Toronto Anti-Summit Nov 12, 2026
Date & Time:
Thursday, November 12, 2026
08:30 – 17:30 EST
Register Today

A Different Kind of Security Event

The InfoSec Anti-Summit challenges the status quo by creating a space for CISOs and security leaders to engage, collaborate, and share real-world experience. Through a series of hands-on workshops, tabletop exercises, mock scenarios, and peer-led discussions, the Anti-Summit encourages maximum exchange of ideas in a setting built for trust, candor, and community. This is not about watching from the sidelines, it is about being part of the conversation. It's not about people on stage talking at the audience, it's about getting people around the table talking with each other. Identify the challenges. Understand how others are solving them. Develop a strategy to safeguard. Welcome to the Anti-Summit.

What to expect

CISO-Led Agenda

Start the day with a realistic tabletop simulation designed to see how you handle the pressure under fire. From there, you'll dive into hands-on workshops led by seasoned security leaders who are opening up their playbooks and sharing the lessons they've learned firsthand.

Connection Over Convention

Find your people and talk honestly about what's working and what isn't in security today. Between the hallways and post-session chats, you'll grow your circle and strengthen existing relationships to build a trusted network you can lean on long after the event ends.

Earn Your CPEs

Keep your certifications up to date while you learn. Every session, workshop, and simulation you attend throughout the day counts directly toward your CPE credits, letting you invest in your career while you connect with the community.

Agenda

08:30 – 09:30
Registration & Breakfast
09:30 – 09:40
Opening Remarks
09:40 – 10:40
Ghost in the Machine: AI Threat Response

This interactive tabletop exercise challenges participants to respond to a sophisticated, multi-vector incident that targets their AI infrastructure through unexpected attack surfaces. Your customers look to you to lead in times of disruption and crisis. This exercise will challenge traditional thinking and disrupt the approach to incident and crisis management.

10:50 – 11:20
Workshop #1: Closing the Cloud Exploitation Gap at Runtime Speed

The window between a vulnerability discovery and active exploitation is now down to minutes. When automated attacks move at machine speed, static posture scans and periodic patch cycles cannot keep pace. Security teams end up trapped in an impossible operational loop: managing an endless queue of configuration alerts while active incidents slip through the noise. This session looks at how cloud defense changes when teams prioritize real-time kernel behavior over static inventory reports. Participants will examine how runtime visibility isolates active compromises from background noise, and explore strategies for using automated containment workflows to stop lateral movement inside containerized environments before an initial entry becomes a major breach.

10:50 – 11:20
Workshop #2: Mapping Cloud Telemetry Directly to Real Attacker Behavior

Cloud environments generate massive volumes of log data, but more data rarely translates to better visibility. Security operations teams routinely ingest millions of cloud events daily, only to spend hours manually correlating disjointed API calls, IAM events, and network traces during an investigation. The result is bloated SIEM costs and missed signals buried under false positives. This workshop focuses on restructuring how teams ingest and analyze cloud telemetry. Participants will walk through practical methods for mapping raw log data directly to known adversary tactics, separating normal cloud operations from actual threat activity, and filtering out telemetry noise before it overwhelms analysts or inflates storage budgets.

11:35 – 12:20
Anti-Roundtable: Hoarders Anonymous and the Great Tool Purge

For years, the security industry has sold us a simple equation: more tools equal more coverage. But in practice, bloated stacks don't just drain budgets, but they also create blind spots. When analysts spend too much time jumping between tools and ignoring false alarms, they miss the real threats. This workshop rejects the myth that stacking more tools means stronger security. We’ll explore how leading AppSec teams are reversing course and shedding redundant point solutions in favor of intentional, integrated architectures. You won't just hear theory. You'll leave ready to audit your own stack and define what real security looks like for your team.

12:30 – 13:00
CISO Led Workshop

Practitioner To Be Announced

12:30 – 13:00
CISO Led Workshop

Practitioner To Be Announced

13:00 – 14:00
Lunch
14:00 – 14:45
Anti-Roundtable: Translating Technical Cyber Risk in Boardroom Metrics

Security leaders face mounting pressure from boards and executive teams to quantify cyber risk in financial and operational terms. Technical metrics like patch latency and alert volume fail to communicate actual business exposure, leaving executive leadership detached from strategic security decisions. This session focuses on bridging the gap between technical operations and executive governance. Attendees will work through actionable models for mapping security risks directly to business continuity, regulatory compliance, and financial liability, enabling CISOs to secure necessary budgets and align security investments with enterprise goals.

15:00 – 15:30
Workshop #1: Consolidating the Security Stack Without Sacrificing Protection

Years of point-solution acquisition have left enterprise security teams managing dozens of disconnected consoles, overlapping feature sets, and escalating licensing costs. This operational sprawl bloats operating budgets while creating critical visibility gaps between tools. This interactive workshop evaluates practical frameworks for auditing the enterprise security stack, identifying redundant security controls, and streamlining architecture into unified platforms. Participants will discuss strategies for cutting operational overhead, simplifying analyst workflows, and maintaining strong defense posturing during vendor rationalization.

15:00 – 15:30
Workshop #2: Governing Non-Human Identities and Autonomous Agents

As enterprises deploy autonomous software agents and automated service accounts, non-human identities now vastly outnumber human employees inside corporate networks. Traditional identity and access management frameworks built around human credentials fail to track the speed, lifecycle, and permissions required by machine-to-machine interactions. This workshop explores how CISOs are extending zero trust architectures to non-human actors. Attendees will examine practical approaches for auditing service accounts, implementing dynamic privilege boundaries, and maintaining continuous governance over automated internal processes.

15:45 – 16:15
CISO Led Workshop

Practitioner To Be Announced

15:45 – 16:15
CISO Led Workshop

Practitioner To Be Announced

16:20 – 17:30
Networking & Happy Hour

Lead Sponsor

Thales

Supporting Sponsors

Brava SecuritySysdigBUI

Reserve your seat

Register for Toronto Anti-Summit Nov 12, 2026

Are you a member of The CISO Society?