Yesterday, I wrote about why CYBR.SEC.Careers is getting aboard CruiseCon 2026 and why I'll be there covering it for CYBR.SEC.Media:

Today, let's get into what we'll actually be talking about.
CruiseCon Privacy & AI departs Galveston aboard Mariner of the Seas Oct. 3 and returns Oct. 8. But this isn't a conventional cybersecurity conference that happens to have been dropped onto a cruise ship. The schedule is deliberately compact: concentrated blocks of talks, roundtables and networking on the days at sea, with Oct. 5 and 6 set aside for group excursions in Costa Maya and Cozumel.
That leaves room for something I particularly value at security conferences: conversations that continue after the speaker leaves the stage. Judging by the agenda, there should be plenty to talk about.
It starts with the CISOs
CruiseCon gets underway Oct. 3 with networking followed by a Global 500 CISO Ask Me Anything Panel featuring Cory Watts, CISO at Memorial Health System, and Justine Bone, executive director of Crypto ISAC.
What counterterrorism can teach cybersecurity
Oct. 4 begins at 7 a.m. with Dexter Ingram, former deputy director for WMD terrorism at the U.S. Department of State, presenting "Dead in the Water — What! Terrorism Taught Me About the Threats You're Actually Facing."
Ingram brings three decades of counterterrorism experience, including work in Afghanistan, at INTERPOL and running the State Department's Office of Countering Violent Extremism. His premise is fascinating because the worlds of counterterrorism and cybersecurity increasingly began colliding during his career.
Encrypted platforms, social engineering and the exploitation of human vulnerabilities are familiar terrain to defenders. Ingram will examine what happens when adversaries adapt, disappear and rebuild faster than the institutions trying to stop them. He'll also address AI-driven radicalization and the increasingly compressed timelines confronting people responsible for organizational risk.
One point in the session description particularly caught my attention: the difference between having intelligence and knowing what to do with it. Cybersecurity has no shortage of data. Turning it into timely decisions is another matter entirely.
When AI becomes the insider threat
At 8 a.m., Erin Whitmore, head of the Adversary Pursuit Group at BlackPoint Cyber, takes on "AI as the Next Insider Threat: Data Manipulation, Cognitive Trust, and the Weaponization of Decision Intelligence."
As AI becomes a trusted input into decisions about cyber defense, fraud, supply chains, capital allocation and other business functions, attackers don't necessarily have to compromise the AI itself. Manipulating training data, telemetry, intelligence feeds or retrieval pipelines may be enough to influence what the system tells humans to do.
That can produce distorted risk models, bad forecasts, misplaced security investments and flawed executive decisions. Whitmore will also examine automation bias — our tendency to put too much faith in machine-generated answers simply because the machine appears authoritative.
That strikes at one of the larger questions surrounding AI adoption right now: What happens when humans begin trusting automated judgment faster than they've learned how to validate it?
More on AI risks:



Privacy has to evolve with the technology
The morning then moves squarely into CruiseCon's other major theme: privacy.
Adriana Winkler, global privacy lead at Accenture, is scheduled at 9 a.m. for "Aligning Worldwide Privacy Regulations."
At 10 a.m., former IAPP Vice President Peter B. Kosmala presents "Professionalizing the Privacy Future." Kosmala will question whether the traditional privacy model — aligning organizational policies and practices with laws and regulations — is sufficient when AI, blockchain and quantum technologies are putting new pressure on information rights and intellectual property.
That's followed by group lunches and afternoon roundtables, where I suspect many of these conversations will continue without microphones or slides.
Then we test the AI hype against reality
After the Costa Maya and Cozumel excursion days, CruiseCon gets back to business Oct. 7.
Ira Winkler, CISO at CYE Security, starts the morning with "AI is Just Math."
At 8 a.m., Kurt Kaufmann, application security leader at Blizzard Entertainment, gets into something I've been wanting to see more of: What has actually happened since security organizations began putting generative AI to work?
Kaufmann will look at areas where LLMs have provided value — including alert analysis, vulnerability work, unfamiliar code, attack paths and threat intelligence — alongside cases where seemingly convincing AI conclusions were simply wrong. The central problem is one security practitioners already understand: a model can organize evidence and recommend next steps, but it doesn't automatically know the production environment, compensating controls, business impact or what an attacker is actually doing. Human validation remains essential.
Security leadership still comes down to people
At 9 a.m., Waste Management CISO Jerich Beason will examine AI across security operations, application security, vulnerability management and threat intelligence, with particular attention to where AI-generated conclusions can appear plausible while missing environmental context or misjudging risk.
Then Sean Barnes, CEO of Wolf Executives, takes the 10 a.m. slot with "Executive Presence: Becoming the Leader People Trust at the Next Level." Barnes will focus on confidence, communication, listening, business understanding and trust — the skills that increasingly matter when security leaders move from explaining technical problems to helping executives and boards make consequential decisions.
And if AI is going to force more complicated conversations about risk, privacy and accountability into the boardroom, those skills aren't becoming less important. They're becoming more important.
Why CYBR.SEC.Careers is on this voyage
There's another reason we're invested in CruiseCon beyond the subject matter.
CYBR.SEC.Careers is an official sponsor of CruiseCon 2026.
As I wrote yesterday, CYBR.SEC.Careers exists to help students, veterans and professionals transitioning into IT and cybersecurity build a pathway into this industry through mentoring, scholarships, certifications, career development and direct access to people already doing the work. That's part of the larger CYBR.SEC.Community mission: support the people already here while creating opportunities for those coming next.
An event that puts people entering and advancing through this profession in sustained contact with CISOs, security practitioners, privacy leaders and people with decades of national-security experience fits that mission pretty well.
I'll be aboard covering all of it for CYBR.SEC.Media. As I mentioned yesterday, I'll be recording video interviews and keeping a daily ship's log with the conversations, observations and lessons that stand out along the way.



