In-person sessions make more sense when the objective is collaboration, live troubleshooting, or workshop-based learning that benefits from immediate interaction. They are also useful when peer networking and informal knowledge exchange are part of the outcome. For distributed teams, the decision should balance learning depth, travel cost, and whether the topic needs guided practice rather than passive attendance.
Why This Matters for Security Teams
For identity and security practitioners, the delivery format is not just a logistics choice. It changes what kind of learning happens. Virtual sessions work for broad updates and passive briefing, but in-person events become more valuable when the goal is to test assumptions, pressure-test procedures, and get unfiltered feedback from peers who have solved the same problems in production.
This matters most in NHI and agentic AI discussions, where teams often need to connect policy, tooling, and incident response in real time. NHIMG research shows that only 1.5 out of 10 organisations are highly confident in securing NHIs, while The State of Non-Human Identity Security highlights a broader confidence gap that is difficult to close through lectures alone. For topics like secrets rotation, workload identity, and access review design, the value is often in the back-and-forth, not the slide deck. In practice, many security teams discover their biggest process gaps only after an incident review or workshop, rather than through planned training.
How It Works in Practice
In-person sessions make the most sense when practitioners need to work through live constraints, not just understand concepts. That includes tabletop exercises, architecture reviews, policy design sessions, and hands-on labs where participants must compare tradeoffs and make decisions together. For NHI governance, that can mean mapping secrets lifecycle controls to NIST SP 800-53 Rev. 5 requirements, or reviewing how failures in rotation, logging, and privilege scoping show up in real environments.
In-person format is especially useful when the expected outcome includes:
- Live troubleshooting across security, platform, and application teams
- Whiteboarding trust boundaries, ownership, and escalation paths
- Practicing incident response for leaked secrets, service accounts, or OAuth apps
- Building shared vocabulary across teams that use different tools and operating models
- Testing whether an approach is actually workable before rollout
The reason is simple: identity problems are often contextual. An access model that looks sound in a policy document can break under the pressure of CI/CD pipelines, third-party integrations, or agent-driven automation. NHIMG’s Ultimate Guide to NHIs is useful here because it frames governance as a lifecycle problem, not a one-time approval. That lifecycle view becomes much easier to explore in person when the group needs to compare how ownership, offboarding, and rotation really happen across teams. These sessions tend to break down when attendance is mostly passive and the audience is distributed across time zones, because the interactive problem-solving that makes the format valuable is lost.
Common Variations and Edge Cases
Tighter collaboration often increases time and travel cost, so organisations need to balance learning depth against operational friction. That tradeoff is usually worth it for high-stakes topics, but not for every session. If the purpose is awareness, policy announcement, or a recurring status update, virtual delivery is often the better fit. Current guidance suggests reserving in-person time for work that depends on immediate interaction, not for content that can be consumed asynchronously.
There are also edge cases where hybrid design is the best answer. For example, a virtual keynote can pair well with an in-person workshop, or a small on-site working group can be used to seed decisions that are then circulated to a wider remote audience. This is especially relevant where the topic involves secrets exposure, third-party access, or NHI risk trends that are already well documented in NHIMG research such as 52 NHI Breaches Analysis and Top 10 NHI Issues. Best practice is evolving here, but the practical rule is consistent: choose in-person when the outcome depends on trust, iteration, and real-time decision-making.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Event-driven identity discussions often expose weak NHI ownership and lifecycle gaps. |
| OWASP Agentic AI Top 10 | A01 | Agentic systems need interactive review when tool access and behaviour are hard to predict. |
| CSA MAESTRO | A2 | MAESTRO stresses cross-functional governance that benefits from direct collaboration. |
| NIST AI RMF | AI RMF governance depends on stakeholder coordination and contextual risk discussion. | |
| NIST CSF 2.0 | ID.AM-2 | Identity asset understanding improves when teams collaboratively map what is in scope. |
Apply AI RMF governance by using facilitated sessions to define risk owners and review context.
Related resources from NHI Mgmt Group
- Why do identity security events matter for practitioners working on workforce, governance, and non-human identity challenges?
- When does automated remediation make more sense than manual review in SaaS security?
- When does on-premise AI security make the most sense for regulated organisations?
- When does ECC make sense for machine identity programmes?