2026-10-03 –, STAGE 2 (Ghost in the Shellcode) Language: English
Over the years as a cybersecurity pre-sales engineer, I've had the privilege of seeing organizations prepare to defend themselves against sophisticated attackers, ransomware gangs, zero-days, and nation-state threats. Sometimes, however, the biggest security problem was much closer to home.
A company wants NAC, but there's no IdP. Another wants PAM while every workstation shares the same local administrator password. Someone wants an anti-spam solution while SPF, DKIM and DMARC are not configured properly. I've encountered passwords stored in passwords.txt, environments where every machine is administered individually.
These aren't just funny war stories. They reveal a recurring problem: security products have prerequisites.
NAC and EDR assume you can manage your endpoints. Vulnerability management assumes you know what assets you have. SIEM assumes you have useful logs and someone who can act on them. Zero Trust assumes you have some idea who your users, devices and applications actually are.
This talk is a collection of strange, surprising and sometimes painful lessons from the security pre-sales trenches, and an argument for asking an uncomfortable question before buying the next security product:
“What should we fix first?”
Because sometimes the most useful thing a security vendor can tell you is:
“You don't need our product yet.”
I'm a cybersecurity Pre-Sales Engineer and Security Architect with over 12 years of experience designing, implementing, and integrating enterprise security solutions across organizations of every size and scale.
In my spare time, you'll probably find me reversing binaries, solving CTF challenges, building random lab environments, or disappearing down a rabbit hole of some new technology that caught my attention. I enjoy taking things apart, understanding the details, and putting them back together, ideally better than before.