Open Sessions
Conference Pass
SecureWorld Plus
VIP / Exclusive
- Wednesday, September 23, 202610:30 amExhibitor Hall openRegistration Level:
Open Sessions
10:30 am - 5:00 pmLocation / Room: Exhibitor HallYour opportunity to visit our solution vendor partners, whose sponsorship makes SecureWorld possible! Peruse the many downloadable resources each booth has to offer.
11:00 amOPENING KEYNOTERegistration Level:
Open Sessions
11:00 am - 11:45 am11:45 amNetworking BreakRegistration Level:
Open Sessions
11:45 am - 12:00 pmLocation / Room: Exhibitor HallVisit the Networking Hall to network with attendees and connect with our vendor sponsors and association partners.
12:00 pmThe Quantum Cryptography RevolutionHead of Security Engineering, MassMutualRegistration Level:
Open Sessions
12:00 pm - 12:45 pmQuantum cryptography isn’t a distant concept; it’s an active, deployable technology that will define the future of secure communication.
This presentation explores how quantum mechanics is reshaping cybersecurity. We’ll cover the limitations of classical encryption in a post-quantum world, the principles behind Quantum Key Distribution (QKD), and real-world implementations already in use. Attendees will also get a glimpse into the quantum-safe future being built today by governments and enterprises globally.
12:00 pmGRC-as-Code: How Security Teams Can Ship AI Governance Without Slowing Down EngineeringRegistration Level:
Open Sessions
12:00 pm - 12:45 pmSecurity governance for AI systems is stuck in 2015. GRC teams write PDF policies. Engineering teams ignore them. When a developer wants to connect a new tool to their AI agent, the review takes days. By the time the policy doc is updated, the architecture has changed twice.
This session presents a policy-as-code approach to AI governance that gives GRC teams direct control over runtime enforcement without requiring engineering deployments. Using OPA/Rego as the policy engine, governance rules become version-controlled, testable, and hot-reloadable artifacts that enforce at the point of action rather than the point of review.
The talk walks through real implementation: writing Rego policies that map to NIST 800-53 controls, building a policy bundle pipeline so GRC pushes updates without deployments, and separating policy ownership from infrastructure ownership so security teams and engineering teams stop blocking each other.
Key Learnings:
- Why document-based AI governance fails in fast-moving engineering organizations
- Implementing policy-as-code with OPA/Rego for AI agent runtime enforcement
- Mapping Rego policies to NIST 800-53 and ISO 27001 control families
- Building a GRC policy pipeline: version control, testing, hot-reload, and audit trails
- Organizational patterns for separating policy ownership from infrastructure deployment
12:00 pmCloud Encryption DynamicsRegistration Level:
Open Sessions
12:00 pm - 12:45 pmThe emergence of cloud computing resulted in a boom in attention on encryption. Where has encryption benefited cloud computing, and where have hopes been dashed? What are today’s models, and what impact will the latest technologies—confidential computing, privacy preserving encryption, homomorphic encryption, for example—have in the years ahead? This session will provide an overview of cloud encryption dynamics that probably contradicts at least one thing you believe on that topic. Come join this session and learn from someone that’s lived in the trenches and values constructive debate.
Paul Rich is the Executive Director of Data Management & Protection at JPMorgan Chase & Co. From 1998 to 2019, he worked at Microsoft where he worked with encryption technologies and developed new features in Office 365 for protecting customer data. Paul aspires to evangelize unfortunate truths and debunk popular myths regarding encryption and cloud computing.
12:45 pmNetworking BreakRegistration Level:
Open Sessions
12:45 pm - 1:00 pmVisit the Networking Hall to network with attendees and connect with our vendor sponsors and association partners.
1:00 pmQuantum Readiness: Preparing Your Organization for a Post-Quantum FutureRegistration Level:
Open Sessions
1:00 pm - 1:45 pmSession details to come.
1:00 pmThe Invisible Heist: How Quantum Computing Is Already Attacking Your Encrypted DataSecurity Engineer, ConfidentialRegistration Level:
Open Sessions
1:00 pm - 1:45 pmNation-states are today collecting encrypted organizational communications with one goal: decrypt them when quantum computers arrive. This confirmed strategy—Harvest Now, Decrypt Later—is named in NSA/CISA joint advisories and attributed to nation-state actors including China’s Volt Typhoon and Salt Typhoon groups. Meanwhile, every commercial Quantum Key Distribution system ever independently tested has been defeated through hardware attacks. And in July 2022, a NIST Post-Quantum Cryptography finalist was completely destroyed by a classical laptop attack in 62 minutes.
This session is a practitioner’s field guide to the quantum threat landscape for IT security engineers. No physics background required. We cover six threat domains: HNDL campaigns and which data categories are already at risk; Shor’s and Grover’s algorithms and their precise impact on RSA, ECDH, AES-128, and SHA-256;three physical attacks that defeated commercial QKD hardware with confirmed evidence; implementation vulnerabilities in the surviving NIST PQC standards including timing side-channels in ML-KEM; and a specific week-by-week enterprise migration roadmap based on the 2024 NIST standards.
This session is the result of deep research into published attack papers, hardware demonstrations, and the NIST PQC standardization process—distilled into intelligence that IT security teams can act on immediately.
1:00 pmFrom Alert Fatigue to Adaptive Defense: Operationalizing AI in the SOCRegistration Level:
Open Sessions
1:00 pm - 1:45 pmSession details to come.
1:45 pmNetworking BreakRegistration Level:
Open Sessions
1:45 pm - 2:00 pmVisit the Networking Hall to network with attendees and connect with our vendor sponsors and association partners.
2:00 pmThe Future of Encryption: Quantum Computing and AIRegistration Level:
Open Sessions
2:00 pm - 2:45 pm“The Future of Encryption: Quantum Computing and AI” explores the impending impact of quantum computing on current encryption methodologies and how AI can offer solutions. This presentation highlights quantum-resistant encryption algorithms, preparing audiences for the significant changes quantum advancements will bring. Case studies from startups and tech firms developing quantum-safe encryption solutions will provide practical insights. The key takeaway will emphasize the urgency of adapting to quantum computing developments to ensure robust, future-proof encryption strategies. This topic is crucial for understanding the evolving landscape of cybersecurity in the quantum/AI era.2:00 pmFrom Pilot to Production: Launch Readiness for Enterprise AI AgentsFocus Areas: AI; Agentic AI; AI GovernanceRegistration Level:
Open Sessions
2:00 pm - 2:45 pmAI agents are new, but the security questions are timeless: who owns the system, what can it access, what actions are allowed, and how do we respond when something goes wrong? As enterprise AI moves from pilots into workflows that retrieve data, call tools, update records, and trigger business actions, this session gives security and governance leaders a practical launch-readiness model covering ownership, risk tiering, data boundaries, identity, tool permissions, human approval, logging, exception handling,
and incident response.Attendees will leave with a launch-readiness checklist that applies timeless security principles to enterprise AI agents: ownership, least privilege, layered control, human judgment, logging, resilience, and incident response.
2:00 pmBeyond Logs: Closing AI-Era Security Blind SpotsRegistration Level:
Open Sessions
2:00 pm - 2:45 pmAI is changing the economics of cyber risk. Vulnerabilities can now be discovered, prioritized, and exploited faster than many organizations can validate their real exposure. A logs-only view is no longer enough because logs show only what systems report, not everything attackers can reach. The highest-risk gaps often sit in east-west traffic, encrypted sessions, fast-moving cloud and container environments, and unsanctioned AI services operating outside formal oversight.
Attendees will learn how network telemetry provides the evidence needed to make better security decisions. It helps teams determine which vulnerabilities are truly exploitable, uncover lateral movement and shadow AI usage, and prioritize detection and remediation around the most critical attack paths. The outcome is not just faster action, but measurably lower cyber risk and stronger business resilience.
2:45 pmNetworking BreakRegistration Level:
Open Sessions
2:45 pm - 3:00 pmVisit the Networking Hall to network with attendees and connect with our vendor sponsors and association partners.
3:00 pmAI, Quantum, and the Cryptographic Countdown: A Ticking Clock for Security LeadersRegistration Level:
Open Sessions
3:00 pm - 3:45 pmAs quantum computing threatens to undermine classical encryption, security leaders are racing to develop cryptographic models that can withstand its power. But quantum alone isn’t the whole story, and artificial intelligence is now accelerating both the development and the threat landscape of cryptographic systems.In this session, we’ll explore how AI is reshaping the field of quantum cryptography, from enhancing quantum key distribution protocols to automating the discovery of post-quantum vulnerabilities. We’ll examine real-world scenarios where AI accelerates the design of quantum-safe algorithms and how adversaries may weaponize AI to exploit cryptographic transitions.Whether you’re planning a migration to post-quantum cryptography or evaluating the security of your digital infrastructure, this talk provides a forward-looking perspective on how AI is shaping the cryptographic future. The era of AI-driven quantum security has begun. Are we ready for it?3:00 pmBeyond the Signature: Advanced Endpoint Detection and HardeningRegistration Level:
Open Sessions
3:00 pm - 3:45 pmSession details to come.
3:00 pmQuantifying Security Debt: Communicating Risk and Driving Remediation with the CFORegistration Level:
Open Sessions
3:00 pm - 3:45 pmSession details to come.
3:45 pmNetworking BreakRegistration Level:
Open Sessions
3:45 pm - 4:00 pmVisit the Networking Hall to network with attendees and connect with our vendor sponsors and association partners.
4:00 pm[Closing Keynote] Beyond Post-Quantum: QKD, AI Agents, and the Future of Critical Infrastructure TrustCISO & Assistant CTO for Security and Infrastructure, City of SeattleRegistration Level:
Open Sessions
4:00 pm - 4:45 pmCritical infrastructure is entering a multi-decade trust transition that no single technology will solve. Post-quantum cryptography is now a mandatory foundation for long-lived systems, software supply chains, identity platforms, and sensitive data protection. Quantum key distribution is also moving from research into selective critical infrastructure pilots and demonstrations, but it comes with real operational limits that security leaders must understand. At the same time, AI agents and machine identities are changing what authentication, authorization, delegation, and provenance mean inside enterprise, operational, and security environments. This keynote separates signal from hype and maps where PQC, QKD, AI agents, machine identity, software provenance, and next-generation cyber operations converge, and where they should not be confused. Attendees will leave with a practical trust map for the next five years: what to inventory, what to modernize, what to ask vendors, and how to prepare critical infrastructure for quantum-era and AI-native security risk without chasing science fiction or vendor checklists.
- Google Cloud SecurityBooth: n/a
Google Cloud Security provides organizations with leading infrastructure, platform capabilities and industry solutions to help them solve their most critical business problems. Google Cloud Security helps customers protect their global operations with solutions such as zero trust security, application and data protection, fraud prevention, and threat detection and response.
Sridhar BoddulaHead of Security Engineering, MassMutualSridhar Boddula is a cybersecurity executive leader and Head of Security Engineering at MassMutual, where he leads enterprise security modernization across identity, cloud, and data protection, driving digital trust, operational resilience, and business-aligned cybersecurity transformation at scale.
Sindhura KonaSecurity Engineer, ConfidentialSindhura is a cybersecurity engineer specializing in emerging threat analysis and enterprise security architecture. With a practitioner's focus on translating complex security research into actionable guidance, Sindhura brings the grounded, real-world perspective to quantum security that is too often absent from discussions dominated by academic theory or vendor messaging.
Jake HammockCISO & Assistant CTO for Security and Infrastructure, City of SeattleJake Hammock is the Chief Information Security Officer, Assistant Chief Technology Officer and Security & Infrastructure Director at the City of Seattle, where he leads the Security & Infrastructure Division delivering citywide cybersecurity, enterprise infrastructure, cloud operations, IT service management, telecom and radio systems, fiber, and network services. He directs programs for incident response, identity and governance, enterprise architecture, and system and network operations, aligning investments to resilience, public safety, and civic administrative priorities across the nation’s 17th largest municipality through This Is Your City programs.
Jake’s career spans executive roles in government and industry. He served as Director of Trust and Vice President of Information Security at NICE inContact, leading board-level cybersecurity and privacy programs during a period of accelerated high growth. He was the Chief Technology Officer for a top 10 global fintech by peak market cap, patenting and deploying technologies used in production today, and later CTO for an energy-sector solutions provider, where he architected AI-driven cybersecurity platforms and advised enterprise energy and public-sector clients. A former U.S. Army Military Intelligence and Cyber Warfare Officer, he commanded Cyber National Mission Force units and served in national security leadership assignments within the Intelligence Community. He is a combat veteran, holds an M.Sc. in Cybersecurity Technology and patents spanning telecommunications, environmental platforms, and decentralized technologies, and he remains active in advancing secure AI, quantum-resilient encryption, data governance, and critical infrastructure protection.
Hone your skills and knowledge and earn 6 CPE credits.
