28 October 2026
it-sa Expo&Congress, room Lissabon, level 1, NCC Mitte, Nuremberg, Germany

09:30–10:15·45 min·Track: Business
The business case: business drivers, purpose and value of a governed Cyber Threat Model
Lerninhalte
- Part 1 · Business drivers for Cyber Threat Modelling
- 1.1) Five business drivers — compliance, risk management, security operations, threat-led testing, accountability
- 1.2) What DORA, TIBER-EU and NIS2 expect a threat model to prove
- 1.3) What a Cyber Threat Model is — three questions, one object; formats in use today — readable by whom, tied to what
- 1.4) How a threat model is produced today — the manual pipeline, and why it no longer scales
- 1.5) 2026 — AI reads the reports, agents act on them: from speed to trust; what it costs when the knowledge layer is not governed
- 1.6) Before you decide — seven questions to ask any threat-modelling approach
- Part 2 · Purpose and value of a governed Cyber Threat Model — for CISO, risk and SOC
- 2.1) Purpose — the governed model as the shared knowledge layer between threat intelligence and security operations
- 2.2) Value proposition — trust by design, not by vendor assurance: reliable reasoning, trust by design, process once – reuse everywhere, vendor independence, flexibility and control
- 2.3) Value by stakeholder — CISO and board, risk manager, head of CDC / SOC manager, TLPT / red-team lead; SOC maturity — moving detection from indicators to adversary behaviour
- 2.4) Agentic SOC platforms and the governed model — who governs what
- 2.5) From principle to platform — the seven questions, answered; the IdoubleS Cyber Threat Modelling platform: value proposition
- 2.6) From the model to the SOC — inferred, validated detection rules for SIEM and EDR, with coverage per technique; deployment and sovereignty — cloud, on-premises, air-gapped
Zielgruppe
- C-Level
- CISO Office
- Risk Managers
- Heads of Cyber Defence Centre
- SOC Managers
- Compliance and Procurement Leads in regulated sectors (DORA · NIS2 · KRITIS · defence and public sector)
10:15–10:30·Break
10:30–11:15·45 min·Track: Business
The joint value proposition with CrowdStrike and SVA, and the reference project
Lerninhalte
- Part 3 · The joint value proposition with CrowdStrike and with SVA
- 3.1) Fal.Con 2026 — what the agentic SOC now delivers (CrowdStrike)
- 3.2) IdoubleS × CrowdStrike — the joint value proposition today, and the next step: complementary in the agentic-SOC era
- 3.3) CrowdStrike × SVA — one platform, delivered and operated in Germany
- 3.4) IdoubleS × SVA — value-added reseller, integration partner, MSSP partnership: the governed model, run as a service
- Part 4 · The reference project — the customer’s story (early-adopter reference customer, German defence sector)
- 4.1) The customer — who they are, and what they were up against; the challenge — refinement that does not scale, and a new question: trust
- 4.2) The objective — a validation plan, not a statement of intent: from TRL 6 to TRL 9, a target of at least 80 % against a jointly worked out baseline, independent raters
- 4.3) The solution — from language to a governed model, from the model to rules that fire
- 4.4) Results (1) — the model, measured against the baseline; results (2) — detection logic and native rules, proven by adversary emulation with SVA
- 4.5) What changed for the customer — in the customer’s own words; the customer’s journey from the flood of reports to rules that fire
- 4.6) Getting started — the scoped pilot: one critical function, its relevant adversaries, two use cases; what comes next — the IdoubleS Attack Graph Community Edition (free, source-available)
Zielgruppe
- C-Level
- CISO Office
- Risk Managers
- Heads of Cyber Defence Centre
- SOC Managers
- Compliance and Procurement Leads in regulated sectors (DORA · NIS2 · KRITIS · defence and public sector)
11:15–11:30·Q&A with IdoubleS, CrowdStrike, SVA and the reference customer
14:00–14:45·45 min·Track: Technik
Producing a Cyber Threat Model today: the challenges, and how AI improves it
Lerninhalte
- Section 1 · The challenges — and the story of six runs against a baseline
- 1.1) Producing a model today — where it breaks: the manual pipeline; the language-model shortcut and the six things it does not supply
- 1.2) The first runs, Q4/2025 — the set-up of test scenario 2 (baseline, six automated runs, four verdicts, target) and what came out: ≈ 61 % / < 50 %
- 1.3) The comparison matrix — six runs against the baseline, technique by technique
- 1.4) Reading the matrix — seven error classes, from reasoning error to hallucination
- 1.5) What the reports demanded of the NLP — the findings behind the rework
- 1.6) From findings to fixes — new functions, improvements and roadmap; the turn: 99 % on re-validation, and the method reused this afternoon
- Section 2 · From concept to platform — how the IdoubleS platform implements what webinar 2 taught
- 2.1) The concept map — where every webinar-2 concept lives in the platform
- 2.2) The attack lifecycle as a threat-centric attack graph across its abstraction layers: ingestion and context building, technique extraction (layer 1, kill chain), cyber-domain entity extraction and relationship creation (layer 2), the governed claim, the analyst gate, threat-actor intelligence
- 2.3) The asset side — critical functions, asset-centric attack trees (CAPEC, CWE, CVE, CPE) and attack paths
- 2.4) From graph to detection — pseudocode (STIX patterns) and native rules for SIEM and EDR
- 2.5) The AI part — the export as knowledge layer; the platform in the value chain, and who works where
Zielgruppe
- Security Consultants
- Security Analysts
- Security Investigators
- Threat Hunters
- Incident Responders
- Detection and SIEM Engineers
- CTI Analysts
14:45–15:15·30 min·Track: TechnikInstructor-led hands-on
Instructor-led hands-on on the IdoubleS CTM platform
Lerninhalte
- Section 3 · One report in, one native rule out — CSIT-22052 live
- 3.1) Set-up — the report, the instance, the SIEM
- 3.2) Step 1 ingest the threat report · step 2 extract techniques and entities · step 3 generate the attack graph and run the analyst gate
- 3.3) Step 4 sample-based analysis of the generated graph against the manually defined baseline — quality and accuracy across the abstraction layers, with the matrix method of section 1
- 3.4) Step 5 generate the pseudocode (STIX pattern) · step 6 generate the native SIEM detection rule (IBM QRadar)
- 3.5) Wrap-up — the chain you just watched is the chain the reference customer measured
Zielgruppe
- Security Consultants
- Security Analysts
- Security Investigators
- Threat Hunters
- Incident Responders
- Detection and SIEM Engineers
- CTI Analysts
15:15–15:30·Break
15:30–16:15·45 min·Track: Technik & Business
The reference project: validation approach, architecture, results, the customer’s view
Lerninhalte
- Section 4 · Showcase of the IdoubleS CTM platform validation, jointly with the integration partner and the early-adopter reference customer
- 4.1) From the business track: set-up and objectives, the early adopter process from TRL 6 to TRL 9, the validation plan with seven test scenarios, how results are measured — three rubrics, no self-assessment
- 4.2) Test scenario 2 — qualitative and quantitative validation of automatically generated attack graphs: exact baseline match, TTP addition rate, triplet meaning per layer; analytical reasoning versus hallucination; first runs vs re-validation
- 4.3) The joint IdoubleS / SVA cloud architecture and joint activities — platform, SIEM, EDR, endpoints; two labs, one validation
- 4.4) Test scenarios 3 and 4 — validation of automatically inferred detection rules for SIEM and EDR: STIX patterns scored by three experts, native QRadar rules proven by adversary emulation with SVA (test cases and execution)
- 4.5) From report to fired rule — the results in one picture
- 4.6) Customer case study and testimonial — the reference customer’s view: why we started, what we measured, what changed; closing words from IdoubleS
Zielgruppe
- Security Consultants
- Security Analysts
- Security Investigators
- Threat Hunters
- Incident Responders
- Detection and SIEM Engineers
- CTI Analysts
- C-Level
- CISO Office
- Risk Managers
- Heads of Cyber Defence Centre
- SOC Managers
- Compliance and Procurement Leads in regulated sectors (DORA · NIS2 · KRITIS · defence and public sector)
16:15–16:30·Q&A with IdoubleS, SVA and the reference customer