Amanda Kollmorgan

also known as

Falk0r Midw3st

International Cybersecurity Speaker · Talk Series Host · Community Builder

I turn security topics that usually put rooms to sleep into talks people actually act on, whether the room is a conference audience, a corporate team, or the students coming up behind us. Host of the Falk0r Midw3st Cybersecurity Talk Series. Share, learn, secure.

Falk0r Midw3st logo: a white dragon holding a shield with a padlock at the center of a network

Stages & audiences

  • DEFCON
  • CypherCon
  • GovIT
  • Cyber Risk Alliance
  • BSides

About

Amanda Kollmorgan
  • Based in Madison, WI · Midwest
  • Travels Regionally, nationally & internationally
  • Formats Keynote · Breakout · Workshop · Panel
  • Languages English

Security is a team sport. I'm here to make the playbook readable.

I've spent almost twenty years in security work across federal and state government building the compliance programs auditors sign off on and, separately, running the operations meant to survive a real attacker. Holding both seats at once taught me the pattern I keep running into: the technical answer already exists, but the paperwork and the adversary are measuring two different things. That gap is where I do my work.

Under the handle Falk0r Midw3st, I run the Falk0r Midw3st Cybersecurity Talk Series, a recurring, no-vendor-pitch space where practitioners in the region share what actually worked, what broke, and what they'd do differently. The name comes from the luckdragon: big energy, a little silly, and absolutely reliable when things go sideways.

I spend about as much time mentoring the next generation of security leaders as I do in an audit committee or a SOC, and I care most about getting people who don't look like the stock photo of a hacker into rooms where decisions get made.

Speaking topics

What I can bring to your stage

Every talk runs 45–60 minutes as a conference session or breakout, or expands into a half-day workshop. I also offer 20-minute lightning talks on request. Happy to tailor to your audience.

TALK 01

Compliant and Compromised: Mapping the Gap Between Your Audit and Your Attacker

Passing an audit and getting breached in the same quarter happens more often than people think, and it's not a contradiction. It just means your evidence measured something different than what the attacker actually exploited. I walk through three control patterns that satisfy assessors while leaving a real path open, map each to the specific MITRE ATT&CK technique it fails to stop, and leave you with a threat-informed validation plan a small team can run, regardless of which regulation is generating the paperwork.

GRC, Compliance & Blue Team

TALK 02

Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills

Cybersecurity has spent a decade investing in tools, frameworks, and controls. Yet the outcome of a real incident still turns on whether the humans in the room trust each other enough to speak plainly and decide under pressure. This talk reframes the human side of cyber, communication, mentorship, trust, and psychological safety, as load-bearing infrastructure rather than a support function. When that layer is weak, technical excellence cannot compensate; when it's strong, ordinary teams produce extraordinary outcomes.

Leadership and Strategy

TALK 03

Rage Bait: Why Women in Cyber Are Tired of Being "Women in Cyber"

The way we do "women in cyber" is broken, and a lot of the people it's supposed to help are done pretending it isn't. The work came with a second job attached: be the gender on the panel, in the mentorship track, at nearly every event that will have you, while the men who should be part of the conversation get told it isn't their room. I make the operational case instead, tracing the metric we got wrong back to what the Women, Peace and Security framework actually asked for. Not headcount. Meaningful participation.

Culture, Diversity & Team Performance

TALK 04

The Logic Looked Fine: Reversing Safety-System Bypass in Critical Infrastructure PLCs

In 2026, Iranian-affiliated actors disrupted PLC operations across US water, energy, and local-government infrastructure without a single zero-day. They reached misconfigured, internet-facing controllers through the manufacturers' own programming software, then modified the safety logic itself: shutdown and alarm routines disabled, HMI displays reading normal while nothing underneath was. I walk through the public advisory this campaign is documented in, then spend the second half on defense that works on a normal budget, from known-good logic validation to monitored gateways in front of controllers that can't defend themselves.

ICS/OT, Threat Intel & Blue Team

Appearances

Where I've spoken

Newest first. If you saw one of these and want the slides, just ask.

  • MAR 2027

    CypherCon

    24–25 March 2027 · Milwaukee, WI

    Upcoming
  • DEC 2026

    GHI-Con

    12 December 2026 · Online

    Upcoming
  • NOV 2026

    DefCamp

    19–20 November 2026 · Bucharest, Romania

    Upcoming
  • NOV 2026

    GovIT 2026

    8–10 November 2026 · Bloomington, MN

    Upcoming
  • OCT 2026

    HackFest Canada

    30–31 October 2026 · Quebec City, Canada

    Upcoming
  • OCT 2026

    Cybersecurity Summit Brasil

    5–6 October 2026 · São Paulo, Brazil

    Keynote
  • SEP 2026

    GrrCon

    24–25 September 2026 · Grand Rapids, MI

    Upcoming
  • ONGOING

    Falk0r Midw3st Cybersecurity Talk Series

    Host & organizer · scheduled around conference bookings, Madison WI area

    Host
  • AUG 2026

    DEFCON: N00b Village

    6–9 August 2026 · Las Vegas, NV

    Speaker
  • JUL 2026

    CyberLab Con 26

    July 2026 · Online · watch below

    Speaker
  • JUN 2026

    U.S. Naval Sea Cadet Corps: Advanced Cybersecurity and Leadership Training Program

    Opening keynote · "Ctrl + Alt + Lead: 5 Things I Wish Someone Had Told Me at Your Age" · 23 June 2026 · Milwaukee, WI

    Keynote
  • JUN 2026

    Cyber Leaders Summit: Miami

    Roundtable moderator · "High-Performing Teams: How do you build resilient, diverse teams that perform under pressure" · 17–18 June 2026

    Moderator
  • JUN 2026

    GrassR00tz

    4 June 2026 · Appleton, WI

    Speaker
  • JUN 2026 Speaker
  • MAY 2026

    BSides312

    16 May 2026 · Chicago · watch below

    Speaker
  • APR 2026

    Wisconsin Governor's Cybersecurity Summit

    Panelist · "Building Wisconsin's Cyber Workforce Pipeline" · 7–8 April 2026 · Appleton, WI

    Panelist
  • APR 2026

    BSides MKE

    3 April 2026 · Milwaukee

    Speaker
  • APR 2026

    CypherCon

    2 April 2026 · Milwaukee

    Speaker
  • MAR 2026

    NEW AITP

    24 March 2026 · Appleton, WI

    Speaker
  • NOV 2025

    GovIT 2025

    20 November 2025 · Bloomington, MN

    Speaker
  • OCT 2025

    Inaugural CRT Conference

    25–26 October 2025 · Wausau, WI

    Speaker
  • OCT 2025

    SysLogic Cybersecurity Summit

    17 October 2025 · Milwaukee

    Speaker
  • MAY 2025

    CyberShield ShieldCon

    31 May 2025 · Virginia Beach, VA

    Speaker

Media

Watch a talk

Full recordings, unedited, from the back of the room.

Ctrl + Alt + Lead

"Hit the gas because CyberLab Con 26 is taking security full throttle with retro arcade energy and modern cyber chaos."

CyberLab Con · Jul 2026

Ctrl + Alt + Lead

"Chicago's Biggest Little Non-Profit Cybersecurity Conference."

BSides312 · May 2026

Speaker kit

Everything an organizer needs

Copy what you need. No form, no email round-trip.

Short bio (50 words)

Amanda Kollmorgan, known in the community as Falk0r Midw3st, is an international cybersecurity speaker and the Security Architect for Veolia North America, and host of the Falk0r Midw3st Cybersecurity Talk Series. With almost twenty years across federal and state government, she speaks on closing the gap between what audits measure and what attackers exploit, and on building human-centered cyber teams.

Long bio (120 words)

Amanda Kollmorgan, known as Falk0r Midw3st, is an international cybersecurity speaker and the Security Architect for Veolia North America, with almost twenty years of experience across federal and state government service, most recently as Deputy IT Director for the Wisconsin Department of Military Affairs and concurrently as Operations Manager of the WI Army National Guard's Defensive Cybersecurity Operations Element. That dual seat, building the compliance programs auditors sign off on while running the operations meant to survive a real attacker, taught her that the widest gaps in cyber rarely show up on paper. She founded and hosts the Falk0r Midw3st Cybersecurity Talk Series, a vendor-free forum where Midwest practitioners share real incidents and real fixes, and has spent an equal amount of her career mentoring emerging leaders and building people-first teams as she has building architecture and running operations. Offstage, she's training for her next endurance race, rewatching Demon Slayer, and still not entirely sure how she keeps ending up with sunken cakes.

Tech & AV

  • Wireless lavalier or handheld mic
  • HDMI to my laptop, 16:9, confidence monitor if available
  • Slides delivered as PDF one week prior on request
  • Recording and photography welcome

Booking

Let's talk about your event

Prefer email?

[email protected]

Response time

Usually within two business days. If your event is inside three weeks, say so in the subject line and I'll move it up.

What I'll ask you

Audience size and seniority, session length, whether it's recorded, and whether travel is covered. Having those ready makes this a one-email conversation.

Fees

Community events, BSides, and student groups: free or travel-only. Corporate and commercial conferences: let's discuss.