Before covering individual events, it is worth naming the thread that connected them. Every major cybersecurity gathering in the first half of 2026 returned to the same question from a different angle: how do you secure systems that are increasingly autonomous? The shift from discussing AI as a tool to discussing AI as an actor, an agentic system that plans, decides, and takes actions, changed the conversation at every level, from technical research tracks to executive panels to regulatory breakout sessions.
Cisco’s President and Chief Product Officer Jeetu Patel, speaking at RSAC 2026, challenged the industry to fundamentally reimagine security for an era where AI agents act as autonomous coworkers. He announced open-source tooling including DefenseClaw, framing the challenge in three directions: protect agents from the world, protect the world from agents, and detect and respond at machine speed. That framing became one of the defining articulations of the 2026 security agenda.
Events Already Completed: January to June 2026
RSAC 2026 Conference | San Francisco | March 23-26
RSAC 2026 was the conference’s 35th annual edition and its largest. Nearly 44,000 attendees from more than 100 countries gathered at the Moscone Center in San Francisco, with more than 700 speakers, 570 sessions across 31 tracks, and 600 exhibitors. The theme for the year was Power of Community, a deliberate counterweight to a threat environment where adversaries are increasingly automated and defenders increasingly isolated. CEO Jen Easterly described RSAC as the trusted forum where practitioners, researchers, innovators, and leaders come together to tackle the challenges shaping our digital world.
The dominant technical theme across sessions was agentic AI, followed by offensive and defensive cyber capabilities and resilience under fast-evolving regulations. The RSAC Innovation Sandbox, which recognises the most innovative early-stage security company each year, was won by Geordie AI, whose platform gives enterprises real-time visibility into their AI agent footprint, monitors agent behaviour and posture, and natively identifies and mitigates risk. The choice of an AI governance platform as the most innovative startup of 2026 was itself a signal of where practitioner attention had shifted.
Session highlights included a panel featuring four former NSA Directors discussing offensive cyber operations, a Cryptographers’ Panel marking its 25th year at the conference, and the agentic AI panel that challenged the concept of a human in the loop in AI deployment. Tim Brown, SolarWinds’ CISO, spoke publicly about the SEC indictment arising from the 2020 breach, making the case for clear communication policies as personal liability has become a routine part of the CISO role. Accenture and Anthropic jointly announced Cyber.AI, a platform using Claude as a central reasoning engine to automate security workflows, at the RSAC exhibitor floor.
Black Hat Asia 2026 | Singapore | April 21-24
Black Hat Asia returned to Marina Bay Sands in Singapore for a four-day programme featuring training courses across all skill levels, a Summit Day, and a two-day main conference. Black Hat Asia positions itself as the primary technical security research event for the Asia-Pacific region, covering offensive techniques, vulnerability research, and defensive tooling across enterprise and operational technology environments. The event ran alongside growing regional focus on NIS2-equivalent frameworks being adopted across Southeast Asia and increased government-private sector collaboration on critical infrastructure protection.
Google Cloud Next 2026 | Las Vegas | April 22-24
Google Cloud Next 2026, held in Las Vegas, centred on enterprise AI adoption and the security implications of cloud-native AI infrastructure. Security-focused breakout sessions covered AI and machine learning threat vectors, infrastructure modernisation, and compliance for AI-assisted workloads. The event is increasingly relevant to security practitioners as AI workloads move from experimental to production environments, creating new attack surface across cloud identity, data pipelines, and API integrations.
GISEC Global 2026 | Dubai | May 5-7
GISEC Global 2026 was the 15th edition of the Middle East and Africa’s largest cybersecurity event. Held at the Dubai Exhibition Centre at Expo City, the event brought together more than 25,000 infosec professionals from more than 180 countries, alongside global enterprises, CISOs, government dignitaries, technology buyers, ethical hackers, and security innovators. More than 750 international cybersecurity brands exhibited across the three-day programme, organised in collaboration with the UAE Cybersecurity Council, Dubai Electronic Security Centre, Ministry of Interior, and Dubai Police.
GISEC 2026 included the Dubai Cyber Challenge, CTF competitions, the GISEC Decode format, a Global Cyber Drill, and the GISEC Escape Room, reflecting a philosophy of experiential security education alongside the standard keynote and panel programme. Sessions addressed AI-driven threats and defence strategies, with one particularly noted presentation by SECUINFRA’s Felix Gutjahr demonstrating how adversaries use AI across the full attack chain and what that implies for modern defence operations. The event’s positioning as a collaboration hub for the Middle East, Africa, and Asia reflects the region’s accelerating investment in national cybersecurity infrastructure.
Gartner Security and Risk Management Summit 2026 | National Harbor, MD | June 1-3
The Gartner Security and Risk Management Summit, held at National Harbor, Maryland, drew approximately 4,500 security and risk professionals for analyst-led sessions on business resilience, risk management, and strategic security programme design. The event is CISO-focused rather than practitioner-focused, making it the primary venue for conversations about board engagement, security programme investment, and governance frameworks. AI governance and regulatory convergence across the EU AI Act, NIST AI RMF, and sector-specific requirements were prominent across the programme.
Events Still to Come: July to December 2026
| Event | Date and Location | What to Watch For |
| Black Hat USA 2026 | August 1-6, Las Vegas | Vulnerability research, AI security tooling, agentic AI exploitation and defence. Largest technical security conference in North America. |
| DEF CON 34 | August 7-10, Las Vegas | CTF competitions, Villages, AI security hacking research, offensive security techniques. Runs immediately after Black Hat. |
| Aspen Cyber Summit 2026 | November 18, Washington DC | Policy-driven discussion on AI regulation, government-private sector coordination, and cross-border cybersecurity governance. |
| GITEX Global 2026 | December 7+, Dubai World Trade Centre | Largest tech expo in Middle East and Africa. Cloud, AI, security, and telecom. Key venue for enterprise procurement and regional strategy. |
| Black Hat Middle East and Africa 2026 | December 1-3, Riyadh | Premier cybersecurity conference and exhibition for the Gulf region. Connects global decision-makers with MEA security leadership. |
| Gartner IAM Summit | December 7-9 | Identity and access management, zero trust architecture, AI identity governance. |
Table 1: Upcoming major cybersecurity events, July to December 2026. Sources: Journeybee (2026 conference guide), EventBrowse (updated June 17, 2026), Cybersecurity Dive (February 2026), Black Hat USA website, GITEX official registration.
What the 2026 Conference Agenda Tells Us
Three conclusions emerge from reading the 2026 conference agenda as a whole rather than individual events.
- First, the AI governance conversation has moved from optional track to central theme in the space of one conference cycle. RSAC 2025 discussed agentic AI. RSAC 2026 started from the assumption that agentic AI is already deployed, already creating access without oversight, and already in need of controls that do not yet widely exist. The same shift is visible at GISEC, Gartner, and Google Cloud Next.
- Second, regulatory convergence is producing a new type of conference session. Two years ago, compliance sessions addressed GDPR, sector regulations, and data protection. In 2026, the same tracks are covering EU AI Act timelines, NIST AI RMF adoption, supply chain legal obligations under NIS2 and DORA, and the intersection of AI model risk with existing financial services and healthcare regulatory frameworks. The audience for these sessions has expanded from GRC practitioners to include CISOs, engineering leadership, and legal counsel.
- Third, the Middle East and Asia are no longer peripheral to the industry calendar. GISEC Global 2026’s 25,000 attendees from 180 countries and GITEX’s December event at the Dubai World Trade Centre represent a regional security market that now commands the same attention as North American and European events from the same global vendors and security leaders.

Leave a Reply