Presented by Marc Cressall, CISSP, President • ISC2 Salt Lake City
In a three-card monte game, the audience watches the lady (the card) and misses the move (the sleight of hand). The same thing is happening in AI security right now: teams are fixated on what the AI can do — the capability, the demo, the agent — while the real attack surface happens in the move: the data it's trained on, the prompts it trusts, the permissions it holds, the outputs it's allowed to act on.
What we cover:
- Why "AI security theater" is the new compliance theater — green dashboards, checkbox governance, and visible controls that don't stop real risk
- The three-card monte of AI: misdirection (watching the model), sleight of hand (unexamined agent permissions), audience management (performing for auditors), and the illusion of safety (false confidence from visible measures)
- A live demonstration of the misdirection — watch the capability, miss the attack surface
- The "Reclaim Reality" framework applied to AI: shift from compliance to capability, eliminate performative friction, foster a no-fault transparency culture, and measure reality (detection/response time, actual coverage) instead of appearance
Takeaways attendees walk away with:
- A framework to spot AI security theater in their own programs
- A Monday-morning checklist to audit their AI/agent attack surface
- A practical path from checkbox governance to real AI security capability