BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//INTERSCT. - ECPv6.17.4//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:INTERSCT.
X-ORIGINAL-URL:https://intersct.nl
X-WR-CALDESC:Events for INTERSCT.
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:Europe/Amsterdam
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20240331T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20241027T010000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20250330T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20251026T010000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20260329T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20261025T010000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=Europe/Amsterdam:20250616T084500
DTEND;TZID=Europe/Amsterdam:20250616T183000
DTSTAMP:20250611T150902Z
CREATED:20250514T153621Z
LAST-MODIFIED:20250611T150902Z
UID:5537-1750063500-1750098600@intersct.nl
SUMMARY:2025 INTERSCT. Conference
DESCRIPTION:Introduction\n			\n				\n				\n				\n				\n				With the Internet-of-Things (IoT) we are seamlessly connecting the cyber and the physical worlds extending the risk area to safety requiring a broader perspective on security. IoT is turning out to be one of the weakest spots in our infrastructure. With billions and in the near future potentially trillions of devices\, the security risks are growing at great rates. Our economic and societal forces are creating a perfect storm\, a pervasive infrastructure of trillions of IoT devices which on one hand will oversee our lives and economy\, and on the other hand will be completely unmanageable from a security perspective. \nTo compound the risk\, IoT systems are often devised and engineered in places where we have no control on\, and unless we want to basically surrender our digital sovereignty by only relying on foreign solutions for our national cyber security\, we need to find a way to secure them regardless of provenance and built-in malicious intents. \nWe cannot secure something we cannot manage\, we need to rethink the security paradigm\, delegating part of the security management to the system that needs to autonomously adapt to the changing environment\, while remaining under our supervision\, and rethink accordingly all our security technologies. We need to be able to design\, develop and manufacture IoT systems-of-systems in a fundamentally different way enabling the overall system to become robust\, resilient and trustworthy\, even in the presence of individual IoT devices that are insecure or even compromised in a Zero-trust environment and providing the right ecosystem for their wide adoption within industry. We actually need to be able to design\, develop and manufacture new types of IoT devices with security-by-design\, privacy-by-design\, resilience-by-design and all by-default\, robustness and resilience in mind; while continuously preserving all safety requirements\, these devices must pro-actively manage their security\, actively respond to attacks\, recover from attacks\, resume and restore themselves to a predefined level of operation following an attack etc.\, \nDuring the 2025 INTERSCT. Conference on cyber security of Internet-of-Things\, on 16 June 2025 at the Huygens Building of Radboud University Nijmegen\, we will address many of these issues with an impressive line-up of invited speakers\, panelists\, and moderators. There will be keynote addresses by Elisa Costante\, Éireann Leverett and Jeroen van der Ham (UT)\, two series of parallel sessions related to the various work packages in the NWO NWA INTERSECT project (Design\, Defense\, Attack\, and Governance)\, a series of plenary sessions related to the state-of-the-art in cyber security of Internet-of-Things\, as well as a networking lunch and a networking reception at the end of the event. \n			\n				\n				\n				\n				\n				\n					\n					\n						\n						Programme\n					\n				\n			\n				\n				\n				\n				\n				\n					\n					\n						08:45 - 09:25 Reception + Networking\n						 \n					\n				\n			\n				\n				\n				\n				\n				\n					\n					\n						09:25 - 09:30 Opening by dr. Erik Poll\n						\n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Erik Poll\n					Radboud University Nijmegen \n					\n					\n				\n			\n			\n				\n				\n				\n				\n			\n				\n				\n				\n				\n				\n				\n				\n				\n				\n				\n				\n					\n					\n						09:30 - 10:45 First series of parallel sessions\n						\n					\n				\n			\n				\n				\n				\n				\n				\n					\n					\n						09:30 - 10:45 Parallel session on WP2 ("Design") \n						Moderated by dr. Erik Poll \nProgramme \n\nIntroduction by Erik Poll (RU)\nJan Rooduijn (NCSC)\, “New developments & trends in SAST“\nSwarna Kumarswamy-Das (TNO)\, “Cyber resilient SE design methodology“\nXavier de Carné de Carnavalet (RU)\, “Home router security\, habits & attitudes“\n\n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Erik Poll\n					Associate professor at Radboud University Nijmegen \n					Erik Poll will present an introduction to the objectives and (intermediate) results of WP2. \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Jan Rooduijn\n					Netherlands National Cyber Security Center (NCSC) \n					Title\nNew developments in static analysis \nSummary\nThis talk presents findings from a study conducted by the NCSC\, combining a literature review and a survey of 44 Dutch software developers on the use of static application security testing (SAST) tools. It compares modern and established tools\, highlights common challenges developers encounter in their use\, and offers a set of modest recommendations. \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Swarna Kumarswamy-Das\n					TNO \n					Title\nCyber resilient SE design methodology \nSummary\nCyber security is now an essential prerequisite for a secure society. There is an increased dependence on digital products and systems while the environments in which they operate are complex and dynamic. This makes securing them challenging. Hence there is a growing need to design inherently resilient products and systems with the ability to prevent\, withstand\, recover\, and adapt from incidents. This benefits business continuity\, reducing the cost of damages\, product updates and recalls\, thereby lowering overall life cycle and operating costs. This talk will showcase TNO’s research and vision on cyber resilient system design. This methodology shows the synergy between systems engineering and cybersecurity. Furthermore\, this presentation shows initial ideas on how autonomous cyber resilience can be applied at different levels while designing systems. \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Xavier de Carné de Carnavalet\n					Radboud University Nijmegen \n					Title\nUser Configuration Practices and Security Risks in Home Router Defaults \nSummary\nIn an online survey of 392 participants from various regions\, we find that 91% of home routers operate with default settings. We also examine how users approach router setup and maintenance\, revealing that many rely on minimal configuration and a significant number never update their firmware. These behaviors\, shaped by region\, age\, and IT background\, leave devices exposed to persistent risks. Motivated by these insights\, we analyzed 40 recent commercial routers across 14 brands and uncovered widespread security flaws in default configurations and basic feature implementations. We identified a total of 89 weaknesses and vulnerabilities. To support future assessments\, we developed a threat-model-based analysis framework. Our findings and methodology offer actionable insights for users\, manufacturers and researchers aiming to improve the security of consumer routers. \n  \n					\n				\n			\n				\n				\n				\n				\n				\n					\n					\n						09:30 - 10:45 Parallel session on WP4 ("Attack") \n						Moderated by prof. dr. ir. Herbert Bos and dr. Cristiano Giuffrida \nProgramme \n\nIntroduction by Herbert Bos / Cristiano Giuffrida\nSander Wiebing\, “Training Solo: On the Limitations of Domain Isolation Against Spectre-v2 Attacks“\nHannah Kool\, “Genesis Market Sales: Pricing and Discounting Patterns in a Cybercriminal Marketplace“\,\nRoy Ricaldi\, “Trust Beyond Underground Forums: Uncovering the Trust Signals Supporting Telegram’s Cybercrime Economy“\nRoy Ricaldi\, “An Experimental Design to Investigate Attacker Actions on an Access-as-a-Service ‘Criminal’ Platform“\n\n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Herbert Bos\n					Full professor at Vrije Universiteit Amsterdam \n					\n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Cristiano Giuffrida\n					Associate professor at Vrije Universiteit Amsterdam \n					\n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Sander Wiebing\n					Vrije Universiteit Amsterdam \n					Title\nSpecre-V2 attacks: Then and Now \nSummary\nModern computer processors often “guess ahead” to run faster\, predicting what tasks they might need to perform next. Unfortunately\, attackers can trick these processors into guessing wrongly\, causing sensitive information (like passwords or private data) to leak. In this talk\, we’ll briefly introduce Spectre-v2 attacks and show how we have researched this topic for several years. We’ll then present our latest research\, “Training Solo\,” demonstrating that even today’s de facto mitigation method—domain isolation—fails to fully mitigate against Spectre-v2 threats. \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Hannah Kool\n					NWO-i NSCR \n					Title\nGenesis Market Sales: Pricing and Discounting Patterns in a Cybercriminal Marketplace \nSummary\nCybercrime-as-a-Service (CaaS) platforms like Genesis Market enable cybercriminals to buy and sell tools\, services\, and bots. In this context\, bots refer to compromised user profiles containing stolen data. As bots were a product in Genesis Market\, understanding how they are priced is crucial. Unlike legitimate platforms\, CaaS markets lack standardized pricing\, making price a mechanism not just for reflecting value\, but also for signaling credibility\, quality\, and trustworthiness. Previous research has examined how specific bot characteristics influence pricing\, primarily focusing on direct economic value. However\, less is known about how multiple characteristics collectively shape pricing\, or how pricing may serve as a signal of trust. Drawing on rational choice theory and signaling theory\, this study investigates whether pricing and discounting in Genesis can be interpreted as trust signals. We analyze the relationship between bot characteristics and (extreme) pricing and discounting patterns using Conjunctive Analysis of Case Configurations (CACC) to identify patterns among variables. CACC provides insights that traditional methods might overlook\, enabling a deeper understanding of how combined factors relate to pricing decisions within Genesis. The patterns identified could reflect underlying assumptions about product value or perceived reliability\, offering insights into the decision-making processes in CaaS markets. \n  \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Roy Ricaldi\n					Eindhoven University of Technology \n					Title\nTrust Beyond Underground Forums: Uncovering the Trust Signals Supporting Telegram’s Cybercrime Economy \nSummary\n“Telegram has become a central hub for cybercriminal activity\, favored for its privacy features\, user anonymity\, and ease of use. Unlike traditional underground forums\, where persistent identities and reputation systems helped establish trust\, Telegram lacks many of these structural elements. This raises important questions about whether and how trust is built in these newer\, more fluid marketplace environments\, to anticipate the evolution of cybercrime and inform more effective disruption strategies. In our work\, we characterize the Telegram cybercrime ecosystem by identifying key market segments and developing a framework of trust-building mechanisms that enable trade within those segments. We apply this framework at scale across 1\,116\,071 messages from 167 Telegram communities. Our analysis shows that although trust signals are less formalized and often sparsely distributed\, cybercriminals on Telegram still actively signal trust using various strategies\, from proof-of-delivery and vouching messages to pinned rules and automated bots. To estimate how frequently these signals are actually encountered by users\, we implement a Monte Carlo simulation that models cybercriminal browsing behavior across different market segments. Our results reveal substantial variation: some segments exhibit dense\, consistent trust signaling\, while others remain fragmented and low-signal\, reflecting differences in maturity and structure across illicit markets. Together\, our findings suggest that Telegram supports its own evolving landscape of trust\, shaped by immediacy and native features of the platform.“ \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Roy Ricaldi\n					Eindhoven University of Technology \n					Title\nAn Experimental Design to Investigate Attacker Actions on an Access-as-a-Service ‘Criminal’ Platform \nSummary\nAccess-as-a-Service (AaaS) has reduced barriers to cybercriminal activity\, enabling less skilled offenders to execute sophisticated attacks relying on remote access to compromised systems. Despite the growing accessibility of these services\, little is understood about the factors influencing criminal decisions in the selection of their targets and the ensuing attack process. This short paper outlines the design and implementation of a `criminal’ AaaS platform aimed at attracting cybercriminal users to study their behavior. The platform\, modeled after illicit marketplaces in the dark web\, includes various market signals to assess their influence on cybercriminal decision-making and a ‘honeypot’ setup to evaluate attacker actions. In this paper\, we describe the methodology and infrastructure we are building to this purpose. \n					\n				\n			\n				\n				\n				\n				\n				\n					\n					\n						10:45 - 11:15 Break\n						\n					\n				\n			\n			\n				\n				\n				\n				\n			\n				\n				\n				\n				\n				\n				\n				\n				\n				\n				\n				\n					\n					\n						11:15 - 12:30 Second series of parallel sessions\n						 \n					\n				\n			\n				\n				\n				\n				\n				\n					\n					\n						11:15 - 12:30 Parallel session on WP5\n						Moderated by Lorenzo Dalla Corte \nProgramme \n\nPratham Ajmera\, “Two birds with one stone? Analysing the EUs use of product regulation frameworks to enhance product cybersecurity”\nLorenz Kustosch\, “Regulating Smart Device Support Periods: User Expectations and the European Cyber Resilience Act.”\nSuzanne Nusselder\, “Dissecting the dual dynamics between cybersecurity and data protection: Friends or foes? A paradox hidden behind the ‘State-of-the-Art’ in Article 32 GDPR.”\n\n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Lorenzo Dalla Corte\n					Tilburg University \n					Lorenzo Dalla Corte will give an introduction to the objectives and (intermediate) results of WP5 on “Governance” \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Pratham Ajmera\n					\n					Title\nTwo birds with one stone? Analysing the EUs use of its product regulation framework to enhance product cybersecurity \nSummary\nThe Internet’s development over the past couple decades has enabled it to become ubiquitous\, achieved in great part by connecting devices we use into a ‘community of devices’ known as the Internet of Things (“IoT”). The potential IoT holds also raises a strong call for cybersecurity\, especially considering the criticality of some sectors IoT enhances. In response\, the past few years have seen several legislations to ensure a high level of cybersecurity across the European Union\, the most recent being the EU Cyber-Resilience Act (CRA). The CRA is a risk-based product regulation that sets baseline cybersecurity requirements for all products within its scope; only when they are demonstrably met may a product enter the European market. The CRA’s approach is in line with the EUs framework for product regulation\, i.e.\, the New Legislative Framework (NLF)\, a framework that while general in nature\, has been used in several instances to harmonise product safety requirements across the European market. However\, this is the first time the NLF has been used to address product cybersecurity\, which while arguably intersecting with product safety\, refers to a concept that is quite different. Safety addresses direct harm to consumers\, whereas cybersecurity may be seen as focusing more on the design and use of ICT infrastructures. The NLF has essentially been ‘transplanted’ into regulating product cybersecurity as well through the CRA. However\, it is still unclear how ‘suitable’ the NLF would be in providing for cybersecurity in products that are as diverse and dynamic as IoT devices. This paper examines the suitability of NLF style product (safety) regulation in a cybersecurity context. In conducting said examination\, it is necessary to explore product safety as a concept through its characterisation in law and determining elements of product safety that govern the relationship between consumers and market operators. It is also necessary to explore cybersecurity as a concept focusing on primarily protecting infrastructures\, regardless of who uses said infrastructure; again determining elements relevant to its intersection with safety. Finally\, the NLF must be examined as a point of intersection between these two concepts through its transplant into the cybersecurity regulatory framework. The NLFs suitability for cybersecurity regulation shall be determined based on the differences between safety and cybersecurity\, and weighing the NLF against how it addresses these differences. Reference is made to multiple NLF-style legislations\, including the aforementioned CRA\, the Medical Devices Regulation\, etc. when concrete comparisons are required during analysis. \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Lorenz Kustosch\n					\n					Title\nSmart Device Support Periods: User Expectations and the Cyber Resilience Act \nSummary\nMany smart home devices stop receiving security updates long before they stop working—leaving millions of them vulnerable. The upcoming European Cyber Resilience Act aims to fix this by requiring manufacturers to support devices for their expected use time. But what do users actually expect? To find out\, we ran a large survey across five EU countries\, discovering that most people expect their smart devices to last – and be supported – for longer than current industry norms or even the proposed five-year baseline. People also think differently about how long smart and non-smart devices should last. As consumer expectations are directly tied to product conformity with the CRA\, we reflect on these results and position them within the wider regulatory product conformity landscape. \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Suzanne Nusselder\n					\n					Title\nDissecting the dual dynamics between cybersecurity and data protection: Friends or foes? A paradox hidden behind the ‘State-of-the-Art’ in Article 32 GDPR. \nSummary\nCybersecurity and data protection are often characterised as “two sides of the same coin” and as mutually reinforcing. However\, the relationship between data protection and cybersecurity is not all smooth sailing. Importantly\, the manner in which cybersecurity is pursued in practice and in which cybersecurity systems are implemented may simultaneously pose risks to data protection. This presentation will investigate the dual dynamics between data protection and cybersecurity in the context of the GDPR’s security requirements. Below the surface of Article 32 GDPR a paradox emerges whereby cybersecurity tools albeit implemented for the protection of personal data\, simultaneously pose risks to data protection. Special attention will also be paid to the notion of ‘state of the art’ (SoA) which is a key criterion for determining the appropriateness of the TOMs that are to be implemented pursuant Article 32(1) GDPR\, yet remains elusive. The research will sketch a more tangible interpretation of SoA in the context of Article 32 GDPR in order to determine what specific technological cybersecurity solutions are implemented pursuant Article 32 GDPR \n					\n				\n			\n				\n				\n				\n				\n				\n					\n					\n						11:15 - 12:30 Parallel session on WP3\n						Moderated by Jerry den Hartog \nProgramme \n\nIntroduction by Jerry den Hartog\nPresentation by Chakshu Gupta\nPresentation by Jorrit Olthuis\n\n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Jerry den Hartog\n					Eindhoven University of Technology \n					Jerry den Hartog will give an introduction to the objectives and (intermediate) results of WP3 on “Defence” \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Chakshu Gupta\n					University of Twente \n					Title\nDoes IoT Device Identification work under realistic conditions? \nSummary\nThe Internet of Things (IoT) is now integrated into nearly every aspect of our daily lives. However\, the security of these devices remains a major concern. Researchers are actively exploring various methods to secure IoT devices\, including detecting anomalies\, monitoring vulnerable systems\, and identifying data leaks. A critical first step in many of these security methods is identifying the devices connected to the network. In this presentation\, we explore to what extend IoT device identification techniques are effective under real-world conditions. \n					\n				\n			\n				\n				\n				\n				\n				\n				\n					Jorrit Olthuis\n					\n					Title\nSecurity of Autonomous Navigation Systems \nSummary\nAutonomous Navigation Systems (ANSs) are revolutionizing transportation and logistics by enhancing operational efficiency and reshaping industry standards. However\, the absence of human intervention during operational failures makes ANSs more vulnerable to cyberattacks and their consequences. Although prior research has addressed the security challenges of ANSs and proposed various defenses to prevent and mitigate cyberattacks against ANSs\, we still lack a comprehensive understanding of the ANS attack surface and the effectiveness of both attacks and defenses. To address this gap\, we conduct a systematic review of 125 articles on cybersecurity for ANSs\, focusing on their domain\, characteristics\, and the attack and defense strategies studied in the literature. Our analysis reveals notable research trends\, open gaps\, and areas for future investigation. Security research on navigation functions remains limited\, despite their central role and the risks associated with their compromise. Moreover\, our analysis reveals a lack of cross-domain research\, resulting in threats and defenses analyzed for one domain being overlooked in others. Finally\, we identify discrepancies between attacks and defenses studied in the literature\, with a disproportionate focus on defense strategies. \n					\n				\n			\n			\n				\n				\n				\n				\n			\n				\n				\n				\n				\n				\n				\n				\n				\n				\n				\n				\n					\n					\n						12:30 - 13:30 Lunch + Networking\n						\n					\n				\n			\n			\n				\n				\n				\n				\n			\n				\n				\n				\n				\n				\n				\n				\n				\n				\n				\n				13:30 - 13:55 ACCSS Roadmap for R&D in cyber security\n			\n				\n				\n				\n				\n				\n				\n					Zeki Erkin\n					Delft University of Technology \n					Title\nA New National Cybersecurity Research Agenda is Coming \nSummary\nIn response to growing global cybersecurity threats and the rapidly evolving digital landscape\, the Netherlands is preparing a new National Cybersecurity Research Agenda. Cybersecurity is no longer a niche concern—it is a cornerstone of national resilience\, economic stability\, and democratic integrity. The recent geopolitical tensions and increasing cyberattacks worldwide have only underscored the urgent need for robust\, forward-looking cybersecurity strategies. As one of Europe’s digital frontrunners\, the Netherlands must remain at the forefront of cybersecurity innovation and preparedness.Over the past several months\, we have worked diligently to gather input from researchers across the country\, consult with key stakeholders\, and study recent developments in the field. This collective effort reflects our belief that the agenda must be inclusive\, multidisciplinary\, and representative of the national research community.The upcoming agenda is not just a snapshot of current trends; it is intended to serve as a long-term strategic guideline—a shared foundation to guide research\, foster collaboration\, and shape funding priorities. It will support researchers\, policymakers\, and industry in identifying common goals and navigating the complex cybersecurity landscape together.Before looking ahead\, we will take a brief moment to reflect on what previous national research agendas have delivered. From strengthening our academic and industrial networks to shaping impactful policies\, these past efforts have laid the groundwork for the next step forward.The new agenda is organized around five central research themes: Design\, Defend\, Attack\, Use\, and Recover. These themes provide a structured approach to understanding and addressing the full spectrum of cybersecurity challenges. We will offer a sneak preview of these themes and share how they align with ongoing efforts to embed security by design\, security by default\, and the protection of digital sovereignty and autonomy.Importantly\, cybersecurity is not solely a technical issue—it intersects with law\, economics\, psychology\, public policy\, and more. This agenda embraces a multidisciplinary approach\, ensuring that our collective response is as complex and adaptive as the threats we face.Together\, this new agenda aims to inspire\, coordinate\, and empower the Dutch cybersecurity research community for years to come. \n					\n				\n			\n				\n				\n				\n				\n				13:55 - 14:20 National Technology Strategy Cyber Security \n			\n				\n				\n				\n				\n				\n				\n					Stephanie Ottenheijm\n					Topsector ICT \n					Title\nHow to build an ecosystem for Secure by Design?From research to action \nSummary\nThe Netherlands is at the forefront of cybersecurity and digital resilience. However\, in today’s rapidly evolving digital landscape\, this is no position to become complacent. To maintain our leadership\, we must look ahead. What’s next in threats? And\, what’s next in opportunities to counter them? \nRecognising the critical importance of cybersecurity for the safety\, wellbeing\, and economic prosperity of our country\, the Dutch government has identified Cybersecurity Technologies as a key area for investment over the next decade. The ambition is clear: \n“By 2035\, cybersecurity will be an integral part of the Dutch economy. Through the widespread adoption of security-by-design\, security-by-default\, and cybersecurity throughout organisational and supply chains\, the Netherlands will become digitally secure\, resilient\, autonomous\, and prosperous.” \nBut how do we embed security as a fundamental element of successful innovation\, right from the design stage? And how can this not only keep us safe\, but also foster a thriving industry that exports secure products and services across the globe? And how will that help us not only to stay safe\, but also build a blooming industry of secure products and services across the globe? \nAchieving this vision requires an ecosystem of diverse organisations working toward a common goal. The Action Agenda is being developed to bring organisations together and define the collaborative actions needed to overcome the barriers to our shared ambition. \nWe invite you to join us in this session to explore which hurdles we must overcome and the best ways to address them. Together we can build the roadmap to a thriving cybersecurity industry that keeps the Netherlands safe and prosperous. \n  \n \n					\n				\n			\n				\n				\n				\n				\n				14:20 - 15:05 Invited talk by Jeroen van der Ham\n			\n				\n				\n				\n				\n				\n				\n					Jeroen van der Ham\n					University of Twente \n					Title\nEverything you need to know about CVEs \nSummary\nVulnerabilities are the bread and butter of cybersecurity. Any discussion on cybersecurity will mention vulnerabilities at some point. But what do we really know about vulnerabilities? Very often CVE numbers are used\, and the number of CVEs keeps going up\, should we be worried? And what is going on with all of the new vulnerability registries? This presentation will help you understand the world of metadata for vulnerabilities. We will discuss what kind of metadata is available for vulnerabilities\, what all the different metadata means\, where does it comes from\, and how it will help you (or not). \nBiography\nJeroen van der Ham-de Vos (he/him) is associate professor of Cyber Security Vulnerability Management in the Design and Analysis of Communication Systems (DACS) group at the University of Twente. His research currently focuses on vulnerability prioritisation and management\, incident response\, the many developments in coordinated vulnerability disclosure and ethics of cybersecurity and computer science.He has worked at the National Cyber Security Centre-NL from 2015 until 2023 as a cybersecurity researcher. There he coordinated the NCSC Research Agenda\, was the national expert on Coordinated Vulnerability Disclosure\, and was part of crisis teams such as with Wannacry or Log4J.He is member of the editorial board of the ACM journal Digital Threats: Research and Practice\, is an active member of the FIRST community\, and was the co-editor of the Code of Ethics for Incident and Security Teams\, and serves on several programme committees. \n					\n				\n			\n				\n				\n				\n				\n				15:05 - 15:35 Break\n			\n				\n				\n				\n				\n				15:35 - 16:35 Invited talk by Éireann Leverett\n			\n				\n				\n				\n				\n				\n				\n					Éireann Leverett\n					Killara Cyber\, CTO \n					Title\nAnticipating Cyber Risk in the Internet of Things \nSummary\nWe know we need security in IoT\, but the details matter. How much security and privacy do we need? How much does it cost? What should we focus on?  What kinds of harms will there be? How much will they cost\, and how will they emerge? Can we predict anything to help us make decisions? \nQualitative predictions are easy\, but it’s the quantitative ones that matter. How many vulnerabilities will there be\, and what vectors will they have? How many of those will get exploited\, and how much does this cost society? Beyond these simple questions though\, we need to anticipate cyber crime while we’re writing the software\, firmware\, and hardware. We need to embrace the science of security that comes after the decade wasted by asking “what are the chances of that?”. \nThis is a talk about the world we want to be living in during the future\, not the one we’re living in today. To get from here to there\, we need to learn to quantify\, measure\, predict\, and estimate. We need data that drives the science of security and privacy\, and we could do a lot more with what we already have. \nBiography\nÉireann Leverett has been a member of the digital forensics and incident response community since 2005. His two decades in the security and privacy have taken him through many jobs at GE\, IOactive\, University of Cambridge\, Airbus\, Tidal Cyber\, and lately as an entrepreneur CTO at Killara Cyber. He has been on red team and blue team\, and now does data science\, risk\, and DFIR at scale. He has written many papers and one book\, been on countless programming committees\, and founded vulnerability forecasting conference. He hates writing about himself in the third person\, but he reads enough to be interesting. \n					\n				\n			\n				\n				\n				\n				\n				16:35- 17:25 Invited talk by Elisa Costante\n			\n				\n				\n				\n				\n				\n				\n					Elisa Costante\n					Forescout Research\, VP of Threat Research \n					Title\nIT vs. Everything Else: Why OT\, IoT\, and Medical Devices Are the Next Cyber Battleground \nSummary\nWhile traditional IT systems have matured in cybersecurity practices\, the growing ecosystem of unmanaged and cyber-physical systems (CPS) — including operational technology (OT)\, medical devices\, and IoT — is rapidly becoming the biggest risk exposure of enterprise security.These devices are often built without security in mind\, operate in highly sensitive environments\, and are notoriously hard to patch\, monitor\, or even inventory. The result? A rising wave of vulnerabilities\, many of them quietly exploitable\, affecting everything from factory floor controllers to hospital infusion pumps and smart building sensors.This talk explores the key differences between IT and non-IT environments\, why traditional security approaches fail in CPS contexts\, and how the threat landscape is evolving. We’ll walk through real-world examples of attacks\, trends in vulnerability disclosure\, and the unique challenges posed by regulation\, uptime constraints\, and vendor lock-in. \nBiography\nElisa Costante\, Phd.\, is the VP of Threat Research at Forescout. In her role\, she leads the activities of Forescout Research – Vedere Labs\, a team of cyber security researchers focused on vulnerability research\, threat analysis and threat mitigation. Under her leadership\, Vedere Labs has discovered 200+ new vulnerabilities in OT and IoT devices and shed light into the implication of supply chain vulnerabilities and in-security by design that affect the OT world. Project Memoria deserves a special mention in this regard. It is the largest systematic study on vulnerabilities in TCP/IP stacks used in embedded devices. Under Project Memoria\, Elisa and her team analyzed 14 different TCP/IP stacks\, uncovering 97 vulnerabilities that could impact 3 billion-plus devices around the globe. Elisa and the team leverage their findings as a tool for broader education on the necessity of enacting improved procedures surrounding the development and security of essential connected devices. \nElisa has 10+ years of experience in OT/IoT/IoMT security space. In her prior role\, she was CTO at SecurityMatters\, where she led product innovation activities in the field of network intrusion detection. Elisa holds a PhD in Cyber Security from the Eindhoven University of Technology where she specialized in machine learning techniques for data leakage detection. \nElisa’s mission is to advance the state of the art in cybersecurity threat research and threat intelligence\, and to create value for her customers\, partners\, and stakeholders. She is responsible for defining the research strategy and vision\, overseeing the research projects and collaborations\, and driving the technology transfer and integration with products and services. Elisa also enjoy mentoring and coaching the next generation of cybersecurity leaders and innovators and she is a frequent speaker at public events and conferences. \n					\n				\n			\n				\n				\n				\n				\n				17:25 Closing\n			\n				\n				\n				\n				\n				\n				\n					Sandro Etalle\n					Eindhoven University of Technology\, Scientific director of INTERSECT \n					\n					\n				\n			\n				\n				\n				\n				\n				17:25 - 18:45 Network reception
URL:https://intersct.nl/event/intersct25/
LOCATION:Radboud University Nijmegen (Huygens Building)\, Heyendaalseweg 135\, Nijmegen\, 6525 AJ\, Netherlands
CATEGORIES:conference
ATTACH;FMTTYPE=image/png:https://intersct.nl/wp-content/uploads/2025/05/Background-INTERSECT.png
ORGANIZER;CN="INTERSECT":MAILTO:info@INTERSCT.nl
END:VEVENT
END:VCALENDAR