BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: From Disclosure to Defense: Rebuilding Vulnerability
 \n   Management for the AI Era\n   Tags: Policy @ DEF CON | Creator Talk/P
 anel\n   When: Saturday\, Aug 8\, 14:30 - 15:30 PDT\n   Where: LVCCW Level
  2 W210-211 (Policy Village) - [1]Map\n\n   Description:\n\n   AI has upen
 ded vulnerability discovery. What used to be scarce is now\n   abundant: v
 ulnerabilities can be found faster\, at greater scale\, and\n   across mor
 e systems than ever before. Systems that uplevel vuln\n   hunters are beco
 ming widely available\, to both defenders and malicious\n   actors. Findin
 g vulnerabilities used to be the hard part - but itâ€™s\n   not anymore\, 
 and we need to adapt the vulnerability ecosystem to\n   reflect that. But 
 vulnerability management - thoughtful and methodical\n   disclosure\, tria
 ge\, patching\, and policy - still operates on\n   assumptions of scarcity
 . That mismatch is becoming dangerous. If AI\n   makes vulnerability disco
 very effectively infinite\, what does a safe\,\n   scalable system for han
 dling them actually look like? This panel will\n   discuss how the vulnera
 bility needs to evolve to match the moment.\n   Current policy approaches 
 - especially those mandating rapid reporting\n   or broad sharing of unmit
 igated vulnerabilities - risk making systems\n   less secure in an AI-driv
 en environment. At the same time\, rapid\n   response by defenders is crit
 ical\, and resources are scarce.\n   Disclosure models need to evolve\, go
 vernments need to support\n   defenders\, and incentives must align to ens
 ure that AI-driven\n   discovery strengthens security.\n\n   Speakers:Lind
 sey Cerkovnik\,John Banghart\,Ben Flatgard\,Elizabeth Eigner\n\n   Speaker
 Bio:  Lindsey Cerkovnik\, CISA\n\n   Lindsey Cerkovnik is the Chief of CIS
 Aâ€™s Vulnerability Response &\n   Coordination (VRC) Branch. Her team is 
 responsible for CISAâ€™s\n   Coordinated Vulnerability Disclosure (CVD) pr
 ocess\, the Known\n   Exploited Vulnerabilities (KEV) catalog\, and CISAâ€
 ™s Stakeholder\n   Specific Vulnerability Categorization (SSVC) process. L
 indsey and her\n   team help to maintain\, support\, and advance the globa
 l vulnerability\n   ecosystem by funding and overseeing the CVE and CVE Nu
 mbering\n   Authority (CNA) programs\, leading the production and dissemin
 ation of\n   machine-readable vulnerability enrichment information\, and e
 ngaging in\n   valuable technical collaboration with the vulnerability res
 earch\n   community.\n\n   SpeakerBio:  John Banghart\, Center for Cyberse
 curity Policy & Law\n\n   John Banghart leverages his significant federal 
 government and private\n   sector experience in cybersecurity to navigate 
 issues related to risk\n   management\, government policy\, standards and 
 regulatory compliance\,\n   and incident management. He has successfully l
 ed efforts to address\n   significant and high-profile cybersecurity issue
 s within major\n   government programs and institutions while facing compl
 ex legal\,\n   technical\, and political circumstances. From 2013 to 2015\
 , John played\n   a key role in developing the Obama administration's cybe
 rsecurity and\n   technology policy as the National Security Council's dir
 ector for\n   federal cybersecurity. He led policy\, technical\, and proce
 ss efforts\n   to reduce cybersecurity risk and improve metrics and measur
 ement for\n   all civilian\, military\, and intelligence community agencie
 s. He served\n   as a primary advisor on cybersecurity incidents and prepa
 redness and\n   led the National Security Councilâ€™s efforts to address s
 ignificant\n   cybersecurity incidents\, including those at OPM and the Wh
 ite House\,\n   among others. He also spent several years at the National 
 Institute of\n   Standards and Technology (NIST)\, both as a cybersecurity
  researcher\n   and in the Office of the Undersecretary of Commerce for St
 andards and\n   Technology. John also worked as a senior cybersecurity adv
 isor for the\n   Centers for Medicare and Medicaid Services\, providing le
 adership to\n   the cybersecurity preparations for the Healthcare.gov webs
 ite.\n\n   SpeakerBio:  Ben Flatgard\, JPMorgan Chase\n\n   Ben Flatgard i
 s an Executive Director with JPMorgan Chase Co. He leads\n   public policy
  development and advocacy\, as well as partnership\n   initiatives\, to im
 prove the cybersecurity of the firm\, its customers\n   and clients\, and 
 the broader digital ecosystem. Ben previously served\n   in the Obama Admi
 nistration from 2009-2017. In his most recent post as\n   Director for Cyb
 ersecurity Policy on the National Security Council\,\n   Ben was responsib
 le for leading cybersecurity policy development\n   related to protection 
 of critical infrastructure and emerging\n   technologies. Before joining t
 he National Security Council\, Ben served\n   as Senior Advisor to the Ass
 istant Secretary of the Treasury for\n   Financial Institutions. Prior to 
 his time at Treasury\, Ben held\n   positions at the Department of Commerc
 e and the White House. Ben\n   graduated from the University of Edinburgh.
  He holds fellowships at\n   the Atlantic Council in Washington\, DC\, and
  at the University of\n   Sydney.\n\n   SpeakerBio:  Elizabeth Eigner\, Mi
 crosoft\n\n   Elizabeth Eigner is a Senior Manager on Microsoftâ€™s Global
 \n   Cybersecurity Policy team\, where she leads Microsoft's vulnerability
 \n   policy portfolio\, overseeing efforts to develop and implement\n   st
 rategies that address vulnerability management both in the United\n   Stat
 es and globally. She represents Microsoft on the Hacking Policy\n   Counci
 l\, where she works collaboratively with industry leaders and\n   policyma
 kers to advance responsible cybersecurity and strengthen the\n   framework
 s that underpin software security worldwide. Elizabeth also\n   leads init
 iatives aimed at creating and enhancing national cyber\n   strategies in c
 ountries around the world. She works closely with\n   governments and stak
 eholders to strengthen policy frameworks and\n   promote resilient cyberse
 curity practices globally. Elizabeth also\n   leads Microsoft's Advancing 
 Regional Cybersecurity (ARC) initiative\,\n   focusing on improving incide
 nt response capabilities and cyber\n   capacity building in the Global Sou
 th. Previously\, she served as\n   Microsoftâ€™s representative on the Clo
 ud Service Provider Advisory\n   Board (CSP-AB)\, contributing to FedRAMP 
 public policy discussions and\n   best practices for cloud security. Befor
 e joining Microsoft\, Elizabeth\n   worked at The Washington Technology In
 dustry Association to enhance\n   Washington State's innovation ecosystem.
  At MIT Solve\, she\n   collaborated with tech-based social entrepreneurs 
 on solutions\n   fostering digital inclusion and equitable economic opport
 unity. She\n   holds a B.S. in Political Science from Northeastern Univers
 ity\, with\n   concentrations in Law and International Security.\n\n   '\n
 \n   1. #LVCCW_Level2_West\n\n\n
DTEND:20260808T223000Z
DTSTART:20260808T213000Z
LOCATION:Policy @ DEF  CON - LVCCW Level 2 W210-211 (Policy Village)
SUMMARY:From Disclosure to Defense: Rebuilding Vulnerability Management for
  the AI Era
END:VEVENT
END:VCALENDAR
