Uploaded August 2026 | Updated September 2026, 7 minutes ago
Marthe Råheim Rogndokken (Sopra Steria, NO)
Every cyber attack raises the same question: Who did it? But what should you know before trying to find that out? This talk takes you through the first steps of getting started with threat‑actor profiling — exploring the attribution problem, profiling, existing attribution models, and PACT, a new framework in progress built to facilitate the cyberattack‑attribution process.
Key takeaways:
Attendees will learn how to get started with threat‑actor profiling, understand the key elements that should be included, and apply a structured methodology to the process. The session will also cover challenges and suggestions on how to address them.
---
Marthe Råheim Rogndokken has a background spanning business, law enforcement, and cybersecurity. She has studied International Business in Slovenia. Later she graduated from the Norwegian Police Academy, and served as a police officer in both the first response unit and investigations. Her passion for technology and security led her to Australia, where she specialized further by completing a bachelor’s degree in cyber security. Marthe is currently a Cyber Threat Intelligence Analyst at Sopra Steria, Norway.
Her research on the PACT - a profiling and attribution model - was published in Procedia Computer Science on ScienceDirect 2025, and presented at the International Conference on Industry Sciences and Computer Science Innovation (iSCSi) in Portugal.
Marthe is an experienced public speaker, having presented at several conferences in Norway, including FIRST TC Oslo. She is well-versed in sharing knowledge with both technical and non-technical audiences.
Outside of work, Marthe is drawn to speed and adrenaline — whether it’s go-karting, surfing, or downhill mountain biking.
Marthe Råheim Rogndokken (Sopra Steria, NO)
Every cyber attack raises the same question: Who did it? But what should you know before trying to find that out? This talk takes you through the first steps of getting started with threat‑actor profiling — exploring the attribution problem, profiling, existing attribution models, and PACT, a new framework in progress built to facilitate the cyberattack‑attribution process.
Key takeaways:
Attendees will learn how to get started with threat‑actor profiling, understand the key elements that should be included, and apply a structured methodology to the process. The session will also cover challenges and suggestions on how to address them.
---
Marthe Råheim Rogndokken has a background spanning business, law enforcement, and cybersecurity. She has studied International Business in Slovenia. Later she graduated from the Norwegian Police Academy, and served as a police officer in both the first response unit and investigations. Her passion for technology and security led her to Australia, where she specialized further by completing a bachelor’s degree in cyber security. Marthe is currently a Cyber Threat Intelligence Analyst at Sopra Steria, Norway.
Her research on the PACT - a profiling and attribution model - was published in Procedia Computer Science on ScienceDirect 2025, and presented at the International Conference on Industry Sciences and Computer Science Innovation (iSCSi) in Portugal.
Marthe is an experienced public speaker, having presented at several conferences in Norway, including FIRST TC Oslo. She is well-versed in sharing knowledge with both technical and non-technical audiences.
Outside of work, Marthe is drawn to speed and adrenaline — whether it’s go-karting, surfing, or downhill mountain biking.










