Sponsors
Location

Agenda
May 6, 2026
Jennifer KoldeTHE VERTEX PROJECT
Lee FosterASPECT LABSMay 7, 2026
Greg LesnewichPROOFPOINT
Nicole FishbeinINTEZER
Colin CowieSOPHOS
Michael HorkaLUMEN (Black Lotus Labs)
Julian-Ferdinand VogeleRECORDED FUTURE (Insikt Group)May 8, 2026
Roberto MartinezGOOGLE CLOUD (Mandiant)
Leon ChangTRENDAI
Michael August RaggiCROWDSTRIKECommittee
Kris leads PwC’s Global Cyber Threat Intelligence practice, which tracks a wide variety of targeted threat actors operating from more than 27 countries. This research underpins PwC’s security services and is used by public and private sector organisations around the world to protect networks, defend nations, provide situational awareness and inform strategy.
Kris also leads the EMEA Cyber Threat Operations practice – a front line technical services group responsible for a portfolio of defensive and offensive cyber security services to help clients detect and respond to cyber security threats and incidents.
He has spent the past 20 years at PwC delivering cyber incident response, threat hunting and threat research services to global clients across multiple sectors.
Jennifer Kolde has been an innovator in threat intelligence and analysis for over two decades. As a computer scientist with the federal government, she was a leading force in the early tracking of nation-state threats. Jennifer was part of the original Mandiant Threat Intelligence team and later led the team as its technical director. She supported cutting-edge DARPA research, testified before Congress on emerging cyber threats, and acted as an expert witness on threat intelligence and attribution. She is currently a Principal Intelligence Analyst for The Vertex Project.
Chris is the Deputy Threat Research Manager at SentinelLabs where he leads a dedicated team specializing in the research and analysis of a spectrum of threats. His primary focus is on equipping customers with comprehensive analysis and insights, aiding them in effectively safeguarding their organizations.
Chris’ career spans more two decades, marked by a number of significant roles. Before his current tenure at SentinelOne, he served as Head of Threat Research at Stairwell and as a Sr. Staff Threat Researcher, Research Team Lead at Chronicle (Google Cloud), Manager of Espionage Intelligence at iDefense, and Lead Researcher at Rackspace. He is also an organizer of the annual LABScon conference.
Christopher Glyer is a Technical Director with Microsoft Threat Intelligence, where he oversees the strategic direction and execution of threat intelligence initiatives. In this role, he leads the technical strategy for a team of experts dedicated to identifying, analyzing, and mitigating advanced cyber threats. Christopher’s work involves collaborating with various stakeholders to enhance Microsoft’s security posture and protect customers from emerging threats.
Vicente is a specialist in Threat Intelligence and Threat Hunting. He works in the VirusTotal team in Google as Threat Intelligence Strategist. He holds a degree in Computer Science and an MsC in Artificial Intelligence. He was e-crime manager in S21sec for 5 years and deputy director for EU in Kaspersky’s Global Research and Analysis team for almost 10 years, where he was co-creator and responsible for the APT Intelligence Reporting service.
Timo was involved in the analysis of many of the most spectacular cyber-espionage cases in Germany. He has been tracking the activities and techniques of sophisticated hacker groups for almost a decade. He is the author of ‘Attribution of Advanced Persistent Threats’.

FAQs
PIVOTcon is an invite-only event (with a maximum of 160 vetted attendees) focusing on threat research and technical analysis tradecraft. Contrary to the classic model of presentation tracks, this conference is designed to encourage interaction and sharing between speakers and the audience through:
– One-track only speaking slots
– Discussion panels on observed trends and research methodologies
– Debates on difficult and controversial industry topics
– Research workshops
PIVOTcon will be held in Malaga, Spain from Wednesday 6th May until Friday 8th May. We will start on Wednesday with afternoon workshops & evening Fireside chat, and the main conference will run on the 7th and 8th.
Please complete the Google form here. Anyone can request an invitation using the official form. Our team will verify each request and then send the final registration link to purchase the ticket. Verification may take some time in some cases, so please be patient. Fill in as many details as possible in the Google Form that will help us with vetting, especially the “Referred by” field.
Our goal is to organise a trusted in-person event where threat analysts can share their research, ideas, and uncertainties in a safe environment. Concept is based on intelligence sharing trust groups.
All submissions should be sent via Pretalx platform: https://pretalx.com/pivotcon25/cfp
The talks are 25 minutes of presentation and 5 minutes for Questions & Answers.
Yes, PIVOTcon covers full hotel accommodation, conference fee. Travel costs are covered up to:
- 1500 USD for travels outside Europe
- 500 EUR for travels inside Europe
- 150 EUR for travels inside Spain
If you are the second speaker, we will cover only the event ticket without the accommodation and travel.
PIVOTcon focuses on threat research and will include topics on threat intelligence, threat actors tracking, influence operations in cyberspace, financially motivated cybercrime, private sector spycraft industry, state-affiliated operations but also vulnerability research with the clear link to threat actors.
All submissions will be carefully considered by the members of the PIVOTcon Programme Committee, who are distinguished experts representing multiple research areas.
If you are interested in sponsoring PIVOTcon, please send us an email at info@pivotcon.org
No, talks will not be streamed, nor recorded. We believe that researchers are more keen to share when the results of threat research are not public. PIVOTcon should be a safe place to talk about threat operations and analysis.
The conference is single track only.








































