Thematic CERN School of Computing on Security 2026

→ Europe/London
Cosener's House

Cosener's House

15-16 Abbey Cl, Abingdon OX14 3JD, United Kingdom
David Crooks (UKRI STFC), Andrzej Nowicki (CERN), Catharine Noble (CERN), Kristina Gunne (CERN)
Description

The 20th Thematic CERN School of Computing (tCSC security 2026) will take place on Sunday 27 September until Saturday 3 October.  The theme of the school is "Security of research computing infrastructures" - see the academic programme for more details. 

The school is proposed to people working in academia and research institutes, who as part of their job need to ensure security and resilience of computing resources they manage, and want to be prepared to detect and handle possible security incidents.

This school is organized by CERN in collaboration with the UK Research and Innovation, Science and Technologies Facilities Council (UKRI STFC) The school will take place in Abingdon and will be hosted in The Cosener's House, located in the grounds of the medieval Abbey of Abingdon, 8 miles from Oxford.

Important Dates

  • Wednesday 20 May 2026 - applications open
  • Wednesday 1 July 2026 - applications close at midnight
  • EXTENDED: Wednesday 8 July 2026 - applications close at midnight
  • Thursday 9 July 2026 - invitations sent to the selected participants
  • Monday 17 August 2026 - registration fee payment deadline
CERN School of Computing
    • 16:00 → 17:00
      Registration 1h
    • 17:00 → 17:20
      Welcome to the CERN School of Computing 20m
    • 17:20 → 18:20
      Self-presentation: 1 minute per person 1h
    • 19:00 → 20:30
      Dinner at the Nag's head pub 1h 30m
    • 09:00 → 09:45
      Opening Session 45m
      Speakers: Andrzej Nowicki (CERN), Anton Lawrence (UKRI STFC), Dr David Crooks (UKRI STFC)
    • 09:45 → 10:45
      Security in research and scientific computing 1h
      • computer security: past, present and future
      • current risk landscape
      • most common threats and attack vectors
      • "why are we here?"
      Speaker: Dr David Crooks (UKRI STFC)
    • 10:45 → 11:00
    • 11:00 → 11:30
      Coffee break 30m
    • 11:30 → 12:30
      Security architecture fundamentals 1h

      Security architecture fundamentals
      • fundamental security principles
      • develop skills to be a security architect
      • how to design and provide secure computing infrastructure
      • security standards and frameworks
      • physical security
      • network security: segmentation, firewalls, VPNs

      Speaker: Barbara Krašovec (IJS)
    • 12:30 → 13:15
      Lunch 45m
    • 13:15 → 14:45
      Study time and/or daily sports 1h 30m
    • 14:45 → 15:45
      Defensible security architecture: how to implement security principles 1h

      • data security
      • endpoint security: hardware, host, OS, BMC security, system hardening
      • application security
      • future security trends

      Speaker: Barbara Krašovec (IJS)
    • 15:45 → 16:15
      Coffee break 30m
    • 16:15 → 17:15
      Logging and traceability 1h
      • host-based logs (system and application level), network monitoring
      • the importance of central logging
      • tools and technologies
      • data privacy, dealing with personal and sensitive data, log retention
      • traceability challenges
      Speaker: David Crooks (UKRI STFC)
    • 17:15 → 18:15
      Identity, authentication, authorisation 1h

      • An introduction to the concepts of Identity, Authentication, and Authorization
      • Authentication and authorisation for distributed research
      • Methods for communicating authentication and authorization: Certificates, SAML, OAuth
      • How these technologies fit within research infrastructures

      Speaker: Mr Tom Dack
    • 18:15 → 19:15
      Identity Management & AAI - exercise 1h

      In today's interconnected world, authentication and authorisation have become critical components of modern research infrastructure. In this tutorial we will be exploring traditional methods, such as certificate-based authentication, before progressing to how initiatives like WLCG, IRIS (UK computing resource federation) and SKA SRCNet (Square Kilometre Array - SKA Regional Centres Network) leverage industry-standard, token-based Authentication and Authorization Infrastructure (AAI) to enable large-scale research federations.

      Participants will:

      1. Examine what is a certificate
      2. Perform a SAML SSO
      3. Obtain a token from the issuer and analyse its content to understand the underlying architecture.
      4. (Extended) Issue a certificate and explore how token information translates into certificate issued via automated certificated issuer and how the 2 technologies can be bridged.
      5. (Extended) Use the issued certificate to access research resources in a simulated environment, demonstrating secure and streamlined access workflows.
        By the end of the session, attendees will gain practical skills for implementing modern AAI solutions in global research infrastructures.
      Speaker: Donald Chung (STFC)
    • 19:15 → 20:00
      Dinner at Cosener´s house 45m
    • 08:45 → 09:45
    • 09:45 → 10:45
      Risk management - lecture 2 1h

      The files attached to Risk management - lecture 1 contain all the slides for both lectures

      Speaker: Sven Gabriel
    • 10:45 → 11:00
    • 11:00 → 11:05
      School photo 5m
    • 11:05 → 11:30
      Coffee break 25m
    • 11:30 → 12:30
      Virtualisation and cloud security 1h

      Virtualisation and cloud security
      • virtualisation security fundamentals
      • cloud service models
      • authentication and key management
      • data security in the cloud
      • DevSecOps
      • security in private and public cloud
      • common threats in the cloud
      • security tools

      Speaker: Barbara Krasovec (IJS)
    • 12:30 → 13:15
      Lunch 45m
    • 13:15 → 14:45
      Study time and/or daily sports 1h 30m
    • 14:45 → 15:45
      Vulnerability management 1h
      • vulnerability lifecycle, monitoring, scanning
      • CVE, CVSS, CPE, CWE and related standards
      • special cases: vulnerable hardware, EOL systems etc.
      Speaker: Sven Gabriel
    • 15:45 → 16:15
      Coffee break 30m
    • 16:15 → 16:55
      Student lightning talks 40m
      • STFC CERN-Inspired Security Operations 7m

        Trained in Security Incident and Response through CERN and applied those practices at STFC. This session shares lessons from real-world incident handling, including support for forensic analysis of a cryptocurrency miner attack in a container environment during December 2025. The incident was investigated, contained, and used as a catalyst for developing long-term procedures and defensive initiatives to strengthen resilience against similar attacks.

        Speaker: Santosh Vasant Rane
      • Designing Secure Cloud-Native Multi-Tenant Jupyter Solutions 7m

        Standard multi-tenant JupyterHub deployments bundle user code execution, authentication management, and notebooks within a single container. This presentation shows how JupyterHub can be extended to a hardened, cloud-native architecture that enforces a strict separation of concerns in a zero-trust environment. We decouple the Jupyter runtime into stateless, isolated components, isolating user identity using lightweight proxy sidecars and securing notebooks behind a database-backed API backend.

        Speaker: Stergios Gemelas
      • What is EISCAT 20m

        A whirlwind tour of EISCAT, incoherent scatter and space junk.

        Speaker: Simon Brown
    • 16:55 → 17:55
      Application security 1h
      • web application security, typical web vulnerabilities
      • ethical hacking
      • introduction to pentesting
      Speaker: Sebastian Lopienski (CERN)
    • 17:55 → 18:55
      Application Security - exercises 1h
      Speaker: Sebastian Lopienski (CERN)
    • 19:15 → 20:00
      Dinner at Cosener´s house 45m
    • 08:45 → 09:45
      Container security 1h
      • key concepts of containers (namespaces, cgroups etc.) and Docker
      • container security, threat landscape
      • vulnerability and patch management
      Speaker: Daniel Kouřil
    • 09:45 → 10:45
      Container security - exercises 1h
      Speakers: Daniel Kouril, Daniel Kouřil
    • 10:45 → 11:00
    • 11:00 → 11:30
      Coffee break 30m
    • 11:30 → 12:30
      Intrusion detection with SOC: deployment and operation 1h
      • indicators of compromise (IoCs), threat intelligence sharing, TLP protocol
      • tools and technologies: MISP, Zeek, OpenSearch etc.
      • deploying a Security Operation Center
      • security incidents: detecting and alerting* indicators of compromise (IoCs), threat intelligence sharing, TLP protocol
      • tools and technologies: MISP, Zeek, OpenSearch etc.
      • deploying a Security Operation Center
      • security incidents: detecting and alerting
      Speaker: David Crooks (UKRI STFC)
    • 12:30 → 12:45
      Collect lunch bags 15m
    • 13:00 → 14:00
      Departure of bus to Oxford 1h
    • 14:00 → 21:30
      Oxford visit, punting and dinner 7h 30m
    • 21:30 → 22:30
      Transport by bus to Cosener's house 1h
    • 08:45 → 09:45
      Security Operations 1h

      additional material:
      - source code for communication challenges
      https://codeberg.org/dussa/CommsChallenge/

      Speaker: Sven Gabriel
    • 09:45 → 10:45
      Incident response management 1h

      • incident management and coordination
      • incident analysis and investigation
      • communication with stakeholders
      • containment and eradiction
      • recovery
      • lessons learnt

      Speaker: Barbara Krašovec (IJS)
    • 10:45 → 11:00
      Announcements 15m
    • 11:00 → 11:30
      Coffee break 30m
    • 11:30 → 12:30
      Digital forensics: essentials and data acquisition 1h

      digital evidence handling
      data acquisition (live systems, storage etc.)
      data analysis (OS, file system, network, executables etc.)
      reporting

      Speaker: Daniel Kouřil
    • 12:30 → 13:15
      Lunch 45m
    • 13:15 → 14:45
      Study time and/or daily sports 1h 30m
    • 14:45 → 15:45
      Digital forensics: data analysis 1h
      Speaker: Daniel Kouřil
    • 15:45 → 16:15
      Coffee break 30m
    • 16:15 → 18:15
      Intrusion detection with SOC - exercises 2h
      • indicators of compromise, threat intelligence sharing, TLP protocol
      • tools and technologies
      • deploying a Security Operation Center
      • detecting security incidents
      Speaker: David Crooks (UKRI STFC)
    • 18:45 → 19:30
      Dinner at Cosener´s house 45m
    • 20:00 → 21:30
      Pub quiz at Kings Head and Bell Pub 1h 30m
    • 08:45 → 10:15
      Digital forensics - exercises 1h 30m
      Speaker: Daniel Kouřil
    • 10:15 → 10:30
      Coffee break 15m
    • 10:30 → 11:45
      Introduction to forensics - exercises 1h 15m
      Speaker: Daniel Kouřil
    • 11:45 → 12:00
      Announcements 15m
    • 12:00 → 12:30
      Penetration testing - exercise debriefing 30m
      Speaker: Sebastian Lopienski (CERN)
    • 12:30 → 13:15
      Lunch 45m
    • 13:15 → 14:15
      Study time 1h
    • 14:15 → 15:00
      Exam 45m
    • 15:00 → 15:15
      Short break 15m
    • 15:15 → 16:45
      Incident response - exercise 1h 30m
      • incident management and coordination
      • Sirtfi and trust frameworks
      • communication with local users, external communities, and other stakeholders
      • working with law enforcement
      • privacy aspects
      Speakers: Dr David Crooks (UKRI STFC), Romain Wartel (CERN), Sebastian Lopienski (CERN), Mr Tom Dack
    • 16:45 → 17:00
      Coffee break 15m
    • 17:00 → 18:15
      Incident response - exercise 1h 15m
      • incident management and coordination
      • Sirtfi and trust frameworks
      • communication with local users, external communities, and other stakeholders
      • working with law enforcement
      • privacy aspects
      Speakers: Dr David Crooks (UKRI STFC), Romain Wartel (CERN), Sebastian Lopienski (CERN), Mr Tom Dack
    • 18:15 → 19:00
      Closing Session 45m
      Speakers: Andrzej Nowicki (CERN), David Crooks
    • 19:30 → 21:30
      Closing Dinner at Dorindos 2h
    • 10:00 → 12:00
      Departure 2h