2026-10-29 –, Main Hall
In this talk, we share the story of how we almost got breached.
Long before the report came in, we were busy phasing out a legacy system that was used in train operations. A system that multiple internal and external stakeholders used in their primary traffic management processes.
We had already conducted a risk analysis that highlighted several severe cybersecurity risks, and even though the risks were known, everyone was still surprised when an actual responsible disclosure message came in, notifying us about the vulnerability.
We will show you how we handled this incident, what we learned, and how responsible disclosure helped accelerate the mitigation of cybersecurity risks.
Ola is a Solution Architect with over twenty years of experience in designing and delivering software solutions. She works within the Dutch railway domain, focusing on building resilient systems for a critical infrastructure.
Her work connects architecture and security in practice: from designing identity providers, reverse proxies, and IT/OT gateways to bringing business values into production. She has hands-on experience with risk analysis, penetration testing, shifting security controls left, security monitoring, and incident response.
She brings a pragmatic perspective on how to make security work in real-world systems, balancing resilience, innovation, and cost-efectivness.
Catharine is an Information Security Officer with a focus on advising and assessment. She works within the Dutch railway domain as member of the ProRail cybersecurity team and reports to the CISO. She works as an advisor for multiple IT domains, where mission critical IT-assets are developed and maintained.
She is a supportive and approachable professional who is able to provide advise on diverse levels in the organisation. Thanks to her natural prevention-focused mindset, experience in risk management and her critical view, she brings clarity and makes complex cybersecurity risks clear and managable.