1 / 46

Day 3 — Defense in Depth + Rules of the Road

Hands-On SecAI+ · Working Connections 2026 · Wed, Jul 22 · 9:30 AM – 5:30 PM Central

  • Domain focus: D2.4–2.6 (data protection) + D4 — Governance, Risk & Compliance (19%)
  • By lunch: you can find, redact, and tokenize PII before it ever reaches a model — and scrub it from logs before they ship to a SIEM
  • By end of day: you can map a real AI deployment onto NIST AI RMF 1.0 and place it in an EU AI Act risk tier

Speaker notes

Frame the pivot: Day 2 locked the front door; Day 3 assumes an attacker is already inside the context and asks how we protect the data itself — then, in the afternoon, what rules govern all of this. Two halves, one day: data-protection engineering in the morning, governance/risk/compliance after lunch.