Incident Response: Why Organizations Repeat the Same Critical Mistakes

Incident response teams have more tools, automation and intelligence than ever before. In turn, the opportunities to make mistakes are also greater. Organizations are making the same expensive mistakes over and over again. They ignore warning signs and assume someone else is handling the problem. They trust tools and outside experts too much and rush to contain incidents without identifying the true cause. When it comes to supply chain incidents, they assume that if a breach happens at a vendor or service provider, it’s not an internal problem. In this talk, Alex Holden looks at the common failures that turn manageable incidents into long-term crises. He shares practical lessons from real-world situations, pinpoints common mistakes to avoid and shares a blueprint to help you handle crises efficiently and successfully. You’ll learn how to: - Identify and eliminate the most common incident response mistakes. - Pinpoint the true root cause behind each incident. - Accelerate responses while reducing assumptions and improving the quality of decisions.

2026/11/13
阅读更多

Securing AI Agent Reasoning Against Logic-Layer Attacks in 90 Days

Autonomous AI agents are reshaping enterprise operations. Their advanced reasoning can design and execute multi-step, high-privilege workflow actions. This makes the logic layer vulnerable to goal hijacking, indirect prompt injection and unauthorized tool use. As the EU AI Act takes effect and boards require clear accountability, failures at the logic level carry heavy consequences. Traditional controls can't monitor or validate the complex decision loops of autonomous agents. Enterprises need a deterministic control plane that separates reasoning from execution and verifies intent before actions occur. This control plane should also enforce policies that are testable, auditable, and aligned with NIST AI RMF and ISO/IEC 42001 standards. This session presents actionable architectures that allow CIOs, CISOs, and architects to deploy agentic AI quickly while maintaining oversight. Join Eugina Jordan, CEO and Co-Founder at YOUnifiedAI, to discover proven blueprints, practical implementation patterns and get a 90-day roadmap for deploying secure, audit-ready AI agents at scale. Key Takeaways - Pinpoint where to enforce controls across the four-layer stack: Model, Reasoning, Execution, and Enterprise Logic. - Treat agents as managed identities by enforcing least privilege, just-in-time authorization, and API contracts that strictly define tool access. - Defend against advanced threats by applying I/O filtering and provenance controls to counter indirect prompt injection, tool hijacking, and logic-level exploits. - Adopt a reference architecture and measurable metrics to pilot, strengthen, and scale agentic AI deployments with clear audit evidence.

2026/9/2
阅读更多

The Five-Layer Stack Behind Every Defensible AI System

Enterprise AI is deciding, detecting, and acting in production, while security and governance are still being retrofitted from procurement checklists and annual audits. This session from industry thought leader Noah M. Kenney introduces the AI Governance Stack, a five-layer operating model spanning data, models, system integration, control and monitoring, and audit and evidence. Through a case-study walkthrough of a high-risk enterprise AI system, attendees will see how each layer produces controls that support existing cybersecurity functions, satisfy governance and audit requirements from a single source of truth, and make AI systems defensible to regulators, boards, and incident responders.

2026/9/1
阅读更多

Reduce AI Risk with Threat Intelligence–Driven SecOps

AI-driven automation is reshaping internal operations, but it is also widening the attack surface. Without a clear grasp of the security risks unique to AI, organizations risk exposing critical assets and undermining trust. Addressing these vulnerabilities early is essential to ensure AI deployments strengthen your security posture. This session explores approaches for securing AI operations and strengthening threat intelligence. We will focus on establishing effective security controls, maintaining continuous oversight of AI environments, detecting anomalous activity and responding rapidly to new threats. Join Ernesto Marquez, Project Director at Concurrency Labs Ltd., for actionable guidance on deploying secure AI solutions and building rapid detection and response capabilities within your organization. Key Takeaways: - Identify key risks and common misconfigurations in AI-driven tools and processes. - Apply targeted prevention strategies and evaluate tools that improve threat detection, visibility, and incident resolution. - Strengthen AI resilience, enhance threat visibility, and adopt proactive security strategies for secure AI application deployment.

2026/9/1
阅读更多

How to Assess AI Security

AI system security is imperative with its large uptick in use. Given the complexities of both AI and security, management requires assurance that systems comply with both corporate policy and external regulations. The challenge lies in how to assess such a rapidly evolving technical environment such as AI. This presentation offers a framework for assessing security from an AI perspective and AI system development from a security perspective. It then goes deeper, presenting assessment programs for 12 aspects of AI security, including access controls, recoverability, ethics and robustness. Key Takeaways: - The balance between assessments and audits of AI security. - Basic principles of security, from an AI perspective. - Basic principles of managed AI risk, from a security perspective. - The questions to ask and tests to perform in assessing AI security.

2026/9/1
阅读更多

Proving Threat Hunting ROI: Outcome-Based KPIs for the Modern SOC

Automated tools miss the threats that cause the most damage. While threat hunting is essential for modern security operations, its value is often measured by the number of hunts completed—a metric that overlooks its true operational impact. Without a clear framework for demonstrating risk reduction and guiding detection engineering, SOC leaders struggle to justify investment and prioritize resources. Security teams must adopt outcome-based measurement to capture the full value of threat hunting. This session outlines a practical approach for evaluating threat hunting with KPIs that matter: hypothesis quality, visibility gaps, adversary techniques addressed, and quantifiable risk reduction. These metrics directly inform improvements in MTTD, MTTR, dwell time, and false negatives. Learn how to translate technical hunting results into executive insights that demonstrate resilience gains and support a proactive SOC strategy. Join John Bambenek, President of Bambenek Consulting, to discover proven methods for quantifying threat hunting value and securing the resources your team needs to advance. Key Takeaways: - Define outcome-based KPIs for threat hunting and eliminate vanity metrics. - Connect hunt outcomes to risk posture by tracking MTTD, MTTR, dwell time, and false negative trends to justify investment. - Audit and document hypothesis quality and coverage to improve efficiency. - Present technical results in executive terms, highlighting cost avoidance and strategic roadmap impact.

2026/8/12
阅读更多

Translate Security Operations Metrics into Business Risk Intelligence

Security operations centers produce a lot of data, including alert counts, MTTR, MTTD, incident volumes, and automation rates. But does having all this information really make us safer? As regulatory pressures and board oversight intensify, security leaders need to be able to translate daily operational work into strategic risk insights that executives actually understand. Without this, CISOs struggle to justify security budgets and demonstrate their value to the business. Traditional SecOps metrics like ticket closure rates and detection speeds only tell part of the story. Modern security leaders need frameworks that connect operational performance to exposure reduction, resilience building and strategic decision-making. This session will show you how to turn raw security data into risk intelligence that makes sense to executives and boards. We’ll also look at how AI-driven automation is changing what we measure and helping organizations move away from reactive risk management, towards a proactive approach that supports smart investments and shared accountability. Join Oksana Denesiuk, Board Member for ISSA LA and Senior Product Manager at Kaiser Permanente, to learn practical ways to improve your security operations reporting. Key Takeaways: - Why traditional SecOps metrics (alert volume, MTTR, MTTD) fail without business context. - Practical frameworks for translating operational security data into risk intelligence that drives prioritization and investment decisions - How AI and automation are transforming next-generation security operations, measurement and resilience strategies. - Proven communication techniques CISOs use to present security performance meaningfully to boards and cross-functional stakeholders. - Actionable methods to align SecOps metrics with exposure reduction, business impact, and organizational resilience goals.

2026/8/12
阅读更多

Implement Data-Driven Security with AI and Visual Intelligence

The video surveillance side of the security industry is experiencing its 'iPhone moment.' For more than two decades, physical security ran a predictable playbook. Today, that legacy framework traps organizations in massive "hardware debt" -- consuming storage, energy, space, and hands-on maintenance no one wants -- all while capturing situations and near-misses after it is too late. Advanced cloud architecture and edge-AI are completely eliminating the centralized bottleneck, giving rise to intelligent AI orchestration layers that instantly transform standard cameras into proactive, real-time "video supervisors." Physical security is being rewritten by tools that can deploy custom video-AI agents tracking dwell time, enforcing PPE, collecting business intelligence, and flagging anomalies before harm occurs. This structural shift has fundamentally flipped corporate expectations on their head. Integrators and security operators are no longer just field technicians; they have been thrust into the role of AI consultants. The true differentiator for modern security leadership will not be the speed of deployment, but the caliber of data-driven governance. This session from CEO Robert Messer will deliver concrete guidance on how to move beyond legacy security mindsets, establish objective performance metrics that resonate with the C-suite, and confidently navigate the transition from capital-intensive on-premises hardware to secure, provable results in the cloud.

2026/8/12
阅读更多

Optimizing SOC Defense with Emerging Tech for the AI Era

Cyber adversaries are moving faster, using automation and AI to overwhelm traditional defenses. Legacy SOC architectures cannot keep pace with the scale and speed of these attacks. As the enterprise attack surface expands, security leaders face a critical challenge: adapt their SOC strategy or risk falling behind. The surge of new tools promises solutions, but the real difficulty lies in pinpointing the technologies that will deliver measurable impact and understanding how to integrate them effectively. Security leaders require a practical framework for technology selection that cuts through vendor claims and focuses on tools proven to reduce risk. This session examines how to strategically integrate advanced capabilities that align with compliance requirements, fit within complex environments, and support human analysts without adding to alert fatigue. Join Charles Kolodgy, Principal at Security Mindsets LLC, for guidance on how to modernize your SOC, optimize technology procurement, and build a more resilient, analyst-centered human-machine defense model. Key Takeaways: - Evaluate the real-world strengths and limitations of AI-driven defensive tools to inform objective procurement decisions. - Align technology investments with your current security frameworks and the maturity of your incident response teams. - Assess how new technologies impact SOC workflows, security frameworks, and operational maturity. - Integrate intelligent automation into SOC workflows to support analysts, reduce burnout, and accelerate detection and response times. - Prepare your SOC infrastructure for next-generation advancements, including agentic AI and proactive defense models.

2026/8/11
阅读更多

Preparing Security Analysts for the Reality of Modern Security Operations

Security analysts need more than just technical skills to handle the realities of modern operations. AI, automation, and expanding attack surfaces have outpaced traditional training and certifications. As threats evolve, organizations face a critical skill gap: analysts need to be ready to make decisions and adapt under pressure, not just execute technical tasks. Effective analysts do more than investigate alerts. They make informed decisions under pressure, align with business priorities, and collaborate across teams to drive incident response. To develop these capabilities, organizations need to move beyond technical training and intentionally build operational readiness. Drawing on real-world experience leading enterprise security operations and vulnerability management programs, Mari Galloway shares practical strategies to develop analysts prepared for the moments that matter. Attendees will examine how experiential learning, cross-functional collaboration, leadership development and targeted technology adoption combine to build confident analysts and resilient security teams. Learning Objectives - Assess how AI and automation are redefining the analyst’s role, shifting focus from technical execution to operational decision-making. - Learn practical strategies to develop operationally-ready analysts through experiential learning, cross-functional collaboration and real-world incident preparedness. - Adopt leadership approaches that strengthen decision-making, communication and operational effectiveness so analysts can navigate complex incidents with confidence. - Create development pathways that improve analyst retention, build organizational resilience and prepare the next generation of security operations professionals.

2026/8/11
阅读更多

推荐订阅