Key Topics

AI & Automation

Leveraging AI and machine learning for continuous asset discovery, threat prediction, and automated remediation.

Proactive Strategies

The role of predictive intelligence and its integration with Continuous Threat Exposure Management (CTEM).

Securing Cloud & IoT

Best practices for securing hybrid and multi-cloud environments and managing the attack surface of IoT/OT devices.

Advanced Testing

Moving beyond traditional penetration testing to AI-assisted and automated red-teaming and integrated bug bounty programs.

Sponsored by

SecurityWeek Virtual Event Sponsorships

I want to become a sponsor

SecurityWeek Virtual Events Provide

  • BRAND AWARENESS: Introduce your brand to a large audience and deepen connections with existing customers and prospects through powerful brand integration by being part of a high-profile event that is heavily marketed for months.
  • THOUGHT LEADERSHIP: Demonstrate expertise and build trust by presenting to a targeted, information-hungry audience of cybersecurity professionals.
  • LEAD GENERATION: The scale of SecurityWeek’s virtual events serve as a cost effective lead generation platform to fuel your sales teams.

Agenda

09/16/2026 11:00

Beyond Attack Surface Visibility: Proving What Attackers Can Actually Exploit

Attack surface management gives security teams critical visibility into the assets, vulnerabilities, identities, and services that could create exposure. But visibility alone cannot tell you which weaknesses attackers can actually exploit, how they can be chained into attack paths, or whether remediation eliminated the risk. 

In this session, we’ll show how to operationalize the Continuous Threat Exposure Management (CTEM) framework through a proven, repeatable loop used at scale to connect discovery, validation, prioritization,  remediation, and verification, grounded in evidence of what attackers

can actually do.


Attendees will learn how to:

● Move from attack surface visibility to proven exploitability

● Use attack-path evidence to understand which exposures create meaningful risk

● Verify that remediation actually eliminated exploitable exposure

● Build a continuous loop for measuring whether the organization is becoming harder to compromise

speaker headshot

Stephen Gates
Principal Cybersecurity Strategist Horizon3

09/16/2026 11:30

Modernize Your Attack Surface Management: Machine-Speed Defense with the Wiz Red Agent

As AI models continue to evolve, the window between vulnerability discovery and exploitation has shrunk to just hours. To stay ahead, security teams need to find and remove exposures at AI speed.

Join us for a webinar as we take a deep dive into how Wiz ASM and the Wiz Red Agent, the AI-powered pentester, help teams uncover shadow exposures and remediate exploitable risks at machine speed. Learn how With Wiz ASM helps you discover known exploitable risks such as vulnerabilities and misconfigurations, and the Red Agent uncovers complex, logic-driven vulnerabilities in custom-built applications, to help teams stay ahead of AI threats.

speaker headshot

Shaked Rotlevi
Senior Product Marketing Manager Wiz

09/16/2026 11:55

BREAK

We’re now taking a break!

Take this opportunity to visit the Exhibit Hall and explore our sponsors’ resources, solutions, and latest insights. Their subject matter experts are available now and ready to answer your questions and connect with you.

Be sure to stop by before the next session begins!

09/16/2026 12:15

You Can’t Secure What You Can’t See: SBOM, AIBOM & Software Supply Chain Risk

You can’t secure what you can’t see.


Brian Schleifer sits down with Allan Friedman for a deep dive into Software Bills of Materials (SBOM), AI Bills of Materials (AIBOM), software supply chain security, VEX, and the growing challenge of understanding exactly what is inside the technology organizations depend on.


Friedman explains SBOM in practical terms: modern software isn’t simply written—it is assembled from other software, libraries, dependencies, and components. That makes visibility into those components critical when vulnerabilities such as Log4j, supply chain compromises, malicious updates, and other security incidents emerge.


But generating an SBOM is only the beginning.


The conversation explores how organizations can move from simply collecting SBOMs to integrating them into vulnerability management, asset management, procurement, incident response, third-party risk management, and continuous risk monitoring.


The discussion then turns to artificial intelligence and AIBOM. AI systems introduce additional layers beyond traditional software, including models, training and supporting data, external data sources, RAG architectures, agentic systems, runtime dependencies, and increasingly dynamic components. As AI systems become more autonomous, determining what needs to be captured—and how continuously it must be monitored—is becoming a major cybersecurity challenge.


Brian and Allan also discuss VEX (Vulnerability Exploitability eXchange), why the presence of a vulnerable component does not automatically mean a system is exploitable, and how machine-readable vulnerability information can help security teams prioritize actual risk.


Finally, Allan looks toward the future of software transparency, including cryptographic bills of materials, hardware bills of materials, AI bills of materials, updated international SBOM guidance, and the possibility that these different transparency artifacts eventually converge into what he calls an “OmniBOM.”


In this session:


• What an SBOM actually is—and what it is not

• Why software transparency matters to defenders

• How SBOM can improve vulnerability and incident response

• Why organizations should integrate SBOM data into existing security tooling

• The relationship between SBOM and third-party risk management

• Why vulnerable components are not always exploitable

• How VEX helps organizations determine what vulnerabilities actually matter

• What an AIBOM needs to capture beyond traditional software

• Models, data, RAG, agents, runtime dependencies, and AI transparency

• Why dynamic and agentic AI systems complicate traditional BOM approaches

• Continuous monitoring and continuous risk management

• CISA and international SBOM guidance

• Cryptographic Bills of Materials and post-quantum readiness

• Hardware Bills of Materials

• The future of the “OmniBOM”

• Why defenders need greater visibility into the systems they are responsible for securing


Allan Friedman has spent years helping shape the evolution and adoption of SBOM across government, industry, open source, and the broader cybersecurity community. In this conversation, he explains not only where SBOM came from, but where software transparency is heading as AI fundamentally changes how applications are built and operated.


If you work in cybersecurity, application security, software development, vulnerability management, third-party risk, AI security, software supply chain security, critical infrastructure, or technology policy, this is a conversation worth watching.

speaker headshot

Dr. Allan Friedman
Internationally recognized cybersecurity policy expert

speaker headshot

Brian "SchleiF" Schleifer
Director of Content, Events SecurityWeek

09/16/2026 14:05

Networking & Virtual Expo

Thank you for joining SecurityWeek’s 2026 Attack Surface Management Summit! We hope you found the virtual experience informative, engaging, and valuable. If you missed any sessions, be sure to visit the Auditorium to watch them on demand at your convenience.


A special thank you to our sponsors—Horizon3 and Wiz—for helping make this event possible. Before you go, take a moment to visit their booths, explore their resources, and connect with their subject matter experts.

Register Now

FAQ


Yes, you’ll need to fill out our registration form to gain access to the event. Please fill in the registration form with some basic information to get started.
The information you provide upon registration will be used to establish you as a user on the platform.

SecurityWeek is committed to protecting and respecting your privacy. From time to time, we would like to contact you about our products and services, as well as other content and information from event sponsors that may be of interest to you. You may unsubscribe from these communications at any time.

By registering for this event, you consent to allow SecurityWeek to store and process the personal information submitted to provide you the content requested.
Yes, the vFairs platform is compatible with any computer or mobile device and any browser.
Yes, this event is completely free to attend. We encourage you to login and have a look around at your convenience.
Yes, the event will be available on-demand following the live broadcast.