A private dinner dialog for CISOs and AppSec leaders. No slides. No pitch. Ten seats at one table, and everyone at it shares.
By invitation only. Chatham House Rule applies.
This series exists because the ground under application security is moving faster than any conference agenda. Each city has taken the conversation somewhere the last one could not. All of it under Chatham House Rule, so what follows is theme, not attribution.
Silicon Valley asked what a finding is actually worth. The room converged on an uncomfortable ratio: the volume of findings is exploding while the number that an attacker could actually use stays small. One dataset discussed put it at 7 of 100. Programs built to triage the other 93 are spending their best people on noise.
New York asked what happens when both sides are armed. Defenders run AI to find issues, then queue them for human triage. Attackers now run AI that finds and weaponizes in a single loop. The triage step your program depends on is a step the adversary no longer takes. The line that stuck: your program is not slow because it is poorly built. It is slow because it is playing the wrong half of a contest that used to be fair.
Charlotte asked who wrote your application in the first place. For most of the room the honest answer was nobody in the building. Applications are assembled from vendor platforms, SaaS, open source, and now generated code. When the code is not yours, code review is not available to you. The only security artifact that crosses a company boundary is proof that an attack path works, or proof that it does not.
Toronto picks up from there.
Agentic tooling has collapsed the distance between discovering a flaw and exploiting it. What does a defense program look like when the adversary's cost of weaponization approaches zero?
Claude Code, Cursor, and Copilot ship functioning software faster than any review cycle. Every function they generate is exposed through an API, and the flaws they introduce are authorization and business logic errors that scanners were never built to catch.
Assembled from vendors, SaaS, open source, and generated code, the modern application has no single owner and no single reviewer. How do Canadian financial institutions and enterprises establish proof across boundaries they do not control?
APIs change daily. Annual pen tests and periodic reviews create gaps by design. If continuous validation is the answer, what does it take to make it real, and who is accountable when no single team owns the attack surface?
There is no keynote and no vendor presentation. A moderated roundtable where the agenda above is a starting point and the room decides where it goes. Ten voices, every one of them heard. What is said stays in the room; what is learned leaves with you.
Leads APIsec with a focus on proactive application security. Twenty years in security leadership at McAfee, Intel and Thales, having been part of creating the DLP market, Secure Communications market, and Machine Learning on Big Data market. Faizel has facilitated all three prior sessions in this series.
The first three cities filled by referral before invitations finished going out. Share your details to request a seat, and tell us what question you would put to the table.