0x03 Review board

Five people who read every proposal that arrives.

Whoever chooses the talks chooses the event. So the people who do the choosing are named here, and the way they work is written down before the window opens, not after somebody is rejected.

Board complete

The five were confirmed before the call for papers opens on 1 October 2026, and nobody is listed as a reviewer for 0x03 until they have agreed in writing.

Reviewers
Five Every submission goes to the same board.
Paid
No Volunteers, on both sides of the review.

CFP opens 1 October 2026 Closes 25 December 2026 Decisions 10 to 14 February 2027

Separate from the advisory board

01 How the review works

The idea, not the CV.

A review board's only real job is to be harder to game than a popularity contest. This one reads everything, including the proposals from people nobody in the room has heard of, which historically are most of the interesting ones.

What a reviewer is looking for: a thing you found out, some evidence that you found it out, and a reason the room should care.

A proposal is judged on how specific it is. "Bypassing an EDR" is a topic. "How we got a specific EDR to ignore a specific class of loader, and the three attempts that failed first" is a talk. The second one wins.

  • Nobody is paid, on either side

    Reviewers volunteer, speakers are not paid a fee, and no tier of sponsorship includes a slot on the programme. See the boundaries in the prospectus.

  • A conflict means stepping out

    If a proposal involves a reviewer, their employer, their team, their student, their friend, they say so and take no part in that one. This is written into the call for papers, not left to judgement on the day.

  • A first-time speaker is not a risk

    The pool of people who have spoken before is small and largely the same every year. A proposal from somebody who has never done it is an ordinary proposal, and BSides exists in part to change that number.

  • A rejection is not a verdict on you

    More good proposals arrive than there is room for on a single day of talks. Being turned down at 0x03 is mostly arithmetic, and the same proposal is welcome at the next one.

02 Scoring

Five criteria, and what each is worth.

Every submission is scored against the same five criteria, each weighted out of five. These are the weights as set on the submission form, not a summary written afterwards.

  • 5 out of five

    Technical depth

    Is there real substance in it. Original research, a tool you built, or practical insight that cost you something to get, rather than a competent overview of a subject.

  • 5 out of five

    Originality

    Is this new. An unpublished finding, a fresh angle on a known problem, or work nobody has presented yet. A talk that has already run at three other conferences scores low here and it is the most common reason we say no.

  • 4 out of five

    Relevance to our audience

    The room is researchers, red and blue teamers, students and developers. Useful to them is the test, and that is a wider bar than useful to a specialist in your own subfield.

  • 3 out of five

    Clarity and delivery

    Is the proposal clear and structured, and does it look deliverable. A first-time speaker with a strong idea is not marked down here. We would rather help you prepare than lose the talk.

  • 2 out of five

    Fit and format

    Is the format and length you chose the right one for the material, and does it fit the programme being built around it. The lowest weight of the five, and the easiest one to fix by asking us first.

Nineteen points across the five, and the weighting says what we would trade away: a rough proposal about work nobody has seen beats a polished one about work everybody has.

A score is what the board argues from, not the decision itself. Two proposals on the same number is a conversation between five people, and a reviewer with a stake in either is out of it.

Reviews each
5 Every reviewer reads every submission. Nothing is sampled and nothing is filtered before it reaches them.
How many fit
TBA How many slots the programme has follows the venue schedule, which is not final.
Decisions
10 to 14 February 2027 Nobody hears later than 14 February 2027, accepted or not.

03 The board

Five reviewers.

The board is named in full before the submission window opens, so anybody deciding whether to send in a first-ever proposal can see whose hands it lands in. These five read everything.

Named before the CFP opens

  1. Monnappa K A

    Review board member for Asia, USA and Europe

    Black Hat

    Wrote Learning Malware Analysis, built the Limon Linux sandbox, won the 2016 Volatility plugin contest, and co-founded the Cysinfo research community.

    LinkedIn profile
  2. Adhokshaj Mishra

    Staff Detection Engineer

    SentinelOne

    Works on offensive as well as defensive side of Linux malware research; and has delivered lectures on wide array of topics pertaining to Linux malware in various academic and security conferences, as well as various security chapter meetups.

    LinkedIn profile
  3. Sajan Shetty

    Co-founder

    Cysinfo

    Has taught the malware analysis and memory forensics training at Black Hat in Asia, Europe and the United States, and works on machine learning alongside it.

    LinkedIn profile
  4. Donavan Cheah

    Senior security consultant

    Thales

    Writes for the ISACA Journal on threat modelling and the economics of security, sits on its emerging trends working group, and built a CISO role-playing exercise at Thales.

    LinkedIn profile
  5. Tatsat Thakore

    Project scientist 3

    DIA-SVPCoE

    At the DRDO Industry Academia Sardar Vallabhbhai Patel Centre of Excellence at Gujarat University, whose research covers vulnerability analysis, malware analysis and IoT security.

    LinkedIn profile

An employer is named to say what kind of work the person does. It is not a statement that the organisation endorses, sponsors or has any view about BSides Dehradun. Reviewers read submissions as individuals.

Each line above is drawn from work the person has already published under their own name. A reviewer who prefers their own words has them instead.

Reviewing is roughly a month of evenings in January and early February for somebody who knows a subject well. cfp@bsidesdehradun.com is the address if you want to be asked for the next one.

04 Conflicts

If your proposal involves one of us.

Information security in India is a small world, and a review board drawn from it will overlap with the people submitting to it. The answer to that is disclosure, not pretending otherwise.

Say so in your submission. A line in the notes field is enough: name the reviewer and the connection. A declared overlap has never been a reason to reject a proposal, and it means the review cannot be questioned later.

The same applies in the other direction. A reviewer who recognises a proposal as a colleague's, a student's or their own employer's work says so and takes no part in deciding it, whether or not the speaker mentioned it first.

The two boards are separate lists with separate jobs. The review board reads submissions; the advisory board looks at the conference as a whole and has no part in choosing talks. One person may sit on both, and both pages say so.

Questions about a decision go to cfp@bsidesdehradun.com. Anything about somebody's conduct rather than their judgement goes to the code of conduct contacts, which are a different set of people on purpose.

05 Questions

What a first-time submitter asks.

Who reads my proposal?

All 5 reviewers, every time. Nothing is sampled and nothing is filtered before it reaches them, and there is no second, friendlier queue. The board is named in full on this page before the submission window opens, so you can see whose hands it lands in before you send it.

How is a proposal scored?

Against five criteria, each weighted out of five: Technical depth 5, Originality 5, Relevance to our audience 4, Clarity and delivery 3, and Fit and format 2. Nineteen points across the five, which is not a round number and was never meant to be.

The weighting says what we would trade away. A rough proposal about work nobody has seen beats a polished one about work everybody has, and no amount of scoring on the last two criteria closes that gap. A score is what the board argues from, not the decision itself.

Does a well-known employer help?

No. What a reviewer is looking for is a thing you found out, some evidence that you found it out, and a reason the room should care. A well-known employer supplies none of the three, and its absence subtracts nothing. What decides it is how specific the proposal is.

What if a reviewer knows me?

Say so in the submission. A line in the notes field naming the reviewer and the connection is enough. It costs you nothing, a declared overlap has never been a reason to reject a proposal, and it means the review cannot be questioned later by somebody who noticed it afterwards.

The same applies in the other direction. A reviewer who recognises a proposal as a colleague's, a student's or their own employer's work says so and takes no part in deciding it, whether or not you mentioned it first.

Are reviewers paid?

No. Reviewers volunteer and speakers are not paid a fee. There is no sponsored slot on the programme and no tier of sponsorship that includes one.

Is a rejection a verdict on the work?

Mostly it is arithmetic. More good proposals arrive than there is room for on a single day of talks, and how many slots the programme has follows the venue schedule, which is not final. Being turned down at 0x03 is not a verdict, and the same proposal is welcome at the next one.

When do decisions go out?

Between 10 to 14 February 2027. Nobody hears later than 14 February 2027, accepted or not.

Can I join the review board?

Not for this edition. All five seats are filled, and they were filled before the call for papers opens rather than after. Reviewing is roughly a month of evenings in January and early February for somebody who knows a subject well, and cfp@bsidesdehradun.com is the address if you want to be asked for the next one.

Call for papers

Five readers, one inbox, and no shortcut past them.

The window runs from 1 October 2026 to 25 December 2026. Everything that arrives inside it gets read.