Hack Glasgow 2026

Aaron Kelly

Aaron is an information security and technology engineer who secures Critical National Infrastructure and national interests across the North West of England. He advises Defence, Nuclear and Oil & Gas organisations and implements pragmatic security frameworks for SMEs. His standout achievement is leading an ISO27001 transition to the 2022 standard in seven weeks, and he’s currently supporting SMEs to make meaningful security choices that enable business opportunities.

A student of Computing & IT at The Open University and a member of the British Computer Society, Aaron combines hands‑on technical implementation with governance, compliance and assurance expertise. He focuses on delivering measurable risk reduction, rapid certification readiness, and resilient controls tailored to high‑assurance environments.

Outside work he’s an avid reader, craft‑beer enthusiast and amateur radio operator, volunteering with the Raynet amateur radio emergency communications service.


Session

08-15
10:00
25min
Xterminating Liability through Spreadsheet Malware
Aaron Kelly

What does compliance and accounting have in common? We both have a platform for everything but still default to using Excel. Why? Laziness, cost, ease of use (allegedly) and we're just used to it. Throughout this talk, I'm going to go over all the different ways that I've implemented an ISMS and additional security standards, why I keep going back to spreadsheets even when other tools exist. Death by spreadsheet is something we all experience at some point, and you then get the choice to embrace chaos, and begin to evangelise to all the holy ways of VBA, or you can run and hide, and justify those expensive compliance platforms.

Stage 2