What Attendees say
The technical deep-dives are fantastic – I always walk away with new tools or techniques I’m excited to try out. You can tell the organizers are doing this for the community – from the thoughtful mix of speakers to the awesome variety of venues..
The talks delivered real, practical value – not just high-level theory or vendors promoting their products – and I walked away with actionable insights I could apply right away. I’d absolutely attend again.
It was a fantastic opportunity to learn from fellow practitioners, share real-world insights, and make meaningful connections. A must-attend event for anyone passionate about application security and staying ahead in the field…
Join us at Planet Cyber Sec AI AppSec, where security professionals, developers, and business leaders come together to bridge the gap between AI, agile development and strong security practices. This high-energy conference brings together top talent from around the world and California’s dynamic InfoSec community.
Take part in engaging talks, practical sessions, and meaningful conversations that deliver real-world insights into secure software development. You’ll have plenty of opportunities to connect with peers, learn from experienced professionals, and grow your network.
At AI AppSec, you’ll:
Learn from leading experts and seasoned speakers who share practical insights on secure software development.
Build valuable relationships and collaborate with top-tier cybersecurity professionals.
Engage in insightful discussions and workshops tailored to today’s most relevant security trends.
Earn CPE credits while strengthening your software security skills.
Set at the beautiful Annenberg Community Beach House along California’s scenic coastline, AI AppSec offers an inviting atmosphere ideal for networking, relaxing, and enjoying beachside moments with peers.
Want to be the first to know when registration opens?
Join our newsletter and stay informed as we release the full agenda and speaker lineup.
We look forward to seeing you there!
Featured Speakers

Opening Keynote
Ira Winkler
Field CISO @ AISLE

Closing Keynote
Julie Morris
Head of Executive Thought Leadership | Persona Media

Michael Wylie, MBA, CISSP
Author | Speaker | 4x CVEs | Threat Hunter | People Leader

Edward Bonver
Product Security / Cybersecurity Leader

Richard Greenberg
CEO, Layer 8 Masters

Ron Dilley
Field CISO at Reflex Security

Chris Lindsey
US Field CTO, OX Security

Serafino Sini
Senior Cybersecurity Executive and CISO for North America at Yamaha Motor Corp., USA

Bennett Norton
Solutions Leader at Armis

David Boewer
Exposure Management Field CTO at Armis

Chris Ward
CEO, Fire Mountain Labs

Horica “Rico” Ionescu
Information Security Manager at Finvi

Dutch Schwartz
Field CISO and Evangelist, Nisos

Alexander Braehler
Founder & CEO at Tekkno, Inc., COO, Layer 8 Masters

Sana Talwar
Product Security Engineer, ServiceNow

Fayeron Morrison, CPA, CFE
Founder and President of Elemental AI

Dan Meacham
Vice President of Cyber and Content Security at Legendary Entertainment

Jason Kramer
Senior AI Engineer

James Green
Co-founder & Chief Product Officer at Heeler

Jimmy Xu
Field CTO at Cycode

Mike Miller
Solutions Consultant at Upstack
Sponsors, Orgs, Exhibitors











June 03 2026
8:00 AM - 8:45 AM
Registration & Breakfast & Networking
8:45 AM - 9:00 AM
Garden Terrace Room

Richard Greenberg
Ceo at Layer 8 Masters
Welcome Address
Welcome to the Planet Cyber Sec AI Conference. Join us in Room Garden Terrace for the Welcome Note to kickstart a day of insightful discussions and networking.
Get to Know Our Exhibitors & ORGs
As part of our commitment to supporting the broader cybersecurity community, we’ve invited non-profit organizations and exhibitors in the InfoSec space to take part in this year’s conference. During this session, each group will briefly introduce themselves, share their mission, activities, and how you can get involved. If you'd like to learn more, be sure to visit their booths throughout the day.
9:00 AM - 9:35 AM
Garden Terrace Room

Chris Ward
CEO, Fire Mountain Labs
Breaking the Black Box: An Overview of AI Governance and Tabletop Simulation
This session provides an overview of AI governance, combining framework fundamentals with a walkthrough of a live tabletop simulation. Participants will explore the AI model lifecycle and learn how to apply the NIST AI RMF and MITRE AI Maturity Model to manage real-world risks and build organizational resilience.
9:40 AM - 9:50 AM
Garden Terrace Room

Jimmy Xu
Field CTO at Cycode
Lightning Talk
Securing the Agentic Development Lifecycle – From AI Risk to Machine Speed Remediation
AI is rapidly transforming software development from a linear process into a continuous, autonomous system — what many are now calling the Agentic Development Lifecycle (ADLC). AI agents can now plan, generate, test, deploy, and even remediate software with minimal human intervention. As a result, application security is shifting from securing applications alone to securing the entire AI-driven software lifecycle itself.
In this lightning talk, Jimmy explores how modern application security must evolve to defend the Agentic Development Lifecycle, where the system that builds software increasingly becomes the system attackers target. Through modern AI attack chains and emerging real-world attack patterns, this session breaks down how organizations should approach security across five critical areas:
• Discovery — understanding the AI ecosystem, agents, and dependencies
• Governance — defining policy, identity, and control boundaries
• Guardrails — enforcing safe behavior in real time
• Runtime Defense — continuously observing, adapting, and responding at machine speed
• AI-Powered Remediation — prioritizing real exploitability and reducing existing security backlog with autonomous remediation
The session also addresses a critical reality: while governance and guardrails help reduce new risk, organizations still face massive existing vulnerability backlogs — and AI is dramatically accelerating exploitation.
The talk concludes with a live demonstration of how modern ADLC Security Platforms like Cycode can apply visibility, governance, guardrails, and AI-assisted remediation in real-world AI-native development environments.
9:55 AM - 10:15 AM
Garden Terrace Room

Bennett Norton
Solutions Leader at Armis

David Boewer
Exposure Management Field CTO at Armis
Lightning Talk
Shift Smart, Shift Zero: Unleashing Autonomous AppSec Without Losing Control
"Shift Left" gave us alert fatigue. "Shift Smart" helped prioritize. Now, welcome to Shift Zero: the era of invisible, frictionless security powered by autonomous AI agents. But who secures the bots? Join us to discover how Agentic Development Security (ADS) can automate your AppSec pipeline, and learn how to use the OWASP Agentic Security Initiative (ASI) to stop attackers from hijacking your AI guardrails. Stop burning out developers and start building secure, autonomous pipelines today.10:15 AM - 10:35 AM
Break - Vendor Expo
10:35 AM - 11:20 AM
Garden Terrace Room

Ira Winkler
Field CISO @ AISLE
Opening Keynote
The Myth of Mythos
Anthropic's recent announcement of the Mythos tool was akin to a seismic event in cybersecurity. The US government got involved and called a meeting of banking executives. Words like apocalypse were thrown around. This presentation will address the hype versus the reality of Mythos. It will allow attendees to understand the issues and figure out how Mythose actually impacts you.
11:25 AM - 11:35 AM
Garden Terrace Room

James Green
Co-founder & Chief Product Officer at Heeler
Lightning Talk
Preparing for the Post-Mythos Vulnerability Apocalypse: A Fix-First Future
As new large-scale disclosure events (“Mythos”-level moments) reshape the landscape, security and engineering teams are left overwhelmed by endless findings, manual triage, and upgrade fatigue.
In this talk, James Green explores what it means to prepare for the “post-Mythos” world and why the industry must move beyond detection. Instead, he introduces a fix-first approach that shifts the burden away from developers and toward intelligent automation.
By leveraging autonomous agents, organizations can automatically generate validated pull requests for dependency upgrades, continuously monitor CI feedback loops, and iteratively resolve failures. Delivering merge-ready fixes without developer toil.
Attendees will learn how to:
- Rethink vulnerability management in an era of constant disclosure
- Eliminate manual triage and reduce developer friction
- Implement agent-driven remediation workflows that scale
- Create continuous feedback loops that ensure fixes actually ship
This session offers a practical blueprint for moving from “more findings” to real risk reduction: at scale.
11:40 AM - 11:50 AM
Garden Terrace Room

Chris Lindsey
US Field CTO at OX Security
Inside the Modern Threat Landscape: Attacker Wins, Defender Moves, and Your Priorities
Every AI security tool you use today depends on a cloud API call. Your threat detection, your incident triage, your intel analysis, all of it running on someone else's infrastructure.
What happens when that's not an option? Or when you decide it shouldn't be?
While defenders continue to invest in stronger controls, attackers increasingly succeed by exploiting existing trust paths. Today's most impactful breaches are less about novel exploits and more about consistently abused techniques.
This session examines how modern compromises actually occur, based on analysis of aggregated real-world incident data. Rather than cataloging breach headlines, we focus on the attack techniques currently delivering the highest return for adversaries, the assumptions they repeatedly exploit, and why these patterns continue to succeed. We then evaluate which defensive mitigations are measurably reducing risk in production environments — and which commonly recommended practices are proving less effective.
To ground these patterns in concrete attacker tradecraft, the session includes a technical dissection of two Chrome extensions — with over one million active installations — that functioned as trojans in production environments, evading detection while operating entirely through legitimate browser APIs. These were not obscure tools. They were widely trusted, actively recommended, and covered by mainstream press before their malicious behavior was fully understood. We will walk through the actual source code of both extensions, showing precisely how the malicious functionality was constructed, concealed, and executed at scale.
Attendees will leave with:
- A breakdown of the three attack vectors responsible for a disproportionate share of recent breaches
- A line-by-line analysis of two real-world trojanized Chrome extensions, including the techniques used to evade detection and abuse trusted browser APIs
- A practical framework for evaluating defensive investments based on security-per-dollar impact
- A risk prioritization approach grounded in observed attacker behavior rather than theoretical threat models
Who should attend:
Security architects, AppSec and cloud security practitioners, blue team leads, and security leaders responsible for prioritizing risk and investment decisions.
What this session is not:
A vendor pitch, a breach post-mortem, or a speculative look at future threats.
11:50 AM - 1:00 PM
Lunch - Vendor Expo
1:00 PM - 1:35 PM
Garden Terrace Room

Michael Wylie. MBA, CISSP
Author | Speaker | 4x CVEs | Threat Hunter | People Leader
Talk
The AI-Assisted Cybersecurity Analyst
AI is fundamentally reshaping the cybersecurity landscape, and if defenders don’t learn to master AI as a copilot, the attackers will be unstoppable. This talk will explore how AI serves not as a replacement, but as a powerful "copilot" that augments human expertise, allowing analysts to handle the overwhelming volume and velocity of modern cyber threats. No marketing fluff, just real talk.
Key Takeaways:
- Pattern Recognition at Scale: Learn how AI's core strength is its unparalleled ability to identify subtle, malicious patterns buried within massive datasets of benign artifacts, a feat often impossible for human analysts or traditional rule-based systems.
- The Power of Prompt Engineering: Demystify the art and science of communicating with LLMs. We will break down the essential elements of a high-quality prompt (Instructions, Context, Input Data, and Output Indicators) to ensure precise, actionable, and relevant results in day-to-day security tasks.
- Advanced AI Tuning: Discover how to use powerful controls like the System Prompt to define the AI’s persona (e.g., Threat Hunter, Incident Responder) and how the Temperature hyperparameter can be adjusted for tasks requiring high precision (low temperature) versus creative brainstorming (high temperature).
1:40 PM - 2:15 PM
Garden Terrace Room

Ron Dilley
Field CISO at Reflex Security
Sovereign AI: Building Security Capabilities That Never Phone Home
Every AI security tool you use today depends on a cloud API call. Your threat detection, your incident triage, your intel analysis, all of it running on someone else's infrastructure.
What happens when that's not an option? Or when you decide it shouldn't be?
The hardware caught up. The models got small enough. The protocols standardized. I'll walk through what a local AI security stack looks like in practice: local inference, persistent memory, tool integration through MCP, all running on hardware you control. What fits on what hardware, which security use cases actually work better locally, and the engineering that makes it reliable enough to trust.
Not anti-cloud. Just pro-choice about where your security data goes.
No vendor pitches. Built and running today.
2:20 PM - 2:55 PM
Garden Terrace Room
Cybersecurity Leaders Panel
Join Cybersecurity leaders on a dynamic panel, which will be focusing on the rapidly changing and evolving challenges presented by AI adoption, internally and externally. Other panelists include Serafino Sini, CISO for North America at Yamaha Motor Corp., USA, and Horica Ionescu, Information Security Manager at Finvi
Richard Greenberg
CEO, Layer 8 Masters
Moderator

Serafino Sini
Senior Cybersecurity Executive and CISO for North America at Yamaha Motor Corp., USA
Panelist

Fayeron Morrison, CPA, CFE
Founder and President of Elemental AI
Panelist

Horica "Rico" Ionescu
Information Security Manager at Finvi
Panelist

Dan Meacham
Vice President of Cyber and Content Security at Legendary Entertainment
Panelist
2:55 PM - 3:15 PM
Break - Vendor Expo
3:15 PM - 4:00 PM
Garden Terrace Room

Julie Morris
Head of Executive Thought Leadership | Persona Media
Closing Keynote
Your Cyber Why: Strategic Personal Positioning for a Future-Proof Career
You are not a commodity. You are one of a handful of people who can do what you do. But most of us are still defined by the work in front of us each day. High capability often means being under-positioned for what comes next, being seen too narrowly, and missing opportunity, growth, and influence.
Julie Morris examines strategic personal positioning as the lens and filter through which others experience you: in day-to-day leadership, broader reputation, and demonstrated value. Through strong same-market examples, she will show how to operationalize your positioning in a market being reshaped by AI.
4:00 PM - 5:00 PM
Happy Hour and Raffle Drawing
9:00 AM - 9:35 AM
Club Room

Dutch Schwartz
Field CISO and Evangelist, Nisos
Talk
Your New Hire Works for Pyongyang
North Korea doesn't need to breach your perimeter. They're submitting resumes.
DPRK-affiliated IT workers have infiltrated numerous Fortune 500 company, generating $250M to $800M annually to fund ballistic missile programs. Detected incidents have jumped 220% year-over-year. If your company hires remote employees, regardless of your company size, then you are a target. Traditional background checks will not solve this because these are state-sponsored actors using stolen identities.
In this session, we will walk through how the scheme works; AI-generated identities, deepfake interviews, domestic laptop farms, and coordinated operator networks surviving inside companies for up to 14 months. We will ground it in real cases, then leave you with a practical highlight of the top TTPs that you can implement immediately.
9:40 AM - 10:15 AM
Club Room

Mike Miller
Solutions Consultant at Upstack
Talk
Finding the Right MSSP: What Works, What Doesn’t, and Why
Learn the process in which Mike has used for over a decade to help clients vet, compare and select Managed Security Partners. As a vendor agnostic solutions consultant Mike has developed a thorough process for discovering the needs and desired outcomes of the client, selecting a short list of providers that are best fit to support, jointly evaluating providers for best fit, negotiating best solution and assisting in deployment and ongoing support as the partner. Learn how the process has worked with numerous engagements and lessons learned to help you in your next Managed services Partner evaluation.10:15 AM - 10:35 AM
Break - Vendor Expo
11:25 AM - 11:50 AM
Club Room

Alexander Braehler
Founder & CEO at Tekkno, Inc., COO, Layer 8 Masters
Talk
Building Deterministic IaC: Lessons from a Real-World Attempt
Infrastructure as Code promises deterministic, repeatable systems—but in practice, hidden state, environment dependencies, and inconsistent tool behavior introduce non-determinism in subtle ways. In this session, I share a 6+ month real-world attempt to eliminate non-determinism from an IaC-driven environment. Rather than focusing on tools or best practices, this talk examines where those practices break down under real conditions—across APIs, execution environments, and automation workflows. Attendees will gain a practical understanding of where determinism fails in modern infrastructure, what it actually takes to enforce it, and how to decide where that level of rigor is worth the cost.11:50 AM - 1:00 PM
Lunch - Vendor Expo
1:00 PM - 1:35 PM
Club Room

Jason Kramer
Senior AI Engineer
Talk
Your Model Remembers More Than You Think
Pretrained models power today’s AI systems, but they also import unknown and often undetected vulnerabilities. When teams fine-tune and deploy these models, they assume they are shaping behavior. In reality, they may be inheriting it.
This session shows how adversarial behaviors, including evasion techniques, poisoned data artifacts, and hidden backdoors, persist across model reuse and transfer into downstream systems. Through real experiments and NIST-supported evaluations, we demonstrate how these risks survive fine-tuning and evade traditional validation methods.
We break down why current testing approaches fail and how attackers can exploit model inheritance as an attack amplifier. We also present practical detection and mitigation strategies that work in real-world environments where retraining is not always feasible.
1:40 PM - 2:15 PM
Club Room

Sana Talwar
Product Security Engineer, ServiceNow
Talk
Prompt Injection: When Words Become Exploits
Your AI reads an email, then follows a link and summarizes a document. What if any of those contained instructions? Prompt injection lets attackers hijack AI systems not by breaking in, but by slipping commands into data the model is already processing. This talk goes deep on real CVEs, documented incidents, and peer-reviewed research: from a GitHub Copilot RCE to Slack AI data exfiltration to enterprise RAG manipulation. We will map every attack class to OWASP LLM Top 10 and NIST AI RMF, walk through attack mechanics with examples and give AppSec teams a practical framework for threat modeling, vendor evaluation, and defense in depth.2:20 PM - 2:55 PM
Club Room

Edward Bonver
Product Security / Cybersecurity Leader
Talk
AI-Generated Code, Real-World Vulnerabilities: A Production Incident Register
I rebuilt a 25-year-old website using an AI coding assistant as my full-time development partner. Over three months, the AI generated thousands of lines of code across multiple languages and configurations. It found real vulnerabilities, wrote input validation, built deployment pipelines, and produced code that passed its own reviews. It also introduced a critical production outage with a single misconfigured directive, wrote a security validation script with over a dozen exploitable gaps, silently destroyed cache data using a textbook "safe deploy" pattern, injected raw HTML into data fields creating stored XSS vectors, and hallucinated plausible but wrong reference data at scale.
I documented every failure into a security incident register — dozens of entries, each with the AI-generated artifact, the vulnerability, how it was discovered, and the fix. This talk presents that register, mapped to both the OWASP Top 10 and the OWASP Top 10 for LLMs.
You'll see how AI applies security patterns it has learned while failing to verify the assumptions those patterns require, why partial security in AI-generated code is more dangerous than no security, and how defence-in-depth, adversarial code review, and explicit security contracts turned a pattern of recurring failures into a hardened development workflow. You'll leave with key takeaways from this experience: a practical framework for writing security requirements AI can actually enforce, designing guardrails that catch what AI misses, and building with AI without trusting it blindly.
Who Should Attend:
Application security engineers, penetration testers, DevSecOps practitioners, software architects evaluating AI coding tools, and security leaders building governance frameworks for AI-assisted development. This talk assumes familiarity with OWASP, secure SDLC practices, and code review.
What You'll Learn:
- How AI-generated code maps to OWASP Top 10 and OWASP Top 10 for LLMs — with real exploit paths from a production codebase
- Why AI applies correct security patterns with unchecked preconditions and how to catch this systematically
- How a short AI-written security script contained over a dozen vulnerabilities — and what structured adversarial review looks like in practice
- How AI output injection creates stored XSS vectors — and why defence-in-depth at the template layer is the only reliable mitigation
- How AI orchestration systems bypass their own quality gates under pressure — the trust boundary problem in multi-agent pipelines
- How to write enforceable security contracts for AI coding assistants: input validation patterns, forbidden function lists, and mandatory output encoding
- A categorized incident taxonomy with severity distribution, detection methods, and lessons learned
Richard Greenberg, CISSP is a well-known Cyber Security Leader and Evangelist, CISO, Advisor, and speaker.
Richard brings over 30 years of management experience and has been a strategic and thought leader in IT and Information Security. His Project Management, Security Management and Operations, Policy, and Compliance experience has helped shape his broad perspective on creating and implementing Information Security Programs.
Richard has been a Chief Information Security Officer (CISO) for 15 years, Director of Surveillance and Information Systems, Chief of Security Operations, Director of IT, and Project Manager for various companies and agencies in the private and public sectors.
You may have heard Richard’s interview as a Cyber Security expert on Will Ferrell’s Ron Burgundy podcast: https://www.iheart.com/podcast/the-ron-burgundy-podcast-30270227/episode/cyber-security-47951911/.
Richard is the Founder and CEO of Security Advisors LLC, which offers fully-managed security assessments and network and software penetration testing services that allows organizations to continuously assess their internal and external cyber risk posture, and helps companies with compliance issues. He is also the CEO of Layer 8 Masters, which has been putting on the content-rich Planet Cyber Sec conferences and CISO-CIO Forums.
Richard is an Information Systems Security Association (ISSA) Distinguished Fellow, one of only 64 worldwide, and has received their Honor Roll designation (only 55 worldwide). He has also been selected as a finalist for both the (ISC)2 Americas Information Security Leadership Award in the Senior Information Security Professional category and the Los Angeles Business Journal CIO of the Year in Security.
Richard has served on the OWASP Global Board of Directors, leads the OWASP LA Chapter, and has been Co-Chair of the highly successful AppSec California conferences. Richard also is President of the Information Systems Security Association Los Angeles Chapter and is Chair of their widely recognized annual Security Summit and CISO Forum.
Richard is dedicated to diversity in our field. He started and chairs the annual Women in Security Forum, and supports creating a more open and welcome community. Richard’s reach in the Southern California region is extensive. He has worked diligently to bring together the various Southern California IT and InfoSec organizations to enhance their collaboration efforts, to help reach new IT and InfoSec professionals.
Richard has been a published author and has spoken worldwide on Information Security, individually and on panels.
Meet Our Expert Team
Founded by four seasoned cybersecurity professionals who are not just organizers, but true experts in the field themselves. Drawing from their collective wealth of experience and deep-rooted insights, our events offer a rare opportunity to engage with top-tier professionals who understand the intricacies and challenges of cybersecurity firsthand. Elevate your knowledge, network with the best, and stay ahead of the curve as we pave the way for a safer digital world, together.

Richard Greenberg
Chief Executive Officer

Haral Tsitsivas
Chief Information Officer

Dave Wettenstein
Chief Financial Officer

Alexander Braehler
Chief Operating Officer
Ira Winkler,
Ira Winkler, CISSP is the Field CISO for AISLE, former Chief Security Architect at Walmart, and author of You Can Stop Stupid, Security Awareness for Dummies, and Advanced Persistent Security. He is considered one of the world’s most influential security professionals, and has been named a “Modern Day James Bond” by the media. He did this by performing espionage simulations, where he physically and technically “broke into” some of the largest companies in the World and investigating crimes against them, and telling them how to cost effectively protect their information and computer infrastructure. He continues to perform these espionage simulations, as well as assisting organizations in developing cost effective security programs. Ira also won the Hall of Fame award from the Information Systems Security Association, as well as several other prestigious industry awards. CSO Magazine named Ira a CSO Compass Award winner as The Awareness Crusader. Most recently, Ira was named 2021 Top Cybersecurity Leader by Security Magazine.
Ira is also author of the riveting, entertaining, and educational books, Advanced Persistent Security, Spies Among Us and Zen and the Art of Information Security. He also writes for a variety of online sites, including RSA Conference, DarkReading and ComputerWorld, and for several other industry publications.
Mr. Winkler has been a keynote speaker at almost every major information security related event, on 6 continents, and has keynoted events in many diverse industries. He is frequently ranked among, if not the, top speakers at the events.
Mr. Winkler began his career at the National Security Agency, where he served as an Intelligence and Computer Systems Analyst. He moved onto support other US and overseas government military and intelligence agencies. After leaving government service, he went on to serve as President of the Internet Security Advisors Group, Chief Security Strategist at HP Consulting, and Director of Technology of the National Computer Security Association. He was also on the Graduate and Undergraduate faculties of the Johns Hopkins University and the University of Maryland. Mr. Winkler was previously elected the International President of the Information Systems Security Association, which is a 10,000+ member professional association.
Mr. Winkler has also written the book Corporate Espionage, which has been described as the bible of the Information Security field, and the bestselling Through the Eyes of the Enemy. Both books address the threats that companies face protecting their information. He has also written hundreds of professional and trade articles. He has been featured and frequently appears on TV on every continent. He has also been featured in magazines and newspapers including Forbes, USA Today, Wall Street Journal, San Francisco Chronicle, Washington Post, Planet Internet, and Business 2.0
Mike Wylie
Michael Wylie, MBA, CISSP, leads Zscaler’s Threat Hunting team, bringing over a decade of hands-on experience in proactive threat detection and incident response. As a former threat hunting Director at both CrowdStrike and a major consulting firm, he has a proven track record of building and scaling elite SecOps teams.
Michael’s expertise is grounded in practical application, developed through training for organizations including the U.S. Department of Defense and leading sessions at conferences like DEFCON. His work focuses on bridging the gap between cutting-edge research and real-world practitioner challenges.
Ron Dilley works at Reflex Security as the Field CISO, focusing on technical evangelism, channel management, and community presence, while pushing the boundaries of what’s possible in technology to deliver exceptional value for clients. He is also on the IANS Research Faculty and a published author.
Dutch Schwartz serves on the Cloud Security Alliance CxO AI Safety Council, where he helps shape enterprise AI governance frameworks for responsible deployment. As Field CISO and Evangelist at Nisos, he brings 30 years of cybersecurity leadership to the challenge of managing human-driven risk in the age of AI. At AWS, he served on the inaugural AI Security Working Group and co-authored a Security Blog on securing generative AI.
A sought-after speaker on the human side of AI and cybersecurity, Dutch holds an MBA, cybersecurity certificates from MIT and Harvard University, the AI Programme certificate from Oxford University, and is a Qualified Technology Executive (QTE). He is currently earning a master’s degree in psychology to help make AI more responsible and secure for everyone.
Sana Talwar is a Product Security Engineer at ServiceNow, where she helps build secure software and strengthen product resilience. Her journey in tech began in high school when she was featured in the CodeGirl documentary for creating an app that solved a community problem. She teaches cybersecurity at a local community college and speaks on topics that bridge security, education, and emerging technologies.
Edward Bonver
Edward Bonver, CISSP, CSSLP, is a cybersecurity leader with more than 25 years of experience spanning software development, assurance, and product security. His background includes roles at Raytheon Technologies, Symantec, Digital Equipment Corporation, Veritas Technologies, and Arctera, where he has worked across the spectrum from real-time operating systems and networking protocols to enterprise-scale product security programs.
A recognized software security evangelist, Edward served on the OWASP Los Angeles Chapter Board of Directors and helped organize multiple OWASP AppSec California conferences. He also served on the SAFECode Board of Directors, representing Symantec and Raytheon Technologies, contributing to SAFECode working groups and publications. He speaks regularly at global security events and contributes to security community forums and industry alliances.
The incidents in this talk come from his personal project — a poetry website he has maintained for 25 years — rebuilt over three months with AI assistance, producing a security incident register that maps real AI failures to OWASP controls.
Fayeron Morrison, CPA, CFE is the Founder and President of Elemental AI, a strategic advisory firm that helps boards and executive teams establish AI oversight that is proportionate to risk, legally defensible, and built to evolve with the technology.
She brings more than 25 years of experience in audit, fraud examination, and corporate governance, including 11 years at Coopers & Lybrand (now PwC). Today, she works with boards and leadership teams to translate AI from a technical topic into a governance discipline -clarifying accountability, surfacing risk, and strengthening oversight.
Fayeron is a graduate of the Stanford Graduate School of Business AI Leadership program and serves as Co-Chair of the Private Directors Association’s AI Governance Special Interest Group. She is also a contributor to the PDA National AI Task Force developing AI Oversight Governance: The Private Director’s Body of Knowledge (2026).
Her work is anchored by the Elemental AI Governance Navigator, a proprietary diagnostic used to assess organizational AI maturity and risk across seven critical domains. She is the author of Elemental AI: The Briefing, a weekly Substack and podcast focused on AI governance for boards and executives.
Julie Morris
Julie Michelle Morris serves as Head of Thought Leadership for a select group of leading executives and enterprises in cybersecurity, AI, and policy. Her work focuses on translating technical expertise into strategic thought leadership and growing revenue by building audience trust. She is deeply interested in how ideas spread, how trust is earned, and how influence can be used in service of others at scale. She speaks and teaches regularly on both the strategic case for thought leadership and the tactics that make it effective, hosts the How to Thought Leadership podcast, and is writing her first book, a reinvention field guide focused on aligning personal ambition, market demand, and a minimum viable brand in an AI-shaped world, for release in summer 2026.
Chris Ward
Chris Ward is the CEO of Fire Mountain Labs, where he leads the company’s mission to advance safe and assured AI. Under his direction, Fire Mountain Labs delivers pioneering AI assurance solutions to enterprise and government clients, ensuring AI systems are deployed with security, integrity, and accountability.
With over a decade of experience in AI and AI Security, Chris has coauthored 23 publications in the field and brings deep technical and operational expertise. A veteran of of the U.S. Navy and Federal Civil Service, Chris also brings deep expertise from Space and Naval Warfare (SPAWAR) Systems Center Pacific, the Naval Information Warfare Center (NIWC), the MITRE Corporation, and several successful AI startups. His background spans operational technology, national security, and cutting-edge AI innovation.
As a trusted voice in the AI ecosystem, Chris operates as an honest broker – bridging government, industry, academia, and small organizations. He advocates for AI adopters navigating a crowded and hype-driven landscape, championing pragmatic, secure, and trustworthy solutions that serve the public good and strengthen national resilience.
Before founding Fire Mountain Labs, Chris held senior leadership roles in AI security research and red teaming, where he shaped industry standards in AI risk assessment, penetration testing, secure AI governance, and adversarial threat modeling.
Serafino Sini
Serafino Sini is a senior cybersecurity executive and CISO for North America at Yamaha Motor Corporation, U.S.A., supporting enterprise cybersecurity and risk management across a global organization. He brings deep experience in cyber risk management, security architecture, and governance within large automotive and manufacturing environments.
Prior to Yamaha, Serafino held longstanding roles at Toyota Motor Corporation, where he contributed to enterprise security architecture and information security consulting initiatives focused on aligning security strategy with business objectives.
A CISSPcertified leader, Serafino is active in the cybersecurity community as a member of the Information Systems Security Association (ISSA – Los Angeles) and an AutoISAC Advisory Board participant and member of the Gartner Southern California CISO community. He is a frequent conference speaker, sharing executive insights on cybersecurity leadership, risk management, and industry collaboration.
Dan Meacham is the Vice President of Cyber and Content Security at Legendary Entertainment and a highly decorated industry leader, recognized as the 2021 SC Media CSO of the Year and the 2020 ISE West Security Executive of the Year. With over 25 years of experience across the legal, healthcare, accounting, and media sectors, he brings a multidisciplinary perspective to protecting high-value digital assets. A CISSP-certified professional trained by members of the U.S. Secret Service and the NSA, Dan is a leading voice in the governance of “Agentic AI” and an active advisory board member across the IT and cybersecurity communities. He continues to drive innovation in security frameworks and collaborative intelligence as the founder of the “Collective Defense” community.
Jason is dedicated to advancing the state of the art in secure and robust AI. With a bachelor’s degree in computer science from San Diego State University, he is focused on ensuring trust, security, privacy, bias, and robustness of AI/ML models. Jason has led the development efforts of a commercial solution for the detection and repair of vulnerabilities in deep learning systems, and the co-author of multiple patents related to the cybersecurity of systems including AI/ML, embedded devices, supply chain, and others. His passion for improving the field has driven him to push the boundaries of what is possible and make a meaningful impact in the fields of AI and cybersecurity.
Horica “Rico” Ionescu is an information security leader with a decade of experience driving security operations and regulatory compliance in the software industry. He is motivated by driving cultural change to embed secure practices across teams and business processes.
He is currently an Information Security Manager at Finvi, where he oversees the information security team.
Outside of work, Rico is a voracious reader who enjoys a good cup of coffee, cycling (road and mountain biking), and spending time with his family. He currently lives in Tallahassee, Florida.
David Boewer, Exposure Management Field CTO, brings over 19 years of experience as a commercial and technology leader, including more than 8 years leading go-to-market strategies. He has spent over 15 years advising on and implementing cybersecurity solutions for large enterprises, along with over 10 years addressing complex operational challenges.
Bennett is a cybersecurity leader with 24 years of experience helping organizations tackle the today’s modern security challenges. As a Solutions Director at Armis, he specializes in cutting through complexity to deliver security strategies that work in the real world — not just on paper. He brings a practitioner’s mindset to every conversation, with deep experience across the evolving threat landscape facing modern enterprises.
Outside the security world, Bennett is a coach, a father of four, and can usually be found on a mountain bike or behind a wake boat — all of which, he’d argue, require about the same level of risk management.
Chris Lindsey is a seasoned speaker who has appeared at conferences, webinars, and private events. Chris draws on expertise from more than 15 years of direct security experience leading and building security programs and over 35 years of experience leading teams in programming, software, solutions, and security architecture.
Mike is a Connector, a Solution Finder and Problem Solver. With 20 plus years in technology and thousands of enterprise IT project engagements, Mike Miller has a wealth of knowledge, experience and an extensive network. Mike has worked as a sales leader for major corporations like AT&T, NetApp, Internap and currently works as a Vendor Agnostic Solutions Consultant.
Mike is a Solutions Consultant serving the Enterprise IT community with a Client Advocate approach. He helps solve problems with an extensive network of providers and partners that can deliver results. Mike specializes in Managed Services, Network, Security, Cloud Computing, UC and the modern CX Contact Center. Mike has built a large and loyal client base with many major logos. Mike and his partners have built a large network of IT Executives by establishing groups, hosting events, speaking engagements and running a Podcast (Boardroom sessions Podcast with Mike Miller) to name a few channels. When not in the company conference room, Mike can be found on a paddle board, surfboard, bike or running on the local trails. He lives in Huntington Beach with his wife and 3 children.
Co-founder & Chief Product Officer at Heeler
Jimmy Xu is the former Field CTO at Cycode and a technology leader with over 23 years of experience spanning application security, cloud security, DevSecOps, and AI-native systems. He has led security transformation initiatives across enterprise, public sector, consulting, and high-growth cybersecurity organizations, helping teams modernize how software is built and secured in the era of AI-driven development.
At Cycode, Jimmy helped shape the company’s AI-native application security strategy, including the design of Cycode Maestro, an agentic AI system focused on exploitability analysis and autonomous remediation workflows. He is a frequent speaker at OWASP, Cloud Security Alliance, and industry conferences, where he focuses on securing the Agentic Development Lifecycle, AI software supply chains, and modern AI attack surfaces.
Richard Greenberg, CISSP is a well-known Cyber Security Leader and Evangelist, CISO, Advisor, and speaker.
Richard brings over 30 years of management experience and has been a strategic and thought leader in IT and Information Security. His Project Management, Security Management and Operations, Policy, and Compliance experience has helped shape his broad perspective on creating and implementing Information Security Programs.
Richard has been a Chief Information Security Officer (CISO) for 15 years, Director of Surveillance and Information Systems, Chief of Security Operations, Director of IT, and Project Manager for various companies and agencies in the private and public sectors.
You may have heard Richard’s interview as a Cyber Security expert on Will Ferrell’s Ron Burgundy podcast: https://www.iheart.com/podcast/the-ron-burgundy-podcast-30270227/episode/cyber-security-47951911/.
Richard is the Founder and CEO of Security Advisors LLC, which offers fully-managed security assessments and network and software penetration testing services that allows organizations to continuously assess their internal and external cyber risk posture, and helps companies with compliance issues. He is also the CEO of Layer 8 Masters, which has been putting on the content-rich Planet Cyber Sec conferences and CISO-CIO Forums.
Richard is an Information Systems Security Association (ISSA) Distinguished Fellow, one of only 64 worldwide, and has received their Honor Roll designation (only 55 worldwide). He has also been selected as a finalist for both the (ISC)2 Americas Information Security Leadership Award in the Senior Information Security Professional category and the Los Angeles Business Journal CIO of the Year in Security.
Richard has served on the OWASP Global Board of Directors, leads the OWASP LA Chapter, and has been Co-Chair of the highly successful AppSec California conferences. Richard also is President of the Information Systems Security Association Los Angeles Chapter and is Chair of their widely recognized annual Security Summit and CISO Forum.
Richard is dedicated to diversity in our field. He started and chairs the annual Women in Security Forum, and supports creating a more open and welcome community. Richard’s reach in the Southern California region is extensive. He has worked diligently to bring together the various Southern California IT and InfoSec organizations to enhance their collaboration efforts, to help reach new IT and InfoSec professionals.
Richard has been a published author and has spoken worldwide on Information Security, individually and on panels.
Alexander Braehler is a Cyber Security Architect and a Wazuh Security Engineer with over40 years of experience in IT/IS consulting for SMBs and enterprises. He joined the information security community in 2011 and has since been actively involved with various security industry organizations, including the Southern California chapter of HTCIA, where he served as 1st VP and Chapter President. Alexander is also an Infrastructure Liaison Officer with FBI Infragard, an active member of USSS Cyber Fraud Task Force, and the Cloud Security Alliance. He was a key member of the conference planning committees for OWASP L.A. and ISSA L.A.
Haral Tsitsivas is a cybersecurity leader and software developer with 40+ years of IT and software development and 20+ years of systems and software security experience, specializing in threat modeling, product security reviews and assessments.
Haral was an Orange County OWASP chapter leader, served on the board of the OWASP Outreach Committee and was the Vice-Chair of the OWASP Chapter Committee.


