WICCON 2026: two days of technical cybersecurity, hands-on workshops and new perspectives
The WICCON 2026 schedule is now live. On 29 and 30 October, cybersecurity professionals, researchers, students and enthusiasts will come together at De Lichtfabriek in Haarlem for two days packed with technical talks, hands-on workshops and discussions about the challenges shaping cybersecurity today.
Following the announcement of this year's conference earlier this summer, the schedule offers a first look at the breadth of expertise taking the stage. From software supply chain security and hardware hacking to AI security, ransomware and digital sovereignty, WICCON 2026 brings together a wide range of topics.
View the full WICCON 2026 schedule.
From supply chains to hardware hacking
The schedule opens with a look at responsible disclosure and what organisations can learn from security vulnerabilities in legacy systems. From there, attendees can dive into subjects including software supply chain attacks, social engineering and even the security implications of decades-old technology.
Technical sessions are a major part of the schedule. Garance de la Brosse will explore how attackers can weaponise CI/CD pipelines to distribute malicious versions of popular open-source packages, while Marijke Moolenaar takes a more unusual route into low-level security with a talk about using the FORTH programming language in shellcode.
Hardware security also gets its moment on stage. Hardware security researcher g0mb4ck will demonstrate runtime electromagnetic fault injection and an APPROTECT bypass, based on CVE-2025-9709.
AI security takes centre stage
Artificial intelligence is another recurring theme throughout WICCON 2026. Rather than treating AI as a single topic, the schedule approaches it from several different angles.
Sessions explore the security of LLMs and AI agents, including prompt injection, system prompt leakage and the risks of connecting AI systems to tools and integrations. Yianna Paris will share practical lessons from testing AI-powered applications, and Anca Maria Capota's workshop allows participants to work hands-on with vulnerabilities from the OWASP Top 10 for LLM Applications.
The schedule also looks beyond the technology itself. Monika Stewart explores the overlap between social engineering and the way generative AI can influence human judgement, while other sessions consider what AI means for offensive security and the future role of human penetration testers.
Together, these sessions reflect an important shift in cybersecurity: securing AI systems requires understanding not only the technology, but also the humans and organisations that build and use them.
Cybersecurity is more than technology
The schedule contains plenty of technical content but WICCON also looks at the organisational, geopolitical and human sides of cybersecurity.
Kim van Wilgen will explore digital sovereignty and what happens when organisations lose strategic flexibility through technology choices, vendor dependencies and operational complexity. Dominique Heuff takes a geopolitical perspective on Russia's evolution as a cyber threat actor.
Other sessions examine ransomware negotiations, financial crime, crisis management and cybersecurity awareness. Becky Stacey will use data from ransomware leak sites and negotiation chats to examine the ecosystem behind ransomware-as-a-service. Ieva Salnaite looks at how attackers increasingly control the narrative surrounding a breach to leverage for more damage.
There is also room for a healthy dose of humour and honesty. Rosanne Pouw will discuss the use of humour to make cybersecurity awareness more effective, and Fleur van Leusden will challenge the idea that cybersecurity is always a meritocracy, by sharing lessons from more than a decade in the field.
Learn by doing
A key part of WICCON is the opportunity to get hands-on. Alongside the conference talks, the schedule includes interactive workshops covering subjects such as social engineering, fuzzing, CTFs and LLM security.
The CTF introduction workshop, organised with Challenge the Cyber, is designed to give people who are new to Capture the Flag competitions a low-pressure way to get started. Participants can work together, experiment with challenges, ask questions and learn the basics.
For more experienced practitioners, the schedule offers opportunities to explore topics such as coverage-guided fuzzing and vulnerabilities in AI agents in much greater depth.
The workshops are included in the regular conference ticket, making practical learning an integral part of the WICCON experience rather than an additional cost.
A schedule built around expertise and community
WICCON's all-women speaker line-up remains central to the conference. The 2026 speakers come from a broad range of backgrounds, including offensive security, hardware security, incident response, AI, threat intelligence, awareness, governance and cybercrime.
That combination of technical expertise and different perspectives is exactly what makes WICCON distinctive. The conference was created to put women's technical achievements in cybersecurity in the spotlight while providing a welcoming environment for the wider cybersecurity community.
Security Delta (HSD) is proud to support WICCON as an endorsing partner. By supporting initiatives such as WICCON, we contribute to an ecosystem where knowledge is shared, cybersecurity talent can develop, and a wider range of experts get the visibility and opportunities they deserve.
Join WICCON 2026
WICCON 2026 takes place on Thursday 29 and Friday 30 October 2026 at De Lichtfabriek in Haarlem. The schedule runs from 10:00 to 18:00 on both days, with registration starting at 09:00.
Whether you want to sharpen your technical skills, explore the security implications of AI, learn from experienced practitioners, meet future colleagues or spend two days surrounded by people who enjoy breaking and understanding things, WICCON has something to offer.
Explore the full schedule and get your WICCON 2026 ticket