Skip to content

Details

Cyber Scotland Connect is thrilled to announce our next event in Central Edinburgh at CodeBase Edinburgh, supported by RiverSafe, which has kindly sponsored the event!

Time/Date: November 26th, 2026, 17:30-20:30
Location: CodeBase Edinburgh, 37a Castle Terrace, Edinburgh EH1 2EL

Please note that we have a limit of 80 attendees, so please update your RSVP if you can no longer make it.
Agenda

  • 17:30 - Doors Open
  • 17:55 - Harry from CSC: Welcome!
  • 18:00 - Gary Hunter
    The Path to an Agentic SoC*: A practical, real-world framework for introducing AI safely into security operations without falling into the “AI all the things” trap. Learn how to combine IaC, human-in-the-loop automation, agent constraints and AI Error Budgets to improve speed and coverage. Based on first-hand experience from an eight-person security team protecting a FTSE 350 SaaS platform across AWS and GCP.
  • 18:30 - Joshua A.
    Reading Malware Config Off the Blockchain (NullReceiver Malware)
    How a developer-targeted campaign used next.config.js and .vscode/tasks.json as execution primitives, and why config files deserve the same scrutiny as application code.
  • 19:00 - Rory McCune
    Surviving 2026 - A Security practitioners Field Guide to LLMs and Agents*: This year I've tested nearly 50 models and used several of them to build real projects, from production software to PoC exploits. Over the course of the year agents have gone from novelty to everyday tooling, bringing new capabilities and a new attack surface with them.*
    This talk is a practical guide from someone who's been hands-on all year. We'll talk about which models and tools actually deliver, how to get useful work out of agents, and where they fail, from confidently wrong output to security refusals. I'll also take a look at how to evaluate the constant stream of new releases without drowning in hype, so you leave with an approach that will still hold up when next week's model drops.
  • 19:30 - Caleb Eghan
    Break the bank: welcome to the other side of the login screen:
    A lot of apps look secure from the login screen. This session shows what happens once you get past it.
    Using Rozolo, our deliberately vulnerable banking app, we follow a single £1 payment through the API layer and watch it turn into exposed customer data and unauthorised transactions. The weaknesses on show are the ones a scanner or firewall tends to miss: broken authorisation, weak object-level access control, and data the API hands back without being asked for it.
    The API layer is now the softest part of most estates, and perimeter controls do little to defend it. We use the walkthrough to show where a modern API security strategy actually earns its place: visibility over what your APIs expose, authorisation enforced per object rather than per endpoint, and testing that hunts for logic and access flaws rather than known signatures.
  • 20:30 - Close

Please ensure you RSVP to this event, as we're limited in the number of people we can accommodate.

Keeping CSC Accessible for All
Cyber Scotland Connect has always been, and will always be, free to attend. We believe that barriers to entry—especially for students, career switchers, and those currently seeking new opportunities—should be nonexistent.
How you can help: If you are established in your career and find value in our sessions, we invite you to Pay It Forward.
While there is zero obligation, we have launched a Buy Me a Coffee page. Your contributions help us cover our essential running costs, which are mostly refreshments and some minor infrastructure costs, ensuring that those in our community who are currently unemployed or studying can continue to attend and network at no cost.

  • Tickets: Always £0.
  • The Goal: A sustainable, community-funded future for CSC.
  • The Impact: Supporting the next generation of Scotland’s cyber talent.

Please ensure you have reviewed our code of conduct, which outlines our expectations for all participating in our community and the consequences for unacceptable behaviour.

Related topics

Events in Edinburgh, GB
Application Security
Cybersecurity
Network Security
Ethical Hacking
Information Security

You may also like