Type: CyberBay Summit 2026
Security & Threats
The ABCs Of Software Supply Chain Security | Blake Hearn
This session explores the growing cybersecurity risks within modern software supply chains and how organizations can reduce their open-source attack…
This session explores the growing cybersecurity risks within modern software supply chains and how organizations can reduce their open-source attack surface through more secure containerization and dependency management practices. The speaker examines major supply chain attacks including SolarWinds, Log4j, and the XZ Utils backdoor, showing how vulnerabilities in open-source dependencies and build systems continue to impact organizations at scale. Topics include software bills of materials (SBOMs), container security, CVE management, dependency sprawl, supply chain trust, multi-stage container builds, minimal container images, FIPS validation, STIG compliance, reproducible builds, and secure release pipelines. The presentation also demonstrates how hardened “built-from-source” container approaches can dramatically reduce vulnerabilities, improve compliance readiness, and minimize operational overhead for development and security teams managing modern cloud-native infrastructure.
Security & Threats
Cybersecurity IR Resources For Smaller Organizations | George Zimmerman
This session explores practical, low-cost approaches organizations can use to strengthen cybersecurity incident response capabilities without large security budgets or…
This session explores practical, low-cost approaches organizations can use to strengthen cybersecurity incident response capabilities without large security budgets or dedicated enterprise tooling. The speakers walk through the full incident response lifecycle using the NIST framework, covering preparation, detection, containment, eradication, recovery, and post-incident analysis, while highlighting free and accessible resources available through CISA. Topics include building incident response plans, maintaining asset inventories, security awareness training, phishing simulations, threat intelligence feeds, tabletop exercises, vulnerability scanning, logging and monitoring tools, recovery planning, and documenting lessons learned. The presentation also demonstrates how small teams and public-sector organizations can leverage free CISA services, cyber hygiene assessments, tabletop exercise packages, and performance goal frameworks to improve readiness, resilience, and coordination during cyber incidents.
AI, Innovation & Emerging Technology
The Quantum Break is Coming: Will You Be Ready? | Roger Grimes
This session provides a deep dive into the rapidly approaching impact of quantum computing on modern cybersecurity, encryption, and digital…
This session provides a deep dive into the rapidly approaching impact of quantum computing on modern cybersecurity, encryption, and digital infrastructure. Cybersecurity expert Roger Grimes explains how sufficiently capable quantum computers could soon break the asymmetric cryptography that protects most of today’s internet traffic, authentication systems, software signing, VPNs, Wi-Fi, and secure communications. The presentation explores core quantum concepts including superposition, entanglement, cubits, Shor’s Algorithm, Grover’s Algorithm, and how quantum systems dramatically outperform classical computing for certain mathematical problems. The discussion also covers the timeline toward “Q-Day,” the global shift toward post-quantum cryptography, the risks of “harvest now, decrypt later” attacks, and the urgent need for organizations to begin quantum readiness and cryptographic migration projects now. Real-world guidance is provided around post-quantum planning, crypto agility, password security, AI-assisted attacks, and how governments and major technology vendors are preparing for the next era of computing.
Leadership & Executive Strategy
Crisis Management Preparations For Executives | John Ford
This session explores how executive teams can prepare for and lead through major cyber incidents, with a focus on crisis…
This session explores how executive teams can prepare for and lead through major cyber incidents, with a focus on crisis decision-making, communications, authority structures, and operational readiness during ransomware and breach scenarios. Drawing from real-world experience as a former CISO and incident response leader, the speaker breaks down the difference between prepared and unprepared organizations, showing how confusion around authority, communications, and escalation can dramatically worsen the impact of an attack. The presentation covers executive tabletop exercises, ransomware response strategy, breach communications, cyber insurance coordination, legal and regulatory escalation, vendor and third-party breach scenarios, and the importance of building organizational “muscle memory” through realistic crisis simulations. Real-world examples including Colonial Pipeline, MGM, Caesars, Change Healthcare, and 23andMe are used to illustrate how executive decisions can shape the long-term outcome of a cyber crisis.
Security & Threats
The New Attack Surface Hotness: Your SSO Dashboard | Allan Liska
This session explores how single sign-on (SSO) platforms and SaaS providers have become a major target for modern cybercriminals. The…
This session explores how single sign-on (SSO) platforms and SaaS providers have become a major target for modern cybercriminals. The speaker breaks down how ransomware groups like Scattered Spider and ShinyHunters use sophisticated social engineering, voice phishing (“TOAD” attacks), fake SSO portals, and MFA bypass techniques to compromise organizations through help desk impersonation and real-time phishing kits. Topics include SaaS security risks, identity-based attacks, device code phishing, lookalike domains, cloud data exposure, logging challenges with SaaS providers, and the growing importance of monitoring third- and fourth-party risk. The presentation also examines practical defenses including phishing-resistant MFA, passkeys, DNS monitoring, employee awareness, and stronger visibility into cloud environments and SSO activity.
Security & Threats
AI With Intention | Jim McGann
This session explores the growing reality that ransomware recovery is no longer just a backup problem — it’s a data…
This session explores the growing reality that ransomware recovery is no longer just a backup problem — it’s a data integrity problem. The speaker examines how modern ransomware attacks target backups directly, use AI-driven tactics to evade detection, and dramatically extend recovery timelines for organizations of every size. Topics include cyber resiliency, the NIST Cybersecurity Framework, AI-powered ransomware detection, clean recovery strategies, data integrity validation, and the operational challenges organizations face when recovering from large-scale attacks. The presentation also highlights how AI is being used defensively to identify corruption patterns, detect compromised recovery points, and help organizations recover faster with confidence.
Security & Threats
The Dark Web’s New Gold Rush | Cat Karow
A thought-provoking session exploring how AI is transforming cybercrime from isolated attacks into a scalable service economy. The speaker breaks…
A thought-provoking session exploring how AI is transforming cybercrime from isolated attacks into a scalable service economy. The speaker breaks down the rise of identity-state theft, scam compounds, AI-driven fraud, deepfakes, and cybercrime-as-a-service, while examining how trust, identity, and human behavior have become the new battlegrounds in modern cybersecurity. Practical insights include zero trust architecture, detecting trust anomalies, protecting against social engineering, and understanding the growing role of data brokers and organized cybercrime infrastructure.
