Global CISO Community
Executive Summit
September 28-30, 2026 | Waldorf Astoria Monarch Beach Resort & Club
September 28-30, 2026
Waldorf Astoria Monarch Beach Resort & Club
Collaborate with your global peers
Get together with other CISOs who lead global operations at this exclusive, three-day summit to exchange ideas and validate strategies unique to large, complex organizations. Engage in candid discussions, dive deep into critical issues and validate strategies with other enterprise heads of security on the challenges unique to large, complex organizations. Executives are assured a level of information exchange and interaction with true, global peers beyond a regional community on discussion topics driven by Global CISOs, for Global CISOs.
Connect with true peers who lead their function globally and have similar opportunities and challenges, gain new perspectives and share experiences unique to the global nature of your role, and participate in discussions and sessions geared specifically toward global security leaders.
Leading international organizations by balancing tactical cyber defenses with strategic innovation
Strengthening relationships to position cybersecurity as a core factor in global business decisions
Navigating access management and compliance in complex ecosystems of a fragmented regulatory world
Global CISO Governing Body
The Governing Body Co-Chairs shape the summit agenda, ensuring that all content is driven By CISOs, For CISOs®.
Governing Body Co-Chairs

Derek Anthony
bp
CISO & SVP, Digital Security

Derek Benz
The Coca-Cola Company
SVP & CISO

Tim Callahan
Aflac
SVP & Global CISO

Andy Kirkland
The Walt Disney Company
Global CISO

Marc Varner
Lowe's Companies
Global CISO

Juan Gomez-Sanchez
McLane Company
VP, Cyber Resilience

Marcos Marrero
H.I.G. Capital
Chief Information Security Officer
What to Expect
Agenda
Executive Boardroom Sessions
Navigating Geopolitical Risk — Securing Critical Dependencies
Geopolitical tensions and nation-state cyber threats are reshaping the risk landscape for global organizations. Attacks on critical infrastructure, both digital or physical, can disrupt business operations and national economies. Global CISOs must proactively identify and address vulnerabilities across the supply chain and infrastructure ecosystem.
Join this boardroom to discuss ways to:
- Map and regularly assess dependencies on critical infrastructure and third-party suppliers
- Develop cross-functional crisis response plans for infrastructure disruptions
- Foster global intelligence sharing and collaboration to anticipate and mitigate emerging threats
AI Agents at Scale — Protecting Global Enterprises
For global enterprises, securing the agentic enterprise is a fundamental transformation in how data security, AI risk, and operational resilience intersect. As autonomous AI agents proliferate across complex environments, the greatest risks now reside in the data these agents can access and act upon—beyond traditional model or perimeter defenses. Forward-thinking CISOs who address this convergence will position their organizations for competitive advantage and regulatory confidence in the age of AI.
Join this session to explore:
- Strategies for global visibility and control over AI deployments
- Protecting sensitive enterprise data from AI-driven risks
- Building resilient, compliant frameworks for converged AI threats
Building a Resilient Digital Executive Protection Program
Executives' high-visibility lifestyles and global travel make them valuable targets for threat actors, including those motivated by geo-political forces. CISOs must move beyond traditional corporate defenses to safeguard the organization from reputational, financial, and cyber risks that originate in an executive’s personal digital life. Complete digital executive protection addresses this gap–protecting executives beyond the office walls including their personal movements through tailored global travel advisories and by securing devices, multiple domestic and international home networks, and online accounts.
Join this session to discuss how to:
- Incorporate a strong digital executive protection framework into a worldwide security strategy
- Analyze the personal attack chain and how digital vulnerabilities lead to physical risk
- Combat global cyber threats in the age of AI
Adaptable Defenses for Next-Level International Attacks
Beyond deepfakes, fraud, and phishing attacks, next-gen attackers can launch complex campaigns that hit hard and fast across teams and regions. With AI and automation, threat vectors are evolving faster than most security teams can even triage. Global CISOs must adapt and scale defenses quickly– leveraging AI to fight AI.
Join this session to discuss:
- Evolving attack vector trends your peers are witnessing around the world
- Bridging the gap between digital and human risk to fight back with real-time threat intelligence
- Scaling adaptable defenses quickly and globally to defend your organization’s brand
Accelerate Your Global AI Security Strategy With Scalability
AI is embedded into business around the world, shaping how organizations develop into the future. To build an effective AI security strategy that gives visibility and context into your increasingly complex global environment, CISOs must scale security on a whole new level.
Join this session to discuss:
- Identifying and assessing AI-related risks, including data exposure and model vulnerabilities
- Scaling AI security measures as technology and threats evolve
- Implementing security controls throughout the AI lifecycle, from development to deployment
Global Strategies for the New Era of Identity Security
Access has fundamentally changed across the world. The growth of AI agents, cloud infrastructure, and machine identities is outpacing traditional access models, increasing both complexity and risk. This shift demands a new approach to identity security especially for international companies faced with complex environments.
Join this roundtable to discuss:
- Defining identity in a world where humans are the minority
- Creating infrastructure access for AI agents that is dynamically controlled, auditable, and limited to what’s necessary
- Putting up guardrails and ensuring true compliance across international borders
Mastering Agentic AI Oversight Beyond Human Risk
As agentic AI transforms the workplace, CISOs must shift from global access validation to intent and behavior oversight for both people and AI agents.
Join this session to discuss:
- Governing AI across global employees and autonomous agents
- Operationalizing real-time, intent-based risk mitigation
- Building future-ready frameworks for agentic AI governance
Compliant Here, There, and Everywhere?
Regulations don't stand still — and neither do the organizations trying to keep up with them. For CISOs managing multi-national environments, staying compliant isn't just a technical challenge. It's a communication challenge. AI has accelerated both. Organizations getting this right aren't doing more. They're working from better data.
Join this session to discuss:
- Foundations and data strategies that strengthen governance and build trust because compliance on paper isn’t true continuous compliance
- Anticipating and adapting to shifting regulations with scalable, AI-supported strategies that translate security posture into metrics boards and operational leaders can act on
- What consistent, measurable compliance looks like when your control environment spans multiple geographies, frameworks, and levels of technical knowledge
Staying Compliant When Your AI Agents Don't Know Borders
AI agents now access sensitive data and execute decisions without human approval, and sometimes beyond their intended scope. For Global CISOs operating across dozens of jurisdictions, each with its own regulatory framework, agent overreach is both a security risk and a compliance event. Your peers face the same question: how do you maintain continuous compliance when autonomous systems move faster than your audit cycles, and regulators move faster than your legal teams?
Join this moderated peer discussion to explore:
- Detecting and preventing agent overreach before it becomes a compliance violation across jurisdictions
- Building governance frameworks that scale, from PCI and HIPAA to GDPR and emerging AI-specific regulations
- Aligning legal, audit, and security teams around shared accountability for agentic AI oversight
AI’s Dual Impact – Speed and Vulnerabilities
AI can create incredible business advantages through speed and innovation, especially in application development. But applications continue to be a point of huge concern for data breach entry points. In a world of evolving threats, can Global CISOs be champions for maintaining a competitive edge through innovation without trading security risk or compliance.
Join this session to discuss:
- AI’s dual impact on application development speed for competitive advantages and security vulnerabilities
- Next-gen data breaches trends involving application security and how to get ahead to stop data breaches
- Navigating complex regulations on AI and data on a global scale
Effective Third-Party Risk Strategies for Global Ecosystems
Every vendor, partner, or provider you work with is a little piece of your ecosystem – with one misstep a ripple can impact your entire global organization. A thoughtful and effective third-party risk management strategy maps out risks, implements safeguards, and builds reliable partnerships for compliance in the face of constantly changing international regulations.
In this session, you will discuss:
- Fighting the continuing expansion attack surface including AI
- Critical alignment of people and process elements with advanced technologies
- Implementing practical strategies for leveraging threat intelligence in TPRM
Keynote Sessions
Resilient Leadership in a High-Velocity Environment
Global CISOs face a powerful opportunity to ignite innovation and influence change across organizations and beyond. Effective security leaders champion resilience, fuel growth, and, at the heart of it all, put people first even as technology evolves like never before.
Join Alan Rosa, CISO & SVP, Infrastructure and Operations at CVS Health, as he challenges you to:
- Shape the future role of the Global CISO
- Define “CISO’s Ethos” in an AI-driven world
- Go beyond the busy day-to-day to discover your passion and elevate your leadership
The Resilience Gap — Why CISOs Now Own Brand Continuity
Downtime is no longer just an security problem — it's a brand event. When disruption hits, your response time, your recovery architecture and your communication strategy are all under scrutiny from customers, regulators and the board simultaneously. The focus must now shift to what actually matters — how to restore a minimum viable business fast, stay compliant across conflicting global regulations and demonstrate readiness before you're forced to prove it under pressure.
Join this session to walk away with:
- A measurable framework for minimum viable business recovery that speaks the board's language
- Tactics for maintaining continuity across jurisdictions with divergent sovereignty and compliance demands
- An executive communication playbook for before, during and after an incident
Strengthening Global AI Security and Governance
CISOs must secure the enterprise as generative AI adoption grows, while maintaining governance, compliance, and visibility across borders. As employees use browser-based AI tools, organizations face risks from unapproved applications that can lead to data leakage, security breaches, and regulatory exposure. Responsible AI adoption requires balancing innovation with control. Operational, security, and compliance threats from “Shadow AI,” including cross-border data flows, highlight the need for policies that protect the enterprise while supporting secure, productive AI use globally. By advancing security posture and implementing robust policies, organizations can confidently meet the demands of AI-driven transformation.
Join this session to discover:
- Mitigating risks from unauthorized AI tools
- Implementing globally compliant security policies
- Safeguarding data with secure AI adoption
Secure the AI Wave at Scale — Zero Trust for Control and Resilience
AI risk is inherently cross-border: global teams adopt AI at different speeds, vendors introduce concentration risk, and data flows challenge sovereignty mandates and residency requirements. Global CISOs have gone through several technology mega waves throughout their tenured careers, but AI is a gigawave that requires a new level of security to maintain continuity through outages, legal challenges, and regulatory change—without relying on temporary stopgaps such as default blocking. A Zero Trust approach enables secure, scalable AI while meeting the demands of executive stakeholders and regulators.
Join this session to learn how to:
- Implement executive- and board-ready AI governance with consistent visibility, measurable controls, and reporting across geographies
- Enforce digital sovereignty by managing data processing boundaries and applying region-specific policy for AI usage and sensitive data handling
- Strengthen business continuity through resilient enforcement and reduced systemic exposure to provider outages, regional restrictions, and legal constraints
Unlocking Elite Leadership — An Evening with Venus Williams
Experience an exclusive fireside chat with legendary athlete, entrepreneur and advocate Venus Williams at the Global CIO & CISO Gala. A Grand Slam champion, four-time Olympic gold medalist and visionary business leader, Venus will focus on:
- Driving innovation and unlocking proven strategies to fuel business growth
- Building resilience, mental toughness and a winning mindset
- Leading with purpose, authenticity and individuality to shape your leadership legacy
Breakout Sessions
Trust by Design – From CISO to International Business Influencer
In today’s dynamic world, Global CISOs must elevate beyond tactical experts to strategic business partners who influence true change. The time has come to redefine security leadership into business leadership by championing a responsible culture of innovation, driving organizational growth, and taking personal ownership of the company’s reputation.
Join John Gift, SVP & Global CISO at PepsiCo as he shares his perspective on:
- Reducing risk while improving resiliency on an international scale to maintain the company’s brand and customer’s trust
- Building a responsible culture of emerging technology from AI to digital twins
- Developing intentional relationships to navigate complex global regulations and challenges
Navigating Agentic AI's Convergence of Data and Access
Agentic AI is reshaping global security. As legacy models fail, leaders must embrace a strategic mindset shift to thrive. By converging data and access into a unified approach, enterprises can overcome the explosion of shadow tools and build a foundation that secures trust at scale.
Join this session to explore how to:
- Gain visibility across complex ecosystems to uncover shadow AI
- Orchestrate a unified foundation that secures global enterprise trust
- Define a clear path toward a resilient AI future
Leadership in A Complex Global Environment — A Focus on Adaptability
On the world stage, Chief Information Security Officers must navigate global uncertainty by turning challenges into strategic opportunities—emerging as more adaptable, resilient leaders.
Join this session to hear from a panel of leaders from different areas of the globe as they discuss:
- Leading international organizations by balancing tactical cyber defenses with strategic innovation
- Strengthening relationships to position cybersecurity as a core factor in global business decisions
- Navigating access management and compliance in complex ecosystems of a fragmented regulatory world
Preventing Data Loss in a Distributed World
As volatility reshapes the risk landscape for global organizations, CISOs must align data loss prevention strategies with business objectives and evolving regulatory requirements.
Join this session to explore:
- Navigating DLP in an expanded, AI-driven risk landscape
- Reinforcing global enterprise resilience across environments
- Ensuring comprehensive visibility and unified governance
Securing the International Agentic Enterprise with Intent-Based Identity
Agentic AI is rewriting enterprise security from the inside out for global enterprises, and agent creation is exponentially growing. Most are ungoverned, not because identity and security teams aren't paying attention, but because current frameworks were never built for actors that behave this way. What most executives have yet to internalize: agents are actually easier to secure than humans. Every prompt tells you exactly what the agent intends to do.
Join Danny Brickman, CEO & Co-Founder, Oasis Security to uncover:
- Why agentic AI makes identity the critical control plane, and where your exposure is highest
- How intent-based access governance replaces static policies with real-time, scoped enforcement across the globe
- How leading international enterprises are unifying human and non-human identity security before regulators force their hand
Innovation Spotlight Session
Innovation Spotlight
Be among the first to see what’s new and next in the security solutions landscape! CEOs from early-stage providers will get the chance to showcase their innovative solutions to the most pressing cybersecurity challenges and face questions from CISOs in an exciting session that's always a fan favorite.
Spotlight Presenters from:
- Nullify
- Helmet
- Arcade
- Jazz Security
- Furl
- Sidekick Labs
Peer-to-Peer Meetings Session
Peer-to-Peer Meetings
Connect with like-minded peers in a one-on-one setting through Peer-to-Peer Meetings. You will be matched with peers in your community based on your shared interests and priorities.
Apply to Participate
Apply to participate in the Global CISO Community Executive Summit.
Gartner facilitates exclusive, C-level communities by personally qualifying and understanding the priorities, challenges and interests of each member.
Our selective approach maintains the high quality of the network and ensures top-level discussions with peers from the world’s leading organizations.
Each application will be reviewed, and once your participation is confirmed, you will have access to year-round community programs.
Location
Venue & Accommodation
Waldorf Astoria Monarch Beach Resort & ClubDiscounted nightly rate of $495 + taxes and fees.
Regardless of the venue policy, any cancellations made after September 4th (cutoff date) are subject to a cancellation fee of one (1) night room charge plus tax
A block of rooms has been reserved at the Waldorf Astoria Monarch Beach Resort & Club at a reduced conference rate. Reservations should be made online or by calling +1 (949)-234-3200. Please mention Gartner C-level Communities Global CISO & CIO Executive Summit to ensure the appropriate room rate.
Deadline to book using the discounted room rate of $495 USD (plus tax) is September 4, 2026.
Community Program Manager
For inquiries related to this community, please reach out to your dedicated contact.
