9 AI Security Lessons From CYBR.SEC.CON 2026
Nine AI security lessons for CISOs on agents, identity, governance, compliance, cognitive risk, open source and human resilience.
Nine AI security lessons for CISOs on agents, identity, governance, compliance, cognitive risk, open source and human resilience.
Entergy CISO Ann Delenela used her CYBR.SEC.CON. 2026 keynote to argue that AI and accelerating change demand something technology cannot provide: deliberate, accountable human leadership.
A small but growing cohort of organizations has moved agentic AI from pilot to production and is already operating at a fundamentally different level. The gap between them and everyone else is growing.
A new Forrester/TransUnion survey finds 77% of security leaders rank reputation damage above revenue loss after a cyberattack — and the reasoning behind that shift matters more than the stat itself.
Chinese intelligence operatives are using fake consulting firms, job offers and recruiter profiles to target U.S. security clearance holders and other government and defense professionals.
Detection engineering has always been expensive, slow, and dependent on scarce senior talent. AI is changing that resource equation — and giving security teams a way to measure and close coverage gaps that most programs have never been able to quantify.
Agentic AI is delivering sharper triage, faster investigations, and reduced analyst burnout at the organizations that have committed to production deployment. For everyone else, the gap is compounding, and the security implications are already visible.
Network segmentation, credential hygiene, behavioral monitoring, automated containment. The OpenAI incident didn't invent these requirements. It proved that skipping them in agent environments has consequences.
Applications average 22 critical vulnerabilities while teams fix just 3.4 per month, exposing a widening AppSec gap that AI is making harder to close.
AI-powered attacks are moving faster than traditional IOC sharing can keep up, forcing security teams to rethink how they detect threats and share threat intelligence.
Many believe cybercriminal asymmetry allows foreign cybercrime gangs to operate with near impunity, and that decades of legislative fixes, like the repeatedly stalled Active Cyber Defense Certainty Act, have gone nowhere. Others are concerned that the doctrine may create more mayhem than it solves.
Agentic AI is closing the SOC automation gap that SOAR never did, whether the guardrails around it are explicit enough to stop a breach, survive a regulatory audit or a court case is a different question.
SAP attackers moved within 72 hours of a patch, showing how AI-assisted exploit development is collapsing vulnerability response time.
Agentic AI demands identity, observability, egress controls and inventory to detect rogue actions and enforce enterprise guardrails.
AI agents breached real systems. We separate autonomous AI cyberattacks from human-assisted operations and industry hype.
Self-adapting AI worms, a vetoed California bill, and a 1.4% replacement rate: how AI's founders split on security, regulation, and jobs at Ai4 2026.