Events

A GRC Engineer's Guide to BSides Augusta 2026

Our recommended path through Tracks 1, 2, and 3. A curated conference companion for GRC practitioners and people interested in GRC Engineering at BSides Augusta 2026.

A conference day is bigger than the talks on the grid.

For most practitioners, the lasting value is the people you meet, the ideas you notice, and the topics you decide to go study after you get home.

A 30- or 60-minute session can put a new problem, tool, or technique in front of you. It will not make you an expert. Take notes. Ask questions. Save things to research later. And leave space in the day to meet people.

BSides is a cybersecurity conference. We are not walking it as spectators. Watch what people are building, attacking, and defending, then ask what it means for governance, risk, compliance, and assurance.

The path below is our GRC cut through Tracks 1, 2, and 3. You do not have to follow it exactly. When two sessions offer different kinds of value, we will help you choose.

During the breaks, look for the orange GRC flag. Come introduce yourself, compare notes, or talk GRC Engineering with Danielle Koppel, Toyeeb Atanda, and other practitioners following the guide.

This guide is editorial guidance from GRC Engineering Club Augusta. It is not official BSides Augusta programming. Session facts below come from the official Pretalx schedule, which remains the source of truth and may change.

Recommended path

BSides Augusta 2026 GRC Engineering path

  1. 9:00 AM10:00 AM

    RecommendedKeynote

    Keynote - Tim Kosiba

    Tim Kosiba

    What you'll hear

    NSA Deputy Director Tim Kosiba opens the day in Track 1, with a simulcast into the other rooms.

    Reasons to attend

    Start with the same context as everyone else before the tracks split.

  2. 10:00 AM11:00 AM

    Best ChoiceTrack 2

    Ai-pocalypse

    Tim Crothers

    What you'll hear

    A data-first look at what AI can and cannot do for defenders, without the usual hype cycle.

    Reasons to attend

    The strongest GRC Engineering fit in this hour for telling usable AI practice from noise.

  3. 11:00 AM11:15 AM

    Hallway Con

    Find the orange GRC flag. Come introduce yourself and talk GRC Engineering with Danielle, Toyeeb, and others following the guide.

  4. 11:15 AM11:45 AM

    Best ChoiceTrack 1

    Your AI Agent Takes Orders From Strangers: Prompt Injection and the Path to Governing Agents

    Steven Jung

    What you'll hear

    How prompt injection shows up once enterprise agents read mail, browse, query systems, and act on their own — and what security needs before leadership ships them.

    Reasons to attend

    Direct GRC overlap: governance, approvals, inventory, and whether the agent is auditable.

  5. 11:45 AM12:45 PM

    Lunch

    Find the orange GRC flag. Compare morning sessions with Danielle, Toyeeb, and other practitioners, or just sit down and talk.

  6. 12:45 PM1:45 PM

    Choose your session

    Best ChoiceTrack 1

    Hands, Eyes & Memory: A Live Progressive Demo From Stateless Chatbot to Fully Agentic AI

    Mark Baggett

    What you'll hear

    A live Python walkthrough from a memory-less chat script to context, memory, and fully agentic behavior.

    Reasons to attend

    Pick this if you want to see how agentic systems are actually assembled.

    Overlaps with Know Thy Extensions at 12:45 PM — you cannot attend both openings.

    AlternativeTrack 3

    Know Thy Extensions: Governing the Browser Attack Surface in the Enterprise

    Zach Schrag, JD Delgado

    What you'll hear

    How invisible Chrome extensions become an enterprise control problem, and what an allow-list with a real approval workflow looks like.

    Reasons to attend

    A concrete case of governance as technical control design.

    Continues at 1:15 PM with Attacks and Defenses for Multi-Agent AI Systems.

  7. 1:15 PM1:45 PM

    RecommendedTrack 3

    Attacks and Defenses for Multi-Agent AI Systems

    Moazzam Khan

    What you'll hear

    An attacker view of multi-agent environments: prompt injection, RAG poisoning, tool abuse, privilege escalation, and data leaving the intended boundary.

    Reasons to attend

    Useful if you need compromise paths that go beyond a single-agent threat model.

    Track 3 path only. Hands, Eyes & Memory runs in Track 1 until 1:45 PM.

  8. 1:45 PM2:15 PM

    RecommendedTrack 3

    The Intelligence-Driven Advantage: A Practical Guide to Building CTI Into Your Security Program

    Timothy De Block

    What you'll hear

    Treat CTI as a force multiplier: actionable context leadership can use, not another indicator feed.

    Reasons to attend

    Helps turn intelligence into prioritization and risk decisions, not just detections.

  9. 2:15 PM2:45 PM

    Choose your session

    Best ChoiceTrack 2

    The Sector Everyone Ignores: Why K-12 Is Critical Infrastructure and What We Can Learn From It

    Eric Logan

    What you'll hear

    K-12 as an enterprise network with sensitive data, thin staffing, and a security problem that still gets treated like a side obligation.

    Reasons to attend

    Strong fit if you care about governance, institutional risk, and controls under resource limits.

    AlternativeTrack 3

    More Human Than Human: Why the Skills AI Can't Replicate Are the Ones We Stopped Teaching

    George Sandford

    What you'll hear

    Burnout, mentoring gaps, and the human skills that still matter as teams lean harder on AI tooling.

    Reasons to attend

    The better pick if your goal for the hour is people leadership, not sector risk.

  10. 2:45 PM3:00 PM

    Hallway Con

    Find the orange GRC flag. Compare afternoon sessions with Danielle, Toyeeb, and others, or plan the last block together.

  11. 3:00 PM4:00 PM

    Best ChoiceTrack 3

    Pocketful of Control Planes: Attack Chains Against Agentic AI (and How to Kill Them)

    david a girivn

    What you'll hear

    Attack chains against agentic systems: tool chaining, credential bleed, autonomy drift, and pivot paths that old controls were not built for.

    Reasons to attend

    One of the strongest hours on how agentic systems fail past traditional assurance.

  12. 4:00 PM5:00 PM

    Choose your session

    Best ChoiceTrack 1

    Hold My Coffee, I'm Building a Security Tool": Security Without Gatekeepers in an AI-First World

    David J. Bianco, Tamara Chacon

    What you'll hear

    How AI-assisted development lets practitioners build security tools outside a formal engineering queue — and what that does to review, ownership, and risk.

    Reasons to attend

    A strong close if you treat GRC Engineering as a building discipline.

    AlternativeTrack 2

    HOW I HACKED THE DOD (by accident) AND SAVED THEM BILLIONS

    Jared Hrabak

    What you'll hear

    A routine look at promotion records in a DoD web app that exposed IDOR flaws and wide-open access control in a personnel system.

    Reasons to attend

    A classic assurance story: overprivileged access, weak control design, and what a records review actually found.

  13. 5:00 PM

    Community Dinner

    A small post-conference dinner with the Augusta and Atlanta chapters at Tacocat, 208 10th St. RSVP at luma.com/te14hf4f by Friday, October 16.

Before you go

Keep up with the chapter

More from the Cyber City.

Browse other events, explore the Field Guide, or join the roster to hear what the Augusta chapter is building next.