
Start the day with a realistic tabletop simulation designed to see how you handle the pressure under fire. From there, you'll dive into hands-on workshops led by seasoned security leaders who are opening up their playbooks and sharing the lessons they've learned firsthand.
Find your people and talk honestly about what's working and what isn't in security today. Between the hallways and post-session chats, you'll grow your circle and strengthen existing relationships to build a trusted network you can lean on long after the event ends.
Keep your certifications up to date while you learn. Every session, workshop, and simulation you attend throughout the day counts directly toward your CPE credits, letting you invest in your career while you connect with the community.
This interactive tabletop exercise challenges participants to respond to a sophisticated, multi-vector incident that targets their AI infrastructure through unexpected attack surfaces. Your customers look to you to lead in times of disruption and crisis. This exercise will challenge traditional thinking and disrupt the approach to incident and crisis management.
The window between a vulnerability discovery and active exploitation is now down to minutes. When automated attacks move at machine speed, static posture scans and periodic patch cycles cannot keep pace. Security teams end up trapped in an impossible operational loop: managing an endless queue of configuration alerts while active incidents slip through the noise. This session looks at how cloud defense changes when teams prioritize real-time kernel behavior over static inventory reports. Participants will examine how runtime visibility isolates active compromises from background noise, and explore strategies for using automated containment workflows to stop lateral movement inside containerized environments before an initial entry becomes a major breach.
Cloud environments generate massive volumes of log data, but more data rarely translates to better visibility. Security operations teams routinely ingest millions of cloud events daily, only to spend hours manually correlating disjointed API calls, IAM events, and network traces during an investigation. The result is bloated SIEM costs and missed signals buried under false positives. This workshop focuses on restructuring how teams ingest and analyze cloud telemetry. Participants will walk through practical methods for mapping raw log data directly to known adversary tactics, separating normal cloud operations from actual threat activity, and filtering out telemetry noise before it overwhelms analysts or inflates storage budgets.
For years, the security industry has sold us a simple equation: more tools equal more coverage. But in practice, bloated stacks don't just drain budgets, but they also create blind spots. When analysts spend too much time jumping between tools and ignoring false alarms, they miss the real threats. This workshop rejects the myth that stacking more tools means stronger security. We’ll explore how leading AppSec teams are reversing course and shedding redundant point solutions in favor of intentional, integrated architectures. You won't just hear theory. You'll leave ready to audit your own stack and define what real security looks like for your team.
Practitioner To Be Announced
Practitioner To Be Announced
Security leaders face mounting pressure from boards and executive teams to quantify cyber risk in financial and operational terms. Technical metrics like patch latency and alert volume fail to communicate actual business exposure, leaving executive leadership detached from strategic security decisions. This session focuses on bridging the gap between technical operations and executive governance. Attendees will work through actionable models for mapping security risks directly to business continuity, regulatory compliance, and financial liability, enabling CISOs to secure necessary budgets and align security investments with enterprise goals.
Years of point-solution acquisition have left enterprise security teams managing dozens of disconnected consoles, overlapping feature sets, and escalating licensing costs. This operational sprawl bloats operating budgets while creating critical visibility gaps between tools. This interactive workshop evaluates practical frameworks for auditing the enterprise security stack, identifying redundant security controls, and streamlining architecture into unified platforms. Participants will discuss strategies for cutting operational overhead, simplifying analyst workflows, and maintaining strong defense posturing during vendor rationalization.
As enterprises deploy autonomous software agents and automated service accounts, non-human identities now vastly outnumber human employees inside corporate networks. Traditional identity and access management frameworks built around human credentials fail to track the speed, lifecycle, and permissions required by machine-to-machine interactions. This workshop explores how CISOs are extending zero trust architectures to non-human actors. Attendees will examine practical approaches for auditing service accounts, implementing dynamic privilege boundaries, and maintaining continuous governance over automated internal processes.
Practitioner To Be Announced
Practitioner To Be Announced
Are you a member of The CISO Society?