Program Sikkerhetsfestivalen 2026

Operational Technology

Pirates Of The North Sea

Onsdag 2 · Home hotel Hammer, moen nede

NorwegianHigh-level 40 min

John Andre Bjørkhaug

John Andre Bjørkhaug

Red Team Lead

John-André Bjørkhaug holds a degree in electronic engineering, but has spent most of his career happily breaking things instead of building them. He has been working as a penetration tester since 2008, with a primary focus on infrastructure, physical security, industrial control systems, IoT, and social engineering.

Egil Aspevik

Egil Aspevik

Netsecurity, RedTeam

Egil has been doing IT since Monkey Island 1, Turbo Pascal and DOS. He is a member of the Netsecurity RedTeam and has worked in IT his whole life.

He takes these speaker biography descriptions as an opportunity to create a false image of himself, and he is usually recognized as the smartest and most handsome man in the room. He is also the strongest person on earth.

How secure are the ships that move the world’s cargo and passengers?

This talk presents red team operations against cruise ships, cargo vessels, and shipping companies, showing how attackers can board vessels undercover as passengers and pivot from guest networks into corporate and operational systems. In the talk it is demonstrated how weak network segmentation, legacy OT, and insecure satellite and wireless infrastructure enable full compromise of both IT and safety-critical environments.

Through real world examples, we show how physical access to bridges, communication rooms, and engine spaces was combined with cyber attacks, and how navigation and communication systems can be disrupted using GPS and AIS spoofing and jamming with cheap and simple equipment.

The talk Pirates of the North Sea reveals why modern ships are one of today’s most overlooked cyber-physical attack surfaces, and what offensive security work in these environments can teach us about how to defend expensive, lifesaving and critical infrastructure.

  1. When freedom is at stake - from Ukraine's frontline to Norwegian preparedness 5 · Kulturhuset Banken, Festsalen
  2. Hack Faster Than You Deploy: Integrating Continuous Penetration Testing into the SDLC. 1 · Frimurerlosjen, rom 1
  3. WSL: Nice for developers, even nicer for red teamers 1 · Frimurerlosjen, rom 2
  4. CI/CD: The Most Privileged System in Your Cloud 10 · HeartBox, Byscenen
  5. Employer Oversight Meets Neural Insight: Business Case, Risks and Governance 11- Breiseth, Storlon
  6. Fra styrerom til sikkerhetsvakt: Den røde tråden fra risikostyring og compliance til operativ sikker 2 · Home hotel Hammer, moen oppe
  7. Innsidere og spionasje 3 · Hvelvet, Gullsalen
  8. Supply Chain Security - Protecting your business - End to End 4 · Kommunestyresalen, Lillehammer rådhus
  9. Hva gjør vi for de små ? 5 · Kulturhuset Banken, Expedisjon
  10. Kriseledelse i blindebukk – strategi og jus når skjermene går i svart 5 · Kulturhuset Banken, Holbøsalen
  11. verdivurdering2025_final_v4_ENDELIG.xlsx 6 · Lillehammer kino, sal 2
  12. Det er ikke deg, det er systemet! HOP som nøkkelen til robust cybersikkerhet 6 · Lillehammer kino, sal 4
  13. Exposing a cybercrime network 9 · Victoria Scandic, sal 1+2
  14. Hvordan overleve en pentest 9 · Victoria Scandic, sal 3
  15. UPN Gone Wrong: Breaking Identity Security in Azure & Entra ID 5 · Kulturhuset Banken, Expedisjon
  16. Passord: trusselmodell, beskyttelse og hvorfor kompleksitet betyr noe 5 · Kulturhuset Banken, Expedisjon