Tabletop Lessons from 3 Decades and 2 Continents @FIRSTdotorg
Tabletop Lessons from 3 Decades and 2 Continents  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 7 minutes ago
enneth Van Wyk (KRvW Associates, LLC, US)

The authors have decades of experience in incident response operations as well as in building and delivering realistic tabletop exercises across two continents. In this session, they dive deeply into the most common and painful lessons they've observed, and how to prevent them.

---

Kenneth R. van Wyk is an internationally recognized information security expert and author of three popular books, Enterprise Software Security, Secure Coding, and Incident Response. In addition to providing consulting and training services through his company, KRvW Associates, LLC (https://KRvW.com). He also currently is a faculty member at IANS Research (https://iansresearch.com) and a visiting scientist at Carnegie Mellon University’s Software Engineering Institute.

Ken served 11 years on the Forum of Incident Response and Security Team’s (FIRST, https://first.org) Steering Committee and Board of Directors. Ken was previously the project founder and leader of the Open Web Application Security Project (OWASP) iGoat project (github.com/owasp/igoat) and served 10+ years on the Board of Directors for SecAppDev (http://secappdev.org).

Ken has over 30 years experience as an IT Security practitioner in the commercial, academic, and military sectors. He has held executive and senior technologist positions at Tekmark, Para-Protect, Science Applications International Corporation (SAIC), the U.S. Department of Defense, Carnegie Mellon University, and Lehigh University.

At Carnegie Mellon University’s Software Engineering Institute, Ken was one of the founders of the Computer Emergency Response Team (CERT®). He holds a mechanical engineering degree from Lehigh University and is a frequent speaker at technical conferences, and has presented tutorials and technical sessions CSI, ISF, USENIX, FIRST, AusCERT, and others.

Elliott Atkins is the founder of Exercise3, an NCSC-UK assured provider of cyber incident exercising which uses realistic scenarios to help organisations test and improve their cyber incident preparedness. Prior to founding Exercise3, he held a series of senior roles, including Head of the UK Government’s Computer Emergency Response Team (GovCertUK), Head of Cyber Intelligence at QinetiQ and Head of Incident Response at Nominet, the UK top-level domain registry.

Elliott is a Professor of Practice at the University of Wales Trinity Saint David, a Fellow of the British Computer Society and a FIRST Liaison Member. He was appointed by Her Majesty the Queen as the first Chief Information Security Officer to the Royal Household in 2021.
Tabletop Lessons from 3 Decades and 2 ContinentsUncovering the Whispers of an APT Targeting Specific Industries in South AsiaOperational Efficiency in CTI: A Blueprint for SMEs Using Open-Source AI and Cognitive AutomationMalicious Code-signing at Scale: How Attackers Impersonate Thousands of Real BusinessesDiving into the CVSS Base Score Metrics - An Exploratory Analysis Bridging Product Security...EU Cyber Resilience Act - A Product Owner’s ApproachContextual SBOMs: Unlocking Precise Vulnerability Management with Build-Time Content IntelligenceThe AI Arms Race in Vulnerability Management, Who’s Winning?Disparate Data, Distorted Decisions: Vendor Data Bias in CTIImproving Security Across Nations with FIRST: Enrico Lovat, FIRST MemberImproving Security Across Nations with FIRST: Cornelia Shipindo, FIRST MemberThe Clock is Ticking: CRA Compliance at Scale
FIRST |

Tabletop Lessons from 3 Decades and 2 Continents

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER