Tuesday, February 09, 2027
9:00-9:45am
Tuesday - 2/09/27
|
MSP Expo Cybersecurity (Room 250A)
Navigating the AI Attack Surface: Threat Vectors, Data Leakage, and Browser-Level Governance
MSPC-01 Generative AI expands the corporate attack surface through shadow AI usage, prompt injection, unauthorized extensions, and data exposure. This session bridges macro threat landscape analysis with practical endpoint control. Learn how to identify emerging AI threat vectors, evaluate organizational risk, bring the web browser under formal management, and implement role-based access controls (RBAC) to prevent data leakage.
Register me |
10:00-10:45am
Tuesday - 2/09/27
|
MSP Expo Cybersecurity (Room 250A)
Navigating the AI Regulatory Wave: EU AI Act, State Privacy Statutes, and Small Business Compliance
MSPC-02 Emerging AI privacy legislation—from the EU AI Act to US state-level disclosure mandates—is quickly impacting small businesses and their technology partners. This panel translates complex regulatory trends into plain-language obligations, examining risk classifications, transparency mandates, and data governance rules to equip MSPs for billable compliance reviews.
Register me |
11:00-11:45am
Tuesday - 2/09/27
|
|
12:00-12:30pm
Tuesday - 2/09/27
|
|
1:30-2:15pm
Tuesday - 2/09/27
|
MSP Expo Cybersecurity (Room 250A)
AI Governance in Practice: Building Managed Advisory Services and Recovering Failed Deployments
MSPC-05 Rushed AI adoption creates severe governance gaps, data exposure, and operational disruption. Bringing together experienced advisors and operators, this panel provides a complete governance framework for delivering repeatable AI governance managed services (readiness assessments, policy generation, RBAC) while offering a recovery playbook for stabilizing mismanaged projects.
Register me |
2:30-3:15pm
Tuesday - 2/09/27
|
MSP Expo Cybersecurity (Room 250A)
MFA & Passkeys Aren't the Finish Line: What “Assurance” Means for the Environments You Run
MSPC-06 Credential theft and phished MFA remain top breach vectors, but proving identity assurance involves much more than enabling MFA. Grounded in NIST SP 800-63B standards and FIDO2/WebAuthn architecture, this session outlines a framework to evaluate true authentication assurance across service desk reset workflows, technician stacks, and client environments.
Register me |
3:30-4:00pm
Tuesday - 2/09/27
|
|
Wednesday, February 10, 2027
9:00-9:45am
Wednesday - 2/10/27
|
MSP Expo Cybersecurity (Room 250A)
Exposing the Blind Spots: Translating Pen Test Trends into Continuous Attack Surface Visibility
MSPC-08 Real-world penetration testing reveals that major breaches rarely stem from exotic zero-days, but from recurring identity gaps and misconfigurations that periodic scans miss. Learn how to combine deep pen-testing insights with continuous attack surface visibility across endpoints, cloud resources, and identity stores to deliver proactive, risk-based security services.
Register me |
10:00-10:45am
Wednesday - 2/10/27
|
MSP Expo Cybersecurity (Room 250A)
Adding 24/7 security monitoring is critical for capturing enterprise security spend, but building it profitably is one of the toughest operational hurdles MSPs face. This session examines the true cost-benefit trade-offs of building an in-house SOC versus partnering with wholesale white-label or co-managed MDR providers. Attendees will walk through tech stack selection criteria (SIEM, XDR, and telemetry ingestion), engineer-to-client staffing ratios, alert triage playbooks that eliminate alert fatigue, and packaging strategies to profitably price and sell 24/7 MDR to mid-market clients.
Register me |
1:30-2:15pm
Wednesday - 2/10/27
|
MSP Expo Cybersecurity (Room 250A)
Navigating Regulatory Compliance & Cyber Insurance: CMMC, HIPAA, and Underwriting Rules
MSPC-10 Strict cyber insurance carriers and expanding regulatory mandates like CMMC, HIPAA, and FTC Safeguards are giving your clients major headaches—creating a massive revenue opportunity for your MSP. This session bridges the gap between technical controls and executive compliance. Learn how to launch a billable Compliance-as-a-Service (CaaS) offering, effortlessly satisfy tough underwriting requirements (MFA, EDR, immutable backups), and position your team as the hero that protects clients from policy denials, audit penalties, and sudden deal-breakers.
Register me |
2:30-3:15pm
Wednesday - 2/10/27
|
MSP Expo Cybersecurity (Room 250A)
When ransomware strikes a client environment, the decisions made in the first two hours determine whether your MSP survives the crisis or faces existential legal and financial liability. This session walks through an actionable Incident Response (IR) playbook for handling a major breach under pressure. Learn the exact protocols for technical containment and forensic preservation, when and how to engage breach counsel and insurance adjusters, how to execute transparent crisis communications, and how to safely orchestrate a systematic recovery without compromising evidence.
Register me |
Thursday, February 11, 2027
9:00-9:45am
Thursday - 2/11/27
|
MSP Expo Cybersecurity (Room 250A)
Hardening the Service Desk: Zero Trust, IAM, and Defending Helpdesks from Social Engineering
MSPC-12 Helpdesk technicians have become prime targets for modern social engineering attacks, credential theft, and helpdesk takeover schemes. This practical session delivers a blueprint for executing Zero Trust and identity controls across your service desk and client environments. Learn how to eliminate local admin rights, deploy Privileged Access Management (PAM) and credential vaulting, enforce technician identity verification protocols, and implement micro-segmentation to ensure your helpdesk remains a secure fortress rather than a back door for attackers.
Register me |
10:00-10:45am
Thursday - 2/11/27
|
MSP Expo Cybersecurity (Room 250A)
Defending the Remote Workforce: Advanced Email Security, CSPM, and User Awareness
MSPC-13 With hybrid work a permanent reality, traditional network perimeters offer little protection against targeted Business Email Compromise (BEC), account takeovers, and dangerous cloud security gaps. This session provides a practical framework for building a multi-layered cloud security offering for distributed teams. Learn how to combine API-based email security (stopping impersonation and enforcing DMARC) with Cloud Security Posture Management (CSPM) to catch M365/Azure misconfigurations, and integrate continuous security awareness training that transforms end-users into an effective first line of defense.
Register me |
11:00-11:45am
Thursday - 2/11/27
|
|































































