Event series

it-sa Expo&Congress 2026 — Intelligence-Driven Cyber Threat Modelling, From CTI to Real-World Defence

A free three-part webinar and workshop series, in English and German, that takes participants from Cyber Threat Intelligence to a governed Cyber Threat Model — and to detection coverage they can prove.

Dates
October 2026
Location
Online & Onsite at it-sa Expo&Congress 2026 Nuremberg, Germany
Sessions
6 sessions

About this series

A free three-part webinar and workshop series, in English and German, that takes participants from Cyber Threat Intelligence to a governed Cyber Threat Model — and to detection coverage they can prove. Two online webinars build the input, the vocabulary and the concepts; the onsite workshop at it-sa Expo&Congress 2026 in Nuremberg shows the business case, the IdoubleS Cyber Threat Modelling platform, the joint value proposition with CrowdStrike and SVA, and the validation results of an early-adopter reference project in the German defence sector — with an instructor-led hands-on.

One thread through all three events: the same critical function and the same adversary (MUMMY SPIDER delivering Emotet — CrowdStrike Intelligence Tipper CSIT-22052, used with CrowdStrike’s approval), taken from intelligence report to threat model to validated detection rule.

  1. Online webinar 1

    14 October 2026

    Goals

    • How bespoke cyber threat intelligence (CTI) is created
    • How it is adopted by a Cyber Threat Model (CTM)
    • How it represents end-to-end threat scenarios

    Reference framework

    TIBER-EU (ECB)

  2. Online webinar 2

    21 October 2026

    Goals

    • Understand cyber-domain-specific frameworks, taxonomies and concepts
    • Formalise them into a CTM that humans and AI can reason over
    • Facilitate SOC operations in the AI and agentic-SOC era

    Conceptual reference framework

    Semantic Cyber Threat Modelling (Bromander et al.)

  3. it-sa onsite workshop

    27 + 28 October 2026

    Goals

    • Business drivers for Cyber Threat Modelling
    • IdoubleS, CrowdStrike and SVA: joint value proposition and reference project in the German defence sector
    • Introduction of the IdoubleS solution, its value and the validation results from the reference project

    Solution

    IdoubleS Cyber Threat Modelling platform

Speakers: Rukhsar Khan (Founder and CEO, IdoubleS; GIAC Certified Forensic Analyst, Gold-level #12275), Yusuf Khan (Co-founder and CTO, IdoubleS), Samet Katilmis (IdoubleS), Benjamin Hufschmidt (Manager Public Sector Germany, CrowdStrike), Hendrik Onnenga (Public Sector / BWI Lead, SVA), Sascha Rüsenberg (Security Engineering, SVA), Janis Damberg (SVA) — and, at the workshop, the early-adopter reference customer from the German defence sector.

Practical information: Free of charge · English and German · online (webinars) and onsite (it-sa Expo&Congress 2026, Nuremberg) · registration via the series page. Participants of the workshop receive an accompanying limited-edition book (first come, first served).

The IdoubleS team looks forward to welcoming you in person at our booth in Hall 7, Booth #7-714 during the it-sa Expo&Congress 2026 Event.

Sessions

6 sessions
  • 01

    Webinar

    14 October 2026, 12:30–14:30 CEST

    EnglishTechnical

    Online

    • What is Cyber Threat Intelligence, how does it differ from a Cyber Threat Model — and what makes a threat model defensible to a supervisor?

    What You'll Take Home

    Participants can say what a Cyber Threat Model is, which elements it must contain, and what makes one defensible under DORA and TIBER-EU — and they have seen one built, from business parameters to a scored threat scenario with an attack tree.

  • 01

    Webinar

    14. Oktober 2026, 15:30–17:30 Uhr MESZ

    GermanTechnical

    Online

    • Was ist Cyber-Threat-Intelligence, wie unterscheidet sie sich von einem Cyber-Threat-Modell — und wodurch wird ein Threat-Modell gegenüber einer Aufsichtsbehörde belastbar und nachvollziehbar?

    What You'll Take Home

    Die Teilnehmenden können erklären, was ein Cyber-Threat-Modell ist, welche Elemente es enthalten muss und wodurch es unter DORA und TIBER-EU belastbar wird — und sie haben gesehen, wie ein solches Modell von den Geschäftsparametern bis zu einem eingestuften Threat-Szenario mit Attack-Tree aufgebaut wird.

  • 02

    Webinar

    21 October 2026, 12:30–14:30 CEST

    EnglishTechnical

    Online

    • Which concepts, taxonomies, methodologies and frameworks formalise a Cyber Threat Model — and what has to be true before a machine, or an AI agent, can act on the result?

    What You'll Take Home

    Participants can place any claim on the two ladders and name its vocabulary, read a governed claim with its evidence, confidence and validation status, spot the six gaps of generation and the field that closes each — and describe how AI agents of any platform consume a governed model without owning it.

  • 02

    Webinar

    21. Oktober 2026, 15:30–17:30 Uhr MESZ

    GermanTechnical

    Online

    • Welche Konzepte, Taxonomien, Methoden und Frameworks formalisieren ein Cyber-Threat-Modell — und welche Voraussetzungen müssen erfüllt sein, bevor eine Maschine oder ein KI-Agent auf Basis des Ergebnisses handeln kann?

    What You'll Take Home

    Teilnehmende können jede Aussage in die beiden Ebenenmodelle einordnen und das verwendete Vokabular benennen, eine regulierte Aussage mit ihrer Evidenz, ihrem Vertrauensgrad und ihrem Validierungsstatus lesen, die sechs Lücken der Generierung erkennen und das jeweilige Feld benennen, das sie schließt – und beschreiben, wie KI-Agenten beliebiger Plattformen ein reguliertes Modell nutzen, ohne die Hoheit darüber zu übernehmen.

  • 03

    Onsite Workshop

    27. Oktober 2026, 09:30–11:30 und 14:00–16:30 Uhr MEZ

    GermanTechnicalBusiness

    it-sa Expo&Congress 2026 Nürnberg, Deutschland

    it-sa Expo&Congress logo
    • Der Business-Case: Business-Treiber, Zweck und Mehrwert eines regulierten Cyber-Threat-Modells

    • Das gemeinsame Nutzenversprechen mit CrowdStrike und SVA und das Referenzprojekt

    • Ein Cyber-Threat-Modell heute erstellen: die Herausforderungen und wie KI es verbessert

    • Angeleitetes Hands-on auf der IdoubleS CTM-Plattform

    • Referenzprojekt: Validierungsansatz, Architektur, Ergebnisse, Kundensicht

  • 03

    Onsite Workshop

    28 October 2026, 09:30–11:30 and 14:00–16:30 CET

    EnglishTechnicalBusiness

    it-sa Expo&Congress 2026 Nuremberg, Germany

    it-sa Expo&Congress logo
    • The business case: business drivers, purpose and value of a governed Cyber Threat Model

    • The joint value proposition with CrowdStrike and SVA, and the reference project

    • Producing a Cyber Threat Model today: the challenges, and how AI improves it

    • Instructor-led hands-on on the IdoubleS CTM platform

    • The reference project: validation approach, architecture, results, the customer’s view

Free ticket for it-sa Expo&Congress 2026

The onsite workshop takes place at it-sa Expo&Congress in Nuremberg. With our voucher code, your it-sa ticket is free of charge: copy the code and redeem it in the it-sa ticket shop.

Exclusive voucher code
593876itsa26

Please use the following link to redeem your voucher:

Redeem your voucher

Register

Select sessions *

Webinars (Online)

Workshops (Onsite at it-sa Expo&Congress)

This site is protected by reCAPTCHA. Details on how your data is processed can be found in our Privacy Policy.