Schedule

Conference – October 20, 2026

Shadow IT

Sessions related to the main conference topic „Shadow IT” are highlighted with a gray background.
Time Arena Scenario Panorama – Business Partners
Moderator
08:00 - 09:00
09:00 - 09:15
Dr. Christian Folini's avatar
Dr. Christian Folini
Program Chair, Swiss Cyber Storm
Show description
Guests are welcomed by the organizers for this year’s Swiss Cyber Storm conference.
Show description
There is no talk on this track at this time, check the schedule of the Arena track instead.
Show description
There is no talk on this track at this time, check the schedule of the Arena track instead.
09:15 - 09:55
U.S. Lieutenant General (Ret.) Karen H. Gibson's avatar
U.S. Lieutenant General (Ret.) Karen H. Gibson
Former Deputy Director of National Intelligence for National Security Partnerships
Show description
Drawing on her experience safeguarding every aspect of the U.S. Senate’s operations and a career spanning military intelligence and cyber operations, Karen Gibson explores a fundamental challenge for cyber defenders: protecting what you cannot always see or control. From legacy systems and forgotten technology to workforce practices and third-party dependencies, she examines how hidden vulnerabilities accumulate — and what leaders can do to better understand risk, strengthen resilience, and protect the mission.
Show description
There is no talk on this track at this time, check the schedule of the Arena track instead.
Show description
There is no talk on this track at this time, check the schedule of the Arena track instead.
09:55 - 10:05
Marc Bollhalder's avatar
Marc Bollhalder
Organizer and Lead, Swiss Hacking Challenge
Manuel Bürge's avatar
Manuel Bürge
Organizer, Swiss Hacking Challenge
Show description
There is no talk on this track at this time, check the schedule of the Arena track instead.
Show description
There is no talk on this track at this time, check the schedule of the Arena track instead.
10:05 - 10:50
10:50 - 11:20
Hannes Lubich's avatar
Hannes Lubich
Prof. FHNW, retired
Show description
Shadow IT covers far more than apps installed without authorization or PCs and routers brought in from home. This talk discusses how uncontrolled IT also stays hidden in devices, cloud services and supply chains. Causes include hard-to-use corporate systems, time pressure, insufficient resources, pressure to outsource services, as well as user creativity and a lack of discipline among privileged power users and administrators. This creates potential risks from unpatched systems to data leakage, compliance violations, unknown dependencies and unclear responsibilities. As complexity, regulation and misuse increase, training and policies alone are not enough. What is needed: up-to-date inventories, limited privileges, adequate supplier due diligence, ongoing monitoring, automated pattern detection, rapid response, sufficient evidence of due-diligence compliance, realistic fallback plans, and a new understanding of trust.
Stephane Adamiste's avatar
Stephane Adamiste
Information Security & Data Privacy Expert at Soluss AG
Show description
Swiss electronic voting is one of the most scrutinised and controversial topics in cybersecurity, marked by significant public criticism and vulnerabilities uncovered in earlier system versions. This talk shares field experience from auditing the Swiss e-voting system, focusing on infrastructure and operations. It explores the concrete challenges faced during audits, from assessing complex and distributed architectures to verifying controls across organisational boundaries, and provides an informed perspective on the security of the system.
Dani Syed's avatar
Dani Syed
Founder and CEO of KIDAN
Show description
Attackers innovate faster than defenders can model them. That is not a temporary gap, it is the permanent condition of cybersecurity. Military doctrine accepted an equivalent truth decades ago and abandoned pure prediction in favour of hardened, adaptive defence. Security teams are only now catching up.
11:25 - 11:55
Nadim Kobeissi's avatar
Nadim Kobeissi
Director at Symbolic Software
Show description

Virtually all privacy depends on well-designed cryptographic protocols, yet a person working in security should be able to examine a protocol without having to become a formal-methods specialist first. Existing tools offer considerable power — but should mastering that machinery be the price of admission?

Verifpal gives you an easy way to define the model. Use its language to describe who knows what, what they compute, and what they send. Built-in cryptographic operations, a browser-based workbench, live editor feedback and protocol diagrams guide you to an iterative model-attack-repair cycle that allows to you examine or enhance the protocol in terms of robustness. Close to the release of Verifpal 1.0 in August 2026, Verifpal was used to discover three new authentication flaws in WalletConnect, one reproduced against an unmodified SDK, and novel weaknesses in SimpleX Chat. Verifpal performs bounded attack search, not unbounded proofs.

12:00 - 12:30
Sébastien Schnyder's avatar
Sébastien Schnyder
Manager Cyber Threat Intelligence Services Europe at Google
Show description

We’ll look at three aspects of adversarial use of AI in this talk:

  1. AI use along the kill chain: the changing economics of cyberthreats. In this section, we will take an interactive journey along the cyber kill chain to explore how AI adoption increases actor speed and sophistication, and which security controls are best suited to prevent those threats.
  2. Lessons from the frontlines: how state-backed threat actors leverage AI every day. We will share concrete observations of how sophisticated threat actors leverage AI, including examples of self-generating malware.
  3. Threats from AI adoption: how poorly planned adoption or excessive agency can create risks for companies and public institutions. We will discuss concrete examples of agents „going rogue” and which controls could have stopped them.
Yannik Goldgräbe's avatar
Yannik Goldgräbe
Security Architect at Swisscom
Show description

Enterprises run on cryptography — but hardly anyone can say where it actually lives. TLS gets terminated somewhere in the infrastructure, the container base image decides which OpenSSL you run, algorithms come from library defaults. Everything works, and that’s exactly the problem: healthy cryptography is invisible.

We term this „shadow cryptography”. It’s the functional crypto that nobody sees/manages end to end. Pressure is now building from several directions at once — shrinking certificate lifetimes (browser forum), faster vulnerability discovery (AI), tightening regulation, the post-quantum transition. Different storms, same weakness: not knowing your cryptographic landscape.

12:30 - 14:00
14:00 - 14:30
Mazin Ahmed's avatar
Mazin Ahmed
CEO and Founder at Fullhunt
Show description
Shadow IT doesn’t come from one bad decision. It builds up over time as infrastructure grows, people move between teams and companies, vendors deploy systems, cloud environments change, and documentation falls out of date. A single forgotten development instance or an untracked database server can become the path to a serious breach. I have spent years running Internet-wide scanning and building the tooling behind it at FullHunt. I have also run hundreds of security reviews focused on Shadow IT and the ways organizations gradually introduce risk into their external attack surface. In this talk, I’ll show how Shadow IT grows and scales across organizations and the recurring patterns I have seen in the wild. I will introduce the Attack Surface Reduction Maturity Framework, a practical model organizations can use to understand where they stand in their attack surface reduction journey and how they can move from outdated inventories to continuous visibility. Finally, I will present real findings discovered during this research and responsibly disclosed to Swiss organizations.
Ernesto Hartmann's avatar
Ernesto Hartmann
Chief Cyber Defence Officer at InfoGuard AG
Show description

Cyberattacks rarely begin with a big bang. Attackers often move unnoticed through corporate environments for weeks before striking.

Yet what if these risks were visible beforehand?

14:35 - 15:05
Thomas Naunheim's avatar
Thomas Naunheim
Cyber Security Architect at glueckkanja
Show description
Many organisations face the challenge of effectively securing their privileged users while also avoiding lateral movement paths when delegating privileged access. In addition, operating and further developing Privileged Admin Workstations (PAWs) generates significant effort and complexity.
15:10 - 15:40
Bonnie Viteri's avatar
Bonnie Viteri
Principal Technical Security Engineer at Yahoo
Show description
The SwissCyber Initiative (SCI) maps Switzerland’s cybersecurity ecosystem and examines current and future gaps in cybersecurity R&D, with a particular focus on companies and key cybersecurity subdomains. Combining a nationwide stakeholder survey with reworked and cleaned structured data from sources such as Crunchbase and ZEFIX, the project identifies perceived R&D gaps, emerging technologies and threat priorities, and the characteristics and geographical distribution of active organizations. It also reveals how companies are financed and by whom, offering an initial perspective on the digital sovereignty of Switzerland’s cybersecurity sector. These insights are integrated into a web-based platform that enables interactive exploration and comparison through smart filters. The presentation will highlight key findings from the R&D-gap analysis and demonstrate two use cases illustrating how survey insights, ecosystem data, and financing information can be combined to support evidence-based analysis of Switzerland’s cybersecurity landscape.
Antony Ancelin's avatar
Antony Ancelin
Technical Lead Incident Response at Swiss Post Cybersecurity
Show description

Self-managed infrastructure promises agility and autonomy. But what happens when it also slips outside the visibility of the teams responsible for defending it?

Our session examines a real-world incident in which an independently operated infrastructure became the starting point of a full-scale compromise inside an enterprise. The breach remained undetected until it was uncovered by luck rather than by security controls – highlighting how ownership gaps can quietly become security gaps.

15:40 - 16:20
16:20 - 16:50
Show description
Vulnerability Management just got even harder to do. An avalanche of AI-assisted attackers, combined with enormous waves of security updates, makes it even more challenging than it already was. As defenders, we know that there was security debt in keeping up with all the security updates, vulnerabilities, and defensive actions that we could take. Before AI, defenders were mostly able to keep up with patching. But now the security debt is due, and many of the defenders have trouble keeping up. Jeroen will present his ideas on efficiently dealing with the firehose of vulnerability information. We can finally let go of the CVSS score, focus on the technical and organisational aspects of vulnerabilities, with a way to lure the hidden IT systems out of the shadows.
Felix Linker's avatar
Felix Linker
Security Researcher at ETH Zurich
Show description
Conflict increasingly takes place online. And also aid providers, hospitals, and humanitarian organisations increasingly rely on digital infrastructure like servers and networks. In the physical world, the emblems of the Red Cross, Red Crescent, and Red Crystal identify protected sites such as hospitals, but no equivalent signal exists in cyberspace. The Digital Emblem project is building that missing signal: a machine-readable marker identifying digital infrastructure as protected under International Humanitarian Law.
16:55 - 17:30
Show description
What happens when the signals we learned to trust: a familiar voice, a local dialect, authority, belonging, even the feeling that “this person is one of us”, can be artificially manufactured? Cybersecurity has spent decades teaching users to behave more rationally. But social engineering succeeds precisely because humans do not make decisions like security systems, especially under pressure. In this closing keynote, behavioural analyst An Gaiser explores trust as both a human vulnerability and a security capability. Through live audience interaction, Swiss cultural cues, AI-enabled deception, investigative interviewing and behavioural science, she challenges one of cybersecurity’s most persistent ideas: that the human is simply the weakest link. If we treat the people we are trying to protect as the problem, why would they trust us enough to report when something has gone wrong? The future of cyber defence requires more than deciding what is real. It requires understanding why humans trust what they trust, and becoming worthy of that trust ourselves?
Show description
There is no talk on this track at this time, check the schedule of the Arena track instead.
Show description
There is no talk on this track at this time, check the schedule of the Arena track instead.
17:30 - 21:00
Show description
Our standing dinner allows everybody to mingle, meet friends and talk about the many interesting talks of the day. Naturally, most of the speakers will still be around, so don’t rush off after the last talk.
Show description
Our standing dinner allows everybody to mingle, meet friends and talk about the many interesting talks of the day. Naturally, most of the speakers will still be around, so don’t rush off after the last talk.
Show description
Our standing dinner allows everybody to mingle, meet friends and talk about the many interesting talks of the day. Naturally, most of the speakers will still be around, so don’t rush off after the last talk.
18:30 - 18:45
Show description
Distribution of prizes for the Sponsoring Raffle.
Show description
Distribution of prizes for the Sponsoring Raffle.
Show description
Distribution of prizes for the Sponsoring Raffle.
Copyright © 2026
 
Swiss Cyber Storm
Hosting graciously provided for free by Nine