Cover Image for ISC2 Silicon Valley - August 2026 Chapter Meeting
Cover Image for ISC2 Silicon Valley - August 2026 Chapter Meeting
Avatar for ISC2 Silicon Valley

ISC2 Silicon Valley - August 2026 Chapter Meeting

Register to See Address
Santa Clara, CA
Registration
Past Event
Welcome! To join the event, please register below.
About Event

β€‹πŸ™ This month's in-person meeting is generously hosted by Santa Clara University.

​Join the ISC2 Silicon Valley Chapter for our August 2026 meeting. We're doubling up on the same underlying problem from two directions: the dependencies you inherit, and how little your tooling actually tells you about them.

🎀 Session 1 | Billions of Unprotected Installs: The Exposure Window Your Program Is Not Measuring

​Cassie Crossley, Co-Founder & CEO, VulNow

​Most vulnerability management programs are built on a reasonable assumption: if something dangerous is in your dependencies, a CVE will tell you. That assumption has a structural gap, and this talk puts a number on it. When open source maintainers fix security bugs, they do not always file a CVE immediately. Coordinated disclosure processes run on timelines measured in weeks and months. The fix exists in the code. The advisory does not exist yet. During that window, CVE-based scanners report clean results, patch prioritization queues stay quiet, and downstream packages accumulate installs by the hundreds of millions.

​This talk walks through the mechanics of how that gap forms, why it is a structural feature of open source maintenance rather than an exception, and how to quantify the exposure it creates using a simple metric practitioners can take back to their teams: unprotected installs during the silent fix window. For widely deployed packages, that number reaches into the billions before any scanner has a signal to act on.

​Attendees will leave with a clearer model of where CVE-based tooling has inherent blind spots, a practical way to reason about and communicate PreCVE exposure to leadership, and a more honest answer to the question their CISO is already asking: what does "no CVEs found" actually mean?

β€‹πŸŽ€ Session 2 | The Agent Did Not Breach You. Your Architecture Did.

​Mohit Bansal, Senior Manager, Security Engineering, Webflow | Tushar Badlani, Security Specialist, Figma

​When your AI agent takes an action that harms a customer, who do you call? Most security teams cannot answer that question β€” not because they lack process, but because the architecture underneath their agentic deployments was never designed with that question in mind. This talk walks through five assumptions baked into standard agentic AI architectures that attackers have already mapped and are actively exploiting: sub-agent fan-out with no scope inheritance controls, MCP tool chains that replicate every early mistake npm made, shared memory layers with no trust boundary, audit logs that cannot distinguish authorized agent behavior from compromised agent behavior, and the confused deputy pattern β€” a vulnerability class documented in 1988 that now has API access to your production environment.

​About the Speakers
Cassie Crossley is the Co-Founder and CEO of the AI cybersecurity company VulNow, focused on software and supply chain vulnerability intelligence. A global leader in technology and risk management, she has more than 25 years of experience driving innovation and resilience across critical infrastructure, manufacturing, and technology sectors. Previously Vice President of Supply Chain Security at Schneider Electric, Cassie established one of the industry's most comprehensive supplier cybersecurity programs and helped shape global standards for software supply chain assurance. She is the author of "Software Supply Chain Security: Securing the End-to-End Supply Chain for Software, Firmware, and Hardware" (O'Reilly Media) and a recognized authority on operational resilience, transparency, and cyber risk governance. Her leadership and advocacy continue to influence how organizations worldwide secure the digital ecosystems they depend on.

​Mohit Bansal is Senior Manager, Security Engineering at Webflow, where his job is keeping security practices sound while agentic AI reshapes how every team in the company builds. As AI-powered tooling expands the ways code is written, committed, and deployed, it widens the attack surface and opens new classes of exposure that legacy controls were never built to catch. His team operates at that frontier, staying ahead of incidents before they happen, in an environment where the AI-powered threat count is only trending one direction.

​Tushar Badlani is a Security Specialist at Figma, focused on scaling Customer Trust and Third-Party Risk Management programs. With 10+ years building security programs across vendor assurance, customer assurance, customer trust, and compliance, his career spans EY, TCS, and 6.5 years at Okta β€” first as Customer Assurance NAM Manager, then as Global Customer Audit Manager leading the program across AMER, EMEA, and APJ. He also serves as a strategic advisor at Drata, advising on GRC, assurance, and compliance program design. He earned his master's degree from Syracuse University and is based in the San Francisco Bay Area.

​Event Details
πŸ“… Date: Tuesday, August 11, 2026
⏰ Time: 6:00 PM – 8:00 PM PT
πŸ“ Format: In-person
πŸŽ“ 2 CPEs for ISC2 members

β€‹πŸ’ Venue
Santa Clara University
Edward J. Daly Science Center, Room 206
500 El Camino Real, Santa Clara, CA 95053

β€‹πŸ…ΏοΈ Parking
Permits are enforced on campus until 8:00 PM, so plan for parking.

​Paid: North Campus Parking Structure, 1063 Alviso St β€” entrances on The Alameda and Alviso Street. $5 half day via the AMP Park mobile app. ADA spaces and EV charging on level 1. Install the app before you arrive.

​Free 2-hour visitor permit: valid in designated Visitor and "F" spaces only β€” Guadalupe "F" Lot, Leavey "F" Lot, Loyola Hall, Main Parking Structure ramp, the visitor lot beside it, Performing Arts Annex "F" Lot, and University Villas. Two hours from issuance, one per 24 hours.

​Full details: https://www.scu.edu/parking-and-transportation-services/parking-services/visitor-parking/


β€‹πŸ™ Help spread the word β€” repost and invite your network across the cyber community

β€‹πŸ€ Join the Community: Open Google Form


β€‹πŸŽ™οΈ Speaker Opportunities β€” Open Call

​ISC2 Silicon Valley is booking sessions through Q4 2026, and we're opening the mic to the wider cybersecurity community. Not an ISC2 member? Doesn't matter. If you've got something worth sharing, we want you on our stage.

​Hard-won lessons. Fresh research. War stories you can finally talk about. First-time speakers and seasoned presenters all welcome.

​We're especially interested in:

  • ​Practitioner-led talks β€” what you actually built, broke, and fixed (vendor-neutral)

  • ​AI/ML security β€” agentic systems, prompt injection, model supply chain

  • ​Identity & access β€” non-human identity, agent authorization, IGA evolution

  • ​Detection & response β€” behavioral analytics, deception, IR lessons learned

  • ​GRC in motion β€” measuring program effectiveness, board-level metrics, regulatory shifts

​⏱️ Up to 40 minutes + Q&A
πŸ“ In-person at our monthly meeting
πŸ‘₯ Audience: 40–80 working security practitioners β€” CISOs, IR leads, security engineers, GRC pros
πŸŽ“ CPE-eligible for attendees

β€‹πŸ“© Submit your pitch β†’

Location
Please register to see the exact location of this event.
Santa Clara, CA
Avatar for ISC2 Silicon Valley