In his CYBR.SEC.CON. 2026 keynote, Joe Marshall introduces the Human Incident Response Framework, a practical playbook for recognizing cybersecurity burnout, secondary traumatic stress, vicarious trauma and moral injury — and responding before the human incident becomes a crisis.
Featured
Ann Delenela, VP and CISO at Entergy, on the lessons surviving the fall of South Vietnam, hang gliding over the Pacific and leading through a personal health crisis can teach security leaders about the age of AI.
RegScale CISO Dale Hoak explains why point-in-time cybersecurity compliance cannot keep pace with AI-driven threats — and why continuous controls, risk management and resilience must replace the checkbox mindset. (Sponsored by RegScale)
Community Corner
See allFrom the CYBR.SEC.Community
Cybersecurity Coherence Reduces Cognitive Risk, But Is Not Perfect
Three teams are talking at once. An attacker may still be active. The logs disagree. The current owner is on vacation. A cloud console shows one state, the SIEM shows another, and the incident commander has a spreadsheet that was copied from a spreadsheet that was correct last quarter.
How 9/11 Led Me to Cybersecurity — and What 25 Years Has Taught Me
Twenty-five years after the Sept. 11 attacks, I look back at how 9/11 changed my life, led me into cybersecurity and shaped how I see our responsibility to protect the systems and civilization we depend on.
Your Security Architecture May Be a Sideways Driveway
Security architecture accumulates “adaptation debt” when local fixes, exceptions and compensating controls force users, systems and now AI agents to work around designs that no longer match how identity, authority and data actually flow.
What Radio Jamming Taught Me About DDoS
From Army signal intelligence and radio jamming to modern DDoS defense, the same lessons in reconnaissance, timing, disruption and adaptation reveal how attackers overwhelm networks — and how defenders can stay ahead.
The Human Factor in IAM: Why Identity Programs Succeed or Fail
Most IAM failures don't start with a broken platform. They start with a person making a reasonable decision under bad conditions.
Latest Articles
See all
CISOLeadership
Does the CISO Need a Board Seat? That's Not the Real Question
RegScale CISO Dale Hoak says the cybersecurity leadership debate should focus less on reporting lines and more on ensuring cyber risk reaches the board — while security, compliance and engineering stop fighting separate battles. (Sponsored by RegScale)
Open-Source SecuritySuricataCYBR.SEC.CON
Open Source Security Runs The Internet. Kelley Misata Says Code Is Only Half The Battle
At CYBR.SEC.CON 2026, OISF President Kelley Misata explains why critical open source security projects like Suricata depend on more than developers — and why funding, governance, licensing and succession planning are now cybersecurity issues.
Hugging FaceAI GovernanceAI security risks
OpenAI Agents Left a Wider Trail on Hugging Face
OpenAI agents left a larger public trail on Hugging Face than the company documented in its account of unauthorized activity earlier this year, according to a new SentinelLabs investigation.
LaunchPadCYBR.SEC.CON
Astelia wins CYBR.SEC.CON 2026 LaunchPad competition
The exposure management startup beat four other early-stage cybersecurity companies at CYBR.SEC.CON 2026, pitching an approach that focuses remediation on vulnerabilities attackers can actually reach.
AI security risksHuman Risk ManagementCYBR.SEC.CON
AIpocalyptic Decisions: Andy Ellis Warns AI Could Exploit How Humans Make Choices
CYBR.SEC.CON. 2026 speaker Andy Ellis explores how AI, algorithms and human cognitive shortcuts could combine to undermine the decision-making systems that helped humanity thrive.
Cognitive WarfareCognitive SecurityCYBR.SEC.CON
The Cognitive Pearl Harbor: Winn Schwartau Says Cybersecurity Must Learn to Ignore
CYBR.SEC.CON. 2026 opening keynote argues that critical thinking is no longer enough in an age of AI, algorithms and information overload. Security starts with knowing what deserves our attention.
AI.SEC.CONAI GovernanceCYBR.SEC.CON
AI Failures Aren't New Security Failures. Liz Wharton Says Fix the Basics
At CYBR.SEC.CON. 2026’s first AI.SEC.CON. track, Elizabeth Wharton argues that headline-grabbing AI disasters keep exposing familiar failures in validation, least privilege, data governance, trust boundaries and change control.
Podcasts & Video
See all
Podcast
Compliance Whack-a-Mole with Dale Hoak
Video
Trust in the Age of AI
Video
CometJacking and Domain Swarms: Hunting AI Attacks in the Staging Phase
Video
You Can’t Automate Judgment: The Limits of AI in Cyber Threat Intelligence
Podcast
From Used Car Sales to Counterterrorism with Christian Schnedler
Video
T-10: Countdown Without Readiness
Video
Microsoft RemoteApp Breakout and Bypasses
This talk by Jon Rhodes explores security vulnerabilities and evasion techniques targeting Microsoft RemoteApp, focusing on breakout methods that escape the isolated RemoteApp container to access the underlying host system, as well as bypasses for common detection and restriction mechanisms.