
ISC2 Silicon Valley - September 2026 Chapter Meeting
Description
๐ Hybrid meeting โ Palo Alto Networks HQ, Santa Clara + Zoom ๐ This month's meeting is generously hosted and sponsored by Palo Alto Networks. Join the ISC2 Silicon Valley Chapter for our September 2026 meeting. Identity is the control plane now, and agents are the thing straining it โ acting continuously, carrying borrowed authority, and gathering privilege faster than anyone planned for. This month we're taking that from both ends: how to hold the line in the cloud environments you already run, and how the underlying authorization model has to change when the requester isn't a human logging in. ๐ค Session 1 | Cloud Privilege is on Fire, and Agents are Gasoline: Facing Uncomfortable Truths in Identity Security Matt Carle, Head of Product, Sonrai Security The move to cloud promised better identity security than we'd ever had. The hyperscalers built powerful IAM, but it proved confusing to operate, and development spawned far more identities than anyone planned for. Scale won, and stolen credentials are now the primary route into cloud environments. Agents are the next scale shock โ a wave of identities that gather privilege relentlessly in service of finishing the task, whatever it costs. Gas on a fire that's been growing for years. AWS, GCP, and Azure IAM remain powerful, byzantine, and underused. Draconian zero-standing-privilege programs and thousands of policy edits won't survive contact with a brownfield environment โ workloads break and developers stop cooperating. Matt makes the case for a guardrails-first approach: enforce at the organization boundary instead of per identity, define least privilege by permission sensitivity, and give every identity โ human and non-human โ a path back to access that doesn't disrupt existing developer workflows. Attendees will be able to compare organization-level guardrail primitives across AWS, Azure, and GCP (SCPs and RCPs, Azure RBAC and Entra, GCP IAM deny policies) and identify where each breaks down at enterprise scale; evaluate why non-human identities โ service principals, CI/CD pipelines, AI agents โ fall outside request-based access programs, and what a control model that actually covers them has to do differently; and apply a risk-weighted definition of least privilege, based on permission sensitivity and observed usage rather than policy completeness, to sequence enforcement without disrupting workloads. About the Speaker Matthew Carle is the Head of Product at Sonrai Security, previously holding senior roles at Noetic Cyber and Patriot One Technologies, and was a World Wide Product Manager at IBM. ๐ค Session 2 | Agentic Identity & Access Management โ From IAM to AIAM Harrison Tang, Co-Founder & COO, Spokeo IAM was built for humans who log in. AI agents break that model three ways at once: they act continuously and autonomously, they carry borrowed authority delegated from humans and other agents, and the content they read can redirect what they do โ because an LLM's context window draws no line between instructions and data. Harrison starts from how an LLM agent actually works, shows why prompt injection is a structural property rather than a patchable bug, and rebuilds IAM around a different question: not "who are you?" but "may this specific request be honored?" Expect access-matrix fundamentals, capability-based authorization, verifiable credentials, verifiable delegation chains, and where the W3C, DIF, and IETF standards are heading. About the Speaker Harrison Tang is an entrepreneur and technology executive who co-founded Spokeo in 2006 and currently serves as its COO. He was named Ernst & Young Entrepreneur of the Year in Los Angeles in 2015, and Spokeo has been recognized by Forbes, Deloitte, Inc., and the Los Angeles Business Journal. He previously served as Co-Chair of the W3C Credentials Community Group and as Chairman of the Monte Jade Science and Technology Association of Southern California. A recognized thought leader in data and technology, Harrison has been featured in the Wall Street Journal, Consumer Reports, and the LA Times, and has spoken at CES, DataCon LA, and other technology and data conferences. Originally from Taiwan, Harrison moved to Silicon Valley at age 13. He holds bachelor's degrees in Economics and Electrical Engineering and a master's degree in Electrical Engineering from Stanford University. ๐ Event Details ๐ Date: September 08, 2026โฐ Time: 6:00 PM โ 8:00 PM PT ๐ Format: In-person & Zoom๐ Education: CPE-eligible ๐ข Venue Palo Alto Networks3000 Tannery Way, Santa Clara, CA 95054Building 3, 2nd FloorSC3.2.415 Multi-purpose Room 16SC3.2.417 Multi-purpose Room 17 ๐ ฟ๏ธ Parking is available in P1 South and in the lot between Buildings 1 and 3. A campus map will be shared with registrants.๐ป Can't make it in person?This month's meeting is hybrid. Join us on Zoom:https://us06web.zoom.us/j/82363587569Remote attendees are CPE-eligible โ stay for the full session and email the board to have your CPEs recorded. ๐ Help spread the word โ repost and invite your network across the cyber community ๐ค Join the Community: https://forms.gle/DHMUh2uh4F5sjPXv6 ๐๏ธ Speaker Opportunities โ Open Call ISC2 Silicon Valley is booking sessions through Q4 2026, and we're opening the mic to the wider cybersecurity community. Not an ISC2 member? Doesn't matter. If you've got something worth sharing, we want you on our stage. Hard-won lessons. Fresh research. War stories you can finally talk about. First-time speakers and seasoned presenters all welcome. โฑ๏ธ Up to 40 minutes + Q&A ๐ In-person at our monthly meeting ๐ CPE-eligible for attendees ๐ฉ Submit your pitch โ
Event location
Let your network know you`re going
Share this event to start conversations, invite colleagues, and connect before it begins.