Security leaders have spent years building programs around a defined rhythm: threats evolve, defenses adapt, budgets catch up eventually.
That rhythm is broken. In June, the Five Eyes cybersecurity agencies warned that AI is accelerating the speed, scale, and sophistication of attacks faster than most organizations can prepare. Cyber resilience is now a Board-level risk, not an IT checkbox.
The full impact that the Five Eyes statement warns of becomes more apparent when we understand what that acceleration actually demands of the people defending hybrid identity systems every day.
According to Microsoft, identity-based attacks rose 32% in just the first half of 2025. That’s a risk that just keeps compounding as the number of non-human identities increases. Machine identities already outnumber human ones 10:1, trending toward 100:1 as agentic tools proliferate. Every one of those agents is a new identity that needs governance and protection—and most security teams didn’t budget headcount or process for a workforce that multiplies overnight.
That’s why gatherings like the Hybrid Identity Protection Conference really matter. HIP Conf 26 is happening September 8–10 in Nashville at a moment when identity teams are being asked to protect identity systems against faster-moving attackers, manage permissions and access for a wave of AI agents nobody fully understands yet, and prove (not just claim) that they can recover when something goes wrong.
This isn’t a conference that stands only on theory. It’s about getting specific about the attack paths you’re defending, building deeper technical understanding of the complexities of your entire identity fabric, and attaining confidence that when a cyber incident does happen, you’re ready to recover completely to a trusted state.
Here’s why that combination is worth clearing your calendar.
The AI-adoption pace creates human problems for cyber resilience
Throughout 2026, agentic AI has been a key topic driving conversations about cyber resilience. The technology straining identity teams is the same one the rest of the business is racing to adopt. Business leaders are pointing agentic AI at real workflows to move faster and compete effectively. But agents must log in and authenticate to operate inside your systems. That means every AI initiative is also an identity decision, regardless of whether security practitioners were in the room when it was launched.
In addition, cyber risk is growing because attackers are also using AI agents to discover credentials, exploit excess permissions, and propagate attacks at machine speed.
As a result, organizations report a security confidence gap that shows up consistently in Semperis research: only 32% of organizations worldwide say they’re very confident they could fully regain control of their identity infrastructure after an AI-related breach.
That’s not a failure of tools or teams. It’s evidence that the operating model that determines how fast teams can detect, decide, and respond hasn’t caught up to how fast the environment now changes.
Alex Weinert | Checklist: Prepare Your Identity Fabric for the Agentic Era
“As your business bets more on agents, it bets more on your identity fabric—because if identity fails, so do the agents and every process they support.”
Identity security can’t happen in isolation
Redefining the resilience model is a cross-disciplinary effort. Closing gaps and reducing risk means pulling in leadership, security practitioners, and technical teams.
At HIP Conf 26, Semperis Director of Crisis Management Courtney Guss will make this case directly in the session, Identity Is the Business: Translating Identity Security Into Executive Action. Her argument is that identity risk remains widely misunderstood outside technical teams. Closing that gap is now a leadership challenge, not just a technical one.
That theme echoes a broader point about identity recovery: it’s not a purely technical restoration event—and identity security was never really one team’s job. AI has just made the cost of pretending otherwise much higher, much faster.
Why redefining resilience is worth your whole team’s time
This is precisely the gap HIP Conf is designed to close—not with theory alone but with the kinds of sessions that cyber leaders and practitioners actually ask for.
Four tracks for the people who have to show up
HIP Conf 26’s track structure maps almost exactly to the roles that cyber resilience needs filled.
Identity Security Research is where gaps get found before they become headlines. This is the discovery layer, coming directly from the people whose job is to see the exploit before it has a name. Among the highlights:
- SpecterOps’ Michael Grafnetter is presenting new research on KDS root key exposure.
- Datadog’s Katie Knowles dissects Entra ID Access Package abuse.
- TrustedSec’s Brandon Colley reveals attack paths in Entra Conditional Access.
- Saviynt’s David Lee explores agentic governance.
Identity Masterclasses offer practical, technical talks zoom in on where the fixes actually get built. A sampling:
- Accenture’s Joe Kaplan is sharing how his team scaled Conditional Access governance to 1.1 million users.
- Microsoft’s Linda Taylor and Mariam Gewida are walking through the practical roadmap for retiring NTLM.
- Sentinel Technologies’ Michael Soule introduces a hybrid identity protection maturity model that ties capabilities to outcomes instead of checklists.
- Sam Erde and Merill Fernando are teaching teams to build custom identity security tests with Maester.
CISO track—new this year—is where technical findings become business decisions. In addition to Guss’s session:
- Walmart Principal Engineer Melissa Cronquist examines how AI is redefining identity verification and trust boundaries.
- Semperis’ Tim Springston spotlights a critically under-acknowledged risk: losing access to your own cloud tenants.
- A four-CISO panel from Acadia Health, Uplight, Fortitude Re, and Diversity Health speaks candidly about the psychological weight of making calls under pressure—the human side of leadership that rarely gets airtime.
Crisis Management is where everyone comes together when the gap is already exploited. Sessions cover the full response and recovery cycle:
- Microsoft’s Ryan O’Donnell drills down into a scenario for catching attackers during data collection—enabling faster triage and limiting damage.
- Capgemini’s Benjamin Cauwel adds battle-tested frameworks for defining your Minimum Viable Company (MVC), building your chain of command, and strengthening business continuity.
- Cohesity’s Neil Ashworth explores what makes successful crisis management drawing from lessons learned from response and recover across hundreds of ransomware and wiper attacks.
- Resolving gaps, preventing the next one, and ensuring your business can not just withstand an attack but operate through one—and come back stronger—requires people from across your organization, working together.
That’s the real argument for HIP Conf 26’s structure: it mirrors the room a resilient organization actually needs assembled, long before the next crisis forces the point.
Bring the room, not just a representative
That’s the case for sending more than one person. A researcher, an engineer, a senior leader, and a crisis-minded stakeholder each get something distinct and something shared—value that a single “security representative” attending alone simply can’t bring back to the rest of the team.
Resilience isn’t a single team’s job anymore. It’s a room your organization must build in advance, deliberately, before the pressure of a real incident forces people in who’ve never worked together.
HIP Conf 26 is one concrete place to start building it.
The pace of change isn’t slowing down, and neither is the pressure on the people defending against it. Registration for the 2026 Hybrid Identity Protection Conference is still open for September 8–10 in Nashville. Take advantage of the chance to get ahead of a problem that isn’t waiting for anyone’s budget cycle to catch up.
