
Start the day with a realistic tabletop simulation designed to see how you handle the pressure under fire. From there, you'll dive into hands-on workshops led by seasoned security leaders who are opening up their playbooks and sharing the lessons they've learned firsthand.
Find your people and talk honestly about what's working and what isn't in security today. Between the hallways and post-session chats, you'll grow your circle and strengthen existing relationships to build a trusted network you can lean on long after the event ends.
Keep your certifications up to date while you learn. Every session, workshop, and simulation you attend throughout the day counts directly toward your CPE credits, letting you invest in your career while you connect with the community.
This interactive tabletop exercise challenges participants to respond to a sophisticated, multi-vector incident that targets their AI infrastructure through unexpected attack surfaces. Your customers look to you to lead in times of disruption and crisis. This exercise will challenge traditional thinking and disrupt the approach to incident and crisis management.
Traditional DLP can identify policy violations, but insider incidents rarely begin with a single obvious event. AI usage, departing employees, cloud collaboration, and subtle behavioral changes often look like normal work until the full picture emerges. In this collaborative investigation, you’ll work alongside fellow security leaders to evaluate an unfolding insider risk scenario. As new evidence emerges, your team will reassess risk, debate response strategies, and compare approaches with peers. Attendees will leave with practical questions and ideas you can immediately apply to your own Insider Threat program.
Standard compliance frameworks frequently turn into a chaotic scramble of chasing down evidence and dealing with audit friction that slows your entire engineering team down. This fast-paced session skips the theoretical consulting slides to show you how to build a security program that sails through frameworks like SOC 2 or ISO 27001 without stopping business momentum. We will map out how to leverage existing technical data to automate your evidence gathering, eliminate duplicate control testing, and confidently prove trust to enterprise buyers. You will leave with an actionable roadmap to run an audit defense that actually strengthens your security posture instead of just checking boxes.
Traditional scanners drown defenders in theoretical alerts while adversaries use weaponized automation to quietly chain minor weaknesses into full-blown network compromises. This 45-minute peer roundtable skips the basic compliance checklists to analyze exactly how modern attackers find and exploit the hidden connections across your environment. Participants will break down real-world multi-stage attack paths, sharing practical strategies to identify critical exposure points and cut off the adversary's lateral movement before they can reach your crown jewels. You will engage in an open exchange on how to validate your true blast radius, eliminate defensive assumptions, and prioritize remediation based on actual exploitability rather than arbitrary severity scores.
Most organizations can point to an AI pilot they're proud of, but few can say with confidence what it actually returned. This talk offers a practical framework for measuring AI ROI honestly across the full lifecycle of an initiative, from before the first line of code to well past the pilot phase. Attendees will leave with a pre-build definition process for what "success" actually means and what baseline to measure against, avoiding the trap of retrofitting metrics to justify a project after the fact. A framework for weighing hard numbers against soft signals, so cost savings and headcount don't overstate the picture while harder-to-quantify value, like decision quality, reclaimed time, and customer experience, doesn't get overlooked. And a measurement cadence, ownership model, and reporting structure that holds up 12 to 18 months in, past the novelty phase, whether results decay or finally reveal their real value.
To Be Announced
Your penetration test wrapped one week ago. No critical findings. Then a critical CVE drops in a third-party component sitting in your environment, and suddenly that clean report means nothing. This roundtable puts participants across security, engineering, risk, and communications in the hot seat. Visibility gaps, incomplete coverage, post-assessment config changes - the scenario gets messier as the clock runs out and external pressure builds. Decisions have to be made before the answers are in. The lesson isn't about the vulnerability. It's about the dangerous comfort of a recent assessment. Participants leave with a sharper understanding of where point-in-time testing creates false confidence - and what a more defensible validation posture actually looks like.
Internal security is mature. The external perimeter, where your brand actually lives across social, messaging, and the open web, isn't. In this 30-minute workshop, we walk the room through a coordinated agentic attack on a single brand and ask you to honestly assess whether your program can detect, prioritize, and dismantle it before customers are harmed. You'll leave with the Digital Trust Kill Chain, a framework for mapping adversarial operations across the agentic internet, and a short self-assessment you can take back to your team.
Many organizations have strong visibility into identity and access, but far less confidence in their ability to actually control it. This workshop will focus on how security teams are managing access in practice across SaaS, non-human identities, and constantly changing environments. We will compare what is working, where traditional approaches fall short, and how teams are evolving beyond static roles and periodic reviews to achieve more reliable control over access.
Every CISO has to at some point present to a board, or to executive leadership at their company, even The Imperial CISO. In this simulation exercise, attendees will help fellow CISO Society member Mea Clift survive presenting bad security news to Darth Vader and other key Imperial stakeholders. Through audience-driven decisions, she'll prioritize risks, communicate critical vulnerabilities, respond to uncomfortable questions, and balance candor with diplomacy. Join us for a Star Wars-themed exploration of executive communication, cyber risk, and the timeless lesson that ignoring exhaust-port vulnerabilities rarely ends well.

Are you a member of The CISO Society?