Global CISO Forum 2026

Schedule

Thu, 08 Oct, 2026 at 08:00 am to Fri, 09 Oct, 2026 at 05:00 pm

UTC-06:00
Location

Westin Peachtree Plaza | Atlanta, GA

Advertisement
Global CISO Forum: An invite-only gathering of CISOs and security leaders for trusted, closed-door peer discussions.
About this Event

EC-Council’s Global CISO Forum is an invite-only, closed-door event gathering the highest level executives from across industries and countries to discuss the most pressing issues in information security.

  • Invite-only and closed-door: attendance is limited to CCISO certification holders, CCISO students, EC-Council-invited security practitioners, and director-level or above information security executives, and marketers or business development professionals aren’t permitted to attend.
  • Purpose: it’s designed as a strategic venue for peer-to-peer exchange and deep dialogue among the world’s C-suite and senior security leaders on the most pressing challenges in cybersecurity. The closed-door nature exists specifically to create an atmosphere of trust and confidentiality that enables open exchange of lessons learned, failures, and forward-looking strategies.
  • Format: closed-door sessions, interactive discussions, and curated roundtables.

Agenda

🕑: 09:10 AM - 10:00 AM
Joint Keynote 1
Host: To Be Revealed
🕑: 10:00 AM - 10:50 AM
Joint Keynote 2
Host: Chris Roberts

Info: Principal Architect and Global Field CTO at Worldwide Technology, have also been called a Strategist, Researcher, Hacker, Speaker, recovering CISO, Advisor, etc.

Now also writing on the Ghost platform, "Plaintext"

Currently supporting the organization through project, client, and research focused areas, some of the recent thing have been focused within the transportation, aerospace, deception, deepfake, identity, cryptography, AI/AdversarialAI, and services sectors.

Over the years, I've founded or worked with numerous organizations specializing in human research, data/threat intelligence, transportation, cryptography, and deception technologies. These days I'm working on spreading risk, maturity, collaboration, and communication messaging across the industry.

When not working I'm either hunkered down with a good set of headphones/amp, and enjoying the audiophile world OR charging round the countryside on a mountain bike or three, mostly to preserve mental health, but also exercise


🕑: 10:50 AM - 11:40 AM
Joint Keynote 3
Host: To be Revealed
🕑: 12:45 PM - 01:30 PM
The Future of the CISO: Evolution or Extinction?
Host: Lovelie Moore, BISO of Toyota

Info: Artificial intelligence is reshaping cybersecurity from the ground up. Tasks once performed by entry- and mid-level professionals are increasingly being augmented or automated, changing how security teams operate, how talent develops, and how future cybersecurity leaders gain the experience necessary to lead. As AI moves beyond analysis and recommendations toward autonomous decision-making, a larger question emerges: What happens when that disruption reaches the CISO? This interactive executive roundtable will explore whether AI will simply make cybersecurity leaders more effective or fundamentally redefine the CISO role itself. Using real-time live polling, participants will anonymously respond to intentionally debatable questions about AI, leadership, accountability, resilience, trust, and the future scope of cybersecurity leadership.


🕑: 01:30 PM - 02:15 PM
Failure-Mode Risk Analysis: Making Material Risk Legible to the Board
Host: Keyaan Williams, Managing Director CLASS-LLC

Info: Boards are rarely starved for cybersecurity information. They are starved for clarity about how the enterprise could plausibly fail, what consequences would follow, and whether leadership has made explicit decisions about those exposures. Much of today’s cyber risk reporting emphasizes controls, maturity scores, and probabilistic heat maps. These artifacts create the appearance of rigor while leaving directors unable to form judgment under fiduciary scrutiny.


🕑: 03:05 PM - 03:50 PM
inSECURITY
Host: Jim West

Info: inSECURITY is an immersive, interactive cybersecurity performance where the audience learns core concepts—risk management, vulnerability management, incident handling, and more—by actively participating with everyday actions like using their wallets, phones, and even throwing a piece of paper away. This is not typical user training or a slide-driven lecture. Jim West leads participants through the what, how, and most importantly the why behind modern cyber risk, making security personal and immediately relevant to any role or experience level. InSECURITY is designed to dramatically increase engagement and retention by turning abstract security rules into memorable, real-world moments attendees won’t forget.


Governing Decision Integrity in the Age of AI and Deception
Host: Greg Carpenter

Info: Digital trust can fail even when technical systems remain operational. Manipulated telemetry, synthetic identities, deepfakes, spoofed communications, corrupted data, and authoritative-looking AI outputs can distort executive and operational decisions without triggering conventional security controls. This panel examines perception security as an enterprise governance and policy problem. It addresses accountability for validating consequential information, the controls required to protect institutional decision-making, and the mechanisms organizations need to identify, escalate, and recover from attacks on trust itself. Panelists will consider how decision integrity should be incorporated into AI governance, enterprise risk management, incident response, third-party oversight, crisis communications, and board reporting. The objective is a practical governance framework for preserving institutional judgment.


From Zero Trust to Zero Intent: The Next Architecture Shift
Host: Rajan Behal

Info: Zero Trust was built on a deceptively simple principle: never trust, always verify. For a decade, that principle reshaped enterprise security — collapsing the perimeter, enforcing least privilege, and demanding continuous verification of every human identity, device, and session. Then agentic AI arrived. The principle held. The architecture broke. Zero Trust assumes that "verify" means something — that behind every access request is a principal whose identity can be confirmed, whose device posture can be assessed, and whose behavior can be baselined against human patterns. AI agents satisfy none of these assumptions. They authenticate via API keys and OAuth tokens. They have no device. They run 24/7 with no behavioral signature that human-calibrated UEBA can interpret. And they don't just access resources — they make decisions, execute transactions, and trigger downstream workflows, all within a permission set approved once at provisioning


CISO–CAIO–CLO Triad: Who Owns the Human Layer?
Host: George Dobrea

Info: In today’s threat landscape, technology alone is no longer enough. While organizations continue to invest in advanced security controls and AI-driven capabilities, the human layer remains both the greatest vulnerability and the most powerful line of defense. This session explores the evolving CISO–CAIO–CLO triad—Chief Information Security Officer, Chief AI Officer, and Chief Learning Officer—and the critical question: who truly owns human risk, workforce readiness, and cyber resilience? Bringing together cybersecurity leadership, AI strategy, and organizational learning, the presentation examines how these three executive roles must collaborate to transform awareness into action, skills into resilience, and culture into a strategic security asset. Attendees will gain practical insights into governance models, workforce upskilling, AI-enabled learning, and leadership alignment needed to build a truly cyber-ready organization.


Behind the Vendor Risk Curtain: Context Beats Scores
Host: Jason Stewart

Info: Vendor risk may seem manageable until a critical moment reveals its true nature. The dashboard shows green, the questionnaire is filled out, the score is acceptable, and the annual review has been completed. However, when a vendor outage, a ransomware attack, a failed integration, or a supply chain disruption occurs, leaders often realize that the score does not address the most crucial questions. This fireside-style session aims to uncover the illusion of control in traditional third-party risk management (TPRM). The conversation will move beyond the basics of TPRM to address more challenging leadership questions, such as how to identify hidden dependencies, differentiate between compliance activities and true resilience, and translate vendor risk into actionable decisions for executives. The session will challenge the score-first approach adopted by many TPRM programs.


Crisis Leadership for the Converged AI, Identity, and Third-Party Incident
Host: Bidemi Ologunde

Info: The hardest incidents in 2026 are not isolated events. They are converged crises: a deepfake call triggers fraudulent approval, a third-party platform becomes unavailable, an internal AI assistant exposes sensitive data, and attackers exploit the confusion to expand access. This executive session presents a continuity-first operating model for stacked cyber events. It will explore the human factors that drive failure under pressure, including misinformation, conflicting signals, and overtrust in automated systems. It will also show how to align privacy, legal, communications, operations, and security leadership around a single crisis framework. Finally, it will demonstrate how deception technologies and controlled false environments can be used in rehearsals, table-tops, and live defense to validate response paths, expose weak decisions, and maintain essential operations while the organization restores trust.


Advertisement

Where is it happening?

Westin Peachtree Plaza, 210 Peachtree St. NW, Atlanta, United States

Event Location & Nearby Stays:

Tickets

USD 27.37 to USD 199.00

Know what’s Happening Next — before everyone else does.
EC-Council Foundation
Host or PublisherEC-Council Foundation

Ask AI if this event suits you