Event Agenda
October 20th – 21st, 2026 // Austin, Texas
October 20th – 21st, 2026 // Austin, Texas
Theme : Resilience Blueprint: Navigating the Next Era of Cyber Risk
| Day 1 // October 20th, 2026 08:30 – 5:00 CDT | |
| 08:15Registration & Coffee | |
| 08:50Opening Address – Chair: Joe Carroll, CIO & Head of Cybersecurity, CITGO Petroleum | |
| 09:00 As threat actors increasingly target local governments, school districts, and municipal utilities, defending the state’s digital perimeter requires a unified front. In this keynote presentation, the Cybersecurity State Coordinator of Texas for CISA pulls back the curtain on the federal blueprint designed to shield the state’s 16 critical infrastructure sectors. This session breaks down how Texas public and private entities can move from a reactive posture to proactive resilience. Attendees will discover how to leverage CISA’s no-cost risk assessments, tap into real-time threat-sharing networks, and build operational continuity plans capable of mitigating sophisticated, state-sponsored cyber disruptions. .
. | |
| 11:20 While speed to market is important, rapid software deployment shouldn’t come at the expense of robust security. This session provides security leaders with a strategic roadmap to balance aggressive innovation with ironclad enterprise application security. We will explore how to integrate automated security guardrails directly into development workflows, allowing your team to ship code faster while minimizing risk. Discover how to foster a collaborative culture between security and engineering teams, transforming security from an obstacle into a competitive advantage. .
. | |
| 10:25Networking Break | |
| 11:05 Most security programs measure effort—not outcomes. CISOs patch thousands of vulnerabilities and deploy countless tools, yet real resilience depends on proving defenses actually work. Organizations are shifting from assumptions to evidence by using autonomous pentesting to view environments through an attacker’s lens. Cyber resilience isn’t about being perfect—it’s about getting better over time. And the only perspective that truly matters is the attacker’s. .
. | |
| 11:35 As AI capabilities accelerate, the means to defend our systems grows, but so does the ability for malicious actors to launch harmful attacks. This panel explores whether AI will secure our digital infrastructure or systematically dismantle it. Central to this debate is the recent development of Claude Mythos Preview, an unreleased frontier model that recently autonomously exposed over 10,000 high-severity vulnerabilities across critical software. Does this herold a revolution in cyber defense, or are there major concerns for what harm future AI-powered attacks will bring? .
. | |
| 12:05 With many threats going under the radar, what you can’t see will hurt you. This session demonstrates how External Attack Surface Management (EASM) uncovers hidden vulnerabilities and shadow IT. Learn to think like a threat actor, identifying exposed digital assets and closing critical security gaps before they are exploited. . . | |
| 12:15 In today’s cyber landscape, dark data has emerged as an intricate challenge, accentuated by the untapped potential of threat intelligence. While copious amounts of threat intelligence are at organizations’ disposal, many find themselves ill-equipped with the security tools needed to harness this vital information, relegating essential insights to the realm of dark data. In this session, we delve into vital technological advancements that empower organizations to embark on threat hunting within the vast expanses of dark data. .
. | |
| 12:45Lunch | |
| 1:45 As organisations race to integrate Generative AI, the boundary between innovation and risk has never been thinner. In this case study session, our expert speaker moves beyond theoretical frameworks to provide a candid look at how a leading enterprise successfully implemented its AI governance structure. We will explore the journey from managing “Shadow AI” to establishing a robust, scalable environment that prevents data leakage whilst empowering users. .
. | |
| 2:15 As traditional network boundaries dissolve, identity has become the primary battleground for enterprise security. Legacy MFA is no longer enough to stop sophisticated attackers utilizing AI-driven phishing and session hijacking. This session explores how to modernize your identity strategy by aligning MFA with a strict Zero Trust architecture. We will dive into the transition toward phishing-resistant authentication—such as passkeys—and discuss how to leverage continuous behavioral signals to verify trust. Learn how to transform authentication from a static checkpoint into an adaptive, continuous shield for your organization. .
. | |
| 2:45 As AI technology advances, cybercriminals are rapidly shifting from manual exploits to automated, targeted, and rapid AI-powered attacks. To survive this new threat landscape, legacy defense strategies are no longer enough. This session explores how organizations can leverage machine learning and automated response tools to outsmart adaptive threats. We will break down the anatomy of an AI-driven breach and demonstrate how to build an active, predictive defense framework that neutralizes threats before they disrupt your business. .
. | |
| 3:15 This essential session explores the strategic use of SIEM and SOAR platforms to break down the silos between IT Operations and Security teams. Learn how establishing a unified operating model enhances workflows, automates repetitive tasks, and ensures security findings are remediated rapidly and effectively across the enterprise. We will detail best practices for platform integration, creating high-value automation playbooks, and maximizing the return on your security technology stack. . – Yadu Singh, Senior Director, Head of Vulnerability Management & Offensive Security, GEICO . | |
| 3:45Networking Break | |
| 4:15 T1:How Do We Balance the Speed of AI-Driven Security Automation with the Need for Human Oversight to Prevent False-Positive Actions? – Senior Expert, TrendAI . T2: How do We Scale Passwordless Authentication Across Legacy Systems that Lack Modern Identity Support? – Senior Expert, Atakama . T3: Rein In Your Microsoft 365 Tenant: Resilience for Identities and Configurations – Michael Smith, Solutions Engineer, CoreView . . | |
| 4:55 Today’s CISOs find themselves in an impossible position: expected to stop every sophisticated cyber threat while simultaneously driving rapid business growth. Modern security leaders must act as a business enabler. In this dynamic panel discussion, top security leaders will share how they navigate this delicate high-wire act. Discover how modern CISOs translate technical vulnerabilities into business risk for the board, overcome executive burnout, and implement strategic security frameworks that actually accelerate digital transformation and corporate innovation. .
. | |
| 5:35Closing Remarks – Joe Carroll, CIO & Head of Cybersecurity, CITGO Petroleum | |
| 5:45Drinks Reception | |
| 7:00Dinner hosted by Dispel (Invite Only) | |
| Day 2 // October 21st, 2026 08:35 – 4:55 CDT | |
| 08:35Registration & Coffee | |
| 08:50Opening Address – Chair: Joe Carroll, CIO & Head of Cybersecurity, CITGO Petroleum | |
| 09:00 Translating complex regulatory mandates into everyday cybersecurity operations is a critical challenge for the modern enterprise. Compliance is not a standalone checkbox; it must be structurally embedded into their defensive architecture. This panel brings together senior cybersecurity leaders to discuss practical strategies for harmonizing frameworks like ISO 27001 and NIST 2.0 with stringent regional mandates, including the Texas Data Privacy and Security Act (TDPSA). Join to learn how to build an agile governance roadmap. .
. | |
| 09:40 The launch of the NIST CSF 2.0 expands the gold standard of security beyond critical infrastructure to all organizations, introducing the pivotal “Govern” function. Transitioning to this modernized framework requires moving past rigid check-the-box exercises toward a dynamic, risk-based strategy. This session provides a practical roadmap to decode the updated guidelines, optimize asset management, and align cybersecurity maturity with overarching business goals. Discover how to operationalize NIST 2.0 across your entire ecosystem, fostering a culture of continuous assessment that satisfies auditors while aggressively reducing your enterprise attack surface. .
. | |
| 10:10Networking Break | |
| 10:50 With hybrid workforces and cloud adoption running apace, security begins and ends with identity. In this case study presentation, we explore a real-world enterprise journey of successfully deploying a comprehensive IAM framework. We will walk through the entire lifecycle of the implementation, from navigating multi-directory complexity and overcoming user resistance to achieving a true Zero Trust posture. Hear a practical blueprint for consolidating access controls, automating user provisioning, and enforcing strict security without bottlenecking business productivity. .
. | |
| 11:20 To survive today’s modern cyber attacks, organizations must move beyond human-scale processing and embrace the Velocity Shift. In this session, we examine the transition from human-led, tool-assisted security to AI-driven operations. We will explore how to integrate ML and GenAI into the fabric of the SOC to automate high-volume triage, predict adversary movement, and execute defensive maneuvers at a speed that traditional workflows simply cannot match. .
. | |
| 11:50 In today’s cyber landscape, dark data has emerged as an intricate challenge, accentuated by the untapped potential of threat intelligence. While copious amounts of threat intelligence are at organizations’ disposal, many find themselves ill-equipped with the security tools needed to harness this vital information, relegating essential insights to the realm of dark data. In this session, we delve into vital technological advancements that empower organizations to embark on threat hunting within the vast expanses of dark data. .
. | |
| 12:20 Explore trends in AI usage over the past few years and understand which groups are adopting AI fastest, what types of data they are inputting, and what tools they are using, both sanctioned and unsanctioned. Then pivot to how to identify and protect against sensitive data being misused with AI tooling. . . | |
| 12:30 Join this interactive group discussion session with the whole audience with our expert moderator as we consider these questions. .
. | |
| 1:00Lunch hosted by Rubrik | |
| 2:00 Traditional application security often forces developers to choose between velocity and safety, resulting in friction, bypassed workflows, and vulnerable software. This session explores how to shift security from a reactive gatekeeper to an automated enabler. Discover how to embed seamless, context-aware guardrails directly into existing integrated development environments and CI/CD pipelines. We will discuss how we provide developers with real-time, actionable feedback and automated remediation guidance. Learn to foster a culture of shared responsibility, empowering engineering teams to write secure code by default without sacrificing development speed. .
. | |
| 2:30 Your security is only as strong as your least-secure vendor. With supply chain attacks surging, organizations can no longer afford to treat third-party risk management as a static, check-the-box compliance exercise. In this session, our expert speaker delivers a pragmatic, risk-based framework for identifying, prioritizing, and mitigating vulnerabilities across your entire software and vendor supply chain. We will explore how to move away from exhausting, one-size-fits-all security questionnaires and shift toward continuous, automated threat monitoring.
. | |
| 3:00 In the current threat landscape, the “Detection-to-Response” gap is where organizations lose the most ground. Waiting for an alert to fire gives the initiative to the adversary. True cyber resilience means moving away from reactive firefighting and toward a model of Proactive Cyber Operations. In this session, our expert outlines the roadmap for evolving your security posture to neutralize threats before they become more serious. .
. | |
| 3:30Networking Break | |
| 4:00 Traditional security awareness training is failing. As generative AI democratizes, attackers are bypassing text-based phishing in favor of hyper-realistic deepfake video calls and synthetic voice-cloning scams that effortlessly dupe well-meaning employees. This session equips security leaders with a modernized blueprint for human-centric defense. We will examine real-world case studies where synthetic media bypassed multi-million dollar defenses, and we will break down the precise physiological and contextual cues employees must look for to identify AI deception. .
. | |
| 4:30 The most sophisticated security stack is ineffective without the human intelligence to drive it. In this session, we discuss the acute cyber security skills gap by shifting the focus from external recruitment to internal talent evolution. We will explore how security leaders can build resilient, high-performing teams by implementing structured upskilling and cross-skilling programmes. .
. | |
| 5:10Closing Remarks – Joe Carroll, CIO & Head of Cybersecurity, CITGO Petroleum | |
| 5:20End of Conference | |