Maarten Goet

Maarten Goet

Microsoft MVP & RD

Actions

Maarten is a MVP since '07 and a RD since '15, and a regular speaker at conferences around the world. He is the Chief Threat Officer at Wortell Enterprise Security, and founder of Experts Live and Yellowhat.

Badges

  • Most Active Speaker 2024
  • Most Active Speaker 2023

Decade of Ransomware: From Viruses to Machine-Speed Attackers

Ransomware did not begin with Bitcoin or criminal affiliate networks. The first documented case arrived on a floppy disk in 1989. Since then, every generation of attack has reduced the time defenders have to respond.

Viruses automated infection. Worms demonstrated global propagation at machine speed. Cryptocurrency made digital extortion practical, while ransomware-as-a-service transformed specialist crime into an industry. Human-operated groups then turned ransomware from a malicious payload into a complete campaign: acquire access, compromise identities, move laterally, steal cloud data, disrupt operations, and apply pressure. In many modern extortion cases, attackers no longer need to encrypt a single file.

Now AI is removing another constraint: human effort. Recent agentic attacks have explored unfamiliar environments, chained vulnerabilities, recovered from failure, and performed thousands of actions without fatigue. These incidents were not ransomware, but they demonstrate the operating model future extortion campaigns can adopt.

Join Maarten, a 20-year+ MicrosoftMVP, and follow that evolution from 1980s malware to today’s machine-speed attacker. Using real incidents, Maarten will examine why every transition required defenders to expand their approach—from antivirus and backups to identity protection, attack-path analysis, data security, cross-domain detection, and automated containment.

Maarten will connect those lessons to Microsoft Entra, Defender XDR, Sentinel, Purview, Security Exposure Management, and Attack Disruption, before looking toward Project Perception and agentic defense. The conclusion is hopeful: attackers may be gaining speed, but defenders already possess many of the signals and enforcement points required to respond. The next step is connecting them into a system that can act at machine speed while keeping human judgment where it matters most.

After this session, attendees will be able to:

• Explain how ransomware evolved from automated malware into human-operated, service-based, data-driven, and increasingly agentic campaigns.
• Identify why antivirus and backups alone cannot address identity compromise, SaaS data theft, double extortion, and machine-speed attacks—and map Microsoft Security capabilities to those gaps.
• Build a modern response strategy using attack-path context, high-confidence automated containment, data and identity controls, and human governance.

Target audience: Security practitioners, SOC analysts, incident responders, security architects, and security leaders.
Level: 200
Preferred duration: 45–60 minutes.
Format: Strategic-to-technical conference session; no special technical requirements.

When Attacks Move at Machine Speed: Project Perception and Microsoft’s New Security Stack

AI is changing the economics of cyberattacks. It can search larger attack surfaces, generate more activity than analysts can triage, and keep operating long after the SOC goes home. Defending against that shift takes more than another copilot or a faster alert queue. It requires a security system that can continuously perceive, reason, and act—without taking people out of command.

Maarten begins with why the tempo of cyber defense is changing. We will then examine the Microsoft Security platform many organizations already operate, connecting signals and controls across Defender, Sentinel, Entra, and Purview to the visibility, context, and actuators this new approach requires.

Join Maarten, a 20 year+ Microsoft MVP and go inside Microsoft Project Perception: its shared security context, multi-model harness, and specialized red, blue, and green agents. We will trace how these agents discover attack paths, investigate meaningful risk, and turn findings into corrective action as one continuous loop.

Finally, Maarten will map this architecture to the attacks defenders now face—and explore a hopeful future in which autonomous defense amplifies security teams while humans remain firmly in control.

After this session, attendees will be able to:

• Explain why machine-speed attacks require a continuous perceive-reason-act cycle instead of simply producing more alerts.
• Map Defender, Sentinel, Entra, and Purview capabilities to the signals, security context, and enforcement foundation behind Project Perception.
• Describe how red, blue, and green agents collaborate across attack-path discovery, investigation, and remediation—and identify where human control belongs.

Target audience: Microsoft security practitioners, SOC analysts, security architects, and Defender/Sentinel engineers.
Level: 200
Preferred duration: 45–60 minutes.
Format: Strategic-to-technical conference session; no special technical requirements.

Maarten Goet

Microsoft MVP & RD

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top