Program Sikkerhetsfestivalen 2026

Physical Security

The Endpoint that walks: Mobile Devices as Physical Security Risks

Tirsdag 2 · Home hotel Hammer, moen oppe

EnglishDetailed 40 min

Lorena Carthy-Wilmot

Lorena Carthy-Wilmot

Head of Security Strategy at iVerify

Lorena Carthy-Wilmot is a digital forensics and cybersecurity professional and has built her career across law enforcement, journalism, and consulting, with a focus on mobile forensics and sensitive, time-critical investigations. Lorena led the Forensic Technology Services Lab at PwC Norway, conducted digital investigations into complex criminal cases as a Special Investigator with the Norwegian Police's Section for Digital Police Work, and served as a security engineer across six newsrooms at Schibsted, where she protected the communications and work of journalists operating in high-risk environments. At iVerify she supports incident response investigations and acts as a subject matter expert in mobile security and digital forensics for CISOs and security leaders across Europe. Beyond her professional pursuits, Lorena enjoys playing roller derby and hiking.

Lorena is based in Oslo, Norway.

Physical security traditionally focuses on buildings, access control, surveillance, and personnel safety. At the same time, mobile devices are usually treated as an IT problem. This separation creates a critical blind spot.

Mobile phones are physical assets. They move through secure and insecure environments, cross trust boundaries, and stay with people during stress, conflict, authority interactions, and incidents. They are at home and abroad. They are cameras, microphones, tracking devices, identity containers, and access tokens and all carried directly on the body.

This talk reframes mobile security as a physical security and human risk problem. Using real-world scenarios from journalism, public sector operations, emergency response, and law enforcement contexts, it demonstrates how mobile devices undermine traditional physical security assumptions and why security culture often fails at the human layer.

  1. Insecure Vibes: The Risks of AI-Assisted Coding 1 · Frimurerlosjen, rom 1
  2. When defenders go low, we go high(level) - bypassing application control using stage 1 beacons 1 · Frimurerlosjen, rom 2
  3. PQC-migrasjon for store virksomheter 10 · HeartBox ,Teatersalen
  4. Hawaii Pizza – How dare you? (or do I really care?) 10 · HeartBox, Byscenen
  5. Sikkerhetskrav i randsonen: Slik treffer sikkerhetskravene underleverandørene 11- Breiseth, Storlon
  6. A Recipe for Resilience: Using Purdue and IEC 62443 to Secure Europe's Food Supply 2 · Home hotel Hammer, moen nede
  7. Innsiderisiko: forskningsperspektiver og foreløpige funn 3 · Hvelvet, Gullsalen
  8. Sykt mange sikkerhetskrav i offentlig anskaffelse: Må det være sånn? 4 · Kommunestyresalen, Lillehammer rådhus
  9. En felles IAM-virkelighet for offentlig sektor, er det mulig? 5 · Kulturhuset Banken, Expedisjon
  10. Maritime næring i skuddlinjen - erfaringer fra dagene da USA og Israel angrep Iran 5 · Kulturhuset Banken, Festsalen
  11. Når tiden forsvinner. Strategier for fremtidens digitale beredskapsarbeid 5 · Kulturhuset Banken, Holbøsalen
  12. AI i digital etterforskning 5 · Kulturhuset Banken, Kafeen
  13. Maverick RiskJockey: en AI-drevet CISO-funksjon 6 · Lillehammer kino, sal 2
  14. 10 «dumme» spørsmål - og hva de avslører om sikkerhetskulturen 6 · Lillehammer kino, sal 4
  15. Podcast O3C 7 · Microbryggeriet
  16. Et tu, vendor? A story of vendor ransomware leaks and heartaches 9 · Victoria Scandic, sal 1+2
  17. Multi-Agent Orchestration to Catch Bad Guys 9 · Victoria Scandic, sal 3