Next event in:

CyberThreat wordmark logo
Register for CyberThreat 2026

Happening at Roundhouse, London on 16th-17th November. Register now for £1199 inc VAT.

CyberThreat logo mark

CyberThreat

CyberThreat is back, bringing together Europe's cyber security community for another groundbreaking two-day conference that promises to inspire and innovate.

CyberThreat is one of the largest cyber security conferences in the UK and aims to deliver the best technical conference for experts in the field. In addition to presentations from world-renowned cyber security experts and rising industry stars, CyberThreat features many hands-on opportunities for in-person delegates in the form of CTF events, team problem solving and hackable badge challenges to create an exclusive and unique experience.

"I really enjoyed the CyberThreat experience and my hats off to you and the team. You all pulled off one hell of a great conference!"

Ryan Nolette, Lead Cloud Security Architect at Arrowstreet Capital

Tailored for security practitioners, this immersive event covers both offensive and defensive disciplines, placing a significant focus on technical aspects. It provides exceptional value to cyber security professionals at all levels, fostering an environment where attendees can share experiences, knowledge, tools and techniques to advance the field.

Register for CyberThreat 2026

Attendees talking at CyberThreat 2023 A SANS employee talking to camera

Agenda

10:00-11:00

Registration and networking

11:00-11:10

Moderator opening remarks

Speaker photo

Ciaran Martin

Director, CISO Network

SANS Institute

Speaker photo

Paul Chichester

Director of Operations

NCSC

11:10-11:20

Capture The Flag briefing

Speaker photo

Simon Vernon

Principal Technical Architect

SANS Institute

11:20-11:45

The great rewrite: AI, geopolitics, and the new rules of cyber defence

Speaker photo

James Lyne

Chief Executive Officer

SANS Institute

11:45-12:15

How and why insider risks move from edge case to primary threat in 2026

Speaker photo

Thomas Mannie Wilkan

Head of Research

Lab-1

12:15-13:15

Lunch

13:15-13:45

We asked our AI Red Teaming agent to shut down a wind farm... so it did

Speaker photo

David Mound

Head of Research

Shinobi Security

13:45-14:15

Sandworm's Trojan Odyssey

Speaker photo

Thomas Padden

Principal Intelligence Analyst

BAE Systems

14:15-14:45

Npm install malware: Tracking two years of famous Chollima's obfuscation evolution

Speaker photo

Parthiban Rajendran

Threat Intelligence Lead

Atlassian

Speaker photo

Shiva Palaniappan

Senior Security Researcher

Microsoft

14:45-15:15

After Mythos: Operationalising vulnerability remediation in the age of AI-driven discovery

Speaker photo

Sylvain Cortes

VP Strategy

Hackuity

15:15-15:45

Networking break

15:45-16:15

Following the Relay: A DFIR Investigation into Ink Dragon's espionage network

Speaker photo

Eli Smadja

Director, Security Research

Check Point Software

16:15-16:45

The long phish: The evolution of identity-focused Russian espionage operations

Speaker photo

Mark Kelly

Staff Threat Researcher

Proofpoint

16:45-17:10

Closing keynote: Ukraine's cyber war playbook

Speaker photo

Ivan Kalabashkin

Deputy Head of Cyber Department

Security Service of Ukraine

17:10-17:20

Moderator closing remarks

Speaker photo

Ciaran Martin

Director, CISO Network

SANS Institute

17:30-19:30

Networking drinks

08:00-09:00

Doors open

09:00-09:10

Moderator opening remarks

Speaker photo

Ciaran Martin

Director, CISO Network

SANS Institute

09:10-09:35

Opening keynote: Title TBC

Speaker photo

Maciej Siciarek

Director of CSIRT Division

NASK

09:35-10:05

Inside BlueNoroff's fake meeting campaign

Speaker photo

Eoin Healy

Principal Threat Researcher

Arctic Wolf

10:05-10:35

Satellite receiver hardware penetration testing

Speaker photo

Salman Shakeep Abulatif

Cybersecurity Consultant

ISKRA Protect

10:35-11:05

Networking break

11:05-11:25

Title TBC

Speaker photo

Garry Byrne

Head of Incident Investigation & Response

Tesco

11:25-11:55

Inside Telegram's Russian payment gate network

Speaker photo

Adrian Dacka

Penetration Tester

Independent Security Researcher

11:55-12:25

Defending in a complex world: Sense-making for cybersecurity before the plan

Speaker photo

Anne Leslie

Head of Cloud Risk

IBM

12:25-13:25

Lunch

13:25-13:55

When AI agents become attackers

Speaker photo

Anna Lena Fehlhaber

Technology Strategy Lead AI/Cyber Security

Leibniz Universität Hannover

13:55-14:15

Technical session

14:15-14:45

Native functionality, native consequences: The engineering of cyber-physical effects

Speaker photo

Ric Derbyshire

Principal Security Researcher

Orange Cyberdefense

14:45-15:15

Burn after hacking: The effects of countering state espionage

Speaker photo

Alex Clarke Smith

Principal Consultant

Google Threat Intelligence Group (Mandiant)

15:15-15:25

Capture The Flag awards

15:25-15:30

Moderator closing remarks

Speaker photo

Ciaran Martin

Director, CISO Network

SANS Institute

Challenges

Attempt the pre-summit capture the flag challenges. The better the hack, the less you pay.

Attendee competing in the CTF at CyberThreat

The challenges are hosted on ranges.io, simply head over and sign up for a free account, then add the event code.

Visit: ranges.io

Event code: brisk-sand

There are various degrees of difficulty with the challenges. You are entitled to complete multiple challenges but the discount given will be up to the value of the hardest challenge you complete. For example, if you complete an 'Easy' challenge, then go on to complete a 'Medium', you will receive the 50% discount.

Once you have solved a challenge, please email the answer to cyberthreatctf@sans.org to receive your discount code.

#1 - Easy

Insider Image

Win a 25% off code

#2 - Easy

Curve Calamity

Win a 25% off code

#3 - Medium

Mighty Monolith

Win a 50% off code

#4 - Hard

Key Kerfuffle

Win a 75% off code

About CyberThreat

Presenter on stage at CyberThreat 2023 Person on the welcome desk at CyberThreat 2023

Empowering Europe's cyber security sector

Focusing on security practitioners and spanning the full spectrum of offensive and defensive disciplines, the event has a strong technical emphasis, encouraging collaboration on bleeding edge techniques, case studies from the field and new security tools.

Register for CyberThreat 2026

Two attendees talking at CyberThreat 2023

Why it exists

CyberThreat is hosted by the SANS Institute with the support of its founding partner; the UK's National Cyber Security Centre (NCSC). It evidences the UK Government's commitment to equip practitioners with the skills and knowledge required to defend against cyber threats and also addresses the cyber skills gap, by developing and growing talent.

CyberThreat aims to deliver the best technical conference globally for cyber security practitioners. In addition to presentations from world-renowned cyber security experts and rising industry stars, CyberThreat features many hands-on opportunities for delegates in the form of in-person CTF events.

Why you should attend

  • Watch inspiring keynote presentations delivered by renowned subject matter experts in the offensive, defensive and forensic fields.
  • Take part in the CyberThreat CTF; a super-technical, unpredictable and dynamic experience that allows you to participate as an individual or team up with your colleagues or friends.
  • Learn from SANS experts and hear unique insight from the UK's NCSC.
  • Network with like-minded security practitioners.
  • Attempt the interactive hackable badge challenge. Designed to test the most technically advanced delegates, the CyberThreat badge is, dare we say it, even more challenging than DEF CON's badges.
  • And much, much more...

Hosted by

SANS logo

With our founding partner

NCSC logo

Government Discount

Photo of the keynote speaker

CyberThreat 2026 Government Departments Discount

We are pleased to offer CyberThreat 2026 tickets to members of the UK and EU Governments at half the ticket price. Similar to previous editions, we are opening a ballot for members of the government. Through the form, a member of the team will be in contact, and you will be eligible for 50% off.

Learn more

50%
OFF

Location

Our next event will be held in London at the iconic Roundhouse in Camden, a historic performing arts venue originally built in 1847 as a steam engine repair shed before becoming one of London's most renowned music and cultural spaces.

Tube or Train

The nearest tube station is Chalk Farm on the Northern Line, just a 2-minute walk from the Roundhouse. Camden Town station on the Northern Line is approximately a 10-minute walk away. The nearest Overground station is Camden Road, around a 10-minute walk from the venue.

Bus

You can get to the Roundhouse using routes 24, 27, 31 and 168, which stop along Chalk Farm Road and Camden High Street, both a short walk from the venue.

Bicycle

There are cycle racks located outside the Roundhouse on Chalk Farm Road for those wishing to cycle to the venue.

Car

The Roundhouse is located in a busy central London area within the Congestion Charge and ULEZ zones. There is no on-site parking and parking nearby is very limited.

Air

The Roundhouse is approximately 10 miles from London City Airport, 20 miles from Heathrow Airport and 30 miles from Gatwick Airport.

Photo of Stamford Bridge

Code of Conduct

Attendees at CyberThreat 2023 playing with the hackable badge

All participants at CyberThreat are required to agree and adhere to the following code of conduct to help us achieve a safe and positive event experience for everyone. As organisers of this event, the NCSC Team and SANS are dedicated to providing a positive learning and sharing experience for all participants. We there for expect participants to conduct themselves appropriately. Unacceptable behaviour includes intimidating, harassing, abusive, discriminatory, derogatory, or demeaning conduct by any participant at our events or online communities including Twitter and other online media.

Harassment includes offensive verbal comments related to gender, gender identity and expression, age, sexual orientation, disability, physical appearance, race, ethnicity, religion, technology choices, sexual images in public spaces, deliberate intimidation, stalking, following, harassing photography or recording, sustained disruption of talks or other events, inappropriate physical contact, and unwelcome sexual attention. If a participant engages in behaviour that violates this code of conduct, the CyberThreat team may take any action they deem appropriate, including warning the offender or expulsion from the conference with no refund.

If you are being harassed, notice that someone else is being harassed, or have any other concerns, please contact a member of conference staff immediately. If you have any concern about inappropriate behaviour you witness at the event or online, please report this anonymously by emailing cyberthreat@sans.org and we will look into this and respond appropriately. In-person event staff can be identified by EVENT badges or can be found at the Information Desk.