Examples
The below submissions have different elements that stood out to our Program Committee judges. We’ve highlighted the distinctions that lend strength when compared against other submissions on a particular topic.
- Session details
- Note the details provide depth, validity, expertise, and specifics.
- Don’t spend time highlighting the problem.
- Make it very clear what the particular speaker has to offer and why they should stand out against other similar submissions.
- Clear focus on education
- Beyond awareness—not just awareness for the sake of being aware.
- None are a pitch for a particular product or service.
- More than good submissions
- Speakers have strong domain expertise—as illustrated in their bio—to support their cases to present on these topics (the biographies and vantage point of the proposed speakers is hugely important in the evaluation process).
While these submissions stood out to our Program Committee, the submitters also responded to Program Committee feedback and made updates accordingly within their decks. In many cases, they took advantage of the speaker training and rehearsal options that RSA Conference™ offered, and they delivered. We recommend reviewing their submissions, slides, and actual recordings where available.
Note: To access the presentations and slides, you will need to login to/create an account for the RSAC™ Community Portal.
| SESSION TITLE | Defining, Measuring, and Managing Agentic AI Risk: OWASP AIVSS |
| SESSION ABSTRACT |
In 2026, agentic AI will challenge our legacy risk models. This leadership panel will unite experts from government, AI model developer, and open standard to cover the value of an open standard like OWASP AIVSS to be used as one of the foundational frameworks for Agentic AI Risk Management. Attendees will gain strategic insights on building trust and managing enterprise risk in the age of Agentic AI. |
| SESSION DETAIL |
In 2026, the deployment of agentic AI is a standard business practice, but our methods for managing its unique risks are not. Legacy risk frameworks are insufficient for governing autonomous systems that can learn, adapt, and develop emergent behaviors. This creates a critical blind spot for enterprise leaders and national security stakeholders alike. This panel addresses this governance gap head-on, addressing the "what, why, and how" of measuring agentic AI risk at a strategic level: Defining the New Risk Landscape (What): Expanding on why agentic AI demands a shift from a code-centric security view to a semantic-centric governance model. How to measure the most significant business and mission-critical risks that leaders currently cannot see on their dashboards. The Imperative for a Global Standard (Why): Drilling down on the industry-wide need for a common language to discuss and measure AI risk. We will explore how a framework like the OWASP AI Vulnerability Scoring System (AIVSS) can create a foundation building block for Agentic AI Risk Management. A Roadmap for Governance (How): Finishing with actionable takeaways on preparing for this new era. Addressing the organizational and talent gaps required to manage AI risk, the role of open standards in demonstrating due diligence, and the value proposition for investing in the people, processes, and tools for a mature AI security program. This session is not a technical deep-dive. It is a high-level, strategic dialogue designed to provide CISOs, policymakers, and business leaders with the insights needed on their journey to learn about and govern the future of AI responsibly. |
| REVIEWER ASSESSMENT | This submission is strong because it directly addresses the lag between agentic AI adoption and the frameworks needed to manage it. The details focus on a timely and underserved governance gap with a clear, structured "what, why, how" arc that speaks directly to a CISO and executive audience. The inclusion of a concrete standard (OWASP AIVSS) and actionable organizational takeaways elevates it beyond thought leadership into something attendees can actually apply. |
| SESSION TITLE | |
| SESSION ABSTRACT | Forget about best practices, my job is dealing with the worst ones—from using default Microsoft tenant configurations to trusting vulnerability scan findings. Learn from the mistakes of others and don’t fall victim to any of my least favorite dumb ways to die (or get compromised and lose data). |
| SESSION DETAIL | I spent about a year working for a company that wasn't just one company - it was 90+ companies, and rapidly acquiring more. In the course of building an IR program for them and dealing with an unending stream of website compromises and BECs, I uncovered all sorts of terrible decisions, bad configurations, and tenants that were left in default states long enough that when updates were made to them, they were never picked up or enabled. I'll be talking about bad and misconfigured vulnerability scans (or worse, scanners that don't cover major vulnerabilities), bad ways to handle incident response when it comes to adversary in the middle phishing attempts (and ways to make them less impactful), some terrible Microsoft defaults (like never making sure your older tenant had audit logging enabled, and disabling oauth consent), bad developer decisions (writing your own input validation, storing passwords in plain text in your database, etc), and more. There's a million dumb ways to die and fortunately many of them don't require a whole lot of effort to fix, and attendees should come away with a list of changes to make and configurations to double check in their own environments. I would say this session straddles technical and general, if only because the detail on remediating some of these issues does require experience in those tools and an understanding of the concepts behind things like identity providers and vulnerability management, and a general practitioner may not be familiar with them, or a SOC analyst, but newer security engineer would find value and even an older one that has taken some stuff for granted would come away with some things to check on. |
| REVIEWER ASSESSMENT | With a focus on the year spent inside a complex, sprawling multi-entity environment, this submission has credibility. The authentic, hard-won specificity invites immediate trust. The "dumb ways to die" framing is memorable and the explicit promise of a concrete checklist of fixes makes the attendee value proposition unusually clear. |
| SESSION TITLE | Beyond Jericho: Salvaging Zero Trust from Buzzword Bingo |
| SESSION ABSTRACT |
Despite years of enthusiasm since the Jericho Forum and Google's BeyondCorp, many still struggle to implement Zero Trust. The principles are known, but operationalizing ZTA stalls. Have CISOs been gaslit? The disconnect between promise and reality is painful. This session will deliver a practical framework for turning buzzwords into building blocks for successful programs. |
| SESSION DETAIL |
Zero Trust has become the poster child for cybersecurity transformation and for buzzword fatigue. Introduced by the Jericho Forum in 2004, popularized by Google’s BeyondCorp in 2014, and formalized by NIST and CISA over the past five years, the concept promised a safer, more resilient enterprise. Yet for many security leaders, adoption has stalled. Why? This session explores how visionary ideas get lost in translation between pundits, vendors, and practitioners. We’ll unpack four patterns that derail progress: Misalignment. Pundits pontificate where engineers fear to tread. Thought leaders theorize, vendors overpromise, and engineers are left with impractical tools. We’ll provide tips for using buzzwords to garner excitement for projects without over-selling. All-or-Nothing Fallacy. Many treat transformation as a single milestone. The all-or-nothing fallacy. Since the days of “Cloud first”, leaders have attempted transformations by placing large bets and believing the value would come when everything was done. Yet technical debt, cultural drag, failures of the technology, pitfalls in the buzzwords get in the way. We’ll show how to extract core concepts and creative ideas from fluffy concepts. Shifting Definitions. As buzzwords mature, the goalposts move. Adoption surveys show declining success because definitions evolve faster than deployments. The trick is managing stakeholders’ and peers’ expectations while sustaining momentum. Amara’s Law. “We tend to overestimate the effect of a technology in the short run and underestimate the effect in the long run.” Creating a cycle that capitalizes on project successes while taking advantage of new openings that happen post-implementation. The resulting framework bridges the gap between theoretical principles and operational reality. It begins with identifying core business use cases and mapping out existing trust assumptions, followed by evaluating technologies not on their marketing claims but on their actual ability to support those use cases. This is not a one-size-fits-all model, but a tactical guide to making Zero Trust (and really, any buzzword) into real, sustainable, and outcome-focused tactics. As it says in the abstract, turning buzzwords into building blocks for successful programs. |
| REVIEWER ASSESSMENT | This submission stands out for reframing a worn-out topic into something genuinely useful. Rather than relitigating what Zero Trust is, it diagnoses why good ideas fail in practice and gives practitioners a transferable framework applicable well beyond Zero Trust. The four-pattern structure (misalignment, all-or-nothing fallacy, shifting definitions, Amara's Law) is intellectually rigorous and signals a speaker who has thought carefully about the problem, not just the solution. |
| SESSION TITLE | Flush Worthy or Fight Ready? Catching Attackers in SaaS Logs! |
| SESSION ABSTRACT |
Ever felt SaaS logs are useless? This talk will expose 10 outrageous logging fails used by attackers to hide in plain sight: missing data, nonsense events, vanishing trails, and more. From M365 & Salesforce to Copilot & Gemini, each example will show the investigation roadblocks it creates, followed by enrichments, correlations and tricks to turn broken logs into detections and catch attackers. |
| SESSION DETAIL |
This is an ADVANCED TECHNICAL TALK, focusing on real-world SaaS logging failures that SOC analysts encounter daily while trying to catch real threat actors - not theory. We’ll dissect 10 outrageous examples from M365, Salesforce, GitHub, Workday, Copilot, Gemini, and more, showing how each failure cripples detection or investigation. For every fail we’ll provide actionable workarounds: enrichments, correlations, and investigation tricks, that defenders can apply immediately. The goal: give security teams practical techniques to fight back even where SaaS vendors fail. We’ll start with the broader challenges of SaaS logs from an IR/SOC perspective: inconsistent formats, lack of standardization, delays of 24–48 hours, and vendors’ poor understanding of what useful security logs require. AI SaaS (Copilot/Gemini/etc.) adds new challenges, often exposing even less security-relevant logging than traditional SaaS. We’ll outline the main categories of bad logging and tie each to the specific detection, investigation, and response tasks they break. The core of the session will walk through 10 examples of terrible SaaS logging. Each will be demonstrated with real-world example, gaps between expectations and reality, and the security implications. For every case we’ll explain what’s wrong, why it matters, and how to fix it using other logs, configuration data or enrichment techniques. Examples include login sequences split across multiple sources (M365), missing user identifiers (Salesforce and others), unlogged authentication type (critical in SaaS phishing campaigns), out-of-order events, cryptic event descriptions, and events that never appear at all. We will also demonstrate new challenges introduced by AI SaaS (Copilot, Gemini, etc.). Mitigation & Conclusion: We’ll close with strategies and tactics for defenders: preparing for SaaS logging gaps, enriching and correlating data during incidents, and building resilience against missing or misleading records. We’ll provide guidance on evaluating logs across SaaS platforms, handling retention and collection issues, and identifying weaknesses early. Finally, we’ll call on SaaS vendors to step up their logging - because defenders shouldn’t have to fight blind. Attendees will leave with concrete techniques to turn weak logs into real detection power - tools they can apply right away. This is a must-attend session for SOC analysts and incident responders determined to catch attackers despite SaaS blind spots. |
| REVIEWER ASSESSMENT |
This submission delivers exactly what advanced technical tracks are designed for — real artifacts, named platforms, and specific failure modes that SOC analysts will recognize from their own queues, paired with immediate workarounds rather than vendor-dependent fixes. The structure of "here's what's broken, here's why it matters, here's how to work around it today" across ten concrete examples makes it one of the more actionable technical submissions a defender-focused audience could walk into. |
| SESSION TITLE | Preparing for AI Vulnerability Exploitation: Preventing Cataclysm |
| SESSION ABSTRACT | AI vulnerability discovery is no longer speculative. AI ranks #1 on HackerOne's leaderboard. DARPA's AIxCC uncovered 54 vulnerabilities in hours. APT28 reportedly folds LLMs into malware, closing the exploitation gap. This session will examine evidence of this shift and provide concrete strategies to prepare for the coming flood of vulnerabilities. |
| SESSION DETAIL |
An AI system is already ranked number one on the HackerOne bug bounty leaderboard. In DARPA's AIxCC challenge, 54 vulnerabilities were uncovered in hours of compute time, and Google's Gemini-based Big Sleep has identified dozens more. Adversaries like APT28 are reportedly folding LLMs into malware, closing the final gap of exploitation, and a flood of vulnerabilities is on the way, driven by exponential growth in discovery and a rapidly shrinking time to exploit. The purpose of this talk is to present evidence of how this shift is already underway, and to help the community prepare. Attendees will learn: - How to build scalable triage and remediation flows to handle vulnerability volume. - How to implement near-term defensive strategies to shrink attack surfaces and increase resilience. - How to extend resilience beyond the enterprise by shaping the broader ecosystem, influencing vendors, supporting open-source security, and building coalitions with peers. - How to prepare for a collapsing time-to-exploit and the risks of automatic exploitation during live operations. We face a convergence of accelerated vulnerability discovery and shortened exploitation timelines. While security professionals are trained to avoid FUD, the facts themselves demand urgent attention. The traditional model of vulnerability management, designed for human-paced discovery, requires immediate evolution to handle AI-scale threats. Throughout the session, we'll distinguish between genuinely transformative AI capabilities and incremental improvements to existing tools like fuzzing and static analysis, helping attendees separate signal from noise in the AI security landscape. Attendees will leave with actionable frameworks for evolving their vulnerability management programs to handle AI-scale threats while avoiding both complacency and panic. |
| REVIEWER ASSESSMENT | This submission opens with concrete, verifiable evidence (HackerOne leaderboard, AIxCC results, Big Sleep findings) rather than speculation, which immediately separates it from the crowded field of AI-and-security talks that lead with hype. The explicit commitment to distinguishing transformative AI capabilities from incremental ones, combined with actionable frameworks for vulnerability management at AI scale, gives it urgency and makes it both intellectually honest and practically valuable for a senior technical audience. |