

ISC2 Silicon Valley - August 2026 Chapter Meeting
βπ This month's in-person meeting is generously hosted by Santa Clara University.
βJoin the ISC2 Silicon Valley Chapter for our August 2026 meeting. Agents are shipping to production faster than the controls around them are being designed, and the assumptions holding those deployments together are already on the map for attackers. This session names five of them.
βπ€ Session | The Agent Did Not Breach You. Your Architecture Did.
βMohit Bansal, Senior Manager, Security Engineering, Webflow | Tushar Badlani, Security Specialist, Figma
βWhen your AI agent takes an action that harms a customer, who do you call? Most security teams cannot answer that question β not because they lack process, but because the architecture underneath their agentic deployments was never designed with that question in mind. This talk walks through five assumptions baked into standard agentic AI architectures that attackers have already mapped and are actively exploiting: sub-agent fan-out with no scope inheritance controls, MCP tool chains that replicate every early mistake npm made, shared memory layers with no trust boundary, audit logs that cannot distinguish authorized agent behavior from compromised agent behavior, and the confused deputy pattern β a vulnerability class documented in 1988 that now has API access to your production environment.
βAbout the Speakers
βMohit Bansal is Senior Manager, Security Engineering at Webflow, where his job is keeping security practices sound while agentic AI reshapes how every team in the company builds. As AI-powered tooling expands the ways code is written, committed, and deployed, it widens the attack surface and opens new classes of exposure that legacy controls were never built to catch. His team operates at that frontier, staying ahead of incidents before they happen, in an environment where the AI-powered threat count is only trending one direction.
βTushar Badlani is a Security Specialist at Figma, focused on scaling Customer Trust and Third-Party Risk Management programs. With 10+ years building security programs across vendor assurance, customer assurance, customer trust, and compliance, his career spans EY, TCS, and 6.5 years at Okta β first as Customer Assurance NAM Manager, then as Global Customer Audit Manager leading the program across AMER, EMEA, and APJ. He also serves as a strategic advisor at Drata, advising on GRC, assurance, and compliance program design. He earned his master's degree from Syracuse University and is based in the San Francisco Bay Area.
βEvent Details
π
Date: Tuesday, August 11, 2026
β° Time: 6:00 PM β 8:00 PM PT
π Format: In-person
π 2 CPEs for ISC2 members
βπ’ Venue
Santa Clara University
500 El Camino Real, Santa Clara, CA 95053
Edward J. Daly Science Center, Room 206
βπ
ΏοΈ Parking
Permits are enforced on campus until 8:00 PM, so plan for parking.
βPaid: North Campus Parking Structure, 1063 Alviso St β entrances on The Alameda and Alviso Street. $5 half day via the AMP Park mobile app. ADA spaces and EV charging on level 1. Install the app before you arrive.
βFree 2-hour visitor permit: valid in designated Visitor and "F" spaces only β Guadalupe "F" Lot, Leavey "F" Lot, Loyola Hall, Main Parking Structure ramp, the visitor lot beside it, Performing Arts Annex "F" Lot, and University Villas. Two hours from issuance, one per 24 hours.
βFull details: https://www.scu.edu/parking-and-transportation-services/parking-services/visitor-parking/
βπ Help spread the word β repost and invite your network across the cyber community
βπ€ Join the Community: https://forms.gle/DHMUh2uh4F5sjPXv6
βποΈ Speaker Opportunities β Open Call
βISC2 Silicon Valley is booking sessions through Q4 2026, and we're opening the mic to the wider cybersecurity community. Not an ISC2 member? Doesn't matter. If you've got something worth sharing, we want you on our stage.
βHard-won lessons. Fresh research. War stories you can finally talk about. First-time speakers and seasoned presenters all welcome.
βWe're especially interested in:
βPractitioner-led talks β what you actually built, broke, and fixed (vendor-neutral)
βAI/ML security β agentic systems, prompt injection, model supply chain
βIdentity & access β non-human identity, agent authorization, IGA evolution
βDetection & response β behavioral analytics, deception, IR lessons learned
βGRC in motion β measuring program effectiveness, board-level metrics, regulatory shifts
ββ±οΈ Up to 40 minutes + Q&A
π In-person at our monthly meeting
π₯ Audience: 40β80 working security practitioners β CISOs, IR leads, security engineers, GRC pros
π CPE-eligible for attendees
βπ© Submit your pitch β