[1 CPE] Why Layered Identity Defense Is the Best Offense

  Presented by Sean Deuby, Principal Technologist, Americas • Semperis

Cyberattackers are adept at finding ways through your defenses and into identity systems like Active Directory, Entra ID, and Okta, and endpoint defenses won’t stop them. From there, they can move laterally, escalate privileges, access sensitive data and resources, and inject malware or ransomware.

AI has supercharged these attacks through automation and making it easy for unsophisticated actors to execute sophisticated attacks. One consistent lesson has come from experiences with frontier AI models and agents: identity protection has become even more important than it already was.

Implementing a layered defense that includes identity threat detection and response (ITDR) and robust identity recovery is key to true cyber resilience.

[1 CPE] Empower AI with Security by Design

  Presented by Palo Alto Networks

As AI rapidly transitions from experimental chat tools to the backbone of enterprise software, organizations face a critical turning point in securing their modern application stack. You’re invited to this exclusive workshop, “”Empower AI with Security by Design,”” to safely accelerate AI adoption without exposing sensitive data. In this session, we demonstrate how embedding real-time guardrails directly into the AI lifecycle enables teams to innovate at machine speed without increasing their attack surface.

Participants will gain actionable insights into our comprehensive approach to securing custom AI applications and enterprise usage – Powered by Precision AI™. Whether your teams use AI code assistants, build custom agentic applications, or govern employee access to public tools, this session delivers the definitive framework to address your AI strategy.

[1 CPE] Building Trust for What’s Next: PKI Modernization & Quantum Readiness

  Presented by Doug Knight, RVP, Solutions Engineer • DigiCert

Certificate lifetimes are shrinking. Browser requirements are evolving. Machine identities are growing exponentially. At the same time, organizations are beginning to plan for post-quantum cryptography while supporting new AI-driven systems that depend on trusted digital interactions.

These changes are transforming PKI from a traditional security function into the operational trust layer for modern business.

This session provides a practical roadmap for modernizing PKI, improving visibility into machine identities, automating certificate lifecycle management, and building crypto-agility for future cryptographic transitions. Attendees will leave with actionable steps to reduce operational risk today while preparing for post-quantum security and the next generation of digital trust.

[1 CPE] Proving Cyber Resilience: Measuring Outcomes, Not Effort

  Presented by Andy Rezabek, Sales Engineer • Horizon3

Most security programs measure effort — not outcomes. Organizations patch thousands of vulnerabilities, deploy dozens of tools, and run annual tabletop exercises… but when an attacker shows up, none of that matters.

What matters is whether they can prove their defenses actually work.

In this talk, Horizon3 shares how leading organizations are using autonomous pentesting to see their environment through the attacker’s eyes — continuously, safely, and at scale. By shifting from assumptions to proof, they’ve learned to:

  • Prioritize what’s exploitable. Focus limited resources on the weaknesses that truly put the business at risk that are known to be abused by threat actors.
  • Quickly fix what matters. Close the loop from find → fix → verify and reduce your exploitable attack surface.
  • Reduce attacker dwell time. Use pentest results to precisely deploy honeyTokens to detect compromise early, and to continuously prove your EDR and SIEM are tuned and working as intended.

Cyber resilience isn’t about being perfect — it’s about getting better over time. And the only perspective that truly matters is the attacker’s.

[1 CPE] Securing the AI Era: Protecting Your Organization from the Latest AI Threats

  Presented by Ryan Dennison, Inside Channel Account Manager • ESET

Artificial Intelligence is transforming the way organizations operate, but it is also creating new opportunities for cybercriminals. From AI-powered phishing and deepfake impersonation attacks to advanced malware and automated social engineering, businesses face an evolving threat landscape that demands next-generation protection.

In this session, we’ll discuss innovative security capabilities designed to safeguard users, devices, and data. Attendees will get an exclusive look at the newest AI-powered security enhancements launching this month. Join us to discover how your organization can embrace AI with confidence while staying protected against the threats of tomorrow.

[1 CPE] Keep Your Eye on the Lady (AI): Securing and Governing AI Systems

  Presented by Marc Cressall, CISSP, President • ISC2 Salt Lake City

In a three-card monte game, the audience watches the lady (the card) and misses the move (the sleight of hand). The same thing is happening in AI security right now: teams are fixated on what the AI can do — the capability, the demo, the agent — while the real attack surface happens in the move: the data it’s trained on, the prompts it trusts, the permissions it holds, the outputs it’s allowed to act on.

What we cover:

  • Why “AI security theater” is the new compliance theater — green dashboards, checkbox governance, and visible controls that don’t stop real risk
  • The three-card monte of AI: misdirection (watching the model), sleight of hand (unexamined agent permissions), audience management (performing for auditors), and the illusion of safety (false confidence from visible measures)
  • A live demonstration of the misdirection — watch the capability, miss the attack surface
  • The “Reclaim Reality” framework applied to AI: shift from compliance to capability, eliminate performative friction, foster a no-fault transparency culture, and measure reality (detection/response time, actual coverage) instead of appearance

Takeaways attendees walk away with:

  • A framework to spot AI security theater in their own programs
  • A Monday-morning checklist to audit their AI/agent attack surface
  • A practical path from checkbox governance to real AI security capability

[1 CPE] Attackers Aren’t Breaking In, They’re Logging In

  Presented by Jenna Barry, Product Marketing Manager • CyberFOX

Access is the attack surface. Every security framework comes back to the same four fundamental access controls: privilege, credentials, network, and destinations. The problem is that these controls were designed for organizations with dedicated security teams, while lean IT teams are left to operate them with limited time, people, and resources.

This session breaks down what access actually looks like in practice: what a single credential can reach, why AI agents can inherit the same permissions you have, and why proving who had access matters more than simply describing your controls.

[1 CPE] Proving Cyber Resilience: Measuring Outcomes, Not Effort

  Presented by Jake Mickley, Sr Solutions Architect • Horizon3

Most security programs measure effort — not outcomes. Organizations patch thousands of vulnerabilities, deploy dozens of tools, and run annual tabletop exercises… but when an attacker shows up, none of that matters.

What matters is whether they can prove their defenses actually work.

In this talk, Horizon3 shares how leading organizations are using autonomous pentesting to see their environment through the attacker’s eyes — continuously, safely, and at scale. By shifting from assumptions to proof, they’ve learned to:

  • Prioritize what’s exploitable. Focus limited resources on the weaknesses that truly put the business at risk that are known to be abused by threat actors.
  • Quickly fix what matters. Close the loop from find → fix → verify and reduce your exploitable attack surface.
  • Reduce attacker dwell time. Use pentest results to precisely deploy honeyTokens to detect compromise early, and to continuously prove your EDR and SIEM are tuned and working as intended.

Cyber resilience isn’t about being perfect — it’s about getting better over time. And the only perspective that truly matters is the attacker’s.

[1 CPE] Agents Inherit Your Debt: Governing AI Agents Against the Risks Security Tools Won’t Catch

  Presented by Dr. Ken Knapton

Agentic AI introduces new risks into your enterprise, some of which won’t be detected by security tools and controls. For example, there isn’t a patch for indirect prompt injection – it is an authority that is granted to the agent. This session covers how the attack chain works, why your existing stack stays quiet through all five steps, and a six-rule governance model (mapped to ISO/IEC 42001) that bounds what an agent may read, do, and send.

We will also discuss the data debt and tech debt that your agents inherit. Duplicated data, systems you never retired, and years of unrevoked access all become executable at machine speed. You’ll leave with a 90-day plan that requires decisions rather than budget.

Dr. Ken Knapton is a veteran CIO, CISO, author, and educator with deep experience leading technology, cybersecurity, and data strategy in complex organizations. A seven-time CIO, he has guided businesses through operational risk, cyber risk, and the challenges that come with emerging technologies. He holds a doctorate in big data governance, advanced degrees in strategic IT leadership and business administration, and maintains CISSP and C|CISO certifications. In addition to his executive leadership work, he serves as an analyst and adjunct research advisor for IDC’s IT Executive Programs and teaches graduate cybersecurity courses. As the author of Unveiling Tech Debt and Cyber Safety, Dr. Knapton is known for translating technical risk into practical leadership action, with a particular focus on AI, governance, and the safe adoption of technology in the workplace.

[1 CPE] State of the Union: Annual Information Security Report

  Presented by Chad Spoden, Sr Information Security Consultant, Solution Architect Manager • FRSecure

The result of over 100 incident cases handled by the FRSecure response team in the last two years, Sr Information Security Consultant Chad Spoden will dive into the latest threats and response techniques you need to know—and what you can do to minimize the risk and impact of similar events. The breakdown will cover Business Email Compromise, Ransomware, and Internal Compromise. You can’t afford to miss it!