Atharv Tiwari

Atharv Tiwari

COO Nevis Info Systems, Security Trainer, Cyber Crime Researcher,

New Delhi, India

Actions

A cybersecurity expert, criminology researcher, and entrepreneur, currently serving as the Chief Operating Officer at Nevis Infosystems and the Co-Founder & Director of NCORE Foundation. At Nevis, he drives product development, secure technology solutions, and innovative GenAI-based services, while at NCORE he empowers law enforcement agencies and professionals through advanced cyber investigation and security training.

He has solved 150+ real-world cybercrime cases and trained 10,000+ students, 200+ teachers, and 300+ law enforcement officers on digital safety, cybercrime investigation, and cloud security. As an entrepreneur, he is building products like Neviscater — bridging design, security, and usability — to create safer and smarter digital ecosystems.

With past experience at the Ministry of Defence (DRDO) and as a Graduate Project Manager at Kounsel, he has led security-focused software projects and helped startups build safe, user-friendly products.

Known for simplifying complex cybersecurity concepts, he regularly speaks at global and national conferences, mentors young professionals, and supports law enforcement with modern investigation techniques. His mission is clear — to make technology safer, accessible, and impactful for everyone.

Area of Expertise

  • Business & Management
  • Government, Social Sector & Education
  • Humanities & Social Sciences
  • Information & Communications Technology
  • Law & Regulation

Topics

  • Entrepreneurship
  • cybercrime
  • cyber security
  • OSINT (Open Source Intelligence)
  • Policy Development
  • Cybersecurity and Cybercrime
  • technology policy
  • detecting financial crime
  • investigations
  • Tech Startups
  • Workplace Investigations
  • Data Retention Policies
  • Entrepreneur
  • Entrepreneurship in Tech
  • Social Entrepreneurship
  • NGO
  • OSINT for Investigations
  • Cybercrime First Response
  • Digital Evidence Handling & Courtroom Readiness
  • Cyber Laws for Investigators
  • FIR-Ready Cybercrime Documentation & Case Building
  • UPI & Online Banking Fraud Investigation
  • Mule Account & Scam Network Analysis
  • Social Engineering & Phishing Investigation
  • Mobile Forensics Fundamentals
  • WhatsApp/Telegram Cybercrime Ecosystem Tracking
  • Incident Response & Crisis Handling
  • Threat Intelligence & Attribution Basics
  • Security Program Management
  • Cross-Functional Team Leadership
  • Product Security Management
  • Security Governance & Policy Management
  • Crisis Communication During Breaches
  • Scaling Security in Startups
  • Information Security Program Management

The Digital Witness Crisis

In today’s world of disappearing messages and slow legal processes, digital evidence often vanishes before justice can be served. This talk uncovers how cross-border cybercrime — especially against youth — is going unpunished due to platform non-cooperation, jurisdictional confusion, and the failure of current legal systems to adapt. Backed by field investigations and policy research, the session proposes bold, actionable reforms like fast-lane treaties, evidence preservation mandates, and a global accountability index to ensure digital crimes don’t escape through legal silence.

Securing the Invisible : Real Talk on Cloud Security, Mistakes & Missions

Cloud security isn’t magic — it’s about smart design, catching mistakes, and building a security-first mindset. This talk dives into real breaches, common pitfalls, and how teams can stay secure without slowing down. No fluff, just practical strategies, real stories, and a few memes.

Startup Firewalls: Blending Cybersecurity, AI, and Entrepreneurship for Resilient Products

Building something new whether it’s a startup, a side project, or a product inside a larger company always brings both excitement and risk. Interestingly, the same vulnerabilities hackers exploit in code often mirror the blind spots founders and teams face in business. Without resilience at the core, it doesn’t take much for things to unravel.

In this talk, I’ll connect lessons from cybersecurity, AI, and entrepreneurship to show how thinking like an attacker can make you a stronger builder. We’ll explore how AI can accelerate innovation while introducing hidden risks, why security principles double as powerful business strategies, and how adopting a hacker’s mindset helps startups prepare for the unexpected.

This isn’t a deep dive into code or startup theory it’s about bridging technology, security, and business with real stories and practical frameworks.

Invisible Gavel: How Justice Is Silenced in the Digital Age

In an era where our lives unfold online, justice is no longer just decided in courtrooms—it’s shaped by invisible forces behind screens. Messages vanish, evidence auto-deletes, platforms remain silent, and victims—especially the young—are left without recourse. As a cybercrime intervention officer, Atharv Tiwari has seen firsthand how truth is lost not because crimes didn’t happen, but because the digital systems weren’t built to remember or respond. This talk uncovers how silence, invisibility, and indifference in the digital world quietly erode our collective sense of justice. It’s not a story of broken laws—but of laws never applied, and of a gavel that falls where no one can hear it.

Decoding the Investigator’s Mind: Turning Cybercrime Casework into Identity Defense Playbooks

While adversaries map attack paths, investigators trace them backward. This talk bridges those worlds translating real cybercrime investigation workflows into structured identity-defense playbooks. Drawing from practical experience training law-enforcement officers and security teams, the session introduces a step-by-step model to document and mitigate identity-based exposures using investigative reasoning. Attendees will learn how to convert investigation logs into attack-path timelines, connect forensic artifacts to identity relationships in BloodHound, and design post-incident remediation playbooks. Real, anonymized case studies illustrate how investigative documentation can accelerate attack-path detection and reduce time-to-mitigation. The talk concludes with actionable frameworks that help organizations operationalize Attack Path Management by embedding investigative discipline into daily defensive operations.

Cross-Domain Graphs: Investigative OSINT to Privilege Escalation in Hybrid Identity

Modern identity ecosystems span on prem Active Directory, Entra ID, and SaaS platforms. These interconnected systems silently create hybrid attack paths that allow adversaries to move laterally across trust boundaries. This session introduces Cross-Domain Graphs, an investigative framework that links open-source intelligence (OSINT) to BloodHound style graph analysis for exposing identity-based risks. Attendees will learn how to collect and enrich public artifacts, safely transform them into graph data, and visualize relationships that reveal privilege escalation routes across multiple identity providers. Using sanitized, reproducible examples, the talk demonstrates how investigative workflows originally designed for digital-forensics and cyber-crime cases can be repurposed for Attack Path Management. We conclude with practical detection queries, least-privilege enforcement steps, and a published mini-repo containing example Cypher queries and graph snippets. Participants leave with a repeatable method to discover and mitigate hybrid identity exposures before attackers do.

Agents with Authority: Governing AI-Driven Non-Human Identities Across Hybrid Enterprise Attack Path

Autonomous AI agents are no longer experimental. They negotiate API calls, execute multi-step workflows, request delegated permissions, and persist OAuth tokens across enterprise environments all without human oversight at the transaction level. In identity governance terms, they are non-human identities (NHIs) with dynamic, context-driven authority. The problem is structural: our identity frameworks were built for human principals and static service accounts. They were not designed to govern systems that reason, adapt, and propagate privilege.

This session maps AI agents as identity nodes within hybrid attack graphs spanning Active Directory, Entra ID, and SaaS platforms. Drawing from investigative workflows converted into defensive playbooks, the presentation demonstrates how autonomous agents expand attack surfaces through three realistic vectors: prompt injection attacks that redirect agent behaviour while preserving token legitimacy; API abuse chains that exploit over-permissioned service principals; and lateral movement patterns invisible to conventional SIEM correlation rules because no human credential was misused.

Three enterprise case studies, a Frankfurt bank treasury exfiltration, a German manufacturer HR agent breach, and a law firm SaaS OAuth takeover ground the threat model in operational reality. The session introduces the ARIA Framework (Autonomous Risk and Identity Architecture), a governance model addressing privilege lifecycle management, behavioural baselining, decision-chain logging, and audit trail requirements aligned with GDPR and EU AI Act obligations.

Attendees leave with a structured governance posture, a threat model template, and three specific CISO-level actions implementable within existing IAM and PAM programmes with no new tooling required for the first two.

Atharv Tiwari

COO Nevis Info Systems, Security Trainer, Cyber Crime Researcher,

New Delhi, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top