Top 10 Reasons to Attend SecureWorld
Conference Agenda
Filter by registration level:
  • session level iconOpen Sessions
  • session level iconConference Pass
  • session level iconSecureWorld Plus
  • session level iconVIP / Exclusive
  • Wednesday, September 23, 2026
    10:30 am
    Exhibitor Hall open
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    10:30 am - 5:00 pm
    Location / Room: Exhibitor Hall

    Your opportunity to visit our solution vendor partners, whose sponsorship makes SecureWorld possible! Peruse the many downloadable resources each booth has to offer.

    11:00 am
    OPENING KEYNOTE
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    11:00 am - 11:45 am
    11:45 am
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    11:45 am - 12:00 pm
    Location / Room: Exhibitor Hall

    Visit the Networking Hall to network with attendees and connect with our supporting solution providers and association partners.

    12:00 pm
    The Quantum Cryptography Revolution
    • session level icon
    speaker photo
    Head of Security Engineering, MassMutual
    Registration Level:
    • session level iconOpen Sessions
    12:00 pm - 12:45 pm

    Quantum cryptography isn’t a distant concept; it’s an active, deployable technology that will define the future of secure communication.

    This presentation explores how quantum mechanics is reshaping cybersecurity. We’ll cover the limitations of classical encryption in a post-quantum world, the principles behind Quantum Key Distribution (QKD), and real-world implementations already in use. Attendees will also get a glimpse into the quantum-safe future being built today by governments and enterprises globally.

    12:00 pm
    GRC-as-Code: How Security Teams Can Ship AI Governance Without Slowing Down Engineering
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    12:00 pm - 12:45 pm

    Security governance for AI systems is stuck in 2015. GRC teams write PDF policies. Engineering teams ignore them. When a developer wants to connect a new tool to their AI agent, the review takes days. By the time the policy doc is updated, the architecture has changed twice.

    This session presents a policy-as-code approach to AI governance that gives GRC teams direct control over runtime enforcement without requiring engineering deployments. Using OPA/Rego as the policy engine, governance rules become version-controlled, testable, and hot-reloadable artifacts that enforce at the point of action rather than the point of review.

    The talk walks through real implementation: writing Rego policies that map to NIST 800-53 controls, building a policy bundle pipeline so GRC pushes updates without deployments, and separating policy ownership from infrastructure ownership so security teams and engineering teams stop blocking each other.

    Key Learnings:

    • Why document-based AI governance fails in fast-moving engineering organizations
    • Implementing policy-as-code with OPA/Rego for AI agent runtime enforcement
    • Mapping Rego policies to NIST 800-53 and ISO 27001 control families
    • Building a GRC policy pipeline: version control, testing, hot-reload, and audit trails
    • Organizational patterns for separating policy ownership from infrastructure deployment
    12:00 pm
    Cloud Encryption Dynamics
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    12:00 pm - 12:45 pm

    The emergence of cloud computing resulted in a boom in attention on encryption. Where has encryption benefited cloud computing, and where have hopes been dashed? What are today’s models, and what impact will the latest technologies—confidential computing, privacy preserving encryption, homomorphic encryption, for example—have in the years ahead? This session will provide an overview of cloud encryption dynamics that probably contradicts at least one thing you believe on that topic. Come join this session and learn from someone that’s lived in the trenches and values constructive debate.

    Paul Rich is the Executive Director of Data Management & Protection at JPMorgan Chase & Co. From 1998 to 2019, he worked at Microsoft where he worked with encryption technologies and developed new features in Office 365 for protecting customer data. Paul aspires to evangelize unfortunate truths and debunk popular myths regarding encryption and cloud computing.

    12:45 pm
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    12:45 pm - 1:00 pm

    Visit the Networking Hall to network with attendees and connect with our supporting solution providers and association partners.

    1:00 pm
    The Invisible Heist: How Quantum Computing Is Already Attacking Your Encrypted Data
    • session level icon
    speaker photo
    Security Engineer, Confidential
    Registration Level:
    • session level iconOpen Sessions
    1:00 pm - 1:45 pm

    Nation-states are today collecting encrypted organizational communications with one goal: decrypt them when quantum computers arrive. This confirmed strategy—Harvest Now, Decrypt Later—is named in NSA/CISA joint advisories and attributed to nation-state actors including China’s Volt Typhoon and Salt Typhoon groups. Meanwhile, every commercial Quantum Key Distribution system ever independently tested has been defeated through hardware attacks. And in July 2022, a NIST Post-Quantum Cryptography finalist was completely destroyed by a classical laptop attack in 62 minutes.

    This session is a practitioner’s field guide to the quantum threat landscape for IT security engineers. No physics background required. We cover six threat domains: HNDL campaigns and which data categories are already at risk; Shor’s and Grover’s algorithms and their precise impact on RSA, ECDH, AES-128, and SHA-256;three physical attacks that defeated commercial QKD hardware with confirmed evidence; implementation vulnerabilities in the surviving NIST PQC standards including timing side-channels in ML-KEM; and a specific week-by-week enterprise migration roadmap based on the 2024 NIST standards.

    This session is the result of deep research into published attack papers, hardware demonstrations, and the NIST PQC standardization process—distilled into intelligence that IT security teams can act on immediately.

    1:00 pm
    Quantum Readiness: Preparing Your Organization for a Post-Quantum Future
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    1:00 pm - 1:45 pm

    Session details to come.

    1:00 pm
    From Alert Fatigue to Adaptive Defense: Operationalizing AI in the SOC
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    1:00 pm - 1:45 pm

    Session details to come.

    1:45 pm
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    1:45 pm - 2:00 pm

    Visit the Networking Hall to network with attendees and connect with our supporting solution providers and association partners.

    2:00 pm
    [Panel] Our Prediction into the World of Quantum Litigation
    • session level icon
    speaker photo
    AI and Emerging Risk Strategy Lead, Beazley
    speaker photo
    Head of Risk Solutions, Crum & Forster
    speaker photo
    Managing Partner, Tittmann Weix
    Registration Level:
    • session level iconOpen Sessions
    2:00 pm - 2:45 pm

    Quantum litigation does not exist yet.

    This session maps where the first cases will come from, what harm theories will actually survive a motion to dismiss, and what the litigation landscape looks like once decryption events start materializing. Drawing on the existing framework of data breach class actions, regulatory enforcement, and negligence doctrine, this talk builds a litigation roadmap for a threat that most have not started thinking about and most organizations have not started defending against.

    We start with the cases that are already predictable. Federal contractors who miss the 2030 post-quantum cryptography deadline. Software vendors making quantum-ready representations they cannot back up. Organizations with long-confidentiality data, health records, financial archives, legal communications, sitting on legacy cryptography while the harvest window stays open.

    Then we get to the harder question. When a quantum decryption event finally happens, what does the plaintiff actually have to show? Harm timing problems, standing doctrine, statute of limitations questions, and the evidentiary challenges. None of this has been litigated. There’s no reason why harm in the area of quantum will not reach the court system.

    The negligence theory is already written. And these three attorneys will be bringing the crystal ball to this audience of technical practitioners.

    2:00 pm
    The 2027 PQC Control Plane
    • session level icon
    AI-Orchestrated Cryptographic Discovery, Hybrid Migration, and Safe Rollback
    speaker photo
    Sr. Security Engineer, Exeter Finance LLC
    Registration Level:
    • session level iconOpen Sessions
    2:00 pm - 2:45 pm

    By 2027, the challenge will no longer be choosing post-quantum algorithms. It will be migrating thousands of hidden cryptographic dependencies without disrupting production. This session will present a vendor-neutral, AI-assisted PQC control plane that continuously discovers quantum-vulnerable cryptography, builds live CBOM and dependency maps, prioritizes migration risk, orchestrates hybrid classical-PQC transitions, validates interoperability and performance, and safely rolls back unsuccessful changes across cloud, identity, and critical-infrastructure environments.

    This is timely because NIST’s current work is moving toward automated cryptographic discovery, inventory, testing, and practical migration, while my session would take the audience into the next stage: operational orchestration in 2027.

    2:00 pm
    Beyond Logs: Closing AI-Era Security Blind Spots
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    2:00 pm - 2:45 pm

    AI is changing the economics of cyber risk. Vulnerabilities can now be discovered, prioritized, and exploited faster than many organizations can validate their real exposure. A logs-only view is no longer enough because logs show only what systems report, not everything attackers can reach. The highest-risk gaps often sit in east-west traffic, encrypted sessions, fast-moving cloud and container environments, and unsanctioned AI services operating outside formal oversight. 

    Attendees will learn how network telemetry provides the evidence needed to make better security decisions. It helps teams determine which vulnerabilities are truly exploitable, uncover lateral movement and shadow AI usage, and prioritize detection and remediation around the most critical attack paths. The outcome is not just faster action, but measurably lower cyber risk and stronger business resilience.

    2:45 pm
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    2:45 pm - 3:00 pm

    Visit the Networking Hall to network with attendees and connect with our supporting solution providers and association partners.

    3:00 pm
    The Quantum Debrief
    • session level icon
    speaker photo
    CNN Military Analyst; U.S. Air Force (Ret.); Founder & President, Cedric Leighton Associates, LLC
    speaker photo
    Founding Partner, CYFORIX (Former CISO & Sr. Executive at Keurig Dr Pepper, Comcast, HD Supply, and GE)
    Registration Level:
    • session level iconOpen Sessions
    3:00 pm - 3:45 pm

    Artificial Intelligence is no longer just a driver of productivity—it is the primary battlefield of modern global conflict. Yet, the foundation supporting today’s AI—from encrypted data pipelines and sovereign compute clusters to decentralized model training—relies on classical public-key cryptography that is fundamentally vulnerable to quantum adversaries. This session connects geopolitical volatility with the immediate risks to model integrity, data sovereignty, and cognitive security at the intersection of AI and quantum computing.

    We will examine how major powers (such as China, Russia, and the EU) are racing toward “Harvest Now, Decrypt Later” strategies targeting proprietary model weights, training datasets, and semiconductor supply chains. The discussion then pivots to the integration of Agentic AI in critical infrastructure, highlighting how adversaries are pairing automated exploit engines with side-channel attacks to compromise post-quantum implementations. Join us for a forward-looking strategy that moves beyond ethical frameworks to deliver a battle-tested roadmap for crypto-agility, PQC migration, and model alignment in an era of unprecedented quantum-enabled disruption.

    3:00 pm
    AI, Quantum, and the Cryptographic Countdown: A Ticking Clock for Security Leaders
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    3:00 pm - 3:45 pm
    As quantum computing threatens to undermine classical encryption, security leaders are racing to develop cryptographic models that can withstand its power. But quantum alone isn’t the whole story, and artificial intelligence is now accelerating both the development and the threat landscape of cryptographic systems.
    In this session, we’ll explore how AI is reshaping the field of quantum cryptography, from enhancing quantum key distribution protocols to automating the discovery of post-quantum vulnerabilities. We’ll examine real-world scenarios where AI accelerates the design of quantum-safe algorithms and how adversaries may weaponize AI to exploit cryptographic transitions.
    Whether you’re planning a migration to post-quantum cryptography or evaluating the security of your digital infrastructure, this talk provides a forward-looking perspective on how AI is shaping the cryptographic future. The era of AI-driven quantum security has begun. Are we ready for it?
    3:00 pm
    Quantifying Security Debt: Communicating Risk and Driving Remediation with the CFO
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    3:00 pm - 3:45 pm

    Session details to come.

    3:45 pm
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    3:45 pm - 4:00 pm

    Visit the Networking Hall to network with attendees and connect with our supporting solution providers and association partners.

    4:00 pm
    [Closing Keynote] Beyond Post-Quantum: QKD, AI Agents, and the Future of Critical Infrastructure Trust
    • session level icon
    speaker photo
    CISO & Assistant CTO for Security and Infrastructure, City of Seattle
    Registration Level:
    • session level iconOpen Sessions
    4:00 pm - 4:45 pm

    Critical infrastructure is entering a multi-decade trust transition that no single technology will solve. Post-quantum cryptography is now a mandatory foundation for long-lived systems, software supply chains, identity platforms, and sensitive data protection. Quantum key distribution is also moving from research into selective critical infrastructure pilots and demonstrations, but it comes with real operational limits that security leaders must understand. At the same time, AI agents and machine identities are changing what authentication, authorization, delegation, and provenance mean inside enterprise, operational, and security environments. This keynote separates signal from hype and maps where PQC, QKD, AI agents, machine identity, software provenance, and next-generation cyber operations converge, and where they should not be confused. Attendees will leave with a practical trust map for the next five years: what to inventory, what to modernize, what to ask vendors, and how to prepare critical infrastructure for quantum-era and AI-native security risk without chasing science fiction or vendor checklists.

Exhibitors
  • Google Cloud Security

    Google Cloud Security provides organizations with leading infrastructure, platform capabilities and industry solutions to help them solve their most critical business problems. Google Cloud Security helps customers protect their global operations with solutions such as zero trust security, application and data protection, fraud prevention, and threat detection and response.

Return to Agenda
Keynote Speakers
Speakers
  • speaker photo
    Sridhar Boddula
    Head of Security Engineering, MassMutual

    Sridhar Boddula is a cybersecurity executive leader and Head of Security Engineering at MassMutual, where he leads enterprise security modernization across identity, cloud, and data protection, driving digital trust, operational resilience, and business-aligned cybersecurity transformation at scale.

  • speaker photo
    Sindhura Kona
    Security Engineer, Confidential

    Sindhura is a cybersecurity engineer specializing in emerging threat analysis and enterprise security architecture. With a practitioner's focus on translating complex security research into actionable guidance, Sindhura brings the grounded, real-world perspective to quantum security that is too often absent from discussions dominated by academic theory or vendor messaging. Her presentations are the result of deep research into published attack papers, hardware demonstrations, and the NIST PQC standardization process—distilled into intelligence that IT security teams can act on immediately.

  • speaker photo
    Craig Linton
    AI and Emerging Risk Strategy Lead, Beazley

    As part of the Underwriting Management team at Beazley, I help develop strategy, guidelines, applications, policy language, and best practices around new and emerging cyber risks. I am responsible for running the Underwriting Management AI Strategy Group, the Cross-Product AI Strategy Group, and the AI Exposure Working Group. Each of these groups focuses on how we address the challenges presented by AI.

    Before Beazley, I worked as an insurance coverage attorney, which was where I was first exposed to the world of insurance. I studied law at Emory University and also have a degree in Political Science from Furman University.

  • speaker photo
    Violet Sullivan
    Head of Risk Solutions, Crum & Forster

    Violet Sullivan leads cyber consulting services at Crum & Forster. She works with insurance carriers, trade associations, and individual business clients from around the world providing expert guidance on cybersecurity threat management and response. She represents Crum & Forster within the legal, insurance, and risk management channels to develop long-term relationships, recurring revenue, and new business growth. Ms. Sullivan is a licensed attorney in Texas and Pennsylvania and a Certified Information Privacy Professional (CIPP/US), with her JD and MBA degrees from Baylor University. In addition to her full-time role, Violet serves as a professor of Cybersecurity & Privacy Law for Baylor Law School’s LL.M. Degree in Litigation Management, the first of its kind nationwide. Her diverse practice experience at both the individual and policy levels has prepared her for developing new tools and approaches to solving what is fast-becoming a pervasive and costly challenge in modern industry: how to respond to a cybersecurity incident.

    Early in her career, Violet worked on the incident responses for some of the largest and most notable data breaches to date, including: Home Depot, Sony, and Anthem. Her experience in managing scaled breach responses led to her expertise and proficiency in proactively preparing organizations for cyber incidents. In the past eight years, she has facilitated over 450 cyber incident simulations (tabletops) for public and private sector companies, including many Fortune 100 companies.

    As a cybersecurity and privacy attorney, Violet provides consulting services to respond to the needs of various cybersecurity programs. She reviews and develops customized incident response plans to ensure organizations are prepared to respond efficiently and effectively to a data breach. Violet also helps improve internal coordination by facilitating customized tabletop simulations focused on "pressure-testing" an organization's incident response procedures and protocols. Each of these customer-facing services mentioned has been built and developed for the purpose of creating long-standing relationships that turn to Violet for guidance, referrals, questions, and future projects.

    As a cybersecurity and privacy professor, Violet developed the entire curriculum for an innovative course on cybersecurity and privacy law for licensed attorneys working toward their LL.M. degree. The specific focus on litigation management has made Sullivan’s course and her lecture series uniquely valuable to experts across the United States.

  • speaker photo
    Louisa Weix
    Managing Partner, Tittmann Weix

    Tittmann Weix helps insurance claims professionals to manage and resolve their claims in Cyber & Privacy, Media & IP, and Technology E&O. Founded in 2020 by Louisa Weix and Raymond Tittmann, seasoned insurance lawyers, the company is majority woman-owned and Chambers ranked; Best Law Firms, US News.

    About me:
    - I played rugby for the United States Rugby Team from 1993-1996, and played in the 1993 Canada Cup and the 1994 World Cup. I also played for the Richmond Rugby Club in London.
    - Love to travel with my twin daughters—hiking in the Swiss alps or Azores, visiting London and Paris, or road tripping on the Oregon and California coast.
    - I have been testing beers all over the U.S. (as an instrumentation specialist) before I became an insurance expert.

  • speaker photo
    Ankit Gupta
    Sr. Security Engineer, Exeter Finance LLC

    Ankit Gupta is a cybersecurity leader with more than 15 years of experience in cloud security, identity protection, and threat detection. He currently leads enterprise security initiatives at Exeter Finance, focusing on building resilient, future-ready architectures. Ankit holds multiple industry certifications, including CISSP and CCSP, and is a contributing author and speaker at IEEE. His work emphasizes secure design, AI governance, and preparing organizations for post-quantum threats.

  • speaker photo
    Col. Cedric Leighton
    CNN Military Analyst; U.S. Air Force (Ret.); Founder & President, Cedric Leighton Associates, LLC

    Cedric Leighton is a CNN Military Analyst and a retired United States Air Force Colonel. On CNN, he has provided incisive commentaries on the Israel-Hamas War, the War in Ukraine, the U.S. withdrawal from Afghanistan, and numerous other conflicts around the world. His analysis has been seen by millions of viewers around the world and provided much needed context to some of the most pressing national security issues of our time. As a U.S. Air Force officer, Colonel Leighton served at U.S. Special Operations Command, the Joint Staff, and the National Security Agency, where he helped train the nation's cyber warriors. A Middle East combat veteran, he is the recipient of numerous military awards, including the Defense Superior Service Medal and the Bronze Star. After serving 26 years as a U.S. Air Force Intelligence Officer, Col. Leighton founded a strategic risk consultancy and became the co-founder of CYFORIX, where he advises multinational businesses on developing better cyber strategies designed to reduce risk and unpredictability.

  • speaker photo
    VJ Viswanathan
    Founding Partner, CYFORIX (Former CISO & Sr. Executive at Keurig Dr Pepper, Comcast, HD Supply, and GE)

    VJ Viswanathan is a global technology and security executive with more than 25 years of experience spanning AI, cloud and enterprise platforms, cybersecurity, privacy, and technology risk. He has held senior executive roles at large enterprises, including Keurig Dr Pepper, Comcast, HD Supply, and GE, where he led technology, cybersecurity, privacy, and risk programs across highly complex and distributed environments.

    Today, VJ works with boards and executive teams on the security challenges created by AI, automation, and digital sprawl—helping leaders understand where traditional security models fall short and how to adapt. He currently serves as Founding Partner of CYFORIX and CEO of TORQE, focused on strategic defense and enterprise transformation.

  • speaker photo
    Jake Hammock
    CISO & Assistant CTO for Security and Infrastructure, City of Seattle

    Jake Hammock is the Chief Information Security Officer, Assistant Chief Technology Officer and Security & Infrastructure Director at the City of Seattle, where he leads the Security & Infrastructure Division delivering citywide cybersecurity, enterprise infrastructure, cloud operations, IT service management, telecom and radio systems, fiber, and network services. He directs programs for incident response, identity and governance, enterprise architecture, and system and network operations, aligning investments to resilience, public safety, and civic administrative priorities across the nation’s 17th largest municipality through This Is Your City programs.

    Jake’s career spans executive roles in government and industry. He served as Director of Trust and Vice President of Information Security at NICE inContact, leading board-level cybersecurity and privacy programs during a period of accelerated high growth. He was the Chief Technology Officer for a top 10 global fintech by peak market cap, patenting and deploying technologies used in production today, and later CTO for an energy-sector solutions provider, where he architected AI-driven cybersecurity platforms and advised enterprise energy and public-sector clients. A former U.S. Army Military Intelligence and Cyber Warfare Officer, he commanded Cyber National Mission Force units and served in national security leadership assignments within the Intelligence Community. He is a combat veteran, holds an M.Sc. in Cybersecurity Technology and patents spanning telecommunications, environmental platforms, and decentralized technologies, and he remains active in advancing secure AI, quantum-resilient encryption, data governance, and critical infrastructure protection.

Propel your cyber career at SecureWorld!

Hone your skills and knowledge and earn 6 CPE credits.