

ISC2 Silicon Valley - September 2026 Chapter Meeting
βπ Hybrid meeting β Palo Alto Networks HQ, Santa Clara + Zoom
βπ This month's meeting is generously hosted and sponsored by Palo Alto Networks.
βJoin the ISC2 Silicon Valley Chapter for our September 2026 meeting. Identity is the control plane now, and agents are the thing straining it β acting continuously, carrying borrowed authority, and gathering privilege faster than anyone planned for. This month we're taking that from both ends: how to hold the line in the cloud environments you already run, and how the underlying authorization model has to change when the requester isn't a human logging in.
βπ€ Session 1 | Cloud Privilege is on Fire, and Agents are Gasoline: Facing Uncomfortable Truths in Identity Security
βMatt Carle, Head of Product, Sonrai Security
βThe move to cloud promised better identity security than we'd ever had. The hyperscalers built powerful IAM, but it proved confusing to operate, and development spawned far more identities than anyone planned for. Scale won, and stolen credentials are now the primary route into cloud environments. Agents are the next scale shock β a wave of identities that gather privilege relentlessly in service of finishing the task, whatever it costs. Gas on a fire that's been growing for years.
βAWS, GCP, and Azure IAM remain powerful, byzantine, and underused. Draconian zero-standing-privilege programs and thousands of policy edits won't survive contact with a brownfield environment β workloads break and developers stop cooperating. Matt makes the case for a guardrails-first approach: enforce at the organization boundary instead of per identity, define least privilege by permission sensitivity, and give every identity β human and non-human β a path back to access that doesn't disrupt existing developer workflows.
βAttendees will be able to compare organization-level guardrail primitives across AWS, Azure, and GCP (SCPs and RCPs, Azure RBAC and Entra, GCP IAM deny policies) and identify where each breaks down at enterprise scale; evaluate why non-human identities β service principals, CI/CD pipelines, AI agents β fall outside request-based access programs, and what a control model that actually covers them has to do differently; and apply a risk-weighted definition of least privilege, based on permission sensitivity and observed usage rather than policy completeness, to sequence enforcement without disrupting workloads.
βAbout the Speaker
βMatthew Carle is the Head of Product at Sonrai Security, previously holding senior roles at Noetic Cyber and Patriot One Technologies, and was a World Wide Product Manager at IBM.
βπ€ Session 2 | Agentic Identity & Access Management β From IAM to AIAM
βHarrison Tang, Co-Founder & COO, Spokeo
βIAM was built for humans who log in. AI agents break that model three ways at once: they act continuously and autonomously, they carry borrowed authority delegated from humans and other agents, and the content they read can redirect what they do β because an LLM's context window draws no line between instructions and data. Harrison starts from how an LLM agent actually works, shows why prompt injection is a structural property rather than a patchable bug, and rebuilds IAM around a different question: not "who are you?" but "may this specific request be honored?" Expect access-matrix fundamentals, capability-based authorization, verifiable credentials, verifiable delegation chains, and where the W3C, DIF, and IETF standards are heading.
βAbout the Speaker
βHarrison Tang is an entrepreneur and technology executive who co-founded Spokeo in 2006 and currently serves as its COO. He was named Ernst & Young Entrepreneur of the Year in Los Angeles in 2015, and Spokeo has been recognized by Forbes, Deloitte, Inc., and the Los Angeles Business Journal. He previously served as Co-Chair of the W3C Credentials Community Group and as Chairman of the Monte Jade Science and Technology Association of Southern California. A recognized thought leader in data and technology, Harrison has been featured in the Wall Street Journal, Consumer Reports, and the LA Times, and has spoken at CES, DataCon LA, and other technology and data conferences. Originally from Taiwan, Harrison moved to Silicon Valley at age 13. He holds bachelor's degrees in Economics and Electrical Engineering and a master's degree in Electrical Engineering from Stanford University.
βπ
Event Details
π
Date: September 08, 2026
β° Time: 6:00 PM β 8:00 PM PT
π Format: In-person & Zoom
π Education: CPE-eligible
βπ’ Venue
Palo Alto Networks
3000 Tannery Way, Santa Clara, CA 95054
Building 3, 2nd Floor
SC3.2.415 Multi-purpose Room 16
SC3.2.417 Multi-purpose Room 17
βπ
ΏοΈ Parking is available in P1 South and in the lot between Buildings 1 and 3. A campus map will be shared with registrants.
π» Can't make it in person?
This month's meeting is hybrid. Join us on Zoom:
https://us06web.zoom.us/j/82363587569
Remote attendees are CPE-eligible β stay for the full session and email the board to have your CPEs recorded.
βπ Help spread the word β repost and invite your network across the cyber community
βπ€ Join the Community: Open Google Form
βποΈ Speaker Opportunities β Open Call
βISC2 Silicon Valley is booking sessions through Q4 2026, and we're opening the mic to the wider cybersecurity community. Not an ISC2 member? Doesn't matter. If you've got something worth sharing, we want you on our stage.
βHard-won lessons. Fresh research. War stories you can finally talk about. First-time speakers and seasoned presenters all welcome.
ββ±οΈ Up to 40 minutes + Q&A
π In-person at our monthly meeting
π CPE-eligible for attendees
βπ© Submit your pitch β