2026-07-25 –, Track 1
Detection engineering is about more than alerts and SIEM rules; it is the practice of understanding attacker behaviour and building the visibility needed to detect it. As AI becomes embedded into enterprise environments through agents, copilots, and connected ecosystems, organisations face new identity, data, and supply chain risks that are difficult to monitor using traditional approaches. This talk explores how detection engineering can help illuminate these emerging threats and asks a bigger question: if every breach contains valuable lessons, why does cybersecurity still lack an effective way to share them with the wider industry?
Many organisations invest heavily in SIEM platforms and security tooling, yet struggle to answer a simple question: what attacks can we actually detect? Detection engineering seeks to bridge that gap by focusing on visibility, telemetry, attacker behaviour, and continuous improvement rather than simply collecting logs and generating alerts.
At the same time, organisations are rapidly embedding AI into everyday business operations. AI assistants, autonomous agents, MCP servers, and AI-powered workflows are becoming trusted participants in enterprise environments. These systems are creating entirely new security challenges. AI agents increasingly operate with delegated permissions, access sensitive corporate data, and interact with critical business systems, introducing new identity risks that traditional security models were never designed to handle. The growing ecosystem of models, plugins, connectors, MCP servers, and open-source components also introduces significant supply chain risk, often with limited visibility into how these systems operate or what dependencies they rely upon.
As adoption accelerates, these challenges will inevitably contribute to new classes of security incidents, compromises, and failures. Yet cybersecurity has a problem of its own. Unlike industries such as aviation, which have mature processes for investigating accidents and sharing lessons learned, cybersecurity lacks an effective mechanism for collective learning. Breaches are often hidden behind legal agreements, reputational concerns, or private incident reports, leaving the broader community unable to benefit from the lessons they contain.
This talk explores what detection engineering is, how it extends beyond traditional SIEM deployments, and why it is becoming increasingly important as AI reshapes enterprise environments. It also examines the growing AI attack surface, the identity and supply chain risks that accompany it, and why the industry may need its own equivalent of an aviation accident investigation board if we want to stop repeating the same mistakes and start learning from each other's failures.
Jared is the Head of Security at Synthesis, where he specializes in enterprise cloud architecture. Jared is passionate and deeply committed to guiding large organizations through the complexities of architecting, securing and operationalizing enterprise cloud environments. Beyond Jared’s professional responsibilities, Jared is an enthusiastic advocate for community building, serving as the organizer of several local security events, including 0xcon, BSides Cape Town, and BSides Joburg. Jared’s research focuses on cybersecurity topics that intersect with national security and foreign policy issues such as encryption, privacy, surveillance, disinformation, and nation-state activity.
