RSS:2026 Track 1 (Day 2) :: Rochester Security Summit

RSS:2026 Track 1 (Day 2)

AI Security Without the Noise: How to Evaluate Third‐Party AI Tools Without Flooding Your SOC

Joe Cicero
10:00 am - 10:50 am

AI has shifted from promise to pressure as organizations face a flood of third-party tools that often increase noise over security. This session explores how leaders can cut through the hype by prioritizing governance and data grounding over surface-level automation. We will examine how Microsoft Copilot for Security leverages a trusted foundation and first-party threat intelligence to improve analyst efficiency and investigation quality, ensuring AI strengthens operations while maintaining control.

Joe Cicero

Joe Cicero is the Chief Marketing Officer at Security Risk Advisors, he leads brand and ecosystem strategy with a focus on measurable impact. Specializing in translating complex cybersecurity challenges into authentic stories that address customer needs. With a leadership background at Microsoft, Joe has advised Fortune 100s and governments on strategy and active incidents. His experience includes scaling global device management and launching first-party managed security services. He also advocates for simplifying programs and building partnerships that enable secure, scalable outcomes for all stakeholders.

Title: AI and Cybersecurity: Dual Use, Widening Gaps in Capabilities, and Protecting NYS

Meghan E. Cook
11:00 am - 11:50 am

Artificial Intelligence (AI) is making cyber crime cheaper, faster, and scalable but, on the other hand, it can also be a force multiplier in scanning codes for vulnerabilities, validate findings, and generating proposed fixes. The use depends on what side you are on but it also widening the gap between well-and under-resourced government entities. This presentation will touch on what we know about AI dual use and how NYS has been actively strengthening its statewide cyber defenses of government entities and critical infrastructure through new regulations, grants, and strategic infrastructure investments.

Meghan E. Cook

Meghan Cook is Chief Cyber Officer for the State of New York. She leads cross agency efforts to protect NYS from cyber threats. In this role she oversees cyber threat assessment, mitigation, and response across NYS agencies, coordinates with NYC, local governments, critical infrastructure to share threat intelligence, works across industry and government to build meaningful partnerships, and works collaboratively across sectors to strengthen cyber defenses and generate public value for NYS. Previously Meghan was the Director of the Cyber Incident Response Team (CIRT) and Assistant Director of the Office of Counter Terrorism (OCT) at the NYS Division of Homeland Security and Emergency Services (NYS DHSES). There, Meghan led a team to provide NYS local governments, non-executive state agencies and schools cyber services and incident response. As OCT Assistant Director, she led statewide initiatives to address multi agency and intergovernmental cyber challenges. For 25 years, Meghan was the Program Director for the Center for Technology in Government (CTG), a globally renowned research institute at University at Albany/SUNY as well as Adjunct Professor at Nelson A. Rockefeller College, and Advisor to the NYS Local Government Information Technology Directors Association (NYSLGITDA). She has published numerous research and practice articles, book chapters, and reports on digital transformation and cybersecurity in local government, including the Cybersecurity Primer for Local Government Leaders and Artificial Intelligence (AI) and Public Managers: Key Questions and Recommended Actions. She is a highly sought speaker and facilitator, having delivered over 400 thought-leadership and strategy development sessions for government leaders all over the world. Meghan has won several awards including Excelsior College’s Alumni Achievement Award, University at Albany Engagement Award, SUNY Adirondack’s Trailblazer Award, and the SUNY Excellence and Chancellor Awards. She has a BA from Excelsior University and an MPA and MS from the University at Albany/SUNY

The Good News: One Prompt Took My AI Security Scores to 70%. The Bad News: The Other 30%. I Need a Minute

Scott Bly
1:00 pm - 1:50 pm

I built Hermia, an open-source LLM security evaluation framework, and ran it across four GPU backends spanning NVIDIA, AMD, and Apple silicon. Then I watched one model pass a security test 97% of the time on one backend and 35% on another. Same model. Same weights. Same prompt. It wasn't wrong — it was slow, and the test clock ran out before the answer arrived. In security, late is a failure. That's when I stopped trusting the aggregate score. This talk is about what the pass rate hides. I'll show a controlled result — strengthen one guardrail prompt and capable models jump from 0% to 100%, while weaker ones don't move — then run Hermia live so you can see the failure modes the average was covering for. Bring a laptop to run it during Q&A.

Scott Bly

Scott Bly is the Field CISO and Director of the Cybersecurity Practice at Systems Integration Solutions, where he was employee #1. Over 20+ years he has built security practices from scratch and advised Fortune 100 CISOs. He is the author of Hermia, an open-source LLM security evaluation framework, and runs a heterogeneous private AI inference fleet as a working reference for the AI security architecture his team deploys for clients. Scott came to security sideways — a USC film degree first — which is why he can make a hard technical finding land in a room. He has spoken at OWASP, ISC2, API Days, and SCaLE, and holds the CISSP, CSSLP, and CISM among 40+ certifications.

AI Security Myths We Can Finally Stop Repeating

Cris Thomas
2:00 pm - 2:50 pm

Every week a new headline warns that AI is about to destroy cybersecurity, or save it. Vendors promise AI defense, researchers warn of AI attacks, and execs are left wondering what's real and what's marketing. This talk cuts through the noise. Drawing on decades of watching security hype cycles come and go, Space Rogue examines the most common AI security claims being repeated today and tests them against reality. With real-world examples, and a healthy dose of skepticism, attendees will learn which AI threats deserve immediate attention, which are overblown, and which security fundamentals matter now more than ever. The goal isn't to dismiss AI risks, it's to help security professionals focus on the ones that actually matter.

Cris Thomas

Cris Thomas is a seasoned cybersecurity expert with over two decades of experience in information security, specializing in risk management, threat intelligence, and security strategy. Known in the industry as "Space Rogue," a pioneering member of the hacker collective L0pht Heavy Industries. Cris has a proven track record in leading security initiatives, developing comprehensive security programs, and advising on cybersecurity policy. Adept at building and leading teams to protect organizational assets in dynamic threat landscapes.