Looking Ahead: Five Cybersecurity Predictions That Will Shape 2027

The cybersecurity landscape continues to evolve at a rapid pace, driven by emerging technologies, shifting attacker tactics, and changing business priorities. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores five key cybersecurity predictions that are expected to significantly influence how organizations manage risk and defend against threats as 2027 approaches. Attendees will gain insight into anticipated developments across areas such as AI-driven attacks and defenses, ransomware evolution, regulatory pressures, workforce challenges, and security architecture trends. The session will focus on what these predictions mean in practical terms and how security leaders can begin preparing today to stay ahead of tomorrow’s threats and build more resilient, future-ready cybersecurity strategies.

2026/11/4
阅读更多

Ransomware Readiness: Preparing Your Security Team Before an Attack Hits

Ransomware remains one of the most disruptive and costly threats facing enterprises today, and preparation is critical to minimizing its impact. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he discusses how security teams can build ransomware readiness before an attack occurs, rather than reacting under pressure once systems are locked and operations are disrupted. Attendees will learn how to assess ransomware preparedness, close common gaps in visibility and response, and ensure backup, recovery, and communication plans are tested and trusted. The session will also explore how security, IT, legal, public relations, and executive teams can align ahead of time to reduce downtime, contain damage, and maintain control during a high-pressure ransomware event.

2026/10/7
阅读更多

Compliance Was Designed for Humans

Peel back any compliance framework, and you'll find a person hiding under it. Attestation means somebody put their name on a claim and would rather not be embarrassed. Access review means asking whether this particular human still needs this particular key. Every one of those mechanisms runs on intent, judgment, and consequences, and every one of them stops meaning anything the moment you remove the human. Agents bring none of the three to work. An agent has objectives rather than intent, inference rather than judgment, and no meaningful exposure to being walked out by HR on a Friday. What it does have is production credentials, commit access, the ability to provision infrastructure, and sometimes a company card. Most organizations have onboarded an extraordinarily privileged insider who skipped the background check, never got a least-privilege review, reports to nobody in particular, and has no offboarding process. This session on September 29, 2026 at 1:00 p.m.Eastern/10:00 a.m.Pacific sponsor Snyk does the practical translation. We'll figure out how to build an evidence trail that can answer "who granted this capability?" now that "who performed this action?" returns something unhelpful. Key Takeaways -How to treat AI agents as non-human identities with a complete lifecycle: provisioning, least privilege, periodic review, and revocation that actually happens. -How to relocate accountability to the point of delegation. -What breaks in attestation, access review, and incident response when your actor can't be held responsible for anything. 1 Group A CPE

2026/9/29
阅读更多

Operationalizing AI Vulnerability Scanning in the Era of Agentic Threats

The economics of application security have fundamentally shifted. With agentic AI models now able to uncover and chain complex, zero-day logic flaws at machine speed, the window between vulnerability and active exploit has collapsed. Traditional SAST tools that rely on rigid syntax matching and regex signatures may not be sufficient on their own. These tools can lack semantic context and can miss the complex business logic flaws that modern AI-driven attackers easily exploit. To close this gap, organizations must transition toward context-aware, agentic scanning. But putting this into practice requires cutting through the marketing hype. On September 24, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific, Sponsor Google Cloud and Host, ISC2 share a grounded, pragmatic approach to adopting AI-driven application security. We break down the real-world mechanics of integrating AI-based scanners into CI/CD workflows, balancing token economics at scale, and strategies for mitigating model hallucinations. 1 Group A CPE

2026/9/24
阅读更多

Systems Security Certified Practitioner (SSCP) Info Session

Join us for a deep dive into Systems Security Certified Practitioner (SSCP), the security operations and network security credential from ISC2, creator of the CISSP. As organizations continue to pursue digital transformation initiatives, the threat landscape is always expanding. Yet cybersecurity leadership talent is scarce. That’s where SSCP from ISC2 comes in — to help fill the gap. Once certified, the opportunities for certified professionals are near limitless. The SSCP is ideal for IT administrators, managers, directors and network security professionals responsible for the hands-on operational security of their organization’s critical assets. It shows you have the advanced technical skills and knowledge to implement, monitor and administer IT infrastructure using security best practices, policies and procedures. In this 60-minute live virtual session, you’ll learn: - If SSCP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your SSCP questions during the Q&A section. Register now and begin your SSCP certification journey today! CPE Credit: 1 Group B CPE Credit

2026/9/23
阅读更多

Operationalizing CTEM: From Assumptions to Evidence

Continuous Threat Exposure Management (CTEM) gives security teams a framework for continuously identifying, prioritizing and reducing exposure. But turning that framework into action requires more than visibility and risk signals. Teams need evidence of what attackers can actually exploit, what those exposures enable, and whether remediation truly removed the risk. On September 22 at 1:00 p.m.Eastern/10:00 a.m. Pacific sponsor Horizon3 and host ISC2 will examine how organizations can operationalize CTEM through a repeatable cycle of discovery, validation, prioritization, remediation and verification. We’ll explore why validation is the pivot from assumption to evidence, how attack-path context can improve prioritization, and why verification is essential to proving that exposure has actually been reduced. The result is a practical approach to continuous exposure management grounded in evidence of what attackers can actually do. 1 Group A CPE

2026/9/22
阅读更多

Solving for Precision: Building Agentic SOC Workflows That Hold Up in Production

Agentic AI is great at producing results that are accurate enough to impress, but not precise enough to trust at scale. “Close enough” won’t work in the SOC. As security teams look to add AI agents to their stacks, how can they close this gap between an “accurate” demo and agents precise enough for production? Join Sponsor Strike48 and Host, ISC2 on September 17, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a discussion on how to build SOC agents for precision, reliability, and consistency across runs. Key Takeaways include: -How narrow, interconnected agents beat monolithic agents on reliability. -Where deterministic automation should be used over cognitive agent reasoning. -Why connectivity and data visibility matter for agent performance.

2026/9/17
阅读更多

The AI Arms Race: Attackers, Defenders, and the Future of Cybersecurity

Artificial intelligence is rapidly reshaping the cybersecurity landscape, giving attackers new ways to automate, scale, and personalize cyberattacks while providing defenders powerful tools to detect and respond faster than ever. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores how AI is being used on both sides of the threat equation and what this escalating arms race means for organizations. Attendees will learn how AI-driven threats such as advanced phishing, deepfakes, and automated malware are changing attacker tactics, as well as how security teams can leverage AI for threat detection, response, and risk reduction. The session will highlight practical considerations for preparing defenses as AI continues to transform the future of cybersecurity.

2026/9/16
阅读更多

The 4x Breach Gap: What Happens When AI Outruns Identity and Data Security

AI agents operate with real enterprise permissions. They can gain those permissions quickly through their own identity or a borrowed one, while most identity programs still move at the pace of employee onboarding. Netwrix’s 2026 Data and Identity Security Report shows the cost of this mismatch: Organizations where AI significantly expanded the identity footprint reported a 43% breach rate, compared with 11% where it did not. Many fast adopters were already ahead of their peers on security fundamentals. This session on September 15, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific examines the data behind the gap: why 74% of organizations lack a unified view of sensitive data and the identities that can access it, why only 19% fully govern non-human identities even though 41% already use agentic AI in production, and why compromised identities and misconfigured permissions account for 75% of sensitive data exposures. We will close with the two areas where organizations fall furthest behind: remediation speed, with only one in four acting immediately through automation, and hidden escalation paths in Active Directory, where just 26% trust that their environment has no misconfiguration that could enable privilege escalation. Attendees will leave with a maturity benchmark for governing identity and data at machine speed. 1 Group A CPE

2026/9/15
阅读更多

Your Sneak Peek Into Three New Session Formats at ISC2 Security Congress (#3)

ISC2 Security Congress 2026 is right around the corner, and we’re so excited about this year’s speaker line-up that we decided to bring a sample of this year’s content to you early! This year, Security Congress is introducing several exciting new interactive session formats, including ACTion Rooms: Advancing Cybersecurity Together, AI Incident Rooms, and Tabletops and Gamified Exercises. Hear from three of our esteemed conference speakers as they preview these formats and share highlights from their presentations. By joining this webinar, you’ll get a snapshot of content from the following sessions: Tabletop/Gamified: From Alert to Action: An Interactive SOC Triage Simulation for Security Analysts AI Incident Room: AI-Driven Data Classification Failure and Impact ACTion Room’s “Sharing the Cybersecurity Profession” series, including Session 4: Connecting the Cyber Dots: How the Profession Learns, Evolves and Advances Join us live September 10, 2026 at 1:00 pm Eastern/10:00 a.m. Pacific to be among the first to gain valuable insights into these formats sessions, plus have an opportunity to ask your questions. Like what you see? Register for ISC2 Security Congress 2026 to unlock access to even more great content this October. Link: https://web.cvent.com/event/0bba3198-226e-4607-aad5-dbf9a382ef2e/websitePage%3Ae3e1427f-5c48-423a-a0e5-60dcec1c4363 You won’t want to miss this enlightening webinar that's the third in a series of three 2026 Security Congress Sneak Peek webinars!

2026/9/10
阅读更多

推荐订阅