I'm currently open for speaking opportunities at private and public events. My goal in each talk is to analyze different facets of why defensive infosec is challenging and offer my advice on how to make defense more strategic and innovative rather than reactionary and tactical.

You can see my public speaking history below to gain a sense of my work. Additionally, I frequently speak at private events/summits that are not listed below, including workshops for corporate security teams.

Upcoming Talks

  • Keynote

    Where: Hacktivity | Budapest, Hungary

    When: October 25 - 26, 2019

Previous Talks

  • Controlled Chaos: The Inevitable Marriage of DevOps & Security

    Where: Black Hat USA | Las Vegas, NV

    When: August 7, 2019

    Slides

  • Security Delusions

    Where: QCon NYC | New York, NY

    When: June 26, 2019

    Slides

  • Keynote: On Resilience in Infosec

    Where: ISACA New York Metropolitan Chapter's Spring Membership Meeting | New York, NY

    When: April 11, 2019

  • Why Defense is Hard

    Where: NYPD Cyber Intelligence and Counterterrorism Conference | New York, NY

    When: March 19, 2019

  • The Cybersecurity Industry Makes Millions, But Is It Keeping Us Safe?

    Where: Motherboard CYBER Podcast | The Internet

    When: March 4, 2019

    Audio

  • Risk Quicksand in Information Security

    Where: Art into Science: A Conference on Defense | Round Rock, TX

    When: January 30, 2019

    Slides

  • Risky Business #527 -- Featuring Alex Stamos, The Grugq, Susan Hennessey, Brian Krebs, Kelly Shortridge and Bobby Chesney

    Where: Risky Business Podcast | The Internet

    When: January 22, 2019

    Audio

  • We Turn Our Backs on Cybersecurity Rock Stars

    Where: CISO / Security Vendor Relationship Podcast | The Internet

    When: November 19, 2018

    Audio

  • Paint by Numbers: Measuring Resilience in Security

    Where: Square R00t | NYC

    When: November 14, 2018

    Slides

  • Paint by Numbers: Measuring Resilience in Security

    Where: DuraznoConf | Durazno, Uruguay

    When: October 4, 2018

    Slides | Video

  • Paint by Numbers: Resilience in Security

    Where: AusCERT | Gold Coast, Australia

    When: May 31, 2018

    Slides | Video

  • Keynote: Security as Product

    Where: BSides Knoxville | Knoxville, TN

    When: May 18, 2018

    Full Text | Video

  • #womenterprise Sector Series: Security

    Where: NY Enterprise Technology Meetup | NYC

    When: May 16, 2018

  • Panel: AI in Security, Gaps Between Theory and Practice. Demonstrating Value to Customers

    Where: USENIX Security & AI Networking Conference (ScAINet '18) | Atlanta, GA

    When: May 11, 2018

  • Threat Prioritization: Freeing the White Whale

    Where: HackNYC | NYC

    When: May 8, 2018

    Slides

  • Practical Magic: Behavior-based Security Design for IoT

    Slides

    Where: Troopers | Heidelberg, Germany

    When: March 12, 2018

  • DevOps in the Real World: Culture, Tools, Adoption

    Audio

    Where: Oracle Developer Podcast | The Internet

    When: February 20, 2018

  • Why Defense is Hard

    Where: NYPD Cyber Intelligence & Counterterrorism Conference 2018 | NYC

    When: February 13, 2018

  • Risky Business #485 -- Infosec startups overfunded, good exits unlikely

    Audio

    Where: Risky Business Podcast | The Internet

    When: January 31, 2018

  • A Dangerous Folly: Why Individual Attack Prediction Can’t Be Our Goal

    Slides

    Where: Art into Science | Austin, TX

    When: January 30, 2018

  • Return Oriented: 2017 InfoSec Market Recap

    Where: BSidesNYC | NYC

    When: January 20, 2018

  • Defensive Exploitation: How to Pwn Your Attacker's Decision-making

    Slides

    Where: ZeroNights | Moscow, Russian Federation

    When: November 17, 2017

  • Closing Keynote: The Red Pill of Resilience

    Video | Slides | Full Text

    Where: Countermeasure 2017 | Ottawa, Canada

    When: November 10, 2017

  • Big Game Theory Hunting: The Peculiarities of Human Behavior in the InfoSec Game

    Slides

    Where: BSides PDX | Portland, OR

    When: October 21, 2017

  • Opening Keynote: The Red Pill of Resilience

    Slides

    Where: Rochester Security Summit | Rochester, NY

    When: October 19, 2017

  • Risky Business #464 -- Why your game theory theories are wrong

    Audio

    Where: Risky Business Podcast | The Internet

    When: August 9, 2017

  • Big Game Theory Hunting: The Peculiarities of Human Behavior in the InfoSec Game

    Slides

    Where: BlackHat USA | Las Vegas, NV

    When: July 26, 2017

  • O'Reilly Security Podcast: Overcoming common missteps affecting security decision-making

    Soundcloud

    Where: O'Reilly Security Podcast | The Internet

    When: May 24, 2017

  • Disrupting the attack lifecycle: how do attackers behave?

    Slides sans gifs :'(

    Where: RiskSec | New York, NY

    When: May 2, 2017

  • Volatile Memory: Behavioral Game Theory in Defensive Security

    Video | Slides

    Where: Troopers | Heidelberg, Germany

    When: March 23, 2017

  • Know Thyself: Optimizing Team Decision Making
    Slides

    Where: Art into Science: A Conference for Defense | Austin, TX

    When: January 26, 2017

  • Privacy vs. Security: A False Tradeoff?
    Webinar

    Where: BrightTalk Privacy vs. Security Summit | The Internet

    When: October 2016

  • Duo Tech Talk
    Video | Slides

    Where: DuoSecurity Tech Talks | Ann Arbor, MI

    When: November 11, 2016

  • The Art of Explanation: Behavioral Models of Infosec
    Video | Slides

    Where: Hacktivity | Budapest, Hungary

    When: October 21, 2016

  • Behavioral Models of Infosec: Industry irrationality & what to do about it
    Slides

    Where: NCC Open Forum | NYC

    When: August 2016

  • DIY Education in Cyber Security
    Slides

    Where: NYU Poly's Career Discovery in Cyber Security: A Women's Symposium | NYC

    When: July 2015

  • Cyber Education: Your Options & Resources Mapped Out
    Slides

    Where: NYU Poly's Career Discovery in Cyber Security: A Women's Symposium | NYC

    When: October 2014

  • You've Been Hacked — IP Security in the Digital Domain

    Where: ipCG Thought Leadership Conference | Stowe, VT

    When: November 2013