Security &
Risk Forum

November 9–10, 2026 · Washington DC

Agenda

Session type
Select
Session topics
Select

There are no results for this filter set. Try refining to see more options.

Monday

Nov 9
  • 1:15 pm – 2:30 pm EST AI Security Certification
  • 1:30 pm – 2:30 pm EST Workshops: Reskilling Cybersecurity Teams For The Agentic Era
  • 1:30 pm – 2:30 pm EST Deep Dives
  • 2:40 pm – 3:10 pm EST Case Study Sessions
  • 3:10 pm – 3:40 pm EST Forrester Women's Leadership Program: Networking Experience
  • 3:10 pm – 3:40 pm EST Coffee & Networking Break
  • 3:40 pm – 4:40 pm EST Deep Dives
  • 3:40 pm – 4:40 pm EST Workshops: Implementing AEGIS
  • 3:40 pm – 4:40 pm EST Workshop: Kick Off Your Quantum Security Migration Journey
  • 4:50 pm – 5:05 pm EST Welcome Remarks
  • 5:05 pm – 5:25 pm EST Keynote: Trusted Autonomy Starts With Securing Intent
  • 5:25 pm – 5:35 pm EST Host Remarks
  • 5:35 pm – 7:00 pm EST Welcome Reception

Tuesday

Nov 10
  • 8:30 am – 9:30 am EST General Breakfast
  • 9:30 am – 9:40 am EST Welcome Remarks
  • 9:40 am – 10:00 am EST Keynote: Identity Context Is King
  • 10:05 am – 10:25 am EST Guest Keynote: More Information To Come
  • 10:25 am – 10:30 am EST Host Remarks
  • 10:30 am – 11:00 am EST Coffee & Networking Break
  • 11:00 am – 11:30 am EST Breakout Sessions
  • 11:40 am – 12:10 pm EST Case Study Sessions
  • 12:10 pm – 12:40 pm EST Breakout Sessions
  • 12:10 pm – 1:10 pm EST Workshop: AEGIS Powers Trusted AI At Scale
  • 12:40 pm – 1:40 pm EST Networking Lunch
  • 1:40 pm – 1:45 pm EST Welcome Back
  • 1:45 pm – 2:05 pm EST Guest Keynote: More Information To Come
  • 2:10 pm – 2:30 pm EST Keynote: Forge The Trusted Future
  • 2:30 pm – 2:35 pm EST Host Remarks
  • 2:45 pm – 3:15 pm EST Breakout Sessions
  • 2:50 pm – 3:50 pm EST Workshop: Zero Trust For Public Sector
  • 3:15 pm – 4:00 pm EST Coffee Break & Networking
  • 4:00 pm – 4:30 pm EST Breakout Sessions
  • 4:40 pm – 4:45 pm EST Welcome Back
  • 4:45 pm – 5:05 pm EST Guest Keynote: More Information To Come
  • 5:05 pm – 5:25 pm EST Keynote: Advancing Data Controls To Secure Agentic AI
  • 5:25 pm – 5:30 pm EST Closing Remarks
  • 5:30 pm – 6:40 pm EST Reception

Monday Nov 9

1:15 pm – 2:30 pm EST

AI Security Certification

Session details coming soon.

Speakers:
Allie Mellen, Principal Analyst, Forrester

1:30 pm – 2:30 pm EST

Workshops: Reskilling Cybersecurity Teams For The Agentic Era

Generative and agentic AI are reshaping cybersecurity work and the skills that security teams need to remain effective. This workshop will help CISOs rethink upskilling, career paths, and role design so practitioners can supervise AI-assisted decisions, preserve human judgment, and build trust in security outcomes. Join this workshop to: 

  • Define the cybersecurity skills that matter most in an AI-augmented operating model. 
  • Redesign career paths as AI changes how practitioners build judgment and experience. 
  • Build a reskilling strategy that supports trust, accountability, and resilience. 

Speakers:
Jess Burn, Principal Analyst, Forrester

1:30 pm – 2:30 pm EST

Deep Dives

AI Fundamentals
Minimum Viable Zero Trust

Organizations beginning or advancing Zero Trust initiatives often struggle due to limited budgets, organizational misalignment, and uncertainty about where or how to begin. Achieving Zero Trust does not necessarily require a massive technology investment or organizational overhaul. You can make meaningful progress by adopting a pragmatic, high-impact approach focused on risk reduction while building a foundation for longer-term maturity. This session will explore implementing minimum viable Zero Trust to deliver measurable security improvement through existing investments, operational changes, and governance. 

Attendees will learn how to:  

  • Use existing infrastructure as the foundation for a modern Zero Trust architecture. 
  • Conduct a gap analysis to prioritize low-cost, high-impact investments and activities to improve Zero Trust capabilities. 
  • Build realistic roadmaps to continuously improve Zero Trust maturity. 

Speakers:
James Plouffe, Principal Analyst, Forrester
Carlos Rivera, Senior Analyst, Forrester

2:40 pm – 3:10 pm EST

Case Study Sessions

3:10 pm – 3:40 pm EST

Forrester Women's Leadership Program: Networking Experience

Session details coming soon.

3:10 pm – 3:40 pm EST

Coffee & Networking Break

Enjoy refreshments and snacks while networking with peers in the Partner Lounge.

3:40 pm – 4:40 pm EST

Deep Dives

AI Fundamentals
Command The Next Act With AI-Led Vulnerability Discovery And Remediation

AI-led vulnerability discovery and exploit generation are rapidly reshaping cybersecurity. Capabilities once limited to elite researchers or nation-state actors are now being scaled for both defenders and adversaries, compressing the gap between discovery and weaponization. The implications extend beyond security operations, driving new questions around accountability, governance, and risk. Attendees will learn: 

  • How organizations are adapting to this shift, where AI is outpacing traditional processes, and which new risks and bottlenecks are emerging. 
  • How to identify AI-driven advantages and address asymmetric risks. 
  • How to align roles, metrics, and investments to operate at machine speed. 

Speakers:
Erik Nost, Senior Analyst, Forrester
Janet Worthington, Senior Analyst, Forrester

3:40 pm – 4:40 pm EST

Workshops: Implementing AEGIS

Agentic AI creates new opportunities and new exposures. Forrester’s AEGIS framework is intended to help organizations safely adopt agentic AI using three core principles and six different domains. This workshop will provide a deeper dive into AEGIS, helping practitioners better understand the framework as well as align it with their existing initiatives, processes, and architectures. 

Attend this workshop to: 

  • Understand the three core principles of AEGIS and how they relate to other cybersecurity principles. 
  • Learn about key activities and outcomes related to each of the six AEGIS domains and how to incorporate them into existing processes and architectures. 
  • Learn how the application of AEGIS enables compliance across multiple regulatory regimes. 

Speakers:
James Plouffe, Principal Analyst, Forrester

3:40 pm – 4:40 pm EST

Workshop: Kick Off Your Quantum Security Migration Journey

Quantum security migration will be one of the most significant security transformations your organization undertakes over the next few years, but the constantly changing timelines and evolving regulatory mandates make it difficult to take a breath and determine where to start. This workshop provides a practical framework for building a quantum security migration team, identifying critical dependencies, and managing risk across complex environments. Through guided exercises and discussion, attendees will leave with actionable steps for turning quantum security awareness into a coordinated plan. 

Join this workshop to: 

  • Identity your Q-day team. 
  • Prioritize assets and systems for quantum security migration. 
  • Surface third-party risks and develop key questions for your vendors and partners. 

Speakers:
Sandy Carielli, VP, Principal Analyst, Forrester

4:50 pm – 5:05 pm EST

Welcome Remarks

Forrester CEO, George Colony will kick off the Forum with words of welcome and questions to keep in mind to help you get the most out of your Security & Risk Forum experience.

Speakers:
George Colony, CEO, Forrester

5:05 pm – 5:25 pm EST

Keynote: Trusted Autonomy Starts With Securing Intent

AI compresses decision cycles until controls built for human-paced systems cant keep up, but autonomous systems wont break security by ignoring instructions — theyll break it by following instructions too literally, pursuing the wrong goal too efficiently, or turning helpful behavior into ungoverned power. CISOs now need to govern intent, not just access, data, prompts, or outcomes. This keynote introduces Forresters research on securing intent and gives security leaders a new model for classifying agent behavior, proving trust, and controlling autonomy before technically compliant systems create strategically unacceptable risk.

Speakers:
Jeff Pollard, VP, Principal Analyst, Forrester

5:25 pm – 5:35 pm EST

Host Remarks

What’s Ahead: Making the Most Of Your Forum Experience

Following the opening keynote, our host, VP, Research Director Merritt Maxim, will highlight the key themes shaping the event and provide a roadmap to sessions, discussions, and networking opportunities. Learn how to navigate the agenda, connect with peers, and get the most value from your Forum experience.

Speakers:
Merritt Maxim, VP, Research Director, Forrester

5:35 pm – 7:00 pm EST

Welcome Reception

Join us for an opening night reception full of networking, fun, food and refreshments.

Tuesday Nov 10

8:30 am – 9:30 am EST

General Breakfast

9:30 am – 9:40 am EST

Welcome Remarks

Speakers:
Merritt Maxim, VP, Research Director, Forrester

9:40 am – 10:00 am EST

Keynote: Identity Context Is King

As agents begin taking autonomous actions, securing agentic identity becomes the foundation for ensuring that every action is trusted, governed, and secure. Access decisions must be driven by rich identity context that combines intent, risk, guardrails, operational realities, and regulatory expectations to guide agent behavior in real time. This keynote explains how to use dynamic identity context to deploy and secure agentic AI architectures at scale. 

Speakers:
Andras Cser, VP, Principal Analyst, Forrester

10:05 am – 10:25 am EST

Guest Keynote: More Information To Come

10:25 am – 10:30 am EST

Host Remarks

Forrester VP, Research Director Merritt Maxim kicks off the morning with words of welcome and what to keep in mind to help you get the most out of your S&R Forum experience.

Speakers:
Merritt Maxim, VP, Research Director, Forrester

10:30 am – 11:00 am EST

Coffee & Networking Break

Enjoy refreshments and snacks while networking with peers in the Partner Lounge.

11:00 am – 11:30 am EST

Breakout Sessions

Leading The Trust And Assurance Organization
The Rise Of The Trust And Assurance Organization

Generative and agentic AI are rewriting the CISO mandate from protector of systems to provider of trust and assurance. This shift demands a new operating model: restructured teams, new capabilities, and far deeper collaboration across the business. CISOs must also navigate the complexities of integrating agentic AI into their security programs. This session will delve into the transformative potential of agentic AI and its uses, implications, and challenges, helping security leaders: 

  • Learn how AI is changing CISOs’ roles and organizational structures. 
  • Prepare for evolving and merging functions, roles, and responsibilities. 
  • Strengthen stakeholder management skills to align competing priorities across security, IT, legal, and the business. 

Speakers:
Jess Burn, Principal Analyst, Forrester

Guardrails To Mitigate AI Risk
Guardrails For Applications Using AEGIS

As organizations rapidly adopt AI in application architectures, the challenge extends beyond building intelligent systems to effectively governing them. Forrester’s AEGIS framework provides a structured approach to AI-enabled application security, yet many teams struggle to translate its principles into operational guardrails. 

In this session, Janet Worthington explores how leading organizations are operationalizing AEGIS to establish robust guardrails throughout the application lifecycle. The focus is on embedding policy, automating enforcement, and creating feedback loops to ensure that AI-enabled applications remain aligned with security, risk, and compliance expectations at scale. 

Attendees will learn how to: 

  • Translate AEGIS principles into enforceable guardrails across development, deployment, and runtime environments. 
  • Identify gaps between policy intent and technical implementation that create hidden risk exposure. 
  • Align security, engineering, and governance stakeholders around shared accountability and measurable outcomes. 

Speakers:
Janet Worthington, Senior Analyst, Forrester

AI For Security
Agent Vs. Agent: CNAPPs AI-SPM Uses AI Agents To Secure AI Agent Infrastructure

Cloud-native application protection platforms’ AI security posture management (AI-SPM) capabilities are becoming a strategic control point for securing enterprise AI at scale. As organizations adopt AI services, such as the Amazon Bedrock, Microsoft Foundry, and Google Gemini Enterprise platforms, security leaders need stronger visibility into misconfigurations, configuration drift, identity risks, and emerging governance gaps. This session examines the priorities for building an effective AI agentaided AI-SPM program across people, process, and technology. It will outline how to reduce operational risk, improve regulatory readiness, strengthen oversight of AI environments, and deliver measurable business value through more resilient, compliant, and well-governed AI infrastructure. 

Speakers:
Andras Cser, VP, Principal Analyst, Forrester

11:40 am – 12:10 pm EST

Case Study Sessions

12:10 pm – 12:40 pm EST

Breakout Sessions

Leading The Trust And Assurance Organization
Defend Against AI Attacks With Zero Trust

The abstract idea of “AI-powered attacks” is filling a lot of headlines and a lot of marketing copy. Like any threat assessment, practitioners must strike a balance between prioritizing the most likely and the most dangerous. This session will provide a brief overview of the AI-powered attacks observed in the wild, break down their tactics and techniques, and provide insights into how Zero Trust can help mitigate threats or contain potential damage. 

Join this session to: 

  • Learn the “what” and “how” of AI-powered attacks in the wild. 
  • Understand how to apply Zero Trust principles to defend against this emerging class of attacks. 

Speakers:
Allie Mellen, Principal Analyst, Forrester
James Plouffe, Principal Analyst, Forrester

Guardrails To Mitigate AI Risk
Build Resilience For AI

Large-scale AI failures don’t just glitch — they can trigger systemic collapses ranging from unintended cost runs, financial losses, and algorithmic bias scandals to the complete shutdown of critical systems. These major financial and operational disruptions have hit companies such as Zillow, Volkswagen, Air Canada, McDonald’s, and UnitedHealthcare. Don’t let your organization be the next headline.  

Join this session to: 

  • Create severe but plausible AI failure scenarios. 
  • Establish best practices to create AI resilience. 

Speakers:
Amy DeMartine, VP, Senior Research Director, Forrester

AI For Security
IAM For Agentic Architectures: From Least Privilege To Least Agency

AI agents can act, adapt, and make decisions at machine speed, creating risks that traditional identity and access management (IAM) was never designed to address. Securing agentic architectures requires more than controlling access; it requires governing autonomy. This session explores why least privilege is no longer enough and how IAM must evolve for the agentic era. 

Attendees will learn how to: 

  • Distinguish least agency from least privilege and understand why both are required for agentic AI security. 
  • Establish a modern identity security foundation for agentic AI. 
  • Apply dynamic authorization, short-lived credentials, and identity risk signals to constrain agent behavior. 

Speakers:
Geoff Cairns, Principal Analyst, Forrester

12:10 pm – 1:10 pm EST

Workshop: AEGIS Powers Trusted AI At Scale

Agentic AI is accelerating innovation, but it is also overwhelming leaders with fragmented frameworks, inconsistent guidance, and rising governance demands. The AEGIS framework cuts through this complexity, providing a unified, regulation-aware blueprint to help you govern AI systems and agents with clarity, accountability, and trust. In this hands-on workshop, you will learn how to align your AI governance strategy to core standards while addressing emerging risks from agentic architectures along with regulatory pressure. You will leave with a practical, scalable approach to governing AI that reduces complexity while strengthening trust and control across your organization. 

Join this session to: 

  • Simplify AI governance by aligning to a unified framework that maps to major regulatory and risk standards. 
  • Move from fragmented, static policies to continuous, adaptive governance for AI systems and agents. 
  • Prioritize high-impact controls and build a scalable foundation for trusted, compliant AI across the enterprise. 

Speakers:
Enza Iannopollo, VP, Principal Analyst, Forrester

12:40 pm – 1:40 pm EST

Networking Lunch

1:40 pm – 1:45 pm EST

Welcome Back

Speakers:
Merritt Maxim, VP, Research Director, Forrester

1:45 pm – 2:05 pm EST

Guest Keynote: More Information To Come

2:10 pm – 2:30 pm EST

Keynote: Forge The Trusted Future

AI agents process data, make decisions, take actions, and pursue outcomes autonomously. In this new reality, security is essential but no longer sufficient to build trust. Explainability, accountability, and fairness are indispensable, yet only a governance model embedded in the runtime fabric of AI can deliver them. Too many governance models lack enforcement mechanisms and clear outcomes, making trust an elusive target. The key to success is extending the foundational principles of the AEGIS framework to AI governance models to manage risks beyond security. Join this session to identify who you must collaborate with, which steps you must take, and how to get started redefining AI governance through continuous risk management, least agency, and adaptable controls for the agentic era. 

Speakers:
Enza Iannopollo, VP, Principal Analyst, Forrester

2:30 pm – 2:35 pm EST

Host Remarks

Speakers:
Merritt Maxim, VP, Research Director, Forrester

2:45 pm – 3:15 pm EST

Breakout Sessions

Leading The Trust And Assurance Organization
Token Economics: Security Budgets In The AI Age

AI won’t make cybersecurity cheaper by default. As agentic AI moves into security operations centers, security platforms, and autonomous workflows, CISOs face a new cost model built on inference tokens, AI credits, premium reasoning models, integration work, and unpredictable consumption. This session shows security leaders how to spot AI cost exposure, govern token consumption, and defend security budgets before overages, throttling, or unfunded agentic workloads create operational risk. Join this session to: 

  • Decode how token pricing, AI credits, and agentic workflows reshape security budgets. 
  • Govern consumption before AI-enabled security tools create the next cloud-cost surprise. 
  • Defend security budgets as AI shifts cost, risk, and accountability across the enterprise. 

Speakers:
Jeff Pollard, VP, Principal Analyst, Forrester

Guardrails To Mitigate AI Risk
Contracts: AI Guardrails With Teeth

As AI adoption accelerates, policy alone is not a sufficient control. The real guardrails are contractual — the clauses that define, assign, and legally ensure transparency, accountability, and action across the third-party ecosystem. This session shows how to turn AI principles into enforceable obligations that satisfy regulatory expectations, protect the organization, and make “regulation by contract” a deliberate strategy rather than an accident of paperwork. If it’s not in the contract, it’s not an enforceable guardrail. 

Join this session to learn: 

  • Why contracts are the most underutilized tool in the risk tech stack. 
  • Why regulatory ambiguity increases the value of contracts, especially in AI. 
  • How to use contractual terms for AI transparency, accountability, and oversight. 

Speakers:
Alla Valente, Principal Analyst, Forrester

AI For Security
From Human-Led To AI-Driven: The New Reality Of OT Security

The thought of introducing AI-driven automation into operational technology (OT) environments makes security teams cringe. Yet as attacks on business operations rise, AI can mean the difference between staying online and grinding to a halt. This session aims to help you: 

  • Identify the risks from OT security gaps. 
  • Understand where AI delivers value. 
  • Chart a path to adopting AI while maintaining safe, reliable uptime. 

Come to learn how AI isn’t replacing operators and analysts but empowering them.

Speakers:
Paddy Harrington, Senior Analyst, Forrester

2:50 pm – 3:50 pm EST

Workshop: Zero Trust For Public Sector

Federal, state, and local government agencies continue to face mounting pressures to modernize cybersecurity programs while meeting evolving mandates, budget constraints, and operational demands. Zero Trust is now the foundational strategic framework for protecting critical systems, sensitive data, and public services, but many organizations struggle to translate policy into practical application of Zero Trust that aligns it to existing security investments, mission priorities, regulatory requirements, and measurable risk reduction. 

Attendees will learn how to: 

  • Align Zero Trust initiatives with federal mandates, compliance requirements, and agency missions. 
  • Prioritize security capabilities around high-risk, high-impact areas to improve resilience without requiring wholesale technology replacements. 
  • Build out milestones for deliverables around identity, devices, networks, applications, and data. 

Speakers:
Carlos Rivera, Senior Analyst, Forrester

3:15 pm – 4:00 pm EST

Coffee Break & Networking

Enjoy refreshments and snacks while networking with peers in the Partner Lounge.

4:00 pm – 4:30 pm EST

Breakout Sessions

Leading The Trust And Assurance Organization
Get Value From Threat Intelligence With Agentic AI

Agentic systems have the potential to be a force multiplier for security teams by amplifying how threat intelligence is operationalized within SecOps. But the reality today is messy — AI agents are inconsistently defined and unevenly implemented, making it difficult to separate substance from marketing noise. 

This session cuts through that confusion by bridging agentic AI with modern threat intelligence needs by highlighting high-value use cases (and what makes them high-value), exposing common pitfalls, and outlining how to design a meaningful AI agent. It also dives into testing and validation measures required to keep the outcomes of these systems reliable at scale. And most importantly, it helps security leaders understand how to measure ROI for AI-enabled outcomes. Attendees will gain insights they can use to prepare for the adoption of agentic capabilities, whether they arrive directly or are embedded within existing security solutions. 

Speakers:
Jitin Shabadu, Analyst, Forrester

Guardrails To Mitigate AI Risk
Defending Against Rogue Agents With AEGIS

AI agents are proliferating across enterprises. These agents hold credentials, access sensitive systems, and execute actions without human intervention. They are the new insider threat surface. Detection technology and tactics, however, have not kept pace. This talk breaks down the threat management domain of the AEGIS framework to reduce the risk posed by AI agents of all kinds: those managed by the organization and those not. 

Join this session to: 

  • Discover technologies and techniques for monitoring agents, collecting telemetry, and baselining behavior. 
  • Understand how to detect and respond to agentic AI threats as part of the AEGIS framework. 

Speakers:
Joseph Blankenship, VP, Research Director, Forrester

AI For Security
Adapting Application Threat Modeling For Agentic AI

As AI agents increasingly browse, transact, retrieve data, and execute tasks on behalf of users, application security teams must rethink how they identify users, establish trust, and assess risk. Traditional threat models assume that users are human and that automation is predictable, leaving many organizations unprepared for agent-driven behavior, delegated authority, and new abuse pathways. This session explores how agentic traffic is reshaping application attack surfaces, trust boundaries, and security assumptions. Attendees will learn how to adapt threat modeling practices to account for AI agents, machine identities, and emerging application interaction patterns. 

Join this session to: 

  • Understand how autonomous agents reshape application attack surfaces. 
  • Identify new abuse cases and trust failures involving AI agents. 

Speakers:
Sandy Carielli, VP, Principal Analyst, Forrester

4:40 pm – 4:45 pm EST

Welcome Back

Speakers:
Merritt Maxim, VP, Research Director, Forrester

4:45 pm – 5:05 pm EST

Guest Keynote: More Information To Come

5:05 pm – 5:25 pm EST

Keynote: Advancing Data Controls To Secure Agentic AI

Agentic AI expands the existing challenges organizations have across both using and protecting data. While data security and privacy is a shared responsibility, the act of applying data controls to enforce policies rests on security teams. Collaboration is necessary for applying the data controls of the AEGIS framework, yet organizational dependencies and varied maturity across data security, privacy, and data governance functions often leave security teams stuck when figuring out how to proceed. This session outlines an approach for moving forward to enable the data controls that have the greatest impact on risk mitigation while navigating dependencies in parallel to continue advancing the maturity of your controls. 

Speakers:
Heidi Shey, Principal Analyst, Forrester

5:25 pm – 5:30 pm EST

Closing Remarks

Speakers:
Merritt Maxim, VP, Research Director, Forrester

5:30 pm – 6:40 pm EST

Reception

Join us for refreshments and light appetizers. All registered attendees are welcome.

Download Agenda
Please note: Your downloaded agenda will reflect the filters applied from above. To download the full agenda, please hit “clear all” at the top of this page to clear your filters.

Security & Risk Forum · November 9–10, 2026 · Washington DC

Register
Sign in or create an account to register.