Camp 2026 Talks & Bios
Post-Quantum Cryptography: What you need to know now.
Eric Jacobsen, Boston University
About the talk
Within the next few years, a quantum computer may be able to break the encryption that protects nearly everything on the internet — banking, healthcare records, government communications, and the credentials that hold it all together. That moment has a name: Q-Day. And preparing for it starts now.
Post-quantum cryptography (PQC) is the field developing encryption algorithms built to survive the quantum era. Standards are being finalized, vendors are starting to ship support, and organizations that wait too long to build crypto-agility — the ability to swap out cryptographic algorithms as the landscape changes — will find themselves scrambling when it matters most.
In this session, we’ll dig into what PQC actually is, when Q-Day might realistically arrive, and what a transition really involves: what’s already safe, what isn’t, and the hard tradeoffs organizations will face as they get ready. The goal isn’t to hand you a finished playbook — it’s to make sure you’re asking the right questions before the industry runs out of runway to answer them.
About the speaker
Eric Jacobsen, chief information security officer at Boston University, has enterprise-wide responsibility for the university’s information security program. He is accountable for all aspects of information security, including identity and access management, governance, compliance, policy development, vulnerability management, incident response, daily security operations, and awareness. He has worked in information technology for over 30 years as an operator, administrator, programmer, incident responder and security architect. Boston University is the one of the largest private research universities in the country, with 3 campuses serving 37,000 students from 140 countries, over 11,000 faculty and staff, 17 schools and colleges, and 300 programs of study.
Unlocking Identity: Implementing Passwordless Authentication at Harvard
Ingrid Skoog & Nathan Hall, Harvard University
About the talk
MFA can’t stop today‘s attacks. Prompt bombing, SIM swapping, and attacker-in-the-middle phishing kits routinely defeat it, and account compromises are climbing. Harvard’s answer: Go Passwordless. This session shares our multiyear passwordless rollout across 500,000 HarvardKey accounts. Passwordless is now the default for the entire community, with 70% of active users adopting it and mandatory enforcement for all staff members. We’ll cover why MFA fails against modern phishing, the friction points that challenged widespread adoption, and the design and rollout decisions that turned resistance into buy-in.
About the speaker Ingrid Skoog
Ingrid is a cybersecurity leader with 20+ years leading security and privacy programs across the government, private sector, academia, and civil society. She currently serves as the Data Privacy and InfoSec Officer for Harvard’s Faculty of Arts & Sciences. In this role, she identifies and mitigates risk with Harvard leadership and the broader University community. Ingrid has a passion for using her expertise in digital security to educate and protect at-risk people. She is an active board member for the Center for Digital Resilience and serves on the Harvard Committee on the Use of Human Subjects. Prior to Harvard, she served as the Director of R&D for MITRE’s Center for Threat-Informed Defense and built a privacy program for a global for-profit corporation.
About the speaker Nathan Hall
Nathan has spent 25 years in academic information security, working across institutions of varying size and complexity. He currently serves as Deputy Chief Information Security and Data Privacy Officer at Harvard.
His career spans a range of environments, from building a cybersecurity program from the ground up at SUNY Oneonta as its first dedicated security professional, to a decade of hands-on engineering and security architecture work at Boston College, to five years leading Harvard’s security operations team.
In his current role, Nathan works closely with partners across the university to reduce institutional risk through practical, collaborative approaches. His work includes leading incident response, facilitating tabletop exercises, and overseeing security assessments, along with leading initiatives such as passwordless authentication and ZTNA, modernizing information security policy, and developing security metrics to inform and engage senior leadership.
SRE, Platform Engineering, Devops Oh My!!!! I Embraced CI/CD and You Can Too!
Ethan LeClair, Boston University
About the talk
Join us on an overly ambitious tallk where we explore embracing one of many DevOps concepts: Continuous Integration / Continuous Deployment. This talk gives a primer on getting started with implementing CICD into your workflows to improve reliability, velocity, and security of your application/infrastructure code.
About the speaker
Ethan is currently employed at Boston University as an Identity and Access Management Architect. He spent the last few years prior to his current employment at BU managing AWS Cloud Infrastructure for a SaaS platform. Outside of work, he is an avid runner and is most likely training for his next race.
Russian Counterintelligence and Counter-Proliferation
Jenna Wall & Kris Grahame, FBI
About the talk
The presentation provides an overview of the Russian intelligence and security services, as well as trends observed and cases studies from the FBI and the US Intelligence Community in recent years. Topics addressed include proliferation and sanctions evasion, traditional and economic espionage, influence operations, and a look at how Russia has targeted the Northeast US over the years.
About the speaker Jenna Wall
Intelligence Analyst (IA) Jenna Wall has worked for the FBI since 2020 working Transnational Organized Crime, Domestic Terrorism and Counterintelligence and Counter-Proliferation matters related to Russia, Israel, and Cuba. She has a BA in Political Science from Indiana University and a BS in Criminology with a focus on the Russian Political system from Trine University.
About the speaker Kris Grahame
Supervisory Intelligence Analyst (SIA) Kristopher Grahame has worked for the FBI since 2006 on Counterintelligence and Counter-Proliferation matters related to Russia, China, Iran, and several other countries. He has a BA in Russian studies from Hobart College and an MBA from Northeastern University.
Bootc for Local AI: Private Log Analysis and Ransomware Recovery Edition
Mallory Ren, Boston University
About the talk
For those that missed it, the Bootc for Local AI series returns with a new scenario. Sammy Securityanalyst has received a tip that Timmy Threatactor plans to breach the Big Bad Bastion Host to nefarious ends. Undeterred, Sammy sets up a local llama.cpp instance running Qwen3.6 and pi.dev to catch Timmy Threatactor in the act. Despite Sammy’s newfound visibility into the Big Bad Bastion Host, Timmy deletes and unregisters the LUKS keyfile from disk and powers the machine down, demanding a ransom to make the machine boot again. In the pit of despair, Sammy remembers that the system was built from a bootable container image. Throwing their Bitcoin wallet passphrase in the shredder, Sammy fires up a terminal to reimage the Big Bad Bastion Host. Will Sammy recover in time to deliver story points for the All-Important Generic Scrum Ceremony meeting they have in 30 minutes? We will bootc.
About the speaker
Mallory Ren has worked as a Linux Systems Administrator at Boston University since 2023.
Navigating AI Accelerated Development Securely
Stephen Choate, Boston University
About the talk
Description: As artificial intelligence revolutionizes software engineering with unprecedented speed and automated code generation, development teams face a complex landscape of new vulnerabilities and governance challenges. This talk explores how IS&T’s AI and Data Engineering team ensures robust security and governance standards remain in place without sacrificing the velocity AI-driven development offers. Attendees will learn how we integrate security guardrails, manage risk, and foster a culture of secure innovation across the entire development lifecycle.