Idea: A new #InfoSec conference called "The Boring Security Conference". It covers topics and hands-on advice that are what actually keeps organizations secure. No zero-days, no APTs and no "if the criminal does these 39 things in precise order and you're not watching your owned" talks.
@chetwisniewski Sessions could be like "making inventory slightly less horrible", "tactics for convincing people that documentation is important", "how to protect those Windows XP SP1 machines you still have on the network for reasons"
@SmartAsABrick Absolutely. "EDR Grab back: Everyone bring their favourite queries to exchange". Understanding vulnerability disclosures: Reading between the lines and understand that unauthenticated RCE means patch now!