Loading…
Type: Talk clear filter
Monday, June 1
 

10:40am PDT

Adapt Your IR for AI
Monday June 1, 2026 10:40am - 11:00am PDT
The 2026 BSides Vancouver theme perfectly captures the current state of enterprise security. As organizations rapidly adopt AI capabilities, the attack surface has expanded far beyond simple chat interfaces and into the core of how businesses operate. Security operations teams are now tasked with defending a complex, multi-layered AI ecosystem, often without the necessary visibility, standardized tooling, or established playbooks.
This presentation moves past the hype to break down the practical realities of Incident Response (IR) across the complete AI architecture. We will explore the specific threats, telemetry blind spots, and triage strategies associated with four distinct pillars of enterprise AI adoption:
  • The AI Pipeline & MLOps: Defending the supply chain. 
  • Locally Hosted AI Applications: The unique IR challenges of managing self-hosted open-source models. 
  • Agentic Workflows: Triaging incidents when autonomous systems go off the rails. 
  • Widespread LLM Usage: Managing the daily operational risks of enterprise LLM adoption, from analysts without Pandas familiarity using LLMs to generate Python code for Jupyter notebooks, to standard prompt injection and data leakage in corporate applications.
Attendees will leave with a pragmatic framework for adapting their current IR capabilities to this new reality. We will outline actionable steps to update response playbooks for AI systems and build the necessary cross-functional workflows between security, data science, and engineering.
Speakers
avatar for Ryan Clarke

Ryan Clarke

Principal Incident Response Consultant, Mandiant (Google Cloud)
Ryan is a Principal Incident Response Consultant for Mandiant (Google Cloud). As part of the Incident Response team, he provides emergency services to clients when a security breach occurs. He also conducts purple teams, threat hunts, table top exercises, forensic investigations and... Read More →
avatar for Muhammad Muneer

Muhammad Muneer

Principal Consultant - Incident Response, Mandiant (Now Part of Google Cloud)
As a Principal Incident Response Consultant and the global lead for Threat Hunting Program Development at Mandiant, Muhammad Muneer guides organizations through cybersecurity crises and proactively identifies emerging threats. He has also pioneered and led the development of the Securing... Read More →
Monday June 1, 2026 10:40am - 11:00am PDT
Track 4 - Room 1700 - Sponsored by Aikido Security
  Talk, Track 4
  • Topic AI
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Topic
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.