Events

A GRC Engineer's Guide to BSides Augusta 2026

Our recommended path through Tracks 1, 2, and 3

A curated conference companion for GRC practitioners and people interested in GRC Engineering at BSides Augusta 2026.

A conference is more than a schedule of talks.

For most practitioners, some of the greatest value comes from the people you meet, the ideas you discover, and the topics you decide to explore after you get home.

A 30- or 60-minute conference session can introduce you to a new problem, tool, technique, or area of expertise. It usually will not make you an expert. Take notes. Ask questions. Save things to research later. And leave room in your day to meet people.

BSides Augusta is a cybersecurity conference, not a GRC Engineering conference. That is part of what makes it useful. We get to see what practitioners across the security industry are building, attacking, defending, and thinking about, then ask what those developments mean for governance, risk, compliance, and assurance.

We went through Tracks 1, 2, and 3 and built a recommended path for GRC practitioners and people interested in GRC Engineering. You do not have to follow it exactly. When two sessions offer different kinds of value, we will help you choose.

And during the breaks, look for the orange GRC flag. Come introduce yourself, compare notes, or talk GRC Engineering with Dwight and other practitioners following the guide.

This guide is editorial guidance from the Atlanta and Augusta GRC Engineering chapters. It is not official BSides Augusta programming. Session facts below come from the official Pretalx schedule, which remains the source of truth and may change.

Recommended path

BSides Augusta 2026 GRC Engineering path

  1. 9:00 AM10:00 AM
    RecommendedKeynote

    Keynote - Tim Kosiba

    Tim Kosiba

    What you'll hear

    NSA Deputy Director Tim Kosiba opens the conference in Track 1, simulcast to Tracks 2 and 3.

    Reasons to attend

    Everyone starts here for shared context before track-specific sessions.

  2. 10:00 AM11:00 AM
    Best ChoiceTrack 2

    Ai-pocalypse

    Tim Crothers

    What you'll hear

    What defenders can actually do with AI today, and what that means for security teams sorting through the current tooling wave.

    Reasons to attend

    Best GRC Engineering fit in this slot for separating AI signal from noise.

  3. 11:00 AM11:15 AM

    Hallway Con

    Find the orange GRC flag. Come introduce yourself and talk GRC Engineering with Dwight and others following the guide.

  4. 11:15 AM11:45 AM
    Best ChoiceTrack 1

    Your AI Agent Takes Orders From Strangers: Prompt Injection and the Path to Governing Agents

    Steven Jung

    What you'll hear

    How prompt injection shows up in enterprise agents and what security teams need as agents read email, browse, and act autonomously.

    Reasons to attend

    Strong GRC crossover on governance, approvals, auditability, and inventory.

  5. 11:45 AM12:45 PM

    Lunch

    Find the orange GRC flag. Compare morning sessions with Dwight and other practitioners, or just sit down and talk.

  6. 12:45 PM1:45 PM

    Choose your session

    Best ChoiceTrack 1

    Hands, Eyes & Memory: - A Live Progressive Demo From Stateless Chatbot to Fully Agentic AI

    Mark Baggett

    What you'll hear

    A live walkthrough from a simple chat script to memory, context handling, and agentic behavior in Python.

    Reasons to attend

    Strong pick if you want a practical picture of how agentic systems are built.

    Overlaps with Know Thy Extensions at 12:45 PM — you cannot attend both openings.

    AlternativeTrack 3

    Know Thy Extensions: Governing the Browser Attack Surface in the Enterprise

    Zach Schrag, JD Delgado

    What you'll hear

    Moving from invisible browser extensions to an allow-list posture with a practical approval workflow.

    Reasons to attend

    A concrete example of governance as technical control design.

    Continues at 1:15 PM with Attacks and Defenses for Multi-Agent AI Systems.

  7. 1:15 PM1:45 PM

    Track 3 path continues at 1:15 PM

    RecommendedTrack 3

    Attacks and Defenses for Multi-Agent AI Systems

    Moazzam Khan

    What you'll hear

    Attacker-focused look at multi-agent environments: prompt injection, RAG poisoning, tool abuse, and privilege escalation.

    Reasons to attend

    Useful for understanding compromise paths beyond single-agent threat models.

    Track 3 path only. Hands, Eyes & Memory runs in Track 1 until 1:45 PM.

  8. 1:45 PM2:15 PM
    RecommendedTrack 3

    The Intelligence-Driven Advantage: A Practical Guide to Building CTI Into Your Security Program

    Timothy De Block

    What you'll hear

    Pragmatic CTI as a force multiplier, emphasizing actionable context over indicator feeds alone.

    Reasons to attend

    Helps translate intelligence into prioritization leadership can act on.

  9. 2:15 PM2:45 PM

    Choose your session

    Best ChoiceTrack 2

    The Sector Everyone Ignores: Why K-12 Is Critical Infrastructure and What We Can Learn From It

    Eric Logan

    What you'll hear

    Why K-12 deserves enterprise-level risk treatment despite constrained staffing and sensitive data.

    Reasons to attend

    Strong fit for governance, institutional risk, and security under resource limits.

    AlternativeTrack 3

    More Human Than Human: Why the Skills AI Can't Replicate Are the Ones We Stopped Teaching

    George Sandford

    What you'll hear

    Burnout, mentoring gaps, and human skills that remain essential as teams adopt more AI tooling.

    Reasons to attend

    Useful counterpoint if your goals lean toward people leadership over sector risk.

  10. 2:45 PM3:00 PM

    Hallway Con

    Find the orange GRC flag. Compare afternoon sessions with Dwight and others, or plan the last block together.

  11. 3:00 PM4:00 PM
    Best ChoiceTrack 3

    Pocketful of Control Planes: Attack Chains Against Agentic AI (and How to Kill Them)

    david a girivn

    What you'll hear

    Real attack chains against agentic systems: tool chaining, credential bleed, autonomy drift, and pivot paths.

    Reasons to attend

    One of the strongest sessions on how agentic systems fail beyond traditional controls.

  12. 4:00 PM5:00 PM

    Choose your session

    Best ChoiceTrack 1

    Hold My Coffee, I'm Building a Security Tool": Security Without Gatekeepers in an AI-First World

    David J. Bianco, Tamara Chacon

    What you'll hear

    How AI-assisted development lowers the barrier to building security tools outside a formal engineering queue.

    Reasons to attend

    Strong close for GRC Engineering as a building discipline.

    AlternativeTrack 2

    HOW I HACKED THE DOD (by accident) AND SAVED THEM BILLIONS

    Jared Hrabak

    What you'll hear

    How a routine records review exposed IDOR flaws and broad access control failures in a DoD personnel system.

    Reasons to attend

    Classic assurance story about overprivileged access and control design.

  13. 5:00 PM

    Community Dinner

    A small post-conference dinner with members from both the Augusta and Atlanta chapters. Location and RSVP details coming soon.

Before you go

Keep up with the chapter

More from the A.

Browse other updates, explore events, or join the roster to hear what the Atlanta chapter is building next.