[1 CPE] Proving Cyber Resilience: Measuring Outcomes, Not Effort

  Presented by Andy Rezabek, Sales Engineer • Horizon3

Most security programs measure effort — not outcomes. Organizations patch thousands of vulnerabilities, deploy dozens of tools, and run annual tabletop exercises… but when an attacker shows up, none of that matters.

What matters is whether they can prove their defenses actually work.

In this talk, Horizon3 shares how leading organizations are using autonomous pentesting to see their environment through the attacker’s eyes — continuously, safely, and at scale. By shifting from assumptions to proof, they’ve learned to:

  • Prioritize what’s exploitable. Focus limited resources on the weaknesses that truly put the business at risk that are known to be abused by threat actors.
  • Quickly fix what matters. Close the loop from find → fix → verify and reduce your exploitable attack surface.
  • Reduce attacker dwell time. Use pentest results to precisely deploy honeyTokens to detect compromise early, and to continuously prove your EDR and SIEM are tuned and working as intended.

Cyber resilience isn’t about being perfect — it’s about getting better over time. And the only perspective that truly matters is the attacker’s.

[1 CPE] State of the Union: Annual Information Security Report

  Presented by Chad Spoden, Sr Information Security Consultant, Solution Architect Manager • FRSecure

The result of over 100 incident cases handled by the FRSecure response team in the last two years, Sr Information Security Consultant Chad Spoden will dive into the latest threats and response techniques you need to know—and what you can do to minimize the risk and impact of similar events. The breakdown will cover Business Email Compromise, Ransomware, and Internal Compromise. You can’t afford to miss it!

[1 CPE] AI Changes Everything

  Presented by Michael Lippman, Regional Channel Systems Engineer • Fortinet

AI, data sovereignty, and identity are reshaping how organizations think about security. This panel discussion explores how to protect emerging AI workloads, maintain control of sensitive data, and provide secure access from anywhere.

[1 CPE] The People Behind the Threats and Trends: Observations from the Front Lines

  Presented by Peter Ingebrigtsen, Sr Technical Marketing Manager US • Arctic Wolf

Cybersecurity threats are shaped and stopped by the people on the front lines. This session explores how Arctic Wolf Labs research and SOC expertise uncover emerging threat patterns, contextualize real-world attacks, and turn raw telemetry into actionable defense –– showing how human-driven security operations deliver scalable protection in an evolving threat landscape.

[1 CPE] How to Not Suck at Cybersecurity… in the Age of AI

  Presented by Vincent Romney • Deputy Chief Information Security Officer, Nu Skin & Pharmanex

AI isn’t fixing cybersecurity. It’s accelerating it… for good or bad. In this keynote, Vincent Romney, author of How to Not Suck at Cybersecurity, breaks down why organizations continue to struggle with the same core security problems, and how AI is about to make those problems happen faster, at scale. Blending real-world experience, practical guidance, and a healthy dose of snark, Vincent cuts through the hype around AI to show where it actually helps, where it fails, and where it can quietly create new risks. You’ll leave with a clearer understanding of how to strengthen your fundamentals, use AI without losing control, and avoid the uncomfortable truth: if your security already sucks… AI helps you suck faster.

Vincent Romney is a cybersecurity executive, author, and “snark-fueled” advocate for doing security right. As Deputy CISO at Nu Skin Enterprises, he has spent over two decades designing and leading security programs across cloud, application, and enterprise environments, including building AI governance and threat modeling frameworks in complex global organizations.

A former Air Force cyber warfare specialist, Vincent combines real-world offensive and defensive experience with a practical approach to security leadership. He is the author of How to Not Suck at Cybersecurity, where he breaks down security fundamentals into clear, actionable steps that scale from individuals to enterprise environments. His speaking style blends technical depth, real-world examples, and humor to help audiences cut through hype, focus on what actually matters, and avoid making expensive mistakes.

[1 CPE] The 2026 AI SOC Leadership Report: What Security Leaders Really Want

  Presented by Torq

Torq surveyed 450 SOC leaders globally to find out what AI is actually doing inside the SOC. The findings challenged some assumptions — and confirmed others.

We’ll dig into insights including:

  • Why 97% of security leaders are confident AI can handle triage, but only 35% are using it there
  • What’s behind the trust barrier that 92% of leaders say is holding AI back
  • What 85% of leaders mean when they say they want a “unified platform”
  • Where teams plan to expand AI over the next 12 months — and what’s standing in their way

[1 CPE] AI Agents Have More Access Than Employees: Discovery, Enforcement, and Audit Evidence

  Presented by Chris Hoesly, Field CTO and Craig Pfister, Vice President, Sales Engineering • BigID & Kiteworks

An AI agent is authenticated once, on a service account with broad read access. Six months later it surfaces one patient’s data in another patient’s file. That failure is ordinary: 64% of organizations running AI in production had an AI-related security incident this year. Most place no limits on what data their agents can reach, and two-thirds of AI use runs through non-corporate accounts on corporate devices. When these breaches are investigated, the failure is rarely the model — it is the access around it. This session covers discovery, classification, per-request enforcement, and the evidence auditors now ask for.

[1 CPE] 30 Years of Security Assumptions Broke: Rethinking Security Controls in the Age of AI

  Presented by Rob Larsen, Advisor • Silverfort

Frontier AI has quietly retired a three-decade assumption: that defenders have time to react after an attacker moves. Autonomous models now compress full attack chains into minutes, chaining ordinary misconfigurations at machine speed with no hesitation and no fatigue. Detection becomes forensic instead of preventive. Vulnerability management can’t patch fast enough. Periodic access reviews can’t review fast enough.

The answer requires a fundamental shift: from preset admin-time access rules and too-reactive detection to controls placed at the moment it matters most: runtime. Every identity, human, machine, or AI agent, must authenticate to act. That moment is the only control point capable of operating at machine speed, intervening before lateral movement begins.

This session gives security leaders the framework to drive that shift — examining why traditional controls collapse against AI-powered adversaries, what runtime enforcement looks like in practice, and how to elevate identity to a genuine, autonomous enforcement point at the center of a modern security operating model.

[1 CPE] Proving Cyber Resilience: Measuring Outcomes, Not Effort

  Presented by Andy Rezabek, Sales Engineer • Horizon3

Most security programs measure effort — not outcomes. Organizations patch thousands of vulnerabilities, deploy dozens of tools, and run annual tabletop exercises… but when an attacker shows up, none of that matters.

What matters is whether they can prove their defenses actually work.

In this talk, Horizon3 shares how leading organizations are using autonomous pentesting to see their environment through the attacker’s eyes — continuously, safely, and at scale. By shifting from assumptions to proof, they’ve learned to:

  • Prioritize what’s exploitable. Focus limited resources on the weaknesses that truly put the business at risk that are known to be abused by threat actors.
  • Quickly fix what matters. Close the loop from find → fix → verify and reduce your exploitable attack surface.
  • Reduce attacker dwell time. Use pentest results to precisely deploy honeyTokens to detect compromise early, and to continuously prove your EDR and SIEM are tuned and working as intended.

Cyber resilience isn’t about being perfect — it’s about getting better over time. And the only perspective that truly matters is the attacker’s.

[1 CPE] 2026 Global Threat Landscape Report: Insights & Findings

  Presented by Eric Teece, Director, Systems Engineering • Fortinet

In 2026, the threat landscape cannot be accurately described through isolated indicators or single-domain trends. Adversaries operate across an end-to-end lifecycle that begins well before intrusion through exposure discovery, access brokerage, and industrialized preparation, and continues through exploitation, persistence, monetization, and operational impact.

Across exposure, exploitation, execution, and impact, the common variable is not just attacker sophistication. It is speed and reuse.

Come and learn our findings in exposure, weaponization, exploitation, post-exploitation, impact, cross-threat convergence, execution model, and cloud.