Saturday, October 10, 2026

HUSTEF 2026 - Finally Made It

HUSTEF was on my list of conferences to go to for quite a long time. Lots of people raved about it and I was curious to experience it for myself. This year, I finally made it there!

It all started with getting invited to the review board, helping out with evaluating proposals so that the program committee could make an informed decision. So I thought, why not submitting sessions myself and see if I'd also get a chance to speak? And it worked! I consider myself fortunate to have been selected among the many papers submitted.

Time flew by this year, and now it was time to travel to the beautiful city of Budapest. A long but comfortable train ride, some time to settle down and rest at the hotel, then I met Micha Kutz for dinner. Always nice to catch up with long-time friends from the community! 

Tutorial Day

The first day was reserved for full-day and half-day tutorials. I gave my workshop "Secure Development Lifecycle Applied – How to Make Things a Bit More Secure than Yesterday Every Day" as a half-day tutorial at one of the sponsoring companies who kindly provided their office space for it.

I've given this workshop plenty of times already and it's always super interesting to see different kinds of groups engage with the material in their own way, based on their own experience. I'm also very happy to see that the concept does work out with most folks, coming from very different backgrounds! This time I had mostly people working in testing and quality roles as they are the main audience for HUSTEF. I really enjoyed seeing them work through the exercises, ask questions, share their own related stories, and generally having fun doing so.

And then a truly special thing happened. The tutorial was over - yet participants didn't leave. They stuck around. They waited for each other having a bio break, they kept talking. They all left the location together, heading back to the city center, planning to have lunch together - and invited me in! That was too good an opportunity to decline, no matter how tired I was or what else I needed to tackle in the afternoon. We had a lovely lunch together, sharing even more experiences - what could be a better start for the conference?

At some point, I needed to head back to the hotel and do final preparations for the next day. Then it was time for speakers dinner. I met Sonja Nešić on the way to the restaurant, a lovely chance to catch up with each other. The dinner place was literally on a boat, yet I got lucky that it was firmly anchored and did not move in any perceivable way. I already had the experience of having speakers dinner on a boat in the past and I can only tell you it's not a great idea if you have motion sickness. The place's acoustics unfortunately couldn't handle the noise well and I struggled a lot with processing my environment, barely hearing what people said and straining my voice to make myself heard. On the bright side, the food was excellent and I had really great company. For example, I just loved catching up with Clare Norman and Jitesh Gosai, talking about light and deep topics, and finding out that all three of us are scripting our talks. I'm in good company!

Conference Day 1

The first conferencing day arrived and it was packed with amazing talks - it was a true challenge to pick which sessions to witness live. Also, I had to skip two slots in order to be ready for my own talk and then catch my breath right after. It was a pity to miss Nicole van der Hoeven's keynote "Asimov’s Zeroth Law of Robotics: Observability for AI" this way, I was really looking forward to it. Also, I would have loved to see Micha Kutz's talk "WTFM: Where’s the F****** Manual⁈ – Why we avoid writing documentation, why we shouldn’t, and how to keep it useful with minimal pain". Good thing the talks were recorded and I can catch those I missed later on - even though it's never the same as experiencing them live on-site.

  • Keynote "Beyond Vibe Coding: What It Actually Takes to Build with AI and Stay Accountable" by Kristoffer Nordström. Well, AI tooling usage can found around many corners these days. Yet what does it really take to get good value from it, how to build software with these tools and still know exactly what you're doing and especially why? Kristoffer shared his story and what he found made the difference. I really liked the following of his takes: When building becomes cheap, we need judgment in the room. 
  • "The art of getting out of the way: Facilitation for quality professionals" by Clare Norman. Loved that Clare shared her insights on such an underrepresented and yet so crucial topic. Lots of invaluable advice, brilliant presentation! I especially loved her emphasis that facilitation is all about listening and supporting everyone in the group in doing their best thinking together - and that includes generosity and fairness. 
  • "The Rubber Duck that talks back" by Benjamin Bischoff. Benjamin pointed out that we had hype cycles before AI tooling, like search. And all the shortcomings that come with new technology, hyped or not. He also shone a light on how we can use our skepticism for good. Benjamin encouraged us to make use of our brains, apply discipline and differentiate unnecessary from necessary friction. 
  • "AI applications security puzzle" by Maryia Tuleika. Maryia told a story on how security concerns evolved over the years, while some are still remaining alike. Especially for current AI tooling, how do we secure them? She points out that we should rather focus on the system and constrain the tools we have at that level. I really liked her take: "Don't ask only whether you can trust AI - build and test for the moment you can't." Maryia based her talk on detailed research in the space, gathering insights from the community - worth a read, and I'm honored to be among the people she consulted. 
  • "Out of Security Exception – What to Do Without an Expert to Secure Your Software" by me. I presented what engineering teams can do themselves to improve their product's security posture without having a security expert at hand. I've given this talk already at BSides Luxembourg this year, yet in a longer and more detailed form. This time I needed to cut it down to the essentials to fit the time slot. It seems the message came across nonetheless!
  • "How quality is created, maintained and lost in complex software systems" by Jitesh Gosai. I've seen Jit present many years ago and was already back then impressed by both his presentation skills and by how much his point of view overlaps with mine. His talks and thoughts just resonate a lot with me, so I had to check out this one as well. He walked us through the famous CrowdStrike outage that made the world stop turning for a bit, and what we can learn from it. It was a great reminder that complex failures never have a single root cause and they require us to acknowledge and improve the socio-technical system. 
  • Keynote "Could Personas Be Your Insight Superpower?" by Steve Watson. Are personas still relevant or needed in the age of fancy AI tooling? Steve says yes, and I agree. He presented how we can use them in a meaningful way and demonstrated the pitfalls when creating actually insightful personas without missing out on what's relevant for our target user group. As he shared, the risks are in the gap between our assumptions and our users' reality. 

I truly appreciate the lunch breaks were decently long to get some rest and also socialize. I had the chance to briefly speak with Vitaly Sharovatov - always a pleasure, ever since we met at NewCrafts Paris 2024. Same with Sérgio Freire and Mazin Inaad! Would have loved to catch up more with each of them.

What I thoroughly enjoyed was the opportunity to have a quiet and relaxed dinner with Heather Reid, Léna Nyström and Rachel Kibler. We had discovered the perfect place for it as well, with delicious food, calm atmosphere and awesome service. For me it was an utterly needed chance to take a break for a little while before the pressure will be on again the next weeks.

Conference Day 2

The final conference day came with yet another bunch of awesome talks.

  • Lean Coffee with Gáspár Nagy. I thoroughly enjoy lean coffee sessions, and yet I did not plan to join this one. That being said, I had arrived early enough at the venue, so I decided to just join in. We had insightful conversations on the usage of AI for slides, how spending money on tokens that goes to foreign companies destroys our local economies, how everyone turning into a vibe coder and wanting to bring their projects into production causes a huge problem and how to navigate it.
  • Keynote "Now You See Me" by Heather Reid. What can I say. Awesome content, awesome delivery. More people need to hear this. Heather talked about what makes upper leadership not see what people achieved, while they themselves feel it's clearly there to see. Perspectives matter and we all only have our own viewpoint available. Making things visible in ways that allow others to see things is crucial for any career - no matter if you have a leadership title or not. 
  • "'As is' is not a requirement – it’s failure in a fancy suit" by Léna Nyström. I loved how Léna walked us through three cases in her career where it seemed people wanted a copy of what's been built before. Yet is it ever a true copy? Of course not. It needs to be modern. Some things aren't relevant anymore. No one has the complete picture. Did anyone even ask what's actually needed or what wasn't working well with the old solution? We should listen to this signal of "It should work as is" and find out what questions are unasked. 
  • "Looks Perfect. Runs Fine. Completely Wrong. A Live Hunt." by Christine Pinto. Christine took us on the investigation of an incident where all things came together so that a bunch of AI tools enabled attackers to exfiltrate data and demand ransom from a company. Based on the audience response it seems the message landed - supply chain attacks using AI tooling are way too common these days to stay inactive. 
  • "Quality Signals on Pull Requests: How We Stopped Shipping Bugs Without Slowing Delivery" by Marco Andrade. Marco shared an all too well-known story of flaky end-to-end tests. He pointed out what the underlying issues were and what steps they took to make sure they got actual feedback and hence value from these tests. Marco warned people not to become the gatekeeper and scapegoat but have teams trust their pipelines. 
  • Keynote "You’re not really ready for AI (but testing can help)" by Callum Akehurst-Ryan. I really appreciate that Callum shared his personal story and showed vulnerability on stage - we need to see more of such good examples. These are the cases we all can learn the most from. Callum shared how much AI amplified all the dysfunctions that already existed before in the teams and how that ended up badly for his organization and him personally. He emphasized that we can't just demand attention from people who don't have capacity to listen. We have to roll up our sleeves, make things better ourselves, and hence become part of the solution. 
  • "The Tale of Two Pipelines: Why Your CI/CD Can’t Fix Cultural Debt" by Chris Armstrong. Technical debt oftentimes isn't technical at all. It's rooted in a lot of other types of debt, deeply human ones. Chris presented how it doesn't matter if your engineered delivery pipeline is fast if your team can't actually get things through due to other types of debt. He also showed how such debt can look like and what to do about it. The core: optimize for flow. 
  • "When Your AI Testing Partner Lies to Your Face: Detecting and Defeating Completion Theater" by Dragan Spiridonov. Dragan addressed how AI tooling can claim to offer confidence, yet there's either no evidence for it or the evidence indicates a different situation. He shared how you can spot this and what to do instead not to let ourselves be swayed by AI. Now, Dragan didn't only give this talk, but also a full-day tutorial and a masterclass. People clearly appreciated what he shared, in the end he won the conference's best presentation award! Check out his experience report on the conference as well. 
  • "The Quality Nervous System" by Kevin Pyles. Kevin presented a different approach to solve the overwhelm of too much data, getting flooded while still not knowing whether you can release a new software increment. He compared it to the human nervous system which also has to deal with huge amounts of data points and signals and transform them into meaningful output at scale. He also demonstrated how quality as a living capability could look like. 
  • Keynote "Rethinking the Automation in Testing Principles" by Richard Bradshaw. Richard looked back 10 years ago when he and Mark Winteringham came up with a set of principles to achieve more effective testing through the help of automation. He contrasted them with today's world, presented revisions made and why (check out the reasoning in Richard's own words). The principles in their new form are staying relevant and keep serving as an invaluable tool to use our thinking skills and help make better software - focusing on intent and judgment. "If you can't answer why something exists or should exist, change it." Hear, hear! 

Conferences have a way to start slowly, make you forget how time flies by, and suddenly they're over. That's what happened here as well. Good thing we could prolong the community spirit for a while on the last evening. I joined a great dinner initiated by Kristoffer Nordström, with Cassandra H. Leung, Chris Armstrong, Marta Firlej, Mateusz Holewski and Richard Bradshaw. Later on, we were joined by Alex Cusmaru, Jamina Pöllänen and Gek Yeo. We moved on to a bar and stayed until it closed - it was finally time to end the evening. What can I say. Amazing food, amazing company. The best part of every conference. Thanks everyone for making this such a perfect end for my first HUSTEF!

Well, it wasn't quite over for me yet. I still had one day in Budapest. My chance to sleep in, go for a walk, do a bit of sightseeing. Truly ending the conference with another great dinner and conversation together with Jamina Pöllänen. Time to go home, time to share my experiences. Thank you everyone who made this conference a pleasure to be at!

Saturday, September 5, 2026

SoCraTes 2026 - Managing Energy

It's been my fifth time at SoCraTes Germany this year. It felt like diving into a familiar place where I can experience a proper timeout from everything for a few days, and soak up one variation of how "good" can look like. By far not perfect or without potential for improvement, but truly good. Being there the fifth time, with my communities from various conferences and tech areas overlapping more and more, also meant that I met a lot of wonderful people again that I just enjoy spending time with, be it in deep conversations, sharing our passions, or spending our time on the silliest fun activities. The great thing about SoCraTes is that the organizers intentionally craft the space, so I won't only meet people who I've grown close to, but every year I'm getting to know lots of amazing people I haven't met before. I truly enjoy making new connections. The sad thing is, that I will never be able to do any of my connections justice in how I choose to spend time with them. I'm grateful nonetheless for all of you.

 

Arrival Day 

This year was truly exhausting so far. Which meant that I couldn't start into SoCraTes well rested with my energy levels fully charged - they were rather in the lower parts already. Not a great idea in hindsight, but hey, you have what you have and you choose how to work with that. The travel day went well, I had plenty of time catching up with Martin Schmidt during the train ride, and enjoyed meeting a few first people when arriving at the venue.

The evening was calm, with great conversations at our dinner table about organizing conferences, the conference I co-organize, company culture and what it means for people wanting to go to conferences. Yep, there was a pattern for sure! The evening went longer, topics changed, I could catch up with a few people and then it was time to rest in preparation for the next day.

 

Training Day

This year, Juke Trabold was the facilitator for the conference. I was truly happy to see them again in this role, as for me, Juke is one of the most skilled, considerate, thoughtful and kind persons, facilitators and moderators I know of. They set the space for all of us from the start in a manner that resonated throughout the event.

During the opening, I met Daniel Steinhauer in person again, a former colleague, dear friend and conference co-organizer fellow. It's been his first SoCraTes and I'm still super happy he trusted my (and other folks') recommendation to experience it for himself.

The training day offered less sessions than the last years, and it was still hard for people to make a choice. For me the decision was fortunately straightforward, so one thing less I needed to spend energy on. Another change was that the first training was twice as long as the second slot, an interesting experiment. It worked out for me this year.

For the first session, it was instantly clear to me that I would join Gitte Klitgaard's training "Psychological Safety Awareness" as soon as I read she's going to give a session. I've had the honor to witness her talks and workshops in the past and speak with her personally many times. Every time I'm going to Gitte's workshops I'm gaining new insights about the topic and myself. Even when doing a workshop I've been to already in the past, like this one. It's worth it every single time. Invaluable. This training was once again bringing different aspects to my attention. Gems like: "If you are not failing, it's either not challenging enough or you're not safe enough." or "You can't just follow a guideline to create a safe environment as it's about the fear we have inside." Also on the facilitation of the session itself, like "Ask people to pass explicitly so they used their voice on the room, so it's easier to use it again." or "One reason I sit down here is not to be the teacher, you're not reporting to me." I also made new realizations about myself - which doesn't often happen in training settings. With Gitte, they just show up. She's setting the space in a way that allows that to happen for me. Anyways, I cannot share much deeper insights here as the training rule rightfully was that nothing leaves the room. I can say, however, that I really appreciate my fellow training participants for sharing so openly with each other, giving each other the room to do so as well, and practicing listening to each other.

For the second training I chose Diana Montalion's "From Feature Factory To Forge". I only witnessed Diana on stage before and was curious how her energy would show up in a hands-on session. It did show a lot and I loved it! Perfect for this late afternoon session. Also, I was pleasantly surprised to see Sofia Katsaouni co-facilitating the session, adding another angle on the topic and leading by example with her human skills. What both of them offered us was a fun group exercise in multiple evolutionary steps. We had to design a movie review themed system. Decide what are the core concepts for it. Have another group provide us definitions for those concepts without interaction, so there were plenty of surprises to deal with! We defined our core capabilities. We had the system challenged by people from other groups. We could evolve it further in short time. Our group even checked if the domain name we had in mind was still available! A key phrase that stuck with me was "Agreement on words is not the same as agreement on meaning." Oh my, we've all been through that. Besides that, I really enjoyed Diana's references to improv theater (I really like the "yes, and" to build on each others' ideas). A fun surprise was the mention of "No Vehicles In The Park", a super fun exercise I had the pleasure to have Elizabeth Zagroba facilitate. Best thing: She was at the conference as well and obviously now had to run this session there, too! I heard people loved it just as much as I did a few years back. She's the best in doing these sessions - not only these sessions, obviously, yet they are a true highlight. If you ever have the opportunity, join and witness your brain be tied up in knots (in the best way possible)!

After the training sessions, I met plenty of folks again and then settled for a calm dinner with Elizabeth Zagroba and Joep Schuurkes to catch up a bit with each other. Then it was time for wold café already, where we ran three rounds of finding a random table, sitting down with a bunch of people, and connecting with each other over a few guided questions. Always a nice start to the main part of the conference and I'm usually getting to know new people this way! Just like this time as well. The evening went on, I dove into a deep and long conversation to catch up with Gitte, and suddenly it was again time to go to bed.

 

Open Space Day 1

Juke introduced everyone to the concept of an open space, then the first marketplace of ideas opened. SoCraTes Germany is the largest open space conference I know of, and this year they probably had a new record with way over 200 people joining. It can really be daunting to pitch a raw idea in front of such a big crowd, let alone wait for this pitch while standing in the very long queue, trying to listen to the current presenter. I'm truly glad this wasn't my first time speaking at conferences, and not my first time at SoCraTes. I'm always in awe how many new people and also youngsters dare to do so! That's one of the very special parts of this conference. It's scary, and at the same time many people feel safe to do it nonetheless.

As usual at open space conferences, I make myself a plan which sessions I want to go to - and then things happen differently. Just like this time, when during the first session slot I met Susanne Neunes in the hallway and we basically opened our own session, talking about the Open Security Conference, organizing, ideas, and a lot more. 

  • "Threat Modeling" by Martin Schmidt. I knew Martin had revised his talk and wanted to do either a dry run or have a conversation about the topic. I was curious to hear the talk, learn how he presents the topic to the audience, and what worked for them. It was great to see people interested in this, the following conversation and knowledge exchange was great as well. A core message: "Just start. Better do something than do nothing." I can't agree more!
  • "All time favorite computer games" by me. At open space conferences, plenty of people host sessions on all kinds of passions, hobbies and more. I had never proposed a session on a non-tech topic before, yet this year I thought, why not? The year was so stressful and I should focus on some pure fun topics anyways. So I pitched it as a lunch session and was pleasantly surprised seeing lots of folks already at the table, eager to share their most favorite games. And we did! You could literally see the people's eyes light up when talking about their highlights. Together, we came up with a really nice list of amazing games to enjoy. This didn't only give energy in the moment, it was a great idea in hindsight as it grew beyond the event. We now have a SoCraTes games channel on Discord and even our own private Steam group (many thanks to Frank Sons for making all of this happen!). Super cool to see what comes out of a simple idea.
  • "Supply chain security" by Bertram Vogel. I really appreciate people bringing security topics and raising awareness on certain risks. In this case, Bertram shared the specific supply chain risks for Node and npm. There's been plenty of examples in the last years for sure. He advocated for good options to offer further layers of defense to protect ourselves, while acknowledging that we always need more. I left the session a tad early to prepare for my own upcoming session, yet overall I felt he reached people to look into this topic further which is great for all of us.
  • "Capture the Flag Together (Beginners' Edition)" by me. Well, I know, it's not the first session I do to introduce people to security testing and witnessing how people can find and exploit vulnerabilities to see or do what they are not supposed to. And yet, these sessions are usually good fun. Seems there's also always people coming! This time again, I had a huge room, difficult to moderate yet it seems it went okay enough. Sadly, I already noticed during the session I was lacking energy to help steer this group in a better way. At least some folks did come back for more in the evenings. 
  • "OpSec" by Eric. This session sounded really interesting as it was focused on personal security which I really wanted to learn more about. But then I had to realize that my energy levels were super low, my brain too tired to focus on the session. So I had to leave early and found myself in the coffee corner just chatting a bit before the evening closing of the first set of sessions. Good time to write some kudos cards as well! Before I experienced this way of appreciating and recognizing someone else, I never understood the concept of physical kudos cards. Now I'm their biggest fan. There's just something special about receiving a written thank you, and even better: giving it to someone else and seeing their face light up.

Dinner time! This evening, I tried to catch up with as many dear community friends as possible, and it worked. Like with Thierry de Pauw and their two kids, and Marc Kalmes. I had a fabulous time at table 19 and I had the impression it worked out for the others just as well. 

Well. And then I continued my self-imposed, now well-established tradition to host an evening session: "Capture the Flag Together (Adventurer's Edition)". This time, I even had it start late to make more time to talk with people beforehand. And still, once again, so many people showed up, curious to explore and learn together. It was a really nice session, while it was also a very frustrating session as we didn't get the flag yet. When we realized it was late in the night already we agreed to tackle this again the next evening with a fresh perspective. 


Open Space Day 2

While the day before I had already realized I'm lacking energy, this day I couldn't deny it anymore. Usually, I manage to get myself out of bed for the second marketplace, even if just barely. This time I just couldn't. Good thing is I wanted to be easy on myself anyway and not propose a session during the day but rather join more from others. And then it happened again, the first time slot I ended up in an impromptu hallway track session. I just talked with folks and enjoying my time while allowing myself to start the day slower.

  • "Security card game" by Philipp Zug, Martin Schmidt and me. Oh right, didn't I say no session for me today? Well, no session to pitch today, as Philipp was so kind to take this over for us. And yet, of course I wanted to join our little group that bonded together a few years ago at SoCraTes 2023 and started building a security-themed game as a little relaxed side project. Every year since we hosted a playtest session at SoCraTes, so obviously we were eager to see how people interacted with the game in its current state. It didn't evolve as much as we planned to since last year, and yet there were some significant improvements. This time, it showed! For the very first time, people in the room really played the game as is. They chose a scenario to play. They went slowly, card by card, making thoughtful decisions together. They introduced a group voting. They pondered back and forth about potential outcomes of their decisions. It was such a joy to observe! Also, this group had wonderful feedback once again that will help us in the coming year to improve the game further. Definitely an energy-giving session.
  • "Photography" by Camille de Pauw. I love art. Especially visual art. Whenever I interact with art, it makes me connect with a part of myself that I don't often have the capacity to connect to and it re-energizes me. This session was just beautiful. Camille dared to showcase favorite pieces of a photography project she worked on, with the theme of feminism, capturing women resting in themselves and showcasing strength in doing what they're doing. Camille prepared the room in a way that when you entered the session, you instantly dove into a different world. Not the conference session you'd expect! Suddenly you're confronted and engaging with her pieces, alongside many others who do the same in their own way. Some people just looked intensely at the photos. Others discussed their origin and making. Some found details others missed. Some evaluated what they liked and what they would change. It was just beautiful. I admire Camille's courage to do this. For me, my heart and soul was full after this session and I really wouldn't have missed it. 
  • "How to delete stuff" by Elizabeth Zagroba. So many people joined to exchange their experiences on a very crucial topic that is far from easy but all of us face sooner or later: the topic on how to get rid of software. Features, services, you name it. Decommissioning and sunsetting things is hard. Deleting even lines of codes can be hard for people (personally, I usually really enjoy this). I loved how this session truly engaged people, how they listened to each other sharing advice and hardships, how we all took note on ideas that might help us delete more stuff that most definitely should be deleted. A few gems I took with me were "Get people moving, just moving alone helps", and the idea of ADRs as "Any decision record" to take away the pressure, make it everyone's job, be clear it doesn't have to be perfect and lower barrier. Ingenious.
  • "Cat Hicks' 'Psychology of software teams'" by Simon Görtzen. I've been following Cat Hicks for a while on social media and was inspired by many takes from her researcher point of view on software team dynamics. As soon as I heard she wrote a book, I had to get it. Well, I truly lack capacity this year and I have not read her book yet. Even better that Simon did and gave a session to review the core points as well as comment them with what parts resonated with him. Really insightful session that strengthened my resolution to read this book. A core topic here was the message to recognize "culture and psychological safety as core infrastructure of a learning organization". Hear, hear.

The open space was nearly over by now. We did a retrospective, gave further kudos cards, thanked the hotel staff and childcare folks. With that, the open space was officially closed by Juke. That didn't mean we couldn't propose evening sessions and also longer workshop slots for the next day. And even promote partner conferences, like, who would have guessed, the Open Security Conference that has its origin at SoCraTes 2023 as well. Super cool to have four organizers represented at SoCraTes this year.

Dinner time, conversation time, play time. Finally I had a chance to catch up a bit with Janina Nemec and play our traditional round of SET together. Time flew by and - guess what? - another round of "Capture the Flag Together (Eventually)" started. We continued on the same machine as the day before and hurray, we found the flag! It was fun and we all learned a bunch with this as well. The evening (shall I say night?) closed for me with yet another tradition: long nighttime walks together with Tobias Goeschel, talking about - well, everything. It's an honor, a pleasure, and not taken for granted we can do this, at least once a year.

 

Workshop Day

Last day of the conference, reserved for longer hands-on interactive sessions. I've joined a few of them in the last years, I've given my own workshops, or just gave myself more time to connect with folks. All of that has value. This time I tried again something new. Martin Schmidt and I had considered to propose a threat modeling workshop to conferences next year, so what better opportunity to try ourselves at SoCraTes to introduce people to the topic and give them first-hand experience? It really helped we had talked about the topic multiple times this year already. It also helped I had just been at his talk during the open space. For the workshop day, we had briefly aligned on what we intended to do. Yet the final concept? Due to so many things going on, we created it only half an hour before the workshop. Usually, that would be my horror scenario. Yet as we know each other well, we managed to quickly draft out the structure and exercises and we were indeed ready to go, and calm on top. Super grateful for Martin's trust! Both of us were happy to see all the people who showed up, we had way more participants than expected. We ran the workshop and we saw people were really engaged. They didn't only have fun, they also had insightful discussions and feedback in the end. I can't reveal too much here, yet it seems this workshop idea is truly taking shape for next year. Lots of things went well, we have some tangible improvements, the proof of concept provides value. What a cool insight to take with us.

As we had just spent a lot of energy it was great that the afternoon was calm and I had some time to catch up with things before we headed for dinner. At dinner, how else could it be, people schemed plans for the evening. Lightning talks, conference session summaries, board games. I shared I'd offer another round of Capture the Flag Together as that's my kind of fun - and people instantly signed up for it. So this happened once again! Truth be told, I shouldn't have done it the way I did, as my energy levels were way too low and I didn't manage to facilitate and moderate the room in a way I should have when hosting a session. Lesson learned for the next time.

In the late evening, there were surprisingly few people left. We grouped together and had a really relaxed end of the day. One of my highlights were to playtest a puzzle game - details not to be revealed yet, I'll leave that to the authors! It was super fun, it had everything I need from such a game. A nice way to discover the rules. Just the right level of difficulty, not too easy and difficult enough it's doable but an achievement to solve the puzzle. And a perfectly weird theme you can be playful with. Special shoutout to Claudia Bischoff for fully diving into this together with me!

 

Departure Day 

This late night session would have been the perfect ending. But of course it wasn't, there was still the journey home and that starts with whoever has to leave the venue at the same time. For me it was a perfect opportunity to catch up with Jana Fuerchtenicht on the first leg of the train ride. Thank you so much for keeping my spirits up while my energy levels were crashing, I really appreciate it!

Martin Schmidt and I continued on and chatted for a while until I was on my own. I arrived home and I realized I was completely exhausted. While some of the sessions refilled my batteries, a lot of other happenings had drained me. I had definitely overexerted myself, this time worse than ever as I had already come to the event with a clear deficit. Another reminder that I need to manage my energy levels way more actively than I did this time. Don't get me wrong: this conference is absolutely worth being at and investing energy in. At this event, people care - not only for themselves, but also for each other. Some situations will give a lot of energy, some will drain a lot of energy (and be still invaluable). Sometimes we manage to find a balance, sometimes we don't. This time, I just clearly didn't. A stark reminder for myself and I'm glad I had it. Sometimes we need those reminders to change the way we do things. During the coming year and also at SoCraTes 2027 - I hope to be back!

 

Monday, July 20, 2026

OWASP Global AppSec EU 2026 - Achievement Unlocked

When Mireia Cano and I received the confirmation that our paired talk "Security Champions: Lessons from Opposite Trenches" was accepted at one of the largest OWASP events, the OWASP Global AppSec EU conference, we were speechless. This was too good to be true! We knew the journey there would be very stressful, given the short time left from getting accepted to the conference taking place, and given our lives already had super busy plans for us. And yet, we simply couldn't resist. We fought our way through and overcame every hurdle on the way. We knew why we did it and it was worth it in the end. And Mireia, I'm truly grateful you pulled through together with me! Would we repeat this very stressful experience? Most likely not! But this time, it worked out even better than we hoped for. Here's how the conference went overall.

 


Welcome to Vienna

Vienna was this year's location for the conference which used to move across Europe, and it seems OWASP will stay there for a few years. For me it was a great opportunity to visit the city which isn't that far away from home yet I've never been there.

So I've visited Vienna for the first time, exactly during a period Europe faced an extreme heat wave. The city was burning hot and I was extremely happy that the hotel I chose had working air conditioning and was in walking distance from the conference venue.

Mireia arrived a bit later, and once settled in, we used the time for practicing our talk. I mean, how else could it be. Paired talks are extremely tricky to get right and done well if you don't want to simply patch two half-talks done by two different people in two different styles together and hope for the best. (Nope, that's definitely not how we wanted to do this.) This was our first time to practice in person, and we really needed that opportunity.

Once the duty was done, we enjoyed the rest of the (still very hot) evening over a nice dinner and then called it a day. We knew we would need the energy for what was to come.


First Conference Day

Good thing our talk was scheduled for the second day only, which meant I could fully dive into the experience and check things out on day one. 

That day started with a special breakfast for me. Now, if you know me, I'm neither the breakfast type of person nor am I fully awake at that time of day. This one, however, was too good not to opt in for. It was the "Women in AppSec Breakfast" co-hosted by Tanya Janca, Juliane Reimann, Kim Wyuts, and Marisa Fagan. I mean, how could I miss this chance not only meeting those folks I only knew from social media but also meeting a bunch of other women in my area? I usually love seeing a smaller group of folks first before encountering the whole crowd at a conference, and this one promised to create a safe enough space to make real connections. Turns out, it really did! I met lots of amazing women this morning and we happened to bump into each other again and again during the event. Many thanks to Michelle Mariam Philip, Margot Schepens, Eden Yardeni, Liel and Tina! This pre-conference session truly made me feel welcome from the start and it seems the others were happy about this opportunity just as well.

Here are the sessions I've joined during the rest of the day.

  • Keynote: "The Reinvention of Software Engineering" by Hannah Foxwell. Hannah presented her view on how the software world is changing due to latest AI tooling. She stated that with agentic development, speed of development is outpacing speed of decisions - and yet we really shouldn't just build anything because we can, but something that is worth building. We also need to have the means to ensure safety as things are speeding up. People do and will always matter, so invest in them and broaden their skills.
  • "Why AppSec Fails at Scale (and How to Fix It)" by Eduard Thamm. As Eduard shared, AppSec fails at scale when you keep managing findings instead of designing systems that make secure behavior the easiest path. Preach! Lots of gems in this talk. Like: Security advice that ignores delivery pressure will be routed around - the system rewards shipping fast and often. Haven't we seen that over and over again? Not only with security but all kinds of aspects that make good quality software? Eduard asked everyone to move from findings to mechanisms to make the secure behavior the default. Hear, hear.
  • "Authorization Is Where Your App Goes to Lie" by Eden Yardeni. Eden rightfully pointed out that broken access control issues just keep showing up and stick around among the most common vulnerabilities. Why? Because they're often bound to business logic and hence depend a lot on the underlying intentions of features. It's not straightforward for any application to tell who should be allowed to do what - rather the opposite. Eden's answer to this? Use policy engines so "your product owner's intention compiles into policy as code". Helpful for threat modeling, too!
  • "Retiring CVE Chasing: Defending Against Application Exploit Techniques" by Idan Elor. Idan appealed to the audience that we need to start defending against the underlying techniques instead of just running after getting vulnerabilities fixed (have I already shared how often we're seeing this one?). If we build technique-level controls and detect exploitation attempts, we can cover whole classes at once. Idan presented the application attack matrix to help - a community-driven framework mapping tactics, techniques and procedures against modern applications, which can be used for threat modeling and in architecture reviews.
  • "This Build can Break You - Evil Runners and eBPF for Detection" by Reinhard Kugler. Reinhard shared how different CI/CD runners handle things differently and hence show different attack vectors - yet usually they are highly privileged and a valuable target. How to see what happens in the Kernel space? The answer is eBPF code running in a virtual machine in the Kernel. You can attach functions to a trigger like a syscall, trace event or network call and hence detect malicious activities. As Reinhard said, observability is the first step of defense!
  • Book Signing: Alice and Bob Learn Application Security Tanya Janca. Well, I simply had to seize this opportunity. Tanya had been the most influential person in my security career so far, and by far. I've literally only seen my way into security because of her. Knowing she would be at the conference, I kept looking for an opportunity to talk with her, at least shortly to thank her for her work. At breakfast, this opportunity did not show up and I didn't want to impose. Then, at one of the earlier talks that day, I happened to sit front row (as usual) and prepare my sketchnote for the following talk. I was talking with another person next to me, when someone suddenly turned around to us. It was Tanya! We happened to have a quick chat where I blurted out I was in security because of her making security accessible, and also nervously revealed we'll also have a talk the next day. I was super happy this happened and happened naturally. I still wanted to go to her book signing, now even more (I obviously had her book of course already, yet a physical signed copy is just something truly special). And Tanya remembered me and wished us good luck for the talk. Honestly a true fan-girling moment. Stay tuned, this story continues!
  • "The Devil is in the Defaults - what to do about XSS" by Frederik Braun. Cross-site scripting has been the number one CWE for over 10 years. The measures we have to defend against it still aren't as widely used as they should. Like the Content Security Policy - it's shocking how few websites actually make good use of it. Trusted types are great as they treat all HTML parsing as harmful unless proven otherwise - but they also need to be enabled through a CSP directive (which we know only few even use), and, very unfortunately, they ignore context during HTML parsing. Here comes the HTML sanitizer API to the rescue! It will never allow XSS - guaranteed by the browser and as part of HTML standard. I love that Frederik left with a hope-instilling note: we indeed can fix XSS.

During the day, it was really pleasant to run into some folks I already knew from other conferences! Like Clemens Hübner who Mireia and I met at the Open Security Conference 2025. Or Irfan Qadoos whom I met at both BSides Munich and security meetups. Just loved catching up with both again. The world is small and you never know where you'll meet again.

The official program ended already by 16:15 CEST which I was absolutely not used to from other conferences. Of course, networking events are super crucial and lots of stuff was planned on that end, not only socializing at the venue but also dinners and sightseeing offered by various sponsors. Well, not for Mireia and me this time, because obviously we had to use this last opportunity to practice our talk and make it work for the next day. Lucky us, we could still use the venue for the first dry run so we had a "close to real" practice environment. As things closed down at the venue, we had to move out and do the second run at our accommodation. Once we had a good enough feeling, we called it a day. I took the remaining time of the evening to enjoy a really lovely dinner at a Chinese restaurant offering as authentic as one can get Sichuan food. It was absolutely delicious and just good for the soul after a long stressful period of months. Especially as the very next day, it was on.

 

Second Conference Day

The second day, how else could it be, I was rather late for the first session yet made it just in time. I knew ahead of time I most likely won't be able to join many things next to our own talk, yet in the end I managed to catch a few sessions still. 

  • Keynote: "We Live in the Future: The Death and Rebirth of Application Security" by Gadi Evron. Gadi reminded us that things keep changing and we have to keep changing with them. For example, we cannot trust security configurations anymore when agents can just change them. The perimeter shifted to the endpoint agent, yet security controls don't cover them yet. Gadi raised a big question: English is the new programming language - yet how do we secure English?
  • Book Signing: Threats: What Every Engineer Should Learn From Star Wars with Adam Shostack. Yes, I just had to go to this book signing as well. Of course I had Adam's book as well already. But remember, a signed physical copy is a special thing! Also, you never know what will happen. I just loved that Adam noticed my Star Trek shirt and complimented me on it. Well, that's one of the many reasons I love wearing such shirts. They are a great way to find your kin and have lovely conversations. Just like with Adam this time. Thanks a bunch for that!
  • "Keep It Between Us: Manipulating Humans for Better AppSec (Ethically)" by Nariman Aga-Tagiyev. Nariman focused this talk on human motivation - what makes us do things? What are we actually driven by, how much does this reason come from the outside, and how sustainable is it? He reminded us that with some reinforcement, behavior will become a habit, and we can make use of this in our AppSec programs. Make it obvious, make it attractive, make it easy, make it satisfying. Or: Invert all of the above. The invisible side of AppSec and the secret plan is to convert activities into habits. We can start with writing down what the current good and bad habits are around a problematic behavior we observe.
  • "Security Champions: Lessons from Opposite Trenches" by Mireia Cano and me. It was time. We went on stage. The show was on. Have I said paired talks are a special kind of a challenge? This time, we attempted role plays on stage to convey our messages and have a red thread throughout the talk. Well, it was risky - these role plays could have come across as very cringe and over the top. You can't imagine how happy we were when we received lots of amazing feedback afterwards exactly on those theatrical role plays! Seems we hit just the right note and they indeed helped make the topics tangible and relatable with folks. We pulled through, it was our best version of the talk, and you don't know how happy I am that this was recorded! The relief was real afterwards. We really did it! Time to celebrate. That being said, what did we talk about? Well, Mireia came from the security side, having gathered plenty of experience with designing and running security champions programs with everything that could go wrong and what helps to make them go well and evolve. And I lived that champions experience myself for three years before going fully into security, now running a security champions program myself! We've found four key aspects that truly made the difference for such programs. The slides are already out, yet to get the full experience, you'll have to wait a couple of months until the recording is released.
  • "Using CTFs as a Community of Practice Content Machine" by Marco Macala, Florian Schier, and Christian Buchinger. In this talk, they described the security community they built, what worked and what didn't. Very fitting talk to come just after ours! Marco, Florian and Christian advised to keep the monthly sessions light, comedic and consistent. To make them engaging for different backgrounds. To have open discussions, give people free rein for content. And, what I especially love: there should be no grandstanding from security. So much this, seen this way too often as well! All this made them discover CTFs as a perfect opportunity to increase awareness and skills. They encouraged folks to keep them very basic and limiting the effort to set them up. Especially: education over competition, approachable for everyone! That really resonated with me and my current approaches to CTFs, especially when giving such sessions during open space conferences.
  • "Insecurity as Code: How Modern Software Scaled the Attack Surface" by Igor Stepansky. Igor explained how applications aren't the only attack surface anymore - it's everything around them as well, while everyone is already drowning in findings. Due to AI tooling, alerts are exploding - yet are they even valid? Igor reminded us: You're not behind, you're buried! It's about reliably finding the 1% truly critical. To triage on reachability and business impact and then patch those fast, focusing on what matters. And instead of fixing more findings, we should remove the attacker's leverage. This!

During the day, even though the excitement of the upcoming talk was there, I once again had opportunity to meet folks. Like Frederik Braun whom I was connected with via social media yet we never had a chance to talk before. Or Lars Hermerschmidt whom I heard about through a friend working at the same company. Or Ali Kabiri who was immensely kind helping me out with my (super cool) OWASP badge by getting me an extension for it. Also meeting folks I met before, like Michael Helwig. Really enjoyed all those conversations.

The conference approached its closing, and with that came a very special moment for me. Remember that Tanya Jana wished me good luck for our talk? Well. It happened to turn out that she was attending the same last talk as I was. As I was finishing up my sketchnote, she was coming to the front, chatting with the speaker. While I collected all my stuff, she saw me and asked how our talk went. We started to talk and, as it happens, went to the conference closing together. She was going to sit front row - as I usually do the same, I had no problem joining her. Sitting next to her, chatting, and really enjoying our conversation. This way, I also found out that the conference provided slim-fit conference t-shirts for the first time this year - and I have to thank Tanya for relentlessly trying to make the offering more diverse (no, unisex is not the solution here).

The closing was done. The room emptied. I looked around, and found Clemens with a few folks and joined them. I met Mariia Denysenko this way, realizing we're from the same location - a lovely encounter! It was also a pleasure to meet Michael Koppmann who enabled this whole conference by leading the team of volunteers and relentlessly working behind the scenes.

Then it was time to say goodbye and close this chapter. I had a nice dinner in the area. Calmed down a bit. Prepared for the next day - I was adamant to go sightseeing despite the heat. I thoroughly enjoyed doing exactly that after sleeping in the next day (I love art and art galleries are a great air-conditioned place by nature). The day afterwards, it was time to go home.

My first proper OWASP event was as big as they get. It was a good one in itself. It was a really great one because of the people. And it was definitely a huge achievement unlocked moment for Mireia and me!

Thursday, July 16, 2026

SoCraTes UK 2026 - Instant Connection

My heart is full of gratitude for finding such instant and easy connection. That's probably the best summary I can provide after my very first SoCraTes UK. I would have loved to be able to write this post right after the conference while memories and emotions were fresh, yet life happened and right now is the next best time for it. So let's start at the beginning.


Arrival

As for most conferences, it takes me a while to get to their location so I plan with a travel day back and forth. It reduces most travel worries due to hiccups, makes everything so much more relaxed, and also gives a chance to connect with the first set of people before the event starts. Also in this case, arriving the day before was well worth it. The lovely venue is located in the countryside, surrounded by nature. I had some time to settle in and just breathe. So far so good.

But then there was the heat. Well, that full-blown heat wave was not sparing the region and it presented a challenge throughout the conference. Especially given my hotel room was right under the roof, only had limited capacity to open windows and offered no air conditioning - not even any air circulation in the bathroom. Let's say it was tough, but I survived. 

Having settled in and rested for a bit, it was time for meeting people and then having dinner together. It was great to see people like Amélie Cornélis, Emily Bache, Simon Görtzen, Alexander Alemayhu, Michel Grootjans, or Raimo Radczewski again. At the same time I loved connecting with folks I haven't met before, like Clare Sudbery, James Bel, Claudia Görtzen or Chris Jenkins.


Training Day

SoCraTes UK offered a bunch of trainings this year before the official start of the conference. I really appreciate these short pre-scheduled workshops that bring people together on practicing things hands-on and also provide some topics already to take further into the following open space.

  • TDD Game with Cyber-Dojo by Jon Jagger. If you haven't come across Cyber-Dojo yet, it's a great practice playground for coding katas across all kinds of programming languages. And Jon is its creator! In this session, we split into groups and tried to predict every outcome of our changes, working on a kata. And not only that, we played against an LLM model who tried to predict as well - so our goal was to trick it into false assumptions. Well. The sad news: Nearly no group succeeded. A rather sobering insight. I guess this might change once the domain would become more unique and specialized, yet who knows.
  • Secure Development Lifecycle Applied - How to Make Things a Bit More Secure than Yesterday Every Day by me. I've given this workshop plenty of times already and every time it's fun for me to notice how the groups engage with the material, what kinds of ideas they surface, which ones they try first. As usual, I hope it's also fun for the participants to practice together hands-on on tangible things they can do to make software more secure. I really appreciated the folks that joined, many of them gave detailed feedback - invaluable! - and people seemed to find value in it to take with them.
  • Using TDD to Get Better Results From LLMs/AI by Clare Sudbery. We worked together in pairs to build an app using only an agent, based on a set of requirements provided by Clare. Half of the groups had to use TDD, the other half was obliged not to even mention any kind of testing to the LLM. Curiously, the key insight for me from this workshop was not related to the question "TDD or not TDD" at all. It was that no matter how we implement things, we still need to work with humans first to gain insights on the domain and problem space to gain understanding on what they actually want to have us build. Classic lesson, learned once again.
  • Value Stream Mapping by Tim Ottinger. This was a really cool workshop for me. I've learned about the approach and key concepts from various sources for years and spread it further in one way or the other. This workshop felt super validating that what I've been sharing with my teams and outside was indeed going in the right direction. We all put on paper what the value of our product for a customer is, what they desire and require. Then we mapped out all the steps that need to happen to deliver this value. We annotated that stream to identify value-adding and non-value-adding work, including pure waste. We documented cycle times for each step, as well as waiting times in between the steps. Because one of the main points here is that speeding up a non-bottleneck process produces deeper queues and longer waits - you make the bottleneck worse. We analyzed several example situations and what we could do to make things flow. Well, as a longstanding advocate for pairing and ensembling, the answer how to increase flow was right there for me.

The training day was over, and the main conference started in the evening. It was a true pleasure to have Romeu Moura as a facilitator for the open space. He did a splendid job to get people to not only break ice, but also deeply engage with the values of the conference, really think about what everyone of us, starting with ourselves, can contribute to make this a safe space. This kind of foundation really showed the next days and I believe we took it with us even after the conference had ended.

Dinner time! Had lovely conversations with the folks at our table. Topics didn't stay shallow either, with the round addressing big societal problems as well as generational change. Afterwards, I was already pretty tired and close to call it a day, yet I wanted to check out what people were up to. The board game round intrigued me so much in the end that I stayed for way longer than originally planned. I just love games and the one people tried had a really cool concept, was not easy at all and truly required collaboration of players. You know, those lessons for life games. 


Open Space Day 1

I'm a night owl, so open space marketplaces generally start too early for me. Yet I better be there if I'd like to hear folks pitch their sessions and be ready to host one myself (and of course I do). Here's my pick of sessions for this first open space day.

  • "How can the way we work support democracy?" by Claudia Görtzen. I loved that she raised this topic already the evening before and was super happy she proposed it as a session. Because we all have our share in how we deal with things at work. Should we speak up about issues or not. Do we support unethical companies or not. Do we report misbehavior or not. Do we build this shady feature or dark pattern or not. All these big and small day to day decisions. In this session, we had a really insightful conversation and valuable exchange on tangible things we can do. The ones that stuck with me most? Join a union. Don't go alone - conspire. Learn from the book "Blueprint for Revolution". And the one I keep thinking about: start practicing anarchist calisthenics. 
  • "Your IDE / test suite / security scanner / design system / language server will steal your SSH key, unless ..." by Raimo Radczewski. When a security topic is proposed, I just have to attend! We all started with sharing stories about latest supply chain attacks - well, there were plenty of those happening the last years. Then we gathered ideas on what we can do to for better protection. Lots of good advice and tooling was collected. Like Little Snitch to monitor network calls on MacOS, that I already had on my list as it's been heavily recommended in the security community. As usual, there was also stuff I wasn't aware of yet that I'll definitely look into further, like nono.sh to sandbox any terminal agent, or Deno, where code executing in this Node-compatible JavaScript runtime has no access to read or write arbitrary files on the file system by default (among many more security features).
  • "Capture the flag together (beginner's edition)" by me. What can I say: I just love proposing this session at various open space conferences. So once more, I tried this out - a bunch of people joined and were captivated with capturing that flag. This highly collaborative and highly educational session just keeps giving and comes with pleasant surprises! I thoroughly enjoy doing these. It seems people did appreciate it as well: folks were staying longer, wanting more, and giving plenty of positive feedback afterwards. The one that made me the happiest is their emphasis on how accessible security and penetration testing became to them thanks to these sessions. What more could I want?
  • "How do we defend democracy and fight fascism" by Sarah Peper. I really wanted to continue this theme and engage more with this super crucial topic. Yet as my session before overran, I came to this one rather late. I was pretty tired at that moment in time so I can't really remember much from the conversation. At some point I had to walk out and cater to my needs. But that's also the beauty of open spaces - you're explicitly free, welcome and even encouraged to leave a session when you're neither contributing nor learning or just need something different at that moment in time.
  • "How the way we talk can change the way we work" by Ellen Potter. Ellen hosted an interesting session based on the book "How The Way We Talk Can Change the Way We Work" and the exercises in it. She also posted about it including a description if you want to give it a go yourself. We all started taking note of complaints we have. Then we reflected on what's important to us, basically what makes us complain in the first place. We thought about our own role in this to keep this being a problem, as well as competing commitments that contribute to us being stuck. Finally, we took a deep introspection into which assumptions we base this all on and what experiments we can run to find out what's actually the case. This was such a thought-provoking session! Lots to unravel and try out.

The day was closed, the evening marketplace was opened. I couldn't resist and, after a lovely relaxed dinner, I offered the follow-up to my previous session: "Capture the flag together (adventurer's edition)". Once again, lots of people joined in! And as it usually happens... the evening got longer and longer. We had fun feeling all the rollercoaster emotions of going through frustration and hope and trying ideas and failing and sometimes succeeding by finding a new insight and circling back and wondering what we missed and... You get the picture. In the end, we spent four wonderful hours and managed to capture the flag together. 

 

Open Space Day 2

The longer the conference, the more tired I grow. Which is nothing new. The good thing about open space conferences is that I don't have to feel bad about not going to sessions. Okay, I usually do feel bad at first. Then I realize it's the perfect thing to do right now to not stress myself, follow my needs, and recharge batteries so I can fully enjoy the rest of the day. So I chose a very slow morning without sessions. There were also quite a few personal tasks to do, given this was a period when a lot was going on in my life on top of many travels in a row. So I took the liberty to just miss sessions, although there were really good ones on offer. Instead, I could lift a burden from my shoulders and that was a true relief. In hindsight, giving myself grace that morning was absolutely the best thing I could have done.

Then came lunch time and afterwards I wanted to join sessions again. But things happened differently. A new session was born over lunch, as it happens. So I stayed at my table and our group continued talking about all the things: personal differences, neurodiversity, weird and even surreal situations, academics, health conditions, and so much more. It was just lovely. 

Way sooner than not it was time for the session I pitched myself that day, so I better had to be there! I had called it "Interactions with security folks - gone well and gone badly" and it aimed for an experience exchange. Once again, lots of folks turned up! I started with preparing a flip chart. I set the room so more people than just dominant voices would share. Then I asked for people's experiences and insights - and lots of stories were brought to the table. At some point I asked more specific questions that elicited further insights. The outcome? The "Nay" side of my flip chart filled up rather quickly - something I observe and hear way too often, all the bad experiences people make with security folks. The "Yay" side lagged behind for a long time. Good news: in the end, it was showing a lot more points. There's hope! This session provided lots of food for thought. Not only for my contribution at work, but also for what I want to share in my next talk that I'll soon start to craft.

For the last session slot during the day I picked the "TDD Game" by Ted M. Young. He brought the board game he designed and I was eager to give it a try. Even though we were on a tough time constraint, this game was truly a great experience! The game play and different tactics triggered insightful conversations and at the same time validated what our group knew already based on their own experiences. It would have been really interesting to do this together with people who are not aware of TDD, value stream mapping and flow, collaboration techniques, and all the good practices. Also, the game was super accessible, I felt very safe with my own knowledge and skills - and yet it forced decision making and practicing it. Another interesting thing was that Ted included the concept of exchanging a card as "thinking time", and also that you always have to hold back two (yes, two!) playing cards, otherwise you run out of energy. Really neat. If you have a chance to try this game out yourself, I can only recommend you to give it a go.

A lovely dinner followed, and, how else could it be, I offered once again an evening capture the flag session. I really enjoy them way too much not to. This time, something really cool happened. First, Michel Grootjans went all in and started a whole setup for himself and we could already use it for our session. Second, the group decided to experiment with different ways to collaborate and become more effective together in capturing the flag. Third, it didn't end that night at SoCraTesUK (spending up to six hours and absolutely capturing flags)! The next day at breakfast (that I obviously skipped), people kept talking about these sessions and expressed their eagerness to continue beyond the conference as a SoCraTesUK CTF round. Ellen Potter kindly offered to drive this, and can you imagine, the first session already took place and the second is scheduled! I'm a bit sad I couldn't join any of these (yet), and I'm overjoyed this just happens without me. Just beautiful.


Departure

It was time to leave. My heart was full, the newly found connections were strong. I absolutely appreciate the organizers to craft this space so intentionally. It seemed to be a smaller event this year compared to the previous ones, yet it did not matter at all. I absolutely recommend checking this one out. I'm certain I'm not the only one who got a lot out of it this year.

As a bonus, I opted for a longer stay at the airport so I could meet my dear community friend Tabitha Ncooro for the first time in person. We got to know each other a few years ago during the time I seeked connections into the security community and found her trying the same. Ever since we check in with each other regularly and I've found her to be one of the kindest and wisest people I've ever met in life. It was a true pleasure to meet her in person just after such a wonderful event.

I'm back home. It's been a few weeks since SoCraTes UK. And yet: I still think about this event, how people made me feel, and all the inspiration taken with me from it. This conference brought instant connection and keeps resonating.