Humans and AI agents now share access, data, and decisions. HRMCon 2026 brings together the CISOs and practitioners redefining Human Risk Management for that reality — one day, 16 speakers.
Registration
Free to attend. In-person seating at The UT Club is limited — virtual seats are unlimited.
Why attend
CISOs and security leaders from Fortune 500 enterprises walk through what worked, what stalled, and the numbers they took to their executives.
Every session ships something usable. You leave with:
Forrester's independent market update, the platform unveiling, and a look at 2030 — when prevention tunes itself but accountability still doesn't.
See the sessions
The 2026 line-up
Select any speaker to read their background.
Agenda · September 10
Eleven sessions, breaks built for actual conversation, and dinner with an open bar to close.
Organizations now secure a workforce of both people and AI agents. As identities multiply and autonomous systems take on more work, traditional approaches to measuring human risk fall short. Ashley Rose opens with a vision for the next chapter of workforce security — why measurable incident reduction is replacing activity metrics, and what the unified workforce demands.
AI is reshaping the threat landscape with deepfakes, AI-powered social engineering, and increasingly sophisticated attacks. Forrester VP and Principal Analyst Jinan Budge delivers an independent market update on how buyer priorities are changing, where organizations are investing, and what security leaders should expect as the category matures.
Attacks have evolved beyond email — collaboration tools, messaging platforms, and AI agents create new pathways to compromise. Through live demonstrations you'll experience the next generation of the Living Security Platform, including a first look at a new capability that redefines how organizations identify, prioritize, and reduce workforce risk.
Security focuses on incidents, identity teams on access, compliance on policy. When stakeholders don't agree on the problem, progress stalls before the work begins. This roundtable explores aligning around one clearly defined enemy, one named incident, and a shared set of measurable outcomes — including the growing question of who is accountable when the riskiest identity is an AI agent.
An honest look at what moved HRM from an emerging concept to a funded security priority. Damon shares the early-stage realities of evaluating HRM capabilities, navigating an RFP process, validating assumptions through a proof of concept, and aligning stakeholders around meaningful measures of success. Join to learn practical lessons for identifying converging human risk signals, establishing a realistic first-year roadmap, and scaling HRM efforts in complex enterprise environments.
“Fix the work, not the worker.” Through real-world examples, learn how to identify risk inside crown-jewel workflows, partner with business leaders to redesign high-risk processes, eliminate unnecessary entitlements, and make the secure path the easiest path.
A practical walkthrough of the playbooks connecting workforce risk to real-time security controls: using HRM signals to protect sensitive data, strengthen authentication for higher-risk users, and apply extra controls around privileged access based on measured risk rather than one-size-fits-all policy.
What happens when a mature identity program puts human behavior at the center? Labcorp shares how behavioral insight strengthened their phishing-resistant MFA strategy by revealing the resistance, workarounds, friction, and trust gaps traditional controls miss — and how those lessons apply as AI agents take on greater access.
Most workforce risk programs stall waiting for the perfect data stack. Bayer's team closed the visibility gap for more than half their workforce in six months through a deliberate, region-by-region rollout — starting with the behavioral signals they already had and expanding with each new source.
By 2030, workforce risk management may operate continuously, with access, controls, coaching, and governance adapting in real time around humans and agents. But prevention can tune itself while accountability cannot. What leaders must build now to move toward autonomous prevention without losing clear ownership.
Attackers don't need to hack technology if they can influence people. Through interactive demonstrations blending psychology, mentalism, and real security experience, Gary S. Chan reveals how trust is built, decisions are influenced, and manipulation happens in ways most people never notice.
Two ways to join
A curated day at The University of Texas Club. The sessions matter, and so do the moments between them — breakfast, two networking breaks, and a reception with dinner and an open bar.
Claim an in-person seat
Every session, live from anywhere, plus a Q&A chat our team monitors all day. Recordings follow, so your whole team can register and catch up later.
Join the live stream
HRMCon 2025 recap
Eight full sessions from HRMCon 2025 — a straight preview of the conversations coming to Austin.
Jinan Budge, Forrester + Graham Westbrook, SimSpace
Watch session
Ashley Rose, Living Security + Edna Conway, EMC Advisors
Watch session
Tim Taylor, Mastercard
Watch session
Ashley Atiles + Alfonso Mancuso, Labcorp
Watch session
Larry Whiteside Jr., Confide
Watch session
Mike Siegel + Kelly Harward, Living Security
Watch session
Jacob Revord, Aveva + Amjed Saffarini, Trove + Jon Garza, PSA BDP
Watch session
Customer Success Managers, Living Security
Watch session
Join us September 10 in Austin, or live from anywhere. Registration is free.