KEYNOTES & BRIEFINGS
Talks on vulnerability research, incident response, and building security operations, for technical teams, business leaders, and the MSP community. More than 200 delivered since 2017.
Symmetric Chaos. Asymmetric Talent.
How attackers recruit insiders now, and what that means for your team.
From the meritocratic hacker crews of the 1980s BBS era to today's coercion-fueled "Com" ecosystem, threat actor recruitment has changed completely. Groups now find, pressure, and pay insiders over Telegram, and the person holding the keys is the target. Your perimeter is no longer your network. It's loyalty.
Best for: security leaders, HR and insider-risk teams, and executives.
- > The evolution from voluntary botnets to insider recruitment via Telegram
- > Indicators that someone on your team is being "tapped"
The Panic Gap
Why most IR plans fall apart the moment something real happens. Drawing from incident response work across hundreds of organizations, this talk examines what separates teams that respond effectively from those that spiral.
Best for: executives, IT leaders, and incident response teams.
- > Why playbooks fail when the breach hits
- > Closing the gap between detection and executive communication
Inside the Adversary Mindset
In 2011, Cody was on the other side. As a member of LulzSec, he took part in the Sony Pictures breach, then pleaded guilty and served his sentence. This talk takes that experience apart for defenders: how targets were chosen, what the reconnaissance looked like, and the psychological tactics the group used.
Best for: general audiences, executives, and practitioners who want to see a breach from the attacker's side.
- > How targets were chosen, and what made yours look vulnerable
- > The signals attackers look for before they strike
Building an Effective SOC
Cody built security operations from scratch to 24/7 coverage, and made most of the mistakes along the way. This talk distills those lessons into the critical decisions that determine whether your SOC becomes a detection powerhouse or an expensive alert factory. No vendor pitches. Just the workflow patterns that actually scale.
Best for: SOC managers, MSSPs, and security leaders building or scaling operations.
- > Why most SOCs drown in alerts instead of catching threats
- > The decisions that matter more than your SIEM
This Little Light of Mine
What happens when you can remotely control the lighting at major landmarks? Cody and Nick Schroeder found out. This original research walks through vulnerabilities they found in internet-connected industrial lighting controllers, the kind that illuminate stadiums, bridges, and buildings you'd recognize. It's a case study in how "smart" infrastructure creates attack surfaces no one is watching.
Best for: technical audiences, facilities and OT teams, and anyone responsible for building systems.
- > Authorized live demonstration against real-world ICS lighting controllers
- > Why your building management systems are the next attack surface
On Stage
SELECT PAST CONFERENCE PRESENTATIONS