Conference Description
Key Takeaways
- Three-day conference and workshop series dedicated to cybersecurity incident response, held in Oslo, Norway.
- Hands-on workshops cover malware delivery investigation and incident response management using real-world scenarios.
- Organized with support from FIRST (Forum of Incident Response and Security Teams).
- Designed for incident responders, CERT members, SOC analysts, and security managers from government, healthcare, municipalities, and enterprise organizations.
About the Event
Cold Incident Response 2026 is a specialized in-person event bringing together cybersecurity professionals for three days of workshops, conference sessions, and community networking. The program combines technical training with broader discussions on incident response strategies, threat intelligence, and operational best practices. FIRST provides organizational support, reinforcing the event’s emphasis on collaboration and knowledge exchange among security teams.
Workshop partners include Helse- og KommuneCERT and mnemonic, contributing expertise to the hands-on training components.
Malware Investigation and Response Management
The workshop program focuses on practical skill development through real-world scenarios. Participants work through malware delivery investigation techniques and incident response management processes. These sessions aim to build both technical proficiency in analyzing threats and managerial capabilities in coordinating response efforts.
Conference sessions extend beyond hands-on exercises to address broader incident response strategies and operational security considerations. The combination of workshop and conference formats allows attendees to develop practical skills while gaining exposure to current thinking on threat intelligence and response coordination.
Operational Challenges Addressed
The event targets several persistent challenges facing security teams: detecting and responding to incidents effectively, containing malware outbreaks, coordinating response activities across teams, and maintaining operational readiness. Organizations with mature security operations often struggle to keep response capabilities current as threats evolve, making ongoing training and peer exchange valuable.
Who Should Attend
Cold Incident Response 2026 is structured for cybersecurity professionals with operational responsibilities. The event suits incident response managers, security analysts, SOC analysts, IT security managers, and CERT members. Attendees typically come from organizations where cybersecurity is a core function, including government agencies, healthcare providers, municipal authorities, and large enterprises.
Both technical staff seeking hands-on training and managers looking to improve team coordination and response processes will find relevant content across the three-day program.

