Choose your tickets
Chcon 2026 Conference Ticket for Nov 19 and 20 ticket
General Access to the conference
General Access to the conference
140 ticket(s) left$115.00+ $7.18 feeUse arrow keys to change quantityWed 18 Nov 1pm-4pm: VLANs, Mirror Ports, MAC Filtering, Oh My! (Training and Conference Combo) ticket
Training and Conference ticket! An access code for your conference ticket will be sent to your email and you will be able to use that once tickets are on sale. This workshop will go over the basics of networking, including subnets, VLANs, and firewalls. Have you had a chance to see them in a network setup and plug into a variety of network types to see how they interact? With this opportunity, you will gain firsthand experience with how different network configurations behave and what to look for to identify the configurations in place. This session is aimed at junior pentesters and anyone starting out in penetration testing who has limited networking experience. No prior networking background required, just curiosity. About your instructor Dave/Karit has worked in various parts of the IT industry and has developed a skillset that encompasses various disciplines in the information security domain. Dave currently does Security Consulting in Wellington and runs Kākācon. Dave has presented at a range of conferences such as DefCon, Kiwicon, Aerospace Village @ DefCon, BSidesCBR, CHCon, Unrestcon and at numerous local meetups, along with running training at Kiwicon, Syscan, CrikeyCon, CHCon and TuskCon. He also has a keen interest in aerospace, lock-picking and all things wireless.
Training and Conference ticket! An access code for your conference ticket will be sent to your email and you will be able to use that once tickets are on sale. This workshop will go over the basics of networking, including subnets, VLANs, and firewalls. Have you had a chance to see them in a network setup and plug into a variety of network types to see how they interact? With this opportunity, you will gain firsthand experience with how different network configurations behave and what to look for to identify the configurations in place. This session is aimed at junior pentesters and anyone starting out in penetration testing who has limited networking experience. No prior networking background required, just curiosity. About your instructor Dave/Karit has worked in various parts of the IT industry and has developed a skillset that encompasses various disciplines in the information security domain. Dave currently does Security Consulting in Wellington and runs Kākācon. Dave has presented at a range of conferences such as DefCon, Kiwicon, Aerospace Village @ DefCon, BSidesCBR, CHCon, Unrestcon and at numerous local meetups, along with running training at Kiwicon, Syscan, CrikeyCon, CHCon and TuskCon. He also has a keen interest in aerospace, lock-picking and all things wireless.
Sold out$212.75+ $12.80 feeWed 18 Nov 1pm-4pm: VLANs, Mirror Ports, MAC Filtering, Oh My! (Training Only) ticket
Training only ticket! This workshop will go over the basics of networking, including subnets, VLANs, and firewalls. Have you had a chance to see them in a network setup and plug into a variety of network types to see how they interact? With this opportunity, you will gain firsthand experience with how different network configurations behave and what to look for to identify the configurations in place. This session is aimed at junior pentesters and anyone starting out in penetration testing who has limited networking experience. No prior networking background required, just curiosity. About your instructor Dave/Karit has worked in various parts of the IT industry and has developed a skillset that encompasses various disciplines in the information security domain. Dave currently does Security Consulting in Wellington and runs Kākācon. Dave has presented at a range of conferences such as DefCon, Kiwicon, Aerospace Village @ DefCon, BSidesCBR, CHCon, Unrestcon and at numerous local meetups, along with running training at Kiwicon, Syscan, CrikeyCon, CHCon and TuskCon. He also has a keen interest in aerospace, lock-picking and all things wireless.
Training only ticket! This workshop will go over the basics of networking, including subnets, VLANs, and firewalls. Have you had a chance to see them in a network setup and plug into a variety of network types to see how they interact? With this opportunity, you will gain firsthand experience with how different network configurations behave and what to look for to identify the configurations in place. This session is aimed at junior pentesters and anyone starting out in penetration testing who has limited networking experience. No prior networking background required, just curiosity. About your instructor Dave/Karit has worked in various parts of the IT industry and has developed a skillset that encompasses various disciplines in the information security domain. Dave currently does Security Consulting in Wellington and runs Kākācon. Dave has presented at a range of conferences such as DefCon, Kiwicon, Aerospace Village @ DefCon, BSidesCBR, CHCon, Unrestcon and at numerous local meetups, along with running training at Kiwicon, Syscan, CrikeyCon, CHCon and TuskCon. He also has a keen interest in aerospace, lock-picking and all things wireless.
5 ticket(s) left$97.75+ $6.19 feeUse arrow keys to change quantityWed 18 Nov 1pm-5pm: Playmobil Pirates: a 3-Round Cyber Tabletop (Training Only) ticket
Training only ticket! When you put your business systems, weak controls and leaky third-party contracts down on the same table as the threat actors, things can get interesting. In this 4-hour workshop we'll use Playmobil pirates, a haunted lighthouse, and three fast rounds of play to turn threats, risks and controls into a physical game you'll learn from. We'll set up a tiny pirate-infested ocean on the table and build a business that looks uncomfortably like a real-world organisation. Attendees will rotate between being the business, the attackers and the third party. We'll use simple worksheets to frame typical attacks, set budgets for controls, and rate what happens when the pirates come looking for money, embarrassment, or quiet long-term access. Underneath the Playmobil and the pirate theme, it's a serious exercise: we'll surface how threat actors combine control gaps and insider threats, and how lessons from each round feed back into threat modelling and risk treatment. About your instructor Stephen Coates is a cyber security consultant who helps organisations move from "we've got the paperwork" to "we're actually ready when things go sideways", specialising in tabletop exercises, threat modelling, and ISO/IEC 27001-driven security systems.
Training only ticket! When you put your business systems, weak controls and leaky third-party contracts down on the same table as the threat actors, things can get interesting. In this 4-hour workshop we'll use Playmobil pirates, a haunted lighthouse, and three fast rounds of play to turn threats, risks and controls into a physical game you'll learn from. We'll set up a tiny pirate-infested ocean on the table and build a business that looks uncomfortably like a real-world organisation. Attendees will rotate between being the business, the attackers and the third party. We'll use simple worksheets to frame typical attacks, set budgets for controls, and rate what happens when the pirates come looking for money, embarrassment, or quiet long-term access. Underneath the Playmobil and the pirate theme, it's a serious exercise: we'll surface how threat actors combine control gaps and insider threats, and how lessons from each round feed back into threat modelling and risk treatment. About your instructor Stephen Coates is a cyber security consultant who helps organisations move from "we've got the paperwork" to "we're actually ready when things go sideways", specialising in tabletop exercises, threat modelling, and ISO/IEC 27001-driven security systems.
5 ticket(s) left$97.75+ $6.19 feeUse arrow keys to change quantityWed 18 Nov 1pm-5pm: Playmobil Pirates: a 3-Round Cyber Tabletop (Training and Conference Combo) ticket
Training and Conference ticket! An access code for your conference ticket will be sent to your email and you will be able to use that once tickets are on sale. When you put your business systems, weak controls and leaky third-party contracts down on the same table as the threat actors, things can get interesting. In this 4-hour workshop we'll use Playmobil pirates, a haunted lighthouse, and three fast rounds of play to turn threats, risks and controls into a physical game you'll learn from. We'll set up a tiny pirate-infested ocean on the table and build a business that looks uncomfortably like a real-world organisation. Attendees will rotate between being the business, the attackers and the third party. We'll use simple worksheets to frame typical attacks, set budgets for controls, and rate what happens when the pirates come looking for money, embarrassment, or quiet long-term access. Underneath the Playmobil and the pirate theme, it's a serious exercise: we'll surface how threat actors combine control gaps and insider threats, and how lessons from each round feed back into threat modelling and risk treatment. About your instructor Stephen Coates is a cyber security consultant who helps organisations move from "we've got the paperwork" to "we're actually ready when things go sideways", specialising in tabletop exercises, threat modelling, and ISO/IEC 27001-driven security systems.
Training and Conference ticket! An access code for your conference ticket will be sent to your email and you will be able to use that once tickets are on sale. When you put your business systems, weak controls and leaky third-party contracts down on the same table as the threat actors, things can get interesting. In this 4-hour workshop we'll use Playmobil pirates, a haunted lighthouse, and three fast rounds of play to turn threats, risks and controls into a physical game you'll learn from. We'll set up a tiny pirate-infested ocean on the table and build a business that looks uncomfortably like a real-world organisation. Attendees will rotate between being the business, the attackers and the third party. We'll use simple worksheets to frame typical attacks, set budgets for controls, and rate what happens when the pirates come looking for money, embarrassment, or quiet long-term access. Underneath the Playmobil and the pirate theme, it's a serious exercise: we'll surface how threat actors combine control gaps and insider threats, and how lessons from each round feed back into threat modelling and risk treatment. About your instructor Stephen Coates is a cyber security consultant who helps organisations move from "we've got the paperwork" to "we're actually ready when things go sideways", specialising in tabletop exercises, threat modelling, and ISO/IEC 27001-driven security systems.
3 ticket(s) left$212.75+ $12.80 feeUse arrow keys to change quantityWed 18 Nov 8am-12pm: Nothing Is What It Seems: IR Training (Training Only) ticket
Training only ticket! Facilitated, in-person, low-tech. No laptops, no preparation, no prerequisites. Max 30 people. Most incident response training tells people what to do. Very little of it lets them feel what an incident is actually like: nothing clear, time short, someone has to make a call. The Unseen Hand doesn't mention computers once. You'll step into a story of influence, deception, and uncertain loyalties, where nothing is what it seems and decisions have to be made anyway. Then the debrief connects what just happened in the room to what happens when a real incident breaks. You'll leave knowing something about how you and the people around you behave under uncertainty, the exact conditions of a live incident, and that's not a thing a slide deck or a checklist can give you. This isn't a tabletop exercise dressed up as a game. It's a different category of incident response training entirely, and the only way to understand that is to be in the room for it. Incident response training is well served on process and badly served on the human moment inside it. There's a runbook for every playbook and almost nothing that rehearses making a call on incomplete information, holding your nerve while people watch, or explaining risk to someone who wasn't in the room. Those are the parts that decide how well an incident actually goes, and they're the parts no runbook can teach. Who it's for: people whose day job is already cybersecurity, plus incident response leads, security leads, and anyone running culture or champions work. No preparation, no technical prerequisite. About your instructor Anna Lezhikova is a cyber security consultant based in Wellington, New Zealand. She combines her experience in sociology, business management, communications, and IT to help companies run and grow their business securely in the digital age. Armed with a Master's degree in Sociology, an MBA, and a Diploma in Machine Learning and Artificial Intelligence, Anna's expertise is fortified by practical know-how as a full-stack and DevSecOps engineer. This unique blend equips her with the capability to see problems from different perspectives and come up with holistic solutions.
Training only ticket! Facilitated, in-person, low-tech. No laptops, no preparation, no prerequisites. Max 30 people. Most incident response training tells people what to do. Very little of it lets them feel what an incident is actually like: nothing clear, time short, someone has to make a call. The Unseen Hand doesn't mention computers once. You'll step into a story of influence, deception, and uncertain loyalties, where nothing is what it seems and decisions have to be made anyway. Then the debrief connects what just happened in the room to what happens when a real incident breaks. You'll leave knowing something about how you and the people around you behave under uncertainty, the exact conditions of a live incident, and that's not a thing a slide deck or a checklist can give you. This isn't a tabletop exercise dressed up as a game. It's a different category of incident response training entirely, and the only way to understand that is to be in the room for it. Incident response training is well served on process and badly served on the human moment inside it. There's a runbook for every playbook and almost nothing that rehearses making a call on incomplete information, holding your nerve while people watch, or explaining risk to someone who wasn't in the room. Those are the parts that decide how well an incident actually goes, and they're the parts no runbook can teach. Who it's for: people whose day job is already cybersecurity, plus incident response leads, security leads, and anyone running culture or champions work. No preparation, no technical prerequisite. About your instructor Anna Lezhikova is a cyber security consultant based in Wellington, New Zealand. She combines her experience in sociology, business management, communications, and IT to help companies run and grow their business securely in the digital age. Armed with a Master's degree in Sociology, an MBA, and a Diploma in Machine Learning and Artificial Intelligence, Anna's expertise is fortified by practical know-how as a full-stack and DevSecOps engineer. This unique blend equips her with the capability to see problems from different perspectives and come up with holistic solutions.
2 ticket(s) left$97.75+ $6.19 feeUse arrow keys to change quantityWed 18 Nov 8am-12pm: Nothing Is What It Seems: IR Training (Training and Conference Combo) ticket
Training and Conference ticket! An access code for your conference ticket will be sent to your email and you will be able to use that once tickets are on sale. Facilitated, in-person, low-tech. No laptops, no preparation, no prerequisites. Max 30 people. Most incident response training tells people what to do. Very little of it lets them feel what an incident is actually like: nothing clear, time short, someone has to make a call. The Unseen Hand doesn't mention computers once. You'll step into a story of influence, deception, and uncertain loyalties, where nothing is what it seems and decisions have to be made anyway. Then the debrief connects what just happened in the room to what happens when a real incident breaks. You'll leave knowing something about how you and the people around you behave under uncertainty, the exact conditions of a live incident, and that's not a thing a slide deck or a checklist can give you. This isn't a tabletop exercise dressed up as a game. It's a different category of incident response training entirely, and the only way to understand that is to be in the room for it. Who it's for: people whose day job is already cybersecurity, plus incident response leads, security leads, and anyone running culture or champions work. No preparation, no technical prerequisite. About your instructor Anna Lezhikova is a cyber security consultant based in Wellington, New Zealand. She combines her experience in sociology, business management, communications, and IT to help companies run and grow their business securely in the digital age. Armed with a Master's degree in Sociology, an MBA, and a Diploma in Machine Learning and Artificial Intelligence, Anna's expertise is fortified by practical know-how as a full-stack and DevSecOps engineer. This unique blend equips her with the capability to see problems from different perspectives and come up with holistic solutions.
Training and Conference ticket! An access code for your conference ticket will be sent to your email and you will be able to use that once tickets are on sale. Facilitated, in-person, low-tech. No laptops, no preparation, no prerequisites. Max 30 people. Most incident response training tells people what to do. Very little of it lets them feel what an incident is actually like: nothing clear, time short, someone has to make a call. The Unseen Hand doesn't mention computers once. You'll step into a story of influence, deception, and uncertain loyalties, where nothing is what it seems and decisions have to be made anyway. Then the debrief connects what just happened in the room to what happens when a real incident breaks. You'll leave knowing something about how you and the people around you behave under uncertainty, the exact conditions of a live incident, and that's not a thing a slide deck or a checklist can give you. This isn't a tabletop exercise dressed up as a game. It's a different category of incident response training entirely, and the only way to understand that is to be in the room for it. Who it's for: people whose day job is already cybersecurity, plus incident response leads, security leads, and anyone running culture or champions work. No preparation, no technical prerequisite. About your instructor Anna Lezhikova is a cyber security consultant based in Wellington, New Zealand. She combines her experience in sociology, business management, communications, and IT to help companies run and grow their business securely in the digital age. Armed with a Master's degree in Sociology, an MBA, and a Diploma in Machine Learning and Artificial Intelligence, Anna's expertise is fortified by practical know-how as a full-stack and DevSecOps engineer. This unique blend equips her with the capability to see problems from different perspectives and come up with holistic solutions.
2 ticket(s) left$212.75+ $12.80 feeUse arrow keys to change quantityWed 18 Nov 9am-6pm: Secure Application Design and Coding (Full Day) (Training Only) ticket
Training only ticket! This is a full-day session, 9am-6pm. This is a cut-down version of a two-day, hands-on class the instructor presents quarterly. To fit the one-day timeline, this version uses online lab demos in place of hands-on labs, with a few topics trimmed. When software security flaws are discovered and investigated, the root cause is too often traced to insecure coding practices, inattention to security during design, or both. In this class, we cover the concepts you need to understand, so you can develop software that is Secure by Design and Secure by Default. We'll review core design principles that will guide you toward these goals, bringing the concepts home through concrete examples in code. Our coverage will include general secure coding principles, as well as specific approaches for preventing several of the most common vulnerabilities in application code. We'll address several of the OWASP Top Ten application vulnerabilities (owasptopten.org), plus a few other "deadly sins" of software security, and cover best practices for creating secure default configurations. Topic outline: Introduction, background, and terms of reference Secure by Design principles Secure coding principles Avoiding the worst coding "sins": OWASP Top 10 (2025), the SANS/CWE Top 25, SQL Injection, Broken Authentication, Sensitive Data Exposure, Broken Access Control, Cross-Site Scripting (XSS), Insufficient Logging and Monitoring, Using Cryptography Incorrectly, Arbitrary File Upload Secure by Default principles About your instructor Dr. John DiLeo leads the OWASP New Zealand Chapter. In his day job, John is the Application Security Lead at Gallagher Security in Hamilton. Before joining Gallagher, John led the Application Security Services team at Datacom, providing support and guidance to clients in launching, managing, and maturing their enterprise software assurance programs. Before turning to full-time roles in security, John was active as a Java enterprise architect and web application developer. In earlier lives, John has been a full-time professor and specialised in developing discrete-event simulations of large distributed systems.
Training only ticket! This is a full-day session, 9am-6pm. This is a cut-down version of a two-day, hands-on class the instructor presents quarterly. To fit the one-day timeline, this version uses online lab demos in place of hands-on labs, with a few topics trimmed. When software security flaws are discovered and investigated, the root cause is too often traced to insecure coding practices, inattention to security during design, or both. In this class, we cover the concepts you need to understand, so you can develop software that is Secure by Design and Secure by Default. We'll review core design principles that will guide you toward these goals, bringing the concepts home through concrete examples in code. Our coverage will include general secure coding principles, as well as specific approaches for preventing several of the most common vulnerabilities in application code. We'll address several of the OWASP Top Ten application vulnerabilities (owasptopten.org), plus a few other "deadly sins" of software security, and cover best practices for creating secure default configurations. Topic outline: Introduction, background, and terms of reference Secure by Design principles Secure coding principles Avoiding the worst coding "sins": OWASP Top 10 (2025), the SANS/CWE Top 25, SQL Injection, Broken Authentication, Sensitive Data Exposure, Broken Access Control, Cross-Site Scripting (XSS), Insufficient Logging and Monitoring, Using Cryptography Incorrectly, Arbitrary File Upload Secure by Default principles About your instructor Dr. John DiLeo leads the OWASP New Zealand Chapter. In his day job, John is the Application Security Lead at Gallagher Security in Hamilton. Before joining Gallagher, John led the Application Security Services team at Datacom, providing support and guidance to clients in launching, managing, and maturing their enterprise software assurance programs. Before turning to full-time roles in security, John was active as a Java enterprise architect and web application developer. In earlier lives, John has been a full-time professor and specialised in developing discrete-event simulations of large distributed systems.
7 ticket(s) left$195.50+ $11.81 feeUse arrow keys to change quantityWed 18 Nov 9am-6pm: Secure Application Design and Coding (Full Day) (Training and Conference Combo) ticket
Training and Conference ticket! An access code for your conference ticket will be sent to your email and you will be able to use that once tickets are on sale. This is a full-day session, 9am-6pm. This is a cut-down version of a two-day, hands-on class the instructor presents quarterly. To fit the one-day timeline, this version uses online lab demos in place of hands-on labs, with a few topics trimmed. When software security flaws are discovered and investigated, the root cause is too often traced to insecure coding practices, inattention to security during design, or both. In this class, we cover the concepts you need to understand, so you can develop software that is Secure by Design and Secure by Default. We'll review core design principles that will guide you toward these goals, bringing the concepts home through concrete examples in code. Our coverage will include general secure coding principles, as well as specific approaches for preventing several of the most common vulnerabilities in application code. We'll address several of the OWASP Top Ten application vulnerabilities (owasptopten.org), plus a few other "deadly sins" of software security, and cover best practices for creating secure default configurations. Topic outline: Introduction, background, and terms of reference Secure by Design principles Secure coding principles Avoiding the worst coding "sins": OWASP Top 10 (2025), the SANS/CWE Top 25, SQL Injection, Broken Authentication, Sensitive Data Exposure, Broken Access Control, Cross-Site Scripting (XSS), Insufficient Logging and Monitoring, Using Cryptography Incorrectly, Arbitrary File Upload Secure by Default principles About your instructor Dr. John DiLeo leads the OWASP New Zealand Chapter. In his day job, John is the Application Security Lead at Gallagher Security in Hamilton. Before joining Gallagher, John led the Application Security Services team at Datacom, providing support and guidance to clients in launching, managing, and maturing their enterprise software assurance programs. Before turning to full-time roles in security, John was active as a Java enterprise architect and web application developer. In earlier lives, John has been a full-time professor and specialised in developing discrete-event simulations of large distributed systems.
Training and Conference ticket! An access code for your conference ticket will be sent to your email and you will be able to use that once tickets are on sale. This is a full-day session, 9am-6pm. This is a cut-down version of a two-day, hands-on class the instructor presents quarterly. To fit the one-day timeline, this version uses online lab demos in place of hands-on labs, with a few topics trimmed. When software security flaws are discovered and investigated, the root cause is too often traced to insecure coding practices, inattention to security during design, or both. In this class, we cover the concepts you need to understand, so you can develop software that is Secure by Design and Secure by Default. We'll review core design principles that will guide you toward these goals, bringing the concepts home through concrete examples in code. Our coverage will include general secure coding principles, as well as specific approaches for preventing several of the most common vulnerabilities in application code. We'll address several of the OWASP Top Ten application vulnerabilities (owasptopten.org), plus a few other "deadly sins" of software security, and cover best practices for creating secure default configurations. Topic outline: Introduction, background, and terms of reference Secure by Design principles Secure coding principles Avoiding the worst coding "sins": OWASP Top 10 (2025), the SANS/CWE Top 25, SQL Injection, Broken Authentication, Sensitive Data Exposure, Broken Access Control, Cross-Site Scripting (XSS), Insufficient Logging and Monitoring, Using Cryptography Incorrectly, Arbitrary File Upload Secure by Default principles About your instructor Dr. John DiLeo leads the OWASP New Zealand Chapter. In his day job, John is the Application Security Lead at Gallagher Security in Hamilton. Before joining Gallagher, John led the Application Security Services team at Datacom, providing support and guidance to clients in launching, managing, and maturing their enterprise software assurance programs. Before turning to full-time roles in security, John was active as a Java enterprise architect and web application developer. In earlier lives, John has been a full-time professor and specialised in developing discrete-event simulations of large distributed systems.
2 ticket(s) left$310.50+ $18.42 feeUse arrow keys to change quantity

