BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.ozsecurity.org//ozsec-2026//talk//PN8GXW
BEGIN:VTIMEZONE
TZID:CST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T080000Z
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T090000Z
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-ozsec-2026-PN8GXW@cfp.ozsecurity.org
DTSTART;TZID=CST:20261023T133000
DTEND;TZID=CST:20261023T141500
DESCRIPTION:Technical knowledge alone does not make someone ready to defend
  an organization. Cybersecurity professionals must interpret incomplete in
 formation\, correlate evidence from multiple systems\, make decisions unde
 r pressure\, and explain why their response is justified.\n\nWSU Tech’s 
 Cyber Range provides learners with a broad collection of realistic simulat
 ions modeled on real-world threats and security incidents. Working through
  varied scenarios allows a learner to practice responding to different att
 ack methods while developing the investigative reasoning and technical jud
 gment required in the workplace.\n\nThis session demonstrates that process
  using a simulated FIN7 intrusion as a case study. The investigation begin
 s when law enforcement reports finding an organization’s financial infor
 mation in a threat actor’s possession. Learners must determine what happ
 ened\, identify the affected systems\, establish the scope of the compromi
 se\, and recommend an appropriate response.\n\nLearners correlate SIEM ale
 rts\, firewall traffic\, Windows events\, and system artifacts to uncover 
 a phishing-enabled compromise\, lateral movement\, persistence\, financial
 -data staging\, and exfiltration. Observable performance criteria evaluate
 s ability to identify the initial compromise\, reconstruct the attack\, co
 nfirm data loss\, and propose defensible containment and recovery actions.
 \n\nFIN7 represents one of the many scenarios available in the Cyber Range
 . Exposure to multiple incidents helps a learner develop transferable capa
 bilities rather than memorize a single investigative process. Structured d
 ebriefing then turns missed evidence and incomplete conclusions into targe
 ted opportunities for additional practice.\n\nAttendees will leave with a 
 practical understanding of how they and their teams can use WSU Tech’s C
 yber Range to develop\, refine\, and evaluate job-ready cybersecurity comp
 etencies through realistic\, scenario-based practice.
DTSTAMP:20260920T122542Z
LOCATION:Redbud B
SUMMARY:From Classroom to Cyber Incident: Building Job-Ready Defenders in W
 SU Tech’s Cyber Range - Matthew Lewis\, Jacob Buck\, Adam Shah
URL:https://cfp.ozsecurity.org/ozsec-2026/talk/PN8GXW/
END:VEVENT
END:VCALENDAR
