Curated Agenda · Security Leaders

NIC 2026, built for Security Leaders

This is the security track at NIC 2026, distilled: the sessions worth clearing your calendar for, the speakers worth knowing, and the room you actually want to be in. There's plenty more on the full agenda. This just confirms your highlights are already on it.

Oslo Spektrum, Norway
Oct 13–15, 2026
Keynote: Jeffrey Snover
Cloud & Infrastructure
Why this track, why now

The threat model changed. Has your team?

Identity sprawl, AI-assisted attacks, and infrastructure that spans clouds you don't fully control have made the old perimeter model obsolete. This track is built around what's actually working for security leaders defending real production environments right now, not theory.

90%

Organizations reporting a cybersecurity skills gap on their team, with only 14% saying they have the talent they actually need.

Source: Fortinet, 2026 Cybersecurity Skills Gap Report

$1.76M

Extra breach cost organizations pay when short-staffed on security, compared to teams at full strength.

Source: IBM, Cost of a Data Breach Report

Sessions built for you

The security track, at a glance

Level 300
Tales from Incident Response – “It’s Probably Nothing” (Until It Is)

Michael Nystrøm, Deployment Bunny, The one and only, MVP and Hasain Alshakarti, The Wolf - Principal Cybersecurity Advisor, MVP from Truesec

In this session, I’ll tell real incident response stories and break down what went wrong, why it happened, and what could have stopped it long before the incident response team got involved. Expect hard-earned lessons, a few uncomfortable truths, and practical takeaways you can use before your own pager goes off.

Level 300
60 Life Hacks of Windows in 60 minutes

Sami Laiho, Chief Research Officer, MVP

One of the world's leading operating system experts, shows you 60 tips and tricks about the Windows OS that you didn't even know existed! You will walk out thinking "How did I miss that for all these years!"

Level 400
Breaking Identity at Scale: From DPAPI & TBAL Secrets to Full Domain Compromise

Paula Januszkiewicz, Cybersecurity Expert

This session presents a deep technical exploration of how attackers extract and abuse protected credentials at scale, moving from local access to full domain compromise.

We demonstrate novel techniques for decrypting DPAPI-protected data, abusing TBAL-related key material, and chaining these with authentication protocol weaknesses such as NTLM and Kerberos to achieve lateral movement and privilege escalation.

Level 300
10 security settings you must configure in Windows 11 - 2026 edition

Nicklas Ahlberg, Trusted Security Advisor, MVP

During this session we will cover our top 10 configurations we must configure in Windows 11. We will have a look at what they do and how they affect our devices.

Join for great tips on how to take your Windows security posture to the next level

Level 300
Using LOLBins to circumvent all your security - Even in 2026

Viktor Hedberg, Senior Security Architect, MVP

Did you know that most actors use Windows, to attack Windows? Meaning the built in tools and features allowing for Living Of the Land (LOL) and their binaries (Bins).

This session will showcase that an environment, protected by using EDR is still susceptible ti these types of attacks, even in Windows 11 and in the year 2026.

Level 300
Getting started with Ethical Hacking

Christian Peeters, Principal Cloud Architect and Trainer

In this session, we will explore how hackers operate and which tools you can use to hack (your own) applications. Additionally, we will examine the most common types of vulnerabilities, how to practice exploiting them, and what measures can be taken to prevent them.

Who you'll meet

Some of the names worth planning your day around

Paula Januszkiewicz

Cybersecurity Expert

Hasain Alshakarti

The Wolf - Principal Cybersecurity Advisor, MVP

Sami Laiho

Chief Research Officer, MVP

Also worth your time
Pre-conference masterclass · Oct 13

Breaking the Kill Chain

A full-day, gamified incident-response simulation from Truesec: a real breach timeline, not a slide deck. Built for security leaders who want to pressure-test their own response process against a live scenario, not just read about one.

What you'll walk away with

Four things worth the three days

Defense patterns tested against real attackers
What's actually holding up in other people's environments, not a vendor's threat-model slide.

Direct access to peers defending the same systems
The hallway conversation with someone who's already been through the incident you're preparing for.

A staffing answer, not just a tooling one
Where automation can close the gap your headcount can't, and where it can't.

A report-back your team will actually use
Concrete patterns tied to sessions you chose in advance, not “it was a good conference.”

The details

Cost & logistics

Attendance

Dates

Oct 13–15, 2026

Masterclasses

Oct 13

Main conference

Oct 14–15

Ticket price

From NOK 11.500

VAT

excl. 25%

Good to know

Refunds

None, decide once

Travel to venue

Adjacent to Oslo Central Station

Laptop

Bring your own (masterclasses)

Sway your boss

Need this approved before you book?

Sway your boss is the ready-built pitch for whoever has to sign off on your ticket.

Ready?

Tickets are live now. The automation track only gets fuller from here.