CypherCon 2026

What the Scope? Sh** my Consultant | Client Says

Qasim Ijaz & Luke McOmie

Abstract:

Together, we’ll break down the myths, misunderstandings, and misguided security decisions that plague real-world engagements. More importantly, we’ll provide actionable solutions—how both sides can work together to create realistic scopes, conduct meaningful testing, and drive security outcomes that actually matter.
Agenda:
It’s not in PCI Scope
Can you please disable the EDR?
We have a WAF
850 findings, 150 critical, couldn’t gain access
We have MFA
Can you pentest at night?

Qasim Ijaz & Luke McOmie

Disable the EDR!!

Qasim is the Director of Cybersecurity at a leading healthcare organization, overseeing detection, incident response, vulnerability management, purple teaming, and cybersecurity engineering. With a strong background in offensive security and risk management, he has helped organizations strengthen their defenses against evolving threats. He is also a dedicated educator, mentoring professionals and sharing his expertise at conferences such as BSides and Black Hat. Committed to advancing cybersecurity in healthcare, he drives innovation in proactive defense and risk management.

 

Mr. McOmie is the Vice President of OffSec, Vulnerability Management, and Advisory Services at RedHelm.  He began his career in infosec in 1994, founded r00t Cellar Security Team, SkyTalks, and has contributed to the industry by serving as a trusted advisor, security leader, and mentor. With a career focus in offensive security and a strong technical background, he is recognized for his excellence in developing and executing enterprise security strategies and leading technical and tactical programs. He has founded and contributed to several industry leading organizations over his career including start-ups, fortune 100 enterprises, and federal agencies. As an extrovert, he passionately supports the information security community, is a featured speaker at various conferences, the founder of SkyTalks, a published author, and an industry liaison for many businesses and organizations.

Specialties: Security Leadership & Program Development, Security Service Practice & Team Direction, Red Teaming, Ethical Hacking, Penetration Testing, Social Engineering, Physical Security, Assessments, Incident Response, Compliance. By leveraging these talents and his experience, Mr. McOmie guides companies and executive leaders to understand the importance of, communicating the need for, and addressing the challenges that it takes to create and maintain a strong security posture.