7–9 Apr 2026
Jaarbeurs Supernova
Europe/Amsterdam timezone

Security Days Organisational Committee

Session

Unconference Session

7 Apr 2026, 16:30
Jaarbeurs Supernova

Jaarbeurs Supernova

Utrecht, Netherlands

Conveners

Unconference Session: NIS2 CSIRTs

  • Thijs Kinkhorst (SURF)
  • Floor Jas (SURF)

Unconference Session: Scenario session: How can we prepare for our greatest fears?

  • Charlie van Genuchten (SURF)

Unconference Session: Offensive Security Testing

  • Joost Gadellaa (SURF)
  • Abdul Altawekji
  • Charlie van Genuchten (SURF)

Description

At SURF, we've been pilotting several types of offensive security testing for a few years now. This ranges from attack surface mapping, vulnerability scanning and cloud configuration assessment all the way to SOC-chain tests, pentests and red teaming. We are planning to group some of these efforts in a service to our members, also taking some roles in gathering fidings, making sure others can learn from those and managing follow-up by our members.

We would like to brainstorm with other NRENs how we can serve our members with this type of service. We imagine a session where several NRENs can share what they do, why and how (products, setup, governance) to then split into groups discussing specific topics. Questions we are facing that might be a start:
- When doing vulnerability scans, who has an up-to-date list of assets?
- What does a business case for doing this as an NREN look like? How do you pay for it?
- What open source tools can be used for the different types of tests, how do you host/procure them?
- Are our members ready for full-fledged red teaming exercises?
- How do we relate this to crisis exercises?

Presentation materials

There are no materials yet.

  1. Floor Jas (SURF), Thijs Kinkhorst (SURF)
    07/04/2026, 16:30
    Unconference
    Unconference Ideas

    This session is specific for CSIRTs are or will be formally appointed as a CSIRT under the NIS2 directive (article 10.1). We'd like to strenghten bonds and exchange experiences and ideas about the impact on the team's services portfolio, understand how governance and funding works for this role, and what challenges are faced. The goal is that we can help each other take on this new task in the...

    Go to contribution page
  2. Charlie van Genuchten (SURF)
    07/04/2026, 16:30
    Unconference
    Unconference Ideas

    A session to combine our knowledge to discuss what could happen in case our greatest fears would become reality.
    Setup of the session:

    • Everyone writes down one or two scenarios that they are concerned about (could be geopolitical, climate based or something different)
    • We all vote which 2 or 3 we feel is most likely and impactful
    • Then we have discussions in groups going through...
    Go to contribution page
  3. Abdul Altawekji, Charlie van Genuchten (SURF), Joost Gadellaa
    09/04/2026, 09:00
    Unconference
    Unconference Ideas

    At SURF, we've been pilotting several types of offensive security testing for a few years now. This ranges from attack surface mapping, vulnerability scanning and cloud configuration assessment all the way to SOC-chain tests, pentests and red teaming. We are planning to group some of these efforts in a service to our members, also taking some roles in gathering fidings, making sure others can...

    Go to contribution page
Building timetable...