Workshop | Take the Helm: Living Through a Cyber Crisis

You’re the CIO of a mid-sized company. It’s Saturday morning, systems are down, and nobody can tell you
why. In this hands-on workshop, you take the helm of the victim organization and live through an incident
from the inside — not as a forensic exercise, but as the operational and human scramble it really is.
Working in small teams, you’ll get a network diagram, a set of backups you think you have, and 30
minutes to make sense of what’s happening and produce a plan. Then we start asking the questions that
hurt: Who’s talking to the press? Do you have legal counsel on retainer? What do you tell the journalist
who just got tipped off by someone inside? Where’s the documentation you needed an hour ago? Injects
land in real time and the picture keeps changing. In the final segment we debrief together and connect
every painful moment back to the controls, documentation, and incident response plans that would have
made it easier — drawing on established response frameworks and public playbooks you can take home
and use. Come prepared to decide under pressure. Facilitated by two practitioners who have run and
lived through the real thing.

What participants will take away
1. Where preparation actually pays off — documentation, asset inventory, and tested backups stop being
abstractions the moment you need them and don’t have them.
2. The crisis behind the incident — technical containment is only half the job; press, legal, executive, and
client communications run in parallel and on a faster clock.
3. How to think under capacity overload — recognizing when the team is past its limits, and what to triage,
delegate, or escalate.
4. Decision-making with incomplete information — practising the calls you’ll have to make before you have
the full picture.
5. A concrete set of resources — response frameworks and public incident response playbooks, mapped to
the specific questions the drill raised.


Who it is for
Open to the full BSides audience — analysts, engineers, consultants, GRC, and managers. No prior incident
response experience is required, and the exercise is deliberately not deeply technical: the skills practised here
are the ones that matter as participants move into leadership roles where an incident becomes a business crisis.
Analysts get a preview of the decisions their future selves will make; managers and executives get repetitions
they rarely get outside a real event.

Bio:

Stefan Timotijević — Founder & CEO of Akbko and creator of CyberSensei.ai, and founder of the nonprofit
Hackeurs Sans Frontières (hsf.sh). 25+ years across governance, compliance and resilience, including CISO-level roles in retail, defence and aerospace. Designs and runs cyber crisis simulations.
Alexandre Blanc — Cyber risk and network architecture expert, ranked 4th in Favikon’s Top 50
cybersecurity experts in Canada. LinkedIn Top Voice in Technology and Cyber Sentinel Award laureate,
with two decades protecting sensitive infrastructure and analyzing the global threat landscape daily.

Workshop 2 | Windows Forensics for Insider Threat

Windows Forensics for Insider Threat is an immersive workshop built for beginners looking to get into digital forensics to uncover the traces of malicious insider activity. This session focuses on the artifacts that insiders leave behind when interacting with Windows systems — covering file access, program execution, USB storage usage, Recycle.Bin analysis, disk imaging, file recovery, and browser activity. Through guided activities, you’ll learn how to connect these evidence sources into meaningful timelines that reveal intent, method, and impact.
No prior forensics experience is required. We’ll start from first principles, explain how and why artifacts are created, and guide you through hands-on exercises that demonstrate how investigators reconstruct user actions from raw evidence.
Note: This will mostly be repeated content of last years Windows Forensics for Insider Threat if you have already taken the workshop.
Attendees should have:
•A Windows 10/11 environment (native or virtual) with admin rights.
•Ability to work with disk images and external media.
•Adequate storage (~10 GB free).
•Access to PowerShell and command-line utilities.
Pre-requisites for attendees:
– A working knowledge of Windows internals and basic DFIR concepts (artifacts, imaging, hashing) is recommended.
– Some prior exposure to security operations or investigative workflows will help maximize the value of the exercises.
– A full list of required tools and data sets will be distributed to registered attendees in advance.

Bio: Tyler Chevrier, is a Senior Cybersecurity Specialist at Commissionnaires du Quebec and a part-time Cyber Operator for the 34 Signal Regiment. With a specialization in Digital Forensics and Incident Response, Tyler holds 5 years of experience in the field consulting and leading real-world DFIR investigations. Tyler has delivered numerous presentations on digital forensics and penetration testing concepts.

Places limitées

Un montant symbolique est demandé à l’inscription pour confirmer votre intérêt. Veuillez noter que les workshops ne sont offerts qu’en anglais.