Speaking
I speak at conferences and industry events about software supply chain security — SBOMs, the EU Cyber Resilience Act, DevSecOps, and what it actually takes to ship secure software. The material comes out of running Screenly and sbomify, and out of co-leading one of CISA's SBOM tiger teams.
Keynotes, conference talks, workshops and panels — plus the occasional stint as MC. If you're putting a programme together and one of those would be useful, get in touch.
Where to find me next
Previous appearances
You're STILL not ready for the CRA
Article 14 in practice
44CON
Fireside chat with Wendy Nather on being a CISO in 2026
44CON
MC for Hacker Jeopardy
FOSDEM
CRA-Ready SBOMs: A Practical Blueprint for High-Quality Generation
QCon London
From Chaos to Clarity: Modern SBOM Practices That Actually Work
Digital Signage Summit Europe
Cybersecurity in Digital Signage - Unpatched, Unsecured, Unprotected
Digital Signage Summit Europe
AI Spotlight
Digital Signage Summit Europe
Security Reality Check: 90% of Signage Software Is Not Secure
Digital Signage Summit Europe
AI & Trust / Cybersecurity / Challenges
DevOps Exchange
Securing Your Software Supply Chain: Why SBOMs Are Essential for DevOps and Compliance
Dependency Track Community Meeting
sbomify @ Dependency Track Community Meeting (2025-11-05)
State of Open Con
Screenly’s Journey: Raspberry Pi to x86, BIOS, Coreboot, RISC-V
BSides
Navigating The SBOM Landscape: Formats, Relevance, And Tooling In 2024
SBOM-a-Rama
London DevOps #85
The Essential Role of SBOMs
Canonical (Ubuntu) Engineering Sprint
CycloneDX / Transparency Exchange API (TEA)'s KoalaCon
Looking for press coverage, interviews and podcast appearances instead? Those live on the about page.