Registered Attendees
Live Sessions
Technical Demos
Interactive Expo Hall
Resource Center
AI & Automation
Leveraging AI and machine learning for continuous asset discovery, threat prediction, and automated remediation.
Proactive Strategies
The role of predictive intelligence and its integration with Continuous Threat Exposure Management (CTEM).
Securing Cloud & IoT
Best practices for securing hybrid and multi-cloud environments and managing the attack surface of IoT/OT devices.
Advanced Testing
Moving beyond traditional penetration testing to AI-assisted and automated red-teaming and integrated bug bounty programs.
SecurityWeek Virtual Events Provide
Attack surface management gives security teams critical visibility into the assets, vulnerabilities, identities, and services that could create exposure. But visibility alone cannot tell you which weaknesses attackers can actually exploit, how they can be chained into attack paths, or whether remediation eliminated the risk.
In this session, we’ll show how to operationalize the Continuous Threat Exposure Management (CTEM) framework through a proven, repeatable loop used at scale to connect discovery, validation, prioritization, remediation, and verification, grounded in evidence of what attackers
can actually do.
Attendees will learn how to:
● Move from attack surface visibility to proven exploitability
● Use attack-path evidence to understand which exposures create meaningful risk
● Verify that remediation actually eliminated exploitable exposure
● Build a continuous loop for measuring whether the organization is becoming harder to compromise
Stephen Gates
Principal Cybersecurity Strategist
Horizon3
As AI models continue to evolve, the window between vulnerability discovery and exploitation has shrunk to just hours. To stay ahead, security teams need to find and remove exposures at AI speed.
Join us for a webinar as we take a deep dive into how Wiz ASM and the Wiz Red Agent, the AI-powered pentester, help teams uncover shadow exposures and remediate exploitable risks at machine speed. Learn how With Wiz ASM helps you discover known exploitable risks such as vulnerabilities and misconfigurations, and the Red Agent uncovers complex, logic-driven vulnerabilities in custom-built applications, to help teams stay ahead of AI threats.
Shaked Rotlevi
Senior Product Marketing Manager
Wiz
We’re now taking a break!
Take this opportunity to visit the Exhibit Hall and explore our sponsors’ resources, solutions, and latest insights. Their subject matter experts are available now and ready to answer your questions and connect with you.
Be sure to stop by before the next session begins!
You can’t secure what you can’t see.
Brian Schleifer sits down with Allan Friedman for a deep dive into Software Bills of Materials (SBOM), AI Bills of Materials (AIBOM), software supply chain security, VEX, and the growing challenge of understanding exactly what is inside the technology organizations depend on.
Friedman explains SBOM in practical terms: modern software isn’t simply written—it is assembled from other software, libraries, dependencies, and components. That makes visibility into those components critical when vulnerabilities such as Log4j, supply chain compromises, malicious updates, and other security incidents emerge.
But generating an SBOM is only the beginning.
The conversation explores how organizations can move from simply collecting SBOMs to integrating them into vulnerability management, asset management, procurement, incident response, third-party risk management, and continuous risk monitoring.
The discussion then turns to artificial intelligence and AIBOM. AI systems introduce additional layers beyond traditional software, including models, training and supporting data, external data sources, RAG architectures, agentic systems, runtime dependencies, and increasingly dynamic components. As AI systems become more autonomous, determining what needs to be captured—and how continuously it must be monitored—is becoming a major cybersecurity challenge.
Brian and Allan also discuss VEX (Vulnerability Exploitability eXchange), why the presence of a vulnerable component does not automatically mean a system is exploitable, and how machine-readable vulnerability information can help security teams prioritize actual risk.
Finally, Allan looks toward the future of software transparency, including cryptographic bills of materials, hardware bills of materials, AI bills of materials, updated international SBOM guidance, and the possibility that these different transparency artifacts eventually converge into what he calls an “OmniBOM.”
In this session:
• What an SBOM actually is—and what it is not
• Why software transparency matters to defenders
• How SBOM can improve vulnerability and incident response
• Why organizations should integrate SBOM data into existing security tooling
• The relationship between SBOM and third-party risk management
• Why vulnerable components are not always exploitable
• How VEX helps organizations determine what vulnerabilities actually matter
• What an AIBOM needs to capture beyond traditional software
• Models, data, RAG, agents, runtime dependencies, and AI transparency
• Why dynamic and agentic AI systems complicate traditional BOM approaches
• Continuous monitoring and continuous risk management
• CISA and international SBOM guidance
• Cryptographic Bills of Materials and post-quantum readiness
• Hardware Bills of Materials
• The future of the “OmniBOM”
• Why defenders need greater visibility into the systems they are responsible for securing
Allan Friedman has spent years helping shape the evolution and adoption of SBOM across government, industry, open source, and the broader cybersecurity community. In this conversation, he explains not only where SBOM came from, but where software transparency is heading as AI fundamentally changes how applications are built and operated.
If you work in cybersecurity, application security, software development, vulnerability management, third-party risk, AI security, software supply chain security, critical infrastructure, or technology policy, this is a conversation worth watching.
Dr. Allan Friedman
Internationally recognized cybersecurity policy expert
Brian "SchleiF" Schleifer
Director of Content, Events
SecurityWeek
Thank you for joining SecurityWeek’s 2026 Attack Surface Management Summit! We hope you found the virtual experience informative, engaging, and valuable. If you missed any sessions, be sure to visit the Auditorium to watch them on demand at your convenience.
A special thank you to our sponsors—Horizon3 and Wiz—for helping make this event possible. Before you go, take a moment to visit their booths, explore their resources, and connect with their subject matter experts.