Teil von: it-sa Expo&Congress 2026 – Intelligence-Driven Cyber-Threat-Modelling, von CTI zur realen Abwehr

Session 03

Applied Cyber Threat Modelling — Onsite Workshop (English) | it-sa Expo&Congress 2026

Onsite-WorkshopEnglisch

28 October 2026, 09:30–11:30 and 14:00–16:30 CET

it-sa Expo&Congress 2026 Nuremberg, Germany

Programm

28 October 2026

it-sa Expo&Congress, room Lissabon, level 1, NCC Mitte, Nuremberg, Germany

it-sa Expo&Congress logo
09:30–10:15·45 min·Track: Business

The business case: business drivers, purpose and value of a governed Cyber Threat Model

Lerninhalte
  • Part 1 · Business drivers for Cyber Threat Modelling
    • 1.1) Five business drivers — compliance, risk management, security operations, threat-led testing, accountability
    • 1.2) What DORA, TIBER-EU and NIS2 expect a threat model to prove
    • 1.3) What a Cyber Threat Model is — three questions, one object; formats in use today — readable by whom, tied to what
    • 1.4) How a threat model is produced today — the manual pipeline, and why it no longer scales
    • 1.5) 2026 — AI reads the reports, agents act on them: from speed to trust; what it costs when the knowledge layer is not governed
    • 1.6) Before you decide — seven questions to ask any threat-modelling approach
  • Part 2 · Purpose and value of a governed Cyber Threat Model — for CISO, risk and SOC
    • 2.1) Purpose — the governed model as the shared knowledge layer between threat intelligence and security operations
    • 2.2) Value proposition — trust by design, not by vendor assurance: reliable reasoning, trust by design, process once – reuse everywhere, vendor independence, flexibility and control
    • 2.3) Value by stakeholder — CISO and board, risk manager, head of CDC / SOC manager, TLPT / red-team lead; SOC maturity — moving detection from indicators to adversary behaviour
    • 2.4) Agentic SOC platforms and the governed model — who governs what
    • 2.5) From principle to platform — the seven questions, answered; the IdoubleS Cyber Threat Modelling platform: value proposition
    • 2.6) From the model to the SOC — inferred, validated detection rules for SIEM and EDR, with coverage per technique; deployment and sovereignty — cloud, on-premises, air-gapped
Zielgruppe
  • C-Level
  • CISO Office
  • Risk Managers
  • Heads of Cyber Defence Centre
  • SOC Managers
  • Compliance and Procurement Leads in regulated sectors (DORA · NIS2 · KRITIS · defence and public sector)
10:15–10:30·Break
10:30–11:15·45 min·Track: Business

The joint value proposition with CrowdStrike and SVA, and the reference project

Lerninhalte
  • Part 3 · The joint value proposition with CrowdStrike and with SVA
    • 3.1) Fal.Con 2026 — what the agentic SOC now delivers (CrowdStrike)
    • 3.2) IdoubleS × CrowdStrike — the joint value proposition today, and the next step: complementary in the agentic-SOC era
    • 3.3) CrowdStrike × SVA — one platform, delivered and operated in Germany
    • 3.4) IdoubleS × SVA — value-added reseller, integration partner, MSSP partnership: the governed model, run as a service
  • Part 4 · The reference project — the customer’s story (early-adopter reference customer, German defence sector)
    • 4.1) The customer — who they are, and what they were up against; the challenge — refinement that does not scale, and a new question: trust
    • 4.2) The objective — a validation plan, not a statement of intent: from TRL 6 to TRL 9, a target of at least 80 % against a jointly worked out baseline, independent raters
    • 4.3) The solution — from language to a governed model, from the model to rules that fire
    • 4.4) Results (1) — the model, measured against the baseline; results (2) — detection logic and native rules, proven by adversary emulation with SVA
    • 4.5) What changed for the customer — in the customer’s own words; the customer’s journey from the flood of reports to rules that fire
    • 4.6) Getting started — the scoped pilot: one critical function, its relevant adversaries, two use cases; what comes next — the IdoubleS Attack Graph Community Edition (free, source-available)
Zielgruppe
  • C-Level
  • CISO Office
  • Risk Managers
  • Heads of Cyber Defence Centre
  • SOC Managers
  • Compliance and Procurement Leads in regulated sectors (DORA · NIS2 · KRITIS · defence and public sector)
11:15–11:30·Q&A with IdoubleS, CrowdStrike, SVA and the reference customer
14:00–14:45·45 min·Track: Technik

Producing a Cyber Threat Model today: the challenges, and how AI improves it

Lerninhalte
  • Section 1 · The challenges — and the story of six runs against a baseline
    • 1.1) Producing a model today — where it breaks: the manual pipeline; the language-model shortcut and the six things it does not supply
    • 1.2) The first runs, Q4/2025 — the set-up of test scenario 2 (baseline, six automated runs, four verdicts, target) and what came out: ≈ 61 % / < 50 %
    • 1.3) The comparison matrix — six runs against the baseline, technique by technique
    • 1.4) Reading the matrix — seven error classes, from reasoning error to hallucination
    • 1.5) What the reports demanded of the NLP — the findings behind the rework
    • 1.6) From findings to fixes — new functions, improvements and roadmap; the turn: 99 % on re-validation, and the method reused this afternoon
  • Section 2 · From concept to platform — how the IdoubleS platform implements what webinar 2 taught
    • 2.1) The concept map — where every webinar-2 concept lives in the platform
    • 2.2) The attack lifecycle as a threat-centric attack graph across its abstraction layers: ingestion and context building, technique extraction (layer 1, kill chain), cyber-domain entity extraction and relationship creation (layer 2), the governed claim, the analyst gate, threat-actor intelligence
    • 2.3) The asset side — critical functions, asset-centric attack trees (CAPEC, CWE, CVE, CPE) and attack paths
    • 2.4) From graph to detection — pseudocode (STIX patterns) and native rules for SIEM and EDR
    • 2.5) The AI part — the export as knowledge layer; the platform in the value chain, and who works where
Zielgruppe
  • Security Consultants
  • Security Analysts
  • Security Investigators
  • Threat Hunters
  • Incident Responders
  • Detection and SIEM Engineers
  • CTI Analysts
14:45–15:15·30 min·Track: TechnikInstructor-led hands-on

Instructor-led hands-on on the IdoubleS CTM platform

Lerninhalte
  • Section 3 · One report in, one native rule out — CSIT-22052 live
    • 3.1) Set-up — the report, the instance, the SIEM
    • 3.2) Step 1 ingest the threat report · step 2 extract techniques and entities · step 3 generate the attack graph and run the analyst gate
    • 3.3) Step 4 sample-based analysis of the generated graph against the manually defined baseline — quality and accuracy across the abstraction layers, with the matrix method of section 1
    • 3.4) Step 5 generate the pseudocode (STIX pattern) · step 6 generate the native SIEM detection rule (IBM QRadar)
    • 3.5) Wrap-up — the chain you just watched is the chain the reference customer measured
Zielgruppe
  • Security Consultants
  • Security Analysts
  • Security Investigators
  • Threat Hunters
  • Incident Responders
  • Detection and SIEM Engineers
  • CTI Analysts
15:15–15:30·Break
15:30–16:15·45 min·Track: Technik & Business

The reference project: validation approach, architecture, results, the customer’s view

Lerninhalte
  • Section 4 · Showcase of the IdoubleS CTM platform validation, jointly with the integration partner and the early-adopter reference customer
    • 4.1) From the business track: set-up and objectives, the early adopter process from TRL 6 to TRL 9, the validation plan with seven test scenarios, how results are measured — three rubrics, no self-assessment
    • 4.2) Test scenario 2 — qualitative and quantitative validation of automatically generated attack graphs: exact baseline match, TTP addition rate, triplet meaning per layer; analytical reasoning versus hallucination; first runs vs re-validation
    • 4.3) The joint IdoubleS / SVA cloud architecture and joint activities — platform, SIEM, EDR, endpoints; two labs, one validation
    • 4.4) Test scenarios 3 and 4 — validation of automatically inferred detection rules for SIEM and EDR: STIX patterns scored by three experts, native QRadar rules proven by adversary emulation with SVA (test cases and execution)
    • 4.5) From report to fired rule — the results in one picture
    • 4.6) Customer case study and testimonial — the reference customer’s view: why we started, what we measured, what changed; closing words from IdoubleS
Zielgruppe
  • Security Consultants
  • Security Analysts
  • Security Investigators
  • Threat Hunters
  • Incident Responders
  • Detection and SIEM Engineers
  • CTI Analysts
  • C-Level
  • CISO Office
  • Risk Managers
  • Heads of Cyber Defence Centre
  • SOC Managers
  • Compliance and Procurement Leads in regulated sectors (DORA · NIS2 · KRITIS · defence and public sector)
16:15–16:30·Q&A with IdoubleS, SVA and the reference customer

Anmelden

Sessions auswählen *

Webinare (Online)

Workshops (Vor Ort bei der it-sa Expo&Congress)

Diese Website ist durch reCAPTCHA geschützt. Informationen zur Verarbeitung Ihrer Daten finden Sie in unserer Datenschutzerklärung.