For 15 years, cybersecurity professionals have attended ISC2 Security Congress to learn from industry experts, explore emerging trends and gain practical insights they can take back to their organizations. But as the cybersecurity landscape grows more complex, and more unpredictable, learning needs are evolving.
This year, Security Congress is introducing new, interactive learning formats designed to move beyond traditional presentations and create opportunities for attendees to engage, collaborate and solve problems together. Through immersive discussions, scenario-driven exercises and real-world case studies, participants will have the opportunity to test ideas, strengthen decision-making skills and work through today's most pressing cybersecurity challenges alongside their peers. These new formats include ACTion Rooms, AI Incident Rooms, tabletop exercises and Lessons from the Field sessions.
These sessions will be available for sign-up in advance on the Security Congress mobile app. Registered attendees will be alerted when the app is available to download and use.
Register now for Security Congress to ensure you are the first to sign-up for these new interactive learning sessions with limited availability.
A New Era of Active Learning
Cybersecurity professionals are increasingly being asked to make decisions in situations where the answers are not always clear. Whether responding to a ransomware attack, navigating a data breach or evaluating the implications of AI-driven technologies, security leaders must often act quickly while managing uncertainty.
Recognizing this reality, Security Congress is expanding its educational offerings with learning experiences designed to encourage participation, discussion and practical application. Rather than simply hearing about challenges, attendees will have opportunities to actively explore how they might respond when confronted with them.
These formats reflect a growing recognition that valuable cybersecurity learning doesn't happen only through presentations. It also happens through collaboration, peer discussion and shared problem-solving.
Step Into the AI Incident Room
One of the most innovative additions to Security Congress 2026 is the AI Incident Room, a facilitated, scenario-based learning experience created specifically to examine the growing impact of artificial intelligence on cybersecurity. These 150-minute interactive sessions place participants in the middle of unfolding AI-enabled incidents, challenging them to make decisions as new information emerges and circumstances rapidly evolve.
Unlike technical labs or cyber ranges, the AI Incident Room focuses less on technical execution and more on decision-making, governance, communication and risk management. Participants collaborate with peers to navigate realistic scenarios, evaluate response options and discuss tradeoffs.
Potential scenarios include:
- AI-driven data classification failures
- Third-party AI vendor risk
- Shadow AI adoption across the organization
- AI-driven threat detection failures and corrective actions
Each session follows a structured progression that mirrors real-world incident response:
- Briefing: Participants enter an AI-related incident already in progress and must quickly assess the situation.
- Escalation: New intelligence, complications and organizational challenges emerge.
- Decision Points: Participants evaluate response options, discuss risks and determine the most appropriate course of action.
- Debrief: Facilitators guide reflection and discussion focused on lessons learned and practical takeaways.
Designed for approximately 50 participants per session, the AI Incident Room creates a collaborative environment where cybersecurity professionals can share perspectives, challenge assumptions and learn from one another.
ACTion Rooms: Turning Member Insight Into Action
Building on the collaborative spirit of the AI Incident Room, Security Congress is also introducing ACTion Rooms, facilitated discussions designed to place ISC2 members at the center of conversations shaping the future of the profession.
Rather than listening to a presentation, attendees will be invited to actively participate, share experiences and contribute ideas on issues affecting cybersecurity practitioners today and tomorrow.
Topics include:
- Standards development and professional accountability
- Cybersecurity workforce readiness
- Research that informs industry action
- Ethics and the ISC2 Code of Professional Conduct
- Critical infrastructure resilience
- Future workforce pathways and talent development
ACTion Rooms incorporate interactive elements such as guided discussions, pulse checks, member questions, real-world scenarios, live word clouds and facilitated reflection. These activities are designed to capture the collective expertise of cybersecurity professionals and transform individual perspectives into meaningful dialogue and actionable insights.
The result is a dynamic learning experience where attendees can explore challenges, exchange ideas and contribute directly to conversations influencing the future direction of the profession.
Tabletop Exercises: Practice in Action
Security Congress is also introducing interactive tabletop exercises that combine realistic cybersecurity scenarios with collaborative problem-solving. Available in both 60-minute and 120-minute formats, these sessions allow attendees to practice critical thinking, decision-making and communication in a dynamic learning environment.
Participants may find themselves navigating incident response situations, evaluating security risks or responding to rapidly changing conditions that require thoughtful collaboration and teamwork.
These exercises emphasize practical application and provide a valuable opportunity to test approaches, consider alternative perspectives and strengthen organizational readiness.
Like the AI Incident Rooms, tabletop exercises require advance reservation and are expected to fill quickly.
Lessons from the Field: Real Stories, Real Insights
Not all cybersecurity lessons come from simulations.
Lessons from the Field sessions provide an opportunity for attendees to learn directly from professionals who have faced significant cybersecurity challenges and successfully navigated complex situations. Through candid case studies and firsthand accounts, speakers will share practical experiences, key decisions, lessons learned and outcomes that attendees can apply within their own organizations.
Available to both in-person and virtual attendees, these sessions emphasize real-world experience over theory. Participants will gain insight into how cybersecurity professionals confronted challenges, adapted strategies and strengthened resilience in the face of evolving threats.
For those seeking practical takeaways grounded in actual experience, Lessons from the Field offers a valuable opportunity to learn from peers who have already faced the challenges others may soon encounter.
Why Interactive Learning Matters
The cybersecurity profession is navigating a period of unprecedented change. Artificial intelligence is reshaping technologies, workflows and threat landscapes while introducing new risks, responsibilities and questions for organizations worldwide.
At the same time, cybersecurity professionals increasingly value opportunities to engage with their peers, exchange perspectives and collaboratively explore solutions to emerging challenges.
The new learning formats at Security Congress reflect these evolving needs. Rather than positioning attendees solely as listeners, these experiences place them at the center of the learning process.
Participants are encouraged to discuss, debate and solve problems alongside colleagues from different industries, backgrounds and career stages. In doing so, they gain exposure to diverse viewpoints while strengthening the communication, collaboration and decision-making skills that are essential in today's cybersecurity environment.
New this year, an attendee engagement opportunity partnering with Braindate, allows participants to connect with their peers and put their expertise to work by booking a small group conversation designed around knowledge sharing and practical challenges. These will be reservation-based and more details will be shared with attendees.
Learning That Extends Beyond the Event
Security Congress has always been a place where cybersecurity professionals come together to learn from one another. The introduction of ACTion Rooms, AI Incident Rooms, tabletop exercises and Lessons from the Field sessions expands that tradition by creating opportunities for deeper engagement and more meaningful interaction.
Whether participating in a facilitated discussion, working through a realistic incident scenario or learning from a peer's real-world experience, attendees will leave with practical insights they can apply immediately within their organizations.
As cybersecurity continues to evolve, professional development must evolve with it. These new experiences represent an important step toward creating learning opportunities that are not only educational, but immersive, collaborative and action-oriented.
The future of cybersecurity learning is not just about listening.
It's about participating. Take advantage of thought-leading professional development and spend the week engaged with the global ISC2 and cybersecurity community. ISC2 Members can earn up to 81 CPE credits.
Join Us at ISC2 Security Congress 2026
ISC2 Security Congress isn’t just a conference; it’s where the cybersecurity community comes together to define what’s next.
Join us October 24-25 at the Gaylord Rockies and virtually to be part of the conversations shaping the future of cybersecurity.


