Workshops
Schedule may be subject to change
Workshop • 8 am - 12 pm ET
CANCELLED: Fortifying AI: Detecting and Defending Against Prompt Injection Attacks with Open-Source Tools

Update: Our speaker unfortunately was not able to attend at the last minute. World Pass Attendees are able to select other sessions at this time. We apologize for the inconvenience.

------------

This hands-on lab explores the growing threat of Prompt Injection attacks in Generative AI and equips participants with practical strategies for identifying and mitigating these risks.

In this session you will:

  • Understand the security challenges and vulnerabilities associated with Prompt Injection attacks
  • Learn offensive and defensive techniques using real-world scenarios
  • Apply open-source frameworks like NVIDIA NeMo to build actionable defenses

 

Workshop • 8 am - 5 pm ET
WORLD PASS WORKSHOP: Adversary Tactics and Threat Hunting- Day 1

This interactive workshop equips security professionals with the tools and mindset needed to think like attackers—and defend smarter. Through practical exercises in attack simulation, threat hunting, and detection engineering, participants will explore advanced tactics, uncover key indicators of compromise, and build high-fidelity detections. The session also delves into the dual role of AI in both offensive and defensive operations, providing a cutting-edge perspective on modern cybersecurity strategy.

In this session you will:

  • Emulate real-world attacker behavior and identify critical indicators of compromise
  • Develop and test high-fidelity detections for both network and cloud-based threats
  • Leverage AI to enhance both threat emulation and defensive capabilities

 

This session is exclusive for World Pass Holders only.

Workshop • 8 am - 12 pm ET
WORLD PASS WORKSHOP: Fortifying the Future: Essential Cyber Insurance Strategies for CISOs

Cyber insurance has become a critical component of risk management for today’s CISOs. This session will explore how to strategically evaluate, select, and integrate cyber insurance to strengthen organizational resilience in an evolving threat landscape.

In this session you will:

  • Explore key coverage options, policy considerations, and emerging trends in cyber insurance
  • Learn how to align cyber insurance with your existing security protocols
  • Gain strategies for communicating the value of cyber insurance to executive stakeholders
Instructor:
Dara Gibson, CEO/Owner, Cybersecurity Readiness Advisors
Workshop • 1 pm - 5 pm ET
WORLD PASS WORKSHOP: Cyber Capabilities at Risk - A CISO Workshop

Cyber risk is increasingly synonymous with workforce risk, as traditional cybersecurity models that separate security operations, risk management, and compliance expose organizations to vulnerabilities. This session addresses the pressing challenges of budget constraints, reliance on outsourced talent, and workforce disruptions that strain cybersecurity operations. Attendees will gain insights into managing cyber workforce risks effectively.

In this session you will:

  • Learn to document and optimize talent utilization
  • Map and enhance organizational capabilities
  • Align career aspirations with workload management for improved retention and security. With actionable strategies, transition from reactive to proactive workforce planning
Workshop • 1 pm - 5 pm ET
WORLD PASS WORKSHOP: PCI WTF (What's That Framework): Navigating the New Requirements in PCI DSS v4.0.1 for Enhanced Security and Compliance

Stay ahead of evolving compliance requirements with this in-depth workshop on PCI DSS v4.0.1. Tailored for IT professionals, compliance teams, security leaders, and CISOs, this session offers practical guidance on meeting new standards and preparing for successful audits.

In this session you will:

  • Break down key updates and new requirements in PCI DSS v4.0.1
  • Learn strategies for navigating transition timelines and aligning security practices
  • Understand auditor expectations, evidence collection, and common compliance pitfalls to avoid
Instructor:
Andy Kerr, Senior Manager, LBMC
Workshop • 1 pm - 5 pm ET
WORLD PASS WORKSHOP: Decoding Cybersecurity: How to Speak the Language of Engineers, Management, and Executives

Cybersecurity success depends on more than just technical know-how— it requires clear communication across all levels of an organization. This session offers a practical framework for translating between technical, managerial, and executive perspectives to align security goals with business outcomes.

In this session you will:

  • Learn how to tailor cybersecurity messaging to engineers, managers, and executives
  • Explore real-world examples of bridging communication gaps to gain traction and funding
  • Gain tools to unify security conversations and drive strategic alignment across teams
Instructor:
Benjamin Prest, Owner, Stronghold Cyber Solutions
Workshop • 3:30 am - 12 pm ET
WORLD PASS WORKSHOP: Adversary Tactics and Threat Hunting - Day 2

This workshop offers a comprehensive exploration of attack simulation, threat hunting, and detection engineering for security professionals. Participants will gain insights into attacker tactics and defensive strategies to enhance organizational security.

In this session, you will:

  •  Emulate attackers and identify key indicators of compromise
  •  Develop high-fidelity detections for network and cloud-based attacks
  • Leverage AI for both offensive and defensive security measures
Instructors:
Mike Spitzer, Senior Security Engineer, TrustedSec
Travis Steadman, Security Engineer, TrustedSec
Workshop • 1 pm - 5 pm ET
WORLD PASS WORKSHOP: Presented by InfraGard National Members Alliance: World on Wire: A Global Threat Intelligence Deep Dive

As global tensions escalate and digital perimeters expand, the need to understand the geopolitical forces shaping modern cyber threats has never been greater. This half-day workshop offers a high-impact, intelligence-driven crash course designed to equip cybersecurity leaders with the strategic awareness required to navigate today’s volatile threat landscape.

Participants will gain a clear-eyed view of the latest nation-state campaigns, the growing weaponization of artificial intelligence in offensive operations, and the financial and digital footprint of transnational organized crime. The program will also surface hidden vulnerabilities stemming from unchecked third-party access and supply chain dependencies.

By integrating intelligence, threat detection, and geopolitical analysis, this session empowers security leaders to move beyond reactive defense and build a proactive, informed security posture capable of meeting tomorrow’s challenges with confidence.

You will:

  • Learn how to apply geopolitical intelligence to anticipate nation-state tactics, techniques, and procedures before they target your organization.
  • Gain practical methods to integrate threat intelligence into enterprise decision-making and incident response.
  • Identify hidden third-party and supply chain risks while developing proactive strategies that strengthen resilience across people, processes, and technology.
Instructors:
Corie Burke, Program Manager, InfraGard National Members Alliance
Jeff Macre, Principal Industrial Security Solutions Architect, Darktrace
Curtis Gartenmann, Director of Cyber Threat Intelligence, Americas, Control Risks
Felix Rodriguez, Principal, Digital Risks, Control Risks
Workshop • 1 pm - 3 pm ET
SANS Cyber Executive Workshop

The SANS Executive Cyber Exercise will put you inside a simulated cyber event to help your organization understand what it takes to respond to a cyber incident from a strategic perspective. The simulated exercise will emphasize the importance of a well-practiced cyber crisis plan and the leadership skills required to deal with today's threats. Our facilitators will use real-world experience and industry best practices to expose areas for improvement in an organization's crisis response plans within a safe environment.

A SANS Executive Cyber Exercise (ECE) is a training activity designed to simulate a cybersecurity crisis. Exercises are conducted in a safe, open, and no-fault environment. Participants assess the severity of the attack and determine an effective strategic response.

Learning Objectives:

  • Ability to better assess organizational readiness for a business response to a cyber crisis.
  • Apply industry best practices in cybersecurity, organizational structure, and crisis communications.
  • Understand and plan for emerging trends in cybercrime.
Instructor:
Chris Wilkes, Senior Facilitator, SANS Institute
Workshop • 12:30 pm - 4:30 pm ET
WORLD PASS WORKSHOP: Data Privacy: Navigating the Maze!

In today’s evolving regulatory landscape, a strong privacy program is more than a legal requirement— it’s a competitive advantage. This session will break down key privacy regulations, consent management, and the real-world challenges of operationalizing privacy in 2025.

In this session you will:

  • Gain insights into current and emerging U.S. and EU privacy regulations
  • Learn how to implement and manage effective privacy programs within your organization
  • Understand cookie compliance and consent management to strengthen consumer trust
Instructors:
Wills Catling, Director - Privacy, Myna Partners
Luke Labenski, Principal Solutions Engineer, Myna Partners
William Kenney, Senior Privacy & Compliance Specialist, Myna Partners
Donel Martinez, Director, Myna Partners
Workshop • 12:30 pm - 4:30 pm ET
WORLD PASS WORKSHOP: Decoding Cybersecurity: How to Speak the Language of Engineers, Management, and Executives

Cybersecurity success depends on more than just technical know-how— it requires clear communication across all levels of an organization. This session offers a practical framework for translating between technical, managerial, and executive perspectives to align security goals with business outcomes.

In this session you will:

  • Learn how to tailor cybersecurity messaging to engineers, managers, and executives
  • Explore real-world examples of bridging communication gaps to gain traction and funding
  • Gain tools to unify security conversations and drive strategic alignment across teams
Instructor:
Benjamin Prest, Owner, Stronghold Cyber Solutions
Workshop • 12:30 pm - 4:30 pm ET
WORLD PASS WORKSHOP: Real World Database Encryption - Today & Tomorrow!

This workshop explores the practical realities of securing databases using encryption technologies, with a forward-looking focus on emerging threats and solutions.

In this session you will:

  • Examine current encryption practices and their real-world applications
  • Explore hands-on strategies for Post-Quantum Cryptography (PQC), AI, and vector databases
  • Discover actionable, vendor-neutral techniques to future-proof your data security strategy

 

 

Instructor:
Michael Feinberg, CTO, Leeward Digital, LLC
Workshop • 12:30 pm - 4:30 pm ET
WORLD PASS WORKSHOP: Data Science for Cybersecurity

The cybersecurity landscape generates massive volumes of data—from tools, logs, monitoring systems, and more. To make sense of this complexity, organizations must harness the power of data science and AI/ML. This interactive workshop begins with an overview of key AI, machine learning, and data science concepts tailored for cybersecurity applications. Participants will then dive into a hands-on lab experience using online notebooks to build and train a machine learning model for a real-world cyber challenge.

In this session you will:

  • Understand core AI and machine learning concepts and how they apply to cybersecurity
  • Learn how to visualize and explore cybersecurity data using Python and data science techniques
  • Build and train a machine learning model to solve a cybersecurity problem in a guided, hands-on lab
Instructors:
Devin Cortese, Data Scientist, Carnegie Mellon University, Software Engineering Institute
Emil Mathew, Machine Learning Engineer, Carnegie Mellon University, Software Engineering Institute
Thomas P. Scanlon, Principal Researcher, Carnegie Mellon University, Software Engineering Institute
Workshop • 8:30 am - 12:30 pm ET
RESCHEDULED: WORLD PASS WORKSHOP: AI Assistants for Security Operations

Discover how AI-driven assistants can enhance security operations for organizations of any size or budget. This session will provide a practical roadmap for implementing cost-effective AI tools to support red and blue team functions, threat intelligence, and compliance efforts.

In this session you will:

  • Learn how to select, configure, and integrate open-source, free, and paid AI solutions
  • Explore automation pipelines that boost incident response, red team support, and threat intelligence
  • Understand how to continuously optimize AI tools to keep pace with evolving cyber threats
Instructor:
Samuel Cameron, Principal AI Engineer | Cyber Defense, Verizon
Workshop • 8:30 am - 12:30 pm ET
WORLD PASS WORKSHOP: Rethink, Reinvent, and Lead - Elevating Cybersecurity Teams to High Performance

As cyber threats continue to evolve, so must the teams tasked with defending against them. This session explores how security leaders can reimagine team structures, processes, and culture to build high-performing cybersecurity operations. Drawing from proven frameworks such as Lean Management, the Four Disciplines of Execution (4DX), and the Five Dysfunctions of a Team (5DoT), attendees will gain practical tools to overcome trust deficits, improve collaboration, and align efforts with organizational goals.

In this session you will:

  • Learn how to rethink traditional cybersecurity team models and optimize operations for high performance
  • Explore the use of leadership frameworks like Lean, 4DX, and 5DoT to strengthen decision-making and team cohesion
  • Discover actionable strategies to build trust, foster accountability, and create a culture of continuous improvement
     
Instructor:
Domingo A. Castillo, Chief information security officer, Miami Dade College
Workshop • 8:30 am - 12:30 pm ET
WORLD PASS WORKSHOP: Threat Emulation for Continuous Threat Exposure Management

Threat emulation goes beyond basic security testing—it’s about replicating real-world adversary behaviors through intelligence-driven attack chains to assess and improve organizational defenses. This hands-on session dives into the art and science of threat emulation, showing how to measure exposure, validate detections, and continuously improve incident response capabilities.

In this session you will:

  • Understand the fundamentals of threat emulation and how it enhances security posture
  • Learn how to build, execute, and validate emulation scenarios using free tools and gap analysis
  • Get practical tips to become a highly effective and efficient threat emulator
Instructors:
Trey Bilbrey, Lead Adversary Emulation Engineer, SCYTHE
Tyler Casey, Detection Engineer, SCYTHE
Get in touch
Get in touch
Customer Service
For any and all inquiries please click the button below
Speaking Opportunities

Kris Tanaka
VP, Event Programming

InfoSec World
Stay Informed
Join our mailing list for the latest news on InfoSec World 2025.