CW21 workshop on Cybersecurity Risk Analysis

Wednesday, August 12, 2026 1:00 pm - 4:30 pm EDT (GMT -04:00)

Intro to Cybersecurity Risk Analysis Workshop

Date and time: Wednesday, August 12, 2026, 1:00 - 4:30 pm

Location: Physics (PHY) 235

RSVP: Please fill out the registration form by Friday, August 7th.  

Speaker: Mike Ounsworth, Cryptic Forest Software and Université de Sherbrooke

Light refreshments will be provided during the afternoon break.

Abstract:

Security is never free, so how do you determine the right amount of security for a given software application? This workshop is aimed at students and faculty who have a research interest in cyber security and are curious about the industrial side of triaging, remediating, and countering active exploitation of vulnerabilities. This workshop will introduce methods used in industry for performing risk analysis of software vulnerabilities, including the Red Hat, CVSS, and EPSS rating scales. In the activity portion of the workshop, participants will dissect their chosen vulnerability in the context of a web server or mobile app and rate it using the industry rating scales.

Participant prep work: Bring your favourite attack paper; that is, your favourite cyber security vulnerability. It can be anything from an algebraic cryptography attack to a famous software bug. Read the paper in advance so that you have a basic idea of what the vulnerability is. If you need ideas, see this list: https://www.securinc.io/blog/top-10-most-dangerous-vulnerabilities-of-all-time/