Speakers & Contributors
A directory of the cyber defenders, engineers, and researchers who have delivered high-signal, zero-sales technical talks across Scotland.
Sorcha Lorimer
Founder · Trace Data
"Privacy by Design & Data Ethics"
Translating data privacy regulations into clear, ethical engineering practices and transparent customer consent models.
Laura Irvine
Partner & Regulatory Specialist · Davidson Chalmers Stewart
"Cyber Law & Regulatory Exposure"
Navigating regulatory expectations, GDPR compliance realities, and legal duties following serious security incidents.
Jai Aenugu
Founder & Podcaster · TechTV
"Startup Security Realities"
Balancing rapid startup velocity with essential security baselines.
Anoop Joshi
Senior Security Engineer · Skyscanner
"Securing Cloud Workloads at Scale"
Continuous compliance, automated guardrails, and container security patterns in large-scale multi-account AWS environments.
James Walsh
Director of Cyber Security Practice UK&I · Hays
"The Cyber Market for Scotland and Beyond"
James has over 15 years specialising in Cyber/Information Security working with some of the largest Private and Public Sector organisations. He will provide an update on cybersecurity market trends, talent demand, and recruitment dynamics across Scotland and beyond.
Gerry Grant
Chief Ethical Hacker · Curious Frank / CCS
"Deconstructing the Breach: Real-World Lessons"
Case studies from incident response trenches: common misconfigurations, lateral movement techniques, and practical remediations.
Sarah Clarke
Director · Infospectives
"Ethical Dilemmas in Incident Response"
Navigating ethical responsibilities, privacy rights, and corporate transparency in the heat of a security crisis.
"Governance, Risk & Human-Centred Security"
Exploring paths into GRC and security governance, bridging legal, business, and technological requirements.
Tash Norris
Head of Cyber Security · Photobox Group
"Building Security Culture from Scratch"
Practical strategies for embedding security champions and positive engineering engagement within fast-growing software organisations.
Ian Murphy
Founder & Ethical Hacker · CyberOff
"Real-World Cyber Security & Social Engineering"
A frank, humorous, and sobering dive into social engineering, physical penetration testing, and human behavior in infosec.
Craig McIntyre
Senior Security Engineer · Skyscanner
"Securing Cloud Workloads at Scale"
Continuous compliance, automated guardrails, and container security patterns in large-scale multi-account AWS environments.
Holly Grace Williams
Managing Director · Secarma
"Tales from the Offensive Frontline"
Behind the scenes of complex offensive penetration testing operations: lessons defenders rarely hear.
Colin Cassidy
Principal Security Consultant · IOActive
"ACME Windpharm"
The talk covers the basics of windfarms and their operations, diving into identified security threats and mitigations based on real-life assessments. Colin explores physical and remote access vectors, security hygiene gaps, and lessons from the recent 2025 Polish renewables attack. Key takeaways bust the myth that 'cutting off supply' is the primary danger, demonstrating practical cyber-physical vectors that can lead to actual physical equipment damage.
Sophie Lanc
Community Moderator & Brand LeadCommunity Organiser · Cyber Scotland Connect
"Cyber Scotland Week: Empowering Grassroots Communities"
Opening Cyber Scotland Week 2026 with a celebration of grassroots initiatives, student mentorship, and cross-sector cyber resilience.
Waqas Ahmed
Principal Security Architect
"Architecting for Distributed Teams"
Transitioning legacy VPN concentrators to zero-trust access brokers in weeks instead of years.
The Turing's Testers
Student Initiative · dressCode
"Championing the Next Generation of Girls in Cyber"
Inspiring female school students into computing science, cyber competitions, and addressing the early-stage gender gap in tech.
Rich Macfarlane
Community ModeratorCybersecurity Lecturer · Edinburgh Napier University
"Hardware Attacks & Physical Security Analysis"
Practical demonstrations of side-channel attacks, hardware hacking, and firmware reverse engineering.
"Educating & Training Cyber Students Remotely"
Re-imagining practical lab exercises, virtual CTFs, and keeping student communities connected while campuses were shut.
Scott McAndrew
Systems Engineer · Palo Alto Networks
"Next-Generation Network Architecture"
Securing hybrid cloud perimeters and applying zero-trust segmentation across modern enterprise infrastructure.
Tia Hopkins
VP of Global Solutions Architecture · eSentire
"Navigating Cyber Career Pathways"
Strategies for breaking into infosec, continuous upskilling, and finding mentors across the global cyber community.
Magda de Jager
Community ModeratorSecurity Operations Specialist · N-able
"Transitioning into Security Operations"
Actionable guidance on transitioning from adjacent technical or non-technical domains into frontline security analysis.
"Culture, Inclusion & Community in Scottish Infosec"
Why welcoming diverse backgrounds is essential to tackling Scotland's cyber skills shortage.
Harry McLaren
Co-Founder & OrganiserCo-Founder · Cyber Scotland Connect
"Cyber Scotland Week: Empowering Grassroots Communities"
Opening Cyber Scotland Week 2026 with a celebration of grassroots initiatives, student mentorship, and cross-sector cyber resilience.
"Autumn Community Catch-up & 2026 Roadmap"
A relaxed community evening celebrating new chapter initiatives and previewing upcoming conferences.
"State of the Scottish Cyber Community"
Reflections on regional growth, ecosystem partnerships with ScotlandIS and CyberScotland, and community roadmap.
"Cyber Scotland Connect Reconnect"
Welcoming the community back in person after three years of pandemic disruption, detailing CSC's roadmap for regular regional meetups.
"Welcome to Cyber Scotland Connect"
The vision behind merging two thriving Scottish infosec communities into an inclusive, regular, community-led platform.
"Uniting Scotland's Cyber Community"
Announcing the unification of regional Scottish meetups under Cyber Scotland Connect.
Stuart Peck
Head of Cyber Strategy · ZeroDayLab
"Responding to Global Ransomware Outbreaks"
Strategic incident response insights and operational analysis following the global WannaCry and NotPetya waves.
Toni Scullion
Computing Science Educator & Founder · dressCode
"Championing the Next Generation of Girls in Cyber"
Inspiring female school students into computing science, cyber competitions, and addressing the early-stage gender gap in tech.
Scott McGready
Host & Producer · The Cyber Security Cafe
"Remote Culture & Social Isolation in Security"
Addressing the psychological toll of isolation, fatigue, and constant crisis response during nationwide lockdowns.
Callum Butler
Security Specialist · Rapid7
"Offensive Security in the Wild"
Modern penetration testing techniques, red team methodology, and what defenders need to know about post-exploitation activities.
Andrew Gravett
Security Specialist (Discord: andyg)
"UK Post-Quantum Cryptography (PQC) 2026 - State of the Nation Update"
State of the nation update on UK Post-Quantum Cryptography (PQC) in 2026, exploring implementation pathways, crypto-agility, transition deadlines, and practical engineering readiness.
Chelsea Jarvie
Education Scotland
"Cyber Security Education in Scotland"
Building future infosec talent pipelines across Scottish schools and communities.
Kevin Gray
Community ModeratorInformation Security Manager · NHS Scotland
"Defending Healthcare During a Pandemic"
Rapidly scaling secure telehealth services and safeguarding critical healthcare logistics against opportunist threat actors.
"Healthcare Resilience Lessons"
Managing critical clinical infrastructure when systems and procedures meet reality.
Ken Munro
Pen Test Partners
"IoT Vulnerabilities & Doll Hacking"
Demonstrating hardware and Bluetooth security vulnerabilities in connected consumer devices.
Ash Hunt
CISO & Enterprise Security Leader · Ash Hunt
"Refactoring the Enterprise"
The static control architecture we've built over the past two decades is about to die. SaaS is being pushed into a reformed middleware by the new agentic operating layer, forcing security functions to rethink how controls are designed to enable enterprise 5.0. Data-centric, context-based automation will be unavoidable if security functions want to keep pace with the high velocity business activity of the future.
Jamie O'Hare
Student Leader · ENUSec
"The Next Generation of Cyber Talent"
How student cyber societies bridge academic training and industry demands through hands-on labs and competitions.
Gerry Magennis
Security Specialist · Rapid7
"Offensive Security in the Wild"
Modern penetration testing techniques, red team methodology, and what defenders need to know about post-exploitation activities.
Dave McK
Senior Security Leader
"Incident Response Under Extreme Pressure"
Crisis decision-making, stakeholder communication, and technical recovery when core business infrastructure goes dark.
Federico Charosky
Community Moderator (Alumni)CEO · Quorum Cyber
"Navigating Enterprise Ransomware Incidents"
Lessons from the cyber emergency trenches: ransomware extortion tactics, negotiations, and incident containment.
"What Hiring Managers Actually Look For"
Demystifying entry-level recruitment in cyber: why attitude, curiosity, and problem-solving beat certification memorization.
"Modern Threat Hunting & Managed Detection"
Moving beyond passive alert monitoring to proactive threat hunting and intelligent adversary tracking.
The Beer Farmers
Infosec Collective · The Beer Farmers
"Mental Health & Authenticity in Security"
Breaking the stigma around burnout, impostor syndrome, and mental health challenges facing security practitioners.
Stu Hirst
Co-Founder & OrganiserCo-Founder · Cyber Scotland Connect
"Cyber Scotland Connect Reconnect"
Welcoming the community back in person after three years of pandemic disruption, detailing CSC's roadmap for regular regional meetups.
"Welcome to Cyber Scotland Connect"
The vision behind merging two thriving Scottish infosec communities into an inclusive, regular, community-led platform.
"Uniting Scotland's Cyber Community"
Announcing the unification of regional Scottish meetups under Cyber Scotland Connect.
"Welcome & The Vision for Security Scotland"
Inaugural remarks setting out the ambition to build Scotland's premier grassroots infosec community.
Sean Wright
Application Security Researcher · Independent
"Software Security Confessions"
The overlooked flaws in development pipelines and third-party libraries.
Angus Skinner
Security Practitioner
"Self-Directed Cyber Skills Acquisition"
Leveraging CTFs, home labs, and open community resources to build practical offensive and defensive skills.
Gary Hunter
Community ModeratorSecurity Operations Leader · Trustpilot
"Building Cross-Regional Cyber Communities"
Strengthening ties between Edinburgh, Glasgow, and Dundee cybersecurity ecosystems.
"Incident Response Automation & Modern SOC Metrics"
Practical strategies for streamlining alert triage and building resilient security engineering workflows.
"Lessons from the SOC Trenches"
False positives, misconfigured alerts, and real stories from round-the-clock monitoring.
Javvad Malik
Lead Security Awareness Advocate · KnowBe4
"Uncomfortable Infosec Truths"
A candid panel exploring human errors, near-misses, and why acknowledging mistakes makes security teams stronger.
Richard Grey
Community ModeratorIdentity Specialist · Bright Group
"Identity & Access Misadventures"
When privilege escalation and IAM policies don't go according to plan.
Share Your Defense Lessons with Scotland
Have you built an interesting detection pipeline, analyzed threat adversary tradecraft, or learned painful architectural lessons during an incident? We actively mentor and welcome first-time speakers, student researchers, and seasoned CISOs alike.