A conference is more than a schedule of talks.
For most practitioners, some of the greatest value comes from the people you meet, the ideas you discover, and the topics you decide to explore after you get home.
A 30- or 60-minute conference session can introduce you to a new problem, tool, technique, or area of expertise. It usually will not make you an expert. Take notes. Ask questions. Save things to research later. And leave room in your day to meet people.
BSides Augusta is a cybersecurity conference, not a GRC Engineering conference. That is part of what makes it useful. We get to see what practitioners across the security industry are building, attacking, defending, and thinking about, then ask what those developments mean for governance, risk, compliance, and assurance.
We went through Tracks 1, 2, and 3 and built a recommended path for GRC practitioners and people interested in GRC Engineering. You do not have to follow it exactly. When two sessions offer different kinds of value, we will help you choose.
And during the breaks, look for the orange GRC flag. Come introduce yourself, compare notes, or talk GRC Engineering with Dwight and other practitioners following the guide.
This guide is editorial guidance from the Atlanta and Augusta GRC Engineering chapters. It is not official BSides Augusta programming. Session facts below come from the official Pretalx schedule, which remains the source of truth and may change.
Recommended path
BSides Augusta 2026 GRC Engineering path
- 9:00 AM10:00 AM
Keynote - Tim Kosiba
Tim Kosiba
What you'll hear
NSA Deputy Director Tim Kosiba opens the conference in Track 1, simulcast to Tracks 2 and 3.
Reasons to attend
Everyone starts here for shared context before track-specific sessions.
- 10:00 AM11:00 AM
Ai-pocalypse
Tim Crothers
What you'll hear
What defenders can actually do with AI today, and what that means for security teams sorting through the current tooling wave.
Reasons to attend
Best GRC Engineering fit in this slot for separating AI signal from noise.
- 11:00 AM11:15 AM
Hallway Con
Find the orange GRC flag. Come introduce yourself and talk GRC Engineering with Dwight and others following the guide.
- 11:15 AM11:45 AM
Your AI Agent Takes Orders From Strangers: Prompt Injection and the Path to Governing Agents
Steven Jung
What you'll hear
How prompt injection shows up in enterprise agents and what security teams need as agents read email, browse, and act autonomously.
Reasons to attend
Strong GRC crossover on governance, approvals, auditability, and inventory.
- 11:45 AM12:45 PM
Lunch
Find the orange GRC flag. Compare morning sessions with Dwight and other practitioners, or just sit down and talk.
- 12:45 PM1:45 PM
Choose your session
Hands, Eyes & Memory: - A Live Progressive Demo From Stateless Chatbot to Fully Agentic AI
Mark Baggett
What you'll hear
A live walkthrough from a simple chat script to memory, context handling, and agentic behavior in Python.
Reasons to attend
Strong pick if you want a practical picture of how agentic systems are built.
Overlaps with Know Thy Extensions at 12:45 PM — you cannot attend both openings.
Know Thy Extensions: Governing the Browser Attack Surface in the Enterprise
Zach Schrag, JD Delgado
What you'll hear
Moving from invisible browser extensions to an allow-list posture with a practical approval workflow.
Reasons to attend
A concrete example of governance as technical control design.
Continues at 1:15 PM with Attacks and Defenses for Multi-Agent AI Systems.
- 1:15 PM1:45 PM
Track 3 path continues at 1:15 PM →
Attacks and Defenses for Multi-Agent AI Systems
Moazzam Khan
What you'll hear
Attacker-focused look at multi-agent environments: prompt injection, RAG poisoning, tool abuse, and privilege escalation.
Reasons to attend
Useful for understanding compromise paths beyond single-agent threat models.
Track 3 path only. Hands, Eyes & Memory runs in Track 1 until 1:45 PM.
- 1:45 PM2:15 PM
The Intelligence-Driven Advantage: A Practical Guide to Building CTI Into Your Security Program
Timothy De Block
What you'll hear
Pragmatic CTI as a force multiplier, emphasizing actionable context over indicator feeds alone.
Reasons to attend
Helps translate intelligence into prioritization leadership can act on.
- 2:15 PM2:45 PM
Choose your session
The Sector Everyone Ignores: Why K-12 Is Critical Infrastructure and What We Can Learn From It
Eric Logan
What you'll hear
Why K-12 deserves enterprise-level risk treatment despite constrained staffing and sensitive data.
Reasons to attend
Strong fit for governance, institutional risk, and security under resource limits.
More Human Than Human: Why the Skills AI Can't Replicate Are the Ones We Stopped Teaching
George Sandford
What you'll hear
Burnout, mentoring gaps, and human skills that remain essential as teams adopt more AI tooling.
Reasons to attend
Useful counterpoint if your goals lean toward people leadership over sector risk.
- 2:45 PM3:00 PM
Hallway Con
Find the orange GRC flag. Compare afternoon sessions with Dwight and others, or plan the last block together.
- 3:00 PM4:00 PM
Pocketful of Control Planes: Attack Chains Against Agentic AI (and How to Kill Them)
david a girivn
What you'll hear
Real attack chains against agentic systems: tool chaining, credential bleed, autonomy drift, and pivot paths.
Reasons to attend
One of the strongest sessions on how agentic systems fail beyond traditional controls.
- 4:00 PM5:00 PM
Choose your session
Hold My Coffee, I'm Building a Security Tool": Security Without Gatekeepers in an AI-First World
David J. Bianco, Tamara Chacon
What you'll hear
How AI-assisted development lowers the barrier to building security tools outside a formal engineering queue.
Reasons to attend
Strong close for GRC Engineering as a building discipline.
HOW I HACKED THE DOD (by accident) AND SAVED THEM BILLIONS
Jared Hrabak
What you'll hear
How a routine records review exposed IDOR flaws and broad access control failures in a DoD personnel system.
Reasons to attend
Classic assurance story about overprivileged access and control design.
- 5:00 PM
Community Dinner
A small post-conference dinner with members from both the Augusta and Atlanta chapters. Location and RSVP details coming soon.
Before you go
- Review the official BSides Augusta schedule for room changes and updates.
- See the BSides Augusta 2026 event listing for date, location, and organizer details.
- Bring questions. Some of the best conference value still happens in the hallway.