| Date and Time | Title | |
|---|---|---|
| Jul 22, 2026 11:00am - 11:45am (Eastern) | [Opening Keynote] What If AI Never Existed? What if we stripped away the generative AI hype and evaluated enterprise defense through a purely classical lens? This session examines five core security pillars, from identity management to application security, to prove that traditional engineering fundamentals are still sound. The problem is not that AI has invented entirely new categories of vulnerability, but that it has fundamentally fractured our operational timeline. By focusing on real world use cases like the explosion of the corporate attack surface, this talk bridges the gap between technical reality and strategic management. Designed for practitioners and security leaders, this objective discussion bypasses the marketing buzzwords to show why our security foundations remain intact, and how defensive velocity must adapt to counter automated scale. | ![]() |
| Jul 22, 2026 12:00pm - 12:37pm (Eastern) | Authorized Doesn't Mean Safe: Securing AI Agents in the Enterprise As AI agents become embedded across business workflows, they are gaining the ability to access data, interact with applications, and take action with increasing autonomy. While these capabilities can accelerate productivity, they also introduce new security challenges. An AI agent may have legitimate access to systems and data, yet still make decisions or take actions that create risk for the organization. Join Proofpoint for this 45-minute breakout session examining how security teams can address the growing gap between AI access and AI control. In this session, you’ll learn: · How AI agents expand risk across enterprise applications, tools, and data · Why visibility into AI activity is critical for effective governance · Ways to reduce the risk of data exposure across prompts, responses, and automated workflows · How guardrails and runtime protections help keep AI behavior aligned with business expectations · Practical considerations for securing AI as adoption scales across the organization Discover how organizations can gain greater visibility into AI activity, protect sensitive information, and establish the controls needed to confidently embrace autonomous AI. | ![]() |
| Jul 22, 2026 12:00pm - 12:56pm (Eastern) | Beyond the Hype: Designing AI that Actually Delivers As organizations rush to implement artificial intelligence, many are developing AI capabilities just to stay up with the competition, rather than to solve important challenges. This rush for visibility and innovation has resulted in a rising gap between existing AI systems and those that provide genuine value. The end effect is increased complexity, operational risk, and a misalignment of technology, business needs, and governance. This session investigates why intention and discipline, simply not speed, are the foundations of good AI. It questions the premise that quicker AI adoption inherently leads to better outcomes and investigates how poorly specified AI initiatives frequently generate technical debt, privacy risks, and governance gaps while offering little demonstrable impact. Through a governance and risk-informed lens, the conversation focuses on what useful AI looks like when it is designed to address real operational bottlenecks, customer requirements, and business outcomes. It emphasizes the importance of responsible design, oversight frameworks, and cross-functional accountability in developing AI systems that are both innovative and sustainable. Attendees will leave with a practical methodology for determining whether an AI idea is worth developing, how to incorporate responsibility and discipline into the AI lifecycle, and how to move beyond innovation theatre to AI that adds true value and has long-term impact. | ![]() |
| Jul 22, 2026 12:00pm - 12:28pm (Eastern) | GRC-as-Code: How Security Teams Can Ship AI Governance Without Slowing Down Engineering Security governance for AI systems is stuck in 2015. GRC teams write PDF policies. Engineering teams ignore them. When a developer wants to connect a new tool to their AI agent, the review takes days. By the time the policy doc is updated, the architecture has changed twice. This session presents a policy-as-code approach to AI governance that gives GRC teams direct control over runtime enforcement without requiring engineering deployments. Using OPA/Rego as the policy engine, governance rules become version-controlled, testable, and hot-reloadable artifacts that enforce at the point of action rather than the point of review. The talk walks through real implementation: writing Rego policies that map to NIST 800-53 controls, building a policy bundle pipeline so GRC pushes updates without deployments, and separating policy ownership from infrastructure ownership so security teams and engineering teams stop blocking each other. Key Learnings:
| ![]() |
| Jul 22, 2026 12:00pm - 12:16pm (Eastern) | So You Want to Build a Security Agent? Lessons from Building Bits AI Security Analyst Every security vendor is talking about AI agents. Far fewer have actually shipped one into a SOC. In this session, Rex Guo—the product lead behind Datadog’s Bits AI Security Analyst—goes behind the scenes on how Datadog built an autonomous security agent on top of Cloud SIEM: the architecture decisions, the tradeoffs, and the lessons learned along the way. You’ll see how agentic investigation can compress triage from hours to seconds, where an agent genuinely helps versus where a human needs to stay in the loop, and the practical questions to weigh before you build—or buy—a security agent of your own. If your team is drowning in alerts and trying to figure out where AI actually fits in detection and response, this is a candid look at what works. | ![]() |
| Jul 22, 2026 1:00pm - 1:42pm (Eastern) | Defending the Digital Soul: Data Integrity, Global Bias, and a Three-Pillar Defense Against AI Scraping Organizations are pivoting toward Agentic AI, which results in large-scale data misappropriation evolving from technical nuisance to board-level fiduciary crisis. Drawing on research submitted to the White House OSTP and the Purdue AI Management & Policy program, this session outlines a strategic blueprint for protecting proprietary data. Attendees will explore a Three-Pillar Defense: Technical Architecture, Product-Embedded Safeguards, and Policy-Driven Governance. This session bridges the gap between technical defense and executive risk reporting, providing a practitioner’s roadmap for operationalizing the NIST AI RMF to ensure long-term resilience and data integrity. Attendees will gain a three-pillar strategic framework to reframe AI scraping as a board-level fiduciary risk while learning actionable steps to operationalize NIST AI RMF standards for long-term data integrity. | ![]() |
| Jul 22, 2026 1:00pm - 1:44pm (Eastern) | AI Security in the Agent Era When AI stops writing and starts doing. Shadow AI is the new “Bring Your Own Device,” but the stakes are significantly higher. When employees feed proprietary code or sensitive data into unvetted LLMs, the perimeter doesn’t just leak—it dissolves. In this session, Hemanth Tadepalli breaks down the anatomy of AI Data Risk and provides a tactical roadmap for bringing these “shadow” operations into the light. Using the ISO 42001 framework as our North Star, we will discuss how to build a resilient AI Management System (AIMS) that tames the chaos of unauthorized AI usage while keeping your organization’s data under lock and key. | ![]() |
| Jul 22, 2026 1:00pm - 1:49pm (Eastern) | Governing AI without Starting Over: How to Apply Your GRC Framework to AI Tools Before the Risk Gets Away from You AI adoption inside organizations is accelerating faster than governance frameworks can keep up. While much of the conversation focuses on securing large language models and understanding how they work, many organizations are overlooking a more immediate risk: how AI tools are being introduced, accessed, and used across the business. This session reframes AI governance through a familiar lens—Governance, Risk, and Compliance (GRC). Rather than treating AI as a completely new and undefined risk category, we explore how existing security and risk management practices can be effectively extended to AI tools and platforms. Most organizations don’t need a brand-new AI governance framework—they need to operationalize the one they already have. Attendees will learn how to evaluate AI solutions using practical, established criteria: encryption in transit and at rest, access controls, data handling practices, regulatory alignment (HIPAA, PCI, SOC 2, where applicable), and disaster recovery capabilities. The session walks through how to incorporate AI into vendor risk assessments, third-party risk management programs, and internal control frameworks—delivering a pragmatic approach for security and risk leaders who need to move quickly without reinventing their entire governance model. Attendees will leave with a practical, immediately actionable framework for governing AI tools using the GRC practices they already have—so they can safely enable AI in their organizations without waiting for the industry to agree on a standard.
| ![]() |
| Jul 22, 2026 1:00pm - 1:47pm (Eastern) | Your AI Investment Is Growing. Why Isn't Your ROAI? Organizations have invested millions in AI tools, yet many are struggling to demonstrate meaningful ROAI (Return on AI). The problem isn’t the technology. It’s the gap between providing AI access and enabling employees to use it effectively. While a small group of power users drives results, most employees remain uncertain about when, where, and how to apply AI in their daily work. Add concerns around security, governance, and responsible use, and adoption often stalls before value can scale. In this session, we’ll explore the biggest barriers preventing enterprise AI success and reveal the framework leading organizations use to build workforce readiness, accelerate adoption, and turn AI from a promising investment into a measurable business advantage. | ![]() |
| Jul 22, 2026 2:00pm - 2:35pm (Eastern) | Wanted but Not Trusted: Solving the AI Agent Dilemma in SecOps While adversaries rapidly weaponize AI, defenders are stalling. Despite 84% of security leaders agreeing that autonomous agents should be managing L1 alerts, a mere 22% trust the technology enough to hand over the keys for even the most basic tasks. How do we break this deadlock before we fall permanently behind? Join Tim Leehealey, Strike48 Co-Founder and VP of Strategy, as he deconstructs the AI trust barrier. You’ll discover a pragmatic path forward that favors steady, verifiable automation over risky overhauls. Key Takeaways:
| ![]() |
| Jul 22, 2026 2:00pm - 2:43pm (Eastern) | The Deepfake Dividend: How Fraudsters Turned 'Looks Real' into Real Money Fraud has always exploited trust. Deepfakes industrialize it. This session explores a forensic analysis of the $25M Arup deepfake-enabled fraud case. Attendees will learn how attackers combined social engineering, real-time voice/video impersonation, and “routine” business processes to trigger high-value payments and approvals. You’ll leave with a practical, investigation-ready response framework built for security leaders, fraud examiners, and risk teams working together:
We’ll also pressure-test common misconceptions; why “better deepfake detectors” won’t save you by themselves, how attackers weaponize urgency and authority, and which finance-process controls reduce loss fastest. | ![]() |
| Jul 22, 2026 2:00pm - 2:46pm (Eastern) | Beyond Logs: Closing AI-Era Security Blind Spots AI is changing the economics of cyber risk. Vulnerabilities can now be discovered, prioritized, and exploited faster than many organizations can validate their real exposure. A logs-only view is no longer enough because logs show only what systems report, not everything attackers can reach. The highest-risk gaps often sit in east-west traffic, encrypted sessions, fast-moving cloud and container environments, and unsanctioned AI services operating outside formal oversight. Attendees will learn how network telemetry provides the evidence needed to make better security decisions. It helps teams determine which vulnerabilities are truly exploitable, uncover lateral movement and shadow AI usage, and prioritize detection and remediation around the most critical attack paths. The outcome is not just faster action, but measurably lower cyber risk and stronger business resilience. | ![]() |
| Jul 22, 2026 3:00pm - 4:04pm (Eastern) | Deepfake: Empowering Your Users to Recognize What AI Can Fake Your users are being targeted right now. Deepfake attacks happen every few minutes, and nearly half of all organizations have already been hit. When a deepfake lands in your user’s inbox, will they spot it or fall for it? In this session, Perry Carpenter, Chief Human Risk Management Strategist, and Chris Littlefield, Product Manager, pull back the curtain on the next era of social engineering. Deepfakes, AI agents, and synthetic narratives are reshaping the threat landscape, and traditional training no longer prepares users for attacks that feel real. You’ll learn how to build a workforce that stays calm, curious, and grounded in truth, even when a scam sounds exactly like someone they trust. You’ll leave this session with the strategy and tools to help employees recognize and validate AI-driven manipulation, plus measurable ways to demonstrate to leadership how you can reduce real-world deepfake risks. | ![]() |
| Jul 22, 2026 3:00pm - 4:12pm (Eastern) | Social Engineering Meets AI Jailbreaking This session examines social engineering and AI jailbreaking as the same problem expressed through different systems: the deliberate use of language to move a target toward action. Instead of treating phishing, scams, and prompt attacks as separate disciplines, the presentation breaks them down into shared persuasion mechanics: authority, scarcity, liking, commitment, social proof, urgency, secrecy, and gradual escalation. The course moves from the old confidence game to modern AI-enabled manipulation, showing how attackers recruit victims into a story before they ever ask for money, credentials, access, or action. It then bridges that human model into large language models, explaining how prompts, roleplay, indirect prompt injection, many-shot examples, semantic camouflage, and agentic tool use exploit similar weaknesses in machine behavior. The goal is not just to define these attacks, but to make them recognizable in the moment. Participants will learn to identify pressure, authority claims, skipped verification, escalating requests, and manipulated context across both human communications and AI systems. | ![]() |
| Jul 22, 2026 3:00pm - 4:06pm (Eastern) | From Pilot to Production: Launch Readiness for Enterprise AI Agents AI agents are new, but the security questions are timeless: who owns the system, what can it access, what actions are allowed, and how do we respond when something goes wrong? As enterprise AI moves from pilots into workflows that retrieve data, call tools, update records, and trigger business actions, this session gives security and governance leaders a practical launch-readiness model covering ownership, risk tiering, data boundaries, identity, tool permissions, human approval, logging, exception handling, Attendees will leave with a launch-readiness checklist that applies timeless security principles to enterprise AI agents: ownership, least privilege, layered control, human judgment, logging, resilience, and incident response. | ![]() |
| Jul 22, 2026 3:00pm - 4:10pm (Eastern) | AI Cyber Debrief: Geopolitics, Algorithmic Warfare, and the Frontier of AI Resilience Artificial Intelligence is no longer just a driver of productivity; it is the primary battlefield of modern global conflict. This session connects the dots between geopolitical volatility and the immediate risks to model integrity, data sovereignty, and cognitive security. We will examine how shifting alliances involving major powers like Russia, China, and the EU are reshaping the cyber threat landscape—specifically targeting sovereign AI clusters, decentralized compute networks, and the global semiconductor supply chain. The discussion will pivot to the “internal” evolution of the sector, analyzing the rapid integration of Agentic AI in critical infrastructure and the resulting “black box” regulatory and privacy minefield. From state-aligned actors seeking to poison training datasets to sophisticated syndicates deploying automated exploit-generation engines, we will profile the adversaries threatening the global digital order. Join us for a 2026 outlook that moves beyond mere ethical frameworks, offering a battle-tested strategy for maintaining operational resilience and model alignment in the face of unprecedented global instability. | ![]() |
| Jul 22, 2026 4:15pm - 4:50pm (Eastern) | [Closing Keynote] The Hidden Risks of Shadow AI Why end-to-end AI visibility and control are key today to avoid threats and data loss exposure from AI systems. | ![]() |

