Seth Enoka • Cybersecurity & Incident Response Speaker

Seth Enoka, cybersecurity and incident response speaker

Incident Response · Crisis Decision-Making · Critical Infrastructure

Practical cybersecurity talks on incident response, decision-making, and critical infrastructure

During a real incident, you rarely have all the information you want before somebody needs to make a decision.

Seth's sessions focus on the parts of incident response that are difficult to solve on paper: incomplete evidence, unclear authority, containment decisions, handoffs between technical and business teams, and recovery. The examples come from digital forensics, incident response, enterprise IT, and operational technology.

The material is grounded in incident response practice rather than theory. Technical concepts are explained where they matter, without turning the session into a tools lecture.

DFIR Practitioner · SANS Instructor · GSE · No Starch Press author

Enquire about speaking availability

Speaker Snapshot

Best Fit

Cybersecurity and technology conferences, leadership events, executive forums, critical infrastructure and OT events, risk and resilience conferences, industry associations, private corporate events, and technical communities.

Audience

Executives, boards, CISOs, security leaders, risk leaders, incident response and DFIR teams, legal and communications stakeholders, regulators, and OT or engineering leaders.

Formats

Keynotes, conference presentations, executive briefings, workshops, webinars, panels, fireside chats, and facilitated sessions.

Availability

Based in Perth, Australia. Available for engagements across Australia and APAC, selected international events, and virtual delivery.

Signature Talks

The same topics can be delivered as keynotes, conference talks, executive briefings, webinars, or longer workshops. The examples and level of technical detail can change depending on the audience.

When Incident Response Stops Being a Technical Problem

An incident usually starts as a technical problem. An alert fires, somebody starts triage, and the security team works out whether there’s actually something going on. That changes pretty quickly once containment might take a service offline, evidence suggests data has been accessed, or somebody needs to decide whether customers, regulators, insurers, or law enforcement should be involved.

This talk looks at that transition. Who owns those decisions? What information do they actually need? What can the technical team say with confidence, and what is still unknown? We’ll look at the points where real responses tend to slow down or get confused, and what organisations can work out beforehand so they’re not trying to establish authority and process in the middle of an incident.

From Playbook to Proof: Making Incident Response Operationally Defensible

Most organisations have an incident response plan. They have playbooks, security tooling, external providers, and run an annual tabletop exercise as well. All of those things are useful, but they answer different questions. None of them, by itself, tells you whether the organisation can actually respond.

This talk looks at the gap between having the pieces and knowing they’ll work together. We’ll get into escalation and decision authority, access to evidence, containment, handoffs between technical and business teams, and recovery. More importantly, we’ll look at the assumptions that tend to stay hidden until somebody tries to use the plan during a real incident.

The aim is to get beyond reviewing what the documentation says should happen and test whether the organisation can actually do it.

When You Can’t Just Isolate the Host: Testing OT Incident Response Before the Incident

A lot of enterprise incident response guidance assumes that if a system’s compromised, you isolate it and work out the rest from there. In an OT environment, that might not be an option.

The affected system could be supporting production, controlling a physical process, or performing a safety-related function. Taking it offline might contain the cyber incident while creating a much bigger operational problem.

This talk looks at what that means for incident response. We’ll cover containment decisions, evidence collection, decision authority, vendor involvement, the handoff between cyber and operations, and recovery. We’ll also look at how to exercise those decisions properly, so the first time the cyber and operational teams have to work out what they can actually do isn’t during the incident.

What Organisers Say

SANS Institute AISA Australian Cyber Conference Exterro INFORM Dragos No Starch Press

“Seth Enoka’s expertise contributed immensely to the success of the inaugural Cyber and Infrastructure Security Conference, attended by critical infrastructure leaders from across Australia.”

— Cyber and Infrastructure Security Conference organisers

“Seth delivered a highly relevant and practical session on incident response readiness, focusing on what actually matters in the first 60 minutes of a cyber incident. The content resonated strongly with our audience and sparked meaningful discussion.”

— Smitha Gehlot, Growth Marketing Manager, APJ, Exterro

“Seth’s work on incident response readiness is highly relevant for organisations operating in high-consequence environments. His ability to challenge assumptions and highlight what actually breaks during real incidents makes his sessions particularly valuable for OT and critical infrastructure audiences.”

— Avril Adams, APAC Field Marketing Director, Dragos

Speaking and Public Work

Seth has delivered conference talks, workshops, technical briefings, and webinars for cybersecurity and critical infrastructure audiences.

Representative appearances and published work include SANS Institute, the Australian Cyber Conference, AISA events, the Cyber and Infrastructure Security Conference, Exterro INFORM, Dragos events and research, and Cybersecurity for Small Networks from No Starch Press.

  • From Playbook to Proof: Making Incident Response Operationally Defensible — AISA AdelaideSEC 2026
  • What Actually Matters in the First 60 Minutes of DFIR Triage — Exterro INFORM 2026
  • What’s Really Happening in OT Cyberattacks in 2025 — Australian Cyber Conference, Melbourne
  • Process Code Injection: Detection, Response, and Mitigation — SANS Webcast
  • Cybersecurity for Small Networks — No Starch Press

For slides, recordings, PDFs, whitepapers, and additional public material, visit Presentations, Talks, and Research.

About Seth

Seth Enoka is a digital forensics and incident response practitioner, SANS instructor, author, and founder of Lykos Defence. His work spans enterprise IT and operational technology, including incident response, forensic investigations, incident readiness, and building and leading DFIR capability.

Over the course of his career, he has worked across government, critical infrastructure, manufacturing, mining, oil and gas, and other enterprise environments.

Seth teaches SANS FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics and is the author of Cybersecurity for Small Networks from No Starch Press.

A lot of Seth’s work sits between the technical investigation and the decisions people need to make with the findings. That’s also how he approaches speaking: explain the technical detail that’s necessary, be clear about what the evidence can and can’t tell us, and get back to what somebody needs to do with that information.

Speaking Approach

Seth’s background is in the work itself: digital forensics, incident response, OT and critical infrastructure, consulting, capability development, and technical education. That means a session can move from what an investigator is seeing, to what the response team can reasonably do next, and then to the decision the business actually has to make.

As a SANS instructor, Seth spends a lot of time explaining complex forensic material to people with very different levels of experience. The same approach carries into conference and corporate sessions. There’s enough technical detail to make the point, but not more than the audience needs.

Speaker Resources

Short Bio

Seth Enoka is a digital forensics and incident response practitioner, SANS instructor, author, and Director of Lykos Defence. He speaks about incident response, the decisions organisations have to make during serious cyber incidents, and how those problems change in critical infrastructure and OT environments.

Long Bio

Seth Enoka specialises in digital forensics and incident response across enterprise IT and operational technology environments. He has built and led DFIR capability, investigated incidents, and worked with organisations on incident readiness and response. Seth is a SANS FOR508 instructor, the author of Cybersecurity for Small Networks from No Starch Press, and the founder and Director of Lykos Defence. His talks focus on the practical problems that show up when technical findings have to turn into containment, escalation, communication, and recovery decisions.

AV and Session Needs

Standard conference AV is suitable: lectern or lapel microphone, slide display, confidence monitor where available, and HDMI or USB-C input. Workshops may require participant tables, whiteboards, or breakout space depending on format.

Speaker Kit

Download the PDF speaker kit, short and long bios, headshots, topic summaries, and talk one-pagers. Public recordings, slides, and other material are available on the presentations page.

Download speaker materials

Book Seth

For speaking availability, fees, event briefs, and bureau enquiries, contact Seth directly.

Please include the event date and location, audience, expected format, approximate audience size, preferred topic, and whether the engagement is in person or virtual. contact@lykosdefence.com

Speaking FAQ

Can sessions be tailored to a particular audience or sector?
Yes. The main argument of each session stays the same, but the examples, technical depth, and emphasis can change for executive, technical, OT, critical infrastructure, government, legal, risk, or mixed audiences.
Are the sessions suitable for non-technical audiences?
Yes. Technical details are included where they’re necessary to understand a decision or consequence. Audiences don’t need a cybersecurity or digital forensics background for the leadership-focused sessions.
Does Seth deliver workshops as well as keynotes?
Yes. Topics can be expanded into longer workshops or private sessions where an organisation wants participants to work through the material rather than only hear a presentation.
Is Seth available internationally?
Seth is based in Perth, Australia, and is available across Australia and APAC, for selected international engagements, and virtually.
Does Seth work with speaker bureaus and event agencies?
Yes. Direct organisers, conference producers, event agencies, and speaker bureaus are welcome to enquire.