An is a cybersecurity consultant based in Belgium who has never quite managed to stay on one side of the fence. Her work spans incident response, forensics, threat modelling, cyberdefense projects, and penetration testing, which means she spend roughly equal time thinking about how attacks happen and how organisations survive them.
She spoke at Annacon in 2025 and became genuinely obsessed with what AI actually does to that balance, from both ends of the kill chain.
- The end of human pentesting?
Anca is an Information Security Analyst on the Incident Response team at Adobe. She recently completed her Master's degree and is now on the lookout for new opportunities, events, and challenges to dive into.
Public speaking and knowledge-sharing are a big part her journey in this field. She has delivered talks at events like YouniHack and EduFest, spoke on the importance of AI security at the University Politehnica of Bucharest, NLP Master's courses and labs at the University of Bucharest.
She is constantly working toward new certifications, driven by a simple goal: never stop learning. Beyond presenting, she has been involved in organizing BSides Bucharest at the Adobe office and has attended numerous conferences along the way — always looking for the next room to learn in, or the next stage to speak from.
- LLM Hacking and Latest vulnerabilities on AI agents - OWASP Top 10 for LLM Applications
Becky is a Cyber Crime Intern at the West Midlands Regional Cyber Crime Unit in the UK and a Computer Science student at the University of Birmingham. Her work spans supporting cyber crime investigations, delivering cyber security training, and researching emerging cyber threats. Alongside this, she is involved in educational outreach and conference speaking to improve cyber awareness. She is also active in widening participation in the industry through leadership roles with CyberWomen@Birmingham and Leading Cyber Ladies Midlands.
- What Negotiation Chats Reveal About Ransomware-as-a-Service
Caroline van Gorp, FICA, MBA, is Head of Global FEC Sanctions Change & Portfolio at Rabobank, where she leads large-scale transformation initiatives at the intersection of financial crime prevention, risk, technology, and regulatory change.
With a career spanning financial services, compliance, risk management, and business transformation, Caroline is known for her ability to connect disciplines that are often treated separately. She brings a holistic perspective to risk, exploring how innovation, technology, human behaviour, and governance collectively shape organizational resilience. Pioneer, entrepreneur, and Non-Executive Director for NGOs.
Passionate about the potential of technology to drive meaningful change, Caroline focuses on navigate complex challenges in an increasingly interconnected and digital world. Her work combines strategic thinking with practical execution, enabling sustainable transformation while strengthening trust, security, and customer outcomes.
A speaker and thought leader, Caroline is particularly interested in the paradoxes, wicked problems, and different perspectives. Her insights challenge conventional thinking and encourage audiences to look beyond silos to better understand the evolving risk landscape.
- The Dark Spell of Trust: How Secure Systems become Enablers of Financial Crime
Catharine is an Information Security Officer with a focus on advising and assessment. She works within the Dutch railway domain as member of the ProRail cybersecurity team and reports to the CISO. She works as an advisor for multiple IT domains, where mission critical IT-assets are developed and maintained.
She is a supportive and approachable professional who is able to provide advise on diverse levels in the organisation. Thanks to her natural prevention-focused mindset, experience in risk management and her critical view, she brings clarity and makes complex cybersecurity risks clear and managable.
- Will the train stop running? The value of responsible disclosure.
Danique Lummen is a Cybersecurity Specialist at Royal Schiphol Group and an active contributor to Stichting Challenge the Cyber. Through the foundation, she helps grow and diversify the next generation of cybersecurity talent in the Netherlands, supporting young people with the skills and opportunities needed to excel in the field. Danique was also Team Captain of Team Europe during the first International Cybersecurity Challenge, organized by ENISA, where the team became world champion. She is passionate about strengthening the cybersecurity community by connecting talent, knowledge, and practical experience.
- CTF introduction workshop with Challenge the Cyber
Dominique Heuff holds a Master's Degree in Russian Studies. Currently working as a senior security analyst at the SOC of SSC-ICT - a shared service provider for IT for the Dutch government - she aims to bridge her academic background with her professional experience to place cybersecurity developments in a broader context. This presentation is the result of that ambition.
- War and Unpeace: How Russia became one of the world's most advanced cyber threat actors
Meet Dorota Kozlowska, known as 'Woman in Red,' a renowned penetration tester, social engineering and physical audit specialist. What she brings to the table is a unique blend of technical penetration testing skills, social engineering, hands-on physical security experience, and evolving Red Teaming capabilities. As a sought-after international keynote speaker on Offensive Security related topics, she has captivated audiences at the most prominent events, and biggest stages.
Her passion for sharing knowledge and expertise has been recognized with CEFCYS Cyber Woman of Hope 2023 award, and her appearance on the '40 Under 40 in Cybersecurity 2023' list by Top Cyber News Magazine.
In addition to her speaking engagements, she also hosts popular Podcasts "Ethical Hacking, Guests, and Wholesomeness," and “Inspiring Ladies of Cyber” where she delves into the world of cybersecurity with guests from the industry.
- Social engineering techniques of hacking a human being
Eden Stroet is a security researcher and SOC analyst at Hadrian Security in Amsterdam, where they focus on vulnerability research, automated scanning, and pentesting. They are a volunteer with the Dutch Institute for Vulnerability Disclosure (DIVD) and an active bug bounty hunter on HackerOne and Intigriti. Eden runs two online cyber security communities called Digital Overdose and Hard Way Hacking and Coding. When they're not hacking, they're on an aerial hoop or playing videogames with friends.
- Supabase Shenaningans: Extended Edition
Ten year security expert. Much of which for the government.
Not a well behaved woman.
- Well behaved women seldom make history
Frank Cozijnsen is a seasoned ethical hacker at KPN, the leading telecommunications provider in the Netherlands, where he has worked for over 25 years. Previously, he held roles as a VoIP engineer and system administrator within the same organization.
Frank likes to focus on assessing mobile networking equipment and telecom infrastructure, with a particular interest in binary exploitation and hacking complex environments. He likes to play CTF's and has discovered vulnerabilities in several products using custom fuzzing techniques.
- Coverage-guided Fuzzing
Milena aka g0mb4ck is a Hardware Security Researcher and has just started her journey in Keysight Device Security, formerly known as Riscure B.V.
Her main focus is on fault injection, which is a way to test and break hardware security. Her goal is to really understand how these attacks work so she can help design better defenses.
- Misbehaving while awake: nRF52810 Runtime EM Fault Injection APPROTECT Bypass - (CVE-2025-9709)
Garance works at Depi in the offensive security research team, and she is specialising in software supply chain security. She love understanding and learning random things in the world around her and meeting new people.
- How to capitalise on other people’s popularity to distribute malware: Weaponizing CI/CD Pipelines
Ieva grew up in Lithuania, where the line between an attack and narrative manipulation was the backdrop of daily life. That early exposure became an academic focus (a master's in International Security at Sciences Po Paris, with Ukraine as her case study) and, later, a profession.
She has worked on OT Security and operational resilience projects in Switzerland and is now at Accenture Netherlands, helping clients improve their capabilities in cyber recovery, Major Incident Management, and DORA. Much of that work involves rebuilding crisis management structures to survive contact with a real incident. She studies how attackers pair technical and narrative attacks, arguing most crisis plans still aren't prepared for it.
- The Attacker Posted First: The Breach Wasn't the Expensive Part
Next to her fulltime job at the government, Kaja is the founder of CyberMaster, a fully-immersive cybercrisis simulation that puts teams under the kind of pressure no slide deck can.
The foundation for CyberMaster was laid in her background in criminology, law and technology and cybercrime, cybersecurity and riskmanagement, which is where she learned that cyber problems are rarely just technical: they're about people.
As a proper nerd, she loves to discuss these topics endlessly which is why she is a guest lecturer at the University of Twente and TU Darmstädt, where she does her best to make privacy law sound... less.... like... privacy law and to introduce to technical students that there is also another side of cybersecurity.
Therefore, her work sits at the intersection of privacy, cybersecurity and the human factor and after guiding enough crisis teams. She is convinced people are our strongest link in cybersecurity, NOT the weakest!
- Want to play a game?
Kim van Wilgen is CTO at Schuberg Philis and a trusted advisor to executive teams and technology leaders responsible for mission-critical digital environments. She specializes in operational resilience, cybersecurity, AI adoption, and digital sovereignty.
Kim helps organizations design technology landscapes that remain adaptable in the face of cyber threats, geopolitical uncertainty, and rapid technological change. She is known for translating complex technical challenges into clear strategic choices for business leaders. Her work bridges technology, leadership, and business continuity in an increasingly digital world.
- No IT is no IT problem
Maya is an enthusiastic nerd who found her way into cybersecurity through the developer world. She absolutely loves diving deep into technology, figuring out how things work, and then discussing and exchanging ideas about it with fellow nerds.
She volunteers for Challenge the Cyber by helping out with the events and she has helped with building challenges for the yearly CTF.
- CTF introduction workshop with Challenge the Cyber
Marijke Moolenaar is a Security Expert at DTX with an unconventional path into cybersecurity. With her roots deeply embedded in literature and philosophy, she brings a unique, analytical perspective to the tech world. Before diving into security, she spent time in the ring as a competitive boxer. Today, she combines her philosophical mindset, tech skills, and fighting spirit to dissect complex security challenges and protect digital infrastructures from the ghosts in the machine.
- Hauntology in the Machine: Reanimating a Dead Language to Blindside Modern Security
Monika is a data and AI consultant in the Netherlands, with around 10 years across data quality, machine learning and engineering. Her current focus is AI safety and governance, including the EU AI Act, agentic AI risk and prompt injection.
On her blog ai.stewart.wtf she write about AI news and concerns about AI for business audiences, while keeping it grounded in science. You may have seen her as a visitor at the last EMF, WHY2025 or 39C3.
- The largest social engineering attack ever? The hidden effects of AI on the human mind
Ola is a Solution Architect with over twenty years of experience in designing and delivering software solutions. She works within the Dutch railway domain, focusing on building resilient systems for a critical infrastructure.
Her work connects architecture and security in practice: from designing identity providers, reverse proxies, and IT/OT gateways to bringing business values into production. She has hands-on experience with risk analysis, penetration testing, shifting security controls left, security monitoring, and incident response.
She brings a pragmatic perspective on how to make security work in real-world systems, balancing resilience, innovation, and cost-efectivness.
- Will the train stop running? The value of responsible disclosure.
Rosanne Pouw is Product Manager Awareness and Training at SURF. She helps Dutch research and education institutions increase security awareness with the Cybersave Yourself Toolkit. Her special talent is infusing cybersecurity awareness with optimism, creativity and a multidisciplinary approach.
Part of her role at SURF is stimulating the awareness community of professionals in higher education , sharing thoughts and ideas and developing materials together.
- Humour, your Secret Weapon for more effective Cybersecurity Awareness
Sebastiaan is an Ethical Hacker at KPN with an interest in binary analysis and exploitation, system security and breaking programs in general. Before that, he worked as an incident responder and forensic analyst at KPN-CERT. Whenever opportunity arises, he can be found at CTF events.
- Coverage-guided Fuzzing
Yianna Paris is an Australian-born security researcher now causing trouble as a Senior Offensive Security Consultant at Xebia in the Netherlands. She recently founded her training and research consultancy, Luda Hex. Her experience has spanned from deeply technical, high performing engineering companies to working for checkbox-compliance leadership. She breaks things professionally, from web apps, infrastructure, the architecture behind them, and increasingly the AI-powered systems everyone's bolting on without reading the manual. Her work spans penetration testing, secure coding, hardware and RF hacking, and the OSINT legwork of figuring out what an organisation actually runs versus what it thinks it runs (the two are rarely the same).
She's a DEFCON and Xebia Academy trainer, volunteer teaching kids to code, crafter and loves spending time in her garden. Having made the move from apologetic Aussie to we-say-what-we-mean Dutch directness, she's well-practised at pushing back, both on systems, and on the humans who built them.
- I jailbroke a scam bot with 1 prompt, and so can you