Threat Detection and Incident Response Summit

Threat Detection & Incident Response 2026 Summit

May 20, 2026 – Register

Register for Virtual Events

In an era where “assume breach” is the status quo, organizations must address the maturity of threat detection and incident response programs to mitigate the barrage of incoming malware and ransomware attacks.

SecurityWeek’s Threat Detection and Incident Response (TDIR) Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Diamond Sponsor

Censys

Platinum SponsorsDropzone AI

Snyk Logo

Gold Sponsors

WizDigital Element

 

Sponsorship Information

time iconMay 20, 2026 12:15

From Detection to Decision: Why SAST-DAST Correlation Is the Missing Link in AppSec

Finding vulnerabilities is not the hard part. Knowing which matters and fixing them fast enough is. As AI-generated code enters enterprise codebases at scale and modern applications expose more attack surface through APIs, security teams are accumulating findings faster than they can prioritize them. The real value of combining static and dynamic testing is not coverage for its own sake; it is the runtime context that transforms a static finding from a theoretical risk into a confirmed, actionable one. Without that correlation, teams already overwhelmed by finding volume are spending limited time chasing vulnerabilities that may never translate to real exposure. In this session, Katie Norton, one of the industry's leading analysts covering the application security market, will present IDC market research on how AI-assisted development is reshaping application risk and make the case for an integrated SAST and DAST approach that helps security and development teams cut through the noise and remediate what matters, faster.

speaker headshot

Katie Norton
Research Manager, DevSecOps and Software Supply Chain Security
IDC

time iconMay 20, 2026 11:45

Hunt, Investigate, and Respond at Machine Scale

Learn how to leverage AI agents to work across the full detection and response cycle: from threat intelligence to hunting to investigation to response.

time iconMay 20, 2026 12:45

The Detection Gap: Why AI-Powered Attacks Are Winning Against Legacy Email Security

In 2025 alone, organizations reported over $3 billion in losses due to business email compromise (BEC) to the FBI. Instead of obvious malware or suspicious links, today’s AII-powered attacks exploit human behavior—impersonating executives and vendors, hijacking real conversations, and blending seamlessly into everyday business communications. 

Traditional secure email gateways weren't built to defend against these attacks. They scan for known flagged domains, unusual attachments, malicious payloads, without understanding identity, behavior, or communication context. Without a baseline for what "normal" looks like, they can't distinguish a legitimate email from a convincing impersonation.

This session breaks down why legacy detection is failing and how behavioral AI can close the gap. You'll walk away with:

  • Why your current detection rules are blind to these attacks
  • Why SEGs on their own can’t solve the problem
  • How behavioral baselines enable the protection legacy tools can't deliver
speaker headshot

Jesus Garcia
Solutions Architect
Abnormal AI

time iconMay 20, 2026 13:15

Identity Visibility Meets Automated Defense: Stop Breaches at the Source

Get the blueprint for automated defense. Legacy controls are broken. Attackers are bypassing traditional security controls, exploiting session hijacking and configuration gaps to move laterally and access critical assets. We’re stripping away the theory to give you a practical execution plan for continuous identity assurance. 

speaker headshot

Maziel Martinez
Staff Product Marketing Manager, Identity Management
Okta

speaker headshot

Ariel Zommer
Staff Product Marketing Manager, Security
Okta

time iconMay 20, 2026 14:15

After the Case Closes: Turning Fraud Investigations into Predictive Intelligence

Most fraud programs measure success by cases resolved or losses prevented. But the organizations gaining an advantage today focus on something different: learning systematically from past fraud events. This session explores how IP forensics enables teams to analyze historical infrastructure behavior linked to confirmed fraud activity, revealing patterns that inform future fraud scenarios and risk models. Rather than another detection approach, this talk focuses on operationalizing forensic information— transforming individual fraud events into lasting institutional intelligence.

speaker headshot

Jackie Wadhwa
Head of Product, Cybersecurity & Risk Mitigation
Digital Element

time iconMay 20, 2026 13:45

How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach

Cloud threat intelligence should simplify detection—but often creates noise instead. With vast TI data and automated attacks flooding alerts, many teams struggle to separate real threats from background noise. This session introduces the Zero Noise Approach—a methodology for ingesting and operationalizing Cloud TI through attacker-based baselines, continuous feedback loops, and a “no alert left behind” mindset. Learn how this approach turns TI from overwhelming to actionable, with real-world case studies showing how organizations achieved higher fidelity detections and clearer visibility into attacker TTPs.

speaker headshot

Yotam Meitar
Director of Cloud Response
Wiz

time iconMay 20, 2026 14:45

Breach Response Unfiltered: What Actually Works When the Worst Happens (Panel)

This high-impact panel brings together Joe Sullivan (ex-Uber CSO) and James Beeson, former CISO at Cigna Group, to share firsthand lessons from the front lines of major cyber crises and how incident response is evolving from a technical function to a coordinated, enterprise-wide risk management process.

Moderated by Andy Lunsford, CEO of BreachRx, panelists will dissect responses to the most consequential breaches as lived by executives, investigators, and journalists on the front lines. Through this exploration, the panelists will move beyond theory to examine how real-world incident response unfolds and what it takes to coordinate decisions, actions, and stakeholders under pressure across today’s complex attack landscape.

The conversation will cover how organizations are shifting toward an incident command center model that aligns technical, legal, executive, and communications stakeholders around a single, authoritative view of the incident. Through personal war stories, each expert will offer unfiltered guidance on what worked, what failed, and what must change.

Key session takeaways:

  • Attendees will receive specific recommendations for operationalizing enterprise-wide as a repeatable, governed process.
  • Security practitioners will learn practical frameworks for cross-functional crisis collaboration and strategies to make faster, more consistent, and defensible decisions under pressure.
  • Participants will leave with insights for building an incident response capability that is auditable, defensible, and aligned with enterprise risk.
speaker headshot

Joe Sullivan
Former CSO
Uber & Cloudflare

speaker headshot

James Beeson
Former CISO
Cigna Group

speaker headshot

Anderson Lunsford
CEO and Co-founder
BreachRx

time iconMay 20, 2026 15:30

From Signals to Action: AI-Driven Observability for Modern Threat Detection

Security teams are overwhelmed by data but still under pressure to detect meaningful threats faster. Traditional monitoring approaches often produce high alert volume, fragmented visibility, and slow investigation cycles, especially across cloud-native and distributed environments. The challenge is no longer just collecting more telemetry. It is turning the right signals into timely action.

This session explores how AI-driven observability can improve modern threat detection by helping teams correlate signals across logs, metrics, traces, events, and behavioral patterns to identify suspicious activity earlier and respond with greater precision. Rather than treating observability and security as separate disciplines, the session will show how they can work together to improve detection quality, reduce noise, accelerate triage, and strengthen incident response outcomes in complex enterprise environments.

Attendees will gain a practical view of where AI adds real value in threat detection, including anomaly identification, signal correlation, contextual prioritization, and investigation support. The session will also examine the limits of AI in security operations, the importance of governance and human oversight, and how organizations can adopt AI-driven observability in a way that improves both visibility and actionability without creating additional operational risk.

speaker headshot

Sasi Kiran Malladi
Principal
Amazon

time iconMay 20, 2026 16:00

Prompt Fraud: The Emerging AI Attack Vector Undermining Detection, Audit, and Trust

Generative AI is rapidly transforming enterprise operations, but it is also introducing a new and largely invisible attack surface: prompt fraud. Unlike traditional cyber threats, prompt fraud requires no system breach, malware, or stolen credentials. Instead, attackers manipulate inputs to large language models (LLMs) to generate highly convincing yet falsified outputs that can bypass both security controls and audit scrutiny.

This session reframes prompt fraud as a detection and incident response challenge, not just an audit concern. From fabricated financial narratives to AI-generated approval artifacts and misleading analytical summaries, these attacks operate entirely at the linguistic layer, making them difficult to detect with conventional security tools. As AI-driven deception accelerates and prompt injection ranks among OWASP’s top risks for LLM applications, organizations face a growing blind spot in their threat detection strategies.

Attendees will explore the anatomy of real-world prompt fraud scenarios, the systemic control gaps that enable them, including Shadow AI usage, lack of prompt observability, and insufficient workforce readiness, and why traditional monitoring approaches fail against AI-native threats.

The session introduces a four-pillar defensive framework spanning governance, AI-aware detection engineering, incident response playbooks, and continuous monitoring. It also highlights how advanced techniques such as fine-tuned detection models can dramatically improve identification accuracy, and what security teams must do to operationalize these capabilities.

Finally, the session examines the evolving regulatory landscape, including implications of the EU AI Act, and outlines actionable steps organizations can take today to integrate AI risk into their broader threat detection and incident response strategies.

speaker headshot

Karishma Velisetty
Data Analytics Manager
Spotify

time iconMay 20, 2026 11:00

Building The Modern SOC

As security operations teams modernize with AI and automation, they face a fundamental gap: a lack of real-time visibility into external Internet infrastructure. Without it, both analysts and automated systems are forced to make decisions without the context needed to accurately assess risk, leading to missed threats, wasted investigations, and inconsistent outcomes.

Learn how to close this gap by delivering real-time visibility into global Internet infrastructure, establishing a single, trusted source of Internet intelligence embedded directly within SOC workflows.

SecurityWeek's Threat Detection and Incident Response (TDIR) Summit dives into threat hunting tools and frameworks, and explore the value of threat intelligence data in the defender’s security stack.

This must-attend forum is designed to delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and explore tools and tricks needed in a modern organization.

Expect robust debate on the use of AI/LLMs in incident response tooling, the cost (and curse) of the “log-everything” movement, the value of threat intelligence, and the blending of sophisticated APTs with cybercrime activities.

Key Topics to Be Addressed:

  • The extension of Endpoint Detection and Response (EDR) systems beyond traditional parameters, advancing into the network layers to provide more robust defense mechanisms.
  • Detailed examination of various threat hunting tools and frameworks, including a look at the latest technologies and methodologies being used in modern security programs.
  • The critical role of threat intelligence data and trends around monetization of feeds and government-controlled data release.
  • Best practices in logging and monitoring to spot malware infections and sharing of IOCs (indicators of compromise) artifacts to secure the ecosystem.
time iconMay 21, 2025 11:00

Insights from the 2025 Unit 42 Global Incident Response Report

In a world where cyberattacks are intensifying daily, AI-driven techniques and calculated disruptions from adversaries are redefining how organizations must approach cybersecurity. In 2024, the Unit 42® Incident Response team handled 500+ of the world’s largest cyberattacks — 86% of which directly impacted business operations. Leveraging insights from these incidents, the 2025 “Unit 42 Global Incident Response Report” delivers an in-depth analysis of the evolving threat landscape and attacker's tactics and techniques. In this webinar, explore: -The increasing speed of attacks: Understand how attackers leverage AI and advanced tactics to reach exfiltration within an hour, leaving minimal time to respond. -Evolving attack techniques: Discover how 70% of incidents now span three or more attack surfaces, emphasizing the need for holistic security across endpoints, networks, cloud environments and human factors. -Key emerging threat trends: Explore the rise of disruptive extortion, supply chain vulnerabilities, insider threats and AI-assisted attacks, and how they impact organizations across industries. Gain critical insights, actionable strategies and learn how Unit 42 can help you stay ahead in 2025 and beyond.
speaker headshot

Michael Sikorski
Palo Alto Networks, Chief Technology Officer and VP of Engineering

speaker headshot

Sam Rubin
Palo Alto Networks, VP Global Head of Operations

speaker headshot

David Moulton
Palo Alto Networks, Director, Content Marketing

time iconMay 21, 2025 11:30

A Security Imperative: Identity Threat Visibility and Remediation

In today’s evolving threat landscape, staying ahead of Identity-related risks is critical to maintaining business continuity. Join us for an insightful session where we will share proven strategies to detect, respond to, and mitigate identity threats—with speed and efficiency.

What You’ll Learn:
How to harness the power of Okta and our technology partners to detect and address threats in real-time.
The role of advanced risk analytics, AI-driven tools, and automated response systems in enhancing security.
Actionable steps to secure both users and devices while minimizing disruptions.

This session is tailored for IT and Security professionals looking to strengthen their organization’s defenses. Attendees will learn the importance of implementing integrated solutions, like CrowdStrike, that enable real-time threat remediation and provide deeper visibility into potential Identity risks across the enterprise.

speaker headshot

Johnathan Campos
Okta, Senior Product Marketing Manager

speaker headshot

John Smith
CrowdStrike, Integration Solutions Architect,

time iconMay 21, 2025 12:00

Living Off the Cloud: How to Move Faster Than Attackers with CDR

Living off the cloud attacks are on the rise. Executing rapid, cloud-native techniques to escalate privileges, move laterally between environments, and access critical assets, attackers are targeting the cloud more effectively than ever.

This session will focus on a real-world living off the cloud attack case study, analyzing a step-by-step account of the attack as it unfolded from attackers’ perspective.

We will then switch gears and rewind the attack, explaining how effective detection and response methodologies could — and should — have prevented every step of the attack. Defeating these threats requires powerful centralized visibility and control of all cloud environments and resources. Our key takeaways will therefore be tailored to leveraging the best methodologies and tools to take back the initiative and stop even the most sophisticated cloud attacks.

speaker headshot

Lauren Place
Wiz, Sr. Product Marketing Manager

time iconMay 21, 2025 12:30

A CISO's Guide to Mastering Cyber Incident Response: Are Your Vendors Your Weakest Link?

With 98% of organizations experiencing vendor breaches, preparedness is critical. This webinar equips CISOs and security leaders with strategies to effectively manage third-party cyber incidents. Learn how to leverage a robust playbook to move from reactive scrambling to proactive resilience. Attend to learn how to: - Stop Scrambling: Implement rapid response frameworks. - Communicate Clearly: Develop winning crisis communication plans. - Become Proactive: Discover preventative best practices. - Ask the Right Questions: Vet vendor cybersecurity effectively. - Learn from the Pros: Gain insights from real-world scenarios. Don't let vendors be your vulnerability. Join us to streamline response, communicate effectively, and build a stronger digital ecosystem against escalating third-party threats.
speaker headshot

Steve Cobb
SecurityScorecard, CISO

time iconMay 21, 2025 13:00

Fighting Deepfakes: Transformative Approaches to Protect Your Business

Deepfake-related incidents worldwide increased over 245% in 2024, with some regions seeing alarming growth rates of over 3,000%. When it comes to identity crime, organizations are playing a brand new game with high stakes and uncertain rules. Accepting that human eyes and ears are simply not equipped to accurately discern what is and isn’t real in the digital sphere, is your organization prepared for these threats? Join us for this insightful session as we dive deep into the world of deepfakes; discuss common attack vectors across workforce, customer, and B2B identity use cases; demonstrate effective defense strategies; and recommend best practices to stay ahead of attackers and ensure your organization is protected in an increasingly AI-driven world. Key Takeaways:
--The state of deepfake identity threats and the associated business impacts
--Common attack vectors and points of weakness
--Sample scenarios across industries and use cases
--Existing and new approaches to mitigate deepfake-related fraud
--What’s on the horizon as this threat vector continues to evolve
speaker headshot

Darrell Geusz
Ping Identity, Product Lead, Neo

speaker headshot

Maya Ogranovitch Scott,
Ping Identity, Senior Solution Manager, Fraud

time iconMay 21, 2025 13:30

Leveraging ISP and ASN as New Indicators of Compromise (IOC) in Cyber Threat Intelligence

Traditional threat intelligence often relies on identifying malicious IPs individually, which can be reactive and slow. This session explores different KQL Queries to show how ISPs / ASNs can serve as powerful new IOCs, enabling security teams to proactively monitor entire IP ranges associated with suspicious activity. By tagging and tracking suspicious ISPs, organizations can accelerate threat detection and mitigation, reducing reliance on waiting for specific IP-based alerts. This proposal will help to discover how this approach enhances visibility, speeds up response times, and strengthens cyber defense strategies.
speaker headshot

Sergio Albea
Cloud Security Expert/Architect addicted to Threat Hunting

time iconMay 21, 2025 14:00

Agentic AI: The Next Frontier of Adversarial Threats and Incident Response

Agentic AI-AI systems capable of autonomous decision-making-are rapidly being integrated into enterprise workflows. This session explores how agentic AI blurs the lines between traditional cyberattacks and adversarial AI, introduces new attack vectors (such as phishing via agentic systems and local model tampering), and necessitates a new breed of incident response playbooks. Attendees will learn how to proactively test agentic AI for vulnerabilities, develop tailored incident response strategies, and foster resilience against evolving threats.

speaker headshot

Sanjoy Ghosh
Head of Digital Business & Engineering, BFSI, Apexon

In this keynote at SecurityWeek's 2021 Threat Intelligence Summit, John Lambert, GM of the Microsoft Threat Intelligence Center, discusses how it’s more important than ever for defenders and organizations to come together and better share information that can help the entire ecosystem protect against emerging threats. Lambert shares specific examples of how community resources such as GitHub, MITRE’s ATT&CK Framework, Sigma rules, CodeQL queries and Jupyter notebooks have all been used in recent months to “open-source” security to better defend against sophisticated threats such as NOBELIUM and others.

Register Now

Event Details