I.A.P. – It’s Always Policies! (… Until Reality Gets Involved) - Cybersecurity Conference

I.A.P. – It’s Always Policies! (… Until Reality Gets Involved)

Every organization has them: security policies, authentication policies, password policies, access policies, exception policies… and usually a policy explaining the other policies.

But somewhere between the boardroom, the IT department, compliance requirements, and actual human behavior, things tend to go spectacularly wrong.

In this engaging and humor-filled keynote, Eddy Willems and Righard Zwienenberg take a sharp look at the strange world of Identification and Authentication Policies (I.A.P.) where good intentions, confusing rules and creative users collide on a daily basis.

Why do employees write “Do NOT share passwords” on sticky notes attached to shared passwords? Why do users invent brilliant workarounds to security controls designed to protect them? And why do some policies become so complex that even the people enforcing them no longer understand them?

Through real-world examples, security incidents and decades of frontline experience, this session explores:

  • How security policies are often misunderstood, misapplied or quietly ignored 
  • Why overly complex authentication rules can create less security instead of more 
  • The dangerous gap between compliance and real-world protection 
  • How attackers exploit confusion, exceptions and human behavior far more effectively than technology itself 
  • And how organizations can create policies that people might actually follow 

With a mix of practical insight, recognizable situations, and a healthy dose of humor, this keynote shows that the biggest authentication problem is often not the technology but the policy behind it.

Because in cybersecurity, reality always reads the policy differently.

Mr. Righard Zwienenberg – ESET

Zwienenberg began his work with computer viruses in 1988 after encountering his first virus issues at the Technical University of Delft. This experience sparked his interest in virus behavior, leading him to study and present solutions and detection methods ever since. Over nearly four decades, he has worked for various companies, including CSE Ltd., ThunderBYTE, Norman, and ESET. He has also held or continues to hold positions in several industry organizations, such as AMTSO, AVAR, the WildList, IEEE ICSG, and serves on the Advisory Board for Europol’s European Cyber Crime Center (EC3) and Virus Bulletin. He also runs his own computer security consultancy company (RIZSC).

Zwienenberg has been a member of CARO since late 1991. He is a frequent speaker at conferences, including Virus Bulletin, EICAR, AVAR, FIRST, APWG, RSA, InfoSec, SANS, CFET, ISOI, SANS Security Summits, IP Expo, government symposia, SCADA seminars, and other general security events. Beyond his professional work in security, his hobbies include playing drums, performing magic, modeling balloons, restoring ancient computers, and much more.

Mr. Eddy Willems – WAVCi

Eddy Willems is a globally recognized cybersecurity expert from Belgium, with nearly four decades of frontline experience. He became internationally known in 1989 for helping to solve the infamous AIDS Information Trojan case, widely considered the first ransomware attack, and has since advised governments, law enforcement agencies, and businesses around the world. Eddy is co-founder and board member of EICAR and currently serves on the boards of EICAR and LSEC. He previously served as a board member of AMTSO and AVAR, contributing to international collaboration and standards in cybersecurity testing and threat research. He has held roles as Security Evangelist at Kaspersky and G DATA CyberDefense, and today operates as an independent Security Evangelist at WAVCi, his own company. He also serves part-time as COO of the Clean Software Alliance (CSA). A sought-after keynote speaker and TEDx presenter, Eddy has delivered talks in over 40 countries, engaging audiences ranging from students to C-level executives and industry experts. He is the author of several books, including Cyberdanger (Springer, 2019) and the cyberthriller The Virus (Lannoo, 2025). Eddy is one of Belgium’s most interviewed cybersecurity experts worldwide.