SEC536: Adversarial AI - Penetration Testing AI Systems

AI is already in your workplace. From generative tools that create content in seconds to emerging agentic systems that can plan and take action, your workforce is experimenting, often without fully understanding the risks or responsibilities.
This webcast gives security awareness and culture leaders a clear, accessible primer on generative and agentic AI, followed by practical guidance on what to teach your people. Through live demonstrations and real-world examples, we’ll focus on enablement over restriction, equipping your workforce to use AI confidently, productively, and securely.
In-Person
Arriving in Las Vegas early? Join us the evening before the Summit for Early Bird Registration and Networking. Pick up your Summit credentials, reconnect with colleagues, meet fellow attendees, and start building new connections before the event officially begins.
In-Person
In-Person
In-Person & Virtual
In-Person & Virtual
Before someone will betray their country, they must trust you completely.
Shawnee Delaney spent nearly a decade as a clandestine case officer for the Defense Intelligence Agency recruiting and running spies in denied areas, hostile environments, and combat zones.
Her job wasn't just gathering intelligence. It was engineering trust under the most adversarial conditions imaginable, with people who had every reason not to trust anyone.
What she learned is that trust isn't a feeling. It's a system. And the same psychological principles that drive an asset to hand over classified information shape every high-stakes relationship in business - with your team, your clients, your board, and your adversaries.
In this session, Shawnee decodes the operational science behind human connection: how intelligence professionals identify what drives a person, establish influence without manipulation, and build relationships that hold under pressure. You'll walk away understanding how trust is actually constructed, where it breaks down, and what it costs you when it does.
This isn't soft skills. This is tradecraft.
In-Person & Virtual
In-Person & Virtual
Why do human driven cyber incidents keep repeating, despite years of awareness and training? Because most security decisions are not made in classrooms. They are made under pressure, in poorly designed processes, with tools and workflows that quietly reward insecure behavior.
This session challenges the awareness only mindset and introduces a practical shift in human risk management: designing operational environments where secure behavior becomes the easiest path, not the hardest one.
Through real world examples, you will learn how processes, systems, and constraints shape behavior at scale. The focus is not on perfect programs, but on how to spot high risk moments and redesign conditions so people can do the right thing by default.
Awareness informs. Training guides. But the environment decides.
In this session, you will learn how to:
• Identify the most predictable human attack surfaces and how everyday environments create them
• Redesign processes and systems so secure behavior becomes the easiest, default choice
• Combine awareness, training, and environment design into a scalable strategy for measurable human risk reduction
In-Person & Virtual
Across many organizations, a pattern repeats itself. Phishing simulation runs. Results go to senior leadership. Employees who were tested hear nothing. No one knows if the organization passed or failed. A few months later, nothing has changed.
Working in technology and risk consulting outside the security function, I had an angle on this pattern that practitioners often do not. The problem was never the simulation design. It was the silence after it. The communication loop was broken by default, and the industry had normalized it.
The SANS Security Awareness and Culture Maturity Model names this failure precisely. Stage 2, Compliance Focused, measures success by completion rates with no metric for communicating results back to employees. Stage 3, Promoting Awareness and Behavior Change, is where phishing clicks and report rates first appear. The model identifies the crossing point. What does not spell out is the communication mechanism that gets organizations there. That is what this session addresses.
The research confirms that Stage 2 is where most organizations are stuck. KnowBe4's 2025 report found a baseline phish-prone rate of 33.1% across 14.5 million users. Organizations with structured follow-through reduced that to under 5% within 12 months. Hoxhunt data shows a 7% threat reporting rate in compliance-driven programmes versus over 20% in mature behavior change programmes. The difference is not the simulation. It is what happens after it.
Attendees will leave with two things. First, a five-step communication sequence for closing the feedback loop after any phishing or vishing simulation, covering timing, audience segmentation, and plain-language message framing. This is the practical mechanism for crossing from Stage 2 to Stage 3. Second, a long-term framework for progressing through Stages 4 and 5, drawn from behavior change evidence in adjacent fields and deliberately presented as an open industry debate, because the industry does not yet have consensus on what sustained culture change looks like at scale. That conversation needs to start somewhere.
Virtual
Artificial intelligence (AI) is already reshaping Security Culture and Awareness work. From drafting communication to generating phishing simulation ideas and creating short videos in a couple of minutes. For many practitioners, that creates both opportunity and anxiety: if AI can do the work faster and cheaper, how will this change our role?
In this session, Daisy Wong and Cheryl Wong will explore how Security Culture and Awareness professionals can embrace AI without becoming obsolete. Using the practical concepts of Human in the Loop and Human on the Loop, they will show attendees what can be automated, what needs oversight, and what must remain human-led.
This talk uses real world awareness examples and will go beyond content generation and focus on the capabilities AI cannot replace: strategic thinking, empathy, storytelling, stakeholder influence, and the ability to build trust across an organisation. Attendees will leave with a practical framework to help them use AI responsibly, protect the human value of their role, and reposition themselves as strategic leaders in human risk management.
In-Person & Virtual
Security culture does not improve through annual training, awareness posters, or phishing failure shaming. It improves when it is intentionally designed, measured, and continuously optimized using behavioral intelligence.
This session explores how organizations can move beyond traditional awareness programs and operationalize security culture using data-driven human risk management principles. Drawing from real-world enterprise experience in a multinational environment, this presentation demonstrates how phishing simulation trends, role-based exposure, reporting behavior, repeat failure patterns, and departmental risk concentrations can be transformed into actionable behavioral insights.
Attendees will learn how to identify high-exposure teams, interpret behavioral signals beyond simple click rates, and design targeted interventions that reduce risk without eroding trust. The session will also explore how to shift conversations from “who clicked” to “why risk exists,” aligning security culture initiatives with enterprise risk management and leadership priorities.
Rather than treating employees as the weakest link, this talk reframes them as a measurable and influenceable security control. Participants will walk away with a practical framework for designing security culture intentionally — integrating behavioral analytics, communication strategy, and leadership engagement into a scalable human risk model.
If you are looking to evolve your awareness program into a mature human risk management function that produces measurable outcomes, this session provides both strategic perspective and operational guidance to begin that transformation.
Virtual
Security awareness programs often focus on training content and phishing simulations — yet one of the largest drivers of human cyber risk is workforce instability, skills gaps, and retention challenges.
In this session, Deidre Diamond will explore how security awareness leaders can think beyond training delivery and begin managing workforce risk as part of a broader talent strategy. Drawing from decades of experience in cyber talent intelligence and workforce risk management, she will outline how hiring, onboarding, internal mobility, and retention directly impact organizational security posture.
Attendees will learn:
Participants will leave with a practical roadmap to shift from viewing awareness as a compliance requirement to treating it as an integrated workforce risk management function — one that strengthens culture, reduces vulnerability, and supports long-term resilience.
Virtual
Sara Mikail | From CISO Says No to Partner in Yes
Tim Ward | How Understanding Behavior Reduces Security Risk
Gabi Beasca | What a Spicy Campaign Can Teach Us About Executive Buy-In
Elsie Brown | What AI Becomes the Crisis: What 100+ Simulations Reveal About Human Behavior Under Pressure
Kerry Tomlinson | Unmasking Deepfake Deception: Inside a Celebrity Cyber Scam
From CISO Says No to Partner in Yes | Sara Mikail
Security teams are often branded as the “Department of No.” Policies block progress, controls slow teams down, and the CISO office becomes the villain in the room. We had the same problem and decided to tackle it not with more rules, but with culture. In this lightning talk, I’ll show how we used creative, experience-driven formats to shift that perception and build a lasting security culture across the organization.
How Understanding Behavior Reduces Security Risk | Tim Ward
In this talk Tim introduces the psychology and behavior science behind how we make decisions under pressure. From Kahneman’s System 1 and System 2, through deeper behavioral models that offer real insight into why our people do what they do. People-centric security risk isn’t an awareness or engagement problem, it’s a behavioral challenge. And so an understanding of how we really think, learn and behave at points of risk is fundamental to target and measurably change behavior. Tim will explore Dual Process Theory, nudge theory models like EAST and MINDSPACE, behavior models such as ABC and B=MAP. And offer some simple guidance as to how to use these in your programmes.
Gabi Beasca | What a Spicy Campaign Can Teach Us About Executive Buy-In
A lot of executive buy-in looks the same: a leader forwards the memo, says it matters, and expects the team to follow through. That may drive compliance, but it doesn't always create real influence. In this lightning talk, I’ll share what one 'spicy' campaign taught me about a more visible, human version of executive buy-in. Using a hot-wings-style leadership interview as the example, I’ll show how a high-visibility ask turned into a meaningful leadership moment; not because it was easy, but because it was thoughtfully positioned. This isn't a talk about copying one campaign. It's a talk about rethinking what buy-in can look like when leaders do more than sign off from a distance. Attendees will leave with three practical takeaways they can apply right away: how to choose the right leader to start with, how to position a bigger ask so it feels worth saying yes to, and how to design leadership moments that create momentum beyond a single video or event.
Elsie Brown | What AI Becomes the Crisis: What 100+ Simulations Reveal About Human Behavior Under Pressure
Your employees completed the phishing training. Your executives attended the tabletop. Your awareness program scored its highest engagement numbers yet. So why, when a deepfake of the CFO authorizes a fraudulent transfer, does the organization still fail to catch it in time?
Kerry Tomlinson | Unmasking Deepfake Deception: Inside a Celebrity Cyber Scam
A cyber news reporter takes you along as she goes undercover in a celebrity cyber scam to show you the tools and tactics that scammers are using to steal your money. The scammers in this real-life investigation deployed deepfake images, video and voice to pose as a famous singer. This session will examine how they utilized AI technology to further the crime, side by side with psychological tricks to manipulate us into compliance. Celebrity scams robbed victims of an estimated $5 billion in 2025. This talk will illustrate the latest cyber criminal strategies and the use of deepfakes, not just in this scam but in many others you face at work and at home. You’ll leave with practical strategies and awareness training tips to help your team recognize and resist deepfake-driven scams, even when you can’t trust your own eyes and ears.
In-Person & Virtual
Most organizations measure security culture through surveys, phishing simulations, and training metrics. While useful, these approaches often miss something critical: why employees make the decisions they do. Without understanding the underlying type of security culture in an organization, interventions can feel generic, misaligned, or ineffective.
This session introduces a practical, behavior-focused approach to measuring security culture using Situational Judgment Tests (SJTs), paired with other lightweight methods practitioners can apply in their own environments. SJTs present realistic scenarios and ask employees how they would respond, revealing patterns in decision-making that traditional metrics overlook. The result is a clearer picture of how security is actually understood, prioritized, and acted upon across the organization.
Using real-world examples from a global energy firm, this talk will highlight how different cultural patterns shape employee responses to security expectations and initiatives. Attendees will gain insight into how these patterns influence behavior in ways that are not visible through traditional metrics alone.
This session is not about adding another measurement tool. It focuses on shifting how we think about security culture, from something we broadly assess to something we can diagnose and act on. By the end of the session, attendees will understand why measuring the type of security culture matters, how to begin identifying it within their own organization, and how those insights can be used to better target interventions, training, and communication strategies.
Whether you are leading a security program or designing awareness efforts, this session will provide a practical starting point for moving beyond surface-level metrics toward more meaningful, behavior-driven insights.
Virtual
In-Person & Virtual
We’ve made real progress in security awareness, helping people recognize and respond to threats more effectively than ever before. But what happens when the threats no longer look like threats at all?
AI-generated phishing is now highly personalized and context-aware. Deepfakes can convincingly replicate trusted voices and identities - at the click of a button on widely available platforms that have no technical barrier to entry. And emerging autonomous agentic AI introduces something fundamentally new: systems that can initiate, sustain, and adapt interactions with humans over time.
In this environment, detecting social engineering and scams becomes unreliable, even for experienced professionals.
This keynote argues that the future of human risk management is not about improving detection, but about supporting better decisions under uncertainty. Drawing on behavioral science, real-world examples, and observed attack patterns, this session introduces a practical shift for awareness and culture leaders: from detection-based training to decision-focused design.
Attendees will leave with clear, actionable ways to evolve their programs, including how to redesign phishing simulations to reflect AI-era realism, introduce effective verification behaviors into workflows, and move beyond click-based metrics toward measures of decision quality.
This is not a technical deep dive into AI. It is a practical roadmap for those responsible for influencing behavior at scale, designed to help organizations build resilience in a world where attacks are increasingly convincing, persistent, and human-like.
In-Person & Virtual
Security awareness teams are expected to create engaging, interactive training, but many lack the time, budget or development resources to build anything beyond static content. This hands-on workshop introduces vibe coding: a practical approach to using generative AI as a creative and technical partner to co-build interactive training experiences; without traditional coding skills.
Participants will code along in real time as we collaboratively build a complete security awareness learning experience from scratch. Using AI prompts, lightweight logic, and common learning tools (e.g., Articulate Storyline, Rise, or equivalent platforms), attendees will design scenarios, interactions, branching logic, and assessments that can be reused in their own programs. This workshop prioritizes doing over watching.
Attendees will leave with:
We will intentionally share mistakes, failed prompts, and governance challenges encountered along the way.
Hands-On Workshop Project
Project: Build a short, interactive security awareness training experience (e.g., scenario-based module, microlearning, or branching quiz)
Participants will collaboratively:
No prior coding or AI experience required.
In-Person
At Postman, we recognized that traditional security awareness training was failing. It didn’t make the company safer but it did make our employees cranky.
So we decided to take a step back and ask ourselves:
How do we stay compliant while respecting employees' time?
How do we deliver training that meets people where they are?
How do we know it’s working?
Our approach flipped training on its head. Instead of forcing everyone through the same mandatory course, we introduced a test-out option: prove you know the material, and you're done. For everyone else, we replaced passive video-and-quiz formats with one-minute micro-modules followed by hands-on experiential assessments. The results were immediate. Employees started vociferously and publicly praising security training — some even asked to take it again. Our security engineers called the positive feedback "genuinely wild."
We also ran our first "Phish Fry" during Cybersecurity Awareness Month: a reporting-focused competition that rewarded employees for spotting and flagging threats rather than punishing those who clicked.
This talk covers three actionable shifts any security awareness team can make:
You'll leave with a concrete playbook for making these changes in your own program.
In-Person & Virtual
In-Person & Virtual
In-Person & Virtual
I spent six months redesigning a security team's materials. New structure, clearer guidance, knowledge organised around the questions people ask. It looked great. Within six months, the team reverted to blocking behaviours. We'd rearranged the furniture without changing how security saw itself.
That failure taught me something most security culture programmes miss. We spend effort on the visible layer: policies, awareness campaigns, reporting dashboards. When nothing sticks, we blame "the culture." But the root cause is deeper: the security function's own identity. How a security team defines its purpose shapes every interaction the organisation has with it.
Existing frameworks target the awareness programme and its maturity. This talk targets what sits beneath: the security team's self-concept. "We protect the organisation" and "we serve the organisation" produce completely different behaviours, metrics, and relationships with the business.
I'll introduce a sequenced model for identity-first culture change, tested across two organisations: a technology consultancy and a UK government body. The sequence matters. Change identity, then incentives, then narratives, then systems. The visible behaviours follow. Reverse that order (start with systems, hope behaviours stick) and you get my failure story.
I'll share specific artefacts: persona cards for security's customers, service menus that replaced document libraries, and the metrics that replaced "exceptions denied." I'll address the risk nobody calculates: the cost of security information not reaching the people who need it.
You'll leave with:
In-Person & Virtual
Let's name the thing nobody says out loud: most security awareness officers are the only person on the security team who's never invited into operational conversations. The SOC doesn't ask for your input. GRC doesn't include you in risk assessments. Security Architecture doesn't consult you on control design. You make posters. You send phishing simulations. You wonder if anyone takes you seriously. This workshop exists to change that - permanently!
In 120 minutes, you'll build three integration playbooks drawn from real processes we've run across +30 organizations. Not theory. Not "wouldn't it be nice." Actual workflows you can adapt and execute starting Monday.
Playbook 1: SOC Partnership. You'll map human risk indicators - role, data access, behavioral risk signals, VIP trust relationships - to alert prioritization in your incident management workflow, giving analysts the context they need and taking low-risk incidents off their plate entirely. You'll design a user self-remediation process that reduces SOC noise by 60%.
Playbook 2: GRC Partnership. You'll build a human risk overlay for a real security risk assessment. Most risk registers account for Process and Technology. People are either missing or reduced to "training completed: yes/no." You'll fix that, ensuring risk assessments and associated risk treatment plans reflect actual human risk factors.
Playbook 3: Security Architecture Partnership. You'll identify controls that introduce security friction, call out where human risk factors drive exposure, and redesign controls so the secure path is the easy path.
You'll leave with three ready-to-deploy playbooks, conversation scripts for approaching each team, and a 90-day integration roadmap.
This workshop is for security awareness officers who are done being the poster people and ready to become indispensable partners to their CISO and security team. Take and implement the playbooks that earn you a permanent seat at the table.
In-Person
For a long time, Security Awareness and Incident Response teams operated as separate silos. CSIRT handles technical breaches, while Awareness teams lead compliance and education initiatives. However, there is little structured exchange between these functions. This disconnect creates a critical intelligence gap:
CSIRT sees the "how" of a breach, but Awareness teams lack the real-world data to prevent the "why."
Drawing on my experience at a leading cryptocurrency company, I will provide a framework to establish a data-driven alliance between the Awareness team and CSIRT, enabling companies to move beyond generic training and deploy highly targeted strategies to implement behavioral interventions that make sense for each organization's unique environment.
By leveraging real-world incident data, companies can more effectively mitigate a broad spectrum of unintentional insider risks, starting with phishing, but extending to critical vulnerabilities like leaked credentials, unauthorized shadow IT, and social engineering.
Attendees will leave with practical strategies to:
Initiate the Partnership and Deconstruct the Silos: Tips for Awareness leaders to "speak the language" of the CSIRT to open communication channels and build a recurring “risk sync”.
Look Beyond the Inbox: Identifying human risks that go far beyond phishing by leveraging the direct support of CSIRT data.
Close The Intelligence Loop: Proven methods for translating technical IR post-mortems into actionable security interventions that provide clear, "human-ready" guidance for your users.
Ensure Measurable Impact: KPIs that prove how awareness reduces IR ticket volume, change behavior of the users and improves mean-time-to-remediate (MTTR).
Through this partnership, security awareness becomes more deeply embedded into the organizational culture, transforming it from a compliance requirement into a core business value. This data-driven approach provides the clear, operational evidence needed to secure executive buy-in and demonstrate the tangible ROI of human risk management.
In-Person & Virtual
Building a secure culture at scale it is quite a challenge, especially if you are responsible for driving awareness program in big, global companies - where local lenses make all the difference. We also have been there, trying our best to deliver meaningful awareness initiatives, utilizing mostly feedback about the local human risks.
Our dream was to have one data source that would help us focus on the most immediate risks and most importantly allow us to track the success of our initiatives - a metric based approach! So that is what we did. Joining forces with other security and data teams, we were able to design and build an in-house Human Risk Analysis Dashboard, including clear visualization of the real risk data cascaded to specific location and department.
We would love to share our journey, with all the successes and bumps along the way.
Join us if you would like to hear:
For us this is not only the story about the new “tool” we created, but about the proud moments of brining the real value to our leaders and security teams, who can now make decisions based on the real data we own. It’s also the story about how the passion of our awareness team turned into global solution and helped us prioritize what really matters. Like we say: 'Copy with pride' - we hope to inspire you, support with your journey and stay inspired by the community!
In-Person & Virtual
In-Person & Virtual
The Human Map is a longstanding Summit tradition and a favorite among attendees. At the conclusion of the first day, we create a large world map on the venue floor and invite participants to stand in the location that represents where they live or work. This interactive activity provides a unique opportunity to quickly identify and connect with peers from your region, as well as meet professionals from around the world. Held immediately before the evening networking reception, the Human Map serves as a natural starting point for meaningful conversations and new professional connections.
In-Person
Get ready to light up the night at our Summit Social! Enjoy complimentary food, beverages, and live entertainment from String Me Along, a DJ and live violin duo known for keeping the energy high. Wear your favorite glow-in-the-dark attire and accessories and join fellow attendees for an evening of music, networking, and fun.
In-Person
In-Person
In-Person & Virtual
In-Person & Virtual
One of the biggest challenges our community faces is building credibility and buy-in from key partners, including leadership, communications, and even our own security teams. In this panel, practitioners share the tips, methods, and approaches that have actually worked for them in winning that trust and opening doors.
In-Person & Virtual
In-Person & Virtual
Every SaaS platform invests heavily in securing its own infrastructure. Almost none invest in building the security capabilities of the people using it. That gap is where incidents live, and where this session starts.
Customer Security Evangelism is the structured practice of building security awareness, changing behaviours, and increasing capability within your customer base. It's widely practiced. It's nowhere formalized. No job description. No methodology. No measurement standard. This session changes that.
Drawing on a working program at Guidewire Software, a major insurance technology platform serving hundreds of enterprise clients, attendees will learn how to segment customers by security maturity and design communication that meets them where they are, not where you wish they were. You'll learn how to build a security narrative hierarchy: one version for the board, one for the security team, one for the end user, mapped to frameworks your customers already use. And you'll learn how to define behaviour change metrics that connect evangelism activity to measurable outcomes, the kind that protect program budgets when someone asks what you actually accomplished.
This isn't a product pitch. It's a blueprint drawn from behavioural science and social change communication, applied to the hardest problem in platform security: the people on the other side of your shared responsibility line.
You'll leave with a segmentation model, a narrative hierarchy, and a measurement approach you can start building on Monday.
Attendees will be able to:
In-Person & Virtual
Come ready to solve the problems every security awareness leader is dealing with right now.
Join Hannah and Pooja for a highly interactive roundtable where you’ll roll up your sleeves and tackle real program challenges alongside your peers.
We will examine problems such as:
You won’t just talk about these challenges; you will brainstorm realistic solutions using proven behavioral and program design approaches like EAST, Fogg, and ADDIE. Walk away with ideas you can take back and use immediately, plus a better sense of how other teams are navigating the same pressure points.
In-Person
Psychology draws a distinction between “states” which are short-term influences on behavior and “traits” which are more durable parts of an individual’s personality. Research typically focuses on traits but often neglects the more transient reasons why people take shortcuts or make suboptimal decisions.
In this talk, we will cover the impact of mental health on cybersecurity behaviors. The audience will learn about the toxic and corrosive effect of certain hormones and neurotransmitters on attention and working memory. Then, we will transition the discussion to resilience and cover how one overcomes adversity through positive adaptivity. Finally, we will conclude with a discussion of strategies for building positive mental health and connect those strategies back to positive cybersecurity behaviors.
In-Person & Virtual
The most significant security gap in modern organizations isn't in the cloud; it’s on the front lines. While cybersecurity evolves at the speed of AI, a vast portion of the global workforce operates in physical, high-pressure environments with varying levels of digital maturity.
These employees are often neglected by traditional, screen-based awareness programs, leaving them—and their companies—vulnerable.
In this session, I will share the 'boots-on-the-ground' methodology I used to bridge the gap between corporate security and offline field operations, demonstrating how to transform a deskless, non-technical workforce into a proactive frontline of defense.
Key Takeaways:
Moving Beyond the Inbox: I will outline how to design "analog-friendly" strategies that resonate with operational roles, replacing ineffective weekly email blasts with high-impact physical triggers, on-site visual cues, and face-to-face engagement cycles that exist where the work actually happens.
Measuring Culture Without "Clicks": I will outline how to implement behavioral KPIs tailored for field operations, focusing on the voluntary reporting of physical risks and proactive peer-to-peer accountability. This methodology provides a true 360-degree view of human risk that reflects the operational reality of the front line.
Preparing the Non-Technical Workforce for AI: I will outline how to build a human-centric foundation that reframes security as a core professional trade skill. By anchoring security protocols into existing organizational values, I will show how to cultivate the psychological safety and trust required to operationalize advanced AI policies across a diverse, distributed workforce.
In-Person & Virtual
Mandatory security awareness training is widely deployed, yet frequently criticized for low engagement and limited impact on real-world behavior.
This case study shares how one global organization redesigned its mandatory program to address a specific challenge the awareness community continues to struggle with; how to make mandatory training meaningful, role-relevant, and behavior-focused—without adding time or burden. We will walk through how a traditional annual course was replaced with a modular, role-aware learning experience that adapts to employee context, tenure, and risk exposure, including non-office and operational roles. Rather than adding “games” for engagement alone, we applied lightweight gamification techniques—scenario-based decisions, challenges, and immediate feedback—to reinforce secure behaviors employees face in their day-to-day work.
The session focuses on what worked well, where assumptions failed, and what we had to course-correct. Lessons include balancing credibility with play, avoiding over-gamification, managing scalability across a global workforce, and resisting reliance on completion metrics as a success signal. Finally, we will share how the program is evolving: moving toward behavior-based measurement, deeper role differentiation, and tighter integration with phishing simulations and coaching. Attendees will leave with practical design principles they can apply to modernize mandatory training in their own organizations.
In-Person & Virtual
In-Person & Virtual
Security awareness teams face a difficult reality: employees are moving faster, sharing more, and increasingly using AI in everyday work.
Training completion may look great, yet familiar data mistakes still happen, a confidential file goes to the wrong recipient, an overly broad sharing link exposes sensitive content, permissions remain wider than intended, or customer data is pasted into an AI tool. Why? Because risk often appears in a real work moment, under time pressure, when the employee is simply trying to get the job done.
This session explores a practical alternative to relying on more training or broader reminders: designing safer moments directly into the flow of work. Drawing on lessons from large enterprise data protection and security programs, Pooyan Hamidi will walk through seven micro-interventions organized around when the risky decision happens—before, during, and after the action. You will see how safe defaults, classification at creation, workspace guardrails, just-in-time warnings, justification prompts, AI boundary reminders, and near-miss coaching can help people make safer decisions without unnecessarily slowing legitimate work. The session also covers an important lesson from implementation: even the right interventions can backfire when organizations launch too much at once, use vague policy language, create excessive friction, or measure activity instead of behavior. Attendees will leave with a practical approach for moving from human risk to a specific behavior, moment, intervention, and metric. You will also get a ready-to-use intervention selection checklist, a focused 30-day pilot approach, sample message patterns people will actually read, and a simple measurement model that shows leadership whether risky behaviors are going down and safer choices are becoming habits. The goal is simple: stop asking people to remember security at exactly the right second—and start designing safer choices into the moments that matter.
In-Person & Virtual
Organizational changes shouldn’t derail your Security Champions program. In this hands‑on workshop, you’ll build a practical, outcome‑based operating model that survives leadership turnover.
Using the E2I‑C method (baseline → map → instrument → pilot → roll out), you’ll map activities to outcomes with the Connect / Find / Fix / Prevent (C/F/F/P) framework, define manager‑friendly metrics (visibility, consistency, AI readiness, behavior), and assemble a leadership dashboard leaders can evaluate and iterate. We’ll capture the metrics you can measure now, draft a data dictionary for those you can’t (yet), and design a pilot plan that withstands org changes and skeptical leadership. We’ll also address common pitfalls (like non‑aggregable scorecards) and show how to pivot to shared outcomes and turnover‑proof KPIs.
Attendees leave with: a Champion Charter, Outcome‑Mapping Worksheet, Dashboard Schema & Data Dictionary, a leader‑friendly brief, and a 90‑day rollout plan. The workshop is tool‑agnostic and focused on template-driven steps, behavior signals, and operating rhythms so you can demonstrate value and maintain support even as structures and budgets change.
In-Person
Four people-related questions are increasingly being asked of security teams, yet most human risk management programs struggle to answer them. Which behaviors, and from which groups, are most likely to result in a breach? What is actually changing as a result of our behavioral interventions? Can we measure positive security behaviors, or only identify where they break down? And when we identify a behavioral risk, how precisely and quickly can we respond?
The reason these questions are so difficult to answer is not a lack of tools. It is a lack of a shared language. For years, our field has primarily reported simulation click rates, phishing reports, engagement metrics, and training completion rates because that was all our data could support. This session explores how SebDB, the open-source database of security behaviors, is evolving from a simple list into a comprehensive behavioral ontology that maps the relationships among behaviors, threats, risks, and controls. You'll also see how security professionals around the world are using SebDB to answer the most important human risk management questions and describe their programs using the language of risk.
Starting with the fundamentals, Oz will walk through the SebDB database and ontology in its simplest form before demonstrating how the same structure enables organizations to move from measuring activities to producing meaningful evidence, one question at a time. SebDB is open, free, and vendor-neutral. You'll leave with a practical framework for answering the four questions, an understanding of how to apply SebDB in your own program, and a clear perspective on why answering these questions is what makes you indispensable.
In-Person & Virtual
You ARE the IT department. You are also the security team, the awareness program, and the culture change initiative. You have no budget, no dedicated staff, and a workforce that clicks through compliance training and forgets everything by Friday.
Nobody is coming to save you. But you already knew that. Good thing you like a challenge.
Clicking through an annual module isn't culture. Culture is what your staff does when nobody is watching. And this talk is about building exactly that.
At an alternative education nonprofit, I designed and ran a 12-week voluntary champion program using quest-based learning and fantasy-themed red team trials to reframe security from a compliance burden into something staff actually want to engage with. Here's the ground-level account: the wins, the wipes, and what I'd roll differently on a second playthrough.
You'll leave knowing how to scout champions by behavioral traits rather than technical skills, because the best security advocates in your building probably don't have "security" in their job title. You'll know how to run red team trials that teach rather than punish, with debrief structures that turn getting caught into a learning moment. You'll know how to build toward a tabletop exercise your staff is actually ready for, because champions deserve a victory lap before the boss battle. And you'll know how to design participation pathways that work across communication styles and neurotypes, because a security culture that only works for one kind of person isn't a security culture at all.
You'll walk away with the complete toolkit, ready to adapt for your own organization.
The security team you need is already in your building. Find them, train them, and more importantly, trust them.
In-Person & Virtual
In-Person & Virtual