Skip to content

Details

Join us at the OWASP Scotland Chapter Meeting where we have several talks lined up - see details below.

Pizza and drinks will be provided to the attendees.

This event is perfect for software developers, ethical hackers, and cybersecurity enthusiasts interested in learning about the latest trends in cyber security.

#### Talk 1 - Update from Hays on ‘The Cyber Market for Scotland and Beyond’

Speaker: James Walsh

Bio: James Walsh - Director of Cyber Security Practice UK&I – Hays – James has over 15 years specialising in Cyber/Information Security working with some of the largest Private and Public Sector organisations. He will be giving an update on ‘The Cyber Market for Scotland and Beyond’

#### Talk 2- ACME Windpharm

Speaker: Colin Cassidy

Talk 2 - ACME Windpharm
Synopsis: The talk will cover the basics of windfarms and their operations, I’ll briefly discuss prior research in this area, noting that those findings are still valid today. Then the core of this talk will focus on identified security threats and their mitigations based on real life assessments. The impact these threats can have both in terms of windfarm operation and the physical damage that can be caused. I will show how physical and remote access to the windfarm can be gained, and by investigating the vulnerabilities found, I will show that there is an over-reliance on security boxes and buzzword solutions that has left general, basic, security hygiene lacking. So much so that that in some cases, not only have systems not been patched, but they were installed insecurely in the first place. I will then discuss the recent 2025 Polish renewables attack and how it ties back to all the topics covered earlier.

There will be two key takeaways from this talk. Firstly, I will be busting the myth that ‘cutting off the supply’ is the most interesting attack that can be performed. It is the most likely, and one of the simplest attacks, but it is not the most interesting. Secondly, I will cover a point often glossed over in other talks. When an attacker ‘takes control’ it is often simply left at that, as if taking control was the ‘win condition’. This talk will cover some of the more interesting cyber physical attacks that can be performed on a wind farm and look at some of the ways that actual physical damage could be caused.

Bio: Colin Cassidy used to be a Senior Software Engineer at GE for 15 years working on their Distribution Management System (DMS) which runs most of the UK's electrical distribution network. He is currently atoning for all his software development sins as a Principal Security Consultant with IOActive. Colin has performed several security audits for ICS operators including some of the UKs largest Distribution Network Operators, several windfarms, container ships, shipping terminals, and AMI/smart meter infrastructure. Colin has also presented and Blackhat and Defcon on vulnerabilities found in Industrial Ethernet Switches. In his spare time, he searches for spare time.

Talk 3 - TBC

Related topics

Events in Edinburgh, GB
Application Security
Cybersecurity
Software Security
Web Security
White Hat Hacking

You may also like