
Start the day with a realistic tabletop simulation designed to see how you handle the pressure under fire. From there, you'll dive into hands-on workshops led by seasoned security leaders who are opening up their playbooks and sharing the lessons they've learned firsthand.
Find your people and talk honestly about what's working and what isn't in security today. Between the hallways and post-session chats, you'll grow your circle and strengthen existing relationships to build a trusted network you can lean on long after the event ends.
Keep your certifications up to date while you learn. Every session, workshop, and simulation you attend throughout the day counts directly toward your CPE credits, letting you invest in your career while you connect with the community.
This interactive tabletop exercise challenges participants to respond to a sophisticated, multi-vector incident that targets their AI infrastructure through unexpected attack surfaces. Your customers look to you to lead in times of disruption and crisis. This exercise will challenge traditional thinking and disrupt the approach to incident and crisis management.
Cloud environment scale has far outpaced the availability of specialized security expertise. As non-human identities, cross-account permissions, and sprawling API access multiply, traditional security operations teams struggle to trace intent and spot compromised credentials before lateral movement occurs. This workshop focuses on demystifying complex cloud identity mechanics. Participants will analyze practical approaches for translating raw administrative events and credential usage into clear behavioral timelines, allowing generalist security teams to identify insider risks, detect account takeovers, and investigate cloud incidents without relying on manual log queries.
Many organizations have strong visibility into identity and access, but far less confidence in their ability to actually control it. This workshop will focus on how security teams are managing access in practice across SaaS, non-human identities, and constantly changing environments. We will compare what is working, where traditional approaches fall short, and how teams are evolving beyond static roles and periodic reviews to achieve more reliable control over access.
Your workforce is already using Claude, ChatGPT and other AI assistants, and development teams are shifting coding, testing and QA work to autonomous agents that connect to APIs, MCP servers, SaaS applications, cloud infrastructure and production data. Authentication is only the beginning. In this hands-on workshop, we'll trace an agent request from its originator to the sensitive resource it's trying to reach, mapping the controls along that chain (network controls, API security, MCP gateways, agent identity, model guardrails and runtime authorization) and examining what each one can actually see and stop. The goal: answer what your identity and security stack needs to look like when agents act on behalf of people, NHIs and other agents. You'll leave with a framework for evaluating your agent security stack, identifying gaps and deciding where authentication, connectivity controls and runtime authorization belong as agentic adoption expands.
The cybersecurity industry has never had more engineering talent, more AI capability, or more investment. Yet many of our biggest operational problems remain largely unchanged. We keep innovating around detection, summarization, copilots, and automation, while organizations still struggle with ownership, accountability, authority, remediation, and decision-making, the problems that actually determine whether security outcomes improve. Is this the natural evolution of technology, or are we optimizing for problems that are easier to demonstrate rather than the ones that are harder to solve? In this interactive discussion, we'll explore questions such as why some cybersecurity problems attract enormous innovation while others go untouched, whether we are optimizing for technical elegance or operational impact, what we would build differently if enterprise adoption, not product demos, were the measure of success, where the next decade of AI investment should actually go, and which problems are waiting for someone willing to solve the uncomfortable parts of cybersecurity.
Practitioner To Be Announced
Traditional GRC breaks down under pressure... So let's put it under pressure. Participants will move through hands-on challenges that mirror real life challenges that they need to pass to free a team mate from "Audit Hell". By working physically, collaboratively, and under time constraints, this session shows how AI agents can transform slow, manual compliance into fast, data-driven decision-making. Come ready to move, build, and escape outdated GRC thinking.
As software development teams increasingly rely on AI to generate application code, the sheer volume of software hitting production environments is accelerating exponentially. This surge in deployment frequency brings an unprecedented wave of potential code and cloud vulnerabilities, quickly overwhelming security teams tasked with manually triaging backlog lists. This workshop examines practical strategies for modernizing vulnerability management workflows in high-velocity development pipelines. Attendees will analyze how AI-driven analysis can automate the triage process, filter out non-exploitable security issues, and streamline remediation efforts so engineering teams can focus strictly on high-impact exposures.
Security tools operating in silos often create isolated streams of alerts, forcing security teams to manually piece together whether a code vulnerability poses an actual threat in production. Without shared context between source code, cloud infrastructure, and live runtime behavior, teams waste critical hours chasing low-priority issues while active risks remain unaddressed. This session explores methods for unifying data across the entire software development lifecycle. Participants will evaluate how combining repository analysis, cloud posture, and runtime behavior drastically improves remediation accuracy, reduces false positives, and helps engineering teams fix critical flaws directly inside their existing workflows.
Practitioner To Be Announced
Practitioner To Be Announced



Are you a member of The CISO Society?