SecureWorld conferences blend world-class keynotes, breakout sessions, small group discussions and opportunities to earn cybersecurity CPE.
Open Sessions
Conference Pass
SecureWorld Plus
VIP / Exclusive
- Wednesday, November 4, 20267:30 am[PLUS Course] Securing & Enabling AI: Transform Chaos into Competitive Advantage - Part 1Registration Level:
SecureWorld Plus
7:30 am - 9:00 amCome join this interactive workshop — think hands-on working groups so you are an active participant…this is not 6 hours of being lectured at.
Learn how to secure AI while accelerating innovation—not blocking it. Transform from AI Firefighter to Strategic Business Enabler, with a 90-day roadmap for secure AI deployment in your organization.
Why this course? Imagine your CEO just asked about AI security. Do you have an answer?
While you’re counting vulnerabilities, your competitors are deploying AI at scale.
Every Monday, another department launches an AI tool. Marketing uses ChatGPT for campaigns. Sales deploys AI Sales Development Reps. Customer service automates with chatbots.
And your cybersecurity team? Still writing policies nobody reads.
You’ll master:• The AIR-MAP Methodology™ — Your proven 90-day roadmap from AI chaos to governance• Executive Translation — Turn technical AI risks into boardroom language• NIST AI RMF Implementation — Practical application, not theory• The $12M Question — Secure against deepfake fraud and AI-enabled attacks• Shadow AI Discovery — Find and govern the AI already in your organization• Business-First Security — Protect value, not just systemsWho should attend:Perfect fit:• CISOs facing board questions about AI• Information Security Directors enabling digital transformation• IT VPs without dedicated security teams• Cybersecurity Consultants serving enterprise clients• Risk Managers governing AI initiatives• Aspiring decision makers and those reporting to oneWrong course:• Developers wanting to code AI models• Analysts seeking technical certifications• Anyone looking for hands-on hacking labsThis workshop is NOT about:• Prompt injection techniques• Model architecture security• Technical vulnerability scanning• Writing 200-page policiesThis workshop IS about:• Speaking profit-and-loss to executives• Enabling your AI transformations• Building cybersecurity into AI from day one• Becoming the trusted AI advisorYou’ll leave with:1. The Complete AIR-MAP Toolkit• 90-day implementation roadmap• Discovery templates and workflows• Risk scoring calculators• Executive presentation templates2. Ready-to-Deploy Policies• AI Acceptable Use Policy (customize in minutes)• Vendor assessment questionnaires• Incident Response playbooks3. 30-Minute Strategy SessionComplementary private consultation to apply AIR-MAP to your specific situation.7:30 am[PLUS Course] Master the NIST Cybersecurity Framework v2.0 in Just Six Hours - Part 1Registration Level:
SecureWorld Plus
7:30 am - 9:00 amThis intensive, live workshop is your shortcut to cyber resilience mastery. In just one power-packed day, you’ll walk away with:
- Complete mastery of NIST CSF 2.0 – Understand every component and why it matters to YOUR business
- Your personalized Cyber Risk Map – Identify your organization’s exact vulnerabilities and blind spots
- A step-by-step action plan – No more guessing what to do next
- Real-world case studies – See how organizations just like yours have successfully implemented the framework
- Expert-level confidence – Finally speak cybersecurity with authority and clarity
What makes this different?
This isn’t another theoretical lecture. You’ll spend most of your time actually BUILDING your organization’s cybersecurity roadmap using the proven Cyber Risk Management Action Plan (CR-MAP) methodology. You’ll leave with tools and know-how you can implement immediately.Perfect for:
- IT Directors and Managers
- Cybersecurity Professionals
- Business Leaders responsible for risk management
- Compliance Officers
- Anyone tasked with “figuring out cybersecurity”
Exclusive Bonus: Every attendee receives our comprehensive digital CR-MAP Online Workbook ($197 value), your step-by-step guide to:
- Getting BUY-IN from your senior decision makers
- Discovering your top five cyber risks
- Creating a prioritized risk mitigation plan with implementation roadmap
- A score card you can use to track progress
Warning: This live, in-person intensive has limited seating. Don’t let another cyber incident catch your organization unprepared.
Your organization’s cybersecurity can’t wait. Register now.
7:00 amRegistration openRegistration Level:
Open Sessions
7:00 am - 4:30 pmLocation / Room: Registration Desk / LobbyCome to the Registration desk in the lobby to check-in and get your badge. SecureWorld staff will be available throughout the day if you have any questions.
8:00 amNetworking Hall & SecureWorld Gaming Village OpenRegistration Level:
Open Sessions
8:00 am - 4:30 pmLocation / Room: Networking HallYour opportunity to visit our solution vendor partners, whose sponsorship makes SecureWorld possible, as well as association chapters! Booths have staff ready to answer your questions. Look for participating Dash For Prizes sponsors to be entered to win prizes.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5.
Participate in one or all three gaming options:
- Medusa’s Memory Heist – Created by Microsoft’s Artificial Generative Intelligence Safety & Security Team, Medusa’s Memory Heist is a collection of five mini-games that teach the fundamentals of AI Security: Threat Modeling, Red Teaming, Defense, Logging, and Incident Response. Step up to one of the available laptops and see if you can!
- Defense in Depth Starts at the Door: Lockpick Village from Seattle Locksport – You can’t achieve great cybersecurity without physical security. At the Lockpick Village, hosted by Seattle Locksport, attendees get hands-on experience defeating real-world locking mechanisms, from entry-level padlocks to higher-security hardware. Learn the fundamentals of pin tumbler mechanisms, try your hand with picks and tension tools, and walk away with a sharper eye for physical vulnerabilities. Beginners are welcome; we’ll have all the equipment needed to give it a try.
- AI Security Interactive Game – details TBD
8:00 amAdvisory Council Roundtable Breakfast (VIP / Invite only)Registration Level:
VIP / Exclusive
8:00 am - 8:45 amModerated discussion for SecureWorld Advisory Council members. By invite only.
8:00 amAssociation Chapter MeetingsRegistration Level:
Open Sessions
8:00 am - 8:45 amParticipating professional associations and details to be announced.
9:00 am[Opening Keynote] Beyond Post-Quantum: QKD, AI Agents, and the Future of Critical Infrastructure TrustCISO & Assistant CTO for Security and Infrastructure, City of SeattleRegistration Level:
Open Sessions
9:00 am - 9:45 amLocation / Room: Keynote TheaterCritical infrastructure is entering a multi-decade trust transition that no single technology will solve. Post-quantum cryptography is now a mandatory foundation for long-lived systems, software supply chains, identity platforms, and sensitive data protection. Quantum key distribution is also moving from research into selective critical infrastructure pilots and demonstrations, but it comes with real operational limits that security leaders must understand. At the same time, AI agents and machine identities are changing what authentication, authorization, delegation, and provenance mean inside enterprise, operational, and security environments.
This keynote separates signal from hype and maps where PQC, QKD, AI agents, machine identity, software provenance, and next-generation cyber operations converge, and where they should not be confused. Attendees will leave with a practical trust map for the next five years: what to inventory, what to modernize, what to ask vendors, and how to prepare critical infrastructure for quantum-era and AI-native security risk without chasing science fiction or vendor checklists.
9:45 amNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
9:45 am - 10:10 amLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
10:10 amNever Waste a Good Cyberattack: Turning 'Never Again' into Sustained ChangeAssistant Director, Information Security, Port of SeattleRegistration Level:
Conference Pass
10:10 am - 10:45 amA cyberattack is miserable, but it’s also a golden ticket for change. This session breaks down how to turn chaos into advantage: driving modernization, winning resources, fixing broken processes, and finally getting security the seat at the table it needed before things caught fire. Leveraging lessons learned from the Port of Seattle’s August 2024 ransomware attack, this talk covers the hard truths, and how to turn “never again” into sustained change.
10:10 amBuilding or Rebuilding a Cybersecurity Program: Where to Start and What Matters MostDirector, Information Security, JND Legal AdministrationRegistration Level:
Conference Pass
10:10 am - 10:45 amWhether you’re building a cybersecurity program from scratch or inheriting one that needs to be rebuilt, the hardest question is often the same: Where should you focus first? With limited time, budget, and executive attention, trying to fix everything at once almost guarantees failure.
In this session, veteran security leader Marc Menninger shares a practical approach to building or rebuilding a cybersecurity program. Drawing on decades of experience leading security programs across organizations of all sizes, he’ll discuss how to quickly understand your environment, identify the highest priorities, earn leadership trust, and create momentum with limited resources.
Attendees will leave with a practical approach they can immediately apply to prioritize their next steps, avoid common mistakes, and focus on the activities that deliver the greatest reduction in organizational risk.
10:10 amThe New Era of Phishing: Defending Against Deepfakes and AI-Driven DeceptionRegistration Level:
Open Sessions
10:10 am - 10:45 amSession details to come.
10:45 amNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
10:45 am - 11:10 amLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
11:10 amAPI Security: Managing the Fastest-Growing Attack SurfaceRegistration Level:
Conference Pass
11:10 am - 11:45 amSession details to come.
11:10 amThe Quantum Reckoning: From Policy Mandates to PQC Migration Before Q-DayVP, Cybersecurity Products, JPMorgan ChaseRegistration Level:
Conference Pass
11:10 am - 11:45 amQuantum computing has crossed a critical threshold from a long-term research initiative to an immediate enterprise risk and national security priority. The June 2026 federal executive orders accelerating quantum computing capabilities and directing agencies to adopt post-quantum cryptography (PQC) have fundamentally changed the cybersecurity timeline. Organizations can no longer afford to treat quantum resilience as a future compliance initiative. The threat has already begun.
Nation-state adversaries are actively conducting “Harvest Now, Decrypt Later” (HNDL) campaigns, collecting encrypted intellectual property, financial records, healthcare data, operational technology communications, and other sensitive information with the expectation that future cryptographically relevant quantum computers will decrypt it. For sectors such as financial services, energy, healthcare, transportation, manufacturing, and critical infrastructure, the risk is not limited to future confidentiality loss it extends to long-term operational resilience, supply chain trust, regulatory exposure, and national security.
This session presents a practical, engineering-driven framework for helping enterprises transition from policy awareness to operational readiness. Drawing on experience designing and leading cybersecurity programs across fintech, enterprise environments, and critical infrastructure, the presentation focuses on the organizational, architectural, and governance challenges that determine whether post-quantum migration succeeds.
11:10 am[Panel] Navigating the Evolving Digital BattlefieldSr. Solutions Architect, C1
Panel DiscussionRegistration Level:
Open Sessions
11:10 am - 11:45 amAs organizational footprints expand across cloud, SaaS, OT/IoT, and dispersed workforces, defenders face a more complex and interconnected digital battlefield. This panel brings together experts to explore how today’s threat actors combine automation, social engineering, identity breaches, and software supply-chain attacks into highly coordinated assaults.
Panelists will examine the expanding importance of identity in the modern SOC, the emergence of AI-driven threats such as automated reconnaissance and deepfake-assisted breaches, and how fourth-party dependencies are changing risk visibility. The discussion also connects these trends to organizational resilience—showing how teams can improve detection, response, and business continuity across an evolving attack surface. This comprehensive session provides practical insights for any security leader seeking clarity amid converging threats.
11:45 amNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
11:45 am - 12:00 pmLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
12:00 pm[Lunch Keynote] AI-Accelerated Attacks and Defenses: Preparing for Machine-Speed ThreatsRegistration Level:
Open Sessions
12:00 pm - 12:45 pmLocation / Room: Keynote TheaterSession details to come.
12:00 pmAdvisory Council Roundtable Lunch (VIP / Invite Only)Registration Level:
VIP / Exclusive
12:00 pm - 12:45 pmModerated discussion for SecureWorld Advisory Council members. By invite only.
12:45 pmNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
12:45 pm - 1:10 pmLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
1:10 pmBEC Bang! A Business Email Compromise Table-Top ExercisePrincipal Investigator, Rexxfield; CEO, Dougherty Intelligence & InvestigationsRegistration Level:
Conference Pass
1:10 pm - 1:45 pmLocation / Room: Keynote TheaterIn this interactive, table-top exercise session, the audience is divided into two or three separate groups and designated as companies or entities doing business together. A BEC incident is introduced, and the group is asked to tabletop how to remedy the BEC incident from different perspectives of financial victims, compromise victims, and affected third parties. A gamification of the participation will show which group would have the better chance at a proper recovery based on prior investigations and incidents.
1:10 pmBurnout in Cybersecurity: Recognizing, Preventing, and Managing Team FatigueRegistration Level:
Conference Pass
1:10 pm - 1:45 pmSession details to come.
1:10 pm[Panel] The Double-Edged Sword of AI in Cyber DefenseSales Engineer, SecureFlagVP, Product Management, Endpoint Security, IvantiSecurity Advisor, SplunkRegistration Level:
Open Sessions
1:10 pm - 1:45 pmAI is revolutionizing cybersecurity at all levels, speeding up detection and enabling automated attacks on an unprecedented scale. This session examines AI’s dual role as both a powerful defensive tool and a new threat vector for attackers. Panelists will discuss how AI copilots enhance analyst workflows, triage, and anomaly detection, while also addressing emerging risks such as LLM data leakage, prompt injection, model poisoning, and hallucinations within high-trust SOC processes.
The discussion will cover AI governance and assurance frameworks, evolving regulatory expectations, and the impact of synthetic content—including deepfakes, audio spoofing, and hyper-personalized phishing—on social engineering defenses. Attendees will leave with a solid understanding of AI’s potential, the safety measures needed for responsible deployment, and practical steps for preparing teams and pipelines for an AI-driven threat environment.
1:50 pmNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
1:50 pm - 2:10 pmLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
2:10 pmCybersecurity Resources for Critical Infrastructure PartnersCybersecurity State Coordinator (WA), DHS CISARegistration Level:
Conference Pass
2:10 pm - 2:45 pmThis session introduces the comprehensive, no-cost cybersecurity services offered by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to owners and operators of critical infrastructure in both the private sector and the public sector—including state, local, and tribal governments. Participants will gain insight into CISA’s technical and strategic assessments, such as vulnerability scanning, web application scanning, and maturity evaluations, all designed to bolster cyber resilience. The presentation also covers how to access timely threat notifications, utilize exercise packages, engage with protective security advisors, and receive emergency communications support. Attendees will leave with actionable next steps and key points of contact to help them proactively strengthen their cybersecurity posture, all at no cost to their organization.
2:10 pmOT/ICS Security: Bridging the Air Gap and Achieving Visibility in Critical InfrastructureRegistration Level:
Conference Pass
2:10 pm - 2:45 pmSession details to come.
2:10 pm[Panel] Cloud Security & Multi-Cloud Defense: Securing the Modern EnterpriseFocus Areas: Multi-Cloud & SaaS Governance; Workload & Data Protection; Zero Trust & Edge Security
Panel DiscussionRegistration Level:
Open Sessions
2:10 pm - 2:45 pmModern enterprises rely on a complex mix of cloud providers, SaaS platforms, APIs, and distributed identities—offering agility but also creating new control gaps. This panel gathers leaders in CSPM, workload protection, cloud identity, API security, and SaaS governance to explore the challenges of securing multi-cloud environments at scale.
Panelists will discuss AI-driven misconfigurations, rapid SaaS sprawl, and the persistent risk of API-related breaches, as well as how zero trust principles are applied to cloud entitlements and data flows. The conversation also covers DSPM-led visibility, cross-cloud identity governance, and the convergence of network and cloud security through SASE/SSE. Whether you’re cloud-mature or still early in the journey, this session provides strategies for protecting cloud workloads, identities, and data in environments where every misconfiguration can become a breach.
2:45 pmNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
2:45 pm - 3:15 pmLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
3:15 pm[Closing Keynote] The Strategic Security Debate: Defending the 'Least Bad' Decisions in a CrisisCISO, KP LLCRegistration Level:
Open Sessions
3:15 pm - 4:00 pmLocation / Room: Keynote TheaterIn the world of enterprise cybersecurity, there are rarely perfect solutions—only difficult trade-offs. Join us for an unscripted, high-energy session where top-tier security leaders face off on the industry’s toughest hypothetical scenarios.Moderated in a rapid-fire game show format, our panelists will be presented with difficult “Would You Rather” choices ranging from ransomware negotiation dilemmas and crippling technical debt to extreme budget constraints and the “secure-by-default” friction that can stall business innovation. They won’t just pick a side; they have to defend it against a panel of their peers.Attendees will gain a unique window into the strategic minds of seasoned CISOs, understanding how they weigh business continuity against forensic integrity, and rapid digital transformation against long-term risk management. Come ready to vote on who makes the best case for the “least bad” situation in an era where cybersecurity is a fundamental pillar of national and economic resilience.4:00 pmHappy HourRegistration Level:
Open Sessions
4:00 pm - 5:00 pmLocation / Room: Networking HallJoin your peers for conversation and complimentary beverages. This is a great opportunity to network with other security professionals from the area and discuss the hot topics from the day.
4:00 pm[PLUS Course] Securing & Enabling AI: Transform Chaos into Competitive Advantage - Part 2Registration Level:
SecureWorld Plus
4:00 pm - 5:30 pmCome join this interactive workshop — think hands-on working groups so you are an active participant…this is not 6 hours of being lectured at.
Learn how to secure AI while accelerating innovation—not blocking it. Transform from AI Firefighter to Strategic Business Enabler, with a 90-day roadmap for secure AI deployment in your organization.
Why this course? Imagine your CEO just asked about AI security. Do you have an answer?
While you’re counting vulnerabilities, your competitors are deploying AI at scale.
Every Monday, another department launches an AI tool. Marketing uses ChatGPT for campaigns. Sales deploys AI Sales Development Reps. Customer service automates with chatbots.
And your cybersecurity team? Still writing policies nobody reads.
You’ll master:• The AIR-MAP Methodology™ — Your proven 90-day roadmap from AI chaos to governance• Executive Translation — Turn technical AI risks into boardroom language• NIST AI RMF Implementation — Practical application, not theory• The $12M Question — Secure against deepfake fraud and AI-enabled attacks• Shadow AI Discovery — Find and govern the AI already in your organization• Business-First Security — Protect value, not just systemsWho should attend:Perfect fit:• CISOs facing board questions about AI• Information Security Directors enabling digital transformation• IT VPs without dedicated security teams• Cybersecurity Consultants serving enterprise clients• Risk Managers governing AI initiatives• Aspiring decision makers and those reporting to oneWrong course:• Developers wanting to code AI models• Analysts seeking technical certifications• Anyone looking for hands-on hacking labsThis workshop is NOT about:• Prompt injection techniques• Model architecture security• Technical vulnerability scanning• Writing 200-page policiesThis workshop IS about:• Speaking profit-and-loss to executives• Enabling your AI transformations• Building cybersecurity into AI from day one• Becoming the trusted AI advisorYou’ll leave with:1. The Complete AIR-MAP Toolkit• 90-day implementation roadmap• Discovery templates and workflows• Risk scoring calculators• Executive presentation templates2. Ready-to-Deploy Policies• AI Acceptable Use Policy (customize in minutes)• Vendor assessment questionnaires• Incident Response playbooks3. 30-Minute Strategy SessionComplementary private consultation to apply AIR-MAP to your specific situation.4:00 pm[PLUS Course] Master the NIST Cybersecurity Framework v2.0 in Just Six Hours - Part 2Registration Level:
SecureWorld Plus
4:00 pm - 5:30 pmThis intensive, live workshop is your shortcut to cyber resilience mastery. In just one power-packed day, you’ll walk away with:
- Complete mastery of NIST CSF 2.0 – Understand every component and why it matters to YOUR business
- Your personalized Cyber Risk Map – Identify your organization’s exact vulnerabilities and blind spots
- A step-by-step action plan – No more guessing what to do next
- Real-world case studies – See how organizations just like yours have successfully implemented the framework
- Expert-level confidence – Finally speak cybersecurity with authority and clarity
What makes this different?
This isn’t another theoretical lecture. You’ll spend most of your time actually BUILDING your organization’s cybersecurity roadmap using the proven Cyber Risk Management Action Plan (CR-MAP) methodology. You’ll leave with tools and know-how you can implement immediately.Perfect for:
- IT Directors and Managers
- Cybersecurity Professionals
- Business Leaders responsible for risk management
- Compliance Officers
- Anyone tasked with “figuring out cybersecurity”
Exclusive Bonus: Every attendee receives our comprehensive digital CR-MAP Online Workbook ($197 value), your step-by-step guide to:
- Getting BUY-IN from your senior decision makers
- Discovering your top five cyber risks
- Creating a prioritized risk mitigation plan with implementation roadmap
- A score card you can use to track progress
Warning: This live, in-person intensive has limited seating. Don’t let another cyber incident catch your organization unprepared.
Your organization’s cybersecurity can’t wait. Register now.
- Thursday, November 5, 20267:00 amRegistration openRegistration Level:
Open Sessions
7:00 am - 4:15 pmLocation / Room: Registration Desk / LobbyCome to the Registration desk in the lobby to check-in and get your badge. SecureWorld staff will be available throughout the day if you have any questions.
7:30 am[PLUS Course] Securing & Enabling AI: Transform Chaos into Competitive Advantage - Part 3Registration Level:
SecureWorld Plus
7:30 am - 9:00 amCome join this interactive workshop — think hands-on working groups so you are an active participant…this is not 6 hours of being lectured at.
Learn how to secure AI while accelerating innovation—not blocking it. Transform from AI Firefighter to Strategic Business Enabler, with a 90-day roadmap for secure AI deployment in your organization.
Why this course? Imagine your CEO just asked about AI security. Do you have an answer?
While you’re counting vulnerabilities, your competitors are deploying AI at scale.
Every Monday, another department launches an AI tool. Marketing uses ChatGPT for campaigns. Sales deploys AI Sales Development Reps. Customer service automates with chatbots.
And your cybersecurity team? Still writing policies nobody reads.
You’ll master:• The AIR-MAP Methodology™ — Your proven 90-day roadmap from AI chaos to governance• Executive Translation — Turn technical AI risks into boardroom language• NIST AI RMF Implementation — Practical application, not theory• The $12M Question — Secure against deepfake fraud and AI-enabled attacks• Shadow AI Discovery — Find and govern the AI already in your organization• Business-First Security — Protect value, not just systemsWho should attend:Perfect fit:• CISOs facing board questions about AI• Information Security Directors enabling digital transformation• IT VPs without dedicated security teams• Cybersecurity Consultants serving enterprise clients• Risk Managers governing AI initiatives• Aspiring decision makers and those reporting to oneWrong course:• Developers wanting to code AI models• Analysts seeking technical certifications• Anyone looking for hands-on hacking labsThis workshop is NOT about:• Prompt injection techniques• Model architecture security• Technical vulnerability scanning• Writing 200-page policiesThis workshop IS about:• Speaking profit-and-loss to executives• Enabling your AI transformations• Building cybersecurity into AI from day one• Becoming the trusted AI advisorYou’ll leave with:1. The Complete AIR-MAP Toolkit• 90-day implementation roadmap• Discovery templates and workflows• Risk scoring calculators• Executive presentation templates2. Ready-to-Deploy Policies• AI Acceptable Use Policy (customize in minutes)• Vendor assessment questionnaires• Incident Response playbooks3. 30-Minute Strategy SessionComplementary private consultation to apply AIR-MAP to your specific situation.7:30 am[PLUS Course] Master the NIST Cybersecurity Framework v2.0 in Just Six Hours - Part 3Registration Level:
SecureWorld Plus
7:30 am - 9:00 amThis intensive, live workshop is your shortcut to cyber resilience mastery. In just one power-packed day, you’ll walk away with:
- Complete mastery of NIST CSF 2.0 – Understand every component and why it matters to YOUR business
- Your personalized Cyber Risk Map – Identify your organization’s exact vulnerabilities and blind spots
- A step-by-step action plan – No more guessing what to do next
- Real-world case studies – See how organizations just like yours have successfully implemented the framework
- Expert-level confidence – Finally speak cybersecurity with authority and clarity
What makes this different?
This isn’t another theoretical lecture. You’ll spend most of your time actually BUILDING your organization’s cybersecurity roadmap using the proven Cyber Risk Management Action Plan (CR-MAP) methodology. You’ll leave with tools and know-how you can implement immediately.Perfect for:
- IT Directors and Managers
- Cybersecurity Professionals
- Business Leaders responsible for risk management
- Compliance Officers
- Anyone tasked with “figuring out cybersecurity”
Exclusive Bonus: Every attendee receives our comprehensive digital CR-MAP Online Workbook ($197 value), your step-by-step guide to:
- Getting BUY-IN from your senior decision makers
- Discovering your top five cyber risks
- Creating a prioritized risk mitigation plan with implementation roadmap
- A score card you can use to track progress
Warning: This live, in-person intensive has limited seating. Don’t let another cyber incident catch your organization unprepared.
Your organization’s cybersecurity can’t wait. Register now.
8:00 amNetworking Hall & SecureWorld Gaming Village OpenRegistration Level:
Open Sessions
8:00 am - 3:15 pmLocation / Room: Networking HallYour opportunity to visit our solution vendor partners, whose sponsorship makes SecureWorld possible, as well as association chapters! Booths have staff ready to answer your questions. Look for participating Dash For Prizes sponsors to be entered to win prizes.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5.
Participate in one or all three gaming options:
- Medusa’s Memory Heist – Created by Microsoft’s Artificial Generative Intelligence Safety & Security Team, Medusa’s Memory Heist is a collection of five mini-games that teach the fundamentals of AI Security: Threat Modeling, Red Teaming, Defense, Logging, and Incident Response. Step up to one of the available laptops and see if you can!
- Defense in Depth Starts at the Door: Lockpick Village from Seattle Locksport – You can’t achieve great cybersecurity without physical security. At the Lockpick Village, hosted by Seattle Locksport, attendees get hands-on experience defeating real-world locking mechanisms, from entry-level padlocks to higher-security hardware. Learn the fundamentals of pin tumbler mechanisms, try your hand with picks and tension tools, and walk away with a sharper eye for physical vulnerabilities. Beginners are welcome; we’ll have all the equipment needed to give it a try.
- AI Security Interactive Game – details TBD
8:00 amAdvisory Council Roundtable Breakfast (VIP / Invite only)Registration Level:
VIP / Exclusive
8:00 am - 8:45 amModerated discussion for SecureWorld Advisory Council members. By invite only.
8:00 amAssociation Chapter MeetingsRegistration Level:
Open Sessions
8:00 am - 8:45 amParticipating professional associations and details to be announced.
9:00 am[Opening Keynote] The AI Train Isn't Stopping—What Cybersecurity Does NextCISO, Pacific Blue Cross & PBC SolutionsVP & CISO, Premera Blue CrossRegistration Level:
Open Sessions
9:00 am - 9:45 amLocation / Room: Keynote TheaterAI isn’t slowing down. It’s writing code. Agents are showing up in tools your team never approved. Whatever hesitation exists in the boardroom about cost or risk, the train keeps moving—fast, and often in directions nobody sees until they’ve already arrived. The question isn’t whether AI keeps accelerating. It’s what we do while it does.
This opening keynote brings security leaders together for a candid, unscripted conversation about the tensions nobody has fully resolved: Can you argue some jobs shouldn’t be replaced by AI and still stay competitive? What guardrails do we actually need when adoption outpaces governance? How do you enable AI agents—web-based, local, or buried in third-party tools—without losing visibility into your own data? No hype, no vendor spin—just an honest look at a moment of real uncertainty, and the kind of peer conversation that sends everyone home with more clarity than they came in with.
9:45 amNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
9:45 am - 10:10 amLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
10:10 am10 Questions Your Vendor Hopes You Never AskSecurity Specialist, Customer Trust & Third-Party Risk, FigmaRegistration Level:
Conference Pass
10:10 am - 10:45 amNearly every vendor has embedded AI into their product. Most organizations updated their vendor risk questionnaires but are still asking the wrong questions. Industry research shows that 90% of security leaders report AI visibility, yet nearly six in 10 confirm that ungoverned AI systems exist in their environment. This session presents 10 questions your vendor assessments are missing, drawn from published agentic AI threat models and real supply chain breach evidence from 2025 and 2026. For each question, we cover why standard questionnaires skip it and what a defensible risk decision looks like.
Leave with 10 practitioner-tested questions that expose the gaps between what AI vendors promise and what your current assessment process actually evaluates.
10:10 amLLMs and Agents as Co-Attacker: When Ransomware Weaponizes Your AI CopilotFounder & CTO, Vishva PathShalaRegistration Level:
Conference Pass
10:10 am - 10:45 amHackers are no longer installing malware on their systems, but AI. Such groups as Akira, Qilin, and Scattered Spider have incorporated LLM-powered agents into their attack pipelines to automate spear phishing, generate adaptive exploit code, and do reconnaissance without human supervision. At the same time, the enterprise AI approved developer’s productivity copilots are being backdoored internally, fooled by indirect prompt injection into exfiltrating credentials, circumventing DLP controls, and helping lateral movement.
This session reveals two faces of the menace: the ransomware hackers will use LLMs and agents in adversarial mode, and the chain of attack that transforms your own approved copilot into an accomplice. Using real-world patterns of attacks, adversary intelligence examples of SentinelLABS and Trend Micro, on-stage demonstrations, the attendees will not only observe how these attacks occur but also walk out with a tangible playbook of defense controls: detection signatures, copilot guardrails and governance controls to ensure their AI tools do not become insider threats.
10:10 amMoving Supply Chain Security from a Compliance Checkbox to a Trust-Building EngineSecurity Technical Program Manager, Blue YonderDirector, Cyber Trust, Blue YonderSVP, Global Chief Security Officer, Blue YonderRegistration Level:
Conference Pass
10:10 am - 10:45 amSupply chain breaches cost Fortune 500 companies $4.3M on average—and that’s just the direct cost. The hidden cost? Lost customer trust, damaged reputation, and vendor partner friction that lingers for years.
This session reframes supply chain security from a compliance checkbox into a trust-building engine that drives customer confidence, reduces friction, and unlocks new revenue streams. Learn how to build an “Office of Trust”—a security function that is proactive, transparent, and customer-centric—and why cyber communications should be as strategic as your security operations.
We’ll cover real examples from supply chain incidents, the anatomy of proactive cyber comms (what works, what backfires), and a 90-day roadmap to launch your own Office of Trust.
10:45 amNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
10:45 am - 11:10 amLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
11:10 amMentor Speed Dating: Roundtables on the Real-World Security LandscapeRegistration Level:
Conference Pass
11:10 am - 11:45 am-
How Do You Say No (and Actually Be Heard)? — Security professionals at every level constantly face pressure to approve things they shouldn’t, meet timelines that cut corners, or stay quiet in rooms where decisions are being made above them. This session, moderated by Ann Robinson, covers how to push back effectively, how to frame risk in business terms, and how to build credibility so your “no” carries weight. CISOs have years of hard lessons here that early-career professionals rarely get exposed to.
-
When the Audit Passes but You’re Still Not Secure: Compliance vs. Real Risk — Compliance frameworks (SOC 2, NIST, ISO 27001, PCI-DSS) are often the first language early-career professionals learn—but seasoned practitioners know they’re a floor, not a ceiling. Jonathan Barrios explores the gap between checking boxes and actually reducing risk, how to prioritize when you can’t do everything, and how to use compliance as a tool without letting it drive the entire program. A topic that generates strong opinions and real debate at every level.
11:10 amThe Authorization Problem Nobody Solved Before Giving AI Agents the KeysSr. Security Engineer, AppleRegistration Level:
Conference Pass
11:10 am - 11:45 amAI agents are being deployed across enterprise environments with the ability to call APIs, read files, execute code, and take actions on behalf of users. They chain tool calls, delegate to other agents, and operate without human review at each step. The authorization controls most organizations have in place were simply not designed for this.
This session examines what goes wrong when agents inherit human permissions, how privilege escalates through multi-agent workflows, and why existing controls create a false sense of security. It also covers what the industry is building to address the gap—emerging standards for agent identity, authorization APIs, and real-time trust signaling—and what security teams can do today without waiting for broad adoption.
11:10 am[Panel] The Human Layer: Insider Risk, Behavioral Analytics, and the AI Threat Multiplier
Panel DiscussionRegistration Level:
Open Sessions
11:10 am - 11:45 amPeople have always been the most targeted layer in any organization’s security posture—but AI is rewriting the rules of engagement. Sophisticated phishing campaigns now arrive personalized at scale, deepfake audio and video are eroding the credibility of internal communications, and MFA fatigue attacks are turning security controls against the users they were designed to protect. The threat surface hasn’t changed, but the speed, precision, and plausibility of attacks targeting it have.
At the same time, defenders are gaining new tools. Behavioral analytics and UEBA platforms are surfacing anomalies that static rules would miss, and AI-assisted policy frameworks are helping organizations govern workforce behavior—including how employees interact with AI tools themselves—without sacrificing productivity. This panel brings together practitioners navigating insider risk, identity-based threats, and the governance questions that arise when the line between human error and AI-augmented deception becomes increasingly hard to draw.
11:10 amA Hybrid Approach to Critical Infrastructure Vulnerability Assessment and GovernanceFounder, Public Value LLCRegistration Level:
Conference Pass
11:10 am - 11:45 amWe can no longer afford to view the critical infrastructure as two separate domains: 1) Physical and 2) Cyber. Today’s critical infrastructure is interconnected, intertwined, and/or fused where an event in one attribute affects the other simultaneously, or in parallel. Therefore, the modern critical infrastructure must be assessed and governed holistically.
The country needs a hybrid vulnerability assessment and governance framework that finds and closes vulnerabilities before America’s adversaries find them.
11:45 amNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
11:45 am - 12:00 pmLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
12:00 pm[Lunch Keynote] You Be the CISO: A Live AI Breach SimulationRegistration Level:
Open Sessions
12:00 pm - 12:45 pmLocation / Room: Keynote TheaterA customer support rep pastes a batch of unredacted tickets into a free AI chatbot to save 20 minutes on a slow afternoon. Three weeks later, it lands on the CISO’s desk. This session puts the room in the driver’s seat of exactly that moment—attendees vote live from their phones at each turning point in the incident, from the first discovery through disclosure and the board’s demand for a fix, watching in real time how the room’s instincts split and where they align.
Rather than a lecture on AI risk, this is a hands-on decision exercise grounded in current breach research, revealing how the choices made in the first hours of a data exposure shape everything that follows—legally, financially, and reputationally. Attendees leave with a sharper instinct for how AI-related incidents actually unfold inside an organization, and where the highest-leverage decisions really sit.
12:00 pmAdvisory Council Roundtable (VIP / Invite only)Achieving True Resilience in the AI EraRegistration Level:
VIP / Exclusive
12:00 pm - 12:45 pmIn the cybersecurity arena, AI technology presents new possibilities for both defenders and attackers. The key to withstanding the next evolution of cyber threats? A resilient identity infrastructure.
Whether your organization uses a specific vendor tool or runs a mix of systems and solutions, identity is your digital foundation of trust. If identity is compromised, your organization’s ability to operate is at risk.
Join this closed-door, invitation-only, peer-to-peer discussion to learn insights and practical strategies for building your identity, cyber, and business resilience. This open forum exchange explores:
- ·What does it take to plan for true cyber resilience?
- What happens when your identity infrastructure is under attack?
- How do you manage the complexities of a hybrid identity environment?
- How can security, identity, IT, and business leaders work together to ensure resilience across the entire cyber lifecycle?
This session is generously sponsored by:
12:45 pmNetworking BreakAnd visit the SecureWorld Gaming VillageRegistration Level:
Open Sessions
12:45 pm - 1:10 pmLocation / Room: Networking HallVisit the Networking Hall to connect with attendees and meet our supporting solution providers and association partners.
In addition, take part in one of three interactive areas in the SecureWorld Gaming Village in the Networking Hall, happening from 8 a.m. to 4:30 p.m. on Day 1, Wednesday, Nov. 4, and from 8 a.m. to 3:15 p.m. on Day 2, Thursday, Nov. 5. More details here: https://events.secureworld.io/agenda/seattle-wa-2026/#20030
1:10 pm[Panel] Resilience Engineering: Incident Response, Business Continuity, and Cyber InsuranceFocus Areas: Operational Resilience & BCP; Incident Response & Crisis Management; Cyber Insurance & Executive ReportingRegistration Level:
Conference Pass
1:10 pm - 1:45 pmResilience has shifted from a compliance task to a vital business skill. This panel explores how organizations prepare for disruptive cyber incidents involving multi-cloud setups, SaaS dependencies, supply chain issues, and rapid ransomware attacks. With experts in incident response, digital forensics, MDR, insurance, and crisis management, the panel emphasizes developing response playbooks that mirror current operational dependencies.
Panelists will explore insurer-driven requirements for identity security and MFA, lessons from major SaaS outages, and how to communicate effectively with executives and boards when downtime impacts revenue-critical operations. Attendees will gain a comprehensive understanding of how to engineer resilience—not just respond—and how to align IR, continuity planning, insurance, and business priorities into a unified, enterprise-wide strategy.
1:10 pmQuantifying Security Debt: Communicating Risk and Driving Remediation with the CFORegistration Level:
Conference Pass
1:10 pm - 1:45 pmSession details to come.
1:10 pm[Panel] The Agile Security Professional: Navigating Non-Linear Paths to the TopAssistant Director, Information Security, Port of SeattleVP, Head of Internal Audit, DocuSignRegistration Level:
Open Sessions
1:10 pm - 1:45 pmIn a field where threat vectors shift overnight and technologies evolve constantly, adaptability isn’t just a soft skill—it’s a core security requirement. Yet, navigating a career in cybersecurity rarely follows a straight line. Success often hinges on knowing when to shift gears, expand your skill set, or take calculated risks to enter a new domain.
In this candid and empowering session, a panel of accomplished leaders across cybersecurity explore the art of the career pivot. From moving between technical and strategic roles to transitioning into security from non-traditional backgrounds, these leaders share the pivotal moments that shaped their journeys. They’ll dive into how to recognize new opportunities, overcome career friction, build a supportive network, and translate core strengths into entirely new roles.
Whether you’re aiming for a promotion, considering a shift into a new security specialization, or looking to bounce back from an unexpected career change, this discussion will give you the roadmap to navigate your next move with confidence.
1:45 pmNetworking Break & Cyber ConnectFinal Entries for Dash for Prizes and PassportRegistration Level:
Open Sessions
1:45 pm - 2:10 pmLocation / Room: Networking HallThis is your final chance to visit the Networking Hall and get scanned by our participating partners for our Dash for Prizes. You can also turn in your Passport cards at the Registration Desk before we announce our winner!
2:10 pmOne Request to Rule Them AllChief Hacking Officer, APIsec UniversityRegistration Level:
Conference Pass
2:10 pm - 2:45 pmOne API request, aimed at the right endpoint, can compromise an entire organization. When an API answers without checking who is really asking, a single call can read any record, act as any user, and seize the powers meant for admins alone.
In this rapid-fire, hands-on workshop, you’ll go from zero to hacking your first API in 35 minutes. You’ll find and exploit the most common REST API vulnerabilities in real time, hands on the keyboard, against a live target. No prior hacking experience required. APIs are one of the best first vectors for learning offensive security, and by the end, you’ll have worked the OWASP API Security Top 10 by breaking an API yourself.
Built for beginners and practitioners who want quick, practical techniques they can use the next day—with some fun along the way.
2:10 pmBeyond Login: Designing Identity Controls for Modern Enterprise ProductsMember of Technical Staff, OpenAIRegistration Level:
Conference Pass
2:10 pm - 2:45 pmEnterprise identity can no longer be reduced to a login gate. Modern products span admin consoles, workspaces, APIs, and privileged workflows, often across multiple identity providers and assurance levels. This session presents a vendor-neutral architecture that separates principal eligibility, resource authentication requirements, and session assurance. It examines common failures in coarse-grained SSO and shows how teams can introduce stronger controls using policy evaluation, shadow decisions, decision logging, staged enforcement, and rollback safeguards without causing widespread access failures or creating brittle user experiences.
Attendees will leave with a practical architecture and rollout checklist for building resource-aware authentication and authorization controls across complex enterprise products.
2:10 pm[Panel] The Great Consolidation: Rationalizing the Security StackFocus Areas: Security Stack Consolidation; SecOps Efficiency & ROI; Unified Detection & Response (XDR/SIEM Integration)Head of Global Threat Intelligence, Google CloudRegistration Level:
Open Sessions
2:10 pm - 2:45 pmSecurity teams are under increasing pressure to reduce tool sprawl, streamline SOC workflows, and demonstrate measurable ROI—fueling a wave of consolidation across the industry. This panel explores the shift toward unified detection and response platforms, integrated identity and data controls, AI-enabled SOC copilots that unify telemetry, and architectural simplification that reduces operational drag.
Panelists from XDR, SIEM, platform security, and MSSP providers will discuss frameworks for evaluating ROI, navigating contract consolidation, avoiding visibility gaps, and deciding where consolidation strengthens or weakens security posture. Ideal for leaders facing budget constraints or platform migrations, this session offers practical guidance for optimizing spending without sacrificing coverage.
2:45 pmDash for PrizesRegistration Level:
Open Sessions
2:45 pm - 3:15 pmLocation / Room: Networking HallParticipating sponsors will announce their Dash for Prizes winners. Must be present to win.
3:15 pm[PLUS Course] Securing & Enabling AI: Transform Chaos into Competitive Advantage - Part 4Registration Level:
SecureWorld Plus
3:15 pm - 4:45 pmCome join this interactive workshop — think hands-on working groups so you are an active participant…this is not 6 hours of being lectured at.
Learn how to secure AI while accelerating innovation—not blocking it. Transform from AI Firefighter to Strategic Business Enabler, with a 90-day roadmap for secure AI deployment in your organization.
Why this course? Imagine your CEO just asked about AI security. Do you have an answer?
While you’re counting vulnerabilities, your competitors are deploying AI at scale.
Every Monday, another department launches an AI tool. Marketing uses ChatGPT for campaigns. Sales deploys AI Sales Development Reps. Customer service automates with chatbots.
And your cybersecurity team? Still writing policies nobody reads.
You’ll master:• The AIR-MAP Methodology™ — Your proven 90-day roadmap from AI chaos to governance• Executive Translation — Turn technical AI risks into boardroom language• NIST AI RMF Implementation — Practical application, not theory• The $12M Question — Secure against deepfake fraud and AI-enabled attacks• Shadow AI Discovery — Find and govern the AI already in your organization• Business-First Security — Protect value, not just systemsWho should attend:Perfect fit:• CISOs facing board questions about AI• Information Security Directors enabling digital transformation• IT VPs without dedicated security teams• Cybersecurity Consultants serving enterprise clients• Risk Managers governing AI initiatives• Aspiring decision makers and those reporting to oneWrong course:• Developers wanting to code AI models• Analysts seeking technical certifications• Anyone looking for hands-on hacking labsThis workshop is NOT about:• Prompt injection techniques• Model architecture security• Technical vulnerability scanning• Writing 200-page policiesThis workshop IS about:• Speaking profit-and-loss to executives• Enabling your AI transformations• Building cybersecurity into AI from day one• Becoming the trusted AI advisorYou’ll leave with:1. The Complete AIR-MAP Toolkit• 90-day implementation roadmap• Discovery templates and workflows• Risk scoring calculators• Executive presentation templates2. Ready-to-Deploy Policies• AI Acceptable Use Policy (customize in minutes)• Vendor assessment questionnaires• Incident Response playbooks3. 30-Minute Strategy SessionComplementary private consultation to apply AIR-MAP to your specific situation.3:15 pm[PLUS Course] Master the NIST Cybersecurity Framework v2.0 in Just Six Hours - Part 4Registration Level:
SecureWorld Plus
3:15 pm - 4:45 pmThis intensive, live workshop is your shortcut to cyber resilience mastery. In just one power-packed day, you’ll walk away with:
- Complete mastery of NIST CSF 2.0 – Understand every component and why it matters to YOUR business
- Your personalized Cyber Risk Map – Identify your organization’s exact vulnerabilities and blind spots
- A step-by-step action plan – No more guessing what to do next
- Real-world case studies – See how organizations just like yours have successfully implemented the framework
- Expert-level confidence – Finally speak cybersecurity with authority and clarity
What makes this different?
This isn’t another theoretical lecture. You’ll spend most of your time actually BUILDING your organization’s cybersecurity roadmap using the proven Cyber Risk Management Action Plan (CR-MAP) methodology. You’ll leave with tools and know-how you can implement immediately.Perfect for:
- IT Directors and Managers
- Cybersecurity Professionals
- Business Leaders responsible for risk management
- Compliance Officers
- Anyone tasked with “figuring out cybersecurity”
Exclusive Bonus: Every attendee receives our comprehensive digital CR-MAP Online Workbook ($197 value), your step-by-step guide to:
- Getting BUY-IN from your senior decision makers
- Discovering your top five cyber risks
- Creating a prioritized risk mitigation plan with implementation roadmap
- A score card you can use to track progress
Warning: This live, in-person intensive has limited seating. Don’t let another cyber incident catch your organization unprepared.
Your organization’s cybersecurity can’t wait. Register now.
- APIsec UniversityBooth: TBD
APIsec University was founded with a simple yet powerful mission: to make world-class API security education accessible to everyone, regardless of their background or financial situation.
As APIs have become the backbone of modern applications, the need for skilled security professionals has never been greater. We recognized that traditional education paths weren’t keeping pace with the rapidly evolving API landscape.
Today, we’re proud to serve over 135,000 students worldwide, offering comprehensive, free courses that cover everything from API security fundamentals to advanced penetration testing techniques. Our community includes developers, security professionals, and anyone passionate about building more secure digital experiences.
- C1Booth: TBD
C1’s Cybersecurity Solutions deliver advanced protection across networks, users, applications, endpoints, and cloud environments. Designed to ease the burden on IT teams, our services simplify security management, enhance efficiency, and proactively defend against emerging threats, ensuring your enterprise remains resilient and secure. C1 collaborates with most of the Fortune 100 companies along with other key global industry partners to deliver solutions with a total lifecycle approach. C1 holds more than 5,600 technical certifications across thousands of engineers throughout North America, including three Customer Success Centers.
- Canary TrapBooth: TBD
Canary Trap is a recognized industry leader in offensive security, security advisory and assessment services. Founded by ethical hackers and certified security experts who share in the common goal of protecting organizations from becoming a victim of the next cyber-attack.
Canary Trap combines human expertise with sophisticated tools and, where appropriate, threat intelligence to ensure a thorough, in-depth approach to all security testing and assessments.
- CensysBooth: TBD
Censys is the one place to understand everything on the internet. We have built and operate the world’s largest internet scanning infrastructure and we empower organizations, individuals and security researchers by providing unparalleled visibility into the global internet landscape. We see more of the internet than anyone else, which gives us the most comprehensive internet visibility in the world. Our two main use cases are attack surface management and threat hunting with so many more on the horizon. Through our comprehensive internet data, we strive to enhance cybersecurity, facilitate data-driven decision-making, and reduce internet exposures for commercial and government organizations across the globe.
- Cloud Security Alliance SeattleBooth: TBD
The Greater Seattle Chapter of the Cloud Security Alliance (CSA) is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing in the Pacific Northwest, and provide education on the uses of Cloud Computing to help service providers and customers be secure in the Cloud.
The Greater Seattle Chapter began in late 2010, led by Vivek Bhatnagar and Marc Pinotti, with our first Chapter Meeting held March 24th 2011. Our membership since then has grown to include corporate sponsors and over 1100 executive and senior level security, compliance, and IT professionals from throughout the entire Pacific Northwest, Western Canada, and Alaska.
The Chapter provides a venue for our Members to network, share ideas and research, as well as educational opportunities through quarterly seminars and monthly Chapter meetings that feature presentations by industry experts about Cloud issues, security, and technology.
- Cohesity, IncBooth: TBD
We believe that simplicity is the foundation of modern data management. Our mission is to radically simplify how organizations manage their data and unlock limitless value. The company develops software that allows IT professionals to backup, manage, and gain insights from their data across multiple systems or cloud providers.
- Concentric AIBooth: TBD
Concentric AI is intelligent data security made easy. Its Semantic Intelligence™ platform uses context-aware AI to discover sensitive data, monitor risks, automate remediation, simplify compliance, and accelerate investigations. It delivers smart, targeted protection by understanding how data is used, shared, and exposed. Concentric AI also offers managed services to keep security programs lean, scalable, and effective. This end-to-end platform protects data at rest, data in motion, and all the GenAI tools users interact with—so organizations can stay compliant, reduce exposure, and safeguard critical information wherever it lives and however it travels.
- CyberhavenBooth: TBD
When the DLP market first emerged 20 years ago, the goal was to protect confidential information in on-premises databases, file servers, application servers, other data repositories, and endpoints. Today millions of sensitive documents, files, and other data are being exfiltrated in violation of corporate data policies every day because DLP is completely ineffective in the era of cloud-first applications and Zero Trust security. These data breaches result in stolen IP, damaged brands, and significant financial penalties. Let’s face it, DLP in its current form is nothing more than a compliance checkbox. Cyberhaven is transforming the DLP market and helping organizations secure all of the high-value data they must protect in order to compete and thrive in the digital economy. It’s a big hairy problem, and we are up to the challenge.
- DashlaneBooth: TBD
Dashlane provides complete credential security, protecting businesses against the threat of human risk. Our intelligent Omnix™ platform unifies credential protection and password management, equipping security teams with proactive intelligence, real-time response, and protected access to secure every employee. Over 25,000 brands worldwide, including leading enterprises such as Michelin, Air France, and Forrester, trust Dashlane for industry-leading innovations, patented zero-knowledge security, and an unmatched user experience.
- DHS Cybersecurity and Infrastructure Security Agency (CISA), Region 10Booth: TBD
Through CISA’s efforts to understand and advise on cyber and physical risks to the Nation’s critical infrastructure, we help partners strengthen their own capabilities. We connect our stakeholders in industry and government to each other and to resources, analyses, and tools to help them build their own cyber, physical and communications security, and, in turn, strengthen national resilience.
Led by Regional Director Patrick J. Massey, based in Seattle, Washington, CISA’s Region 10 staff provides cybersecurity, physical infrastructure security, chemical security, and sector outreach services to 271 Tribal Nations and the following states: Alaska, Idaho, Oregon, and Washington.
Region 10 personnel carry out CISA’s five priorities:
- Improve supply chain security against cyber threats from malicious actors and the rollout of 5G technologies;
- Harden federal networks (the civilian .gov domain);
- Reduce risk at soft targets;
- Enhance election security; and
- Protect critical infrastructure that includes industrial control systems and the processes that provide vital services in critical infrastructure.
- Dropzone AIBooth: TBD
Dropzone AI weaponizes LLMs for cyber defenders, delivering the Agentic SOC: AI agents that collaborate 24/7 to beat attackers at scale. Dropzone is ready to go on Day 1 and integrates into your existing tools. AI agents start work immediately to investigate alerts, respond to emerging threats, and proactively hunt attackers. Autonomously and infinitely scalable, with no hidden humans in the critical path. Dropzone works with enterprises and MSSPs including ECS, Avalara, UiPath, and Zapier, and is actively protecting over 300 companies. Learn more at www.dropzone.ai.
- DTEXBooth: TBD
DTEX is the leader in risk-adaptive security, unifying human, data, and AI risk through a behavioral intelligence platform built for enterprise scale to detect threats early and prevent breaches.
- FlareBooth: TBD
Flare Systems enables financial institutions to prevent financial crime. Using AI and over 10 years of criminology research, it extracts actionable intelligence from millions of data points from the dark, deep and clear web in real time.
- FortinetBooth: TBD
Fortinet (NASDAQ: FTNT) secures the largest enterprise, service provider, and government organizations around the world. Fortinet empowers its customers with intelligent, seamless protection across the expanding attack surface and the power to take on ever-increasing performance requirements of the borderless network—today and into the future. Only the Fortinet Security Fabric architecture can deliver security without compromise to address the most critical security challenges, whether in networked, application, cloud, or mobile environments. Fortinet ranks number one in the most security appliances shipped worldwide and more than 500,000 customers trust Fortinet to protect their businesses.
- Gambit SecurityBooth: TBD
Gambit’s Balens is the AI native resilience platform that ensures digital continuity never expires.
Designed to bridge the fragmented nature of recovery operations, Gambit provides a unified governance and control plane across cloud, backups, security tools, and Infrastructure as Code (IaC) to reconcile intent with live reality.
By mapping applications, identifying resilience gaps, and validating recovery paths in real-time, Gambit turns resilience assumptions into business certainty—before an incident ever occurs.
Already trusted by global enterprises to minimize disruption and automate compliance, Gambit enables organizations to stay ahead of ransomware attacks, innovate at speed while proving their recoverability on demand.
- Google Cloud SecurityBooth: TBD
Google Cloud Security provides organizations with leading infrastructure, platform capabilities and industry solutions to help them solve their most critical business problems. Google Cloud Security helps customers protect their global operations with solutions such as zero trust security, application and data protection, fraud prevention, and threat detection and response.
- HarnessBooth: TBD
Harness is a rapidly growing startup that is disrupting the software delivery market. The Harness Software Delivery Platform includes product modules for every aspect of software delivery, including: Continuous Integration, Continuous Delivery, Feature Flags, Cloud Cost Management, Service Reliability Management, Security Testing Orchestration, Chaos Engineering, Software Engineering Insights, Continuous Error Tracking, Code Repository, Internal Developer Portal, Software Supply Chain Assurance, Infrastructure as Code Management and AI/ML infused throughout with AI Development Assistant (AIDA). The platform is designed to help companies accelerate their cloud initiatives as well as their adoption of containers and orchestration tools like Kubernetes and Amazon ECS and make software delivery easier, giving devs their nights and weekends back.
- Washington State InfraGardBooth: TBD
InfraGard is a partnership of individuals representing businesses, academic institutions, state and local law enforcement agencies, and communities who are dedicated to collaborating and sharing information to prevent hostile acts against the United States.
The Evergreen InfraGard Members Alliance area of operation is Washington State and over 600 members. As part of the Western Region, we work closely with the IMAs in Los Angeles, San Diego, Oregon, and Idaho. Our chapter’s mission is, “To protect Washington State’s Infrastructure and critical services by providing a secure platform and trusted community to share experiences and information.”
- ISC2 Seattle ChapterBooth: TBD
Bringing like-minded professionals together in the Greater Puget Sound region to discuss current tactics, techniques, and procedures within cybersecurity.
- ISSA Puget Sound ChapterBooth: TBD
ISSA is the community of choice for international cybersecurity professionals dedicated to advancing individual growth, managing technology risk and protecting critical information and infrastructure.
The Information Systems Security Association (ISSA)® is a not-for-profit, international organization of information security professionals and practitioners. It provides educational forums, publications, and peer interaction opportunities that enhance the knowledge, skill, and professional growth of its members. Join today.
- IvantiBooth: TBD
Ivanti is a global enterprise IT and security software company that provides the trusted data authority for AI-driven, autonomous endpoint management. Ivanti connects IT and security operations data in a unified system of record—giving teams clear visibility of every device in their environment, and the ability to intelligently manage risk.
With automated remediation and self-healing capabilities, IT and security teams can agree on governance, proactively and autonomously resolve issues and operate at scale. At the heart of Ivanti’s offerings is the AI-powered Ivanti Neurons platform, where authoritative data drives decisions across endpoints, services and exposure—so AI acts on what is known, within pre-defined guardrails.
Ivanti fosters an inclusive environment where diverse perspectives are honored and valued, reflecting a commitment to a sustainable future for customers, partners, employees and the planet.
- National Cybersecurity AllianceBooth: TBD
Our alliance stands for the safe and secure use of all technology. We encourage everyone to do their part to prevent digital wrongdoing of any kind. We build strong partnerships, educate and inspire all to take action to protect ourselves, our families, organizations and nations. Only together can we realize a more secure, interconnected world.
- NovacoastBooth: TBD
A uniquely positioned IT services and solutions company, Novacoast is less defined by our broad range of expertise and services than by a perspective rooted in our cooperative environment of adaptable problem solving.
Beyond security specialists, software developers or network engineers, we are guides, allies, and problem solvers.
From implementation services, license fulfillment and technical training to software development, staffing services and custom or emerging solutions, Novacoast is an experienced and comprehensive IT business resource empowered on every level by our flexible and fearless perspective.
- OptivBooth: TBD
Optiv is a security solutions integrator delivering end-to-end cybersecurity solutions that help clients maximize and communicate the effectiveness of their cybersecurity programs. Optiv starts with core requirement of every enterprise—risk mitigation—and builds out from there with strategy, infrastructure rationalization, operations optimization, and ongoing measurement. Learn more at https://www.optiv.com.
- Rapid7Booth: TBD
Rapid7 transforms data into insight, empowering IT and security professionals to progress and protect their organizations. How? Our solutions are powered by advanced analytics and an unmatched understanding of the attacker mindset. This makes it easy to collect data, transform it into prioritized and actionable insight, and get it to the people who can act on it—all in an instant.
- Reach SecurityBooth: TBD
Reach is defining AI-Native Exposure Management by bridging the gap between knowing where you’re exposed and taking action to fix it. We help organizations reduce risk by making better use of the tools they already have delivering clarity, prioritization, and automation to turn understanding into results.
- Robert HalfBooth: TBD
Robert Half, the world’s first and largest specialized talent solutions firm, connects opportunities at great companies with highly skilled job seekers. We offer contract, temporary and permanent placement solutions for roles in finance and accounting, technology, marketing and creative, legal, and administrative and customer support. Named to Fortune’s World’s Most Admired Companies and 100 Best Companies to Work For® lists and a Forbes Best Employer for Diversity, Robert Half is the parent company of Protiviti®. Robert Half is traded on the New York Stock Exchange (symbol: RHI) and is a member of the S&P 500 index.
- RubrikBooth: TBD
Rubrik, the Zero Trust Data Security Company, delivers data security and operational resilience for enterprises. Rubrik’s big idea is to provide data security and data protection on a single platform, including Zero Trust Data Protection, ransomware investigation, incident containment, sensitive data discovery and orchestrated application recovery. This means data is ready at all times so you can recover the data you need and avoid paying a ransom. Because when you secure your data, you secure your applications, and you secure your business.
- SecureFlagBooth: TBD
SecureFlag is a Secure Coding Training platform for Developers and DevOps engineers to learn secure coding through hands-on exercises.
Forget boring slideshows and ineffective quizzes that “teach” developers to just take tests–and are forgotten faster than they can say “security breach.”
Enterprises can effectively augment their Secure Coding Training program with SecureFlag’s on-demand, 100% practical training. Through our platform, developers learn how to identify and remediate real security issues using familiar tools and technologies, in an authentic development environment accessed through the web browser.
SecureFlag delivers on-demand “Adaptive AppSec Learning” through individualized learning paths, real-time feedback, and content tailored to the needs of each learner. Our metrics dashboard highlights areas of improvement at individual, team, and organizational levels to clarify competency, risks, and remedial actions.
- SemperisBooth: TBD
For security teams charged with defending hybrid and multi-cloud environments, Semperis ensures the integrity and availability of critical enterprise directory services at every step in the cyber kill chain and cuts recovery time by 90%. Purpose-built for securing hybrid Active Directory environments, Semperis’ patented technology protects more than 50 million identities from cyberattacks, data breaches, and operational errors. The world’s leading organizations trust Semperis to spot directory vulnerabilities, intercept cyberattacks in progress, and quickly recover from ransomware and other data integrity emergencies.
As part of its mission is to be a force for good, Semperis offers a variety of cyber community resources, including the award-winning Hybrid Identity Protection (HIP) Conference, HIP Podcast and free identity security tools Purple Knight and Forest Druid.
- SnykBooth: TBD
Snyk is a developer-first security company that helps organizations use open source and stay secure. Snyk is the only solution that seamlessly and proactively finds and fixes vulnerabilities and license violations in open source dependencies and container images. Founded in 2015, Snyk is based in London, England.
- Splunk, a Cisco CompanyBooth: TBD
Splunk helps build a safer and more resilient digital world. Organizations trust Splunk to prevent security, infrastructure and application incidents from becoming major issues, absorb shocks from digital disruptions and accelerate digital transformation.
- Sublime SecurityBooth: TBD
Sublime is the new standard for email security. Not just another black box, our AI-powered detection engine detects and prevents email attacks, so security teams can spend less time on email-originated incidents.
- Sumo LogicBooth: TBD
Sumo Logic was founded in 2010 by experts in log management, scalable systems, big data, and security. Today, our purpose-built, cloud-native service analyzes more than 100 petabytes of data, more than 16 million searches, and delivers 10s of millions of insights daily – positioning Sumo among the most powerful machine data analytics services in the world.
- TevoraBooth: TBD
Tevora is an enterprise consulting firm specializing in information assurance, governance and compliance services and solutions. We work with some of the world’s leading companies, institutions and governments to ensure the safety of their information and their compliance with applicable regulations. With a distinctive combination of proven products and services, Tevora aids enterprises in protecting their most important assets from external and internal threats. For more information visit https://www.tevora.com.com/.
- ThreatLockerBooth: TBD
ThreatLocker® is a global cybersecurity leader, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. ThreatLocker’s combined Application Whitelisting, Ringfencing™, Storage Control, and Privileged Access Management solutions are leading the cybersecurity market towards a more secure approach of blocking unknown application vulnerabilities. To learn more about ThreatLocker visit: www.threatlocker.com
- TorqBooth: TBD
Torq is your security product’s favorite security product. Torq Hyperautomation unifies and automates the entire security infrastructure to deliver unparalleled protection and productivity.
- Upwind SecurityBooth: TBD
Upwind is the runtime-powered CNAPP, allowing you to protect everything you run in the cloud with runtime insights. Mitigate the risks that actually matter, identify the root causes of threats in minutes and respond with context and automation.
- WiCyS Western Washington AffiliateBooth: TBD
Rodney Beard, CISSPSr. Cyber Risk Analyst, Cyber Risk Opportunities LLCRodney Beard, CISSP, is a cybersecurity consultant with Cyber Risk Opportunities LLC, bringing more than 20 years of experience protecting organizations across defense, government, and financial services sectors.
Most recently, Rodney served as Information Security Officer at Rivermark Community Credit Union, a $2B institution in Oregon, where he built and led the enterprise security program for seven years. His responsibilities included penetration testing, security architecture, incident response, vendor risk management, and developing security awareness training for employees.
Prior to financial services, Rodney spent eight years as an IT Specialist with the U.S. Army at White Sands Missile Range, where he served as Information Management Officer responsible for IT security across 22 regional locations and 250 employees. He implemented security policies aligned with NIST, Federal, and DoD standards while managing a program portfolio valued at $2.5 million.
Rodney has also taught technology courses as an Adjunct Instructor at Vista College, preparing students for CompTIA A+ and Network+ certifications.
He holds the CISSP certification, CompTIA Security+, Network+, and A+, along with multiple Microsoft certifications. Rodney is based in Casper, Wyoming, and works remotely with clients nationwide.
Kip BoyleCo-Host, Cyber Risk Management Podcast; vCISO, Cyber Risk Opportunities LLCKip Boyle is the Virtual Chief Information Security Officer of Cyber Risk Opportunities, whose mission is to help executives become more proficient cyber risk managers. He has over 24 years of cybersecurity experience serving as Chief Information Security Officer (CISO) and in other IT risk management roles for organizations in the financial services, technology, telecom, military, civil engineering, and logistics industries.
Jake HammockCISO & Assistant CTO for Security and Infrastructure, City of SeattleJake Hammock is the Chief Information Security Officer, Assistant Chief Technology Officer and Security & Infrastructure Director at the City of Seattle, where he leads the Security & Infrastructure Division delivering citywide cybersecurity, enterprise infrastructure, cloud operations, IT service management, telecom and radio systems, fiber, and network services. He directs programs for incident response, identity and governance, enterprise architecture, and system and network operations, aligning investments to resilience, public safety, and civic administrative priorities across the nation’s 17th largest municipality through This Is Your City programs.
Jake’s career spans executive roles in government and industry. He served as Director of Trust and Vice President of Information Security at NICE inContact, leading board-level cybersecurity and privacy programs during a period of accelerated high growth. He was the Chief Technology Officer for a top 10 global fintech by peak market cap, patenting and deploying technologies used in production today, and later CTO for an energy-sector solutions provider, where he architected AI-driven cybersecurity platforms and advised enterprise energy and public-sector clients. A former U.S. Army Military Intelligence and Cyber Warfare Officer, he commanded Cyber National Mission Force units and served in national security leadership assignments within the Intelligence Community. He is a combat veteran, holds an M.Sc. in Cybersecurity Technology and patents spanning telecommunications, environmental platforms, and decentralized technologies, and he remains active in advancing secure AI, quantum-resilient encryption, data governance, and critical infrastructure protection.
Stephanie WarrenAssistant Director, Information Security, Port of SeattleStephanie Warren has more than 28 years of experience in technology, with the past 15 years dedicated to the field of Information Security. As the Assistant Director of Information Security, she brings a seasoned perspective to federal and regulatory compliance, incident response, and data protection. She excels at bridging communication between frontline employees and executive leadership, fostering alignment that strengthens organizational resilience. Her expertise in risk management helps organizations anticipate threats, adapt to challenges, and sustain long-term operational continuity. She holds a Bachelor of Science in Cybersecurity and Information Assurance and is a Certified Information Systems Security Professional (CISSP).
Marc MenningerDirector, Information Security, JND Legal AdministrationMarc Menninger is a seasoned corporate information security and risk management professional with more than twenty years of experience. He has held the Certified Information Security Systems Professional (CISSP) certification since 2000 and the Certified in Risk and Information System Controls (CRISC) certification since 2016. Marc’s career started with his service as a Computer and Communications Officer in the U.S. Air Force from 1992 to 1997. During his tenure, he led a team of 19 UNIX administrators, managing mobile Top Secret fiber optic networks. He was stationed at Langley Air Force Base in Virginia and Barksdale Air Force Base in Shreveport, LA, and served a short tour in the Persian Gulf during Operation Desert Shield.
Transitioning to civilian roles, Marc has navigated through several technical and leadership positions, building his expertise across the United States—from Dallas to San Francisco and, ultimately, Seattle. His roles have included Vice President of Corporate Information Security at Washington Mutual Bank, Security Manager at PEMCO Corporation, Senior Security Manager at Lighthouse eDiscovery, and Director of Cybersecurity at A Place for Mom. Presently, he serves as the Information Security Officer at AstrumU.
Marc's specialty areas encompass Enterprise Risk Assessment, Information Security Program Management, Governance, Risk and Compliance, and more. He lives near Seattle, WA, with his family.
Neha SrivastavaVP, Cybersecurity Products, JPMorgan ChaseNeha is a seasoned cybersecurity leader with a global track record of driving innovation at the intersection of security, emerging tech, and financial services. As VP of Cybersecurity Products at J.P. Morgan Chase, she leads the development of next-generation data protection solutions that secure the foundation of modern financial technology at scale and with impact.
Neha’s career spans strategic and technical leadership roles across Fortune 500 firms and global consultancies, including Deloitte, EY, Accenture, Flagstar Bank, NVIDIA and Bank of America. Her work has taken her across North America, Europe, and Asia, giving her a uniquely global perspective on regulatory landscapes, threat intelligence, and enterprise-scale security architecture. At the core of her leadership is a commitment to innovation, especially in advancing privacy-enhancing technologies, secure AI adoption, and zero-trust frameworks. Neha bridges deep technical acumen with strategic foresight, enabling organizations to not only defend against today's threats but also prepare for the next wave of disruption.
Beyond the enterprise, Neha is an active advisor to early-stage startups and venture firms, where she helps founders navigate the complex intersection of cybersecurity, compliance, and product-market fit. She is passionate about ensuring that innovation in security is not just cutting-edge but also responsible, resilient, and built for real-world impact. Neha also contributes to industry working groups focused on standards development and ethical tech adoption. From securing today’s digital economy to enabling the next generation of secure platforms, Neha brings a visionary yet grounded approach to cybersecurity, one that’s deeply technical, future-focused, and driven by purpose.
Lucas PersellSr. Solutions Architect, C1Lucas brings more than a decade of cybersecurity expertise to the C1 team, specializing in creating outcome-based security roadmaps for complex enterprise environments. With a background spanning systems engineering at Cisco and cloud architecture, he excels at bridging the gap between technical defense and business risk. Lucas is dedicated to helping clients navigate the evolving threat landscape through strategic design, zero-trust frameworks, and a relentless focus on long-term security resilience.
Stephen DoughertyPrincipal Investigator, Rexxfield; CEO, Dougherty Intelligence & InvestigationsStephen is an accomplished U.S. Secret Service investigator with 9-plus years of experience leading complex cybercrime, financial fraud, and international cybercrime investigations. He is recognized for pioneering the U.S. Secret Service’s Business Email Compromise Mission Desk, resulting in the recovery of nearly $500 million in victim funds. He was awarded two U.S. Secret Service Director’s Impact Awards, 2021 U.S. Secret Service Employee of the Year Award, and two DHS Secretary’s Gold Medals of Excellence for outstanding leadership, innovation, and impact. Stephen is an experienced public speaker and instructor, having delivered more than 50 global keynotes to executives, policymakers, and law enforcement on topics including cyber-enabled financial crime, digital forensics, and public-private collaboration. He is dedicated to bridging the gap between law enforcement, government, and the private sector to combat the world’s most sophisticated digital threats through intelligence-driven investigations, rapid response, and cross-border partnerships.
Lewis FoggieSales Engineer, SecureFlagHaving achieved an M.Sci in Astrophysics from Glasgow University in Scotland, Lewis went on to spend three years working for UK Defence, developing radar systems for naval vessels and fighter jets. Looking to take advantage of his communication skills combined with his technical skills, he went on to work as a solutions engineer in FinTech SaaS, before finding a passion for cybersecurity (namely by watching too many documentaries about ransomware) and moving on to SecureFlag.
Chris GoettlVP, Product Management, Endpoint Security, IvantiChris Goettl is the Vice President of Product Management for security products at Ivanti. Chris has over 15 years of experience working in IT, where he supports and implements security solutions for Ivanti customers and guides the security strategy and vision for Ivanti security products. He is also a security evangelist speaking at security events globally where he gives guidance around modern cyber threats and how to combat them effectively. Chris hosts a monthly webinar focusing on Patch Tuesday and security vulnerabilities and frequently blogs about security topics. You can find bylines and commentary from Chris in notable security news sources like SC Magazine, Redmond Magazine, ComputerWorld, ThreatPost, Help Net Security, and more.
Elizabeth SchaedlerSecurity Advisor, SplunkElizabeth Schaedler is a seasoned Splunk Security Advisor, specializing in helping organizations align their security strategies with business risk objectives. She has extensive expertise in leveraging risk-based alerting to address complex challenges such as fraud prevention. With over 20 years of experience in data center operations and cybersecurity, Elizabeth has held senior roles at leading technology companies including Cray Research, HP, RSA, Sun Microsystems, and IBM, mostly in the high-performance computing (HPC) sector. Based in Portland, Elizabeth is a 3rd generation U of O Duck and spends her free time with her husband, recently embarking on the project of organizing the treasures left behind by their two adult children.
Jake RaskoVP, IAM Security, JPMorganChaseJake Rasko is a passionate technology leader with an unwavering belief in the transformative power of technology to change the world. With a diverse career spanning both IT and Security, he has honed his expertise in building, running, and maintaining critical infrastructure securely at a global scale.
Over the course of Jake’s professional journey, he has been a part of notable organizations such as Cruise, Salesforce, and most recently, He is currently VP of IAM Security at JPMorganChase after stints at Blue Yonder and DAT Freight & Analytics.
With a career that began at the help desk and has since soared to leadership positions in global technology companies, Jake exemplifies the power of continuous growth and learning in the technology industry. His journey is a testament to his adaptability, vision, and unwavering commitment to leveraging technology for positive change.
RJ NiesenCybersecurity State Coordinator (WA), DHS CISARJ Niesen serves as the Washington Cybersecurity State Coordinator (CSC) for the Cybersecurity and Infrastructure Security Agency (CISA). As the CSC, he assists state, local, and tribal government stakeholders in enhancing the security and resiliency of critical infrastructure facilities across Washington.
Before joining CISA in November 2024, RJ served for twenty years in the US Army, holding leadership roles across several career management fields, including threat intelligence, protective security, information technology, and cybersecurity. In his previous role with the US Army, he directed Information Technology (IT) and Cybersecurity for the Army's first Multi-Domain Task Force (1st MDTF) upon its establishment in 2020. RJ led a team of twelve IT and four cybersecurity professionals, advising on all matters pertaining to both disciplines as the 1st MDTF expanded from 40 to 2,200 employees within three years. RJ deployed four times during the Global War on Terrorism: Iraq in 2004 and 2009, and Afghanistan in 2007 and 2012. During his service, he earned the Bronze Star and is a Purple Heart recipient.
RJ holds CISSP and PMP certifications and earned an MA in Information Technology Management from Webster University. He enjoys giving back to his community by volunteering as a youth sports coach and serving as an Outreach Coordinator with Reboot Recovery, a non-profit organization that empowers combat veterans to manage trauma and embrace a brighter future. RJ is passionate about his wife of nineteen years, Marisa, their three sons, supporting his local veteran community, and serving the American people!
Jonathan BarriosCISO, Vindicia Inc.Transforming vision into reality through strategic leadership, technology innovation, and governance excellence. For more than 30 years, Jonathan Barrios has led technology programs that fuel growth, build resilience, and strengthen trust for global organizations in financial services, SaaS, and fintech.
An inspirational leader and master storyteller, Jonathan motivates teams to act while grounding his vision in the financial acumen that drives business results. Trusted as a credible voice in decision-making, forging strategic financing partnerships, and defining governance boundaries, he consistently earns a seat at the table wherever he serves.
Jonathan began his technology career at just 16, nurturing a lifelong passion for innovation. Today, as Chief Information Security Officer at Vindicia (an Amdocs company), he leads global cybersecurity strategy, risk management, and compliance for a portfolio of SaaS commerce platforms. His programs protect millions of consumer transactions and embed governance and privacy-by-design into every stage of development. Under his leadership, Vindicia has achieved multi-framework compliance—including SOC 2, ISO 27001, PCI-DSS, and GDPR—while accelerating secure, rapid innovation for clients worldwide.
At the same time, as Director of Information Security & Compliance for the Amdocs SaaS Business Unit, Jonathan oversaw security for six global SaaS products, aligning security roadmaps with product strategy and the rigorous demands of Tier-1 telecom clients.
Earlier in his career, he founded JOBA Technologies, delivering bespoke technology and security solutions across diverse industries. Today, Jonathan is spearheading strategic shifts that transform IT from a functional cost center into a catalyst for business innovation, uniting the organization to operate as a truly global enterprise.
Adam PolitschCISO, KP LLC
Happy Hour
Rodney Beard, CISSPSr. Cyber Risk Analyst, Cyber Risk Opportunities LLCRodney Beard, CISSP, is a cybersecurity consultant with Cyber Risk Opportunities LLC, bringing more than 20 years of experience protecting organizations across defense, government, and financial services sectors.
Most recently, Rodney served as Information Security Officer at Rivermark Community Credit Union, a $2B institution in Oregon, where he built and led the enterprise security program for seven years. His responsibilities included penetration testing, security architecture, incident response, vendor risk management, and developing security awareness training for employees.
Prior to financial services, Rodney spent eight years as an IT Specialist with the U.S. Army at White Sands Missile Range, where he served as Information Management Officer responsible for IT security across 22 regional locations and 250 employees. He implemented security policies aligned with NIST, Federal, and DoD standards while managing a program portfolio valued at $2.5 million.
Rodney has also taught technology courses as an Adjunct Instructor at Vista College, preparing students for CompTIA A+ and Network+ certifications.
He holds the CISSP certification, CompTIA Security+, Network+, and A+, along with multiple Microsoft certifications. Rodney is based in Casper, Wyoming, and works remotely with clients nationwide.
Kip BoyleCo-Host, Cyber Risk Management Podcast; vCISO, Cyber Risk Opportunities LLCKip Boyle is the Virtual Chief Information Security Officer of Cyber Risk Opportunities, whose mission is to help executives become more proficient cyber risk managers. He has over 24 years of cybersecurity experience serving as Chief Information Security Officer (CISO) and in other IT risk management roles for organizations in the financial services, technology, telecom, military, civil engineering, and logistics industries.
Rodney Beard, CISSPSr. Cyber Risk Analyst, Cyber Risk Opportunities LLCRodney Beard, CISSP, is a cybersecurity consultant with Cyber Risk Opportunities LLC, bringing more than 20 years of experience protecting organizations across defense, government, and financial services sectors.
Most recently, Rodney served as Information Security Officer at Rivermark Community Credit Union, a $2B institution in Oregon, where he built and led the enterprise security program for seven years. His responsibilities included penetration testing, security architecture, incident response, vendor risk management, and developing security awareness training for employees.
Prior to financial services, Rodney spent eight years as an IT Specialist with the U.S. Army at White Sands Missile Range, where he served as Information Management Officer responsible for IT security across 22 regional locations and 250 employees. He implemented security policies aligned with NIST, Federal, and DoD standards while managing a program portfolio valued at $2.5 million.
Rodney has also taught technology courses as an Adjunct Instructor at Vista College, preparing students for CompTIA A+ and Network+ certifications.
He holds the CISSP certification, CompTIA Security+, Network+, and A+, along with multiple Microsoft certifications. Rodney is based in Casper, Wyoming, and works remotely with clients nationwide.
Kip BoyleCo-Host, Cyber Risk Management Podcast; vCISO, Cyber Risk Opportunities LLCKip Boyle is the Virtual Chief Information Security Officer of Cyber Risk Opportunities, whose mission is to help executives become more proficient cyber risk managers. He has over 24 years of cybersecurity experience serving as Chief Information Security Officer (CISO) and in other IT risk management roles for organizations in the financial services, technology, telecom, military, civil engineering, and logistics industries.
Rob DavidsonCISO, Pacific Blue Cross & PBC SolutionsRob Davidson brings many years of experience to his role as Chief Information Security Officer at Pacific Blue Cross and Pacific Blue Cross Solutions. His career started with Dell Canada and has progressed though several senior strategic and leadership positions at industry-defining organizations such as Microsoft and Hootsuite. Prior to his recent return to Vancouver, Rob worked through an extended tenure at Microsoft, from the original basics of networking through the launch of the Global Azure Cloud services.
Rob holds an Executive MBA and maintains his original CISSP certification. He enjoys the opportunity to share with and learn from others who are like-minded in his passion for the Security of People, Information, and Technology.
In addition to his core work, you will also find him engaged in Board of Directors (and Board advisory) positions, volunteer opportunities, and working to mentor and assist the next generation of security professionals.
Dr. Adrian M. MayersVP & CISO, Premera Blue CrossDr. Adrian M. Mayers joined Premera Blue Cross in November 2019 as Vice President, IT and Chief Information Security Officer (CISO) for Premera Blue Cross. Dr. Mayers is responsible for providing and optimizing an enterprise-wide security program and architecture that minimizes risk, enables business imperatives, and further strengthens Premera’s security posture. He works closely with Premera’s leadership team to establish and maintain a comprehensive program to protect employees, information assets, and technologies, and mature the corporate culture from security awareness to accountability.
Before joining Premera, Dr. Mayers held senior management positions at Vertafore, Microsoft, Nokia, and Securiguard. He has a strong passion for remaining on the cutting edge of technology and business innovation. Throughout his 25-year career, he has dealt with various aspects of corporate security, such as anti-fraud operations, cybersecurity, intellectual property protection, counterespionage, and loss prevention.
He holds multiple professional certifications, including CISM, CCSP, CFE, CISA, and CDPSE. He earned his doctorate in Business Administration specializing in International Business from Northcentral University, an MBA from Athabasca University, a graduate certificate in cybersecurity from Harvard University, a graduate certificate in counterintelligence from the American Military University, a certificate in digital transformation from MIT, and an engineering technologies diploma from John Abbott College. His academic research pursuits focus on national security, intelligence, special operations forces, cyber warfare, and foreign policy.
Tushar BadlaniSecurity Specialist, Customer Trust & Third-Party Risk, FigmaTushar Badlani is a Security Specialist focused on Customer Trust and Third-Party Risk at Figma. With 10+ years in security, he previously served as Global Customer Audit Manager at Okta, leading audit programs across North America, EMEA, and APJ. His background spans consulting at EY in Technology Risk and Third-Party Risk, advisory roles with security tooling companies, and co-authoring published research on third-party cyber risk. He holds CRISC, CISA, CCAK, and CCSK certifications, as well as an MS in Information Security Management from Syracuse University.
Manoj KumarFounder & CTO, Vishva PathShala
Sarah BontonSecurity Technical Program Manager, Blue Yonder
Talia KerberisDirector, Cyber Trust, Blue Yonder
Dr. Erika VossSVP, Global Chief Security Officer, Blue YonderStrategic security executive with over two decades of transformational leadership across the world's most demanding technology and enterprise environments. Proven track record driving enterprise-wide security strategies that align with business objectives while managing complex, global teams and regulatory compliance frameworks. Recognized expert in designing and implementing comprehensive security architectures that enable digital transformation while maintaining the highest standards of protection across application security, infrastructure security, cloud security, identity and access management, third-party risk, and enterprise threat detection.
In her current role as SVP, Global Chief Security Officer at Blue Yonder, a leading provider of end-to-end supply chain software and solutions for global enterprises, Dr. Voss sets strategic direction and drives execution across all facets of the organization's security program. Leading a high-performing team of security engineers, architects, and security operations experts, she establishes security policies, procedures, and practices that protect enterprise assets while enabling business velocity and innovation. Her responsibilities encompass application security, infrastructure security, access control and identity management, third-party risk management, threat detection and response, and regulatory compliance for complex global supply chains.
Drawing on her extensive tenure at industry-leading organizations including Amazon Web Services, Microsoft Corporation, Oracle Public Cloud, Salesforce, and Capital One, Dr. Voss has consistently delivered transformational security programs that reduce risk, enhance operational resilience, and support scalable growth. Her expertise spans foundational security architecture, fraud detection and prevention, identity management, and enterprise cloud security practices.
Melissa TooleySr. Director, Cyber Customer Trust Enablement, Blue Yonder
Jonathan BarriosCISO, Vindicia Inc.Transforming vision into reality through strategic leadership, technology innovation, and governance excellence. For more than 30 years, Jonathan Barrios has led technology programs that fuel growth, build resilience, and strengthen trust for global organizations in financial services, SaaS, and fintech.
An inspirational leader and master storyteller, Jonathan motivates teams to act while grounding his vision in the financial acumen that drives business results. Trusted as a credible voice in decision-making, forging strategic financing partnerships, and defining governance boundaries, he consistently earns a seat at the table wherever he serves.
Jonathan began his technology career at just 16, nurturing a lifelong passion for innovation. Today, as Chief Information Security Officer at Vindicia (an Amdocs company), he leads global cybersecurity strategy, risk management, and compliance for a portfolio of SaaS commerce platforms. His programs protect millions of consumer transactions and embed governance and privacy-by-design into every stage of development. Under his leadership, Vindicia has achieved multi-framework compliance—including SOC 2, ISO 27001, PCI-DSS, and GDPR—while accelerating secure, rapid innovation for clients worldwide.
At the same time, as Director of Information Security & Compliance for the Amdocs SaaS Business Unit, Jonathan oversaw security for six global SaaS products, aligning security roadmaps with product strategy and the rigorous demands of Tier-1 telecom clients.
Earlier in his career, he founded JOBA Technologies, delivering bespoke technology and security solutions across diverse industries. Today, Jonathan is spearheading strategic shifts that transform IT from a functional cost center into a catalyst for business innovation, uniting the organization to operate as a truly global enterprise.
Ann RobinsonAdjunct Professor, City University of Seattle; VP, Puget Sound ISSA Chapter
Vatsal GuptaSr. Security Engineer, AppleVatsal Gupta is a Senior Security Engineer at Apple with 13 years in identity, access management, and cybersecurity. His current focus is authorization architecture for agentic AI systems and policy-based access control. He contributes to the OpenID Foundation AuthZEN Working Group, the CSA IAM Working Group, and OWASP AISVS. He has spoken at Identiverse 2026, ISC2 Security Congress, and multiple IEEE conferences. He serves on the CyCon NATO CCDCOE Academic Review Committee and the ISSA Journal Editorial Advisory Board. IEEE Senior Member.
Alex Di GiacomoCISO, Sound TransitMr. Di Giacomo is an award-winning, veteran cybersecurity executive with over 26 years of experience leading security strategy and governance across critical infrastructure and corporate environments, both domestically and internationally. His expertise encompasses IT and OT security, security governance, cloud security, disaster recovery, risk and compliance management across multiple industry frameworks, and data privacy. In his current role as Chief Information Security Officer at Sound Transit, he built a nationally recognized, security program from the ground up based on the ISO 27001 international standard, achieving top-tier maturity ratings, confirmed by independent audits. Mr. Di Giacomo holds multiple rigorous, industry-relevant certifications including C|CISO, CISSP, CISM, CISA, CRISC, CDPSE and HISP, and is a frequent speaker, lecturer, and advisor on cybersecurity, risk, and resilience. Mr. Di Giacomo holds both a B.S. in Electronic Engineering degree, as well as a Master of Engineering and Technology Management, Summa Cum Laude.
A strategic visionary and hands-on leader, Mr. Di Giacomo is deeply committed to advancing cybersecurity maturity and resilience. He currently serves on the Washington State Technology Services Board Security Subcommittee and contributes to multiple professional associations including ISACA, ISC2 and ISSA and the IEEE, where he has achieved Senior Member status. Fluent in English, Spanish, and Italian, Mr. Di Giacomo brings a global perspective with a business and mission centric focus to today’s cybersecurity challenges and solutions.
Leonard CasipleFounder, Public Value LLCDr. Leonard Casiple is the founder of Public Value LLC and is a former Green Beret. He is the first in the world to conduct a doctoral study of the CARVER Matrix in a cyber environment. Leonard earned his education from Northeastern University (Doctor of Law and Policy), California Lutheran University (Master of Public Policy and Administration), Thunderbird School of Global Management (Global Master of Business Administration), Excelsior College (BS in Liberal Arts), Defense Language Institute (18-Month Arabic Language Course), JFK Special Warfare Center and School (Special Forces Qualification Course), and Academy of Competitive Intelligence (Master of Competitive Intelligence™).
Sean DeubyPrincipal Technologist, Americas, SemperisSean brings more than 30 years’ experience in enterprise IT and hybrid identity security to his role at Semperis. An original architect and technical leader of Intel's Active Directory and Texas Instrument’s Windows NT network, he is a 15-time MVP alumnus and has been involved with Microsoft identity technology since its inception. His experience as an identity strategy consultant for many Fortune 500 companies gives him a broad perspective on the challenges of today's identity-centered security.
Stephanie WarrenAssistant Director, Information Security, Port of SeattleStephanie Warren has more than 28 years of experience in technology, with the past 15 years dedicated to the field of Information Security. As the Assistant Director of Information Security, she brings a seasoned perspective to federal and regulatory compliance, incident response, and data protection. She excels at bridging communication between frontline employees and executive leadership, fostering alignment that strengthens organizational resilience. Her expertise in risk management helps organizations anticipate threats, adapt to challenges, and sustain long-term operational continuity. She holds a Bachelor of Science in Cybersecurity and Information Assurance and is a Certified Information Systems Security Professional (CISSP).
Michelle Linders WagnerVP, Head of Internal Audit, DocuSignMichelle Linders Wagner, a seasoned risk management executive, brings 25+ years of experience in enhancing compliance and risk posture for Fortune 500 firms. With cyber, compliance, and audit expertise, she builds high performing teams, swiftly identifying fit for purpose solutions that align with business strategy. While she is currently loving her job as the Head of Internal Audit at Docusign, Michelle has loved her prior positions, as well. At Deloitte, she transformed the global risk function; as an executive at Costco, she ran the second line of defense where she matured the global governance, risk, and compliance function; and at SAP, she drove high-priority risk and governance initiatives. Committed to excellence, Michelle excels in leading teams to solve intricate risk challenges.
Brittany Weinstein MolzSr. Director, AI Security & Platform Defense, AscensionPassionate risk and security leader committed to safeguarding the digital landscape with extensive experience in critical infrastructure. Experienced in regulatory compliance across the United States, Europe, and Asia. My passion lies in shaping strategic directions and implementing robust controls meticulously tailored to meet regulatory requirements.
Beyond my technical expertise, I'm devoted to advancing the role of women in security. I actively promote inclusivity in the workplace and offer mentorship to empower aspiring professionals.
Let's unite our strengths and collaborate to create a safer world together.
Corey BallChief Hacking Officer, APIsec UniversityCorey Ball is an offensive security consultant who breaks APIs, agentic systems, cloud, and the networks that connect them, and builds application security tests at scale. He authored "Hacking APIs" (No Starch Press) and founded APIsec University, a free educational platform that has trained more than 150,000 students in application security. He has more than 15 years in IT and cybersecurity across aerospace, agribusiness, energy, financial technology, government services, and healthcare, with more than a 1,000 penetration tests behind him. He holds a bachelor's degree in English and philosophy from Sacramento State University, along with the OSCP, CCISO, CISSP, and several other industry certifications.
Keyao AnMember of Technical Staff, OpenAIKeyao An is a Member of Technical Staff at OpenAI, where she builds enterprise identity and access capabilities for complex, large-scale products. Her work focuses on authentication, authorization, multi-IdP SSO, policy-based access control, and the safe deployment of security-critical changes. Previously at Meta, she developed AI-powered business products and safety systems. She specializes in turning complex security and enterprise requirements into resilient product capabilities that balance strong controls, operational reliability, and usable customer experiences.
Tim GalloHead of Global Threat Intelligence, Google CloudTim Gallo is the Head of Global Threat Intelligence at Google Cloud, he specializes in Cyber Threat Intelligence and Risk everything from Intelligence Operations and Cyber Threat Profile development to risk based analytic approaches to Security Operations. He Joined Google Cloud through the acquisition of Mandiant by Google in 2022, he had spent 5 years at Mandiant prior to the acquisition in a variety of field facing roles covering the aforementioned topics. Before joining Mandiant, Tim leveraged his over 20 years’ experience in information security and intelligence operations to aid in the development and deployment of a number of solutions. Including building client and organizational expertise in Intelligence Led Security and Business Operations. This included the development and product management of some of the first cyber intelligence solutions ever brought to market. These solutions have included threat and vulnerability management tools, IOC prediction algorithms, intelligence services, and strategic intelligence consulting. Today he spends his days helping clients understand the importance of Intelligence as a guiding principle for building out effective security processes and operations and helping clients and vendors find ways to leverage technologies responsibly to build their cyber defense centers and security operations practices. Every once in a while he can be found out in the desert, sometimes on his Harley with a flamethrower, sometimes with just a flamethrower
Aaron HuntDirector, Information Security, KP LLCAn Information Security leader with experience establishing resilient security strategies and procedures enhancing the corporate security posture, through evaluation of risk, promoting security awareness and privacy training, management of incident response, managing relationships with customers and business partners, and ensuring continued compliance through internal, customer and certification security audits.
A proven leader, skilled in managing network and application operations, knowledgeable in many collaboration and web environments and successfully managed services and large scale projects. Experienced in several security frameworks, including ISO 27001, PCI DSS, HITRUST, NIST 800-53, HIPAA, GDPR and SOC.
Rodney Beard, CISSPSr. Cyber Risk Analyst, Cyber Risk Opportunities LLCRodney Beard, CISSP, is a cybersecurity consultant with Cyber Risk Opportunities LLC, bringing more than 20 years of experience protecting organizations across defense, government, and financial services sectors.
Most recently, Rodney served as Information Security Officer at Rivermark Community Credit Union, a $2B institution in Oregon, where he built and led the enterprise security program for seven years. His responsibilities included penetration testing, security architecture, incident response, vendor risk management, and developing security awareness training for employees.
Prior to financial services, Rodney spent eight years as an IT Specialist with the U.S. Army at White Sands Missile Range, where he served as Information Management Officer responsible for IT security across 22 regional locations and 250 employees. He implemented security policies aligned with NIST, Federal, and DoD standards while managing a program portfolio valued at $2.5 million.
Rodney has also taught technology courses as an Adjunct Instructor at Vista College, preparing students for CompTIA A+ and Network+ certifications.
He holds the CISSP certification, CompTIA Security+, Network+, and A+, along with multiple Microsoft certifications. Rodney is based in Casper, Wyoming, and works remotely with clients nationwide.
Kip BoyleCo-Host, Cyber Risk Management Podcast; vCISO, Cyber Risk Opportunities LLCKip Boyle is the Virtual Chief Information Security Officer of Cyber Risk Opportunities, whose mission is to help executives become more proficient cyber risk managers. He has over 24 years of cybersecurity experience serving as Chief Information Security Officer (CISO) and in other IT risk management roles for organizations in the financial services, technology, telecom, military, civil engineering, and logistics industries.
• Create a personalized agenda
• View maps of the venue and Exhibit Hall
• Use secure messaging to network with attendees
• View speaker slides after the conference
• Play CyberHunt, the app game, and compete for prizes
Hone your skills and connect with your regional peers in InfoSec.

















