Select a tab
Black Hat 2026 is a wrap! Here's your recap from WWT
Hosting the week at S Bar gave us the space for real conversations, and the caliber of the discussions made it one of our best years yet. A few themes came up again and again: AI as both a defense tool and a fast-growing attack surface, resilience under pressure, and the identity and governance gaps that keep surfacing in the middle of everything else.
The Cost of Offense Is Collapsing. Our Defenses Cannot Stand Still.
Where the conversations happened
Cocktails and Cyber opened the week at S Bar, in partnership with Akamai, Cloudflare, Darktrace, Forescout, Gigamon, Fortinet, Infoblox, Netskope, Tanium and Rubrik.
Before the formal programming began, customers, partners and practitioners compared notes on what they were actually seeing: where AI was producing real value, where security teams were feeling pressure, which problems were overstated and which risks weren't getting enough attention. The most useful intelligence at Black Hat rarely arrives as a finished conclusion. It usually starts as an observation someone puts on the table early enough for others to challenge it.
The Morning Brief brought together WWT's Rob Joyce, David Luber and Chris Konrad to unpack how AI is reshaping the threat environment.
Their conclusion was direct: the playbook hasn't disappeared — AI has put it on fast-forward. AI agents can research software, navigate networks, identify vulnerabilities and operate continuously without fatigue. Meanwhile many security operations centers still rely on people to review alerts, approve changes and coordinate response.
The panel also surfaced a hard operational tradeoff. For internet-facing devices, traditional test-and-deploy patch cycles may leave a window machine-speed attackers can cross first. Leaders increasingly have to weigh the risk of a self-inflicted outage against the risk of leaving a known path open. There's no risk-free answer — only a decision about which risk you're prepared to own.
WWT's Kate Kuehn and the Honorable Kirsten A. Davies, Chief Information Officer of the U.S. Department of War, convened a community listening session on CMMC and defense cybersecurity.
Following the suspension of CMMC Phase II requirements, the Department is reviewing the program. This session gave the people responsible for implementation a direct channel to explain what they're experiencing — where requirements are working, where they're creating unintended friction and what should inform the review.
That exchange matters. Policymakers need candid feedback from operators, suppliers and practitioners. Industry needs to understand the mission, not just the requirement. Stronger security comes from bringing those perspectives together before friction hardens into failure.
At the WWT Community Breakfast, Acting CISA Director Nick Andersen joined WWT's Madison Horn for a fireside conversation grounded in what infrastructure operators are facing right now.
The discussion ranged from coordinated cyber activity against community water systems to the implications of AI-enabled operations, CISA's priorities and the role industry must play in connecting federal visibility with the realities facing states, local governments and operators. Different examples, same question: are we learning and adapting as fast as the threat environment is changing?
In operational technology, cyber risk doesn't stay contained to data. It reaches the systems that move water, power communities and keep essential services running. Resilience has to be designed across systems, organizations and levels of government.
Marcela Denniston and NVIDIA opened the breakfast with the work of the newly formed Open Secure AI Alliance — reinforcing another theme from the week: securing AI will take shared work across an ecosystem no single company or agency controls.
The Lab: Where Innovation Takes the Stage
The Lab brought emerging cybersecurity technology, industry thought leadership and partner innovation together under one roof — kiosks, a central stage, founder fireside chats and a daily innovation competition.
Innovation Lab. Claroty, Filigran, Doppel, BLACKCLOAK, Command Zero and Keyfactor brought distinct perspectives into the room through innovation pitches and practitioner conversations. This wasn't passive consumption. Participants questioned the ideas and pressure-tested the use cases. At a moment when the market is flooded with AI and security claims, that willingness to expose an idea to scrutiny is a strength.
Immersive Board Experience. We spend a lot of time helping technical people get better at technology. We spend far less helping them communicate what they know once the decision leaves the technical room. Participants took a board seat and worked through a mock cyber scenario from that perspective — where the discussion can't stop at vulnerabilities and controls, and has to account for operations, capital, reputation and timing. Technical truth only creates value when someone else can act on it.
Ask WWT experts...
Wondering what to talk about with us? Here are some ideas.
The AI Proving Ground
Cyber Range
Labs & Learning Paths
Connect with our experts
Thanks to our supporting partners
We'd like to recognize our partners for making our presence at Black Hat USA 2026 possible. Thanks for helping us make a new world happen for our clients!