TL;DR: Cybersecurity conferences in 2026 are shifting from broad threat briefings toward agentic development security, software supply chain governance, and AI guardrails, according to Cycode. The agenda change matters because security teams now need peer benchmarks, operational playbooks, and cross-functional forums that translate AI risk into concrete development controls.
At a glance
What this is: This is Cycode’s 2026 conference guide, and its central finding is that agentic security, AI governance, and supply chain risk now dominate the most relevant event agendas.
Why it matters: It matters because security, AppSec, and IAM teams increasingly need conference content that maps directly to AI-enabled development, identity governance, and supply chain controls rather than generic threat awareness.
By the numbers:
- Gartner projected worldwide information security spending would reach $213 billion in 2025 and grow another 12.5% to $240 billion in 2026.
- Verizon’s DBIR 2025 covered 22,052 security incidents and 12,195 confirmed breaches across 139 countries.
- Verizon found that third-party involvement in breaches doubled year over year from 15% to 30%.
👉 Read Cycode’s guide to the best cybersecurity conferences in 2026
Context
Cybersecurity conference agendas are now a signal of where enterprise risk is moving. In 2026, the strongest events are those that move beyond broad threat awareness and address the operational realities of AI-assisted development, software supply chain governance, and identity controls for systems that act with machine speed.
That shift matters to IAM and security teams because agentic software development introduces new access paths, new approval points, and new secrets exposure risks across the delivery chain. The article’s starting position is typical of the current market: practitioners are no longer looking for inspiration alone, they are looking for usable controls, peer benchmarks, and implementation detail.
Key questions
Q: How should security teams choose cybersecurity conferences in 2026?
A: Security teams should choose conferences by the quality of implementation content, not by attendance numbers or brand recognition. Prioritise events that cover agentic development, supply chain controls, identity-aware segmentation, and hands-on workshops. The best value comes from sessions that help teams convert emerging risk into operating models, policy decisions, and measurable controls.
Q: Why do agentic AI and software supply chain sessions matter to IAM teams?
A: They matter because AI-driven development changes who or what is requesting access, approving actions, and moving code. That creates new machine identities, new secrets exposure points, and new governance questions for IAM, PAM, and NHI lifecycle management. If the event does not address those boundaries, it is only partially relevant.
Q: What do organisations get wrong when they treat conference attendance as awareness only?
A: They often collect information without using the event to sharpen control decisions. That leads to the same generic notes every year, while the real risks sit in delegation, secrets handling, pipeline access, and cross-functional accountability. Conference value should be measured by whether the team leaves with concrete changes to architecture, policy, or operating cadence.
Q: Who should be accountable for agentic development security and supply chain governance?
A: Accountability should sit across AppSec, platform engineering, IAM, and risk leadership, because the failure points span code, identity, and release operations. The right owner is the team that can enforce policy at runtime and prove it across the delivery chain. If ownership is fragmented, the control gaps will be too.
Technical breakdown
Why agentic development changed conference relevance
Agentic development means AI systems can write, review, test, and in some cases deploy code with limited human intervention. That changes which conference sessions matter because the core risks are no longer only application flaws, but also delegation, tool access, prompt handling, and the identity boundary between human approval and machine action. In practice, security teams need forums that cover AI BOMs, agent-level policy enforcement, and how to constrain tool use without breaking delivery speed.
Practical implication: prioritise events that discuss agent governance and machine identity controls, not just generic AppSec content.
How software supply chain risk became a conference mainstay
Software supply chain security now spans source code, dependencies, CI/CD pipelines, build systems, and release workflows. Conferences are treating this as a governance problem because a weak link anywhere in the delivery path can propagate trust failures downstream. The technical conversation increasingly centres on SBOMs, provenance, secure build controls, and release integrity, which is why supply chain sessions now sit alongside cloud and AppSec tracks rather than being treated as niche topics.
Practical implication: look for sessions that show how to operationalise provenance, dependency assurance, and release controls across the SDLC.
Why identity-based segmentation is appearing in network tracks
Identity-based segmentation moves enforcement away from static IP rules and toward the identity of the user, workload, or service making the request. That matters in hybrid environments where IP space is fluid, workloads are ephemeral, and trust needs to follow the principal rather than the network location. Conference content increasingly links network telemetry, application context, and identity signals because the old perimeter model cannot describe modern traffic well enough.
Practical implication: ask whether the event covers identity-aware network policy and cross-domain telemetry, not only firewall or SASE tooling.
Threat narrative
Attacker objective: The objective is to gain durable access to development and release workflows so malicious code, stolen secrets, or manipulated dependencies can be pushed downstream at scale.
- Entry begins when attackers exploit weakly governed credentials or delegated access paths in AI-enabled development and supply chain environments.
- Escalation follows when machine identities, CI/CD permissions, or tool integrations are over-scoped and can be used to extend access across pipelines and repositories.
- Impact occurs when compromised delivery systems, exposed secrets, or manipulated build workflows propagate risk into production software and broader enterprise trust chains.
NHI Mgmt Group analysis
Agentic development is now an identity governance problem, not just an AppSec theme. Once AI systems can write and move code, the relevant control plane expands to include the identity of the agent, the scope of its tool access, and the lifecycle of the credentials it uses. That intersection is where IAM, PAM, and NHI governance now meet software delivery. Practitioners should treat agentic development sessions as architecture sessions for machine identities.
Conference selection is becoming a proxy for control maturity. The events that matter most are the ones that connect AI governance, supply chain assurance, and operational identity controls in a single agenda. That reflects the reality that teams cannot secure AI-enabled delivery with isolated policies or generic awareness. Practitioners should choose events that show how to enforce policy at runtime, not only how to describe the risk.
Software supply chain governance is converging with NHI lifecycle management. The article’s emphasis on CI/CD, provenance, and release workflows points to a broader truth: secrets, service accounts, and automation tokens are now part of the software factory’s trust chain. Secrets lifecycle debt: this is the control gap created when credentials live longer than the delivery processes that depend on them. Practitioners should use events to pressure-test rotation, offboarding, and auditability across pipelines.
Identity-based segmentation is the right lens for hybrid network visibility. Network tracks are increasingly discussing workload identity and application context because static network boundaries no longer describe how modern systems communicate. That does not replace network control, but it does change what good segmentation looks like. Practitioners should expect conference content to move toward identity-aware enforcement and away from address-based assumptions.
Specialist conferences now matter because they compress decision quality. The best gatherings are no longer the largest ones, but the ones that connect engineers, CISOs, regulators, and platform owners around an implementable problem. For teams under budget pressure, that means selecting events that improve control decisions, not just market awareness.
What this signals
Cybersecurity event planning now functions as a governance exercise. Teams that attend only broad flagship conferences risk leaving without the practical detail needed to control AI agents, pipeline identities, and release-time secrets. The more useful question is which sessions will change your operating model, not which ones will simply expand your reading list.
Secrets lifecycle debt: as agentic development spreads, the gap between where credentials live and where they are governed becomes a measurable source of risk. That is why the most valuable conference content will be the content that connects delivery workflows to identity controls and to standards such as the NIST AI Risk Management Framework and the OWASP Agentic AI Top 10.
Conferences that bring together AppSec, platform engineering, and identity teams will shape procurement, architecture, and training decisions for the next budget cycle. Practitioners should look for evidence that the event can help them reduce credential sprawl, clarify ownership, and improve policy enforcement across the software factory.
For practitioners
- Prioritise agentic development sessions over generic threat briefings Build your 2026 conference shortlist around events that cover AI agents, machine identity, and policy enforcement in the software factory. These are the sessions most likely to produce controls you can translate into IAM, PAM, and DevSecOps decisions.
- Use supply chain sessions to test your credential lifecycle assumptions Ask whether the agenda covers CI/CD secrets, build-system access, provenance verification, and offboarding of automation credentials. Those details matter more than vendor roadmaps when your team is trying to reduce blast radius.
- Compare conferences by implementation depth, not audience size Score events on whether they include hands-on workshops, peer roundtables, regulator participation, and cross-functional sessions with developers and security leaders. That is where reusable playbooks tend to emerge.
- Reserve one event for identity-aware network content If your team owns segmentation or hybrid visibility, include at least one conference that discusses identity-based segmentation and workload context. That keeps network strategy aligned with how modern services actually authenticate and communicate.
Key takeaways
- Cybersecurity conferences in 2026 are being judged by how well they explain agentic development, supply chain control, and identity governance.
- The strongest agendas are the ones that turn AI risk into operational decisions across code, credentials, and release workflows.
- Teams should select events for implementation depth, because broad awareness alone no longer closes the control gap.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | The article centres on agentic development and AI-driven software delivery. | |
| OWASP Non-Human Identity Top 10 | NHI-03 | The article repeatedly points to secrets, automation tokens, and CI/CD access as control concerns. |
| NIST AI RMF | GOVERN | AI governance is a recurring theme across the conference agenda changes described here. |
| NIST CSF 2.0 | PR.AC-4 | Conference themes emphasise access control, segmentation, and operational resilience. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0010 , Exfiltration | The article discusses supply chain and credential exposure risks that align with adversary behaviour. |
Use OWASP Agentic AI guidance to assess agent access, delegation, and tool-use controls in development workflows.
Key terms
- Agentic Development Lifecycle: The Agentic Development Lifecycle is the control pattern for building, approving, deploying, and reviewing AI agents before they reach production. It extends software change discipline into identity governance by requiring traceability for creation, access grants, business purpose, and ongoing oversight.
- Identity Segmentation: The practice of separating identities by workload, environment, and risk so one credential cannot easily move across unrelated systems. For machine identities, segmentation is a blast-radius control as much as a least-privilege measure, because shared dependencies can turn a single compromise into a wider operational event.
- Software Supply Chain: A software supply chain is the set of tools, identities, dependencies, and processes that turn source code into deployed software. Because it relies on automation and privileged machine identities, it becomes a governance problem when access, signing, and deployment controls are too broad.
- Secrets Lifecycle Debt: The accumulation of unmanaged credentials, tokens, keys, and certificates that persist beyond their intended use. It becomes a governance problem when secrets are stored in code or pipelines, remain valid after teams move on, or cannot be offboarded and rotated quickly enough.
What's in the full article
Cycode's full blog covers the operational detail this post intentionally leaves for the source:
- Conference-by-conference notes on speaker mix, audience fit, and which event types are better for AppSec, product security, or executive networking.
- The specific agenda themes Cycode highlights for RSAC, Black Hat, OWASP Global AppSec, and specialist events.
- Practical guidance on virtual tiers, live Q&A, and on-demand formats that affect how teams use conference content.
- Cycode's own conference and summit priorities, including the Agentic Development Security Summit and related programming.
👉 Cycode’s full post adds the event-by-event breakdown and attendance guidance for security teams.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the broader security programmes their teams already run.
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org