Speaking

Keynotes, technical sessions and panels on offensive security, OT and industrial control systems, and the human side of the whole mess.

Booking: booking@johnnyxmas.net

Stages Since 2004

  • DEF CON
  • DefCamp
  • HOPE
  • DerbyCon
  • GrrCON
  • THOTCON
  • CypherCon
  • Hackfest
  • BSides Las Vegas
  • QCon New York
  • ManuSec Summit
  • CircleCityCon
  • ShowMeCon
  • DakotaCon
  • SecretCon
  • Graylog GO!
  • Rochester Security Summit
  • Securing Sexuality
  • ISSA Chicago
  • Converge Detroit
  • WOPR Summit
  • BSides Nashville
  • BSides Detroit
  • GRIMM
  • Hak4Kidz
  • PhreakNIC
  • GenCon
  • BSides312

Book Johnny Xmas

I speak to security practitioners, executive audiences and general conference crowds alike, in sessions from a 20-minute keynote to a full-day workshop, in person or remote. Tell me the room and the outcome you want and I'll build the talk around it.

booking@johnnyxmas.net

Speaker Bio

Johnny Xmas serves as Global Head of Offensive Security for a Fortune 200 manufacturing and agriculture corporation, leading penetration testing, red teaming, adversarial simulation and exposure assessment. With more than 16 years in information security and 26 in IT operations, his work centers on the gap between what an organization claims it can detect and what it actually detects.

A fixture of the Chicago security community since 2002, he holds board positions at BurbSec and BSides312. Earlier roles include Director of Cyber Training at GRIMM, infrastructure defense at Kasada, and Lead Researcher on Uptake's industrial cybersecurity platform. He is best known publicly for exposing the TSA master key leaks and the Venmo public-feed privacy failures — research covered by Fox, CBS, NBC, Wired, TechCrunch, ZDNet, Engadget, PCMag, CSO, Vice, The Hill, Entrepreneur, SC Magazine, Infosecurity Magazine and BleepingComputer, and picked up by the German, Dutch and Filipino press. He holds the CISSP.

“I don't seek to be well-known, I seek to be worth knowing.”

Talks Currently on Offer

  • Your OT Environment Isn't Ready for a Pentest

    What actually has to be true before a penetration test of an operational technology environment produces anything but a scared plant manager. Asset inventory, network segmentation and the foundational controls that decide whether a red team engagement in an ICS network is useful or merely expensive.

    OT security · ICS · penetration testing

  • Couch to Compromise: How to Hack (and Defend) Large Companies

    A candid, step-by-step walkthrough of the attack chain used to compromise a large enterprise — every piece of low-hanging fruit, why each one works, and what to do about it. Attendees leave with actions they can take on Monday that raise their security posture with little to no budget, make future penetration tests more cost-effective by removing the cheap shots, and, incidentally, with the ability to become domain admin of an average corporation from their couch.

    red teaming · enterprise security · attack chains

  • Artificial Intelligence, Real Threats

    AI has transcended buzzword status into a potent and accessible tool, and that power cuts both ways. A look at the darker side: how adversaries actually harness AI in sophisticated information security attacks, what that changes about social engineering and enterprise compromise, and which defensive strategies keep you ahead of it.

    AI security · social engineering · threat landscape

  • 5 Lies Enterprise Security Still Tells Itself

    Expired risk acceptances that quietly became policy, asset inventories nobody maintains, an identity perimeter held together with exceptions, vendor risk theater, and expensive controls that detect nothing. Five systemic enterprise security failures, and what to change on Monday.

    security governance · risk · CISO

  • Superposition, not Superstition

    A sober analysis of what quantum computing actually does to your cryptography, minus the vendor panic. Realistic timelines for a cryptographically-relevant quantum computer, the engineering hurdles still in the way, where quantum key distribution genuinely helps, and how a CISO or architect should be planning post-quantum migration today.

    post-quantum · cryptography · security architecture

  • Airgap the Airheads: Imprisoning Serial Phish Clickers

    How a $53B company took internet access away from its repeat phishing clickers, and what happened next. Phishing campaign design that measures something real, the technical implementation, the exception process, business continuity fallout, and the long-term effect on click rates.

    phishing · security awareness · social engineering

  • Poisoning Pidgins in the Park

    A play-by-play of a hobbyist incident response to an active supply-chain attack against a widely used free and open-source communication tool. How the malicious plugin was found, how the community defended itself, and how to build real incident response experience without a badge.

    supply chain · incident response · malware

  • SIEM and the Art of Motorcycle Maintenance

    Selecting, deploying and actually maintaining a SIEM, explained through the mechanics of motorcycle ownership. Why the industry keeps buying detection it never tunes, and what ongoing care a security monitoring platform genuinely requires.

    SIEM · detection engineering · security operations

  • Saving Ryan's Privates

    Despite strong passwords and MFA, the world’s most private digital assets are still being stolen and leaked. Exposes the privacy myths that fail, the methods actually used to take this material, and actionable steps to reclaim control. Works for general audiences as well as security teams.

    privacy · security awareness

  • Ask a (Real) Hacker!

    An unfiltered live Q&A: adversarial mindset, motivations, money laundering, and the tactics behind real intrusions, without the corporate gatekeeping. Works as a closing keynote or an executive session.

    keynote · Q&A · adversarial mindset

  • InfoSecs and the City

    What makes a regional security community work, drawn from two decades in the Midwest scene and the CitySec meetup framework. How to start, revive, or hand off a local security meetup that outlives its founder.

    community · meetups · career development

  • IC (What You Did There)

    Advancing a technical career — and the salary attached to it — without moving into management. Negotiation, levelling, and staying hands-on as an individual contributor.

    career development · individual contributor

  • Travel Hacks for the Traveling Hacker

    Road-tested tactics from a career of nonstop travel: flight pricing, accelerating airline status, surviving coach, packing, jetlag, airport navigation, eating well on the road, and picking a hotel that will not ruin the week.

    business travel · lifestyle

Where I've Spoken

Not a complete history — only the talks there's a recording of. Twenty-plus years of conferences leaves a lot of rooms undocumented.

  • DefCamp 2025 Poisoning Pidgins in the Park
  • ManuSec Summit 2025 Your OT Environment Isn't Ready for a Pentest
  • Hackfest 2025 InfoSecs and the City — the BurbSec meetup framework (panel)
  • CypherCon 7.0 2024 Saving Ryan's Privates: How Nudes Still Leak
  • SecretCon 2024 Hacking Large Companies in 2024
  • ISSA Chicago 2024 SIEM and the Art of Motorcycle Maintenance
  • Hackfest Canada 2024 Artificial Intelligence, Real Threats (webinar)
  • DakotaCon 10.1 2023 Couch to Compromise: How to Hack Large Corporations (keynote)
  • Hackfest Canada 2023 Artificial Intelligence, Real Threats
  • Securing Sexuality 2023 Saving Ryan's Privates: How Your Nudes Get Leaked
  • Webinar 2023 AI Attacks Against Big Business
  • GRIMMCon 0x3 2021 Urban Exploration 101
  • Graylog GO! 2021 Couch to Compromise: How to Hack Large Corporations
  • Webinar 2021 Demystifying the Dark Web
  • HOPE 2020 The U.S. Maker Response to COVID-19
  • Hackfest Canada 2020 Urban Exploration: A COVID-Friendly Hacker Hobby
  • WOPR Summit 0x01 2020 Urban Exploration 101
  • THOTCON 0xA 2019 BurbSecCon
  • Rochester Security Summit 2019 Keynote: the InfoSec bubble and the glass ceiling we built
  • QCon New York 2019 WAF Anti-Bot Bypasses
  • The Circle of HOPE 2018 How to Pwn an Enterprise in 2018 (and 2019, and 2020…)
  • Hackfest Canada 10 2018 Shut Up and Take My Money: Scraping the Venmo Public Feed
  • GrrCON 2017 10 Cent Beer Night: The World We Now Live In (keynote)
  • BSides Las Vegas 2017 How to Accidentally Get a Job in InfoSec
  • THOTCON 0x8 2017 How I Darkweb Economies (and You Can Too!)
  • Hackfest 2017 How to Pwn an Enterprise in 2017 (or 2016, or 2015…)
  • Anomali Cyber Threat Day 2017 Operationalizing Threat Intelligence
  • The Eleventh HOPE 2016 The TSA Keys Leak: Government Backdoors and the Dangers of Security Theater
  • Hackfest 2016 How to Buy Anything on the Dark Web
  • CypherCon 2016 You're Right, This Sucks (with Lesley Carhart)
  • BSides Nashville 2016 InfoSecs in the City: Starting a Successful CitySec Meetup
  • ShowMeCon 2016 IRL Networking for the Recovering Introvert, Part 3
  • GenCon 49 2016 Hacking in Fiction: The Good, The Bad and The Bizarre
  • Hackfest 2015 1993 B.C.: Get Off My LAN! (Hacking in the Olden Days)
  • CircleCityCon 2015 1993 B.C.: Before Cellphones
  • Converge Detroit 2015 That's Not My RJ45 Jack! IRL Networking for Humans, Part 2
  • ShowMeCon 2015 That's Not My RJ45 Jack! IRL Networking for Humans
  • Hak4Kidz 2015 1993 B.C.: When We Stopped Going Outside
  • DerbyCon 4.0 2014 Attack Paths: Breaking Into InfoSec (with Eve Adams)
  • BSides Detroit 2013 CTF lockpicking and locksport
  • PhreakNIC 8 2004 Cracking Encrypted Intelligence · Anti-Consumer Technology