[1 CPE] Beyond Cybersecurity: Assembling Resiliency for the Inevitable Breach

  Presented by BJ Deonarain, Global Quantum and Classic Cyber Security Director • Hitachi Vantara

The Imperative for Resiliency, 100% cyber security is unachievable; breaches are inevitable, where modern threats demand a shift from reactive defense to proactive resilience. Resilience requires mindset and culture change, not just new technology, while focus can sustain operations and limit damage when security fails.

Assembling the resiliency strategic pillars and actions:

  • Risk Assessment: continuous evaluation of assets and vulnerabilities
  • Incident Response: develop, test, and update comprehensive crisis plans
  • Employee Training: ongoing education to make staff the first line of defense
  • Systems Testing: regular audits, penetration tests, and vulnerability scans
  • Partnerships: collaborate with industry experts for knowledge sharing
  • Culture: embed resiliency throughout the organization at every level

BJ Deonarain is a globally focused cybersecurity executive responsible for driving cyber security and cyber resiliency strategy at Hitachi Vantara. With a career spanning technical innovation, client solutions, and cross-functional leadership, BJ combines deep technical expertise with a client-centric approach to mitigate risk and elevate organizational security postures.

[1 CPE] Proving Cyber Resilience: Measuring Outcomes, Not Effort

  Presented by Joe Nay, Solutions Architect • Horizon3.ai

Most security programs measure effort — not outcomes. Organizations patch thousands of vulnerabilities, deploy dozens of tools, and run annual tabletop exercises… but when an attacker shows up, none of that matters.

What matters is whether they can prove their defenses actually work.

In this talk, Horizon3.ai shares how leading organizations are using autonomous pentesting to see their environment through the attacker’s eyes — continuously, safely, and at scale. By shifting from assumptions to proof, they’ve learned to:

  • Prioritize what’s exploitable. Focus limited resources on the weaknesses that truly put the business at risk that are known to be abused by threat actors.
  • Quickly fix what matters. Close the loop from find → fix → verify and reduce your exploitable attack surface.
  • Reduce attacker dwell time. Use pentest results to precisely deploy honeyTokens to detect compromise early, and to continuously prove your EDR and SIEM are tuned and working as intended.

Cyber resilience isn’t about being perfect — it’s about getting better over time. And the only perspective that truly matters is the attacker’s.

[1 CPE] From Vibe Coding to Agentic Engineering: Agile and DevOps in Enterprise AI Development

  Presented by Mike Douglas, SVP Digital Transformation • Lunavi

Enterprises everywhere are racing to incorporate AI into their development practices to improve time to market, create competitive advantages, and avoid being left behind. The tools make it easy to get started, but building mission-critical software with AI is a different challenge entirely. Human + AI development demands security, accountability, and rigorous quality controls that isn’t part of most AI development practices.

In this talk, I’ll show how Agentic Engineering built on a foundation of Agile and DevOps, provides a process for developing software at high speed while keeping humans in the loop, delivering value incrementally, and baking quality into every step through automated security and quality gates. Attendees will leave with a clear understanding of modern AI development tools and processes, and how proven Agile and DevOps practices provide the critical human oversight that responsible AI development requires.

[1 CPE] Better Together: Securing Identity in the AI Era

  Presented by CompuNet, with Microsoft & Palo Alto Networks

Explore how to protect user, machine, and AI identities in the modern workplace by implementing layered controls and complementary security processes. This session highlights how a flexible, multi-platform identity strategy—leveraging Microsoft Entra ID, Idera (formerly CyberArk), and related identity and access management technologies—can address evolving security challenges in the age of AI. Learn how Entra ID capabilities such as Conditional Access, identity governance, and workload identities integrate with privileged access management solutions from Idera to create a cohesive, defense-in-depth identity program. We’ll also touch on adjacent controls across endpoint, cloud, and network security to show how these technologies work together rather than in isolation.

[1 CPE] State of the Union: Annual Information Security Report

  Presented by Chad Spoden, Sr Information Security Consultant, Solution Architect Manager • FRSecure

The result of over 100 incident cases handled by the FRSecure response team in the last two years, Sr Information Security Consultant Chad Spoden will dive into the latest threats and response techniques you need to know—and what you can do to minimize the risk and impact of similar events. The breakdown will cover Business Email Compromise, Ransomware, and Internal Compromise. You can’t afford to miss it!

[1 CPE] The New AI Era in Cybersecurity: What it Means for Your Organization

  Presented by Raymond Neff, Sr Solutions Architect • ESET

This session explores how artificial intelligence is reshaping the modern cyber threat landscape by empowering both attackers and defenders. It examines how adversaries use AI to scale attacks, evade detection, and increase their effectiveness. The presentation also highlights how organizations can leverage AI to build proactive, adaptive defenses that detect and respond to threats more efficiently. Finally, it showcases how ESET applies AI-driven technologies to protect against evolving cyber-attacks and strengthen overall security resilience.

[1 CPE] Building Trust for What’s Next: PKI Modernization & Quantum Readiness

  Presented by Jared Mensinger, Sr Solutions Engineer  • DigiCert

Certificate lifetimes are shrinking. Browser requirements are evolving. Machine identities are growing exponentially. At the same time, organizations are beginning to plan for post-quantum cryptography while supporting new AI-driven systems that depend on trusted digital interactions.

These changes are transforming PKI from a traditional security function into the operational trust layer for modern business.

This session provides a practical roadmap for modernizing PKI, improving visibility into machine identities, automating certificate lifecycle management, and building crypto-agility for future cryptographic transitions. Attendees will leave with actionable steps to reduce operational risk today while preparing for post-quantum security and the next generation of digital trust.

[1 CPE] The Future of Ransomware is Here: ESET’s Latest Threat Report

  Presented by Wafi Choudhury, Enterprise Account Manager • ESET

Join us for an in‑depth walkthrough of the most significant insights from ESET’s latest Threat Report. This session will examine the rise of AI‑assisted attacks, including the discovery of PromptLock, an AI‑powered ransomware prototype. We’ll also explore key shifts in malware‑as‑a‑service, NFC‑driven fraud, and PowerShell‑based delivery techniques, and gain a clear understanding of how ransomware operations are evolving and reshaping today’s threat landscape.

[1 CPE] Cybersecurity and Compliance For 2026

  Presented by Structured

This session examines how organizations can align cybersecurity, privacy, and compliance programs with the realities of 2026. The presentation reviews current threat trends, executive accountability requirements, and the expanding impact of artificial intelligence on risk management. It then connects federal, state, and industry obligations, including NIST CSF 2.0, HIPAA, CJIS, PCI DSS 4.0, CMMC, and emerging privacy laws to practical security program design. Attendees will leave with a clear framework for building a complete security program that integrates governance, segmentation, risk management, Zero Trust principles, and penetration testing to reduce risk and support regulatory readiness.

[1 CPE] Proving Cyber Resilience: Measuring Outcomes, Not Effort

  Presented by Andy Rezabek, Sales Engineer • Horizon3.ai

Most security programs measure effort — not outcomes. Organizations patch thousands of vulnerabilities, deploy dozens of tools, and run annual tabletop exercises… but when an attacker shows up, none of that matters.

What matters is whether they can prove their defenses actually work.

In this talk, Horizon3.ai shares how leading organizations are using autonomous pentesting to see their environment through the attacker’s eyes — continuously, safely, and at scale. By shifting from assumptions to proof, they’ve learned to:

  • Prioritize what’s exploitable. Focus limited resources on the weaknesses that truly put the business at risk that are known to be abused by threat actors.
  • Quickly fix what matters. Close the loop from find → fix → verify and reduce your exploitable attack surface.
  • Reduce attacker dwell time. Use pentest results to precisely deploy honeyTokens to detect compromise early, and to continuously prove your EDR and SIEM are tuned and working as intended.

Cyber resilience isn’t about being perfect — it’s about getting better over time. And the only perspective that truly matters is the attacker’s.