On June 17th, we flew out to Crete for ICVAM-26, the International Conference on Vulnerability Assessment and Management. It’s a research conference, not a security conference per se, and the agenda covered everything from AI in classrooms to lithium battery fires to lentil genetics. You might wonder what a cybersecurity company was doing there. We’ll get to that.

How the day was structured

The morning opened with three keynotes from Prof. Dr. Atul Khajuria, Vilas Balgaonkar, and Anna Kurzych. Then eighteen technical presentations, ten minutes each including Q&A. No bloated hour-long slots. Presenters had to get to the point fast, and most of them did. It made for a better day than the sprawling multi-track affairs you sit through at bigger events.

What caught our attention

Talks were grouped by UN Sustainable Development Goals. Not all of them had obvious ties to cybersecurity. But some did, and the ones that didn’t were interesting for other reasons.

AI in the classroom

This was the cluster we spent the most time thinking about afterward. Three separate presenters looked at AI adoption in education. Dr. Chou Sin Yu talked about integrating AI into creative art teaching during practicum placements. Dr. Chim Ka Man examined AI literacy among early childhood education students — specifically how they actually use AI tools day to day versus what they say about them in surveys, which is a gap worth paying attention to. Hui-Fang Shang’s work on OpenAI tools and EFL writing quality rounded out the set.

The security angle here is probably obvious to anyone reading this blog: every new context where people adopt AI tools is a context where those tools get overtrusted. Teachers learning to use ChatGPT in lesson planning are not thinking about prompt injection. Watching how non-technical users build habits around these systems tells us something about where social engineering is headed.

Predictive maintenance and critical infrastructure

Carlos Villarreal presented on early-life indicators for predictive maintenance in urban rail. Rail networks run on sensor data and connected monitoring platforms now, which means they run on attack surface. The OT/IT boundary in transit systems is messy and getting messier.

Prof. Ing. Zuzana Murcinková’s talk was pure materials science — experimental analysis of composite material properties (CFRP, GFRP). Not our field at all. Still, there’s something useful about hearing infrastructure resilience discussed in a context that has nothing to do with networking or software.

AI agents in marketing workflows

Richie Enrico Tanujaya talked about generative and agentive AI reshaping marketing workflows. Short talk, but it stuck with us. Automated pipelines that touch customer data, fire off communications, and plug into third party APIs — that is our day job from the other side.

Battery fires and risk patterns

Stefan Georgiev’s research on lithium battery fires in Austrian households had a structure that’ll feel familiar to anyone who does threat intel work. Pattern recognition in incident data, risk categorization, prevention modeling. Swap “battery fire” for “credential compromise” and you’re reading an incident report.

Location intelligence for public health

A Colombian team led by Aurora Ines Gafaro Rojas presented semi-automated georeferencing for public health management in Santander. The analytical methods are the same ones showing up more and more in threat intelligence — mapping infrastructure the way epidemiologists map disease.

Why we go to conferences like this

If we only went to security conferences we’d only hear from security people. That’s fine for staying current on CVEs and tooling. It doesn’t help much with thinking about the systems that security sits inside of.

Someone studying how teachers build trust with AI tools knows things about human behavior that most pentesters never think about. An engineer modeling failure modes in rail infrastructure works the same kind of systemic problem we do. You pick up things at these events that you wouldn’t get from a DEF CON talk, and honestly some of the best conversations happened during breaks, not during sessions.

ICVAM is small enough that you actually talk to presenters. That alone makes it worth going.

Crete was a good spot for it, too.

What’s next

We brought back a few threads we want to pull on, particularly around AI adoption patterns and OT security in transit infrastructure. Some of that will show up in future posts.

If you were at ICVAM-26 or work on any of the topics above, get in touch through our contact page.

Want to learn more about what TSO does? See our full range of services, including managed detection and response, attack and prevent, and compliance and strategy.