Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Attack Surface Management Summit 2026

Type Conference
Organization SecurityWeek
Event Format Online
Size 101 - 300 approximate delegates
Registration Free
SPEAKING OPPORTUNITIES

Search for other Cybersecurity Conferences in the United States or discover other Cyber Events in Massachusetts in 2026-2027.

Conference Description

Key Takeaways

  • Virtual summit focused on Attack Surface Management strategies for enterprise security teams
  • Coverage spans vulnerability scoring frameworks, AI security risks, API misconfigurations and multi-cloud compliance
  • Designed for CISOs, security architects, DevSecOps professionals and risk officers in regulated industries
  • Sessions address practical challenges including incomplete asset inventories and generative AI deployment risks
  • Features technical demonstrations and case studies from organisations including Capital One

Introduction

The Attack Surface Management Summit 2026 is a virtual event bringing together cybersecurity practitioners to examine how organisations can systematically discover, classify and monitor their expanding digital footprints. Aimed at enterprise security professionals working across finance, healthcare, energy and technology sectors, the summit addresses a discipline that has grown increasingly critical as cloud adoption, API proliferation and AI integration create new vectors for exploitation. With traditional vulnerability management approaches struggling to keep pace with dynamic infrastructure, the event explores emerging frameworks that combine continuous asset discovery with pragmatic risk prioritisation.

About This Event

The summit operates as a fully virtual programme featuring expert-led sessions, technical deep-dives and interactive demonstrations. Content is structured to serve both technical practitioners and executive-level attendees, with on-demand access complementing live presentations. A virtual expo provides opportunities for attendees to explore vendor solutions and engage with sponsors including runZero, which serves as the presenting sponsor, and Cobalt, a Gold sponsor specialising in offensive security platforms.

From Asset Discovery to Continuous Exposure Management

Attack Surface Management has evolved beyond periodic vulnerability scanning into a continuous discipline encompassing asset discovery, inventory maintenance, classification and ongoing monitoring. The summit examines how organisations can move from reactive patching cycles toward proactive exposure management that accounts for the full scope of internet-facing assets, cloud services and shadow IT.

Sessions explore the practical limitations of relying solely on traditional vulnerability scoring systems such as CVSS, introducing complementary frameworks including EPSS (Exploit Prediction Scoring System) and SSVC (Stakeholder-Specific Vulnerability Categorisation). These approaches aim to help security teams prioritise remediation efforts based on actual exploitability and business context rather than theoretical severity alone.

Securing AI Systems and Data Pipelines

As generative AI becomes embedded in enterprise operations, the attack surface extends into model infrastructure, training data and inference endpoints. The summit dedicates significant attention to AI-specific security concerns including prompt injection attacks, adversarial inputs designed to manipulate model behaviour, and model poisoning through compromised training data.

Particular focus falls on securing AI data pipelines within regulated industries where compliance requirements intersect with emerging technology risks. Organisations deploying AI workloads on platforms such as Databricks and Snowflake face the challenge of maintaining data governance while enabling the rapid experimentation that machine learning development demands. Sessions examine how security teams can establish appropriate controls without creating bottlenecks that undermine AI initiatives.

Cloud Complexity and API Security Challenges

Multi-cloud environments spanning Microsoft Azure, AWS and GCP introduce configuration complexity that frequently results in security gaps. The summit addresses how organisations can maintain visibility across heterogeneous infrastructure while meeting compliance obligations that vary by jurisdiction and industry. API misconfigurations represent a recurring theme, with sessions examining how exposed or poorly secured interfaces have contributed to significant breaches.

The relationship between cloud-native architectures and attack surface expansion receives detailed treatment. Kubernetes deployments, serverless functions and microservices architectures each introduce distinct security considerations that traditional perimeter-focused approaches fail to address adequately.

Practical Frameworks and Real-World Lessons

The programme emphasises actionable insights over theoretical discussion, featuring case studies that illustrate how organisations have implemented exposure management programmes at scale. A Capital One case study offers perspective on managing attack surface challenges within a heavily regulated financial services environment.

Technical demonstrations showcase hybrid approaches that combine commercial tooling with open-source innovation, reflecting a pragmatic recognition that effective security programmes rarely depend on single-vendor solutions. Offensive security perspectives inform several sessions, with pentesting methodologies providing insight into how attackers identify and exploit gaps in organisational defences.

Who Should Attend

The summit is designed for security professionals responsible for protecting complex enterprise environments. CISOs and security architects will find strategic content addressing programme development and risk communication, while security engineers and vulnerability managers can expect technical depth on tooling and methodology. DevSecOps practitioners, risk officers and compliance professionals working in regulated sectors including finance, healthcare and energy represent core audience segments. The content assumes familiarity with enterprise security concepts and is best suited to mid-level and senior professionals.