OWASP Switzerland Event - 25th Anniversary Edition
Details
Join OWASP Switzerland for our OWASP Foundation 25th Anniversary Celebration Meetup; marking 25 years of advancing application security worldwide. This time we meet at the Zurich Information Security and Privacy Center of ETH Zurich.
Three talks on cutting-edge security topics, followed by a festive apéro with finger food, drinks, and all the trimmings to celebrate OWASP's Anniversary!
Program:
15:30 - Doors open: Grab a drink, meet old and new friends from the OWASP Switzerland community
16:00 - Hello from OWASP Switzerland
16:20 - Talk 1, From Tool to Teammate: Making AI a Strategic Partner in Cybersecurity (Andra-Irina Vasile/Senior BISO, SIX)
17:10 - (5min break)
17:15 - Talk 2, Pitfalls in Phishing Prevention: Why well-intended advice may make things worse (Daniele Lain, ETH Zurich)
17:55 - (5min break)
18:00 - Talk 3, From APIs to Agents: OWASP as a Unified Prioritization Lens (Dante Hollingsworth/Cloud Solution Architect and Ibraimo Djalo/Solution Engineer, Microsoft)
19:00 - Networking, Apéro Riche🍷🎂🌮
Talk Details:
Talk 1 Abstract: Move past the hype with a practical blueprint for shifting your AI strategy from a tool you deploy to a teammate you onboard within your cybersecurity operations. This session focuses on eliminating the operational friction that stalls modern security, establishing a secure framework to transition safely from assistive to autonomous cyber defense. Ultimately, it provides a roadmap to maximize operational speed while firmly anchoring human accountability, ethical guardrails and regulatory standards.
***Key Points ***
• Real-Life Operational Examples: Practical use cases for incorporating AI directly into your security operations like SOC, Threat Intelligence, Threat Hunting and Vulnerability Management.
• The "Teammate" Paradigm: Why the goal of AI integration is not to replace human talent, but to remove the repetitive manual workload so your team can focus on high-judgment defense tasks.
• Explainable AI, Ethics & Governance: Critical strategies for managing algorithmic bias, preventing overconfidence in automated alerts, and establishing clear lines of human accountability when a model makes an error.
• The 5-Rule Playbook: Practical framework for rolling out AI, measuring its true operational impact and managing its long-term integration within your security team.
Talk 1 Speaker Bio: I believe security is a modern civic virtue, not just a technical skill. By day, I build cybersecurity strategy in the Swiss financial sector, building resilient frameworks and secure innovation. By night, I’m on a mission to turn "scary hacking" into "digital manners" through my initiative, Netiquetteers. Whether I’m advising product teams on secure workflows, coaching the next generation of cyber talent, or empowering families to navigate the AI era, my goal is the same: translating complex tech into human empowerment.
Talk 2 Abstract:
As users are exposed to an unprecedented range of security threats, a rich ecosystem of support mechanisms has emerged to assist the "last line of defense". Yet as these mechanisms become widely adopted in industry, a question arises: do they provide the support users actually need?
We will start by showing that this is not always the case. Using phishing (one of the most prevalent and damaging cybercrimes) as a case study, I will present results from large-scale, real-world measurement studies that challenge common assumptions: that widely deployed mechanisms such as training and password managers are inherently effective, and that users primarily lack knowledge about this threat and how to detect it. Instead, I will show that phishing susceptibility is often an attention problem, due to limited and poorly surfaced indicators and cues.
To conclude, I will show some recent research results that translate these insights into the design of novel systems that better support secure behavior.
Talk 2 Speaker Bio:
Daniele Lain is a postdoctoral researcher at ETH Zurich, focusing on supporting users in secure decision making through user-facing defenses and system-level security, with a particular interest in how AI can help protect everyone's digital life.
Besides academic work, he is active in Capture The Flag (CTF) cybersecurity competitions, currently coordinating mhackeroni, the leading Italian CTF team.
Talk 3 Abstract:
Security teams are being asked to protect an ever-expanding technology landscape that now spans web applications, APIs, cloud platforms, software supply chains, AI systems, agents, and non-human identities. The challenge is no longer a lack of security guidance. It is knowing where to focus first.
In this session, we explore how OWASP can be used as a unified prioritization lens for modern security programs. Rather than treating the various OWASP Top 10 frameworks as separate checklists, we will examine the common risk themes that connect them and show how a small number of foundational security controls can reduce risk across multiple technology domains simultaneously.
Key Points:
- Understand how multiple OWASP Top 10 frameworks can be mapped to a smaller set of common risk domains and control priorities.
- Identify security investments that reduce risk simultaneously across applications, APIs, CI/CD pipelines, AI systems, agents, and non-human identities.
- Recognize how traditional security challenges are attacks amplified in AI-powered and agentic environments.
- Apply a practical risk-based approach to prioritizing security initiatives when time, budget, and resources are limited.
- Build a more unified security strategy that focuses on foundational controls with the greatest impact across multiple technology domains.
Talk 3 Speaker Bio:
Dante Hollingsworth is a Cloud Solution Architect at Microsoft focused on cloud, AI, and Secure DevOps. With over 20 years of experience in information technology and cybersecurity , he helps organizations secure modern platforms, improve threat resilience, and implement risk-based security strategies across cloud, DevOps, identity, and AI ecosystems.
Ibraimo Djalo is a cybersecurity specialist at Microsoft who helps organizations improve security across identity, compliance, threat protection, and modern digital platforms. With experience spanning engineering, architecture, and customer advisory roles, he is passionate about making cybersecurity practical, accessible, and impactful for organizations of all sizes.
