[1 CPE] Securing the AI Era: Protecting Your Organization from the Latest AI Threats

  Presented by Ryan Dennison, Inside Channel Account Manager • ESET

Artificial Intelligence is transforming the way organizations operate, but it is also creating new opportunities for cybercriminals. From AI-powered phishing and deepfake impersonation attacks to advanced malware and automated social engineering, businesses face an evolving threat landscape that demands next-generation protection.

In this session, we’ll discuss innovative security capabilities designed to safeguard users, devices, and data. Attendees will get an exclusive look at the newest AI-powered security enhancements launching this month. Join us to discover how your organization can embrace AI with confidence while staying protected against the threats of tomorrow.

[1 CPE] Agents Inherit Your Debt: Governing AI Agents Against the Risks Security Tools Won’t Catch

  Presented by Dr. Ken Knapton

Agentic AI introduces new risks into your enterprise, some of which won’t be detected by security tools and controls. For example, there isn’t a patch for indirect prompt injection – it is an authority that is granted to the agent. This session covers how the attack chain works, why your existing stack stays quiet through all five steps, and a six-rule governance model (mapped to ISO/IEC 42001) that bounds what an agent may read, do, and send.

We will also discuss the data debt and tech debt that your agents inherit. Duplicated data, systems you never retired, and years of unrevoked access all become executable at machine speed. You’ll leave with a 90-day plan that requires decisions rather than budget.

Dr. Ken Knapton is a veteran CIO, CISO, author, and educator with deep experience leading technology, cybersecurity, and data strategy in complex organizations. A seven-time CIO, he has guided businesses through operational risk, cyber risk, and the challenges that come with emerging technologies. He holds a doctorate in big data governance, advanced degrees in strategic IT leadership and business administration, and maintains CISSP and C|CISO certifications. In addition to his executive leadership work, he serves as an analyst and adjunct research advisor for IDC’s IT Executive Programs and teaches graduate cybersecurity courses. As the author of Unveiling Tech Debt and Cyber Safety, Dr. Knapton is known for translating technical risk into practical leadership action, with a particular focus on AI, governance, and the safe adoption of technology in the workplace.

[1 CPE] Keep Your Eye on the Lady (AI): Securing and Governing AI Systems

  Presented by Marc Cressall, CISSP, President • ISC2 Salt Lake City

In a three-card monte game, the audience watches the lady (the card) and misses the move (the sleight of hand). The same thing is happening in AI security right now: teams are fixated on what the AI can do — the capability, the demo, the agent — while the real attack surface happens in the move: the data it’s trained on, the prompts it trusts, the permissions it holds, the outputs it’s allowed to act on.

What we cover:

  • Why “AI security theater” is the new compliance theater — green dashboards, checkbox governance, and visible controls that don’t stop real risk
  • The three-card monte of AI: misdirection (watching the model), sleight of hand (unexamined agent permissions), audience management (performing for auditors), and the illusion of safety (false confidence from visible measures)
  • A live demonstration of the misdirection — watch the capability, miss the attack surface
  • The “Reclaim Reality” framework applied to AI: shift from compliance to capability, eliminate performative friction, foster a no-fault transparency culture, and measure reality (detection/response time, actual coverage) instead of appearance

Takeaways attendees walk away with:

  • A framework to spot AI security theater in their own programs
  • A Monday-morning checklist to audit their AI/agent attack surface
  • A practical path from checkbox governance to real AI security capability

[1 CPE] Attackers Aren’t Breaking In, They’re Logging In

  Presented by Jenna Barry, Product Marketing Manager • CyberFOX

Access is the attack surface. Every security framework comes back to the same four fundamental access controls: privilege, credentials, network, and destinations. The problem is that these controls were designed for organizations with dedicated security teams, while lean IT teams are left to operate them with limited time, people, and resources.

This session breaks down what access actually looks like in practice: what a single credential can reach, why AI agents can inherit the same permissions you have, and why proving who had access matters more than simply describing your controls.

[1 CPE] How to Not Suck at Cybersecurity… in the Age of AI

  Presented by Vincent Romney • Deputy Chief Information Security Officer, Nu Skin & Pharmanex

AI isn’t fixing cybersecurity. It’s accelerating it… for good or bad. In this keynote, Vincent Romney, author of How to Not Suck at Cybersecurity, breaks down why organizations continue to struggle with the same core security problems, and how AI is about to make those problems happen faster, at scale. Blending real-world experience, practical guidance, and a healthy dose of snark, Vincent cuts through the hype around AI to show where it actually helps, where it fails, and where it can quietly create new risks. You’ll leave with a clearer understanding of how to strengthen your fundamentals, use AI without losing control, and avoid the uncomfortable truth: if your security already sucks… AI helps you suck faster.

Vincent Romney is a cybersecurity executive, author, and “snark-fueled” advocate for doing security right. As Deputy CISO at Nu Skin Enterprises, he has spent over two decades designing and leading security programs across cloud, application, and enterprise environments, including building AI governance and threat modeling frameworks in complex global organizations.

A former Air Force cyber warfare specialist, Vincent combines real-world offensive and defensive experience with a practical approach to security leadership. He is the author of How to Not Suck at Cybersecurity, where he breaks down security fundamentals into clear, actionable steps that scale from individuals to enterprise environments. His speaking style blends technical depth, real-world examples, and humor to help audiences cut through hype, focus on what actually matters, and avoid making expensive mistakes.

[1 CPE] The 2026 AI SOC Leadership Report: What Security Leaders Really Want

  Presented by Matthew Michaels, Account Executive • Torq

Torq surveyed 450 SOC leaders globally to find out what AI is actually doing inside the SOC. The findings challenged some assumptions — and confirmed others.

We’ll dig into insights including:

  • Why 97% of security leaders are confident AI can handle triage, but only 35% are using it there
  • What’s behind the trust barrier that 92% of leaders say is holding AI back
  • What 85% of leaders mean when they say they want a “unified platform”
  • Where teams plan to expand AI over the next 12 months — and what’s standing in their way

[1 CPE] 30 Years of Applied AI Learnings: Building Secure Enterprise Architecture

  Presented by Greg Hatch, Sr Vice President, Strategic Growth • Gage Technologies

Moving from AI hype to predictable production value requires an infrastructure designed for performance, accountability, From AI hype to predictable production value requires an infrastructure designed for performance, accountability, manageability, and security. This technical session distills 30 years of applied AI experience into a structural roadmap. Learn how to orchestrate next-generation agentic AI and predictive workflows without compromising enterprise safety, data sovereignty, or network performance.

[1 CPE] 30 Years of Security Assumptions Broke: Rethinking Security Controls in the Age of AI

  Presented by Rob Larsen, Advisor • Silverfort

Frontier AI has quietly retired a three-decade assumption: that defenders have time to react after an attacker moves. Autonomous models now compress full attack chains into minutes, chaining ordinary misconfigurations at machine speed with no hesitation and no fatigue. Detection becomes forensic instead of preventive. Vulnerability management can’t patch fast enough. Periodic access reviews can’t review fast enough.

The answer requires a fundamental shift: from preset admin-time access rules and too-reactive detection to controls placed at the moment it matters most: runtime. Every identity, human, machine, or AI agent, must authenticate to act. That moment is the only control point capable of operating at machine speed, intervening before lateral movement begins.

This session gives security leaders the framework to drive that shift — examining why traditional controls collapse against AI-powered adversaries, what runtime enforcement looks like in practice, and how to elevate identity to a genuine, autonomous enforcement point at the center of a modern security operating model.

[1 CPE] AI Agents Have More Access Than Employees: Discovery, Enforcement, and Audit Evidence

  Presented by Chris Hoesly, Field CTO and Craig Pfister, Vice President, Sales Engineering • BigID & Kiteworks

An AI agent is authenticated once, on a service account with broad read access. Six months later it surfaces one patient’s data in another patient’s file. That failure is ordinary: 64% of organizations running AI in production had an AI-related security incident this year. Most place no limits on what data their agents can reach, and two-thirds of AI use runs through non-corporate accounts on corporate devices. When these breaches are investigated, the failure is rarely the model — it is the access around it. This session covers discovery, classification, per-request enforcement, and the evidence auditors now ask for.

[1 CPE] Will AI Take Your Job? One Year Later: How Accurate were the Predictions?

  Presented by Joe Skeen, Solutions Architect • CompuNet

One year later, let’s look back at the wildest predictions that gripped our industry and see how accurate they actually were. This session cuts through the initial panic to examine what the doomsayers got right, where they missed the mark, and how core business disciplines are transforming on the ground. Built for the operational realities of 2026 and looking ahead into 2027, this presentation delivers a practical playbook to help you stop worrying about the algorithm and start directing it.