World Congress 2026 North America

The Era of Machine-Driven Defense is Here: Headless Security

September 24, 2026 14:50 – 15:20 · 30 min Stage 1

World Congress 2026 North America

September 23–25, 2026 · San José, CA

Attend in person

Get tickets

Watch remotely

Watch live with Pro

Pro

Can’t make it to San José? Watch this session live with Pro. You also get:

  • All full videos, bookmarks, and playlists
  • World Congress livestreams
See pricing

What this session covers

Cybersecurity has hit a bottleneck. The problem isn’t gaps in detection or coverage, but because software was built for humans.

Most security tools assume a human-in-the-loop paradigm: alerts surface in dashboards, analysts triage, and engineers remediate through workflows. However, software is no longer just consumed by people. AI is increasingly shouldering the work. Attackers already operate this way, using AI to tailor their campaigns, automate reconnaissance, and chain exploits at machine speed.

Human-centric software design isn’t just sub-optimal, it’s detrimental for machine use in an AI-driven landscape. Developers have already embraced the “as code” paradigm. Infrastructure and pipelines became code, and AI coding agents pushed execution into a programmable layer. When it comes to cybersecurity, software is overdue for a complete redesign: flexible, directly consumable by AI, and built for autonomous execution at machine speed.

This talk introduces headless security: a fundamentally different architecture in which security products are no longer interacted with directly, but consumed via APIs and composed and executed by coding agents. The control loop – discover, prioritize, remediate – moves from dashboards to the environment where software is built and run.

This model reshapes system design and responsibility boundaries. Humans shift from operators to governors, defining intent, constraints, and risk tolerances while agents execute. Security becomes part of the development surface – where workflows are programmable, testable, and version-controlled, with risks resolved inline as code.

Loris will explore how this model works, with implementation and real-world scenarios, including the engineering and security challenges of enforcing trust boundaries and ensuring auditability in a UI-less system.

The future of security is not operations and dashboards. It is outcome-based, meaningful for every user, and embedded in how software is built and run.

Related talks at this congress

Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer at Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer of Docker

Mark Lechner
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 5

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
All sessions at this congress