Speaking
I speak at conferences and industry events about software supply chain security — SBOMs, the EU Cyber Resilience Act, DevSecOps, and what it actually takes to ship secure software. The material comes out of running Screenly and sbomify, and out of co-leading one of CISA's SBOM tiger teams.
Keynotes, conference talks, workshops and panels — plus the occasional stint as MC. If you're putting a programme together and one of those would be useful, get in touch.
Previous appearances
44CON
Being a CISO in 2026 - panel with Wendy Nather
44CON
MC for Hacker Jeopardy
FOSDEM
CRA-Ready SBOMs: A Practical Blueprint for High-Quality Generation
QCon London
From Chaos to Clarity: Modern SBOM Practices That Actually Work
Digital Signage Summit Europe
Cybersecurity in Digital Signage - Unpatched, Unsecured, Unprotected
Digital Signage Summit Europe
AI Spotlight
Digital Signage Summit Europe
Security Reality Check: 90% of Signage Software Is Not Secure
Digital Signage Summit Europe
AI & Trust / Cybersecurity / Challenges
DevOps Exchange
Securing Your Software Supply Chain: Why SBOMs Are Essential for DevOps and Compliance
Dependency Track Community Meeting
sbomify @ Dependency Track Community Meeting (2025-11-05)
State of Open Con
Screenly’s Journey: Raspberry Pi to x86, BIOS, Coreboot, RISC-V
BSides
Navigating The SBOM Landscape: Formats, Relevance, And Tooling In 2024
SBOM-a-Rama
London DevOps #85
The Essential Role of SBOMs
Canonical (Ubuntu) Engineering Sprint
CycloneDX / Transparency Exchange API (TEA)'s KoalaCon
Looking for press coverage, interviews and podcast appearances instead? Those live on the about page.