National CISO Policy Conference 2026
National Technology Security Coalition

National CISO
Policy Conference 2026

A Public-Private Partnership "Where security leaders shape policy, strategy, and the future of cybersecurity."

Wednesday, July 15 | Washington, D.C.
8:00 AM – 5:00 PM ET

Strategic Focus Areas

The AI Agenda

Establishing executive policy for AI-driven security operations and robust defense frameworks to secure the enterprise against AI-augmented threats.

Quantum Resilience

Navigating the transition to post-quantum cryptography and preparing national infrastructure for the cryptographic challenges of the next decade.

Legislative Advocacy

Ensuring the voice of the Enterprise CISO remains central to federal cyber policy, CIRCIA reporting, and national security mandates.

Wednesday, July 15

Conference Agenda

Session Titles & Speaker Assignments Forthcoming

8:00 AM

Registration & Check-In | Breakfast

Check-in and networking breakfast.

9:00 AM

Welcome & Introductions

9:15 AM

Quantum Risk, Policy, and National Security

A candid discussion with Dick Clarke on quantum computing and its implications for cybersecurity, public policy, and national security. The conversation will examine how organizations are approaching post-quantum risk management, from crypto-agility and migration roadmaps to emergency transition planning, incident response readiness, and board-level alignment around the strategic consequences of Y2Q.

10:15 AM

Living in Risk

The current state of risk is a board-level discussion.

From today’s geopolitical climate to the accelerating pace of technological change, how organizations understand and respond to risk is evolving.

In this presentation, Katherine Kuehn will review the top challenges and opportunities facing boards and consider how the risk narrative may need to change over the next several years. The discussion will address the use of cyber capabilities in warfare, the impact of frontier models, how to align risk with board objectives, and the evolving role of the CISO.

11:00 AM

Break

11:30 AM

Risk-Based Resilience: What CISOs Should Expect Next

A forward-looking fireside chat with Nick Andersen, CISA's Acting Director and Deputy Director, on what private-sector CISOs should expect from the evolving threat environment and from the federal government. The conversation will examine how security leaders should prioritize critical assets, exposed vulnerabilities, operational dependencies, and continuity planning in an environment shaped by faster adversaries, near-term AI advances, and persistent nation-state activity.

The discussion will address where current approaches to cyber defense and governance need to evolve, including how industry should prepare for federal incident reporting requirements, how CISA support and programs such as CI Fortify can help reduce operational risk, and what effective government-industry collaboration should look like during a crisis. The conversation will also examine what the public-private partnership should look like going forward as CISA advances vulnerability prioritization, builds new coordination structures, and works with industry to improve resilience rather than information sharing alone.

12:30 PM

Lunch

1:30 PM

Fireside Chat: The Future of the CVE Ecosystem: Incentives, Speed, and the Post-AI Era

For decades, the Common Vulnerabilities and Exposures (CVE) program has served as a cornerstone of global vulnerability management. Today, exponential growth in reported vulnerabilities, increasing ecosystem fragmentation, and the rapid adoption of AI are placing unprecedented pressure on the system.

In this fireside chat, Jay Gazlay, Deputy Associate Director for Vulnerability Management, CISA, will discuss how the CVE ecosystem must evolve to remain trusted, scalable, and effective. The conversation will explore the incentives and participant behaviors shaping the system, the safeguards needed to preserve its integrity, and the operational and governance changes required to support practitioners, policymakers, and industry partners.

The discussion will also examine what vulnerability management looks like in an AI-accelerated threat landscape, where adversaries increasingly operate at machine speed. Gazlay will address the growing demands for speed, scale, coordination, and safe harbor—and how public- and private-sector leaders can work together to prepare the CVE ecosystem for the post-AI era.

2:00 PM

AI Security and Governance in the Covered Model Era — Panel Discussion

As covered models reshape the risk landscape, many existing security policies, governance frameworks, and regulatory assumptions are being tested. This panel will examine which approaches are no longer practical, where policy and legislation need to evolve, and what effective oversight should look like in practice. Panelists will discuss how leaders can balance innovation, accountability, and security while building governance models that are clear, enforceable, and fit for today's operational realities.

3:10 PM

Break

3:25 PM

Cyber Regulation in Practice: Aligning Architecture, Intent, and Outcomes

A fireside chat with Rear Admiral (Ret.) Mark Montgomery on the evolution of U.S. cybersecurity strategy, regulation, and resilience across the public and private sectors. Building from the Cyberspace Solarium Commission’s landmark March 2020 report and its vision of layered cyber deterrence, the discussion will examine how the original strategy has translated into practice: where implementation has advanced, where gaps remain, and where policy, regulation, and operational reality are still misaligned. The conversation will also explore whether that original vision remains fit for purpose in today’s threat environment, including the accelerating impact of AI, agentic systems, software supply-chain risk, critical infrastructure exposure, and increasingly sophisticated nation-state and criminal activity.

Drawing on policy, operational, and private-sector perspectives, the fireside chat will address what must change next: how the U.S. government can better enable resilience, how regulation can more effectively connect strategic intent with practical outcomes, and how private-sector leaders—especially CISOs—can help shape the next phase of national cyber defense.

4:25 PM

Closing Remarks

5:30 PM

Dinner at the Oceanaire Seafood Room

The Executive Cohort

Registration is strictly limited to Fortune 1000 CISOs, Federal Policy Makers, and approved invited guests. Solution providers, vendors, consultants, and sales representatives are not permitted. This closed-door forum is designed for candid strategy development among security and policy leaders.

Request to Attend

Registration is strictly limited to Fortune 1000 CISOs and Federal Policy Makers.

Dress Code: Business Casual

Initializing Secure Registration Form...

National Technology Security Coalition © 2026