Conference – October 20, 2026
Shadow IT
| Time | Arena | Scenario | Panorama – Business Partners |
|---|---|---|---|
Moderator | |||
08:00
-
09:00 | |||
09:00
-
09:15 | Dr. Christian Folini Program Chair, Swiss Cyber Storm Show descriptionGuests are welcomed by the organizers for this year’s Swiss Cyber Storm conference. | Show descriptionThere is no talk on this track at this time, check the schedule of the Arena track instead. | Show descriptionThere is no talk on this track at this time, check the schedule of the Arena track instead. |
09:15
-
09:55 | U.S. Lieutenant General (Ret.) Karen H. Gibson Former Deputy Director of National Intelligence for National Security Partnerships Show descriptionDrawing on her experience safeguarding every aspect of the U.S. Senate’s operations and a career spanning military intelligence and cyber operations, Karen Gibson explores a fundamental challenge for cyber defenders: protecting what you cannot always see or control. From legacy systems and forgotten technology to workforce practices and third-party dependencies, she examines how hidden vulnerabilities accumulate — and what leaders can do to better understand risk, strengthen resilience, and protect the mission. | Show descriptionThere is no talk on this track at this time, check the schedule of the Arena track instead. | Show descriptionThere is no talk on this track at this time, check the schedule of the Arena track instead. |
09:55
-
10:05 | Marc Bollhalder Organizer and Lead, Swiss Hacking Challenge Manuel Bürge Organizer, Swiss Hacking Challenge | Show descriptionThere is no talk on this track at this time, check the schedule of the Arena track instead. | Show descriptionThere is no talk on this track at this time, check the schedule of the Arena track instead. |
10:05
-
10:50 | |||
10:50
-
11:20 | Hannes Lubich Prof. FHNW, retired Show descriptionShadow IT covers far more than apps installed without authorization or PCs and routers brought in from home. This talk discusses how uncontrolled IT also stays hidden in devices, cloud services and supply chains. Causes include hard-to-use corporate systems, time pressure, insufficient resources, pressure to outsource services, as well as user creativity and a lack of discipline among privileged power users and administrators. This creates potential risks from unpatched systems to data leakage, compliance violations, unknown dependencies and unclear responsibilities. As complexity, regulation and misuse increase, training and policies alone are not enough. What is needed: up-to-date inventories, limited privileges, adequate supplier due diligence, ongoing monitoring, automated pattern detection, rapid response, sufficient evidence of due-diligence compliance, realistic fallback plans, and a new understanding of trust. | Stephane Adamiste Information Security & Data Privacy Expert
at
Soluss AG Show descriptionSwiss electronic voting is one of the most scrutinised and controversial topics in cybersecurity, marked by significant public criticism and vulnerabilities uncovered in earlier system versions.
This talk shares field experience from auditing the Swiss e-voting system, focusing on infrastructure and operations.
It explores the concrete challenges faced during audits, from assessing complex and distributed architectures to verifying controls across organisational boundaries, and provides an informed perspective on the security of the system. | Dani Syed Founder and CEO of KIDAN Show descriptionAttackers innovate faster than defenders can model them.
That is not a temporary gap, it is the permanent condition of cybersecurity.
Military doctrine accepted an equivalent truth decades ago and abandoned pure prediction in favour of hardened, adaptive defence.
Security teams are only now catching up. |
11:25
-
11:55 | Ivano Somaini CEO
at
CyberStage GmbH | Nadim Kobeissi Director
at
Symbolic Software Show descriptionVirtually all privacy depends on well-designed cryptographic protocols, yet a person working in security should be able to examine a protocol without having to become a formal-methods specialist first. Existing tools offer considerable power — but should mastering that machinery be the price of admission? Verifpal gives you an easy way to define the model. Use its language to describe who knows what, what they compute, and what they send. Built-in cryptographic operations, a browser-based workbench, live editor feedback and protocol diagrams guide you to an iterative model-attack-repair cycle that allows to you examine or enhance the protocol in terms of robustness. Close to the release of Verifpal 1.0 in August 2026, Verifpal was used to discover three new authentication flaws in WalletConnect, one reproduced against an unmodified SDK, and novel weaknesses in SimpleX Chat. Verifpal performs bounded attack search, not unbounded proofs. | |
12:00
-
12:30 | Sébastien Schnyder Manager Cyber Threat Intelligence Services Europe
at
Google Show descriptionWe’ll look at three aspects of adversarial use of AI in this talk:
| Yannik Goldgräbe Security Architect
at
Swisscom Show descriptionEnterprises run on cryptography — but hardly anyone can say where it actually lives. TLS gets terminated somewhere in the infrastructure, the container base image decides which OpenSSL you run, algorithms come from library defaults. Everything works, and that’s exactly the problem: healthy cryptography is invisible. We term this „shadow cryptography”. It’s the functional crypto that nobody sees/manages end to end. Pressure is now building from several directions at once — shrinking certificate lifetimes (browser forum), faster vulnerability discovery (AI), tightening regulation, the post-quantum transition. Different storms, same weakness: not knowing your cryptographic landscape. | |
12:30
-
14:00 | |||
14:00
-
14:30 | Mazin Ahmed CEO and Founder
at
Fullhunt Show descriptionShadow IT doesn’t come from one bad decision.
It builds up over time as infrastructure grows, people move between teams and companies, vendors deploy systems, cloud environments change, and documentation falls out of date.
A single forgotten development instance or an untracked database server can become the path to a serious breach.
I have spent years running Internet-wide scanning and building the tooling behind it at FullHunt.
I have also run hundreds of security reviews focused on Shadow IT and the ways organizations gradually introduce risk into their external attack surface.
In this talk, I’ll show how Shadow IT grows and scales across organizations and the recurring patterns I have seen in the wild.
I will introduce the Attack Surface Reduction Maturity Framework, a practical model organizations can use to understand where they stand in their attack surface reduction journey and how they can move from outdated inventories to continuous visibility.
Finally, I will present real findings discovered during this research and responsibly disclosed to Swiss organizations. | Andres Maurer Executive Chairman
at
prod @g | Ernesto Hartmann Chief Cyber Defence Officer
at
InfoGuard AG Show descriptionCyberattacks rarely begin with a big bang. Attackers often move unnoticed through corporate environments for weeks before striking. Yet what if these risks were visible beforehand? |
14:35
-
15:05 | Thomas Naunheim Cyber Security Architect
at
glueckkanja Show descriptionMany organisations face the challenge of effectively securing their privileged users while also avoiding lateral movement paths when delegating privileged access.
In addition, operating and further developing Privileged Admin Workstations (PAWs) generates significant effort and complexity. | ||
15:10
-
15:40 | Bonnie Viteri Principal Technical Security Engineer
at
Yahoo | Dr. Loïc Marechal Scientific Collaborator
at
HES-SO Valais-Wallis (IEM) Show descriptionThe SwissCyber Initiative (SCI) maps Switzerland’s cybersecurity ecosystem and examines current and future gaps in cybersecurity R&D, with a particular focus on companies and key cybersecurity subdomains. Combining a nationwide
stakeholder survey with reworked and cleaned structured data from sources such as Crunchbase and ZEFIX, the project identifies perceived R&D gaps, emerging technologies and threat priorities, and the characteristics and geographical
distribution of active organizations. It also reveals how companies are financed and by whom, offering an initial perspective on the digital sovereignty of Switzerland’s cybersecurity sector. These insights are integrated into a web-based
platform that enables interactive exploration and comparison through smart filters. The presentation will highlight key findings from the R&D-gap analysis and demonstrate two use cases illustrating how survey insights, ecosystem data, and
financing information can be combined to support evidence-based analysis of Switzerland’s cybersecurity landscape. | Antony Ancelin Technical Lead Incident Response
at
Swiss Post Cybersecurity Show descriptionSelf-managed infrastructure promises agility and autonomy. But what happens when it also slips outside the visibility of the teams responsible for defending it? Our session examines a real-world incident in which an independently operated infrastructure became the starting point of a full-scale compromise inside an enterprise. The breach remained undetected until it was uncovered by luck rather than by security controls – highlighting how ownership gaps can quietly become security gaps. |
15:40
-
16:20 | |||
16:20
-
16:50 | Jeroen van der Ham-de Vos Associate Professor
at
University of Twente Show descriptionVulnerability Management just got even harder to do.
An avalanche of AI-assisted attackers, combined with enormous waves of security updates, makes it even more challenging than it already was.
As defenders, we know that there was security debt in keeping up with all the security updates, vulnerabilities, and defensive actions that we could take.
Before AI, defenders were mostly able to keep up with patching.
But now the security debt is due, and many of the defenders have trouble keeping up.
Jeroen will present his ideas on efficiently dealing with the firehose of vulnerability information.
We can finally let go of the CVSS score, focus on the technical and organisational aspects of vulnerabilities, with a way to lure the hidden IT systems out of the shadows. | Felix Linker Security Researcher
at
ETH Zurich Show descriptionConflict increasingly takes place online.
And also aid providers, hospitals, and humanitarian organisations increasingly rely on digital infrastructure like servers and networks.
In the physical world, the emblems of the Red Cross, Red Crescent, and Red Crystal identify protected sites such as hospitals, but no equivalent signal exists in cyberspace.
The Digital Emblem project is building that missing signal: a machine-readable marker identifying digital infrastructure as protected under International Humanitarian Law. | |
16:55
-
17:30 | Show descriptionWhat happens when the signals we learned to trust: a familiar voice, a local dialect, authority, belonging, even the feeling that “this person is one of us”, can be artificially manufactured?
Cybersecurity has spent decades teaching users to behave more rationally.
But social engineering succeeds precisely because humans do not make decisions like security systems, especially under pressure.
In this closing keynote, behavioural analyst An Gaiser explores trust as both a human vulnerability and a security capability.
Through live audience interaction, Swiss cultural cues, AI-enabled deception, investigative interviewing and behavioural science, she challenges one of cybersecurity’s most persistent ideas: that the human is simply the weakest link.
If we treat the people we are trying to protect as the problem, why would they trust us enough to report when something has gone wrong?
The future of cyber defence requires more than deciding what is real.
It requires understanding why humans trust what they trust, and becoming worthy of that trust ourselves? | Show descriptionThere is no talk on this track at this time, check the schedule of the Arena track instead. | Show descriptionThere is no talk on this track at this time, check the schedule of the Arena track instead. |
17:30
-
21:00 | Show descriptionOur standing dinner allows everybody to mingle, meet friends and talk about the many interesting talks of the day.
Naturally, most of the speakers will still be around, so don’t rush off after the last talk. | Show descriptionOur standing dinner allows everybody to mingle, meet friends and talk about the many interesting talks of the day.
Naturally, most of the speakers will still be around, so don’t rush off after the last talk. | Show descriptionOur standing dinner allows everybody to mingle, meet friends and talk about the many interesting talks of the day.
Naturally, most of the speakers will still be around, so don’t rush off after the last talk. |
18:30
-
18:45 | Show descriptionDistribution of prizes for the Sponsoring Raffle. | Show descriptionDistribution of prizes for the Sponsoring Raffle. | Show descriptionDistribution of prizes for the Sponsoring Raffle. |