Systems Under Pressure
Rebellion Europe is about systems under pressure.
KEY THEMES
AI governance vs. AI reality
Privacy, surveillance, and power
Infrastructure resilience
Regulation as an attack surface
Operating across borders and constraints
This is where philosophical debates meet operational consequences.
Agenda
Welcome to the Rebellion
Doors open. Grab your badge, set up your exhibit space, and start connecting with the RBLN community.
Underground Exhibits
Open all day. Think less trade show, more operator playground. The RBLN Underground brings together cutting-edge companies, interactive experiences, and the technology driving the next wave of disruption.
Opening Remarks
Kick off RBLN with a welcome from the organizers, an overview of the event experience, and a look at the conversations shaping the future of cybersecurity, AI, and modern defense.
The rise of AI attacks – what we should know about AI powered threats
• Gain practical insight into how agentic malware operates (prompting, orchestration, tool usage), including where it can adapt to defenses and where it breaks. Enabling better threat modeling and detection engineering. • Learn how to identify and detect AI powered malware using existing behavioral signals and reputation systems, and understand why most current samples do not evade well-configured EDR/XDRs. • Understand the current AI powered threat landscape and be able to differentiate the marketing hype from reality.
Fireside Chat: The Future of AI Innovation Beyond Big Tech
Deep Dive Sessions
Built for those who want to go deeper. RBLN Europe’s Deep Dive Sessions move beyond traditional presentations to explore the tools, tactics, architectures, and lessons learned behind today’s most pressing security challenges. These technical, focused sessions provide practitioners with real-world insights, expert-led discussions, and actionable strategies they can take back to their teams. Choose the sessions that align with your interests and the challenges you’re solving today.
6 Hard Lessons from Zero Trust Deployments: What the Field Is Actually Seeing
Zero Trust has quickly moved from security concept to board-level mandate. Yet the reality inside most organizations is far messier than the architecture diagrams suggest. Based on several hundred interviews with IT and security practitioners as well as the analyst community, this session explores what actually happens when organizations attempt to implement Zero Trust. The findings are sobering: roughly 60–70% of Zero Trust initiatives stall before reaching maturity, and fewer than 20% achieve a fully realized Zero Trust architecture. Rather than focusing on theory or vendor frameworks, this session examines seven hard lessons from the field, highlighting both the successes and the failures organizations encounter along the way. Topics include why many Zero Trust initiatives stall, where organizations underestimate complexity, the architectural decisions that matter most, and what successful deployments do differently. This presentation is not a product pitch. Instead, it’s a candid discussion of the hard realities of Zero Trust deployment, grounded in the experiences of practitioners across hundreds of organizations. Attendees will leave with practical insights into what works, what fails, and how to move a Zero Trust initiative from concept to operational reality.
The 0-day Vending Machine: No Mythos Necessary
1. The AI assisted VR era is already here and has very little to do with frontier models. 2. How you can get started adopting these workflows if you are currently not doing so. 3. What this means for everyone else - what’s the patch timeline in 2026 onwards?
Pooling Forensic Evidence Across Borders Without Creating a Surveillance Dataset
•Why pooling forensic evidence is operationally critical but legally dangerous •The design choice that matters most: separating raw artefacts from published intelligence •How AI validation routes submissions without requiring a single trusted authority •A pattern that works across jurisdictions (NL, UA, EU) •Honest limits: what validation still gets wrong
Networking Break
SESE: Social Engineering Second Edition The next frontier of security is…
In the presentation, we will show some older, several newly evolved social engineering attempts with involved, and of course take a peek into the future, where AI, and surely Quantum Computing, will create a Third Edition of Social Engineering. This future promises even more complex threats that challenge the boundaries of identity, authenticity, and trust. As we look ahead, SESE serves as both a warning and a guide, advocating for stronger digital literacy, adaptive defenses, and a forward-looking approach to cybersecurity in an age where machines can manipulate at the speed of thought.
Red-Teaming the Agentic Red-Team
The use of agentic systems to perform offensive security operations has moved from a theoretical possibility to a commoditized capability. However, while the community has focused on creating more and more capable agents, less attention has been allocated to assessing the security of those systems. In this work, we present the first in-depth security analysis of the most widely used agentic systems for offensive security operations. We show that most of these tools share common design flaws that enable an active adversary to exfiltrate API keys, establish persistent footholds, and fully compromise the operator's machine, even when the agent operates inside a sandboxed container. To support our analysis, we introduce a full cyber kill chain for such agentic systems, capturing the progression from initial LLM manipulation to lateral movement, persistence, guardrail bypass, and sandbox escape. Building on our security analysis, we derive a robust architecture for agentic offensive-security tools and propose actionable, broadly applicable design principles that mitigate the disclosed attack paths at the architectural level.
The (Non)Sense of AI
The (Non)Sense of AI challenges attendees to distinguish capability from marketing, automation from intelligence, and innovation from operational reality, while offering pragmatic guidance for building, securing, and using AI systems responsibly in an increasingly agentic world.
Founders in Cyber: How to Stand Out, Scale, and Win in a Crowded Market
Access is Not Authority
You will watch AI deployments get onboarded — a customer-service agent that can make a customer whole, a SOC triage agent producing thousands of imperfect judgments a day, and a team of agents working a newly disclosed critical vulnerability all the way to a production change — as fictional, deliberately simplified design walkthroughs. You will leave able to name, for any agent or agent system in your own shop, what it may do, where that limit is enforced, what evidence it takes to move, who is mandated to decide what, what authority the pieces can assemble between them, and who remains responsible — and with a practical Authority and Oversight Record and a working handout you can put in front of your team on Monday to ask those questions out loud.
Defense Against the Dark Arts: Securing the Web3 Frontier
With $1.2 billion stolen in 2026 alone, modern threat actors are weaponizing sophisticated cross-chain bridge exploits, AI-driven social engineering, and mysterious oracle intelligence at an unprecedented scale. This session maps the rapid evolution of these decentralized threat vectors and delivers critical, battle-tested security lessons straight from the Web3 front lines.
Attention Is the New Attack Surface: What marketers understand about human behaviour that cybercriminals exploit
• Understand why attention has become one of cybersecurity's most important attack surfaces. •Learn The Attention Attack Chain and apply it to social engineering. • Recognise the behavioural and marketing principles that underpin phishing, deepfakes and AI-enabled deception. •Discover practical ways to design security around human behaviour rather than relying solely on awareness training. • Leave with a new perspective on why protecting attention may become as important as protecting endpoints.
AfterFuse Networking Social
Where the RBLN Europe community comes alive—connect, converse, and build what’s next with the people driving the industry forward. AfterFuse is a high-energy night to unwind, connect, and keep the momentum going with attendees, exhibitors, and speakers.
Speakers

Adam Darrah
Vice President of Intelligence · ZeroFox

Afshin Lamei
Senior Security Engineer · Mollie

Andy Lalaguna
Senior Solutions Architect · eSentire

Ani Khachatryan
Chief Technology Officer · Syteca

Bajram Hoxha
Founding Member · Rival Labs

Bram Zentveld
Data & Analytics Consultant · BearingPoint

Candid Wüest
Cyber Security Advisor

Clara Gustafson
Writer

Dawn Perry
Threat Intelligence Analyst (Web3) · Mandiant (Google Cloud)

Dmytro Matviiv
CEO · HackenProof

Eddy Willems
Security Evangelist · LSEC (Leaders In Security)

Filip Mazán
Senior Manager of Advanced Threat Detection & AI Research · ESET

Francisco Dominguez
CTO · Hunt & Hackett

Gilbert Nyandeje
Group Chief Executive Officer & Chairman · Enovise Group

James Foster
CEO · eSentire

Jasper Wognum
CEO · AI Salon Global

Jaye Tillson
CTO Security · HPE

Jeff Hamm
Managing Director · HammNet UG

Jeroen Wijnands
Principal OT Cyber Security Consultant · Northwave Cyber Security

John Spiegel
Field CTO · HPE

Katie Soper
Principal Consultant | GTM & Leadership · Confero

Kevin Zwaan
Ethical Hacker · Q-Cyber

Klaudia Zaika
CEO · Apriorit

Luis Abreu
Founder and CEO · Cyver.io

Matt Chinnery
Senior Solutions Architect · Aryaka

Michael Mosher
Cybersecurity Executive

Michal Bazyli
Founding Cybersecurity Researcher · Cracken

Paul Pols
CTO · Bureau Veritas Cybersecurity Europe

Righard Zwienenberg
Senior Research Fellow · ESET

Robert Hommes
Founder · Moyai

Rogier Fischer
Co-founder and CEO · Hadrian

Sam Pizzey
Security Engineer · Intruder

Sara Carty
Founder and CEO · Unboring

Scott Miller
Security Consultant and Penetration Tester · Accenture Security

Seemant Sehgal
Founder and CEO · BreachLock

Thomas Hemker
Field CISO Advisor · ESET

Uğur Başak
Director of Platform Engineering · TomTom

Vadym Hadetskyi
Researcher

Vincent Swolfs
Director of Hacking · Injexion

Yuthvek MJ
Security Researcher II · Dailyrounds/Marrow
Location
RBLN Europe takes over Hotel Okura Amsterdam. Sessions, workshops, and hands-on chaos happen throughout the venue. Room info below—get ready to make your mark.
Transportation
- •Amsterdam Schiphol Airport (AMS): 15 km
- •Train: Amsterdam Zuid station nearby
- •Tram: Multiple lines accessible from hotel



