top of page

TurkuSec - The Mother of Dra…. CitySecs

2 tuntia sitten
10 min käytetty lukemiseen

I had the opportunity to attend the TurkuSec meetup on  Friday 29th of May 2026, and it was one of those evenings that reminds you why local security communities exist in the first place.

Ten years ago, on 23rd May 2016, a small group of security enthusiasts met in Turku for the first time. Thirty-five people showed up. There was one speaker. It was also Shamil Alifov’s birthday. A decade later, the community gathered at Q Talo on Nummenpuistokatu to celebrate that milestone. Doors opened at 17:40. The talks started at 18:00. After that, the schedule became more of a suggestion than a contract.

Walking in, it did not feel like a formal conference. It felt like a birthday party thrown by people who actually know each other: talks, open mic, workshops, and the kind of after-party energy that changes from event to event but never really goes away.

The birthday meetup was powered by Silverskin Information Security Oy, F-Secure, and the volunteers who keep finding venues that fit everyone in the room.


"I believe networking and collaboration events are important for the Finnish CitySec and cyber community. Such conferences are needed, and it's a perfect opportunity for professionals and students alike: you can listen to top-notch talks and network with people, which is super important." -Ismayil Hasanov, TurkuSec Chairperson

How it started

TurkuSec is part of the CitySec network, which connects local cybersecurity communities across the Nordics and Baltics. But the story in Turku begins earlier than the first meetup.

The University of Turku did not have engineering education until 1999. Cybersecurity arrived slowly, a couple of courses first, then a full master’s degree by 2008, made possible by an industry grant and a master’s degree programme in 2010. The path was pioneered by Seppo Virtanen, Jouni Isoaho, Antti Hakkala, and Petri Sainio.

Back then, Turku had no real infosec community. Meetings between academia and industry happened occasionally, but there was nothing local to belong to. Disobey started in 2016. Shamil Alifov, originally from Azerbaijan, suggested the idea of a regular meetup to Valtteri Niemi, got the green light, and then, for a while, nothing happened. Disobey and Boost Turku gave the idea the push it needed.

The first TurkuSec meetup on 23 May 2016 set the tone for everything that followed: share knowledge, be excellent to each other, and keep showing up.


Ten years on: what TurkuSec became

What started as thirty-five people and one speaker grew into TurkuSec ry, a registered information security association with nearly a meetup a month, roughly nine times a year, through every possible scheduling disaster.


Over the decade, the community added company visits that turned into real conversations, Shadow events, lunch meets, workshops, after parties, and events that were never quite the same twice. Lockpicking tables show up when someone brings them. Cybersauna became part of the vocabulary. Disarray, TurkuSec’s autumn cruise conference, launched as something that sounded slightly unhinged and became a fixture. The community supports Disobey. The flamingo mascot stayed. The pink rubber ducks stayed. Some traditions you simply do not argue with.


Honorary members now include Johannes Kossila, Joona Hoikkala, Peter De Schrijver, Raimo Hilden, Ralf Strandell, and Shamil Alifov, people who shaped what TurkuSec is, not just people who showed up once and left.


The 2026 board carries that forward: Ismayil Hasanov as chair, with Shamil Alifov, Shashika Harshani, Tatu Aalto, Mohd Junaid Ahmed, Madura Rajapakshe, Joona Kannisto, Lotta Saarinen, and Kamran Aliyev. Volunteer-run. No full-time event staff. Just people who keep doing the work.

A decade of talks

Joona Hoikkala’s birthday talk made this visible in a way a timeline never could. He brought printed cards with titles from past TurkuSec meetups, a deck of conversation starters spanning years of community memory.


The range tells you everything about what TurkuSec actually is. Technical depth sits next to humour, industry next to academia, serious incident response next to lock-picking and


Commodore 64 architecture. A few examples from across the years:

  • “Exploiting the Cloud”, Laura Kankaala

  • “ICS Security”, Antti Alestalo (September 2018)

  • “Digital natives…”, Joel Latto

  • “Hacking as a Service / Chinese APT”, Petteri Nakamura (April 2024)

  • “I’m a script kiddie…”, Anne Hautakangas (March 2024)

  • “Bad dreams of a white hat hacker”, Alexander Paltsev (January 2026)


Some titles did not fit Joona’s card categories and got left off, including a May 2023 meetup and talks like “Infosecurity and your mom.” That, too, is TurkuSec.


The birthday evening’s own lineup followed that tradition: AI and human expertise, ADCS detection engineering, and an open-ended conversation about where bug bounty and product security are heading. Three talks, three completely different directions. That is the point.


Birthday evening programme

The celebration opened with a welcome, glasses raised for TurkuSec, practical info, and words from sponsors. Three talks carried the technical part of the evening, with breaks and open mic slots between them. The night closed with Pystyy Vetää, TurkuSec’s open stage for anyone who wants to share something, ask something, or just keep the conversation going.


Schedule

  • 17:40: Doors open

  • 18:00: Welcome and sponsor greetings

  • 18:10: “Is human knowledge still valuable?”, Benjamin Särkkä

  • 18:40: Break / Open Mic

  • 19:00: “ADCS for Defenders”, Niklas Särökaari

  • 19:30: Break / Open Mic

  • 19:45: “To Be Discussed”, Joona Hoikkala

  • 20:30: Pystyy Vetää / Open Mic

“Is human knowledge still valuable?”, Benjamin Särkkä

Benjamin Särkkä, Founder of DisObey and Head of Cybersecurity Assurance at Volvo, opened the talks with a question that has followed the industry all year: what is AI actually good for, and where does human expertise still matter?


His starting point was AI-driven software development, including ideas popularised by figures like George Hotz, and a position that many in the room were quietly thinking: AI is not yet capable of producing secure code in any reliable sense. People who lean on it hardest for security work, he argued, are often not thinking creatively. They are outsourcing the thinking and calling it productivity.


Benjamin also drew a useful distinction between how different AI companies approach the problem. OpenAI aims to solve everything, to be the general intelligence. Anthropic builds models for specific purposes. That difference matters when you are deciding what to trust and where to put your own judgement back in the loop.


The talk moved through trust, opportunism, and a line that landed cleanly in the room: things are not as bad as we like to think, but is that good enough? The answer, plainly, was no. Not doom. Not hype. Just a reminder that “not catastrophic yet” is not the same as “good enough.”


“ADCS for Defenders”, Niklas Särökaari

Niklas Särökaari, Lead Cybersecurity Operations Engineer at KONE, brought the evening back to concrete defender work: Active Directory Certificate Services, and what blue teams can actually do about abuse.


He was clear about scope from the start. The talk would not cover every ESC technique, mainly ESC1, and there would be a lot of KQL. For a Friday evening crowd, that was a fair warning and, as it turned out, exactly what many people wanted.


Active Directory Certificate Services is a Microsoft PKI solution used widely in enterprise environments for authentication, encryption, and signing. SpecterOps documented fifteen publicly known attack vectors in their “Certified Pre-Owned” research. Material aimed at defenders has always been thinner on the ground. Niklas was filling that gap.


ESC1 in practice: a low-privileged user with enrollment rights to a vulnerable certificate template can request a certificate on behalf of another domain identity. Impersonation happens through Subject Alternative Name abuse. The conditions are specific: enrollee supplies the subject, client authentication extended key usage, no manager approval required. When they align, the impact is serious.


Detection: Niklas walked through the event log chain defenders should know: certificate request (4886), approval (4887), template load (4898), and Kerberos TGT request (4768) when the certificate is used. The useful detail is what normal certificate requests look like in the Attributes field versus what abuse looks like, specifically whether expected values like cdc:, rmd:, and ccm: appear as they should.


He demonstrated KQL for catching anomalous requests, correlating issuance events with Kerberos usage, and layering indicators such as PreAuthType 16 for PKINIT, ticket option differences left by tools like Rubeus, Impacket, and Certipy, and shifts in encryption type.


Hardening and tooling: Microsoft Defender for Identity added an ADCS sensor in August 2023, covering PKINIT abuse, suspicious domain controller certificate requests, and ESC7 setting changes. Niklas also pointed to regular auditing with Locksmith, PSPKIAudit, SharpHound 2.3+, Certify, and Certipy, and to deception approaches like Certiception honeypot templates from SRLabs for catching attackers probing ESC1-shaped misconfigurations.


This was a talk you could take back to work on Monday morning. That alone made it one of the highlights of the evening.



“To Be Discussed”, Joona Hoikkala

Joona Hoikkala’s slot was titled “To Be Discussed,” and he meant it literally.

The slides opened as a deck of conversation starters, printed cards carrying titles from past TurkuSec talks, from “Exploiting the Cloud” and “ICS Security” to “Hacking as a Service” and “Bad dreams of a white hat hacker.” Talks that have shaped what this community discusses. Some titles were found but did not fit the card categories, so they were left off. That, too, felt very TurkuSec.


The central thread was blunt: bug bounty is dying, but not for the reason most people assume.


Joona was not making the usual “AI found all the bugs” argument. His concern ran deeper: how we communicate findings, how pentesting and AI-assisted pentesting are being sold, how code audit and tools like Claude Security create a false sense of coverage. Great, but then what? Remediation is still broken. Centralised vulnerability management is still a mess. The mean time to remediate is still embarrassing at most organisations.


Product security teams are under pressure. Impact gets discussed in slides but not in sprint planning. Privacy gets a checkbox. Tomorrow’s problems wait because today’s fire is louder.

The through-line was that the industry is building mythos around AI replacing security work while the actual controls, remediation, impact assessment, and honest conversation between finders and builders, are eroding underneath. Slide after slide returned to the same refrain: we need to discuss current controls, remediation, impact, tomorrow, work, and privacy.


And then, because this is TurkuSec: we need to Pystyy Vetää.


More than the talks

Between sessions, the open mic slots did what they always do: give the room back to the people in it. After the last scheduled talk, the evening shifted into workshops, lockpicking tables, and the hands-on activities that vary from event to event but never really disappear.

TurkuSec has always been more than a speaker lineup. The community runs Disarray, the autumn cruise conference. It supports Disobey. It shows up at company visits, Shadow events, lunch meets, and the informal gatherings that do not always make it into a published schedule.

"Be excellent to each other. Party on, folks. Share knowledge." -TurkuSec Code of Conduct

Behind the scenes

Most people see the talks. The part that keeps TurkuSec running for ten years is everything around them.


Volunteers, not an events company. TurkuSec ry is a registered non-profit association. The board plans meetups, finds speakers, handles sponsors, and shows up on the night to make things work. Membership costs 13,37 euros. You can also support the community with a membership plus donation bundle at 69,42 euros. Nobody is doing this for profit. They are doing it because the community needed a place to exist.


“Schedule, what a concept.” The birthday programme listed start times, but everyone involved knows the schedule is flexible. Talks run long when the room is engaged. Open mic expands when someone has something worth saying. Breaks become conversations. That is intentional. TurkuSec is not trying to be a corporate conference with perfectly timed transitions.


Venues, sponsors, and the invisible work. Someone finds a space that fits, this time Q Talo. Someone coordinates Silverskin Information Security and F-Secure as sponsors. Someone handles registration through events.turkusec.fi. Someone streams to twitch.tv/turkusec so people who cannot attend in person still get access. Ismayil opened the birthday evening with a welcome presentation walking through the full history, from UTU’s first cybersecurity courses to Disarray, under the slide title Mother of CitySecs. Behind every smooth-looking evening is a fair amount of coordination that most attendees never see.


Sponsor greetings at the TurkuSec birthday meetup

The meetup streamed live on twitch.tv/turkusec

The unglamorous prep work. Before the doors open, someone stocks the fridge, lays out snacks, and sorts stickers for the tables. None of it makes the schedule, but all of it shapes how the evening feels.


Activities that change every time. Lockpicking tables appear when the right people are available. Workshops vary. After-party energy shifts depending on who is in the room. Disarray adds a CTF, a cruise ship, and cabin networking on top of the regular meetup rhythm. No two TurkuSec events are identical, and that is part of the appeal.


A code of conduct that is actually meant. Be excellent to each other. Party on, folks. Share knowledge. Pystyy Vetää attitude. It is not decorative text on a website. It is how the community expects people to behave: welcoming to first-timers, serious about knowledge sharing, allergic to elitism.


If you have ever wondered whether these events happen by magic, they do not. A small volunteer crew makes them happen, month after month, year after year. The birthday party was a celebration of that too, not just ten years of talks, but ten years of people doing the unglamorous work of keeping a community alive.

Why show up: TurkuSec, CitySec, and what you actually gain

If you have never been to a TurkuSec meetup, or any CitySec event in the Nordics and Baltics, this is the short version of what you are missing.


You learn something new, even outside your lane. I came for the birthday atmosphere and left with three genuinely different threads to follow: AI and human judgement, ADCS detection engineering, and a blunt conversation about where bug bounty and product security are actually heading. CitySec events are brilliant at broadening your T-shaped skillset. You sit through talks that may not be your day job, and you still walk away smarter. A GRC person hears about KQL. A detection engineer hears about AI hype. Everyone benefits.


You meet people who care about the same things. That sounds obvious, but it is the part that sticks. Students get a low-pressure entry into the industry: real practitioners, real problems, no recruitment theatre. Professionals find a room where knowledge moves in every direction. You might arrive for one talk and end up in a conversation about incident response, lockpicking, or where to find food after the venue closes.


You get Pystyy Vetää. TurkuSec’s open stage is not a polished panel. Anyone can share an idea, ask a question, pitch a project, or just keep the conversation going. Between the scheduled talks, the open mic slots gave the room back to the people in it. That is rare at bigger conferences, and it is one of the reasons TurkuSec has kept its character for ten years.

You become part of something local. TurkuSec is not an isolated meetup. It is part of the CitySec network connecting communities across the region. Showing up once does not mean you need to know everyone already. The atmosphere is welcoming by design: be excellent to each other, party on, share knowledge.


I left the evening with more than notes from three talks. I left with a better sense of where the community has been, where it is going, and why it is worth showing up again.

Meeting like-minded people, TurkuSec style


For information about upcoming TurkuSec events, visit turkusec.fi and events.turkusec.fi.

Speakers

Venue: Q Talo, Nummenpuistokatu 2, 20540 TurkuStream: twitch.tv/turkusec

Pictures: TurkuSec 10th Birthday Meetup

Text: Roosa Yöruusu, W4CFI Articles

 
 
bottom of page