Implementing AI Pentesting While Managing Risk and Cost
Agentic AI is starting to change how penetration testing gets done. It improves speed, depth, and coverage, and it opens new questions around safety, control, governance, and cost. This is a working session to answer them together.
- ✓ A peer discussion among CISOs, not a product presentation
- ✓ Practical inputs from the room, captured into a CISO playbook you can use
- ✓ A small, senior table held under the Chatham House rule
Facilitated across sessions by FireCompass founders and senior offensive security leaders, alongside CISOPlatform.
The playbook we build together
What the room works through
The objective is not a talk track. It is to capture practical inputs from the group and shape a useful playbook for CISOs evaluating or implementing AI-driven penetration testing. Six questions anchor the discussion.
What agentic AI actually is, and how it differs from traditional security automation.
How to evaluate agentic AI platforms, their real capabilities, and the vendors behind them.
How to implement AI pentest agents inside a live enterprise environment.
The key risks: excessive permissions, unintended actions, data exposure, and lack of oversight.
Safety guardrails, governance, and human-in-the-loop controls that keep an agent in bounds.
Managing token usage, infrastructure cost, and overall ROI.
A discussion, not a pitch
This is an interactive peer conversation among security leaders. No slideware, no demo theater. You bring what you are seeing in your own program, the room compares notes, and everyone leaves with a sharper view of how to adopt AI pentesting without giving up control of risk or spend.
Sessions
Three sittings across August and September
Each roundtable is a separate closed-door session with its own host. Seats are confirmed individually, and the venue is shared with confirmed guests.
Your hosts
Who you will be in the room with

Serial security entrepreneur with multiple USPTO patents in network security. Recognized in Fortune's 40-under-40 and a speaker at RSA Conference and TEDx. Earlier founded iViZ, the first company to take penetration testing to the cloud, later acquired by Synopsys.

A veteran technologist who has led security and technology at the highest levels of government intelligence, bringing a defender's view of how offensive AI should be governed and controlled.

More than 23 years solving hard IT security problems, with leadership roles at British Telecom, Tech Mahindra, iViZ (Synopsys), MetricStream, Capgemini, and IBM. Deep grounding in the engineering behind autonomous offensive security.
Seats are limited. By invitation only.
Request your seat and tell us which session works. We will confirm and share the venue.
Request an invitation →Aug 27 · Sep 11 · Sep 24, 2026 · Venue shared on confirmation