Bay Area Anti-Summit Nov 17, 2026
Date & Time:
Tuesday, November 17, 2026
08:30 – 17:30 PST
Venue:
Devil's Canyon Brewing Company
935 Washington St, San Carlos, CA 94070
Bay Area
Register Today

A Different Kind of Security Event

The InfoSec Anti-Summit challenges the status quo by creating a space for CISOs and security leaders to engage, collaborate, and share real-world experience. Through a series of hands-on workshops, tabletop exercises, mock scenarios, and peer-led discussions, the Anti-Summit encourages maximum exchange of ideas in a setting built for trust, candor, and community. This is not about watching from the sidelines, it is about being part of the conversation. It's not about people on stage talking at the audience, it's about getting people around the table talking with each other. Identify the challenges. Understand how others are solving them. Develop a strategy to safeguard. Welcome to the Anti-Summit.

What to expect

CISO-Led Agenda

Start the day with a realistic tabletop simulation designed to see how you handle the pressure under fire. From there, you'll dive into hands-on workshops led by seasoned security leaders who are opening up their playbooks and sharing the lessons they've learned firsthand.

Connection Over Convention

Find your people and talk honestly about what's working and what isn't in security today. Between the hallways and post-session chats, you'll grow your circle and strengthen existing relationships to build a trusted network you can lean on long after the event ends.

Earn Your CPEs

Keep your certifications up to date while you learn. Every session, workshop, and simulation you attend throughout the day counts directly toward your CPE credits, letting you invest in your career while you connect with the community.

Agenda

08:30 – 09:30
Registration & Breakfast
09:30 – 09:40
Opening Remarks
09:40 – 10:40
Ghost in the Machine: AI Threat Response

This interactive tabletop exercise challenges participants to respond to a sophisticated, multi-vector incident that targets their AI infrastructure through unexpected attack surfaces. Your customers look to you to lead in times of disruption and crisis. This exercise will challenge traditional thinking and disrupt the approach to incident and crisis management.

10:50 – 11:20
Workshop #1: Simplifying Cloud Identity Analysis for Security Teams

Cloud environment scale has far outpaced the availability of specialized security expertise. As non-human identities, cross-account permissions, and sprawling API access multiply, traditional security operations teams struggle to trace intent and spot compromised credentials before lateral movement occurs. This workshop focuses on demystifying complex cloud identity mechanics. Participants will analyze practical approaches for translating raw administrative events and credential usage into clear behavioral timelines, allowing generalist security teams to identify insider risks, detect account takeovers, and investigate cloud incidents without relying on manual log queries.

10:50 – 11:20
Workshop #2: Identity Security in Practice: Moving Beyond Visibility to Control

Many organizations have strong visibility into identity and access, but far less confidence in their ability to actually control it. This workshop will focus on how security teams are managing access in practice across SaaS, non-human identities, and constantly changing environments. We will compare what is working, where traditional approaches fall short, and how teams are evolving beyond static roles and periodic reviews to achieve more reliable control over access.

11:35 – 12:20
Anti-Roundtable: Building the Identity and Authorization Stack for the Full Agentic Action Chain

Your workforce is already using Claude, ChatGPT and other AI assistants, and development teams are shifting coding, testing and QA work to autonomous agents that connect to APIs, MCP servers, SaaS applications, cloud infrastructure and production data. Authentication is only the beginning. In this hands-on workshop, we'll trace an agent request from its originator to the sensitive resource it's trying to reach, mapping the controls along that chain (network controls, API security, MCP gateways, agent identity, model guardrails and runtime authorization) and examining what each one can actually see and stop. The goal: answer what your identity and security stack needs to look like when agents act on behalf of people, NHIs and other agents. You'll leave with a framework for evaluating your agent security stack, identifying gaps and deciding where authentication, connectivity controls and runtime authorization belong as agentic adoption expands.

12:30 – 13:00
CISO Led Workshop: The Innovation Paradox: Are we solving the hardest problems, or just the easiest ones to sell?

The cybersecurity industry has never had more engineering talent, more AI capability, or more investment. Yet many of our biggest operational problems remain largely unchanged. We keep innovating around detection, summarization, copilots, and automation, while organizations still struggle with ownership, accountability, authority, remediation, and decision-making, the problems that actually determine whether security outcomes improve. Is this the natural evolution of technology, or are we optimizing for problems that are easier to demonstrate rather than the ones that are harder to solve? In this interactive discussion, we'll explore questions such as why some cybersecurity problems attract enormous innovation while others go untouched, whether we are optimizing for technical elegance or operational impact, what we would build differently if enterprise adoption, not product demos, were the measure of success, where the next decade of AI investment should actually go, and which problems are waiting for someone willing to solve the uncomfortable parts of cybersecurity.

12:30 – 13:00
CISO Led Workshop

Practitioner To Be Announced

13:00 – 14:00
Lunch
14:00 – 14:45
Anti-Roundtable: Escaping the Past for Agentic GRC Era

Traditional GRC breaks down under pressure... So let's put it under pressure. Participants will move through hands-on challenges that mirror real life challenges that they need to pass to free a team mate from "Audit Hell". By working physically, collaboratively, and under time constraints, this session shows how AI agents can transform slow, manual compliance into fast, data-driven decision-making. Come ready to move, build, and escape outdated GRC thinking.

15:00 – 15:30
Workshop #1: Managing the Code and Cloud Vulnerability Explosion Driven by AI

As software development teams increasingly rely on AI to generate application code, the sheer volume of software hitting production environments is accelerating exponentially. This surge in deployment frequency brings an unprecedented wave of potential code and cloud vulnerabilities, quickly overwhelming security teams tasked with manually triaging backlog lists. This workshop examines practical strategies for modernizing vulnerability management workflows in high-velocity development pipelines. Attendees will analyze how AI-driven analysis can automate the triage process, filter out non-exploitable security issues, and streamline remediation efforts so engineering teams can focus strictly on high-impact exposures.

15:00 – 15:30
Workshop #2: Connecting Context Across Code Cloud and Runtime Operations

Security tools operating in silos often create isolated streams of alerts, forcing security teams to manually piece together whether a code vulnerability poses an actual threat in production. Without shared context between source code, cloud infrastructure, and live runtime behavior, teams waste critical hours chasing low-priority issues while active risks remain unaddressed. This session explores methods for unifying data across the entire software development lifecycle. Participants will evaluate how combining repository analysis, cloud posture, and runtime behavior drastically improves remediation accuracy, reduces false positives, and helps engineering teams fix critical flaws directly inside their existing workflows.

15:45 – 16:15
CISO Led Workshop

Practitioner To Be Announced

15:45 – 16:15
CISO Led Workshop

Practitioner To Be Announced

16:20 – 17:30
Networking & Happy Hour

Voices of the Anti-Summit

Aftab Banth
Aftab Banth
Global Head of Security
Puneet Thapliyal
Puneet Thapliyal
Chief Information Security Officer
Robert Jordan III
Robert Jordan III
VP Information Security

Lead Sponsors

P0 SecurityAnecdotes

Supporting Sponsors

PermisoLinx SecurityMazeAikido

Dinner Sponsor

Sysdig

Reserve your seat

Register for Bay Area Anti-Summit Nov 17, 2026

Are you a member of The CISO Society?