[1 CPE] Attackers Aren’t Breaking In, They’re Logging In

  Presented by Jenna Barry, Product Marketing Manager • CyberFOX

Access is the attack surface. Every security framework comes back to the same four fundamental access controls: privilege, credentials, network, and destinations. The problem is that these controls were designed for organizations with dedicated security teams, while lean IT teams are left to operate them with limited time, people, and resources.

This session breaks down what access actually looks like in practice: what a single credential can reach, why AI agents can inherit the same permissions you have, and why proving who had access matters more than simply describing your controls.

[1 CPE] The 2026 AI SOC Leadership Report: What Security Leaders Really Want

  Presented by Torq

Torq surveyed 450 SOC leaders globally to find out what AI is actually doing inside the SOC. The findings challenged some assumptions — and confirmed others.

We’ll dig into insights including:

  • Why 97% of security leaders are confident AI can handle triage, but only 35% are using it there
  • What’s behind the trust barrier that 92% of leaders say is holding AI back
  • What 85% of leaders mean when they say they want a “unified platform”
  • Where teams plan to expand AI over the next 12 months — and what’s standing in their way

[1 CPE] Keep Your Eye on the Lady (AI): Securing and Governing AI Systems

  Presented by Marc Cressall, CISSP, President • ISC2 Salt Lake City

In a three-card monte game, the audience watches the lady (the card) and misses the move (the sleight of hand). The same thing is happening in AI security right now: teams are fixated on what the AI can do — the capability, the demo, the agent — while the real attack surface happens in the move: the data it’s trained on, the prompts it trusts, the permissions it holds, the outputs it’s allowed to act on.

What we cover:

  • Why “AI security theater” is the new compliance theater — green dashboards, checkbox governance, and visible controls that don’t stop real risk
  • The three-card monte of AI: misdirection (watching the model), sleight of hand (unexamined agent permissions), audience management (performing for auditors), and the illusion of safety (false confidence from visible measures)
  • A live demonstration of the misdirection — watch the capability, miss the attack surface
  • The “Reclaim Reality” framework applied to AI: shift from compliance to capability, eliminate performative friction, foster a no-fault transparency culture, and measure reality (detection/response time, actual coverage) instead of appearance

Takeaways attendees walk away with:

  • A framework to spot AI security theater in their own programs
  • A Monday-morning checklist to audit their AI/agent attack surface
  • A practical path from checkbox governance to real AI security capability

[1 CPE] How to Not Suck at Cybersecurity… in the Age of AI

  Presented by Vincent Romney • Deputy Chief Information Security Officer, Nu Skin & Pharmanex

AI isn’t fixing cybersecurity. It’s accelerating it… for good or bad. In this keynote, Vincent Romney, author of How to Not Suck at Cybersecurity, breaks down why organizations continue to struggle with the same core security problems, and how AI is about to make those problems happen faster, at scale. Blending real-world experience, practical guidance, and a healthy dose of snark, Vincent cuts through the hype around AI to show where it actually helps, where it fails, and where it can quietly create new risks. You’ll leave with a clearer understanding of how to strengthen your fundamentals, use AI without losing control, and avoid the uncomfortable truth: if your security already sucks… AI helps you suck faster.

Vincent Romney is a cybersecurity executive, author, and “snark-fueled” advocate for doing security right. As Deputy CISO at Nu Skin Enterprises, he has spent over two decades designing and leading security programs across cloud, application, and enterprise environments, including building AI governance and threat modeling frameworks in complex global organizations.

A former Air Force cyber warfare specialist, Vincent combines real-world offensive and defensive experience with a practical approach to security leadership. He is the author of How to Not Suck at Cybersecurity, where he breaks down security fundamentals into clear, actionable steps that scale from individuals to enterprise environments. His speaking style blends technical depth, real-world examples, and humor to help audiences cut through hype, focus on what actually matters, and avoid making expensive mistakes.

[1 CPE] The People Behind the Threats and Trends: Observations from the Front Lines

  Presented by Peter Ingebrigtsen, Sr Technical Marketing Manager US • Arctic Wolf

Cybersecurity threats are shaped and stopped by the people on the front lines. This session explores how Arctic Wolf Labs research and SOC expertise uncover emerging threat patterns, contextualize real-world attacks, and turn raw telemetry into actionable defense –– showing how human-driven security operations deliver scalable protection in an evolving threat landscape.

[1 CPE] Retaining Your IT Staff: A Panel Discussion on What Works

  Presented by INTERFACE Advisory Council

Many IT professionals will bounce around from different positions for salary increases that may not be as beneficial as they seem. With a robust IT industry in northern Utah, there is not a shortage of opportunities. This makes it a real challenge to maintain your current staff. Are there methods available to hold on to IT talent, even when a salary can’t be matched? How can the IT staffer make the right decisions and not create unforeseen career challenges?

Join the INTERFACE Advisory Council for an open discussion on IT staffing challenges. Hear from peers who have experience recruiting, retaining, and developing IT talent, as well as managing teams through staffing shortages and changing workforce expectations.

We’ll explore practical strategies for identifying and cultivating local tech talent, developing existing employees, and building stronger IT teams from within. Join us for an open and practical conversation about real solutions to Salt Lake City IT workforce challenges.

Panelists:

  • James Duckett, Assistant Operations Director, Technology Division, City of St. George
  • Dan Harmuth, Chief Information Officer, Rocky Mountain University of Health Professions
  • Greg Pugh, Manager, COMSEC, Space Dynamics Laboratory
  • Dan Sitton, Chief Information Officer, CC Bank

Advisory Council Roundtables

Join us during the lunch hour for Advisory Council Roundtables, an interactive opportunity to connect with council members and peers on a variety of timely industry topics. Move freely between tables, share your perspective, and gather practical insights you can take back to your organization. These conversations are informal, high-value, and designed to spark ideas and connection.

Topics & Discussion Leaders:

  • Data Protection in the Age of AI Tyler Tholen, Director, Cybersecurity, Honeywell
  • Ensuring Security and Compliance with AI Pon Vorasane, Director, Technology and Innovation, CCBank
  • Get More Out of Your IT Spending Dan Sitton, Chief Information Officer, CCBank
  • IT Staffing: Onboarding for Success George Sturua, Corporate IT Manager, KÜHL Clothing Company
  • Security Awareness: What Methods Work to “Secure the Human”
    • Mary Huth, Manager, Technology Audit & Cyber Risk, Mountain America Credit Union
    • Danny Yeo, Information Technology Director, Brigham Young University

[1 CPE] AI Changes Everything

  Presented by Jesse Johnson, System Engineer • Fortinet

AI, data sovereignty, and identity are reshaping how organizations think about security. This panel discussion explores how to protect emerging AI workloads, maintain control of sensitive data, and provide secure access from anywhere.

[1 CPE] State of the Union: Annual Information Security Report

  Presented by Chad Spoden, Sr Information Security Consultant, Solution Architect Manager • FRSecure

The result of over 100 incident cases handled by the FRSecure response team in the last two years, Sr Information Security Consultant Chad Spoden will dive into the latest threats and response techniques you need to know—and what you can do to minimize the risk and impact of similar events. The breakdown will cover Business Email Compromise, Ransomware, and Internal Compromise. You can’t afford to miss it!

[1 CPE] Proving Cyber Resilience: Measuring Outcomes, Not Effort

  Presented by Jake Mickley, Sr Solutions Architect • Horizon3

Most security programs measure effort — not outcomes. Organizations patch thousands of vulnerabilities, deploy dozens of tools, and run annual tabletop exercises… but when an attacker shows up, none of that matters.

What matters is whether they can prove their defenses actually work.

In this talk, Horizon3 shares how leading organizations are using autonomous pentesting to see their environment through the attacker’s eyes — continuously, safely, and at scale. By shifting from assumptions to proof, they’ve learned to:

  • Prioritize what’s exploitable. Focus limited resources on the weaknesses that truly put the business at risk that are known to be abused by threat actors.
  • Quickly fix what matters. Close the loop from find → fix → verify and reduce your exploitable attack surface.
  • Reduce attacker dwell time. Use pentest results to precisely deploy honeyTokens to detect compromise early, and to continuously prove your EDR and SIEM are tuned and working as intended.

Cyber resilience isn’t about being perfect — it’s about getting better over time. And the only perspective that truly matters is the attacker’s.