Humans and AI agents now share access, data, and decisions. HRMCon 2026 brings together the CISOs and practitioners redefining Human Risk Management for that reality — one day, 16 speakers.
Registration
Free to attend. In-person seating at The UT Club is limited — virtual seats are unlimited.
Why attend
CISOs and security leaders from Fortune 500 enterprises walk through what worked, what stalled, and the numbers they took to their executives.
Every session ships something usable. You leave with:
Forrester's independent market update, the platform unveiling, and a look at 2030 — when prevention tunes itself but accountability still doesn't.
See the sessions
The 2026 line-up
Select any speaker to read their background.
Agenda · September 10
Eleven sessions, breaks built for actual conversation, and dinner with an open bar to close.
Gary Chan opens the day for the room and the virtual audience — a quick welcome, the shape of what’s ahead, and how the sessions will run.
Organizations now secure a workforce of both people and AI agents. As identities multiply and autonomous systems take on more work, traditional approaches to measuring human risk fall short. Ashley Rose opens with a vision for the next chapter of workforce security — why measurable incident reduction is replacing activity metrics, and what the unified workforce demands.
Attacks have evolved beyond email — collaboration tools, messaging platforms, and AI agents create new pathways to compromise. Through live demonstrations you'll experience the next generation of the Living Security Platform, including a first look at a new capability that redefines how organizations identify, prioritize, and reduce workforce risk.
Human Risk Management starts by defining the outcome your program is built to achieve. Security may focus on incidents, identity teams on access, compliance on policy, and business leaders on operational impact. When those stakeholders don't agree on the problem the program is meant to solve, progress stalls before the work even begins. This roundtable brings together leaders from across the security organization to explore how to align around one clearly defined enemy, one named incident, and a shared set of measurable outcomes before building a Human Risk Management program. Panelists will discuss which workforce behaviors create the greatest downstream impact, who should define success, and how teams can stay accountable to the metrics they establish from day one. The discussion will also confront a growing challenge: when the riskiest "user" is an AI agent, who is accountable for its actions, and would every stakeholder in the organization give the same answer?
Current security metrics track what employees do, but cognitive data reveals why they do it. This talk explores how leveraging psychological insights, attention patterns, and decision-making metrics can transform your approach to human risk management. Instead of relying solely on training after a mistake occurs, cognitive data allows security teams to anticipate vulnerabilities and intervene before a breach happens. Join us to discover how moving beyond behavior opens up opportunities for a more predictive, human-centric defense strategy for organizations.
A mid-day reset: a short mentalism set from Gary Chan before the afternoon sessions.
An honest look at what moved HRM from an emerging concept to a funded security priority. Damon shares the early-stage realities of evaluating HRM capabilities, navigating an RFP process, validating assumptions through a proof of concept, and aligning stakeholders around meaningful measures of success. Join to learn practical lessons for identifying converging human risk signals, establishing a realistic first-year roadmap, and scaling HRM efforts in complex enterprise environments.
The Livvy Awards recognize real outcomes — celebrating this year’s Incident Slayer, Culture Engine, and Unified Workforce Pioneer.
A practical walkthrough of the playbooks connecting workforce risk to real-time security controls: using HRM signals to protect sensitive data, strengthen authentication for higher-risk users, and apply extra controls around privileged access based on measured risk rather than one-size-fits-all policy.
What happens when a mature identity program puts human behavior at the center? Labcorp shares how behavioral insight strengthened their phishing-resistant MFA strategy by revealing the resistance, workarounds, friction, and trust gaps traditional controls miss — and how those lessons apply as AI agents take on greater access.
Most workforce risk programs stall waiting for the perfect data stack. Bayer's team closed the visibility gap for more than half their workforce in six months through a deliberate, region-by-region rollout — starting with the behavioral signals they already had and expanding with each new source.
“Fix the work, not the worker.” Through real-world examples, learn how to identify risk inside crown-jewel workflows, partner with business leaders to redesign high-risk processes, eliminate unnecessary entitlements, and make the secure path the easiest path.
For years, security teams have struggled to change workforce security behaviors, and instill a strong security culture. They are finally moving beyond “training as the silver bullet” toward measurable, behavior-driven protection. Then the agentic era arrived. The workforce is no longer exclusively human, with AI agents operating alongside employees and introducing new risks. At the same time, AI is accelerating change across the workforce, amplifying human-related breaches. This session reframes security culture for a hybrid workforce, helping employees work safely and effectively alongside AI agents.
By 2030, workforce risk management may operate continuously, with access, controls, coaching, and governance adapting in real time around humans and agents. But prevention can tune itself while accountability cannot. What leaders must build now to move toward autonomous prevention without losing clear ownership.
Attackers don't need to hack technology if they can influence people. Through interactive demonstrations blending psychology, mentalism, and real security experience, Gary S. Chan reveals how trust is built, decisions are influenced, and manipulation happens in ways most people never notice.
Ashley Rose closes out the day before the evening reception.
Two ways to join
A curated day at The University of Texas Club. The sessions matter, and so do the moments between them — breakfast, two networking breaks, and a reception with dinner and an open bar.
Claim an in-person seat
Every session, live from anywhere, plus a Q&A chat our team monitors all day. Recordings follow, so your whole team can register and catch up later.
Join the live stream
HRMCon 2025 recap
Eight full sessions from HRMCon 2025 — a straight preview of the conversations coming to Austin.
Ashley Rose, Living Security + Edna Conway, EMC Advisors
Watch session
Tim Taylor, Mastercard
Watch session
Ashley Atiles + Alfonso Mancuso, Labcorp
Watch session
Larry Whiteside Jr., Confide
Watch session
Mike Siegel + Kelly Harward, Living Security
Watch session
Jacob Revord, Aveva + Amjed Saffarini, Trove + Jon Garza, PSA BDP
Watch session
Customer Success Managers, Living Security
Watch session
Join us September 10 in Austin, or live from anywhere. Registration is free.