
Start the day with a realistic tabletop simulation designed to see how you handle the pressure under fire. From there, you'll dive into hands-on workshops led by seasoned security leaders who are opening up their playbooks and sharing the lessons they've learned firsthand.
Find your people and talk honestly about what's working and what isn't in security today. Between the hallways and post-session chats, you'll grow your circle and strengthen existing relationships to build a trusted network you can lean on long after the event ends.
Keep your certifications up to date while you learn. Every session, workshop, and simulation you attend throughout the day counts directly toward your CPE credits, letting you invest in your career while you connect with the community.
This interactive tabletop exercise challenges participants to respond to a sophisticated, multi-vector incident that targets their AI infrastructure through unexpected attack surfaces. Your customers look to you to lead in times of disruption and crisis. This exercise will challenge traditional thinking and disrupt the approach to incident and crisis management.
Traditional DLP can identify policy violations, but insider incidents rarely begin with a single obvious event. AI usage, departing employees, cloud collaboration, and subtle behavioral changes often look like normal work until the full picture emerges. In this collaborative investigation, you’ll work alongside fellow security leaders to evaluate an unfolding insider risk scenario. As new evidence emerges, your team will reassess risk, debate response strategies, and compare approaches with peers. Attendees will leave with practical questions and ideas you can immediately apply to your own Insider Threat program.
In this session, your group will work through a real-world scenario drawn from the environments organizations operate in today. The scenario describes a situation containing policy gaps, credential risks, and identity blind spots. Your job is not to find a vendor. It is to identify what is broken and decide what should change.
Traditional scanners drown defenders in theoretical alerts while adversaries use weaponized automation to quietly chain minor weaknesses into full-blown network compromises. This 45-minute peer roundtable skips the basic compliance checklists to analyze exactly how modern attackers find and exploit the hidden connections across your environment. Participants will break down real-world multi-stage attack paths, sharing practical strategies to identify critical exposure points and cut off the adversary's lateral movement before they can reach your crown jewels. You will engage in an open exchange on how to validate your true blast radius, eliminate defensive assumptions, and prioritize remediation based on actual exploitability rather than arbitrary severity scores.
Most organizations can point to an AI pilot they're proud of, but few can say with confidence what it actually returned. This talk offers a practical framework for measuring AI ROI honestly across the full lifecycle of an initiative, from before the first line of code to well past the pilot phase. Attendees will leave with a pre-build definition process for what "success" actually means and what baseline to measure against, avoiding the trap of retrofitting metrics to justify a project after the fact. A framework for weighing hard numbers against soft signals, so cost savings and headcount don't overstate the picture while harder-to-quantify value, like decision quality, reclaimed time, and customer experience, doesn't get overlooked. And a measurement cadence, ownership model, and reporting structure that holds up 12 to 18 months in, past the novelty phase, whether results decay or finally reveal their real value.
Most penetration tests get scoped in a rush and end with a PDF that sits in a shared drive until the next audit. This workshop shows you how to turn a pentest into one of the highest-value security dollars you spend. Attendees will leave with a framework for hiring the right testing partner, a scoping approach built around real business risk, clarity on when to use black box versus white box testing, a method to verify that alerts and alarms actually fire, and a remediation strategy focused on fixing root causes rather than chasing a findings list.
Your customers are increasingly becoming part of your attack surface. Fake websites, social accounts, marketplaces, and AI-generated impersonation can exploit a company’s identity without ever touching its network. But when that happens, who owns the risk – security, fraud, legal, marketing, trust & safety, or someone else? This will be a candid roundtable conversation about where customer-targeted fraud fits into the modern security program. We’ll debate where the CISO’s responsibility begins and ends, how organizations are dividing ownership and budget today, and how AI is changing the scale and sophistication of impersonation attacks. This isn't a briefing. We'll pose key questions to attendees to compare notes on how their teams are handling ownership, budget, and response in practice. We'll also put everyone's instincts to the test with a live round of "Can You Spot the Fake?" where attendees vote on real versus AI-generated examples and see just how difficult digital impersonation has become. Attendees will leave with perspective from their peers on how security organizations are approaching customer-targeted fraud, where ownership is shifting, and what CISOs should (and shouldn't) own as this threat evolves.
As Ian Malcolm would assert: AI finds a way. And so does disruption be it ransomware, an outage, or a system nobody mapped until it mattered. In this session, we borrow a page from Jurassic Park (and a few bricks from LEGO) to talk about what real resilience looks like when your environment is changing constantly from within with AI deployed and from the outside. We'll explore why protection alone isn't enough, why "we think it'll recover" no longer cuts it with regulators and insurers, and how leading security and infrastructure teams are moving from static continuity plans to continuously validated, provable resilience. Expect a candid conversation on backups, drift, dependencies, and the small, sturdy building blocks that hold up an enterprise when things go wrong, and how to make sure yours are strong enough to survive the unexpected.
You have one goal: get to the vault. In this workshop, you’ll step into the attacker’s seat to steal an organization’s crown jewels: customer data, financial records, classified product information. You’ll study the target company’s security program and environment, choose your method of attack, and pick your entry point. With each attempt, more is revealed – permission chains, misconfigured AD groups, agentic AI usage, and more. Along the way, you’ll get to see an organization through the eyes of an attacker and leave with a sharper case for least-privilege access controls and a clearer view of the growing gap between what you can see and what’s actually there.
Every CISO has to at some point present to a board, or to executive leadership at their company, even The Imperial CISO. In this simulation exercise, attendees will help fellow CISO Society member Mea Clift survive presenting bad security news to Darth Vader and other key Imperial stakeholders. Through audience-driven decisions, she'll prioritize risks, communicate critical vulnerabilities, respond to uncomfortable questions, and balance candor with diplomacy. Join us for a Star Wars-themed exploration of executive communication, cyber risk, and the timeless lesson that ignoring exhaust-port vulnerabilities rarely ends well.












Are you a member of The CISO Society?