Event Agenda

Session details are subject to change. 

July 14

Time
(All times listed in U.S. ET)

Session

10:00 a.m. - 10:45 a.m.

Taming AI Sprawl and Shadow AI Through Strong Governance

The rapid and unfettered adoption of artificial intelligence within an enterprise can result in the rise of “shadow AI” — tools and models used without formal approval — as well as create unwanted AI sprawl conditions. As a consequence, these unmanaged AI systems can expose sensitive data and create new attack surfaces for cyber adversaries, resulting in security and compliance risks.

This panel session will explore how strong AI governance practices can help organizations regain control before cyberattackers can weaponize and exploit these problems. Panelists will discuss practical approaches for identifying shadow AI, reducing uncontrolled AI proliferation, and restoring visibility and accountability into the AI lifecycle. Topics will include risk-based classification of AI assets; layered governance across models, APIs, agents and data pipelines; and aligning internal controls with emerging frameworks such as the NIST AI RMF, EU AI Act and ISO 42001.

Speakers

Pamela Gupta, CISSP: Founder & Co-President of Trusted AI & Enterprise AI Governance Advisor, Multinational Co.

Dheeraj “DJ” Gurugubelli: Sr. Director, Cybersecurity & AI, EY-Parthenon

Michael Powell, CISSP: Director of Cyber & InfoSec, Aston Martin Lagonda LTD

 

10:55 a.m. - 11:55 a.m.

Inside the 2.7x Problem: Vulnerability Discovery Is No Longer the Bottleneck - Sponsored by Cobalt

LLM applications generate serious vulnerabilities at 2.7x the rate of any other asset type, a ratio unchanged across two years of pentest data. Meanwhile, automated agents now reach initial access in under seven minutes at the cost of an API call. Discovery is no longer the bottleneck, and the security programs built around that assumption are exposed.

In this session, Cobalt will unpack new findings from thousands of AI and LLM application pentests and 450 security leaders, sharing what the data reveals and what security teams can do about it.

What you'll learn:

  • How attackers chain prompt injection, now 37.6% of LLM findings, into multi-step exploits against production AI systems
  • How Mythos collapsed the skill barrier to sophisticated offense, and practical steps your team can take to close that gap
  • How to read the adversary patterns behind the numbers, and how to translate those signals into concrete program adjustments that get ahead of where threats are heading next

Speakers

Joe Brinkley: Head of Security Research, Cobalt

Luke Doherty: Head of Customer Engagement, Cobalt

12:05 p.m. - 1:05 p.m.

Preparing for an AI-Driven Threat Landscape - Sponsored by Wiz

AI is changing both the threats organizations face and the technologies they must protect. As vulnerability discovery and exploitation accelerate, security teams need a new approach to understanding and managing risk. In this session, we'll explore how the landscape is evolving, introduce a practical framework for AI threat readiness that’s grounded in real-world cloud security data, and discuss where organizations can begin—from reducing exploitable risk and prioritizing what matters most to securing the growing footprint of AI applications, models, agents and data.

Attendees will walk away with:

  • A clearer picture of how AI is shifting attacker capabilities and the threat landscape
  • A practical framework for assessing and prioritizing AI-related risk
  • Concrete first steps for securing AI assets and reducing exploitable exposure

Speaker

Snegha Ramnarayanan: Manager, Product Marketing, Wiz

July 15

9:00 a.m. - 9:45 a.m. 

The AI Pivot: Safeguarding the Future of ISC2 Certifications

With 30% of cybersecurity professionals already integrating AI tools into their daily operations, artificial intelligence has rapidly become the number one skills need in the industry. As organizations adopt autonomous agents and face emerging regulations like the E.U. AI Act, the role of the cyber professional is shifting from merely protecting systems to actively governing intelligence.

To reflect this reality, ISC2 certifications are evolving. Rather than treating AI as an isolated, standalone topic, AI concepts, techniques and security considerations are integrated directly into subtasks throughout our existing certification portfolio. Through rigorous Job Task Analysis (JTA), Subject Matter Experts (SMEs) ensure that our blueprints continuously test the real-world skills required to navigate the opportunities and challenges AI presents across all domains.

This session will explore how the Exam Content Development team ensures our credentials continue to validate the essential human judgment required to govern the machine. Key Takeaways:

  • The Paradigm Shift: Understand how the rapid adoption of AI is transitioning cybersecurity priorities  from technical system protection to strategic governance and oversight.
  • Integrated Assessment: Discover how AI is already embedded across the ISC2 portfolio, with specific examples of how it impacts domains within the  CISSP, CCSP, CGRC and others.
  • Behind the Scenes of Exam Development: Learn how the JTA process utilizes SMEs to weave emerging AI realities into certification blueprints and how AI itself is being leveraged efficiently in the item development pipeline.

Speakers

Thomas Jackson, CISSP: Sr. Exam Content Development Manager, ISC2

Willard Smith, CISSP: Exam Content Developer, ISC2

10:00 a.m. - 11:00 a.m.

AI Knows No Boundaries: Governing Data Access Before It's Too Late - Sponsored by Netwrix

When AI productivity tools like Microsoft Copilot or ChatGPT are deployed, they don't arrive on a clean slate — they inherit every misconfigured permission, unclassified sensitive file, and over-provisioned account already present in your environment. Most organizations conduct no assessment of what AI can reach before switching it on, and once it’s running, native logs tell you the tool was used but not what it exposed.

In this session, we'll examine how security teams can get ahead of AI-driven data exposure through pre-deployment readiness assessments, continuous visibility into what AI tools access and surface, and enforceable governance policies that extend to non-human identities like AI agents and service accounts — before regulators or threat actors force the issue.

Speaker

Dirk Schrader, CISSP: VP of Security Research & Field CISO - EMEA, Netwrix

11:10 a.m. - 12:10 p.m.

The AI-Driven SOC: Navigating the Shift to Autonomous Defense - Sponsored by Palo Alto

Step into the future of cybersecurity where AI and SecOps converge to neutralize today’s most sophisticated cyber-attacks. In a world where threat actors exploit vulnerabilities across cloud, identity, endpoint, and network domains at an unprecedented, AI-driven scale, traditional human-led defenses are facing a breaking point. AI is no longer just an advantage—it has become the necessary foundation of the modern defense arsenal.

Join this session to explore:

  • How to move your team past the friction of manual triage and reactive monitoring into a modernized, AI-driven SOC that operates at machine speed.
  • The strategy behind breaking down tool silos and using a single data foundation to turn disjointed visibility into real-time,      automated action.
  • Strategic, real-world frameworks to eliminate alert fatigue, bridge the gap between detection and response, and build a more resilient defense posture.

Speaker

Eirik Valderhaug: Sr. Solutions Architect, Cortex, Palo Alto Networks 

 12:20 p.m. – 1:05 p.m.

Are Incident Response Programs Ready for AI?

Incident response is difficult under the best of circumstances. With the advent of AI and the release of AI agents across our operating environments, incident response in the AI era is even more complicated, straining preparedness and aspirations for organizational resilience.

This discussion will look at some of the current challenges IR programs face in addressing AI and Agentic AI risks and make the case that our incident response programs must be prepared to respond at machine speed. Machine-speed timescales call into question whether human-in-the-loop approaches can adequately address the AI risks our organizations confront. This collaborative discussion will help participants think about updates and refinements to their own incident response programs.

Speaker

Matt Stamper: CEO & CISO Advisor, Executive Advisors Group, LLC

 

Join us and earn 6.25 CPE for this agenda.

ISC2 member credits will automatically be added to profiles within two weeks post event.