
Track: Beneath the Surface | Human-Led Cyber Resilience
Session Descriptions
Session 1: Culture | 9:00–9:50
Culture Is Your First Control
Tools and policies only go as far as the culture around them. The teams that catch problems early are the ones where people feel safe reporting a mistake, asking a question, or flagging something that looks off. Building that culture is one of the highest-leverage moves a leader can make, and one of the most under-invested. This session shows what a security-minded culture actually looks like in practice: psychological safety around reporting, awareness programs people don’t resent, and the leadership signals that tell an organization security is real here. Leave with practical ideas you can bring back to your organization.
Session 2: Tooling | 10:00–10:50
The Essential Stack: Tooling That Actually Protects
Cybersecurity tooling used to be a small, simple stack. Today it’s an industry of its own. There has never been more on the market, and it has never been harder to tell what actually moves the needle. This session breaks down the categories every defensible stack needs and what each one is really there to do. You’ll leave with a sharper read on what your stack should look like, and what to demand of the tools in it.
Session 3: Human Capital + Communications | 1:00–1:50
When the Crisis Hits: Caring for People, Communicating Under Pressure
The story is on the front page. Half your team is in shock. The CEO wants to know what to say, the lawyers want to know what not to say, and somebody just sent the wrong message to staff. The hardest problems in a cyber incident aren’t technical. This session pairs the Human Capital Officer’s job (caring for people in crisis, managing trauma, keeping the team functional) with crisis communications: what to say, to whom, when, and how to say it without making things worse. Leave with practical ideas you can take back to your organization.
Session 4: Tabletop Tasting | 2:00–2:50
Tabletop Tasting: Small Plates, Big Lessons for Your IR Plan
Your incident response plan looks great in the binder. How does it look when ransomware hits at 4pm on a Friday, your CFO is on a flight, your top engineer is on PTO, and a journalist is calling for comment? This session serves up a series of small-plate tabletop scenarios, each one stress-testing a specific section of your IR plan. You’ll see where your plan stands up and where it cracks, and leave with the questions worth bringing back to your organization.