Skip to Main Content

How attackers get in and how we stop them

Watch a Live Comedy Hacker show exactly how attackers get into public sector organisations. Then see the same attacks from the other side, through the eyes of the Phoenix Security Operations Centre (SOC).

  • Live attack demos from comedy hacker, Tobias Schroedel.
  • What our SOC detected across the UK public sector this year.
  • A real incident, step-by-step, from first alert to containment.
Blue icon of calendar

Thursday 22nd October 2026

Blue icon of clock

10:00 – 11:30

Blue location icon

Online

40

of public sector organisations we surveyed had a cyber incident in the last two years.

75

of respondents say they don’t have enough in-house cyber security skills.

91

ransomware leak sites were active at the same time in Q1 2026, a new record.

Vulnerabilities are now being exploited within hours of disclosure. Phishing kits are built to get past MFA. Social engineers are targeting service desks directly. Meanwhile, public sector IT teams are telling us that they don’t have the in-house cyber skills to manage this.

Most security events tell you what could go wrong. This one shows you how it happens, then shows you what stopping it looks like. You’ll leave knowing where you could get exposed and how to action it.

  • See the attack live. From MFA tricks and spoofed phone numbers to deepfake video calls, watch the techniques attackers are using against organisations like yours right now.
  • See what the SOC sees. Our analysts show what those same attacks look like in the logs. How often they’re hitting the UK public sector, and how quickly they escalate.
  • Leave with the next steps. Hear guidance built for small teams and tight budgets. Including how to get 24/7 cover without building your own security operations centre.

Join from anywhere and put your questions to Tobias and our SOC team live.

  • Welcome: an introduction from Phoenix and Tobias.
  • Keynote: Tobias Schroedel. Live hacking demos showing how attackers get in.
  • Q&A with Tobias.
  • What we saw in Q1: findings from the Phoenix Threat Report.
  • Inside the SOC, anatomy of a real attack: Tobias showed you the first few minutes of an attack. Here’s what the next few hours looked like in a real incident our SOC handled this year.
  • What does 24/7 threat detection and response look like?
  • Audience Q&A with the SOC team

Get a head start

The Phoenix Threat Report 2026

The biggest theme of the year so far is speed, with vulnerabilities being exploited within hours of disclosure. Read the report before the webinar and bring your questions to our SOC team.

page 3 and 4 of threat report

Your speakers

Tobias Schroedel - Headshot

Tobias Schroedel

Live Comedy Hacker and Cybersecurity Expert

Fred Astfeldt headshot

Fred Astfeldt

Head of Managed Security Solutions, Phoenix

Headshot of Ryan Groom

Ryan Groom

SOC Development Manager, Phoenix

24/7 human-led monitoring, detection, and response.

We are passionate about helping public sector organisations achieve robust cyber security. When it comes to managed solutions, Phoenix stands out as the leading choice. We are a Microsoft Partner for Security, a member of the Microsoft Intelligent Security Association (MISA), and Microsoft’s UK Partner of the Year for 2021.

Our managed SIEM solution utilises Microsoft Sentinel to provide 24/7 threat detection, analysis, and response.

Image of a IT support professional talking on a headset. Image includes our Microsoft MXDR, Microsoft UK Partner of the Year, and Microsoft Security Partner logos.
CTA blue shape

See how they get in. See how we stop them.