From Defense to Resilience
Location: Royal Sonesta Houston
The security leader's job changed again . Forrester now names AI agent threats the number one risk facing CISOs, machine identities outnumber human ones by orders of magnitude, and post-quantum deadlines have turned cryptographic migration into a program with a date attached. Meanwhile the board still expects the AI roadmap delivered safely and on time.
Over three days in Houston, 100 invitation-only C-suite and VP security leaders meet behind closed doors, under the Chatham House Rule, to work out what good looks like: securing AI at enterprise scale, defending an identity perimeter that now includes software agents, and building resilience for the breach that gets through.
Uniquely, every session is recorded, anonymized, transcribed and analyzed, then fed back to the full audience as structured intelligence. You leave with what your peers said in every room, not just your own.
Agenda
2:00pm - 4:30pm
Registration
4:30pm - 4:40pm
MOC Welcome & Meet the Team
4:45pm - 6:15pm
Mission Tracks: The Catalyst
Track 1: Securing AI at Scale: Enabling Innovation Without Introducing Unmanageable Risk
Every security leader in the room is being asked to green-light AI faster than they can govern it, and the CISO who becomes the default "no" risks being blamed for the business falling behind. This track works through the practical middle path: how to give the enterprise real AI velocity while keeping model, data and agent risk inside boundaries you can defend to a regulator.
Expect candid exchange on where guardrails actually hold, what shadow AI is really costing you, and how peers are handling the questions nobody has a settled answer to yet. Across three sessions you'll build a working view of an AI security operating model, covering the controls that matter most, the ones that only look reassuring, and a sequencing plan you can put in front of your CIO and your board when you're back at your desk.
Track 2: Cyber Resilience as a Business Imperative: Preparing for the Breach, Not Just Preventing It
Prevention has a ceiling, and every leader here has met it. This track shifts the conversation to the assumption your board has already quietly made: that something will get through, and what matters is how fast the business stands back up.
It covers the operational reality of resilience, from recovery times that survive contact with a real incident, to the dependencies nobody maps until they fail, to the decisions that have to be pre-made because there's no time to make them live. It also confronts the harder organisational work of getting resilience funded as a business investment rather than a security cost.
You'll leave with a resilience maturity benchmark against peers, a tested approach to the recovery scenarios most often underestimated, and language that connects downtime to enterprise value in terms your CFO will act on.
Track 3: Identity Security: Defending the New Enterprise Perimeter
Identity was already the perimeter. Then AI agents arrived, and the number of non-human identities in the average enterprise began growing far faster than anyone's ability to govern them, which is why KPMG's 2026 research puts non-human identity at the top of the CISO priority list and Gartner has made machine identity a headline security agenda item.
This track tackles what that means operationally: how to discover, own and de-provision machine and agent identities at scale, what privilege should look like for software that acts autonomously on a user's behalf, and how to close the gap that identity-based intrusion campaigns keep exploiting. You'll leave with a discovery-and-governance blueprint for non-human identity, a realistic view of where peers are on the same journey, and a prioritised list of the exposures worth fixing first.
Track 4: Managing Third-Party Risk in an Interconnected Digital Ecosystem
6:30pm - 7:00pm
Cocktail Reception
7:20pm - 9:30pm
Gala Dinner
7:30am - 8:30am
Breakfast
8:30am - 8:40am
MOC Opening
8:40am - 9:05am
Gamechanger
The AI Security Balancing Act: Enabling Innovation Without Creating Tomorrow's Breach
The opening keynote confronts the defining tension of the year: AI adoption is now a survival requirement, and it is simultaneously the fastest-growing source of enterprise risk. Drawing on a live enterprise program rather than theory, this session examines how one security leader has enabled the business to move at speed without writing the incident report of 2027, covering the decisions that earned trust with the CIO and the board, the controls that proved worth the friction, and the moments where saying no was the right call.
You'll leave with a clear-eyed view of what a defensible AI security posture looks like in practice, the questions to ask before your next model or agent goes live, and a sense of where your own programme sits against a peer who is further down the road.
9:10am - 10:40am
Mission Tracks: The Blueprint
As a continuation of the Catalyst Mission track, these sessions will establish a strategic blueprint to chart the pathway toward identifying a solution.
Track 1: Securing AI at Scale: Enabling Innovation Without Introducing Unmanageable Risk
Track 2: Cyber Resilience as a Business Imperative: Preparing for the Breach, Not Just Preventing It
Track 3: Identity Security: Defending the New Enterprise Perimeter
Track 4: Managing Third-Party Risk in an Interconnected Digital Ecosystem
10:45am - 11:15am
Future on Fire
The Network is the Strategy: Why Connectivity Decides Digital Speed
Most conversations about AI and security focus on defending against it. This one flips the lens: how do you use it? Hosted by a practising CISO, this closed-door discussion gets specific about where AI is genuinely earning its place in the security function, from accelerating policy development and review, to triaging and prioritising vulnerabilities against an unmanageable backlog, to compressing the timeline from detection to containment during live incident response.
Expect an honest exchange about what has worked, what over-promised, and what it takes to trust an AI-assisted output when the stakes are high. You'll leave with peer-tested use cases you can pilot immediately, a realistic view of the effort behind each, and a candid account of the failure modes worth avoiding.
11:20am - 11:50am
Future on Fire
When It Mattered Most: Resilience Lessons From a Significant Global Disruption
Security architecture and network architecture stopped being separable some time ago, and for most enterprises the network is now either the enabler of digital speed or the reason initiatives stall. This keynote makes the case that connectivity decisions are strategy decisions: how the network underpins zero trust rather than undermining it, what changes when AI workloads and distributed operations reshape traffic patterns, and where the trade-offs between performance, control and cost are actually being made.
You'll take away a framework for evaluating whether your connectivity model is accelerating or throttling the business, and the questions worth putting to your architecture team before the next investment cycle.
1:00pm - 2:05pm
Roundtables
Leverage AI as a Leader in Security: Policy, Vulnerability and Incident Response
Most conversations about AI and security focus on defending against it. This one flips the lens: how do you use it? Hosted by a practising CISO, this closed-door discussion gets specific about where AI is genuinely earning its place in the security function, from accelerating policy development and review, to triaging and prioritising vulnerabilities against an unmanageable backlog, to compressing the timeline from detection to containment during live incident response.
Expect an honest exchange about what has worked, what over-promised, and what it takes to trust an AI-assisted output when the stakes are high. You'll leave with peer-tested use cases you can pilot immediately, a realistic view of the effort behind each, and a candid account of the failure modes worth avoiding.
2:05pm - 2:35pm
Radical Perspectives
One Cloud, Many Countries: Scaling a Global Platform without Losing Control
Global scale and local control pull in opposite directions, and data sovereignty rules keep tightening the vice. This session examines how organizations are running genuinely global cloud platforms while satisfying an expanding patchwork of residency, privacy and regulatory requirements, without fragmenting into a dozen incompatible regional estates.
It covers architectural patterns that keep sovereignty manageable, the governance model that makes multi-jurisdiction operation sustainable, and where centralization is worth defending against local pressure. You'll take away a practical view of the sovereignty decisions coming down the track and how to design for them now rather than retrofitting later.
2:40pm - 3:45pm
The Provocation Tables
3:50pm - 4:20pm
Radical Perspectives
Zero Trust, Real Results: Securing the Distributed Enterprise
Zero trust has suffered more from enthusiastic marketing than almost any concept in security, which makes an honest account of a real implementation genuinely valuable. This end-user keynote covers what was actually delivered, in what order, and at what cost: where the model produced measurable risk reduction, where it collided with user experience and legacy reality, and how the program kept executive support through the unglamorous middle years.
You'll leave with a realistic sequencing plan drawn from someone who has done it, the metrics that demonstrated progress to a skeptical board, and a clear sense of which zero trust promises hold up in a distributed enterprise and which don't.
4:25pm - 4:55pm
Radical Perspectives
Killing the Mainframe: A Multi-Year Legacy Exit That Delivered ROI
Legacy platforms are where security debt compounds quietly, in unpatchable systems, scarce skills, and controls bolted on decades after the architecture was set. This session tells the story of a multi-year legacy exit that actually finished and actually paid back: how the business case was built and defended across budget cycles, how risk was managed during the long middle period when both old and new ran in parallel, and what the security posture looked like on the other side.
You'll take away a migration approach that survives leadership changes, the arguments that unlock funding for work with no visible feature output, and the risk-reduction case for finally tackling the system everyone has learned to live with.
7:15pm - 10:00pm
Offsite Evening Experience
7:00am - 8:15am
Breakfast
8:15am - 8:20am
MOC Opening
8:20am - 9:50am
Mission Tracks: The Reckoning
Continuing your mission tracks, having built the blueprint we now enter the reckoning – a decisive phase where insights are rigorously challenged and crystallised into solution-led outcomes.
Track 1: Securing AI at Scale: Enabling Innovation Without Introducing Unmanageable Risk
Track 2: Cyber Resilience as a Business Imperative: Preparing for the Breach, Not Just Preventing It
Track 3: Identity Security: Defending the New Enterprise Perimeter
Track 4: Managing Third-Party Risk in an Interconnected Digital Ecosystem
9:55am - 10:25am
Ecosystem Exchanges
10:30am - 11:00am
Radical Perspectives
Beyond Migration: Turning Cloud Sprawl into Operating Leverage
Most enterprises have finished migrating and are now living with the result: sprawling estates, unclear ownership, costs that grow faster than usage and a security posture stretched across environments nobody fully maps.
This session is about the phase after migration, namely consolidating, governing and turning a scattered cloud footprint into genuine operating leverage. It covers the visibility and ownership models that make sprawl manageable, where consolidation delivers both cost and risk benefits, and how to make the case for cleanup work that doesn't ship features. You'll leave with a diagnostic for your own estate and a prioritised set of moves that reduce exposure and spend at the same time.
11:05am - 11:35am
Radical Perspectives
Both Sides of the Court: Playing Offense in the Age of Relentless Adversaries
Most security organizations are structured to absorb attacks. Golan Ben-Oni has spent two decades proving there is another way. As CIO and CISO of IDT Corporation; a role spanning seven verticals from telecoms to fintech, Golan runs one of the most distinctive strategic offensive security programs in the private sector: actively pursuing the state-sponsored threat actors targeting his business, in coordination with partners including Palo Alto Networks, SentinelOne, Mandiant and Microsoft.
From the operation against Russian state actors that made the front page of The New York Times in 2017 to the takedown campaigns he is leading today, this closed-door case study examines what it really takes for a defender to play both sides of the court: when offense is a legitimate and necessary component of defense, how to build the ecosystem and legal partnerships that make it possible, and why collaboration — even with direct competitors — is now a survival requirement. Woven throughout is the tension every leader in the room is living with: driving the AI adoption a legacy enterprise needs to stay alive over the next five years, while denying that same technology to the adversaries working around the clock to get in.
11:40am - 12:10pm
Radical Perspectives
The Composable Core: Re-Platforming Critical Systems Without the Big Bang
Every organization carries systems too critical to fail and too old to defend properly, and the traditional answer of a multi-year big-bang replacement has a failure rate that makes boards understandably nervous.
This session explores the composable alternative: decomposing critical platforms incrementally, delivering value and reducing risk at each step rather than at the end. It covers where to cut first, how to keep security and integrity intact while the architecture is in motion, and how to sustain momentum on a program measured in years.
You'll take away a staged approach to modernizing the systems you can least afford to break, and the governance that keeps an incremental program from stalling halfway.
12:15pm - 12:45pm
MOC Closing
Why attend?
Connect with like-minded senior leaders for a curated agenda, focused on tackling your current business critical challenges and driving industry forward.
Be a part of exclusive shared learning, horizon scanning and actionable insights enabling organizations to deliver transformative strategies.
Build meaningful relationships with solution providers matched to your business priorities to help accelerate your projects and deliver your objectives.
Who attends
Register
interest