Registered Attendees
Live Sessions
Technical Demos
Interactive Expo Hall
Resource Center
AI & Automation
Leveraging AI and machine learning for continuous asset discovery, threat prediction, and automated remediation.
Proactive Strategies
The role of predictive intelligence and its integration with Continuous Threat Exposure Management (CTEM).
Securing Cloud & IoT
Best practices for securing hybrid and multi-cloud environments and managing the attack surface of IoT/OT devices.
Advanced Testing
Moving beyond traditional penetration testing to AI-assisted and automated red-teaming and integrated bug bounty programs.
SecurityWeek Virtual Events Provide
Attack surface management gives security teams critical visibility into the assets, vulnerabilities, identities, and services that could create exposure. But visibility alone cannot tell you which weaknesses attackers can actually exploit, how they can be chained into attack paths, or whether remediation eliminated the risk.
In this session, we’ll show how to operationalize the Continuous Threat Exposure Management (CTEM) framework through a proven, repeatable loop used at scale to connect discovery, validation, prioritization, remediation, and verification, grounded in evidence of what attackers
can actually do.
Attendees will learn how to:
● Move from attack surface visibility to proven exploitability
● Use attack-path evidence to understand which exposures create meaningful risk
● Verify that remediation actually eliminated exploitable exposure
● Build a continuous loop for measuring whether the organization is becoming harder to compromise
Stephen Gates
Principal Cybersecurity Strategist
Horizon3
As AI models continue to evolve, the window between vulnerability discovery and exploitation has shrunk to just hours. To stay ahead, security teams need to find and remove exposures at AI speed.
Join us for a webinar as we take a deep dive into how Wiz ASM and the Wiz Red Agent, the AI-powered pentester, help teams uncover shadow exposures and remediate exploitable risks at machine speed. Learn how With Wiz ASM helps you discover known exploitable risks such as vulnerabilities and misconfigurations, and the Red Agent uncovers complex, logic-driven vulnerabilities in custom-built applications, to help teams stay ahead of AI threats.
Shaked Rotlevi
Senior Product Marketing Manager
Wiz
We’re now taking a break!
Take this opportunity to visit the Exhibit Hall and explore our sponsors’ resources, solutions, and latest insights. Their subject matter experts are available now and ready to answer your questions and connect with you.
Be sure to stop by before the next session begins!
You can’t secure what you can’t see.
SecurityWeek's Brian Schleifer sits down with Allan Friedman for a deep dive into Software Bills of Materials (SBOM), AI Bills of Materials (AIBOM), software supply chain security, VEX, and the growing challenge of understanding exactly what is inside the technology organizations depend on.
Friedman explains SBOM in practical terms: modern software isn’t simply written—it is assembled from other software, libraries, dependencies, and components. That makes visibility into those components critical when vulnerabilities such as Log4j, supply chain compromises, malicious updates, and other security incidents emerge.
But generating an SBOM is only the beginning.
The conversation explores how organizations can move from simply collecting SBOMs to integrating them into vulnerability management, asset management, procurement, incident response, third-party risk management, and continuous risk monitoring.
Dr. Allan Friedman
Internationally recognized cybersecurity policy expert
Brian "SchleiF" Schleifer
Director of Content, Events
SecurityWeek
In this talk, we break down what your attack surface reallylooks like in today’s environments, and why it’s far larger and more complex than the traditional lists of endpoints, networks, and firewalls. Using real-world incidents, we explore three major blind spots most organizations overlook: vulnerabilities hidden in software supply chains and CI/CD pipelines, the explosive growth of Shadow IT/OT assets that bypass governance, and the emerging risks introduced by AI and agentic systems capable of taking actions based on untrusted inputs. Attendees will gain a practical, modern framework for understanding and reducing their true attack surface, with actionable steps to improve visibility and resilience across both IT and OT environments.
Jon “McFly” McEllroy
CDR USN (Retired), Cyber Adversarial Test Tech Fellow
MTSI
NodeZero is an autonomous security platform that safely attacks your environment to show you what a real attacker can actually exploit. In this demo, we'll break down a real NodeZero attack patch step by step showing how the attack unfolds across an environment, and how each discovery determines what happens next.
See how the Wiz Platform helps organizations protect everything they build and run in the cloud.
Thank you for joining SecurityWeek’s 2026 Attack Surface Management Summit! We hope you found the virtual experience informative, engaging, and valuable. If you missed any sessions, be sure to visit the Auditorium to watch them on demand at your convenience.
A special thank you to our sponsors—Horizon3 and Wiz—for helping make this event possible. Before you go, take a moment to visit their booths, explore their resources, and connect with their subject matter experts.
NodeZero is an autonomous security platform that safely attacks your environment to show you what a real attacker can actually exploit. In this demo, we'll break down a real NodeZero attack patch step by step showing how the attack unfolds across an environment, and how each discovery determines what happens next.
See how the Wiz Platform helps organizations protect everything they build and run in the cloud.