BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.ozsecurity.org//ozsec-2026//speaker//SGTUQE
BEGIN:VTIMEZONE
TZID:CST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T080000Z
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T090000Z
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-ozsec-2026-XUUHUV@cfp.ozsecurity.org
DTSTART;TZID=CST:20261023T133000
DTEND;TZID=CST:20261023T141500
DESCRIPTION:Most vulnerability programs do exactly what they were built to 
 do. They scan everything\, ticket the 9.8s and report a shrinking critical
  count to the board. Attackers still walk in through the CVSS 6.2 on the p
 ublic VPN. This talk explains why severity scores were never meant to meas
 ure risk\, and how free signals like CISA KEV and EPSS can cut the list do
 wn to what attackers actually use. It also covers how reachability\, compe
 nsating controls and asset value decide what really matters in your enviro
 nment\, and what CISA's new BOD 26-04 means now that CVSS is out of the fe
 deral decision model. Attendees leave with a practical way to move from "f
 ix 150\,000" to "fix the 40 that will breach you\," plus one question to a
 sk their team on Monday.\n\nTakeaways:\n- Why CVSS measures severity\, not
  risk\n- How to use KEV and EPSS together to prioritize\n- How compensatin
 g controls change exposure\, and what BOD 26-04 means for that\n- A simple
  maturity path from scanning to exposure management
DTSTAMP:20261011T004810Z
LOCATION:Redbud C
SUMMARY:Your vuln program is working perfectly.  For the attackers. - Brad 
 Liggett
URL:https://cfp.ozsecurity.org/ozsec-2026/talk/XUUHUV/
END:VEVENT
END:VCALENDAR
