Most breaches still start with abused credentials and over-permissioned access - yet many organizations are stuck with manual, siloed identity processes. In this session, you’ll learn how to use the Horizons maturity model to quickly baseline where your identity program is today, identify the “next horizon” capabilities that matter most. Designed for RMCS’s Technical audience (but approachable for security leaders), we’ll walk through real-world patterns like: cleaning up birthright access, tightening joiner/mover/leaver workflows, making access reviews less painful (and more meaningful), and extending governance beyond humans to machine identities and AI-era access. We’ll close with a lightweight checklist you can take back to your environment and use immediately.
Principal Solution Consultant at SailPoint. With 20+ years of experience in Identity and Access Management, Cullen specializes in Identity Security and has extensive experience in implementing as well as positioning Identity Security solutions. Prior to joining SailPoint Cullen worked... Read More →
Wednesday June 17, 2026 9:30am - 10:10am MDT GW 225
Drawing from real-world cases, this session explores how digital forensic methodologies have become a critical investigative tool beyond traditional silos, supporting investigations across multiple enterprise functions such as law enforcement, human resources (HR), internal audit, and legal counsel. Bill Hunkapillar and Clifford Stokes Florida State University
Wednesday June 17, 2026 10:12am - 11:00am MDT GW 225
Most successful social engineering is not the mass-sent phishing emails you get in your inbox, where the hacker hopes to trick the victim into clicking on a link. The most successful phishing attacks involve more sophisticated attacks designed to gain your trust and are able to fool even the most careful individuals. They may even target your personal email account, hobbies, and family members. They may even feign a romantic interest. Even though these more sophisticated attacks make up less than 0.5% of all email attacks, they make up 66% of all successful attacks. One attack method is responsible for two-thirds of all successful attacks! Are you or your users prepared to confront such calculated attacks? Join us for this presentation where Roger A. Grimes, CISO Advisor at KnowBe4, walks you through the ins and outs of long-game social engineering advanced techniques.
Wednesday June 17, 2026 12:00pm - 1:00pm MDT GW 225
Last year, we had over 48,000 publicly announced vulnerabilities. That’s over 132 a day, day after-day, and each year the number of vulnerabilities just keeps going up. AI is going to cause the number of vulnerabilities found and exploited to soar, for more reasons than just Mythos! AI will find more vulnerabilities. AI will cause more vulnerabilities. Your time to patch will be minutes…and that’s even if a patch is available. Attend this session to learn: • How AI will impact vulnerabilities • The reality of hackbots • How you will need to update your patch management strategy
Wednesday June 17, 2026 1:30pm - 2:20pm MDT GW 225
Every day, millions of data points about YOU, regardless of your intent or awareness and whether public, leaked, scraped, or sold, are quietly feeding into an ecosystem (largely legal) of personal information. Threat actors, now often trivially, use AI tools to weaponize that personal information at scale against both individuals and their organizations. What once required a non-trivial skillset in OSINT and social engineering can now be executed by anyone with a prompt and a profile or scraped data set – or worse, a team of AI agents.
Wednesday June 17, 2026 2:30pm - 3:20pm MDT GW 225