Skip to content
Modat Try Magnify
FIRSTCON26 · 2026 RECAP

Modat at 38th Annual FIRST Conference

FIRST’s flagship annual conference, drawing incident response and security teams from dozens of countries.

Dates
14 to 19 June 2026
Where
Denver, Colorado, United States
Organiser
FIRST
Modat
Bronze Sponsor, speaker and exhibitor

What ran through it

  • Adaptive defence
  • Passive DNS and pivoting
  • Cloud supply chain attacks
  • Incident response at scale

Conference theme: Peak Defense: Building Adaptive Systems for Modern Threats

Recap

How it went

01

We launched native Passive DNS

Announced at the conference: IP intelligence, device fingerprinting, certificates and Passive DNS unified in one investigation graph, every signal a first-class pivot point. The response from the FIRST community confirmed it addressed a long-standing gap.

02

Soufian presented on cloud supply chain attacks

On the Thursday, "Your Cloud, Their Code: The Supply Chain Attack You Didn’t See Coming" covered how attackers exploit cloud infrastructure through vectors most defender teams are not yet monitoring. Questions continued well after the session ended.

03

We hosted a World Cup watch party

The week opened on the Sunday at Tom’s Watch Bar for the Netherlands’ first match of the 2026 World Cup: a room full of security professionals, a lot of orange, and a much better start than a badge queue. Several conversations that began that evening ran all week.

04

Booth 13, and the main stage

We spent five days with the global FIRST community, on the exhibition floor and on stage, and left Denver with a long follow-up list.

05

Two research reports released at the conference

Stadium of Shadows mapped the infrastructure behind illegal IPTV around the World Cup. The RTSP study found 8,074 live video feeds reachable with no credentials at all.

Who was there

Pick up where we left off.

If you met us at FIRSTCON26, or meant to, write to whoever is closest to your work.

Soufian El Yadmani

Soufian El Yadmani

Founder & CEO

Researcher and ethical hacker, and the person who will happily open the platform and pivot through your indicator with you. Alongside Modat he is Head of Research at CSIRT.global and finishing a PhD at Leiden University on threat actor attribution and hacking automation. He speaks regularly at RISE, FIRST and FS-ISAC.

Karen Sundermann

Karen Sundermann

Head of Public Sector

More than a decade in cyber threat intelligence, data analytics and public safety. Previously VP Government Sector at EclecticIQ, where she led the global federal government business and built partnerships with national cyber security centres, defence organisations and law enforcement across Europe and Asia. Before that, years at IBM on identity fraud detection and disrupting organised crime networks.

Vincent Thiele

Vincent Thiele

Co-Founder & COO

Twenty-five years across finance, government and technology, most of it on your side of the table: Head of Operations for ING Bank’s CISO department, CISO at Cybersprint, then Deputy CISO at Darktrace. A former FS-ISAC board member and current CSIRT.global board member, so he has sat through the vendor conversation from the buying seat.

Koen Volwerk

Koen Volwerk

Director of Sales

Based in the Netherlands, and usually the first point of contact for a commercial conversation: the demo link on this site books time directly with him. He works with security and intelligence teams on where Internet Intelligence fits alongside the tooling they already run, and what it takes to get it into production rather than into a pilot that never ends.

Where we are going next

Four conferences before the end of the year, including a talk in Strasbourg.

See upcoming events

Missed us at FIRSTCON26?

Book a call and we will run the same walkthrough on your own data.

38th Annual FIRST Conference official site

Intent leaves a trace.

Talk to us about your needs