New: Compliance toolkits for the EU AI Act and NIS2 (cybersäkerhetslagen) — templates your auditor will actually accept. Browse toolkits →

Talks

Practitioner-grounded talks on AI security

Anchored in systems I run, not survey papers. Slides, demos and write-ups go up here after each one.

Contributor, OWASP Top 10 for Agentic Applications 2026 · CISSP · PhD · 15+ years enterprise security

For organisers

Talk topics

Each topic is a 30 to 45 minute talk that can be delivered as a conference session or expanded into a half-day workshop.

Securing Agentic AI Systems: A Field Engineer's Guide

Walkthrough of the OWASP Top 10 for Agentic Applications 2026 with live demonstrations of prompt injection, tool poisoning, and confused deputy attacks against representative agent architectures.

Best for: technical conferences, OWASP chapters, security engineering teams.

The MCP Security Disaster: What Goes Wrong When Agents Get Tools

Specific deep dive on Model Context Protocol attack patterns. Tool poisoning, meta-context injection, cross-server attacks. Practical mitigations.

Best for: AI engineering audiences, infrastructure security teams.

AI Act Article 15 in Practice: Cybersecurity Requirements for High-Risk AI

The technical control mapping behind the EU AI Act's cybersecurity requirements. What the article actually requires of engineering teams.

Best for: compliance and governance audiences, IAPP chapters, regulated-industry security teams.

Threat Modeling for Agent Architectures

Hands-on workshop format. Extends STRIDE for agentic systems. Participants threat-model a representative system live.

Best for: engineering teams, internal training.

Previously

OWASP Stockholm: MCP Security, One Year In

OWASP Stockholm Chapter · May 2026

A debrief from a year of hands-on Model Context Protocol security work: where servers trust callers by default, the attack patterns that show up most often, and the mitigations that actually hold.

Read the debrief →

What audiences get

  • Slides and supporting material delivered before the event so AV and accessibility checks can happen properly
  • A demo environment available for hands-on segments (no production data, runs in a sandbox)
  • Time set aside for Q&A. The most valuable part of a talk is usually the questions.
  • Follow-up handouts for participants who want to go deeper

Corporate training

For private engagements (your own engineering org, security team, or partner audience), training is delivered as a 90-minute executive briefing, a half-day workshop, or a private on-site. Get in touch and we'll work out the right format for your team.

Booking

TypeFormatBooking lead time
Conference talk30 to 60 minutes, on stage6 months ahead is best
Private corporate trainingHalf or full day, on-site or remote8 to 12 weeks
Online workshop or webinar60 to 120 minutes4 to 6 weeks

Based in Gothenburg, Sweden. Comfortable traveling within Europe. One to two long-haul trips per year for major events. Honoraria expectations standard for senior practitioner speakers; exact terms depend on event size and format.

Submit a speaking request →