Every program stands on three benches. The executives who facilitate your board exercises, the conference review boards who select the technical content, and the researchers who deliver it. Nobody here teaches for a living. They teach from the work.
The people who facilitate board tabletops and coach your leadership through them, backed by a sitting CISO from the CyberEd board matched to your sector.
Held the CIO and CISO seats simultaneously at a global publisher: research-driven, reputation-sensitive, IP-heavy, with a distributed expert workforce. Facilitates executive exercises, owns the phase rubric and the scoring method, and leads the follow-through coaching after the room clears.

Directs product strategy across the training platform, the lab infrastructure, and the event network the bench is drawn from. Sits on the review boards of Nullcon and Hardwear.io, where the technical content your cohort trains on is selected across offensive, cloud, AI, and hardware security.
A serving CISO from the CyberEd board joins executive exercises as guest faculty: peer credibility for the legal, security, and communications coaching, and a second facilitator so private sessions stay deliverable inside a tight window. Matched to your sector and mandate, whatever the scope.
The Nullcon and Hardwear.io review boards select the technical content your cohort trains on. These are the people deciding what counts as current.

Founder of the events much of this bench is drawn from, and author of the open EXPLIoT framework a generation of IoT security testers learned on. Two decades of offensive security across embedded, IoT, and product security.

Reverse engineers malware where it is hardest to see: phones, wearables, and embedded devices. Founder of a CTF dedicated to smart devices and a fixture on the international mobile and IoT threat research circuit.

Directed research into the most sophisticated state-sponsored operations on public record for over a decade. One of the most cited threat-intelligence researchers in the industry.

Publishes foundational research on the wireless stacks and closed mobile ecosystems billions of devices depend on, presented at the venues where that work gets stress-tested.

Splits time between academic research and paid assessments of web platforms and internet infrastructure, with AI-assisted methodology work on the assessment side.

Published foundational work on trusted execution environment exploitation and fault injection against secure boot on production devices, and trains advanced practitioners on both.

Leads an academic lab focused on what implementations leak rather than what specifications promise: power analysis, side channels, and attacks that cross the hardware-software boundary.

Two decades of side-channel analysis and fault injection against chips submitted for certification, and co-author of the book most hardware security careers start with.

Publicly demonstrated practical key-extraction and glitching attacks against the keyless entry of production electric vehicles and the user terminal of a satellite internet constellation.

Built one of the most respected open training curricula in low-level security, after years of BIOS, UEFI, and firmware threat research inside industry and federally funded labs.
The researchers who write and deliver the instructor-led catalog. Shown here by focus area, because publishing a roster of working trainers turns a teaching bench into a recruiting list.
A fault-injection specialist who defeats hardware roots of trust on shipping consumer and network equipment in the course of paid assurance work. Chains electromagnetic and voltage faults against secure boot into full privilege escalation on production silicon.
Has broken proprietary TEEs, fuzzed trusted applications, and performed large-scale rollback attacks. Works the gap between what a secure element is specified to guarantee and what it actually guarantees once it ships.
Works integrated circuit reverse engineering at the transistor level: silicon analysis, ROM extraction, and recovering the design intent of a part from the die itself when no documentation exists.
Specializes in deep-level exploitation of programmable logic controllers and the protocols underneath them, in environments where a failed test has physical consequences rather than a rolled-back deployment.
Assesses in-vehicle infotainment and telematics control units, and works radio protocol exploitation across LoRa, LoRaWAN, and drone command links. Training content is drawn from real assessments rather than lab rigs.
Builds and teaches the tradecraft end of red teaming: advanced malware execution, EDR bypass, phishing infrastructure, and full APT simulation against a live range rather than a screenshot of one.
Covers both halves of cloud security: hardening Kubernetes and cloud-native infrastructure, and attacking it, including Azure and Entra ID offensive work and the hybrid identity attack paths that cross between on-premise and cloud.
Works adversarial machine learning, LLM exploitation, and the security implications of agentic systems, including the offensive and defensive sides of models that are already in production and already taking actions.
Binary reverse engineering, malware analysis, and vulnerability research, taught from the position of someone who has to triage and fix at distribution scale rather than write up a single sample.
From the conference floor, not a trainer marketplace. Most of the bench headlines the events your team already attends.
Every program is reviewed by a second practitioner in the same field before it ships. Nothing goes out on the author's word alone.
Scoping pairs your program with the member whose field it sits in. You meet them, under NDA, before you commit.