RSS:2026 Track 1 (Day 1) :: Rochester Security Summit

RSS:2026 Track 1 (Day 1)

Punk Rock AI: The Work/Life OS Digital Assistant Big Tech Won't Build for You

JP Bourget
10:00 am - 10:50 am

Most AI assistants forget you between turns. Personal AI Infrastructure (PAI), originated by Daniel Miessler, treats AI as a Life/Work Operating System instead — one that knows your goals, your context, and the work you're actually trying to get done. This talk walks PAI's three pillars: TELOS (your ideal state, codified), the Algorithm (a 7-phase universal primitive with capability gates and security controls that keep USER/ private), and Pulse (the always-on daemon, extended by Cloudflare Workers managed by Arbol). You'll leave with a working mental model of how PAI uses Claude and other AIs to gather the right context and finish real work. You'll leave with the GitHub repo to start running it tomorrow.

JP Bourget

JP Bourget is CEO of Blue Cycle, a Rochester-based boutique cybersecurity advisory and delivery firm he founded in 2020. Before that he founded Syncurity, a SOAR platform acquired in 2020, after coming up the practitioner ladder from analyst to CIO. He's also Advisor and CISO/EIR at Lytical Ventures and advises startups in detection engineering, identity, and AI infrastructure. He co- founded BSides Rochester and runs The Polaris Collective. His focus today is modernizing SecOps and AI readiness and enablement across the business — via Microsoft, Anthropic, Cribl, and the specialty tools that fit each engagement. He still listens to too much punk and has had a Jazz Fest Club Pass since the late 2000s.

Build It, Break It, Learn From It: Designing Bespoke CTF and Malware Analysis Labs for Your Organization

Aaron Walker, Ph. D.
11:00 am - 11:50 am

What happens when a Security Operations Manager uses AI as a force multiplier to build training infrastructure from scratch? This talk answers that question. The SecOps Workshop Platform is an open-source, self-hosted CTF engine and Windows malware analysis lab — built with AI-assisted development and deployed on a single Linux host. It combines five hands-on challenges mapped to real-world attack TTPs with a live detonation pipeline backed by Sysmon telemetry, YARA, CAPA, and a fake-internet sinkhole. The result: a bespoke, repeatable training range any small security team can own and operate — no vendor, no recurring license, no compromise on technical depth.

Aaron Walker, Ph.D.

Aaron Walker, Ph.D., is a cybersecurity leader, researcher, and educator with extensive experience in information security, threat detection, risk management, and security operations. He currently serves in cybersecurity leadership within the retail sector and holds industry-recognized certifications including CISSP, GPEN, GCIA, GAWN, PMP, and Security+. Dr. Walker earned his Ph.D. from the University of Nevada, Reno, where his research focused on applying machine learning and behavioral analysis techniques to malware detection and classification. He has authored numerous peer-reviewed publications and is recognized for advancing practical approaches to cybersecurity defense, threat analysis, and secure computing.

Securing Shadow AI: Practical Controls for AI Risk, Data Exposure, and Vendor Oversight

Lawana Jones
1:00 pm - 1:50 pm

Artificial intelligence has become a new unmanaged risk surface inside modern organizations. Employees are using generative AI to upload data, summarize documents, automate workflows, and support decisions, often without clear policies, oversight, or accountability. This creates “shadow AI” risk across cybersecurity, privacy, vendor management, intellectual property, compliance, and public trust. This vendor-neutral session offers a practical framework for identifying AI use cases, classifying risk, defining decision rights, creating governance workflows, and building a 30–60–90 day AI security roadmap.

Lawana Jones

Lawana Jones is Founder and Chief Technology Officer of Aureon Global AI Technologies and a nationally recognized technology executive, AI governance strategist, and cybersecurity-informed transformation leader. She most recently served as Senior Vice President, Chief Technology Officer/CISO at United Way Worldwide, where she led enterprise technology, AI governance, cybersecurity, data governance, privacy, and digital transformation across a national nonprofit network. Creator of the AI Governance for Social Impact™ Framework, she helps mission-driven organizations move from AI experimentation to responsible, secure, and accountable AI adoption.

AI-Augmented Web App Pentesting: Lessons from the Field

Mike Lisi
2:00 pm - 2:50 pm

AI-assisted pentesting tools are everywhere, promising faster coverage and better results. But how do they actually perform on real engagements, and what must practitioners understand before trusting AI output in a client deliverable? This session draws on hands-on experience integrating AI-augmented tooling into professional web app assessments - what worked, what failed, and where it makes sense. Attendees leave with a framework for evaluating these tools: what to ask vendors, what to test before trusting output, and how AI assistance intersects with methodology, liability, and client expectations including false positives, missed findings, coverage, over-reliance, and skill atrophy.

Mike Lisi

Mike Lisi is the Founder and Principal Consultant of Maltek Solutions, a cybersecurity consultancy specializing in penetration testing, web application assessments, and security awareness. With over 15 years of experience in offensive security, he has conducted hundreds of network and application assessments and developed cyber capabilities across commercial and public sector environments. Mike also serves as President of Red Team Village, a 501(c)(3) nonprofit dedicated to making offensive security education free and accessible to the global security community. He holds a Master's degree in Cybersecurity & Information Assurance and several certifications.