The Judgement Gap: A CISO on AI, Accountability, and What Still Requires a Human

Autonomous tools are moving fast into every corner of security.

Date: Oct 22, 2026 11:00 AM CST

Tony Spinelli has spent his career being that person, as CISO four times, and it shaped how he thinks about the gap between what a tool tells you and what a security leader actually has to answer for. Cobalt Autonomous Pentest runs on that same principle: AI moves fast while a human stays accountable for the result.

In this webinar, Tony joins Cobalt to talk through what that looks like in practice. Attendees will walk away with a sharper set of questions to bring to every security vendor conversation:

  • How to tell the difference between an autonomous tool backed by real accountability and one that isn't

  • What happens when a vendor can't say who stands behind a result

  • Where AI ends and human judgment begins in their own security program

Register for the webinar

Guest Speakers
Tony-Spinelli_headshot
Tony Spinelli
Chief Security Officer, Halcyon

Tony Spinelli is Chief Security Officer at Halcyon and has spent his entire 30+ year career devoted to pioneering and advancing technology, digital transformation, and cybersecurity capabilities across the globe. Mr. Spinelli is widely known for leading some of the world’s most critical organizations, including his role as CISO of Capital One, where he spearheaded the company’s secure adoption of cloud-native computing. He has served as CISO, Board Director and CIO across enterprises such as Capital One, Tyco, Equifax, and First Data, and is a Board Director for Blue Cross Blue Shield Association and Peapack Private Bank. Previously appointed to the US Department of Defense Board, Spinelli continues to provide strategic counsel on cybersecurity, cloud computing, and risk management. He holds multiple patents in data loss prevention, network riskreduction, and cloud innovation, and is deeply committed to advancing the field while mentoring the next generation of technology leaders.

anne-nielsen_headshot
Anne Nielsen
Director, Market Research & Product Marketing, Cobalt

Anne Nielsen is head of Product Marketing at Cobalt. She has 15+ years of cybersecurity experience across product management and marketing roles most recently as Head of Product at JupiterOne. Before then, Anne spent 9 years at Veracode and held positions at other startups including Rapid7 and 451 Research.

Attend Cobalt Speaker Sessions
Meet the Cobalt team to explore a more programmatic approach to security testing. Powered by a combination of AI and elite human pentesters and informed by over a decade of real-world pentesting intelligence, Cobalt helps organizations continuously identify, validate, and remediate vulnerabilities.

Black Hat USA

AI Session

Aug 6, 2026 | 1:30 PM PDT

Meet the Cobalt team to explore a more programmatic approach to security testing. Powered by a combination of AI and elite human pentesters and informed by over a decade of real-world pentesting intelligence, Cobalt helps organizations continuously identify, validate, and remediate vulnerabilities.
GunterOllmann
Gunter Ollmann
CTO, Cobalt

DEF CON 34

Hacking Big Iron: When Modern Security Assumptions Fail on Mainframes

DATE TBA

Mainframes still underpin critical infrastructure such as banking, airlines, and government systems, yet most modern security teams approach them using assumptions formed around Unix, Windows, and enterprise platforms. These assumptions often fail on z/OS, creating blind spots that are difficult to detect and easy to underestimate.

This talk explains how mainframe security actually works and why familiar concepts such as "root," shells, ports, and lateral movement do not translate cleanly. Focusing on components like JES, JCL, RACF, CICS, and PR/SM, we explore where attackers and defenders truly operate today: transactions, security managers, and management boundaries.
Adam-Toscher-speaker
Adam Toscher
Security Researcher, Cobalt

BLACK HAT USA

MCParasite: Universal MCP Worm Security Testing Framework

Aug 6, 2026 | 11:20 AM PDT

MCParasite takes prompt injection and tool poisoning techniques that already exist and chains them into a self-propagating worm that lives inside MCP. A single rogue server poisons the agent's context the moment it connects.

The agent then writes a payload to whatever channel it has access to: Slack, GitHub, Jira, email. A completely separate agent on a different system reads that message, gets infected, and starts executing commands on its own. Shell access, credential theft, data exfiltration. The victim agent never touched the malicious server. We tested 8 models from 4 vendors. 5 out of 6 propagated the worm. We are actively expanding to DeepSeek and others; the talk will cover full results across all major frontier models.
Utku-Yildirim-speaker
Utku Yildirim
Pentester, Cobalt

DEF CON 34

Deep Dive into Fuzzing (Course)

Aug 10 - 11, 2026 | 8:00 AM - 5:00 PM PDT

Attendees would be emulating techniques which would provide a comprehensive understanding of "Crash, Detect & Triage" of fuzzed binaries or software. In "Deep dive into fuzzing" we will be covering a detailed overview of fuzzing and how it can be beneficial to professionals in uncovering security vulnerabilities with a hands-on approach through focus on labs.

Finding vulnerabilities in software requires in-depth knowledge of different technology stacks. Modern day software’s have a huge codebase and may contain vulnerabilities, manually verifying such vulnerabilities is a tedious task and may not be possible in all cases. This training is designed in such a way that it introduces the concept of fuzzing and vulnerability discovery in software’s covering multiple platforms such as Linux & Windows and triage analysis for those vulnerabilities.
Dhiraj-Mishra-speaker
Dhiraj Mishra
Pentester, Cobalt
Zubin-Devnani-speaker
Zubin Devnani
Pentester, Cobalt