[1 CPE] Proving Cyber Resilience: Measuring Outcomes, Not Effort

  Presented by Andy Rezabek, Sales Engineer • Horizon3

Most security programs measure effort — not outcomes. Organizations patch thousands of vulnerabilities, deploy dozens of tools, and run annual tabletop exercises… but when an attacker shows up, none of that matters.

What matters is whether they can prove their defenses actually work.

In this talk, Horizon3 shares how leading organizations are using autonomous pentesting to see their environment through the attacker’s eyes — continuously, safely, and at scale. By shifting from assumptions to proof, they’ve learned to:

  • Prioritize what’s exploitable. Focus limited resources on the weaknesses that truly put the business at risk that are known to be abused by threat actors.
  • Quickly fix what matters. Close the loop from find → fix → verify and reduce your exploitable attack surface.
  • Reduce attacker dwell time. Use pentest results to precisely deploy honeyTokens to detect compromise early, and to continuously prove your EDR and SIEM are tuned and working as intended.

Cyber resilience isn’t about being perfect — it’s about getting better over time. And the only perspective that truly matters is the attacker’s.

[1 CPE] Beyond the Box: Rethinking IT Deployment at Scale

  Presented by Samer Kandah, Sr Solutions Architect • C1

Organizations spend significant time evaluating and purchasing new technology, but the success of a modernization initiative often depends on what happens after the equipment arrives. Configuration, asset tracking, staging, logistics, and deployment can quickly become operational bottlenecks at scale. This session will explore how IT organizations can rethink technology deployment as a repeatable and scalable lifecycle. We’ll look at strategies for centralizing configuration and staging, improving asset visibility, reducing the amount of work required onsite, and creating more consistent deployment outcomes. We’ll also discuss how automation, zero-touch provisioning, and emerging AI capabilities can improve these processes and help organizations get technology into the hands of their users faster and with less disruption to their internal IT teams.

[1 CPE] Why Layered Identity Defense Is the Best Offense

  Presented by Sean Deuby, Principal Technologist, Americas • Semperis

Cyberattackers are adept at finding ways through your defenses and into identity systems like Active Directory, Entra ID, and Okta, and endpoint defenses won’t stop them. From there, they can move laterally, escalate privileges, access sensitive data and resources, and inject malware or ransomware.

AI has supercharged these attacks through automation and making it easy for unsophisticated actors to execute sophisticated attacks. One consistent lesson has come from experiences with frontier AI models and agents: identity protection has become even more important than it already was.

Implementing a layered defense that includes identity threat detection and response (ITDR) and robust identity recovery is key to true cyber resilience.

Advisory Council Roundtables

Join us during the lunch hour for Advisory Council Roundtables, an interactive opportunity to connect with council members and peers on a variety of timely industry topics. Move freely between tables, share your perspective, and gather practical insights you can take back to your organization. These conversations are informal, high-value, and designed to spark ideas and connection.

Topics:

  • Data Protection in the Age of AI
  • Ensuring Security and Compliance with 3rd Parties
  • IT Staffing: Onboarding for Success
  • Get More Out of Your IT Spending
  • Managing Infosec for the Small/Medium Business
  • Security Approach in Public Sector
  • Security Awareness: What Methods Work to “Secure the Human”
  • Zero Trust Strategy: Challenges & Lessons Learned

[1 CPE] AI Changes Everything

  Presented by Michael Lippman, Regional Channel Systems Engineer • Fortinet

AI, data sovereignty, and identity are reshaping how organizations think about security. This panel discussion explores how to protect emerging AI workloads, maintain control of sensitive data, and provide secure access from anywhere.

[1 CPE] State of the Union: Annual Information Security Report

  Presented by Chad Spoden, Sr Information Security Consultant, Solution Architect Manager • FRSecure

The result of over 100 incident cases handled by the FRSecure response team in the last two years, Sr Information Security Consultant Chad Spoden will dive into the latest threats and response techniques you need to know—and what you can do to minimize the risk and impact of similar events. The breakdown will cover Business Email Compromise, Ransomware, and Internal Compromise. You can’t afford to miss it!

[1 CPE] The New AI Era in Cybersecurity: What it Means for Your Organization

  Presented by Jesus Lopez, Sales Engineer • ESET

This session explores how artificial intelligence is reshaping the modern cyber threat landscape by empowering both attackers and defenders. It examines how adversaries use AI to scale attacks, evade detection, and increase their effectiveness. The presentation also highlights how organizations can leverage AI to build proactive, adaptive defenses that detect and respond to threats more efficiently. Finally, it showcases how ESET applies AI-driven technologies to protect against evolving cyber-attacks and strengthen overall security resilience.

[1 CPE] Agents Inherit Your Debt: Governing AI Agents Against the Risks Security Tools Won’t Catch

  Presented by Dr. Ken Knapton

Agentic AI introduces new risks into your enterprise, some of which won’t be detected by security tools and controls. For example, there isn’t a patch for indirect prompt injection – it is an authority that is granted to the agent. This session covers how the attack chain works, why your existing stack stays quiet through all five steps, and a six-rule governance model (mapped to ISO/IEC 42001) that bounds what an agent may read, do, and send.

We will also discuss the data debt and tech debt that your agents inherit. Duplicated data, systems you never retired, and years of unrevoked access all become executable at machine speed. You’ll leave with a 90-day plan that requires decisions rather than budget.

Dr. Ken Knapton is a veteran CIO, CISO, author, and educator with deep experience leading technology, cybersecurity, and data strategy in complex organizations. A seven-time CIO, he has guided businesses through operational risk, cyber risk, and the challenges that come with emerging technologies. He holds a doctorate in big data governance, advanced degrees in strategic IT leadership and business administration, and maintains CISSP and C|CISO certifications. In addition to his executive leadership work, he serves as an analyst and adjunct research advisor for IDC’s IT Executive Programs and teaches graduate cybersecurity courses. As the author of Unveiling Tech Debt and Cyber Safety, Dr. Knapton is known for translating technical risk into practical leadership action, with a particular focus on AI, governance, and the safe adoption of technology in the workplace.