Keynote - Tim Kosiba
Tim Kosiba
What you'll hear
NSA Deputy Director Tim Kosiba opens the day in Track 1, with a simulcast into the other rooms.
Reasons to attend
Start with the same context as everyone else before the tracks split.
Events
Our recommended path through Tracks 1, 2, and 3. A curated conference companion for GRC practitioners and people interested in GRC Engineering at BSides Augusta 2026.
A conference day is bigger than the talks on the grid.
For most practitioners, the lasting value is the people you meet, the ideas you notice, and the topics you decide to go study after you get home.
A 30- or 60-minute session can put a new problem, tool, or technique in front of you. It will not make you an expert. Take notes. Ask questions. Save things to research later. And leave space in the day to meet people.
BSides is a cybersecurity conference. We are not walking it as spectators. Watch what people are building, attacking, and defending, then ask what it means for governance, risk, compliance, and assurance.
The path below is our GRC cut through Tracks 1, 2, and 3. You do not have to follow it exactly. When two sessions offer different kinds of value, we will help you choose.
During the breaks, look for the orange GRC flag. Come introduce yourself, compare notes, or talk GRC Engineering with Danielle Koppel, Toyeeb Atanda, and other practitioners following the guide.
This guide is editorial guidance from GRC Engineering Club Augusta. It is not official BSides Augusta programming. Session facts below come from the official Pretalx schedule, which remains the source of truth and may change.
Recommended path
9:00 AM10:00 AM
Tim Kosiba
What you'll hear
NSA Deputy Director Tim Kosiba opens the day in Track 1, with a simulcast into the other rooms.
Reasons to attend
Start with the same context as everyone else before the tracks split.
10:00 AM11:00 AM
Tim Crothers
What you'll hear
A data-first look at what AI can and cannot do for defenders, without the usual hype cycle.
Reasons to attend
The strongest GRC Engineering fit in this hour for telling usable AI practice from noise.
11:00 AM11:15 AM
Find the orange GRC flag. Come introduce yourself and talk GRC Engineering with Danielle, Toyeeb, and others following the guide.
11:15 AM11:45 AM
Steven Jung
What you'll hear
How prompt injection shows up once enterprise agents read mail, browse, query systems, and act on their own — and what security needs before leadership ships them.
Reasons to attend
Direct GRC overlap: governance, approvals, inventory, and whether the agent is auditable.
11:45 AM12:45 PM
Find the orange GRC flag. Compare morning sessions with Danielle, Toyeeb, and other practitioners, or just sit down and talk.
12:45 PM1:45 PM
Choose your session
Mark Baggett
What you'll hear
A live Python walkthrough from a memory-less chat script to context, memory, and fully agentic behavior.
Reasons to attend
Pick this if you want to see how agentic systems are actually assembled.
Overlaps with Know Thy Extensions at 12:45 PM — you cannot attend both openings.
Zach Schrag, JD Delgado
What you'll hear
How invisible Chrome extensions become an enterprise control problem, and what an allow-list with a real approval workflow looks like.
Reasons to attend
A concrete case of governance as technical control design.
Continues at 1:15 PM with Attacks and Defenses for Multi-Agent AI Systems.
1:15 PM1:45 PM
Moazzam Khan
What you'll hear
An attacker view of multi-agent environments: prompt injection, RAG poisoning, tool abuse, privilege escalation, and data leaving the intended boundary.
Reasons to attend
Useful if you need compromise paths that go beyond a single-agent threat model.
Track 3 path only. Hands, Eyes & Memory runs in Track 1 until 1:45 PM.
1:45 PM2:15 PM
Timothy De Block
What you'll hear
Treat CTI as a force multiplier: actionable context leadership can use, not another indicator feed.
Reasons to attend
Helps turn intelligence into prioritization and risk decisions, not just detections.
2:15 PM2:45 PM
Choose your session
Eric Logan
What you'll hear
K-12 as an enterprise network with sensitive data, thin staffing, and a security problem that still gets treated like a side obligation.
Reasons to attend
Strong fit if you care about governance, institutional risk, and controls under resource limits.
George Sandford
What you'll hear
Burnout, mentoring gaps, and the human skills that still matter as teams lean harder on AI tooling.
Reasons to attend
The better pick if your goal for the hour is people leadership, not sector risk.
2:45 PM3:00 PM
Find the orange GRC flag. Compare afternoon sessions with Danielle, Toyeeb, and others, or plan the last block together.
3:00 PM4:00 PM
david a girivn
What you'll hear
Attack chains against agentic systems: tool chaining, credential bleed, autonomy drift, and pivot paths that old controls were not built for.
Reasons to attend
One of the strongest hours on how agentic systems fail past traditional assurance.
4:00 PM5:00 PM
Choose your session
David J. Bianco, Tamara Chacon
What you'll hear
How AI-assisted development lets practitioners build security tools outside a formal engineering queue — and what that does to review, ownership, and risk.
Reasons to attend
A strong close if you treat GRC Engineering as a building discipline.
Jared Hrabak
What you'll hear
A routine look at promotion records in a DoD web app that exposed IDOR flaws and wide-open access control in a personnel system.
Reasons to attend
A classic assurance story: overprivileged access, weak control design, and what a records review actually found.
5:00 PM
A small post-conference dinner with the Augusta and Atlanta chapters at Tacocat, 208 10th St. RSVP at luma.com/te14hf4f by Friday, October 16.
Keep up with the chapter
Browse other events, explore the Field Guide, or join the roster to hear what the Augusta chapter is building next.