Loading…
Venue: Room: Grand Ballroom C (Street Level) clear filter
arrow_back View All Dates
Friday, November 6
 

10:30am PST

CRA will be Cloud-Scale Engineering Change
Friday November 6, 2026 10:30am - 11:15am PST
 The CRA is coming, and those who want to sell products in Europe will have to change their engineering processes and documentation in dramatic ways. This talk will introduce the CRA, walk through the requirements, the deadlines and the latest guidance documents from the EU.
Speakers
Friday November 6, 2026 10:30am - 11:15am PST
Room: Grand Ballroom C (Street Level)

11:30am PST

Modelling for Agentic Failure; when attack trees meet safety engineering
Friday November 6, 2026 11:30am - 12:15pm PST
Security and engineering teams are leaner in 2026, while the agents they're securing keep scaling. We're handing agents more tasks and more reach, which means when they fail, they fail exponentially. Threat modelling tells you what could go wrong, the next step is to decide which few controls or tests actually stop the disaster you want to prevent.

This talk brings threat models together with safety engineering with the mission of a more data driven approach to securing complex and / or agentic systems. Starting from a single Top Event, FTA models failure as explicit chains of conditions. By modelling OR / AND branches and minimal cut sets you can identify test cases, derive probabilities or understand better which controls to prioritise. Threat modelling and attack trees tell you the routes to a bad outcome while FTA tells you which of those routes to close first, and how to test if you've closed them. Pairing the two gives you agents that fail safely and predictably, and a defensible way to justify where your limited security time goes. Using illustrative examples from the cult movie 2001: A Space Odyssey in this talk we'll walk through translating fault paths into prioritised controls and focused tests.

The audience will take away how pairing FTA-driven testing and prioritisation with threat modelling and attack trees closes the loop that helps us build systems and agents that can fail safely and predictably.
Speakers
avatar for Petra Vukmirovic

Petra Vukmirovic

Head of Information Security and Fractional Head of Product, Numan and Devarmor
Petra is a technology enthusiast, leader and public speaker. A former emergency medicine doctor and competitive volleyball athlete, she thrives in challenging environments and loves creating order from chaos. Initially pursuing a medical career, Petra's passion for technology led... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom C (Street Level)

1:15pm PST

Panel Discussion
Friday November 6, 2026 1:15pm - 2:00pm PST

Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom C (Street Level)

2:15pm PST

Post Quantum Crypto (PQC) - Field-Tested Strategies to Defeat Harvest Now, Decrypt Later
Friday November 6, 2026 2:15pm - 3:00pm PST
Q-Day, the moment a cryptographically relevant quantum computer (CRQC) breaks RSA, ECC, and Diffie-Hellman, has no confirmed date. But for any data with a long secrecy shelf life, it has effectively already happened: adversaries are harvesting encrypted traffic today to decrypt it later (HNDL). Meanwhile, governments have stopped waiting. The recent US Government Executive Order 14409 (June 2026) mandates post-quantum encryption for sensitive federal systems by the end of 2030, CNSA 2.0 requires quantum-safe software signing by 2030, and the EU, UK, Germany, and Australia have all converged on 2030-2035 deadlines. France's ANSSI will no longer certify products without quantum-safe encryption. The mandates exist. What most organizations lack is an executable engineering path.

This session presents a practitioner's migration playbook derived from hands-on work with enterprises beginning their post-quantum transitions. We separate the two halves of the problem that are routinely conflated: confidentiality, where hybrid key agreement (X25519MLKEM768) neutralizes harvest-now-decrypt-later immediately, and authentication and PKI, which is the harder, unfinished half that only matters once a CRQC exists. The session walks through where real migrations stall: hybrid handshakes that fragment across the MTU in QUIC, HSMs that cannot accelerate lattice math, the TLS 1.2 dead end, and the unresolved external mu debate in ML-DSA that risks cross-protocol divergence.

Attendees will leave with a combat-tested roadmap for enterprise PQC migration, a PQC maturity model with a concrete 90-day starting plan, a Cryptographic Bill of Materials (CBOM) template, a vendor briefing checklist, pilot project and a governance RACI model. We will cover how to conduct a cryptographic inventory (discovery), the necessity of "hybrid" key exchange (mixing X25519 with ML-KEM), testing for latency, key sizes, interoperability, and how security teams can upskill and execute rapidly.
Speakers
avatar for Anshu Gupta

Anshu Gupta

Founder, Fixin Security
Anshu Gupta is a seasoned global cybersecurity executive with Fortune 500 advisory experience at EY and KPMG, working with companies including Microsoft, Salesforce, Cisco, and Adobe. He has built and led security programs at high-growth startups and fintechs, including Coupa, HelloSign... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom C (Street Level)

3:30pm PST

From Design Docs to Mitigations: Scaling Pre-Launch Security Review with Historical Decisions
Friday November 6, 2026 3:30pm - 4:15pm PST
Security review is getting squeezed from both sides. Product teams ship faster, GenAI has accelerated how quickly new features get built, and review teams are still expected to read each design doc from scratch and decide what can ship. That breaks down long before the roadmap slows down.

This talk shows an AI-assisted pre-launch review pattern built for that problem. The pipeline does not stop at generating a generic threat list or a dashboard for leadership. It starts with a structured risk taxonomy, mapped control expectations, and a corpus of historically reviewed launches. Given a PRD or design document for any new feature or application—not only GenAI products—it produces a reviewer-ready first pass: likely risks (from OWASP and internal), targeted follow-up questions, relevant control areas, and concrete mitigations grounded in both reviewer expertise and decisions that were approved in similar launches before. The same structure can support rollups for leadership, but the real value is at review time: better questions and earlier mitigations.

A key step is similarity-based retrieval over historical reviews. After the initial pass, the system looks for comparable launches and reuses the risks, control signals, and mitigation patterns that mattered in those cases. This helps recover issues that a single pass often misses and keeps the review grounded in how the organization actually makes launch decisions. Every completed review becomes another case in the corpus, so future reviews start from a richer set of approved precedents.

We will walk through the architecture, the feedback loop, and the places where this fails: thin design docs, stale taxonomies, misleading historical matches, and overconfident model output. We will also share results from a labeled benchmark of 19 PRDs and 205 human-reviewed risk labels. At a recall-oriented operating point, the pipeline reached 75% recall and 60% precision, and historical retrieval recovered 4–9 additional relevant threats per PRD on similar cases. Next steps including adding more data sources such as code repositories & live traffic.

The initial deployment focuses on fraud, but the pattern is being extended to other threat domains that matter in large product organizations, including abuse, privacy, and product security. This is not about replacing reviewers. It is about giving them leverage. Attendees will leave with a practical blueprint for turning blank-page review into a faster, more consistent workflow that surfaces mitigations before the design is already on its way to launch.
Speakers
avatar for Liat Ben Porat

Liat Ben Porat

Director, AI Science, Intuit
Liat Ben Porat leads the AI science organization within Intuit's global trust, fraud, and security group, where she drives the strategy, development, and adoption of AI solutions across security, fraud, compliance, and workforce teams. She also serves as her organization's lead for... Read More →
GS

Guy Shtar

AI Security & Safety Architect, Intuit

Guy Shtar is an AI Security & Safety Architect at Intuit, working on the intersection of GenAI, security, and Trust & Safety. His work focuses on turning subjective review workflows into measurable technical systems, including AI-assisted risk discovery, adversarial testing, and security... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom C (Street Level)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -