General session image of Knowledge Forum D

What intelligence agencies do before reporting: Unmasking APTs before NIS2 requires it

Waiting means reacting. Searching means leading: how intelligence services hunt APTs with forensic indicators, even where no agent runs.

Topic

SIEM / Threat Analytics / SOCAwareness / Phishing / FraudGovernance, Riskmanagement and Compliance

When & Where

calendar_month

Wed, 10/28/2026 01:30 PM - 01:45 PM

location_on

Forum D, Booth 7-742

Download session as iCaldownload_for_offline

Details

  • Format:

    Management lecture

  • Language:

    German

Session description

Speaker: Patrick Perez

Attackers target the most valuable thing we have. Our data. And the problem isn't the attack, it's that we often don't notice it. A professional moves quietly and exfiltrates data without triggering a single classic alarm. Intelligence services don't wait for that warning. They assume the adversary is already inside and search deliberately for the quiet forensic indicators that no standard tool has on its radar. A forensic APT scan makes exactly that visible, even where no agent runs. For 2026, that's no longer a nice-to-have. It's a must.