Training Analysts Without Making the News

Traditional cybersecurity education often teaches incident response through isolated exercises that bear little resemblance to the realities of a modern Security Operations Centre (SOC). Real incidents are messy, time-sensitive, and require technical expertise, critical thinking, and effective teamwork.

This talk introduces Nordvakt, an enterprise SOC simulation platform developed over more than a year and shaped by six years of teaching digital forensics and incident response. Every aspect of the platform has been designed around sound pedagogical principles and informed by observing how students learn, where they struggle, and what helps them develop into confident incident responders.

Rather than completing scripted labs, students investigate realistic cyber incidents using logs, memory captures, network traffic, endpoint telemetry, and digital evidence. They triage alerts, document their findings, make investigative decisions, and experience the complete lifecycle of an incident in an environment that reflects modern security operations.

This session explores the educational philosophy behind Nordvakt, the challenges of designing authentic investigative scenarios, and the lessons learned from building a simulation that places learning—not technology—at its core.

Veronica Shmitt

Veronica Shmitt

Veronica Schmitt has been breaking things professionally—and then explaining exactly how they broke—since 2008. A digital forensicator by trade, hacker by inclination, and educator by choice, she swapped sunshine for snow when she moved to Norway, proving that malware analysis is apparently more exciting than warm weather.

She is Assistant Professor, Head of Subject for Computing, and Programme Lead for Digital Forensics at Noroff University, while somehow also finding time to pursue a PhD in cybersecurity at the University of Plymouth. Her research focuses on making implanted medical devices safer through better logging, observability, and digital forensics. As someone who also happens to have an implanted medical device herself, this research is both professionally fascinating and personally motivating. Yes, she proudly refers to herself as a cyborg.

Veronica holds an MSc in Information Security from Rhodes University, specialising in malware forensics, and has an unhealthy enthusiasm for ransomware, incident response, and staring at hexadecimal until it starts making sense. She firmly believes that if you aren’t collecting the right logs, you’re just practising creative guessing.

Outside academia, she’s a DEF CON Goon, founder of DC2751 and the OWASP Kristiansand Chapter, and a frequent speaker who enjoys diving into the messy details that attackers hope defenders never notice.

Whether she’s reverse engineering malware, investigating incidents, teaching the next generation of DFIR practitioners, or trying to convince people that logs are exciting (they are), Veronica remains convinced that every byte tells a story—you just need to know where to look.