> Markdown version of [/events/world-congress-2026-north-america/sessions/1951-the-era-of-machine](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1951-the-era-of-machine). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # The Era of Machine-Driven Defense is Here: Headless Security - **Date:** Thursday, Sep 24, 2026 - **Time:** 14:50–15:20 (30 min) - **Room:** Stage 1 - **Event:** World Congress 2026 North America ## Description Cybersecurity has hit a bottleneck. The problem isn’t gaps in detection or coverage, but because software was built for humans. Most security tools assume a human-in-the-loop paradigm: alerts surface in dashboards, analysts triage, and engineers remediate through workflows. However, software is no longer just consumed by people. AI is increasingly shouldering the work. Attackers already operate this way, using AI to tailor their campaigns, automate reconnaissance, and chain exploits at machine speed. Human-centric software design isn’t just sub-optimal, it’s detrimental for machine use in an AI-driven landscape. Developers have already embraced the “as code” paradigm. Infrastructure and pipelines became code, and AI coding agents pushed execution into a programmable layer. When it comes to cybersecurity, software is overdue for a complete redesign: flexible, directly consumable by AI, and built for autonomous execution at machine speed. This talk introduces headless security: a fundamentally different architecture in which security products are no longer interacted with directly, but consumed via APIs and composed and executed by coding agents. The control loop – discover, prioritize, remediate – moves from dashboards to the environment where software is built and run. This model reshapes system design and responsibility boundaries. Humans shift from operators to governors, defining intent, constraints, and risk tolerances while agents execute. Security becomes part of the development surface – where workflows are programmable, testable, and version-controlled, with risks resolved inline as code. Loris will explore how this model works, with implementation and real-world scenarios, including the engineering and security challenges of enforcing trust boundaries and ensuring auditability in a UI-less system. The future of security is not operations and dashboards. It is outcome-based, meaningful for every user, and embedded in how software is built and run. ## Speaker ### [Loris Degioanni](https://www.wearedevelopers.com/@loris-degioanni) Founder & CTO of Sysdig ## Related talks at this congress - [The Things Your AI Isn't Telling You](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1710-the-things-your-ai) — Desmond Lamptey - [One Boundary for the Agentic Era](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1871-one-boundary-for-the) — Mark Lechner - [On the Public Clock: Open-Source Defense When You're Not in the Club](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1683-on-the-public-clock) — Nicholas Muy - [Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1432-securing-ai-agent) — Abdel Fane ## Watch remotely Can’t make it to San José? Watch this session live with Pro. You also get: - All full videos, bookmarks, and playlists - World Congress livestreams [See pricing](https://www.wearedevelopers.com/pricing) ## Links - [Get tickets](https://www.wearedevelopers.com/world-congress-north-america/tickets)