Upcoming Events

siberXcon 2026

siberXcon 2026

This executive cybersecurity conference brings together leaders from AI, cybersecurity, government, and academia for a full-day program focused on AI-driven security risk, emerging cyber threats, and the decisions shaping the future of digital trust. Through a curated mix of executive discussions, applied workshops, live demonstrations, and innovation zones highlighting emerging startups and research, the program provides sponsors with meaningful engagement and direct access to enterprise buyers, policymakers, researchers, and industry leaders in a high-trust, limited-attendance environment.

Event Details
Amira Masood
CTO
The UPS Store
CTO at The UPS Store
Asher Jaffri
Manager, Information Technology & Digital Transformation
Town of Erin
Manager, Information Technology & Digital Transformation at Town of Erin
Bassel Assah
Head of Global Cybersecurity GRC
Fiera Capital
Head of Global Cybersecurity GRC at Fiera Capital
Bob Gordon
Strategic Advisor
Canadian Cyber Threat Exchange
Strategic Advisor at Canadian Cyber Threat Exchange
Daniel Pinsky
CSO
CDW Canada
CSO at CDW Canada
David Cachia
Chief Information Officer
Municipality of Clarington
Chief Information Officer at Municipality of Clarington
Dr. Ann Cavoukian
Executive Director
Global Privacy & Security by Design Centre
Executive Director at Global Privacy & Security by Design Centre
Edgard Rodriguez
Director Cyber Threat Intelligence & Research
Rogers
Director Cyber Threat Intelligence & Research at Rogers
Marco Lattavo
AVP, Identity and Security Operations
Definity Insurance
AVP, Identity and Security Operations at Definity Insurance
Maryam Asgariazad
Information Security and Risk Officer
Manulife
Information Security and Risk Officer at Manulife
Director Cyber Resilience and Risk Mgmt
EQ Bank
Director Cyber Resilience and Risk Mgmt at EQ Bank
Michael Rebultan
GRIT Management
Martinrea International Inc.
GRIT Management at Martinrea International Inc.
Nicole Landry
Sr. Director Workforce IAM
CIBC
Sr. Director Workforce IAM at CIBC
Nilesh Shastri
CISO
Canadian Institute of Health Information
CISO at Canadian Institute of Health Information
CISO and CPO
Groupe Robert
CISO and CPO at Groupe Robert
Roy French
CIO
SE Health
CIO at SE Health
Sohaib Syeed Ahmed
AVP, Information Security
First National Financial LP
AVP, Information Security at First National Financial LP
Tushar Chandgothia
VP and CISO
goeasy
VP and CISO at goeasy
  • Enjoy our seamless checkin process and grab your information for the day. We have a fresh selection of breakfast selections available to you right after.

  • About siberX

    Join us as we begin with our land acknowledgements and opening comments from dignitaries and special guests.

  • About siberX

    Refuel with a fresh cup of coffee and light snacks

  • Most businesses treat security cameras like a "black box"—you hope they’re recording, but you pray you never have to actually find anything. If you've ever spent three hours scrubbing through graining footage just to find a missing package or a door left propped open, you know the "legacy tax."
    Join us for an interactive session with Verkada to see how Agentic AI moves you away from passive recording and into a world where you can simply "ask" your building what happened.

    What You’ll Experience

    Natural Language Search: See how anyone on your team—not just IT—can conduct "Google-style" searches across all your sites simultaneously.
    Proactive Deterrence: Move beyond recording crime to preventing it. Learn how AI can identify loitering or unauthorized access and trigger real-time audio warnings before an incident occurs.
    The "Speed Search" Challenge: We’ll put the AI to the test live. We'll ask the system to find a "needle in a haystack" event across thousands of hours of footage to show you exactly how much time your team is currently wasting.

    Actionable Takeaways

    Slash Investigation Time by 90%: Learn how to replace manual scrubbing with instant AI indexing.
    Remote Management: See how to manage 1 or 1,000 cameras from a single phone app without needing on-site servers or VPNs.
    Operational ROI: Discover how to use security data to spot warehouse bottlenecks, track delivery arrivals, and audit safety compliance automatically.

    Stop recording history. Start understanding it.

  • CheckPoint

    A thought-provoking session that explores the emerging crisis of trust in the age of AI deepfakes and synthetic identity. Through live demonstrations of voice cloning and AI-generated imagery, Robert Falzon reveals how convincingly reality can now be fabricated. Not to alarm, but to illuminate a profound shift in enterprise and personal risk.

  • Wiz

    AI is opening up amazing new possibilities, and staying secure at every step is crucial. Join us to explore how the Wiz AI Security Platform provides complete protection for your AI applications, from code all the way to runtime. We’ll show you how to gain full-stack AI visibility, proactively manage risks with our graph-based context, and detect threats across your AI pipelines. Empower your teams to adopt and expand into AI workloads confidently with comprehensive AI Security Posture Management, Runtime Protection, and Code Scanning.

  • Stretch your legs and take a deep breath!

  • SailPoint

    As AI agents take on autonomous roles across enterprise systems, identity governance must evolve beyond human and machine identities to address a new class of actors with dynamic privileges and decision-making capabilities. This session explores how organizations can establish robust identity frameworks for AI agents—covering provisioning, authentication, authorization, and lifecycle management in environments where agents operate, collaborate, and adapt in real time. We will examine emerging risks such as privilege escalation, identity sprawl, and accountability gaps, and outline strategies to enforce least privilege, maintain auditability, and align with existing governance models—ensuring AI agents remain controlled, trusted participants in the enterprise ecosystem.

  • Optiv

    The human response to AI adoption can cause significant risk to organizations. Unclear policies, limited transparency, and fear of job displacement are shaping how employees engage with AI tools and organizations that fail to address these dynamics risk eroding trust and amplifying the use of shadow AI. This fireside chat will explore how leaders can address workforce anxiety while responsibly integrating AI into their organizations.

  • Exabeam

    A forward‑looking look at how security teams can harness AI agents at machine speed while keeping humans firmly in control — redefining SOC operations for the Agentic Enterprise.

  • Stretch your legs and take a deep breath!

  • Armis

    The cybersecurity narrative in 2026 has converged on a single theme: the AI arms race. Adversaries are leveraging generative AI to automate attacks, increase the sophistication of phishing and discover vulnerabilities at machine speed. The window for defenders has collapsed from 8 hours in 2022 to 22 seconds in 2025. The industry response, almost uniformly, has been to argue for faster, smarter, more autonomous defence.

    In my opinion, that’s the right answer to the wrong question.

    On April 7th, 2026, Anthropic announced Claude Mythos - a frontier AI model that identified thousands of zero-day vulnerabilities, many of them critical, in every major OS and web browser, including flaws that survived decades of human review and millions of automated security tests (Anthropic.com). Two weeks earlier, Armis Labs published the Trusted Vibing Benchmark, finding a 100% failure rate across 18 leading generative AI models in producing secure code. Both developments arrived in the same quarter and together they reshaped what enterprise security must do in 2026.

    The attacker side of this equation has been well covered. What’s gone underdiscussed in executive conversations is the defender’s operational reality: an AI-driven flood of discoveries hitting organizations whose vulnerability management programs were built for a world that no longer exists. Most enterprises still cannot reliably answer where a vulnerable component is running, what business process depends on it, or whether the AI-generated code their own developers shipped last week is part of the exposure surface.

  • Agentic AI is accelerating how systems reason, decide, and act, but the real risk isn’t any single attack. It’s the architecture. Prompt injection and context poisoning aren’t edge cases. They are emergent properties of how modern AI operates, where models assemble context from user input, retrieval, memory, and tools, yet treat it all as equally trustworthy.
    The core issue is that the model has no concept of trust. Everything flows into the same context window, where malicious instructions can quietly override intent and drive outcomes.
    Understand where trust breaks across agentic systems and how to redesign those boundaries with a control-centric blueprint for building AI that can move fast and act autonomously while remaining resilient, governable, and secure by design.

  • Anthropic's Claude Mythos released in April, didn't just raise the bar for vulnerability discovery, it rewrote the economics of enterprise security entirely. Mythos-class capabilities will soon become available to every adversary, every defender, and every enterprise development team. Vulnerability backlogs won't grow incrementally, they'll grow by orders of magnitude.

    In this session, ArmorCode Principal Security Advisor Joe Nicastro lays out a candid, vendor-agnostic view of what the post-Mythos landscape actually demands from CISOs, boards, and policymakers. He will address the following topics:

    The implications of Mythos and other frontier models for exposure management
    How discovery has become roughly 10% of the security operations problem and why the remaining 90% will consist of business context, prioritization, routing, SLA tracking, verification, and governance of the AI agents themselves

    Why traditional strategies such as periodic scans, CVSS-based triage, ticket-driven remediation will be challenged in this new world
    What the next decade of enterprise risk reduction will look like
    Attendees will leave with a clear-eyed assessment of the four operating shifts that separate organizations prepared for the tsunami from those still standing on the beach, a framework for governing autonomous AI security agents inside the enterprise, and a 90-day action plan ready for the next board conversation.

  • SANS

    Take a break, enjoy a satisfying lunch, and continue the conversation with peers while building new connections across the cybersecurity community.

  • Refuel with a fresh cup of coffee and light snacks

  • Rubrik

    As autonomous AI systems become more prevalent, organizations face a new set of operational challenges. These challenges are not about the models alone. AI vulnerabilities like prompt injections and context manipulation combine with unpredictable human behaviors to amplify risk.
    To bridge this gap, organizations must shift from reactive risk management to Trust Engineering. This discipline focuses on building trust through human centered design and trust infrastructure. Trust infrastructure includes guardrails, observability, monitors, and recovery mechanisms to ensure systems are reliable and secure.
    This session explores the intersection of human centered design with trust infrastructure to:
    Reduce your surface risk of attack prior to going live.
    Detect and intervene when exceptions occur.
    Deploy recovery mechanisms to ensure resilience.

  • Trend Micro

    In 2024, TrendAI published a four-part series on Rogue AI — artificial intelligence systems acting against the interests of their owners, users, or humanity. The framework defined three causal categories — Malicious, Accidental, and Subverted. The implicit assumption was that AI inference happened on someone else's GPU, behind someone else's API, and crossed a network we could instrument.

    That assumption did not survive the first four months of 2026. Anthropic withheld Mythos on cybersecurity-risk grounds after it autonomously discovered zero-days in every major operating system tested. OpenClaw crossed 247,000 GitHub stars in four months, with roughly 12% of its skills marketplace later found malicious.

    This session updates the Rogue AI taxonomy for the post-OpenClaw, post-Mythos landscape, walks through OWASP's expanded agentic attack surface (ASI01–ASI10), and gives executives a Visibility → Control → Governance playbook designed for agentic AI that no longer needs to call home.

  • Stretch your legs and take a deep breath!

  • As attackers have weaponized AI and automation to overwhelm defenders, SecOps leaders seek to level the battlefield. Join Fareed Cheema from Torq as we examine the role of agentic AI and automation as complementary, vital components of an AI SOC / agentic SecOps strategy that works alongside your staff to expand SOC capacity, accelerate throughput, and reduce risk.

  • Autonomous AI systems are now capable of finding software vulnerabilities—both in code and in running applications—and they’re already being used by both security teams and attackers. That shift is forcing a rethink of how software security actually works. In this session, we’ll cover how security professionals need to evolve to keep up with AI-driven threats, while their organizations are simultaneously shipping more software, faster, using AI. We’ll look at how these changes impact both application owners and security teams, why moving quickly matters, and what falling behind actually looks like.

    Speakers:
  • Telus Business

    This session explores the tension between rapid AI adoption and the 'Shadow AI' dependencies that now permeate the modern supply chain. We are past "blocking ChatGPT" as a security strategy, and need to quickly move to a culture of AI Governance, ensuring that when your team - and your partners - uses AI to drive productivity, they are not sacrificing your organization's security principles"

  • Stretch your legs and take a deep breath!

  • From energy grids to transportation systems, AI is being deployed closer to the edge - where downtime can mean disaster. This talk examines how edge AI enhances monitoring, prediction, and control in critical infrastructure. Learn how to secure systems that operate independently, under pressure, and often without internet access.

  • AI can now clone voices, faces, and writing styles so convincingly that identity itself is under threat. This session explores how generative models blur the line between real and synthetic personas - and what that means for authentication, privacy, and trust. Learn how to prepare for a future where anyone can be anyone.

  • The risk does not require a malicious actor. Your employees are doing their jobs, drafting reports, writing code, preparing client materials, using AI tools that your organization may or may not have approved, configured, or even know about. And in doing so, they may be steadily exposing proprietary research, trade secrets, source code, and confidential strategy to vendor training pipelines, third-party servers, and ultimately to competitors.

    This is the AI IP exposure problem: not a breach, not a hack, but a quiet and continuous outflow that most organizations cannot detect, cannot reconstruct after the fact, and cannot easily assign liability for, because no one did anything wrong.

    This closed-door session explores what happens after the exposure, when an organization discovers that sensitive IP has left the building through an AI tool. Participants will work through a realistic Canadian scenario and discuss what their own organizations are doing, failing to do, and uncertain about.

  • Technology is evolving faster than regulation can keep up. This session highlights the growing gap between AI innovation and policy readiness, offering strategies for proactive self-governance and ethical risk management. Attendees will leave with a clearer understanding of how to lead responsibly when the rules haven’t yet been written.

  • As quantum computing advances from theory to inevitability, Canada’s financial institutions and government systems face growing exposure to cryptographic disruption. This session examines what post-quantum readiness means in practice—identifying vulnerable assets, prioritizing cryptographic agility, and planning for large-scale migration without operational disruption. We will explore emerging standards, hybrid encryption approaches, and risk timelines, while addressing the “harvest now, decrypt later” threat. Attendees will gain a pragmatic roadmap to begin securing critical infrastructure today, ensuring resilience and trust in a post-quantum future.

  • Step into an exclusive evening where Canada’s top cybersecurity leaders gather in a relaxed, upscale setting. Enjoy an open bar, gourmet hors d’oeuvres, and engaging conversations with peers. It’s the perfect opportunity to unwind, connect, and end the day with effortless networking.

  • Grab a drink, network, and break the ice as you get ready for an evening of Unfiltered conversation!

  • The structure steps back, the conversations don’t.

    This is where connections deepen, perspectives shift, and the most valuable moments tend to happen.

    No pressure. No formalities. Just the room, as it is.

  • Enjoy a seamless check-in and get everything you need to start your day with ease.

  • About siberX

    Join us as we begin with our land acknowledgements and opening comments from dignitaries and special guests.

  • Take a moment to step away, recharge, and get ready for what’s ahead.

  • Wiz

    AI is opening up amazing new possibilities, and staying secure at every step is crucial. Join us to explore how the Wiz AI Security Platform provides complete protection for your AI applications, from code all the way to runtime. We’ll show you how to gain full-stack AI visibility, proactively manage risks with our graph-based context, and detect threats across your AI pipelines. Empower your teams to adopt and expand into AI workloads confidently with comprehensive AI Security Posture Management, Runtime Protection, and Code Scanning.

  • Cybersecurity Escape Room

    Security investigations may feel objective, but they’re shaped by human bias. This session explores how cognitive shortcuts like confirmation bias, anchoring, and automation bias impact decision-making under pressure - and how AI tools can amplify these patterns rather than fix them. Through real-world examples and practical techniques, you'll walk away with a clearer picture of how your brain works against you during investigations, and what you can do about it.

  • About siberX

    This roundtable explores the evolving intersection of Indigenous data sovereignty and sovereign cloud infrastructure. The discussion will examine whether meaningful Indigenous sovereignty can be achieved within modern cloud ecosystems built on globally connected, multi-tenant infrastructure. It will also consider whether governance, jurisdiction, privacy, and true control over Indigenous data can be fully realized in today’s digital landscape.

  • About siberX

    This presentation explores the evolving cyber threat landscape, emphasizing major national security risks posed by AI and emerging technologies. It examines the intersection of traditional threats, such as ransomware and phishing, and emerging challenges like deepfakes and phishing schemes particularly in the context of AI advancements.

  • CyberBPO

    Examines the often unseen contributions within Security Operations Centers, where decision-making and incident response rely on a diverse range of roles that are not always equally recognized. Participants will explore how gaps in visibility, recognition, and inclusion can impact team dynamics, performance, and retention. The discussion will focus on practical strategies to ensure equitable acknowledgment of contributions and to strengthen DEI considerations in SOC structures and workflows.

  • Stretch your legs and take a deep breath!

  • ReadySetCyber

    Join us for an interactive, open discussion with CSIS on the current threat landscape and the most pressing threats from hostile states facing the Canadian cybersecurity community and how government agencies can work collaboratively to better address and reduce these threats

    Speakers:
  • SANS

    In today’s threat landscape, identity has become the primary attack surface, and the weakest link. As organizations adopt cloud, hybrid environments, and AI-driven systems, traditional notions of access and trust are rapidly breaking down.

    We will explore the evolving role of identity in cybersecurity and examine how attackers exploit identity gaps and why many current approaches are no longer sufficient.

    This conversation will unpack what it truly means to “know your user” in a modern environment, and what organizations must do now to secure identity before it becomes their greatest risk.

  • About siberX

    Women face cyber threats that are often more targeted, persistent, and personal—yet many security strategies overlook these realities. This session explores how risks like harassment, identity attacks, and digital surveillance uniquely impact women, and where traditional controls fall short. Attendees will gain insight into these patterns and learn how to build more inclusive, gender-conscious cybersecurity approaches that better protect people and organizations.

  • ReadySetCyber

    This round table explores how trust can be intentionally designed into secure systems by accounting for the diverse realities of end users. Participants will discuss how factors such as role, accessibility needs, cultural context, and technical fluency shape interactions with security controls. The conversation will focus on practical approaches to embedding inclusivity, usability, and transparency into system design to strengthen both security outcomes and user trust.

  • CyberBPO

    This topic explores how cybersecurity practices can be effectively incorporated into Agile methodologies. It highlights strategies such as embedding security in sprint planning, defining “security-ready” criteria, and managing vulnerabilities within iterative cycles. The presentation emphasizes maintaining development velocity while ensuring robust security controls.

  • About siberX

    Diversity in threat intelligence is often discussed as a value, but its practical impact is less clearly defined. This session examines what diversity actually translates into for practitioners and executives, from improving analytic rigor and reducing bias in threat assessments to expanding visibility across regions, sectors, and adversary behaviors. It will explore how varied perspectives—across disciplines, backgrounds, and lived experiences—can directly strengthen detection, response, and strategic decision-making. Attendees will leave with a clearer understanding of how to operationalize diversity within threat intelligence functions in a way that drives measurable security outcomes.

  • Stretch your legs and take a deep breath!

  • Artificial intelligence is exploding across every imaginable vertical, use case, and attack vector. Meanwhile, the 60-year-old technology that powers our grids, treats our water, and runs our sewage plants is being yanked online — often by manufacturers who now require an internet connection to function at all. So, what do we do? Run in terror? Pray for the best? Hope Terminator wasn't a leaked draft of the future? This session looks at how AI is reshaping operational technology — for defenders, for adversaries, and for the engineers caught in the middle. We'll talk through marketing theater, examine where AI belongs (and absolutely doesn't) in safety-critical environments, and leave you with a practical lens for governing AI in OT without slowing the mission. Spoiler: the answer isn't terror, prayer, or Skynet. It's planning and creativity.

  • Optiv

    Dynamic and evolving cybersecurity risks cannot be governed by static policy. As exposure shifts across the employee lifecycle spanning roles, pressures and everyday decisions, culture becomes an organization's primary control surface. What is rewarded, tolerated, and reinforced by management practices will define real-world security outcomes, with successful

  • AI promises faster answers, smarter workflows, and meaningful productivity gains, but without proper guardrails, it can also expose sensitive data and introduce new compliance risks. AI doesn’t understand what should be accessed, only what can be accessed. As a result, over-permissioned users, misclassified data, and legacy access issues can quickly lead to unintended data exposure. Join Winslow Technology Group and Netwrix virtually on February 24th to learn how to prepare your environment for safe AI adoption by strengthening data and identity security, reducing risk, and enabling AI with confidence. In this webinar, you’ll learn how to: - Identify the data and identity risks AI can unintentionally amplify - Understand how over-permissioned access and misclassified data lead to exposure - Build the right guardrails to support secure, compliant AI adoption

  • About siberX

    Generative AI has introduced powerful new social engineering techniques. Organizations must develop strategies to detect prompt manipulation, synthetic media, and AI-enabled deception.

  • ReadySetCyber

    Agentic AI systems are increasingly relying on LLMs as routing and decision layers, but those decisions are not purely technical. This session introduces “Consensus Contagion,” a deterministic exploit showing how injected high-status personas can override engineering logic due to RLHF-driven bias. It highlights a critical new attack surface in AI pipelines and offers a path toward more secure, purpose-built architectures.

  • Cybersecurity Escape Room

    This session breaks down quantum computing in practical terms—what it is, where it stands today, and what’s coming next. From Q-Day and its impact on modern cryptography to emerging threats like “harvest now, decrypt later,” it connects the dots between theory and real-world risk. Attendees will also gain insight into NIST PQC standards, Canada’s position on quantum security, and how to begin building a post-quantum migration strategy.

  • CyberBPO

    Security awareness doesn’t start at completion—it starts at engagement. This session reframes how we measure training success by focusing on the full employee journey, from initial awareness to participation and completion. Learn how to identify drop-off points, apply stage-based metrics, and design campaigns that drive genuine, voluntary engagement—not just check-the-box results.

  • SANS

    Take a break on your own schedule, recharge, and continue the conversation with peers across the cybersecurity community.

  • Cybersecurity Escape Room

    Cybersecurity has become increasingly sophisticated, yet trust in systems, teams, and leadership continues to erode. This session explores why the human layer remains one of the most critical and neglected components of security, and why it cannot be “patched” like a technical vulnerability. From breakdowns in communication and overreliance on tools to burnout and misaligned incentives, we examine how organizations are losing trust internally and externally. Designed for both practitioners and executives, this talk offers a candid look at the consequences of sidelining human factors and outlines practical approaches to rebuilding trust as a core element of resilient security programs.

  • CyberBPO

    Security strategies are often well-designed at the top but fail where they matter most: at the point of execution. This session explores the “last mile problem” in cybersecurity, where policies, controls, and frameworks break down as they move from strategy into day-to-day operations. From gaps in communication and ownership to tool overload and competing priorities, we examine why execution consistently falls short despite strong intent. Designed for both practitioners and executives, this talk provides a clear view of where breakdowns occur and offers practical approaches to closing the gap between security design and real-world implementation.

  • Take a moment to step away, recharge, and get ready for what’s ahead.

  • ReadySetCyber

    In cybersecurity, we understand the risk of monocultures - systemic fragility, shared blind spots, and failures that cascade at scale.  The GenAI revolution has brought a new facet to the monoculture risk: systems that at a behavioural level reward standardization, convergence, and sameness. Centralized models, shared datasets, and optimization pressures often treat difference as noise to smooth away, even in the name of safety or neutrality. The result is homogenization in both technology and thought, reinforced by economic, cultural, and technical forces alike. This talk explores how to recognize these problems in engineering and in decision-making and offers practical strategies for using commercial AI systems safely, without flattening perspectives.

  • About siberX

    Every governance framework we rely on assumes a human is in the loop. Someone collects the data, someone makes the decision, someone is accountable. But in modern supply chains, AI systems are already transacting with other AI systems thousands of times per hour, making consequential decisions across organizational boundaries at speeds sometimes no human can review. The machine-to-machine economy is here, and the regulations being drafted to govern it are already obsolete. This session will examine what governance must become when the action lives between organizations rather than within them, and why it will be practitioners, not regulators, who build it first.

  • WiCyS

    An exclusive screening of The WOMEN IN SECURITY Documentary; a powerful film spotlighting the women shaping the future of cybersecurity, intelligence, and protective services. Through candid stories, real-world experiences, and powerful conversations, the documentary explores leadership, resilience, and the impact women continue to have across the security industry. Join us for an inspiring screening followed by a discussion with members of the community.

  • Cybersecurity Escape Room

    Cyber risk is now a board-level concern, yet the gap between technical detail and executive decision-making remains a persistent challenge. This session explores how to translate complex security risks into clear, actionable insights that resonate with boards and senior leadership. Designed for both practitioners and executives, it will cover how to frame risk in business terms, align security priorities with organizational objectives, and communicate trade-offs in a way that informs governance and investment decisions. Attendees will gain practical approaches to elevating security conversations from technical reporting to strategic influence.

  • CyberBPO

    As organizations rely more on contractors, identity assurance is becoming a critical security control—not just an HR step. This session explores how AI-driven identity spoofing and social engineering are creating new insider-risk pathways, even in mature environments. Attendees will gain a practical roadmap to strengthen contractor onboarding, enforce least privilege, and move from vendor trust to organization-validated, auditable controls.

  • Today’s rapidly evolving digital landscape demands that agentic AI systems be evaluated not just for capability, but for measurable risk. This workshop equips CISOs and technology leaders to make smarter AI investments by systematically quantifying the risks of deploying autonomous AI agents.
    We will explore how to leverage indicators such as agent behavior profiles, decision autonomy levels, and system architecture maturity to calculate a comprehensive Agentic AI Risk Index. Special emphasis will be placed on how organizational agility impacts the safe adoption of AI agents that can plan, act, and interact with enterprise systems.
    The session will examine emerging transformation trends, including:
    Rapid adoption of agentic AI and its expanded attack surface,
    New risk vectors such as prompt injection, tool misuse, and autonomous decision errors.

  • As organizations layer on controls to manage risk, they often overlook the unintended consequence of security fatigue—where users become overwhelmed, disengaged, or prone to workarounds. This session explores how over-controlled environments can disproportionately impact different user groups, particularly those with varying roles, access needs, or levels of technical familiarity. Designed for both practitioners and executives, it examines the intersection of usability, equity, and security, highlighting how poorly designed controls can introduce new risks rather than reduce them. Attendees will gain practical insight into balancing strong security with inclusive, user-centered design that supports both compliance and real-world effectiveness.

  • Stretch your legs and take a deep breath!

  • About siberX

    This moderated panel, led by an industry veteran, brings together accomplished female cybersecurity leaders to share unfiltered lessons from the field. Moving beyond theory, the discussion explores what senior management actually looks for when identifying and promoting leadership potential—credibility under pressure, business alignment, and the ability to influence at the executive level. Panelists will reflect on pivotal career moments, missteps, and the realities of navigating leadership paths in cybersecurity. Designed to motivate and equip, this session offers

  • CyberBPO

    Most organizations have the full Defence-in-Depth stack in place—yet breaches continue, driven not by missing controls, but by how they’re used. This session introduces the Extended DiD (E-DiD) Framework, adding four critical layers—governance, culture, AI-driven intelligence, and continuous assurance—to close the real gaps. Walk away with a clear view of where programs fail and a practical 90-day plan to strengthen them.

  • WiCyS Ontario Affiliate

    An exclusive screening of The WOMEN IN SECURITY Documentary; a powerful film spotlighting the women shaping the future of cybersecurity, intelligence, and protective services. Through candid stories, real-world experiences, and powerful conversations, the documentary explores leadership, resilience, and the impact women continue to have across the security industry. Join us for an inspiring screening followed by a discussion with members of the community.

  • ReadySetCyber

    Rigid security models often fail to account for how people actually work, unintentionally excluding users with different needs, roles, or constraints. This session explores how these gaps give rise to shadow workflows—informal, unsanctioned processes that introduce new and often invisible risks. Designed for practitioners and executives, it offers practical approaches to designing more inclusive, adaptable security models that reduce workarounds while strengthening overall resilience.

  • ReadySetCyber

    This session offers a practical starting point for anyone looking to break into cybersecurity. Drawing from personal experience, it introduces a clear Do’s and Don’ts framework to help newcomers build foundational knowledge, gain hands-on experience, and navigate the industry with confidence. Attendees will walk away with actionable guidance, common pitfalls to avoid, and a clearer path into the field.

    Speakers:
  • Cybersecurity Escape Room

    As Canadian organizations push deeper into data-driven personalization, the boundary between value and intrusion is increasingly blurred. This interactive breakout session invites participants to examine real-world scenarios where privacy expectations—shaped by regulation, culture, and trust—are tested or exceeded. Through guided discussion, attendees will explore practical ways to balance personalization with ethical responsibility, transparency, and user trust in a Canadian context.

  • An evening of networking and celebration bringing together cybersecurity professionals, leaders, and changemakers from across the industry.

  • Opening remarks to welcome attendees to an evening celebrating opportunity, innovation, leadership, and the future of cybersecurity, while recognizing the individuals whose long-term contributions have helped shape and strengthen the industry. This session sets the tone for a night focused on connection, impact, and recognition across the cybersecurity community.

  • A recognition segment celebrating emerging leaders and the mentors whose guidance, leadership, and long-term contributions continue to shape the cybersecurity industry. The Emerging Leader Award recognizes rising talent making an impact early in their careers, while the Mentor Award honours individuals dedicated to guiding, supporting, and empowering the next generation of cybersecurity professionals.

  • Explores the responsibility that comes with success in cybersecurity and leadership. This fireside chat examines how creating opportunities for yourself eventually becomes a responsibility to create opportunities for others through mentorship, advocacy, leadership, and community-building. Speakers will reflect on the people who helped shape their journeys and discuss how the next generation of talent can be supported, elevated, and empowered across the industry.

  • A recognition segment honouring leaders who have made a lasting impact through advocacy, leadership, and action within the cybersecurity community. The Woman in Leadership Award celebrates individuals driving meaningful change and innovation across the industry, while the Ally in Action Award recognizes those actively creating more inclusive, supportive, and accessible pathways for others to succeed.

  • A conversation centered around the responsibility that comes with leadership, influence, and long-term impact in cybersecurity. This fireside chat examines how creating pathways for yourself eventually becomes a responsibility to create pathways for others through mentorship, advocacy, leadership, and community-building.

  • A special recognition honouring an individual whose long-term contributions, leadership, and dedication have left a lasting impact on the cybersecurity industry. This moment celebrates a legacy of innovation, mentorship, and influence that continues to shape the future of the community and inspire the next generation of leaders.

  • Reflecting on the long-term impact of leadership, mentorship, and service within the cybersecurity industry. This conversation explores how lasting influence is built over time through resilience, advocacy, innovation, and investing in others. Speakers will share lessons from their journeys, the challenges that shaped them, and the legacy they hope to leave for future generations of cybersecurity leaders.

  • This session concludes the gala with final reflections on the conversations, connections, and achievements recognized throughout the night.

Event Details
Sponsors