Cybersecurity professionals are facing a moment that feels both urgent and defining. Artificial intelligence (AI) is no longer a far-off concept or experimental technology. It is already changing how organizations defend systems, govern risk, build software, manage talent and prepare for the next wave of threats.
We asked ISC2 Security Congress 2026 presenters for feedback on why it is such a valuable gathering for practitioners, leaders and emerging professionals looking for practical lessons they can use immediately. The speakers provided insight into this year’s sessions and what they believe will be the key conversations focused on AI, governance, leadership and the practical work of securing what comes next. We have compiled the responses with slight modifications for editorial purposes.
Across the speakers’ feedback, one theme surfaced repeatedly: AI will dominate the conversation, but not in a theoretical way. Speakers pointed to AI security, agentic AI, AI governance, autonomous security, AI-native development and the operational realities of integrating AI into security programs as key topics for this year’s Congress. Victor Aldana described AI as both “the cause of so many problems” and “the solution to so many problems,” while Debra Christofferson, CISSP, said that AI trends will affect vendor and tool management, proactive incident response, reskilling, hiring and future employability.
That duality is what makes this year’s event especially timely. Security teams are not just asking whether AI matters. They are asking how to adopt it safely, govern it responsibly and keep humans equipped to make sound decisions. Jerrad Dahlager, CISSP, CCSP, said, “One of the biggest conversations will be whether organizations and their people are truly ready for AI,” noting that security teams are using AI for “threat hunting, incident triage, query building and configuration reviews, while training and governance struggle to keep pace.”
Applicable Lessons Learned
For attendees, that means ISC2 Security Congress offers a chance to move beyond headlines and hear from practitioners who are already wrestling with implementation. Speakers emphasized that the value of Security Congress is not simply learning what is changing, but understanding what is working, where teams are struggling and how security professionals can return to their organizations with practical next steps. Nicole Ruiz, CISSP, said the value of attending Security Congress is in the conversations, shared experiences and practical lessons learned that attendees can take back and apply immediately.
From AI Hype to Practical Governance
Several speakers identified AI governance as one of the most important areas for discussion. “Writing an AI policy is the easy part, while turning that policy into operational reality is where the real work begins,” said Anastasia Kim. “Every security leader should be asking: ‘how do we actually move from policy to implementation safely without grinding business innovation to a halt?’ Like it or not, AI is here.”
Diane Jones, CISSP, CCSP, similarly pointed to “control of AI” as a defining cybersecurity challenge, saying AI adoption is outpacing AI governance and that organizations need architectural controls that govern AI-enabled systems without sacrificing their benefits. Her session takeaway focuses on helping attendees stop asking only whether a model is safe and start asking whether an AI system should be allowed to take a particular action.
That shift from broad concern to concrete decision-making is the kind of perspective attendees can expect at Security Congress. Speakers explained that they are preparing attendees in their sessions for practical conversations about accountability, readiness, governance and oversight. Christine Izuakor, PhD, CISSP, said, “attendees need new skills, frameworks and leadership mindsets to balance innovation and oversight in the age of AI,” while Nicole Ruiz said, “operational readiness reviews should help people make consistent, evidence-based risk decisions and document the rationale behind them.”
Agentic AI, Autonomous Security and the Expanding Attack Surface
Agentic AI emerged as another strong topic according to feedback from Security Congress speakers. Kyle Hinterberg called agentic AI “likely the biggest change to cybersecurity since the invention of the computer,” while Christine Izuakor said, “agentic security will dominate conversations because it is far-reaching, impactful and likely to be adopted by almost every company in some form.”
The concern is not only that organizations will use AI. It is that AI-enabled systems may act with increasing autonomy. Tamra Durfee identified AI security, governance and agentic AI risk as dominant discussion topics at Security Congress because AI is creating security risks, becoming part of the security program, expanding the attack surface, accelerating deepfakes and AI-enabled social engineering, and drawing board and regulatory attention.
Sivakumar Sundaramoorthy is looking forward to comparing notes with other leaders who are tackling the shift from reactive security to continuous, intelligence-driven programs. “Conferences like this are one of the few places where you get real, unfiltered conversations about what is actually working,” Sundaramoorthy said.
For cybersecurity professionals responsible for protecting systems today, these are not abstract future risks. They are operational questions that require peer discussion, informed debate and shared learning. ISC2 Security Congress gives attendees access to the people thinking through these issues from different perspectives, including practitioners focused on governance, cloud security, incident response, software supply chain risk, leadership and workforce readiness.
Practical Takeaways Attendees Can Use Right Away
One of the clearest messages from the speakers is that sessions are being built around takeaways that attendees can apply to their day-to-day jobs. Shawn Biederman, CISSP, has a goal for his session: “I want attendees to leave with a security process assessment that can be applied to any environment.” As for the pre-conference presentation from Alice Ouedraogo, CISSP, participants will leave the session with a checklist of pre-incident improvements covering logging strategy, acquisition toolkit readiness and response workflows designed to reduce investigative friction and compress response time before an incident occurs.
Lewis Heuermann, CISSP, said his pre-conference workshop is designed so that participants leave with a prioritized pillar sequence, an 18-month implementation roadmap and a 90-day quick-wins plan tied to business risk. John Spiegel added that “attendees should come away understanding that zero trust is hard but can be done if the program is led correctly.”
Those examples show the practical breadth of attending ISC2 Security Congress. The conference agenda is not only about identifying risks. It is also about giving professionals concrete tools, frameworks and decision-making models they can adapt to their own organizations; thus, making this conference a must-attend event for all cybersecurity professionals.
Career Growth, Leadership and the Human Side of Cybersecurity
This year’s Security Congress will look beyond technology to address the people who make cybersecurity work possible. AI is changing roles, skills and career paths, and several speakers want attendees to leave feeling prepared to adapt.
“Attendees need to take control of their careers and use AI tools to better understand options and career trajectories that may seem out of reach,” said Victor Aldana.
David Foote encourages his peers to attend Security Congress as a career boost to network with other professionals because career changes and new role opportunities in the industry are moving faster than many workers realize, and that cybersecurity professionals may need to rethink, accelerate and reposition for the future.
Leadership also emerged as a critical theme among presenters. “Leadership in cybersecurity is a multiplier, not a title, and leaders who shape the future will treat trust, culture and talent development with rigor,” said Jenai Marinkovic. According to Tamra Durfee, “there is no single CISO career path and successful leaders intentionally build breadth across business operations, risk management, communication, governance and leadership.”
For attendees, Security Congress offers more than technical content; it creates space for reflection, career planning and leadership development at a time when the profession is changing quickly.
The Value of Being in the Room
Perhaps the strongest reason to attend Security Congress is the value speakers place on being together with others from the cybersecurity community. Victor Aldana commented that it is impossible to explain the value of being in the room with other people doing the same work, understanding shared and different challenges, learning together and working together. Jerrad Dahlager’s feedback is that the conversations in hallways and over coffee with other cybersecurity practitioners are just as valuable as the content learned during presentations.
“Cybersecurity is changing too quickly for anyone to keep up alone,” said Diane Jones. “Congress brings together practitioners with different experiences and perspectives to learn from one another, challenge assumptions and return with ideas they can immediately put into practice.”
Deepam Kanjani described Security Congress as a place where the room is full of people who “have to make the call,” not just advise on it.
That is the power of Security Congress which brings together cybersecurity professionals across disciplines, industries and experience levels to exchange ideas that can immediately strengthen how they approach risk, leadership and defense. Attendees can hear from people solving similar problems in different environments, compare approaches, test assumptions and build connections that continue long after the event ends.
Register Now to Be Part of the Conversation
The challenges facing cybersecurity professionals are moving quickly. AI is changing security operations, governance, software development, risk management and career paths. Emerging technologies are creating new questions about accountability, readiness and resilience. Leaders are being asked to move faster while maintaining control. Practitioners are looking for proven approaches, honest lessons and a community that understands the work.
Speaker feedback makes one thing clear: ISC2 Security Congress is where those conversations will happen. It is a place to learn what is working, discuss what is still uncertain and leave with ideas, frameworks and relationships that can strengthen your work and career.
If you are ready to sharpen your perspective, expand your network and prepare for what comes next in cybersecurity, register for ISC2 Security Congress and be part of the conversation.

