Modat at 38th Annual FIRST Conference
FIRST’s flagship annual conference, drawing incident response and security teams from dozens of countries.
- Dates
- 14 to 19 June 2026
- Where
- Denver, Colorado, United States
- Organiser
- FIRST
- Modat
- Bronze Sponsor, speaker and exhibitor
What ran through it
- Adaptive defence
- Passive DNS and pivoting
- Cloud supply chain attacks
- Incident response at scale
Conference theme: Peak Defense: Building Adaptive Systems for Modern Threats
Recap
How it went
We launched native Passive DNS
Announced at the conference: IP intelligence, device fingerprinting, certificates and Passive DNS unified in one investigation graph, every signal a first-class pivot point. The response from the FIRST community confirmed it addressed a long-standing gap.
Soufian presented on cloud supply chain attacks
On the Thursday, "Your Cloud, Their Code: The Supply Chain Attack You Didn’t See Coming" covered how attackers exploit cloud infrastructure through vectors most defender teams are not yet monitoring. Questions continued well after the session ended.
We hosted a World Cup watch party
The week opened on the Sunday at Tom’s Watch Bar for the Netherlands’ first match of the 2026 World Cup: a room full of security professionals, a lot of orange, and a much better start than a badge queue. Several conversations that began that evening ran all week.
Booth 13, and the main stage
We spent five days with the global FIRST community, on the exhibition floor and on stage, and left Denver with a long follow-up list.
Two research reports released at the conference
Stadium of Shadows mapped the infrastructure behind illegal IPTV around the World Cup. The RTSP study found 8,074 live video feeds reachable with no credentials at all.
Who was there
Pick up where we left off.
If you met us at FIRSTCON26, or meant to, write to whoever is closest to your work.
Soufian El Yadmani
Founder & CEO
Researcher and ethical hacker, and the person who will happily open the platform and pivot through your indicator with you. Alongside Modat he is Head of Research at CSIRT.global and finishing a PhD at Leiden University on threat actor attribution and hacking automation. He speaks regularly at RISE, FIRST and FS-ISAC.
Karen Sundermann
Head of Public Sector
More than a decade in cyber threat intelligence, data analytics and public safety. Previously VP Government Sector at EclecticIQ, where she led the global federal government business and built partnerships with national cyber security centres, defence organisations and law enforcement across Europe and Asia. Before that, years at IBM on identity fraud detection and disrupting organised crime networks.
Vincent Thiele
Co-Founder & COO
Twenty-five years across finance, government and technology, most of it on your side of the table: Head of Operations for ING Bank’s CISO department, CISO at Cybersprint, then Deputy CISO at Darktrace. A former FS-ISAC board member and current CSIRT.global board member, so he has sat through the vendor conversation from the buying seat.
Koen Volwerk
Director of Sales
Based in the Netherlands, and usually the first point of contact for a commercial conversation: the demo link on this site books time directly with him. He works with security and intelligence teams on where Internet Intelligence fits alongside the tooling they already run, and what it takes to get it into production rather than into a pilot that never ends.
Where we are going next
Four conferences before the end of the year, including a talk in Strasbourg.
See upcoming events →Missed us at FIRSTCON26?
Book a call and we will run the same walkthrough on your own data.