The network

More than just trainers, practitioners.

Every program stands on three benches. The executives who facilitate your board exercises, the conference review boards who select the technical content, and the researchers who deliver it. Nobody here teaches for a living. They teach from the work.

Leadership and the advisory board.

The people who facilitate board tabletops and coach your leadership through them, backed by a sitting CISO from the CyberEd board matched to your sector.

SM

Sean D. Mack

Lead faculty and facilitator
Managing Director, CXO Advisor, ISMG
Formerly CIO and CISO, Wiley

Held the CIO and CISO seats simultaneously at a global publisher: research-driven, reputation-sensitive, IP-heavy, with a distributed expert workforce. Facilitates executive exercises, owns the phase rubric and the scoring method, and leads the follow-through coaching after the room clears.

Author, The DevSecOps Playbook (Wiley, 2023).
Carlos Enamorado

Carlos Enamorado

Director of Product Strategy and Partnerships, CyberEd
Review board, Nullcon and Hardwear.io

Directs product strategy across the training platform, the lab infrastructure, and the event network the bench is drawn from. Sits on the review boards of Nullcon and Hardwear.io, where the technical content your cohort trains on is selected across offensive, cloud, AI, and hardware security.

Technical operator on delivered executive exercises.
cx

CISO, CyberEd Board Member

Advisory board
Sitting Chief Information Security Officer

A serving CISO from the CyberEd board joins executive exercises as guest faculty: peer credibility for the legal, security, and communications coaching, and a second facilitator so private sessions stay deliverable inside a tight window. Matched to your sector and mandate, whatever the scope.

Selected against your profile. Named at kickoff.

The review board.

The Nullcon and Hardwear.io review boards select the technical content your cohort trains on. These are the people deciding what counts as current.

Aseem Jakhar

Aseem Jakhar

Founder, EXPLIoT · Director of R&D, Payatu
Review board, Nullcon and Hardwear.io

Founder of the events much of this bench is drawn from, and author of the open EXPLIoT framework a generation of IoT security testers learned on. Two decades of offensive security across embedded, IoT, and product security.

IoT and embedded security
Axelle Apvrille

Axelle Apvrille

Principal Security Researcher, Fortinet
Review board, Nullcon

Reverse engineers malware where it is hardest to see: phones, wearables, and embedded devices. Founder of a CTF dedicated to smart devices and a fixture on the international mobile and IoT threat research circuit.

Mobile and IoT malware
Costin Raiu

Costin Raiu

Threat intelligence researcher
Review board, Nullcon

Directed research into the most sophisticated state-sponsored operations on public record for over a decade. One of the most cited threat-intelligence researchers in the industry.

Threat intelligence and APTs
Prof. Dr. Jiska Classen

Prof. Dr. Jiska Classen

Professor, Hasso-Plattner-Institut
Review board, Nullcon

Publishes foundational research on the wireless stacks and closed mobile ecosystems billions of devices depend on, presented at the venues where that work gets stress-tested.

Wireless and mobile ecosystem security
Sebastian Neef

Sebastian Neef

Security researcher, Technische Universität Berlin
Review board, Nullcon

Splits time between academic research and paid assessments of web platforms and internet infrastructure, with AI-assisted methodology work on the assessment side.

Web and infrastructure security
Cristofaro Mune

Cristofaro Mune

Co-founder, Raelize
Review board, Hardwear.io

Published foundational work on trusted execution environment exploitation and fault injection against secure boot on production devices, and trains advanced practitioners on both.

TEE exploitation and fault injection
Dr. Yossi Oren

Dr. Yossi Oren

Head, Implementation Security Lab, Ben-Gurion University
Review board, Hardwear.io

Leads an academic lab focused on what implementations leak rather than what specifications promise: power analysis, side channels, and attacks that cross the hardware-software boundary.

Side-channel and implementation security
Jasper van Woudenberg

Jasper van Woudenberg

CTO, Riscure North America
Review board, Hardwear.io

Two decades of side-channel analysis and fault injection against chips submitted for certification, and co-author of the book most hardware security careers start with.

Hardware evaluation and fault injection
Lennert Wouters

Lennert Wouters

Researcher, KU Leuven
Review board, Hardwear.io

Publicly demonstrated practical key-extraction and glitching attacks against the keyless entry of production electric vehicles and the user terminal of a satellite internet constellation.

Embedded hardware attacks
Xeno Kovah

Xeno Kovah

Founder, OST2 Training
Review board, Hardwear.io

Built one of the most respected open training curricula in low-level security, after years of BIOS, UEFI, and firmware threat research inside industry and federally funded labs.

Firmware and platform security

The technical bench. The trainers

The researchers who write and deliver the instructor-led catalog. Shown here by focus area, because publishing a roster of working trainers turns a teaching bench into a recruiting list.

hw

Hardware Assurance Lead

Founder, an independent hardware-security research lab
Board member, a leading hardware-security conference

A fault-injection specialist who defeats hardware roots of trust on shipping consumer and network equipment in the course of paid assurance work. Chains electromagnetic and voltage faults against secure boot into full privilege escalation on production silicon.

Focus: fault injection, secure boot, production silicon
te

Secure Boot and TEE Lead

PhD, trusted execution environment security
Active researcher, ARM TrustZone

Has broken proprietary TEEs, fuzzed trusted applications, and performed large-scale rollback attacks. Works the gap between what a secure element is specified to guarantee and what it actually guarantees once it ships.

Focus: trusted execution environments, ARM TrustZone
si

Silicon Reverse Engineering Lead

Hardware security evaluation specialist
Founder, a hardware-security lab

Works integrated circuit reverse engineering at the transistor level: silicon analysis, ROM extraction, and recovering the design intent of a part from the die itself when no documentation exists.

Focus: IC reverse engineering, silicon analysis
ot

ICS and OT Lead

Founder, an industrial control security practice
Author of a formal ICS penetration testing methodology

Specializes in deep-level exploitation of programmable logic controllers and the protocols underneath them, in environments where a failed test has physical consequences rather than a rolled-back deployment.

Focus: industrial control systems, PLC exploitation
rf

Automotive and RF Lead

Automotive security researcher and consultant
Software-defined radio and LoRaWAN specialist

Assesses in-vehicle infotainment and telematics control units, and works radio protocol exploitation across LoRa, LoRaWAN, and drone command links. Training content is drawn from real assessments rather than lab rigs.

Focus: connected vehicles, SDR, radio protocols
op

Offensive Operations Lead

Red team research director
APT simulation and adversary tradecraft

Builds and teaches the tradecraft end of red teaming: advanced malware execution, EDR bypass, phishing infrastructure, and full APT simulation against a live range rather than a screenshot of one.

Focus: red team tradecraft, EDR evasion, APT simulation
cl

Cloud and Infrastructure Lead

Cloud security architect
Kubernetes, container orchestration, hybrid identity

Covers both halves of cloud security: hardening Kubernetes and cloud-native infrastructure, and attacking it, including Azure and Entra ID offensive work and the hybrid identity attack paths that cross between on-premise and cloud.

Focus: Kubernetes, cloud-native, hybrid identity
ai

AI Security Lead

AI security researcher
Adversarial machine learning and LLM exploitation

Works adversarial machine learning, LLM exploitation, and the security implications of agentic systems, including the offensive and defensive sides of models that are already in production and already taking actions.

Focus: adversarial ML, LLM exploitation, agentic AI
re

Reverse Engineering and Malware Lead

Security engineer, a major Linux distribution security team
Previously at a leading EDR vendor

Binary reverse engineering, malware analysis, and vulnerability research, taught from the position of someone who has to triage and fix at distribution scale rather than write up a single sample.

Focus: binary RE, malware analysis, vulnerability research

How the bench works.

Sourced

From the conference floor, not a trainer marketplace. Most of the bench headlines the events your team already attends.

Reviewed

Every program is reviewed by a second practitioner in the same field before it ships. Nothing goes out on the author's word alone.

Matched

Scoping pairs your program with the member whose field it sits in. You meet them, under NDA, before you commit.

Meet the bench behind your program.

Named under NDA during scoping · before anything is signed.
See what they teach