Ryan Smith

Ryan Smith is a Senior Security Researcher at Microsoft, where he spends his days chasing detection gaps, writing far too much Kusto, and teaching computers to make slightly better security decisions. His work focuses on Microsoft Defender XDR, detection engineering, threat research, incident correlation, and applying AI to solve security problems that are usually messier than they looked on the whiteboard.

Over the past 20+ years, Ryan has worked across enterprise IT, security operations, cyber defense, and security research. He's happiest when he's digging through telemetry, reverse engineering a problem, or figuring out how to automate something that nobody should have to do manually. If you've ever wondered whether a detection can be improved "just one more time," you're speaking his language.

Outside of Microsoft, Ryan is a founder member of the Vancouver Island Security Research Society and one of the organizers behind BSides Vancouver Island. He firmly believes the best part of cybersecurity isn't the technology, it's the community. Whether it's helping someone give their first conference talk, mentoring newcomers, or debating detection logic over a post-conference beer, he's passionate about making the security community more approachable, collaborative, and just a little less intimidating.

When he's not staring at logs or explaining why the answer is "it depends," you'll usually find him coaching youth wrestling, wandering the backwoods of British Columbia with a fishing rod, tying flies, or starting another side project that somehow turns into six months of work.

Ryan is also a lifelong Star Wars fan whose appreciation leans a little more... Imperial. His collection of Darth Vader, Darth Maul, and General Grievous tattoos makes it pretty clear he's always found the villains more interesting than the heroes. He maintains that the Sith have the better dialogue, Vader remains one of cinema's greatest characters, and if a presentation can include a subtle Star Wars reference without anyone noticing until halfway through, that's a win. While he hasn't quite embraced the Dark Side, he's accepted that "good is a point of view" makes for a surprisingly effective cybersecurity philosophy.

2026 Talk

Talk Title: The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure

Talk Abstract:
Targeting firewalls and VPNs isn't new but their role in enterprise environments has fundamentally changed. Modern network edge infrastructure now operates at the intersection of identity, session management, and policy enforcement, making it a critical control layer rather than just an entry point.

This talk explores how attackers are evolving from using edge devices for initial access to treating them as long-term operational platforms. Drawing from large-scale detection data and real-world incident patterns, we show how adversaries systematically prioritize pre-authentication vulnerabilities, rapidly weaponize exposures, and establish persistence directly within network infrastructure.

We will examine how compromised edge devices provide privileged visibility into authentication flows and network traffic, enabling credential harvesting, session hijacking, and stealthy lateral movement all while evading traditional endpoint and identity-based defenses.

Ultimately, this session reframes the risk: compromise at the edge is no longer just about access it enables control over how trust is enforced across the enterprise. In short, attackers are no longer trying to break into the system—they are attempting to become the system. Attendees will leave with actionable detection strategies and a modern defensive approach to this emerging threat layer.