Loading…
Streaming: https://mssvideo.vcu.edu/RVAsec
arrow_back View All Dates
Wednesday, June 10
 

7:59am EDT

Registration
Wednesday June 10, 2026 7:59am - 5:00pm EDT
If you were not able to attend Day 1, please proceed upstairs to register.
If you were able to register no need to go back to registration.

If you have any questions or issues please stop by for help.

This is also where you can turn in your Passport for Prizes.

WiFi sponsored by RVAsec:
Network is "RVAsec"
Password is "nevermore!"
Wednesday June 10, 2026 7:59am - 5:00pm EDT
Upstairs, Desk

8:00am EDT

Breakfast - Day 2
Wednesday June 10, 2026 8:00am - 8:50am EDT
Come downstairs and enjoy breakfast before the Day 2 welcome session!

Reminder the session starts earlier on day 2, be in your seats by 8:50am!

Menu:
  • TBD
Wednesday June 10, 2026 8:00am - 8:50am EDT
Downstairs, Foyer

8:50am EDT

Welcome - Day 2
Wednesday June 10, 2026 8:50am - 9:00am EDT
Welcome to Day 2 RVAsec 15!

Remarks will be provided about what to expect at the conference and many thanks to our volunteers and sponsors for making it possible.
Speakers
avatar for Jake Kouns

Jake Kouns

Founder, RVAsec
Jake is the founder of RVAsec and was previously the CEO for Risk Based Security that provides vulnerabilities and data breach intelligence. He previously oversaw the operations of the Open Sourced Vulnerability Database (OSVDB.org) and DataLossDB. Kouns has presented at many well-known... Read More →
Wednesday June 10, 2026 8:50am - 9:00am EDT
Upstairs, Grand Ballroom D/E/F/G

9:00am EDT

Dave Lewis - Keynote
Wednesday June 10, 2026 9:00am - 10:00am EDT
Dave has 30+ years of industry experience. He has extensive experience in IT security operations and management. Dave is the Global Advisory CISO for 1Password. He is the founder of the security site Liquidmatrix Security Digest & podcast. Dave also hosts the Chasing Entropy Podcast. He was a member of the board of directors for BSides Las Vegas for 8 years. He currently serves on the advisory boards of Byos.io and Knostic.ai.

Dave has previously worked in critical infrastructure for 9 years as well as for companies such as Duo Security, Akamai, Cisco, AMD and IBM. Previously he served on the board of directors for (ISC)2 as well as being a founder of the BSides Toronto conference.

For fun he is a curator of small mammals (his kids) plays bass guitar, grills, is part owner of a whisky distillery and a soccer team.
Speakers
avatar for Dave Lewis

Dave Lewis

Global Advisory CISO, 1Password
Dave has 30+ years of industry experience. He has extensive experience in IT security operations and management. Dave is the Global Advisory CISO for 1Password. He is the founder of the security site Liquidmatrix Security Digest & podcast. Dave also hosts the Chasing Entropy Podcast. He was a member of the board of directors for BSides Las Vegas for 8 years. He currently serves on the advisory boards of Byos.io and Knostic.ai.Dave has previously worked in critical infrastructure for 9 years as well as for companies such as Duo Sec... Read More →
Wednesday June 10, 2026 9:00am - 10:00am EDT
Upstairs, Grand Ballroom D/E/F/G

10:00am EDT

Vendor Break
Wednesday June 10, 2026 10:00am - 10:30am EDT
Go see our vendors in the Expo!

Menu:
  • TBS

Beverages: Starbucks Regular and Decaf Coffee, Assorted Pepsi Sodas, Hot Water with Assorted TAZO Herbal Teas, available throughout the day. Water stations will be located in all rooms upstairs and downstairs.
Wednesday June 10, 2026 10:00am - 10:30am EDT
Downstairs, Capital Ballroom

10:00am EDT

CTF Competition
Wednesday June 10, 2026 10:00am - 3:00pm EDT
As many of you know, we pride ourselves with this CTF being an all-inclusive learning CTF and not just a ‘stump the chump / who’s the best engineer in the room’ kind of CTF. That said, we need volunteers to come up with fresh ideas, challenges, and setups that are both fun and informative. Additionally, we do want to provide a challenge for those who show up looking for one, so if you are a more advanced user or admin and have some killer challenges that can stump someone, we’ll need those too for the higher tiers.

You’ll need a laptop to participate. Teams can have up to 4 people, or you may compete as an individual.
For those who like to come prepared, we suggest that you have a VM or two ready. You can download Kali Linux here (https://www.kali.org/downloads/) or get a free Windows VM here (https://developer.microsoft.com/en-us/windows/downloads/virtual-machines/). Some tools that might be helpful include CyberChef, BurpSuite, Ghidra, Pwntools, and Wireshark.

The MetaCTF team has been involved with the RVAsec CTF since 2016.

Thanks to RVAsec for sponsoring!
Wednesday June 10, 2026 10:00am - 3:00pm EDT
Downstairs, Capital Ballroom / Middle

10:00am EDT

HackRVA Badge Training & Repair
Wednesday June 10, 2026 10:00am - 4:00pm EDT
Come learn about your badge, get it fixed if there are any issues and talk to HackRVA!

HackRVA is a member-run and organized non-profit makerspace in Richmond, Virginia. HackRVA is a space filled with tools, computers, and people who like to build, invent, tinker, expand their minds, and learn and share new skills. You’ll find a diverse group of individuals who are into electronics, woodworking, embedded software, metalworking, programming, music, art, video, photography, 3D printing, sewing, textiles, and virtual reality—and that’s for starters. HackRVA members have access to the makerspace, tools, community and learning opportunities through member-lead workshops, events and projects.
Wednesday June 10, 2026 10:00am - 4:00pm EDT
Downstairs, Foyer

10:00am EDT

Lock Picking Village and Contest
Wednesday June 10, 2026 10:00am - 4:00pm EDT
A variety of example locks, from simple to extremely hard, along with a picks of all shapes and sizes will be available in our lock pick village.

Stop by and have some fun testing your skills! Provided hand sanitizer will be required to help reduce the modern risks while we explore the oldest security mechanism on earth!

If you fancy yourself a strong picker or have a competitive streak, we are planning to have a time contest of a series of locks, with the fastest through them all taking home something epic.
Wednesday June 10, 2026 10:00am - 4:00pm EDT
Downstairs, Shenandoah

10:30am EDT

The Interview Engine: A Career Readiness Framework
Wednesday June 10, 2026 10:30am - 11:20am EDT
Cybersecurity is about mitigating risk at acceptable cost, and hiring works the same way. This talk pulls back the curtain on how recruiting actually works, then gives security professionals an engineering-minded framework for staying career-ready without waiting for the layoff to start thinking about it.
Speakers
avatar for Vas Khomyk

Vas Khomyk

Sr. Recruiting Consultant, Hampton North
Vas Khomyk is a technical recruiter with Hampton North, a cybersecurity-focused recruiting firm. He runs retained and contingent searches across cybersecurity, defense, and enterprise IT, helping companies fill challenging roles from senior security engineering to VP-level leadership... Read More →
Wednesday June 10, 2026 10:30am - 11:20am EDT
Downstairs, Madison / Jefferson / Monroe

10:30am EDT

Breaking Your Silence: How to Build Influence Without Becoming a "Suit"
Wednesday June 10, 2026 10:30am - 11:20am EDT
In security, we’re taught to let our work speak for itself. But in the real world, "silent" expertise usually gets ignored, underfunded, or misunderstood. Whether it’s imposter syndrome whispering that your latest exploit wasn't "elite" enough or the hesitation to share a tool you built, these internal blockers limit your impact. This session is about moving past the "quiet professional" trap and building a reputation that matches your technical depth without losing your soul to corporate
Speakers
avatar for Heather Antoinetti

Heather Antoinetti

Founder and CEO, Ah-Ha Marketing
Heather Antoinetti is the CEO and founder of Ah-Ha Marketing, a boutique agency specializing in helping technical experts and thought leaders in the cybersecurity and technology sectors amplify their voices and establish authority. With nearly two decades of global marketing experience... Read More →
Wednesday June 10, 2026 10:30am - 11:20am EDT
Upstairs, Grand Ballroom D/E

10:30am EDT

From OSINT to Detection: Building an Agentic CTI Pipeline
Wednesday June 10, 2026 10:30am - 11:20am EDT
Modern threat intelligence moves fast, but detection engineering lags. This talk presents an agentic workflow that transforms OSINT into actionable detections using structured extraction, LLM reasoning, and automated validation. Transparent, auditable pipelines accelerate the CTI lifecycle, from ingestion to Sigma rules, while preserving analyst control, reducing time-to-detection from days to hours.
Speakers
avatar for Andrew Skatoff

Andrew Skatoff

Senior Manager Information Security, Federal Reserve Bank of Richmond
Andrew is a cybersecurity senior leader with over 20 years of experience protecting critical financial infrastructure within the national financial infrastructure. He leads large-scale programs spanning incident response, threat hunting, and detection engineering, and has served as... Read More →
Wednesday June 10, 2026 10:30am - 11:20am EDT
Upstairs, Grand Ballroom F/G

11:20am EDT

Vendor Break
Wednesday June 10, 2026 11:20am - 11:30am EDT
Go see our vendors in the Expo!

Beverages: Starbucks Regular and Decaf Coffee, Assorted Pepsi Sodas, Hot Water with Assorted TAZO Herbal Teas, available throughout the day. Water stations will be located in all rooms upstairs and downstairs.
Wednesday June 10, 2026 11:20am - 11:30am EDT
Downstairs, Capital Ballroom

11:30am EDT

The State of Information Security Today
Wednesday June 10, 2026 11:30am - 12:20pm EDT
The speaker has been in the Information (cyber) security since the late 1900s and will take a look back at the challenges we faced in the beginning and how these challenges have changed and evolved over the past several decades. You think we're doing okay? Let me change your mind.
Speakers
avatar for Jeff Man

Jeff Man

Co-Host, Paul's Security Weekly
Jeff is a respected Information Security advocate, advisor, hacker, evangelist, mentor, teacher, international keynoter, speaker, former host of Security & Compliance Weekly, co-host on Paul's Security Weekly, Tribe of Hackers (TOH) contributor, including Red Team, Security Leaders... Read More →
Wednesday June 10, 2026 11:30am - 12:20pm EDT
Downstairs, Madison / Jefferson / Monroe

11:30am EDT

Alert Fatigue Is a Misdiagnosis
Wednesday June 10, 2026 11:30am - 12:20pm EDT
"Alert fatigue" is a misdiagnosis of a deeper problem: the cognitive decay of the human defender. This talk brings the receipts on how a high-consumption information diet hijacks the prefrontal cortex — and why the answer isn't more automation, but rebuilding the creative muscle that makes humans worth keeping in the loop.
Speakers
avatar for Kim Mahan

Kim Mahan

Founding Apprentice, MAXX Potential
Kim Mahan is the Founding Apprentice at MAXX Potential, a technology consulting firm whose "earn-while-you-learn" model has produced hundreds of engineers‚ including cybersecurity professionals now at Capital One, AWS, Google and beyond. A CISSP and Six Sigma Black Belt with 20... Read More →
Wednesday June 10, 2026 11:30am - 12:20pm EDT
Upstairs, Grand Ballroom D/E

11:30am EDT

Flirting With AI: Pwning Web Sites Through Their AI Chatbot Agents
Wednesday June 10, 2026 11:30am - 12:20pm EDT
Everyone is implementing AI chatbots to improve their customer experience and journey, without increasing call centre costs. But this comes with risk: get the configuration wrong and that chatbot can be convinced to part with data that it shouldn't. We think of conventional cyber security controls as being binary, yet AI can sometimes hallucinate, lie and mislead. It's a brave organization that would trust their perimeter security exclusively to AI. We'll include some live demos to illustrate the problem.
Speakers
avatar for Paul Brownridge

Paul Brownridge

Head of Technical Delivery, Pen Test Partners
Paul Brownridge is Head of Technical Delivery at Pen Test Partners, the ethical hacking firm. Originally from an engineering background, Paul swapped his hard hat for a white hat and has been working in cyber security for the last 10 years. His practical experience of industrial environments... Read More →
Wednesday June 10, 2026 11:30am - 12:20pm EDT
Upstairs, Grand Ballroom F/G

12:20pm EDT

Lunch
Wednesday June 10, 2026 12:20pm - 1:00pm EDT
TBD


** Reminder this is a shorter lunch, talks start back up at 1pm **

Beverages: Starbucks Regular and Decaf Coffee, Assorted Pepsi Sodas, Hot Water with Assorted TAZO Herbal Teas, available throughout the day. Water stations will be located in all rooms upstairs and downstairs.

Seating: You are welcome to take your lunch to any area of the hotel. Banquet tables & chairs can be found on both sides of the Grand Ballroom upstairs. There is also seating downstairs in the Capital Ballroom (Expo). Please note these tables on Day 2 are reserved for the CTF. Various locations downstairs in the Foyer are also available.
Wednesday June 10, 2026 12:20pm - 1:00pm EDT
Downstairs, Foyer

1:00pm EDT

Unlocking Awareness: How an Escape Experience made Security Fun, Engaging, and Approachable
Wednesday June 10, 2026 1:00pm - 1:50pm EDT
How do you turn security awareness from a check‑the‑box activity into a hands‑on, memorable experience for everyone? In this session, we’ll unpack a portable “escape room in a box” designed by our Information Security team to make learning approachable, collaborative, and fun.
Speakers
avatar for Joanna Behan

Joanna Behan

Information Security Analyst, FRB of Richmond
Joanna is an Information Security Analyst who brings a unique blend of creativity and expertise to the field. With a Bachelor of Fine Arts from James Madison University and industry-recognized certifications including CISSP and CGRC, Joanna‚Äôs career spans more than two decades... Read More →
Wednesday June 10, 2026 1:00pm - 1:50pm EDT
Downstairs, Madison / Jefferson / Monroe

1:00pm EDT

Everything Everywhere All At Once: Untangling Security & Privacy Risks Across Today’s AI Tools
Wednesday June 10, 2026 1:00pm - 1:50pm EDT
AI adoption is exploding—but the security promises behind these tools often don’t match the fine print buried in their terms, models, or data flows. This talk cuts through the hype with a no‑B.S. look at the real privacy and security risks across today’s major AI platforms, and gives business leaders and security professionals a clear roadmap for deciding what’s safe, what’s risky, and what’s simply not ready for prime time.
Speakers
avatar for Jon Waldman

Jon Waldman

President, SBS CyberSecurity
Jon Waldman is the Co-Founder and President of SBS CyberSecurity, where he oversees the SBS service teams and the SBS Institute. For more than 20 years, Jon has helped hundreds of organizations identify and understand cybersecurity risks to allow them to make better and more informed... Read More →
Wednesday June 10, 2026 1:00pm - 1:50pm EDT
Upstairs, Grand Ballroom D/E

1:00pm EDT

Initial Access in 2026 – The Power of the Spoken Word
Wednesday June 10, 2026 1:00pm - 1:50pm EDT
Defensive detections and protocols have come a long way. The adoption of MFA was once the sign of a security minded client with a mature security posture but has reached the level of commonplace. Gaining initial access via email or web application has become so difficult that its often skipped entirely as companies opt to place the attacker on the inside of the network as the starting point. Yet, business compromises are on the rise. What are attackers using if they no longer rely on business email compromise as their go-to initial access vector. Well, as was the case with MGM, they’re often just picking up the phone.
Speakers
avatar for Mike Bailey

Mike Bailey

Computer Operator, Rotas

avatar for Ariyan Suroosh

Ariyan Suroosh

Principal Security Consultant, Rotas Security
Ariyan Bakhti-Suroosh is a Principal Security Consultant at Rotas Security, specializing in offensive security, social engineering, and physical facility penetration testing. With over seven years of experience, Ariyan has led enterprise-scale penetration tests, advanced adversary... Read More →
Wednesday June 10, 2026 1:00pm - 1:50pm EDT
Upstairs, Grand Ballroom F/G

1:50pm EDT

Vendor Break
Wednesday June 10, 2026 1:50pm - 2:00pm EDT
Go see our vendors in the Expo!

Menu:
  • TBD

Beverages: Starbucks Regular and Decaf Coffee, Assorted Pepsi Sodas, Hot Water with Assorted TAZO Herbal Teas, available throughout the day. Water stations will be located in all rooms upstairs and downstairs.
Wednesday June 10, 2026 1:50pm - 2:00pm EDT
Downstairs, Capital Ballroom

2:00pm EDT

AI SOC and Securing your Environment
Wednesday June 10, 2026 2:00pm - 2:50pm EDT
This discussion is designed to help teams figure out where AI fits in their environment from an analysis perspective, it is vendor agnostic and includes agentic deployments, as well as AI SOC services, novel attack vectors from independent research, and the overarching philosophy of how the threat landscape has just massively changed and how to adapt to it.
Speakers
avatar for Ryan Bird

Ryan Bird

Security Engineer, GuidePoint Security
Ryan Bird moved to the MVA area in 2017 with his wife. He helped train the United States Army in their ASOT level one program as well as MCTOG in 29 Palms through 2019 with Obsidian Solutions Group before working at Annapolis Defense in a Maritime Security role. After Covid hit he... Read More →
Wednesday June 10, 2026 2:00pm - 2:50pm EDT
Downstairs, Madison / Jefferson / Monroe

2:00pm EDT

Swatting Flies With Sledgehammers: Broken TPRM Programs and How To Fix Them
Wednesday June 10, 2026 2:00pm - 2:50pm EDT
Third-party and supply chain risk is more important now than ever—but TPRM is also more broken and ineffective than ever. This session will review today’s common approaches to TPRM, how we got here, and how we can achieve better outcomes and reasonable assurance with less work. We’ll also explore what that shift could mean for our security programs—and for the industry as a whole. We need a hard reboot, and it has to start with each of us.
Speakers
avatar for Brian Markham

Brian Markham

CISO, EAB Global, Inc.
Brian Markham is an executive, advisor, hacker, and mentor with over 25 years of experience in IT and cybersecurity. Brian currently serves as the Chief Information Security Officer for EAB Global, a leading provider of software, marketing, and research services to institutions of... Read More →
Wednesday June 10, 2026 2:00pm - 2:50pm EDT
Upstairs, Grand Ballroom D/E

2:00pm EDT

Catching Collection in M365: Outlook and SharePoint Canary Tokens
Wednesday June 10, 2026 2:00pm - 2:50pm EDT
After a stolen token grants access to M365, the next move is predictable: search for value before exfiltration. This talk shows how to detect that collection phase using canary tokens built on native telemetry across Outlook and SharePoint/OneDrive. We cover end-to-end implementation and results from live production deployments, including what produced high-fidelity signal and what created noise.
Speakers
avatar for Ryan O'Donnell

Ryan O'Donnell

Senior Security Engineer, Microsoft
Ryan O'Donnell is a Senior Security Engineer at Microsoft. Over the last 13+ years, he's been performing Penetration Tests, Red Team assessments, and Incident Response investigations. Ryan has presented at the followinhttg conferences: Wild West Hackin' Fest, Saintcon, Hack Space... Read More →
Wednesday June 10, 2026 2:00pm - 2:50pm EDT
Upstairs, Grand Ballroom F/G

2:50pm EDT

Vendor Break & Room Change
Wednesday June 10, 2026 2:50pm - 3:10pm EDT
Room change!

We need all attendees to leave both sides of the ballroom quickly as possible so we can open the room for the final session and reception..

Go see our vendors in the Expo!

Beverages: Starbucks Regular and Decaf Coffee, Assorted Pepsi Sodas, Hot Water with Assorted TAZO Herbal Teas, available throughout the day. Water stations will be located in all rooms upstairs and downstairs.
Wednesday June 10, 2026 2:50pm - 3:10pm EDT
Downstairs, Capital Ballroom

3:10pm EDT

Use It Monday: A 5-Step Method for Turning Security Findings Into Stories Executives Act On
Wednesday June 10, 2026 3:10pm - 4:00pm EDT
Security teams produce thorough, accurate reports that executives nod at and never act on. This talk teaches a practical 5-step method for translating findings into narratives that produce decisions — one you'll practice live and use Monday morning.

Speakers
avatar for Victoria Mosby

Victoria Mosby

Founder, Basilisk Security Advisory
Victoria Mosby is a cybersecurity strategist, advisor, and storyteller with 16 years of experience spanning federal consulting, governance and risk, and cybersecurity SaaS. She is the founder of Basilisk Security Consulting, a boutique advisory practice focused on security communication... Read More →
Wednesday June 10, 2026 3:10pm - 4:00pm EDT
Upstairs, Grand Ballroom D/E/F/G

4:00pm EDT

Closing Reception & Awards
Wednesday June 10, 2026 4:00pm - 5:30pm EDT
The closing will take place right after the final talk.  We will have a short break for attendees to get their beverages & Hors d'oeuvres, and then we will do Passport and Lockpick Prizes and CTF awards.

Please note:
Food and drink will not be served until the final talk is completed, so go watch the talk!

Menu:
  • TBD

Bar:
  • Premium Wines: Trinity Oaks - Cabernet Sauvignon, Pinot Noir, Pinot Grigio, Chardonnay
  • Domestic Beer: Yuengling, Michelob Ultra
  • Import Beer & Seasonal Crafts: Corona, Stella, Blue Moon, Local IPA, Local Cider
  • Premium Liquor: Titos Vodka, Citadelle Gin, Cruzan Rum, Jose Cuervo Tequila, Jim Beam Bourbon, Dewar's White Label Scotch, Jack Daniels Whiskey
  • Assorted Pepsi Products, Water and Non-Alcoholic Juices/Punch

Speakers
avatar for Chris Sullo

Chris Sullo

Founder, RVAsec

Wednesday June 10, 2026 4:00pm - 5:30pm EDT
Upstairs, Grand Ballroom D/E/F/G
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -