CIACON 2026: 4 AI Security Speakers Highlight Offense vs Defense
The CIACON 2026 lineup puts AI at the center of both attack simulation and defensive automation. For AI builders, it underscores how quickly generative and agentic AI capabilities are being repurposed for reconnaissance, social engineering, and security operations.
Beat this week
Last 7 days · AI Models
Impact 6.8/10 (+0.8 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 10 percentage points.
This story sits in AI Models — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
AI briefing
Key takeaways
- The CIACON 2026 lineup puts AI at the center of both attack simulation and defensive automation.
- For AI builders, it underscores how quickly generative and agentic AI capabilities are being repurposed for reconnaissance, social engineering, and security operations.
- srilankasource.com
- cambodiantimes.com
- news.webindia123.com
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1All three source articles are identical VMPL press releases published on 2026-09-12 announcing CIACON 2026 in New Delhi; no independent reporting or event date/registration data is provided.
- 2CIACON 2026 speaker list includes Rakshit Tandon (national cybersecurity expert), Nipun Jaswal (Senior Director & Global Capability Leader, Offensive Security at NTT DATA), Sushil Dash (Enterprise Architect and Red Teaming Expert), and Swati Anuj Arya (VP & Global BISO at S&P G).
- 3The release states AI is used by defenders to analyze security events, automate investigations, and assist defenders, while attackers use AI to scale reconnaissance and social engineering.
- 4The conference agenda described spans offensive security, enterprise security, cloud architecture, risk, compliance, AI governance, malware research, cyber law, and CISO leadership.
- 5The article says a security incident now affects customers, operations, reputation, and regulatory responsibilities, not just IT infrastructure.
- 6The release frames cybersecurity discussions as moving from technical-only rooms to include CISOs, enterprise architects, risk professionals, technology leaders, legal experts, and AI-governance participants.
Analysis
- Automates event analysis and investigations at scale
- Enables faster triage across security operations
- Supports AI governance and cross-functional risk controls
- Attackers scale reconnaissance and social engineering
- Blurs distinction between attacker, defender, and technology
- Expands attack surface to regulatory and reputational risk
Analysis
For AI teams, the CIACON 2026 announcement is a live snapshot of model capabilities being pulled into adversarial use cases. The presence of red-teaming experts and AI-governance professionals on the same stage as incident responders indicates that AI safety and security are converging—not just in research papers, but in enterprise operational roles.
On September 12, 2026, a near-identical VMPL press release appeared on three different news aggregation domains—srilankasource.com, cambodiantimes.com, and news.webindia123.com—announcing CIACON 2026, a cybersecurity conference planned for New Delhi. The release is promotional rather than independently reported, so every detail must be read as the organizers' own framing. Its central claim, however, is analytically useful: the cybersecurity battlefield is no longer just human attacker versus human defender, but increasingly AI versus AI. This shift is not hypothetical; it is visible in the people now being pulled into security conversations.
For AI teams, the CIACON 2026 announcement is a live snapshot of model capabilities being pulled into adversarial use cases.
According to the announcement, AI is being deployed on the defensive side to analyze security events, automate investigations, and assist incident responders, while attackers are experimenting with the same technology to scale reconnaissance and social engineering. The result, the release argues, is that the traditional distinction between attacker, defender, and technology is becoming blurred. That framing captures a real operational change: security teams can no longer assume an adversary's reconnaissance is manual or slow, and defensive workflows must be fast enough to match machine-speed probing. The article positions this as the core reason a cybersecurity conference in Delhi is no longer a room full only of penetration testers and network engineers.
The CIACON 2026 speaker lineup is used as evidence of the broadening ecosystem. Named speakers include Rakshit Tandon, described as a national cybersecurity expert; Nipun Jaswal, Senior Director and Global Capability Leader - Offensive Security at NTT DATA; Sushil Dash, Enterprise Architect and Red Teaming Expert; and Swati Anuj Arya, Vice President & Global BISO at S&P G. The agenda spans offensive security, enterprise security, cloud architecture, risk, compliance, AI governance, malware research, cyber law, and CISO leadership. Even though the release provides no registration numbers, no event date, and no independent verification, the composition itself is an industry statement: security leadership now includes risk, legal, and AI-governance roles alongside technical operators.
The inclusion of a global BISO at S&P G and a global offensive-security capability leader at NTT DATA points to a professionalization of the security function in India. Delhi-NCR is becoming part of the conversation not only because it hosts technology and IT-services firms, but because regulatory pressure, client contracts, and cross-border data obligations are pushing organizations to treat security risk as a board-level issue. The release frames a security incident as affecting customers, operations, reputation, and regulatory responsibilities—not just IT infrastructure—which aligns with how Indian enterprises are being forced to expand security ownership beyond the CISO's team.
From a market and industry standpoint, the AI-versus-AI framing has immediate implications for how security budgets and skills are allocated. If defenders use AI for event analysis and automation, there is pressure on security operations centers to adopt AI-assisted triage, reduce mean-time-to-respond, and integrate threat intelligence with governance. Simultaneously, if attackers use AI for reconnaissance and social engineering, the human layer—executives, employees, third-party vendors—becomes a scaled attack surface. Organizations will need to invest not only in AI detection tools but also in adversarial AI testing, red teaming, and policy controls around generative-AI use. The presence of red-teaming and AI-governance speakers at CIACON 2026 suggests these areas are moving from niche to mainstream.
What to Watch
The Delhi-NCR angle matters specifically for India: the country has a large cybersecurity services and IT-outsourcing base, and conferences like CIACON can influence hiring, partnerships, and local regulatory debates. The release does not provide independent data on India's threat volume, but the event's very existence—with senior roles at global firms—reflects a regional capability shift. For international readers, the relevant takeaway is that cybersecurity talent and thinking are increasingly distributed; threat models developed in Delhi for global clients must account for AI-enabled social engineering and automated reconnaissance that cross borders and languages.
Forward-looking, the AI-vs-AI dynamic will likely accelerate as agentic AI and multimodal models lower the cost of both attack planning and defensive orchestration. Organizations that treat this as a purely technical problem risk losing the broader risk, legal, and governance coordination that the CIACON 2026 lineup signals. The next practical step for security and AI teams is to map where AI already touches their attack surface—phishing, code generation, cloud misconfiguration, vendor risk—and to build red-team and governance capabilities in parallel. Whether CIACON 2026 delivers on its promise remains to be seen, because the source material is promotional and lacks independent reporting. But the signal it sends about the industry's direction is clear enough to be a useful planning input.
Source cluster
Primary reporting
Cite This Page
"CIACON 2026: 4 AI Security Speakers Highlight Offense vs Defense." AI Intelligence Brief, September 12, 2026. https://getaibrief.com/story/ciacon-2026-ai-offensive-defensive
How we covered this story
Every story in our AI coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the AI space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled AI-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |