From Defense to Resilience
Location: Royal Sonesta Houston
The security leader's job changed again . Forrester now names AI agent threats the number one risk facing CISOs, machine identities outnumber human ones by orders of magnitude, and post-quantum deadlines have turned cryptographic migration into a program with a date attached. Meanwhile the board still expects the AI roadmap delivered safely and on time.
Over three days in Houston, 100 invitation-only C-suite and VP security leaders meet behind closed doors, under the Chatham House Rule, to work out what good looks like: securing AI at enterprise scale, defending an identity perimeter that now includes software agents, and building resilience for the breach that gets through.
Uniquely, every session is recorded, anonymized, transcribed and analyzed, then fed back to the full audience as structured intelligence. You leave with what your peers said in every room, not just your own.
Agenda
2:00pm - 4:30pm
Registration
4:30pm - 4:40pm
MOC Welcome & Meet the Team
4:45pm - 6:15pm
Mission Tracks: The Catalyst
Track 1: Securing AI at Scale: Enabling Innovation Without Introducing Unmanageable Risk
Every security leader in the room is being asked to green-light AI faster than they can govern it, and the CISO who becomes the default "no" risks being blamed for the business falling behind. This track works through the practical middle path: how to give the enterprise real AI velocity while keeping model, data and agent risk inside boundaries you can defend to a regulator.
Expect candid exchange on where guardrails actually hold, what shadow AI is really costing you, and how peers are handling the questions nobody has a settled answer to yet. Across three sessions you'll build a working view of an AI security operating model, covering the controls that matter most, the ones that only look reassuring, and a sequencing plan you can put in front of your CIO and your board when you're back at your desk.
Track 2: Cyber Resilience as a Business Imperative: How to Position The CISO's Agenda to The Board
Boards no longer need convincing that cyber matters; they need convincing that your agenda is the right use of their money, and the CISOs winning that argument have stopped talking about threats and started talking about resilience: revenue protected, downtime avoided, deals unblocked, obligations met. With personal accountability rising, disclosure rules biting and AI reshaping the risk register faster than annual budget cycles can follow, the gap between a security briefing the board endures and a business case it funds has never mattered more. In this candid, Chatham House Rule discussion, security leaders will compare what actually lands in the boardroom: the metrics that translate control maturity into business exposure, the framing that turns resilience spend into an enabler of growth rather than a tax on it, and the hard-won lessons of budget asks that failed. You will leave with peer-tested language, structures and metrics for your next board conversation, and a sharper answer to the question every director is now primed to ask: "are we resilient enough for the risk we're actually running?"
Same single-paragraph roundtable format as the audit-ready estate one. If you're building out the full session catalogue for the 41st, it might be worth me consolidating everything we've drafted — the two keynotes, the workshop and these roundtables — into one clean synopsis document you can drop into the agenda pack. Just say the word.
Track 3: Identity Security: Defending the New Enterprise Perimeter
Identity was already the perimeter. Then AI agents arrived, and the number of non-human identities in the average enterprise began growing far faster than anyone's ability to govern them, which is why KPMG's 2026 research puts non-human identity at the top of the CISO priority list and Gartner has made machine identity a headline security agenda item.
This track tackles what that means operationally: how to discover, own and de-provision machine and agent identities at scale, what privilege should look like for software that acts autonomously on a user's behalf, and how to close the gap that identity-based intrusion campaigns keep exploiting. You'll leave with a discovery-and-governance blueprint for non-human identity, a realistic view of where peers are on the same journey, and a prioritised list of the exposures worth fixing first.
Track 4: Your Perimeter Is a Myth: Managing Third-Party Risk in an Interconnected Digital Ecosystem
The modern enterprise doesn't have a perimeter; it has a supply chain. Every SaaS platform, API integration, managed service and fourth-party dependency extends your attack surface into organisations you don't control, and the past few years have proven that a single compromised vendor can cascade across hundreds of businesses in hours. Meanwhile boards, regulators, insurers and customers are all asking the same question with growing urgency: how well do you actually know your third parties? Point-in-time questionnaires and annual audits were built for a slower world, and most security leaders know their current programme measures compliance, not risk.
This in-depth, interactive workshop brings senior security leaders together to rebuild the third-party risk playbook for an interconnected era. Working under the Chatham House Rule, participants will benchmark their programmes against peers across industries and tackle the questions that matter in practice: how to tier and prioritise a vendor estate that runs into the thousands, how to move from static assessments to continuous monitoring without drowning the team, how to contract for transparency and incident response before you need it, and how to gain meaningful visibility of the fourth parties hiding behind your third parties. You will leave with practical approaches tested against the collective experience of the room, a clearer view of where your own programme leads or lags, and a concrete set of actions to take back to your organisation, so that when the next supply chain incident hits the headlines, your answer to "could that happen to us?" is grounded in evidence rather than hope.
6:30pm - 7:00pm
Cocktail Reception
7:20pm - 9:30pm
Gala Dinner
7:30am - 8:30am
Breakfast
8:30am - 8:40am
MOC Opening
8:40am - 9:05am
Gamechanger
The AI Security Balancing Act: Enabling Innovation Without Creating Tomorrow's Breach
The opening keynote confronts the defining tension of the year: AI adoption is now a survival requirement, and it is simultaneously the fastest-growing source of enterprise risk. Drawing on a live enterprise program rather than theory, this session examines how one security leader has enabled the business to move at speed without writing the incident report of 2027, covering the decisions that earned trust with the CIO and the board, the controls that proved worth the friction, and the moments where saying no was the right call.
You'll leave with a clear-eyed view of what a defensible AI security posture looks like in practice, the questions to ask before your next model or agent goes live, and a sense of where your own programme sits against a peer who is further down the road.
9:10am - 10:40am
Mission Tracks: The Blueprint
The Blueprint
As a continuation of the Catalyst Mission track, these sessions will establish a strategic blueprint to chart the pathway toward identifying a solution.
Track 1: Securing AI at Scale: Enabling Innovation Without Introducing Unmanageable Risk
Track 2: Cyber Resilience as a Business Imperative: How to Position The CISO's Agenda to The Board
Track 3: Identity Security: Defending the New Enterprise Perimeter
Track 4: Your Perimeter Is a Myth: Managing Third-Party Risk in an Interconnected Digital Ecosystem
10:45am - 11:15am
Future on Fire
The Network is the Strategy: Why Connectivity Decides Digital Speed
Most conversations about AI and security focus on defending against it. This one flips the lens: how do you use it? Hosted by a practising CISO, this closed-door discussion gets specific about where AI is genuinely earning its place in the security function, from accelerating policy development and review, to triaging and prioritising vulnerabilities against an unmanageable backlog, to compressing the timeline from detection to containment during live incident response.
Expect an honest exchange about what has worked, what over-promised, and what it takes to trust an AI-assisted output when the stakes are high. You'll leave with peer-tested use cases you can pilot immediately, a realistic view of the effort behind each, and a candid account of the failure modes worth avoiding.
11:20am - 11:50am
Future on Fire
Racing the Zero-Day Clock: Rethinking Exposure and Patching When Attacks Move at Machine Speed
The window between a patch being published and exploitation in the wild has collapsed from three weeks to under seven days, and with AI now able to reverse-engineer patches, generate exploit code and scan the internet for unpatched targets at machine speed, it is heading toward hours, then minutes. At the same time, patch volumes have quadrupled, leaving even well-resourced teams unable to keep up using yesterday's playbook.
Drawing on his vantage point leading cybersecurity at the world's largest security equipment manufacturer, Chuck Davis cuts through the AI hype to the two shifts every enterprise needs to make now: ruthlessly reducing the internet-facing attack surface, because every camera, sensor and IoT device is a computer on your network and if it doesn't need to be online it shouldn't be, and moving from severity-based to risk-based patch prioritisation, so effort flows to the vulnerabilities that genuinely threaten your organisation rather than the loudest CVSS scores. Attendees will leave with a clear-eyed view of how quickly the ground is shifting and a practical framework for reassessing exposure and patching strategy before the zero-day clock runs down to zero.
1:00pm - 2:05pm
Roundtables
Track 1: AI for Security: Separating Real Capability from Noise in the Security Stack
Most conversations about AI and security focus on defending against it. This one flips the lens: how do you use it? Hosted by a practising CISO, this closed-door discussion gets specific about where AI is genuinely earning its place in the security function, from accelerating policy development and review, to triaging and prioritising vulnerabilities against an unmanageable backlog, to compressing the timeline from detection to containment during live incident response.
Expect an honest exchange about what has worked, what over-promised, and what it takes to trust an AI-assisted output when the stakes are high. You'll leave with peer-tested use cases you can pilot immediately, a realistic view of the effort behind each, and a candid account of the failure modes worth avoiding.
Track 2: Leverage AI as a Leader in Security: Policy, Vulnerability and Incident Response
Most conversations about AI and security focus on defending against it. This one flips the lens: how do you use it? Hosted by a practising CISO, this closed-door discussion gets specific about where AI is genuinely earning its place in the security function, from accelerating policy development and review, to triaging and prioritising vulnerabilities against an unmanageable backlog, to compressing the timeline from detection to containment during live incident response.
Expect an honest exchange about what has worked, what over-promised, and what it takes to trust an AI-assisted output when the stakes are high. You'll leave with peer-tested use cases you can pilot immediately, a realistic view of the effort behind each, and a candid account of the failure modes worth avoiding.
Track 3: Through the Underwriter's Eyes: Running a Security Estate That Earns Cover, Survives the Audit and Pays Out When It Matters
Cyber insurance has quietly become one of the toughest audits a CISO faces. Underwriters now probe MFA coverage, EDR deployment, privileged access, backup isolation and incident response readiness in forensic detail, renewal questionnaires have become attestations with real legal weight, and a control you claimed but couldn't evidence can mean a denied claim at the worst possible moment.
Led by former insurer, this roundtable offers a genuine peek behind the curtain: how carriers actually read your application, which controls move the premium and which merely tick boxes, where policyholders most often misrepresent their estate without realising it, and what claims teams look for when deciding whether you're covered. Working under Chatham House rule, participants will benchmark how peers are aligning their security roadmaps with underwriting expectations, and leave knowing how to prepare for their next renewal or audit with evidence rather than assertions, how to manage the estate so coverage terms improve rather than erode, and how to make sure the policy they're paying for is one that will actually respond.
2:05pm - 2:35pm
Radical Perspectives
One Cloud, Many Countries: Scaling a Global Platform without Losing Control
Global scale and local control pull in opposite directions, and data sovereignty rules keep tightening the vice. This session examines how organizations are running genuinely global cloud platforms while satisfying an expanding patchwork of residency, privacy and regulatory requirements, without fragmenting into a dozen incompatible regional estates.
It covers architectural patterns that keep sovereignty manageable, the governance model that makes multi-jurisdiction operation sustainable, and where centralization is worth defending against local pressure. You'll take away a practical view of the sovereignty decisions coming down the track and how to design for them now rather than retrofitting later.
2:40pm - 3:45pm
Radical Perspectives
The Gym Membership Fallacy: Proving Security Works, Every Day, Across 180 Countries
Buying a gym membership doesn't make you healthy, and buying a tool, writing a process or hiring a team doesn't make your security effective. Only daily practice, measured continuously, does. Surinder Singh Rait leads Global IT Security Assurance at Ericsson, whose networks carry more than half the world's telecom traffic, and his remit is deceptively simple to state and brutally hard to execute: prove to management, boards, regulators, insurers and customers that security actually works.
In this keynote, Surinder shares the four-year journey from standing up a unit that didn't exist to a fully automated assurance capability spanning attack surface management, supply chain security, frameworks from NIST to NIS-2, and real-time control oversight through a single data lake, validating every control, every day, across 180 countries. You will leave with a practical blueprint for building assurance into your own program at whatever scale you operate: how to move from point-in-time audits to continuous evidence, what insurers and regulators actually ask for on the day things go wrong, and how to answer the hardest question a security leader faces, because breaches are not a matter of if but when: "how do we know it's working?
3:50pm - 4:20pm
Radical Perspectives
The New Arms Race: Effective Enterprise Cyber Risk Management in an AI Burgeoning World
AI is rewriting both sides of the cyber risk equation: attackers are using it to industrialise phishing, impersonation and reconnaissance, while boards push to adopt it faster than most risk programs can govern. Chris Bullock, CISO of Aveanna Healthcare, one of the largest home care providers in the US, brings a rare perspective to that challenge, having spent a decade in law enforcement, built security programs from a blank page across retail, energy, gaming, government and healthcare, and still serving as a certified reserve investigator with the Georgia Bureau of Investigation.
Drawing candidly on Aveanna's own security journey and his investigative casework on the front lines of cybercrime, Chris will share a practitioner's blueprint for cyber risk management that holds up in the AI era: quantifying and communicating risk in language the board will fund, governing AI adoption without becoming the department of no, defending a distributed, human-heavy workforce against AI-accelerated social engineering, and knowing which fundamentals still prevent most incidents versus where AI genuinely changes the calculus.
4:25pm - 4:55pm
Radical Perspectives
Killing the Mainframe: A Multi-Year Legacy Exit That Delivered ROI
Legacy platforms are where security debt compounds quietly, in unpatchable systems, scarce skills, and controls bolted on decades after the architecture was set. This session tells the story of a multi-year legacy exit that actually finished and actually paid back: how the business case was built and defended across budget cycles, how risk was managed during the long middle period when both old and new ran in parallel, and what the security posture looked like on the other side.
You'll take away a migration approach that survives leadership changes, the arguments that unlock funding for work with no visible feature output, and the risk-reduction case for finally tackling the system everyone has learned to live with.
7:15pm - 10:00pm
Offsite Evening Experience
7:00am - 8:15am
Breakfast
8:15am - 8:20am
MOC Opening
8:20am - 9:50am
Mission Tracks: The Reckoning
The Reckoning
Continuing your mission tracks, having built the blueprint we now enter the reckoning – a decisive phase where insights are rigorously challenged and crystallised into solution-led outcomes.
Track 1: Securing AI at Scale: Enabling Innovation Without Introducing Unmanageable Risk
Track 2: Cyber Resilience as a Business Imperative: How to Position The CISO's Agenda to The Board
Track 3: Identity Security: Defending the New Enterprise Perimeter
Track 4: Your Perimeter Is a Myth: Managing Third-Party Risk in an Interconnected Digital Ecosystem
9:55am - 10:25am
Ecosystem Exchanges
10:30am - 11:00am
Radical Perspectives
Beyond Migration: Turning Cloud Sprawl into Operating Leverage
Most enterprises have finished migrating and are now living with the result: sprawling estates, unclear ownership, costs that grow faster than usage and a security posture stretched across environments nobody fully maps.
This session is about the phase after migration, namely consolidating, governing and turning a scattered cloud footprint into genuine operating leverage. It covers the visibility and ownership models that make sprawl manageable, where consolidation delivers both cost and risk benefits, and how to make the case for cleanup work that doesn't ship features. You'll leave with a diagnostic for your own estate and a prioritised set of moves that reduce exposure and spend at the same time.
11:05am - 11:35am
Radical Perspectives
Both Sides of the Court: Playing Offense in the Age of Relentless Adversaries
Most security organizations are structured to absorb attacks. Golan Ben-Oni has spent two decades proving there is another way. As CIO and CISO of IDT Corporation; a role spanning seven verticals from telecoms to fintech, Golan runs one of the most distinctive strategic offensive security programs in the private sector: actively pursuing the state-sponsored threat actors targeting his business, in coordination with partners including Palo Alto Networks, SentinelOne, Mandiant and Microsoft.
From the operation against Russian state actors that made the front page of The New York Times in 2017 to the takedown campaigns he is leading today, this closed-door case study examines what it really takes for a defender to play both sides of the court: when offense is a legitimate and necessary component of defense, how to build the ecosystem and legal partnerships that make it possible, and why collaboration — even with direct competitors — is now a survival requirement. Woven throughout is the tension every leader in the room is living with: driving the AI adoption a legacy enterprise needs to stay alive over the next five years, while denying that same technology to the adversaries working around the clock to get in.
11:40am - 12:10pm
Radical Perspectives
The Composable Core: Re-Platforming Critical Systems Without the Big Bang
Every organization carries systems too critical to fail and too old to defend properly, and the traditional answer of a multi-year big-bang replacement has a failure rate that makes boards understandably nervous.
This session explores the composable alternative: decomposing critical platforms incrementally, delivering value and reducing risk at each step rather than at the end. It covers where to cut first, how to keep security and integrity intact while the architecture is in motion, and how to sustain momentum on a program measured in years.
You'll take away a staged approach to modernizing the systems you can least afford to break, and the governance that keeps an incremental program from stalling halfway.
12:15pm - 12:45pm
MOC Closing
Why attend?
Connect with like-minded senior leaders for a curated agenda, focused on tackling your current business critical challenges and driving industry forward.
Be a part of exclusive shared learning, horizon scanning and actionable insights enabling organizations to deliver transformative strategies.
Build meaningful relationships with solution providers matched to your business priorities to help accelerate your projects and deliver your objectives.
Who attends
Register
interest