heat wave was not sparing the region and it presented a challenge throughout the conference. Especially given my hotel room was right under the roof, only had limited capacity to open windows and offered no air conditioning - not even any air circulation in the bathroom. Let's say it was tough, but I survived. 

Having settled in and rested for a bit, it was time for meeting people and then having dinner together. It was great to see people like Amélie CornélisEmily Bache, Simon Görtzen, Alexander Alemayhu, Michel Grootjans, or Raimo Radczewski again. At the same time I loved connecting with folks I haven't met before, like Clare SudberyJames BelClaudia Görtzen or Chris Jenkins.


Training Day

SoCraTes UK offered a bunch of trainings this year before the official start of the conference. I really appreciate these short pre-scheduled workshops that bring people together on practicing things hands-on and also provide some topics already to take further into the following open space.

  • TDD Game with Cyber-Dojo by Jon Jagger. If you haven't come across Cyber-Dojo yet, it's a great practice playground for coding katas across all kinds of programming languages. And Jon is its creator! In this session, we split into groups and tried to predict every outcome of our changes, working on a kata. And not only that, we played against an LLM model who tried to predict as well - so our goal was to trick it into false assumptions. Well. The sad news: Nearly no group succeeded. A rather sobering insight. I guess this might change once the domain would become more unique and specialized, yet who knows.
  • Secure Development Lifecycle Applied - How to Make Things a Bit More Secure than Yesterday Every Day by me. I've given this workshop plenty of times already and every time it's fun for me to notice how the groups engage with the material, what kinds of ideas they surface, which ones they try first. As usual, I hope it's also fun for the participants to practice together hands-on on tangible things they can do to make software more secure. I really appreciated the folks that joined, many of them gave detailed feedback - invaluable! - and people seemed to find value in it to take with them.
  • Using TDD to Get Better Results From LLMs/AI by Clare Sudbery. We worked together in pairs to build an app using only an agent, based on a set of requirements provided by Clare. Half of the groups had to use TDD, the other half was obliged not to even mention any kind of testing to the LLM. Curiously, the key insight for me from this workshop was not related to the question "TDD or not TDD" at all. It was that no matter how we implement things, we still need to work with humans first to gain insights on the domain and problem space to gain understanding on what they actually want to have us build. Classic lesson, learned once again.
  • Value Stream Mapping by Tim Ottinger. This was a really cool workshop for me. I've learned about the approach and key concepts from various sources for years and spread it further in one way or the other. This workshop felt super validating that what I've been sharing with my teams and outside was indeed going in the right direction. We all put on paper what the value of our product for a customer is, what they desire and require. Then we mapped out all the steps that need to happen to deliver this value. We annotated that stream to identify value-adding and non-value-adding work, including pure waste. We documented cycle times for each step, as well as waiting times in between the steps. Because one of the main points here is that speeding up a non-bottleneck process produces deeper queues and longer waits - you make the bottleneck worse. We analyzed several example situations and what we could do to make things flow. Well, as a longstanding advocate for pairing and ensembling, the answer how to increase flow was right there for me.

The training day was over, and the main conference started in the evening. It was a true pleasure to have Romeu Moura as a facilitator for the open space. He did a splendid job to get people to not only break ice, but also deeply engage with the values of the conference, really think about what everyone of us, starting with ourselves, can contribute to make this a safe space. This kind of foundation really showed the next days and I believe we took it with us even after the conference had ended.

Dinner time! Had lovely conversations with the folks at our table. Topics didn't stay shallow either, with the round addressing big societal problems as well as generational change. Afterwards, I was already pretty tired and close to call it a day, yet I wanted to check out what people were up to. The board game round intrigued me so much in the end that I stayed for way longer than originally planned. I just love games and the one people tried had a really cool concept, was not easy at all and truly required collaboration of players. You know, those lessons for life games. 


Open Space Day 1

I'm a night owl, so open space marketplaces generally start too early for me. Yet I better be there if I'd like to hear folks pitch their sessions and be ready to host one myself (and of course I do). Here's my pick of sessions for this first open space day.

  • "How can the way we work support democracy?" by Claudia Görtzen. I loved that she raised this topic already the evening before and was super happy she proposed it as a session. Because we all have our share in how we deal with things at work. Should we speak up about issues or not. Do we support unethical companies or not. Do we report misbehavior or not. Do we build this shady feature or dark pattern or not. All these big and small day to day decisions. In this session, we had a really insightful conversation and valuable exchange on tangible things we can do. The ones that stuck with me most? Join a union. Don't go alone - conspire. Learn from the book "Blueprint for Revolution". And the one I keep thinking about: start practicing anarchist calisthenics
  • "Your IDE / test suite / security scanner / design system / language server will steal your SSH key, unless ..." by Raimo Radczewski. When a security topic is proposed, I just have to attend! We all started with sharing stories about latest supply chain attacks - well, there were plenty of those happening the last years. Then we gathered ideas on what we can do to for better protection. Lots of good advice and tooling was collected. Like Little Snitch to monitor network calls on MacOS, that I already had on my list as it's been heavily recommended in the security community. As usual, there was also stuff I wasn't aware of yet that I'll definitely look into further, like nono.sh to sandbox any terminal agent, or Deno, where code executing in this Node-compatible JavaScript runtime has no access to read or write arbitrary files on the file system by default (among many more security features).
  • "Capture the flag together (beginner's edition)" by me. What can I say: I just love proposing this session at various open space conferences. So once more, I tried this out - a bunch of people joined and were captivated with capturing that flag. This highly collaborative and highly educational session just keeps giving and comes with pleasant surprises! I thoroughly enjoy doing these. It seems people did appreciate it as well: folks were staying longer, wanting more, and giving plenty of positive feedback afterwards. The one that made me the happiest is their emphasis on how accessible security and penetration testing became to them thanks to these sessions. What more could I want?
  • "How do we defend democracy and fight fascism" by Sarah Peper. I really wanted to continue this theme and engage more with this super crucial topic. Yet as my session before overran, I came to this one rather late. I was pretty tired at that moment in time so I can't really remember much from the conversation. At some point I had to walk out and cater to my needs. But that's also the beauty of open spaces - you're explicitly free, welcome and even encouraged to leave a session when you're neither contributing nor learning or just need something different at that moment in time.
  • "How the way we talk can change the way we work" by Ellen Potter. Ellen hosted an interesting session based on the book "How The Way We Talk Can Change the Way We Work" and the exercises in it. She also posted about it including a description if you want to give it a go yourself. We all started taking note of complaints we have. Then we reflected on what's important to us, basically what makes us complain in the first place. We thought about our own role in this to keep this being a problem, as well as competing commitments that contribute to us being stuck. Finally, we took a deep introspection into which assumptions we base this all on and what experiments we can run to find out what's actually the case. This was such a thought-provoking session! Lots to unravel and try out.

The day was closed, the evening marketplace was opened. I couldn't resist and, after a lovely relaxed dinner, I offered the follow-up to my previous session: "Capture the flag together (adventurer's edition)". Once again, lots of people joined in! And as it usually happens... the evening got longer and longer. We had fun feeling all the rollercoaster emotions of going through frustration and hope and trying ideas and failing and sometimes succeeding by finding a new insight and circling back and wondering what we missed and... You get the picture. In the end, we spent four wonderful hours and managed to capture the flag together. 

 

Open Space Day 2

The longer the conference, the more tired I grow. Which is nothing new. The good thing about open space conferences is that I don't have to feel bad about not going to sessions. Okay, I usually do feel bad at first. Then I realize it's the perfect thing to do right now to not stress myself, follow my needs, and recharge batteries so I can fully enjoy the rest of the day. So I chose a very slow morning without sessions. There were also quite a few personal tasks to do, given this was a period when a lot was going on in my life on top of many travels in a row. So I took the liberty to just miss sessions, although there were really good ones on offer. Instead, I could lift a burden from my shoulders and that was a true relief. In hindsight, giving myself grace that morning was absolutely the best thing I could have done.

Then came lunch time and afterwards I wanted to join sessions again. But things happened differently. A new session was born over lunch, as it happens. So I stayed at my table and our group continued talking about all the things: personal differences, neurodiversity, weird and even surreal situations, academics, health conditions, and so much more. It was just lovely. 

Way sooner than not it was time for the session I pitched myself that day, so I better had to be there! I had called it "Interactions with security folks - gone well and gone badly" and it aimed for an experience exchange. Once again, lots of folks turned up! I started with preparing a flip chart. I set the room so more people than just dominant voices would share. Then I asked for people's experiences and insights - and lots of stories were brought to the table. At some point I asked more specific questions that elicited further insights. The outcome? The "Nay" side of my flip chart filled up rather quickly - something I observe and hear way too often, all the bad experiences people make with security folks. The "Yay" side lagged behind for a long time. Good news: in the end, it was showing a lot more points. There's hope! This session provided lots of food for thought. Not only for my contribution at work, but also for what I want to share in my next talk that I'll soon start to craft.

For the last session slot during the day I picked the "TDD Game" by Ted M. Young. He brought the board game he designed and I was eager to give it a try. Even though we were on a tough time constraint, this game was truly a great experience! The game play and different tactics triggered insightful conversations and at the same time validated what our group knew already based on their own experiences. It would have been really interesting to do this together with people who are not aware of TDD, value stream mapping and flow, collaboration techniques, and all the good practices. Also, the game was super accessible, I felt very safe with my own knowledge and skills - and yet it forced decision making and practicing it. Another interesting thing was that Ted included the concept of exchanging a card as "thinking time", and also that you always have to hold back two (yes, two!) playing cards, otherwise you run out of energy. Really neat. If you have a chance to try this game out yourself, I can only recommend you to give it a go.

A lovely dinner followed, and, how else could it be, I offered once again an evening capture the flag session. I really enjoy them way too much not to. This time, something really cool happened. First, Michel Grootjans went all in and started a whole setup for himself and we could already use it for our session. Second, the group decided to experiment with different ways to collaborate and become more effective together in capturing the flag. Third, it didn't end that night at SoCraTesUK (spending up to six hours and absolutely capturing flags)! The next day at breakfast (that I obviously skipped), people kept talking about these sessions and expressed their eagerness to continue beyond the conference as a SoCraTesUK CTF round. Ellen Potter kindly offered to drive this, and can you imagine, the first session already took place and the second is scheduled! I'm a bit sad I couldn't join any of these (yet), and I'm overjoyed this just happens without me. Just beautiful.


Departure

It was time to leave. My heart was full, the newly found connections were strong. I absolutely appreciate the organizers to craft this space so intentionally. It seemed to be a smaller event this year compared to the previous ones, yet it did not matter at all. I absolutely recommend checking this one out. I'm certain I'm not the only one who got a lot out of it this year.

As a bonus, I opted for a longer stay at the airport so I could meet my dear community friend Tabitha Ncooro for the first time in person. We got to know each other a few years ago during the time I seeked connections into the security community and found her trying the same. Ever since we check in with each other regularly and I've found her to be one of the kindest and wisest people I've ever met in life. It was a true pleasure to meet her in person just after such a wonderful event.

I'm back home. It's been a few weeks since SoCraTes UK. And yet: I still think about this event, how people made me feel, and all the inspiration taken with me from it. This conference brought instant connection and keeps resonating.

Saturday, June 13, 2026

Elbsides 2026 - A Welcoming First Time

This year I had my first opportunity to go to Elbsides, the BSides of Hamburg. I had heard lots of folks recommend this conference and I was eager to experience it myself. It's been a lovely couple of days for sure!

On arriving in Hamburg, I met a dear friend for dinner. Really enjoyed the conversations, the tasty food, and in general taking a break after some wildly packed months. It was just what I needed before diving fully into the conference experience.

 

Workshop Day

With batteries recharged, I made my way to the workshop venue. What a warm welcome from the organizers! I knew two of them already from BSides Munich the last years, so it was really nice to catch up.

Then it was time for my own workshop: "Secure Development Lifecycle Applied - How to Make Things a Bit More Secure than Yesterday Every Day". I've given this session plenty of times now, each time to a different kind of audience. The participants I had this time were just great - they happily grouped up, engaged with the hands-on exercises, were eager to bring up even more ideas and try things out together. They truly made my job an easy one! In general, each time I repeat a workshop, I just love to see how different people approach a task and find different things. We can learn so much from each other. At the end of the workshop, participants shared a ton of feedback with me which is invaluable - much appreciated! That's how I knew the time flew by and people couldn't fathom how fast a 4 hour workshop could be over again. This was truly a good start to the conference for me.

Lunch was conveniently served right at the venue, so we could use the time effectively to enjoy the food and also exchange experiences. In the afternoon, I joined a half-day workshop myself: "Exploiting and Securing AI Applications on AWS" by Anne Stein and Robert von Massow. All too relevant these days. No matter if we like generative and agentic AI tooling or not, we have to deal with their outcome and impact at the least. What I really appreciated in this workshop was that the trainers acknowledged this situation. They also were really clear on what kinds of safeguards we can build and where we are at a lost stake due to the probabilistic nature of the beast. In specifics, they emphasized to make the tools that AI agents can call as descriptive as possible to control them via deterministic means as much as possible. AI models, however, can still go rogue on their own terms, so we need to build with this risk as a given. Any guardrails we add are probabilistic as well and hence aren't predictable either. The other part of this workshop I really appreciated was that we had plenty of interactive hands-on exercises to interact with a complex enough and at the same time simple enough system of an LLM having a set of tools available. We practiced both how to exploit the system and get the LLM to do what we wanted, and also how to constrain their reach through making the tools more restrictive, including classics like input validation. I paired up with another participant which was just perfect for the hands-on nature - we came up with more ideas this way and indeed managed to find our ways past the guards, also outside the foreseen path.

The workshop day was over. In the evening, I met a dear community friend I haven't seen for a while. They happened to show me around Hamburg and we had perfect weather for a bit of sightseeing! I love it when these occasions turn up at conferences. After long conversations and a really nice dinner, it was time for me to catch some sleep and get ready for the main conference day.

 

Conference Day

This BSides is a one-track conference. Which comes with benefits: no need to decide where to go, no fear of missing out, no issues trying to change rooms if the schedule is tight! Everyone experiences the same program. Which also means, you'll experience something you wouldn't have chosen otherwise. This really allows for serendipity and insights you would have likely missed. Sure, it might be that you're listening to a talk that's really not relevant for you - but that could happen also if you chose it yourself as you never know how the talk will turn out for real. This time, I did appreciate only having one track as it made sketchnoting easier.

  • Keynote: "Secrets don’t age well: Cyber, Kyber, Quantum and the encryption time bombs" by Natalie Kilber. Quantum computing is one of those areas I haven't learned much about so far. So Natalie's keynote was welcome to introduce a few concepts, in specifics given that cryptography is something most of us don't directly work on, but most of us for sure need to make use of. And in software, we need to prepare for migrating towards quantum. Also, this was the first time I heard about a cryptographic bill of materials (CBOM)!
  • "Harvest Now, Decrypt Later: Bringing Post-Quantum Cryptography to SSH" by Leon Rickert. More quantum! Leon shared a hybrid PQC approach, increasing security through redundancy by having a classical secret and a PQC secret combined in a shared hybrid session key. This could be just the first step in a gradual migration you hoped for. We also need to keep the context of our system in mind, some environments are heavily resource-constrained so performance matters a lot.
  • "Ghost in the Hiring Machine: Catch Fake Personas Before They’re Hired" by Michael Reimsbach and Rishi. This talk comes timely, following all the news where imposters had been hired by companies, thinking these folks were legit applicants. Michael and Rishi showed up what companies can do before a hiring decision in order to figure out whether a person is not who they claim to be, using a whole set of OSINT tools. I love that they also emphasized personal security and reminded us to protect ourselves and applying OSINT defensively.
  • "‘We Have Always Been at War With Eastasia’: Attacks Against Web Archives" by Robin Kirchner. Very interesting talk on how web archives can get targeted by malicious actors, trying to evade or deceive them. Robin presented the techniques that work most of the times that we need to be aware of.
  • "When Trust Breaks Under Pressure" by René Lößner. René shared sound advice on what you can do when confronted with information that is intended to manipulate you into unfortunate actions - and how to even detect that this is happening to you. Remember the FATE and SIFT acronyms.
  • "Let Him Cook! Hacking the Meatmeet BBQ Probe" by Julian (dead1nfluence). That talk was a fun ride of following the rabbit hole of "how does this tool work under the hood". Guess what, it ended up in lots of CVEs getting reported. 
  • "The Map of Artificial Treasures: What to Automate in Security - and Why?" by Michael Helwig. Michael looked at the various options we have using AI systems, how they differ, and what makes more sense to use for which use case. Because not every hammer is for every nail.
  • "Pull the Plug: Kernel-Level Surgery to Blind EDRs" by André Lima. This was a really interesting dive into tricking Windows EDR systems to let your bad driver go through without getting blocked, or even logged. 
  • "I Let My Pi5 Hack: Building a 0$ AI Pentesting Agent" by Nithin Ravi. I really appreciate how Nithin started with the differentiation that AI is not the same as automation and that a lot of things can be automated well without the usage of any AI. AI tooling can be good for what it's actually good at. His journey on how to use low budget tools to build a pen testing agent, however, resulted in the following conclusion: no, you truly don't need AI for everything.
  • "Your Traffic Is Lying to You" by Lisa Fröhlich. Lisa pointed out that the vast ratio of web traffic coming from bots these days and how they go undetected by traditional monitoring systems in the age of AI. We can still learn what's going on - yet only if we truly know our actual valid traffic.
  • "Still Out of Sight? The NIS-2 Reality Check in German SMEs" by Younes Ahmadzei. I've enjoyed Younes' previous version of this talk at BSides Munich 2025. Now that NIS-2 is in effect, how did things change? Unfortunately, nothing much changed as of now. Companies are still behind, while they could have used this opportunity to their own benefit. I love how he concluded that cyber resilience is not created by paper but by empowered companies and active synergies.
  • "The Illusion of Finishability" by Juliane Reimann. This talk was my absolute highlight of the conference. Juliane taught us what's behind our human need for closure, and how people experience this need very differently. Some yearn for closure, others try to avoid closure for as long as possible. This alone explains so much of what I experience every day interacting with various people and also when observing very distinct decision cultures within different teams and companies! Juliane of course also tied this to what we see in security, from statements to behavior and also systems we can use to meet our own needs for closure in a healthy way. 
  • "Keynote: Who comes next?" by Brian Hein and Constantin Jacob. This talk looked at how the threat intelligence community handled things in the past, building tight networks based on the iron principle of KMT: know you, met you, trust you. The problem is, this doesn't fit anymore to today's world of communication and we're loosing the next generation. We need to put in intentional effort to include and grow the next ones after us - and that applies to any community beyond threat intelligence. 

By the way, all of these talks had been recorded and will at some point be published by Elbsides, so that's going to be your chance to check them out yourself. 

The conference closed with a dedicated space for socializing with the community. Afterwards, it was time for speakers dinner. The organizers kindly invited us to really nice food and drinks together in a relaxed atmosphere. It was a great evening among great people, sharing experiences when working in teams but also with many other teams, how to truly help others and make an impact, learning more about wind energy and what's needed to build and maintain these farms, and much more. What a great closure to a great conference.

I went home with my heart full, new connections in my network, ideas sparking. What else can I want from a conference. If you have a chance to join a future Elbsides, seize that opportunity! You won't regret it.

Tuesday, May 19, 2026

BSides Luxembourg 2026 - True Community Spirit

With BSides Luxembourg, my conference year 2026 officially started. And what a kickoff it was! What an inspiringly insightful, community connecting event. We've built fond memories together and this instance will most definitely not be my last one.

Speaking in Luxembourg, how come? Well, it all started with a sketchnote. As usual during on-site conferences, I also took sketchnotes at BSides Munich 2025 and published them on Mastodon. One of the organizers of BSides Luxembourg, Claus Cramon Houmann, saw them and expressed his wish to see me at their event. That brought it to my attention in the first place. I checked out their website and things looked really intriguing!

As I try to get to conferences mostly by speaking, I checked out their call for papers. To my pleasant surprise, they offered financial support to reimburse costs occurring with speaking, aka travel and accommodation (mind me, I'm not speaking of a honorarium here). That's the normal bar I have for conferences, and I'm used to expect this from the many tech events I've been to. Sadly, this doesn't seem to be as common for cybersecurity conferences. Usually, I don't submit without that offer as I’m paying out of my own pocket otherwise – and many underrepresented folks have way less privilege than I have. Hence financial support is a green flag I’m actively looking for, indicating that the conference cares about inclusion and diversity. [Side note: That being said, I do understand that some community-driven non-profit conferences really cannot afford offering financial support (yet). I also am willing to meet them where they are - yet I can only support so many community conferences a year this way. Also, just inquiring about reimbursement often reveals a lot about where the organizers currently are, so I can make a way better informed decision for myself whether I'd like to continue with them or not.]

Back to BSides Luxembourg. I decided to go for it and hope for the best. For real, I caught myself time and time again the last months, hoping that I would get accepted - I had a feeling this would be awesome, and I really, really wanted to get in. The first round of speakers were revealed - I was not among them. I continued to hope. Then the email arrived - clarifying what financial support I would need! If they could make this happen, I would be in. I honestly loved this transparency from the start, as it made me trust this would be good for real.

Well, as you can see, I made the program indeed. My latest workshop and a brand-new talk got accepted. We also agreed that an older talk would serve as backup talk in case any speaker won't be able to make it. You can't imagine just how happy I was! Until I realized how close it was to the conference already. That was beginning of March. The conference took place beginning of May. I just agreed to a brand-new talk. Aaaaahhhh!!! This was cutting it awfully close to my taste. Especially given I knew what else was happening during these two months. Then I learned that even more and more had to happen during these exact two months as well. Literally everything all at once at the same time. Two travels, creating yet another brand-new conference talk with a dear co-speaker (and figuring out what works for us doing so), editing the latest novel of my best friend, preparing for all other upcoming conferences with due dates, oh and I also happen to co-organize my own conference, right? Of course we had certain immovable due dates during this exact time frame. All of this costing enormous amounts of hours and hours and hours.

What an absolutely stressful time. I knew it would be worth it, it was worth it, and yet. I cut and canceled everything I could (okay, not as ruthlessly as I would have loved to due to my inner people pleaser, and yet as much as I could possibly do). I halted my personal challenge. Friends and family didn't really see me during this time. The only thing I did not cut was movement - I even increased it because it was a one-time-too-good-to-possibly-true offer. I also didn't want to repeat my mistake to cut on exercise as I did the last years - and I had dearly paid for it as this resulted in losing range of movement, strength and general quality of life. I had just reclaimed some very basic capabilities I would not give up again anytime soon.

All in all, this was such a close call. Massive kudos to the folks who joined the dry run of my new talk, giving me just the constructive and tangible feedback I needed, allowing me to revise it heavily and cut it to the first version it had to become. Everything was close-knit to the very last moment, even finishing last tasks on my travel to Luxembourg. Anyone who knows me for a while, knows that this is absolutely not me. I'm the over-preparer par excellence, and while I've gotten pretty good at keeping things "good enough", this was unheard of. But hey, I made it. Still wonder how, but I made it.

Alright, fast forward to the conference! Here's how it went.

 

Arrival Day

My travel required to change trains several times - and to my pleasant surprise, it worked out. I arrived well in time to do another dry run of my brand-new talk and also prepare last things for my workshop. Most speakers had come together in a Signal group which made it easy to find a bunch of folks to go to dinner with together. I make use of such opportunities whenever I can as they allow getting to know a few people in a smaller setting before the conference starts.

Putting faces to names or aliases from the chat was great. I even uncovered I've already met one of the speakers already back at New Crafts 2024! The tech world is small, the conference speaker world even smaller. We enjoyed a lovely dinner and conversations on all kinds of topics together before it was time to prep for the next day.

 

Workshop Day

My own workshop "Secure Development Lifecycle Applied - How to Make Things a Bit More Secure than Yesterday Every Day" was scheduled for the morning just before lunch. We had a nice group of folks from all kinds of backgrounds coming together to learn and practice. The session worked out pretty well and my duty was done for the day! Things were off to a good start.

The lunch break was decently long to enjoy the food, have conversations with participants and also get some rest before the afternoon. I've decided to join "How to Read Code to Find Vulnerabilities" by Louis Nyffenegger. I was curious about this workshop due to a few reasons. First, I've been part of a code reading club a while ago, actively practicing techniques to understand code snippets and exchanging insights. Second, reading code was a big part of my previous role as a quality engineer, and still is as security engineer, with the specific focus on security. Third, I was keen on learning how Louis teaches code reading, as this is a topic I want to share further myself, and also given he's the founder of PentesterLab and I liked their style of conveying knowledge and skills. Long story short, it's been a really interesting workshop indeed! He shared a bunch of advice on what to look for when reading code and how to train this skill. We ran lots of exercises together on finding flaws in various code snippets, dissecting what made these insecure and how to build things in a secure way. Both detection and also knowing how to do better is such a crucial skill to hone. As the cherry on the top, Louis gave away copies of his book "CVE Archeologist's Field Guide: Methodology and lessons from 10 vulnerability analyses" - so much appreciated!

Right afterwards, I managed to get into the session "Dismantle The Bomb" by Stijn Tomme. This was designed as an escape game like scenario - and way too much fun to spoil what happened in this session! Let's just say: it's been the very first time I've seen a key being cut, a potato battery lighting up an LED, and cutting wires to deactivate the bomb. We had a really nice group to solve the riddles and puzzles together - teamwork for the win! Anyone having a chance to catch this session, go for it. We had a massively good time with this well-designed game, used our collective skills in new ways and came in touch with things that are not as common. Perfect for the afternoon - energy was really high afterwards.

Time for me to go back to the hotel and practice my talk for the last time, then head for the speakers dinner. The organizers were so kind to make this happen for us and we enjoyed lovely Vietnamese street food together - much appreciated! That kind of opportunity is usually great to connect with other speakers, learn about their passion topics and values, and just have a good time. As usual, we also discovered a few first-time speakers among us and shared experiences; we're all in the same boat and new folks are very welcome to realize they are not alone with struggles like last-minute preparations, coping with nervousness, and more. It was a great evening and things were ready for the conference days.

 

Conference Day 1

If you had seen the program for this conference, you probably understood my massive struggle to decide which sessions to attend live. There were the main conference tracks, as well as an AI village, a detection engineering village, a lockpicking village and a car hacking village. So many amazing sessions to choose from! In addition, talks were hosted across not only one building, but two - without many breaks in between to get from A to B, which really made a difference in my choices. Fortunately, most talks had been recorded and I will still have a chance to catch up. Some talks, however, were not recorded, so I tried to prefer them where I could. Also, as usual at on-site conferences (as shared already above), I did sketchnotes for almost all talks I attended.

  • "Things Fall Apart: Allying Cybersecurity and Diplomacy against Authoritarian Disorder" by Luc Dockendorf. I was a bit late for this opening talk by Luxembourg's Cybersecurity and Digitalisation Ambassador, so I chose not to sketchnote it. I did, however, really appreciate the clarity in addressing the current planetary, geo-political and social challenges we face. What a strong opener for the conference!
  • Keynote: "Identity Security Just Exploded" by Wendy Nather. Wendy presented what makes identities for authentication such a challenge, back in the days, and especially nowadays given AI agents. Lots of problems that never got solved (like delegation) are multiplying now. What we can do right now is to make sure our fundamentals are covered. 
  • "What Does Threat Modeling Solve for AI Security?" by Nathan Pembe. Nathan made a great point how threat modeling can not only help to make pentesting efforts a lot more targeted, it also helps fill the gaps to implement security controls for audits in the age of AI. I really appreciated his down-to-earth call to focus on realistically reachable attack paths and separate those from noise.
  • "Beyond the Prompt: A Framework for Agentic AI Attack and Defense Strategies" by Jeremy Snyder. Jeremy walked us through the major risks that AI agents introduce. It's not only about the agent itself or the model used, but we need to consider the whole architecture including interfaces to retrieve incoming data as well as the output created. This talk was full of awesome questions to ask!
  • "Cloud Misconfigurations: Poke Poke, Breach" by Kat Fitzgerald. This was a talk that was not recorded - hence I asked Kat afterwards if she consented to me publishing my sketchnote of her talk. Fortunately, she agreed! This was a really cool talk about how misconfigurations just keep coming and showing up in various (way too known) shapes and forms. All the classics included. The solution: policy as code to provide safe guardrails! No chasing, instant feedback, actual clarity.
  • "Managing Uninvited Guests: Securing Open Source Dependencies" by Frithjof Hoffmann. Originally, this talk was meant to be given together with Kadi McKean who unfortunately couldn't make it. This was an ever-green reminder to evaluate which dependencies we really want to build on and which ones to keep out. SBOMs can help find vulnerable packages, while we also need to acknowledge that scans can be flawed. 
  • "Out of Security Exception - What to Do Without an Expert to Secure Your Software" by me. This was the premiere for my brand-new talk. For anyone who missed it, it was recorded so you can still check it out once it's published. Unfortunately, there was no immediate feedback feasible as the next talk started right after mine. Yet all in all, I'm quite content with how it went and people seemed happy enough as well. 
  • "The Forgotten Fingerprint: DNS Based OSINT Techniques for Product & Service Discovery" by Rishi. This talk looked at TXT records in specifics and how they could be used in threat hunting and hence accelerate incident response. Rishi demonstrated both OWASP Amass and Nuclei as two of the main tools you can use to start your discovery today. 
  • "Turnkey Code – Enhancing Secrets Management in Large Scale Organizations" by Diogo Lemos. Diogo presented an interesting case study of what they learned when building a proper secrets management platform. They needed to control the noise and consider the whole lifecycle - including rescanning safely without overwriting human triaging decisions. 

That was the last session for the day. Participants gathered, enjoyed good food and conversations together, sharing their insights of the day with each other. Then it was time for "Security Impress Karaoke" hosted by Kirils Solovjovs. Basically PowerPoint Karaoke but using OpenOffice Impress, with slides sourced from Cybersecurity talks. Lots of folks accepted the challenge to present random slides thrown together and combine them in a way that's concise and hilarious at the same time! Good fun.

 

Conference Day 2

The final conference day started tired and early, as it's usually the case for me the longer a conference goes. And yet, I wouldn't miss it and didn't regret it one bit.

  • "The High-Performance Fuel for Social Engineering (Now in AI Flavors!)" by Glen Sorensen. Glen showcased how much data companies are collecting about us. They claim to have legitimate interest, yet do they really? What's considered justified, by whom? The problem here is that all this data is used for highly effective social engineering attacks. Having LLMs at hand, this danger became even more imminent. Glen shared lots of things we can do to reduce our own attack surface.
  • "Spyware: The Invisible Threat" by Julien vander Straeten. Really interesting talk on spyware as a specific type of malware. Its goal is to persist on the device, deep in the lower layers, and exfiltrate all kinds of data. Lots of countries buy spyware, including 14 EU countries - and quite a few of those also produce their own. Spyware is expensive, though, so attacks are highly targeted.
  • "Confound and Delay: Honeypot Chronicles from the Digital Battlefield" by Kat Fitzgerald. Yet another talk by Kat that was not recorded - so once again I asked her if I could publish my sketchnote, and luckily, she gave her okay for this one as well. This was a really cool talk on what you can learn through deception, offering attackers a realistic enough trap to observe their behavior. What they try to do. Including hilarious attempts! Honeypots can not only reveal how attackers operate but also predict production threats. 
  • Lightning talk "Good things can happen at conferences" by me. Well. This was not planned at all! Hence there's no proper abstract either. Here's the background story: On the workshop day, I shared with Claus as organizer of BSides Luxembourg that I am co-organizing the Open Security Conference (short osco). He instantly offered us their partnership - something I was just about to ask them as well. Super cool and kind! And then he shared there might be still a lightning talk slot available and asked whether I'd like to share a bit about osco. I usually don't do lightning talks at all, yet this one I felt would be feasible - it's pretty easy to talk about my own conference after all, I've done that plenty of times already. I kept this option in mind and inquired the next day whether the slot would still be free. Organizers shared it wasn't clear yet until the following day, but at best I would be ready for it. So at midnight I sat down and drafted a script. I knew I could just do a shameless plug - yet I wanted to give people more of a real message than just the mere promotion of our event. So I thought, what if I told the story how osco came to be? In general, how good things happened at conferences? I would have had plenty of examples on that matter, yet I decided to focus on three events. One, conceptualizing osco at SoCraTes 2023. Two, meeting my now manager at the first osco edition and only weeks after getting hired by him. Third, our freshly made partnership at BSides Luxembourg. Now I had my script ready to go. The last conference day came, and during the lunch break just before the lightning talks, I asked again if that slot would still be free. It was indeed! Just 15 minutes before the talks started, mine was added to the program. Then I realized, everyone else had slides - I had planned to just tell my story. But one supportive slide would be great indeed as a visual support. So I put our logo on one slide. A QR code next to it. That would do. Finished just a minute before going on stage! My whole speaking experience paid off in that moment. I went on stage and told my story. I made it. Later people came to me to tell me how much they loved the idea of osco and how good this talk was. For me as a recovering perfectionist and over-preparer, this whole feat was a real achievement unlocked! It seems I hit a note there. I'm already very curious if I'll ever learn what people took with them in the end. But well. Here's the script as I prepared it, and only slightly adapted when telling the story live.
    This is a true story on how good things can happen at conferences. 

    The year is 2023. I'm not yet working in security. I'm part of an engineering team, building products hands-on together. 

    I'm at a tech conference, called SoCraTes. It's a special kind of conference, as its program gets created right at the beginning of the conference - by the participants. The format is called an open space. It's designed in a way that everyone can contribute and everyone can learn in the ways they want at that moment in time, about the topics they want to learn about at that moment in time.

    So I'm at that open space conference, where I get to have a say on the program. I have a clear focus topic: I want to learn more about application security. Oh cool, there's a person who works in security and is also curious to learn more from other participants. His name is Claudius.

    Claudius and I, we agree to host a session together on usable security. Lots of folks join our session and we learn from each other. It's energizing. Claudius and I find we work well together, so we decide to host a workshop. Another success! Inspiring.

    We sit at lunch, and Claudius shares his idea with me: he wants to start a new conference. A security one. In the open space format. He feels that that's currently missing in the security community. I was hooked! And I added: Yes, a community-driven, non-profit conference - for everyone interested in cybersecurity, no matter their current roles or skills. Breaking down barriers and gatekeeping. I believe we all can learn from each other. 

    The idea of osco was born - the Open Security Conference. 

    We find further co-organizers on our journey. We find participants who love the idea. The idea becomes reality.

    Good things can happen at conferences.

    The year is 2024. We have the first edition of osco. Small. People love it. Many will return the following year. 

    And I? I also enjoy our conference. I'm sitting at dinner next to Rudi, who talks about his security team at his company. It sounds like a good place. Little do I know that I'm sitting next to my now manager, just 3 weeks before I will get laid off from my former company. Yes, I co-organized a conference and I got a job thanks to it. In application security. 

    Good things can happen at conferences.

    Fast forward to 2026. Our organizer team is preparing to host the third edition of osco on November 5th to 8th, in Germany, close to Frankfurt am Main.

    I'm here, at BSides Luxembourg. I talk with Claus and the other organizers. I share about osco - and our two conferences partner up. 

    Good things can happen at conferences.

    If an opportunity presents itself to you, seize it. It might come with the person right next to you, at lunch or dinner. Look out for them. 

    And if you're curious to learn more about the Open Security Conference? Come to me, get a postcard to spread the word, and become part of our story.

    Good things can happen at conferences - and beyond. 

    Thank you. 
  • "Building Secure AI: Making Threat Modeling a Core Part of Development" Diana Waithanji. This talk was the perfect closure to the conference for me! Diana explained her approach to threat modeling, where I just sat and kept nodding along. Like that there's no one way to do threat modeling. Diana showcased how frameworks like STRIDE are still applicable when it comes to threat modeling AI systems - as one of many possible ways. She involved the audience actively and we heard from several people what they do and how it works for them. She also emphasized the importance of fostering good relationships with engineering teams, involving the whole team and collaborating across roles, as well as making threat modeling sessions high-energy and inclusive. So much this! Diana's talk highly resonated with my own experience. 

And that was it. Originally, I had planned my last conference afternoon differently beforehand, with more talks - yet things came different than expected. First with me joining the lightning talks at last notice, and then with me standing by to give my backup talk, as pre-agreed with organizers. In the end, I didn't have to give it, and I used that unexpected time as a lovely chance to catch up with Marina Stephanova, one of the organizers, instead.

Right after the conference ended, there was yet another neat opportunity: Marina invited interested speakers to go sightseeing together and showing us around Luxembourg city! An offer way too good to refuse for sure. We had a lovely group of around 15 people, the weather was perfect, and we enjoyed a nice tour together while learning about Luxembourg's history and people. Afterwards, we had a great dinner together. Once we headed back to the hotel, how could it be differently, the last core of us ended up in the hotel lobby. Just really good company (thanks to Ellis Stannard and Leonardo Wolff Takemasa Fernandes!), deep conversations in the middle of the night (extra special thanks to Diana Waithanji and Sonia Seddiki!), while tasting fiery hot snacks from India (huge shout-out to db here!). What could be better. 

 

Returning Home

The next day it was time to depart, saying thank you to everyone one more time, and take my memories with me. I realized how tired I was, and while that made it a more complicated ride home than it would have needed to be, I did arrive safely and roughly in time.

My heart was full and brimming of the community spirit I just experienced. Lots of folks I met for the first time where it was just easy to connect with each other. Some people I even met the second time; the world is small! What a pleasant surprise. And not to forget all the care that organizers put into all the little details, always ready to help out and solve things or make them at least better, always appreciative of feedback. Special kudos to the team for making this whole event such a welcoming and inclusive experience, I really felt that I belonged. Their choices how to craft this space for community showed in everything: representation among the speakers, reflected in the participants joining, the options in conference T-shirt fits and range of sizes, the food offer, the choice of language. Everything. It clearly showed their continuous intentional effort and it paid off. 

Looking back, this was such a good conference. The smooth organization, the speakers and participants from all kinds of backgrounds, the variety of super interesting topics, the space to connect with each other and stay connected. Can only recommend you checking this one out next year! It won't be my last BSides Luxembourg for sure. I'll cherish the memories we've made together and the kind feedback this community provided.