Featured Speaker: Ron Reyer
Ron Reyer is a seasoned cybersecurity executive serving as CISO and vCISO for LKCM Headwater Investments, where he provides strategic security leadership across a 23‑company private equity portfolio, including a $2B NASDAQ‑listed enterprise. He specializes in turning cybersecurity programs into operational and competitive advantages for private equity firms, mid‑market companies, and global organizations. Ron previously led security for ERIKS North America, part of a 10,000‑employee multinational, coordinating security efforts across Europe and Asia. Before entering the private sector, he spent 15 years as Director of IT Services for the Bethel Park School District, earning multiple regional awards for technology leadership.
Topic: AI Security: Risks, Realities, and Recommend Actions
AI adoption has outpaced most organizations’ ability to govern it. The core challenge is a fundamental shift in the threat model: traditional security assumes code behaves deterministically, while AI systems interpret instructions and data probabilistically — making them influenceable in ways software is not. Existing controls help, but they do not close the gap.
This session maps the full AI risk surface across eight categories and dives deep into seven critical themes shaping enterprise exposure today:
Shadow AI — Employees using public LLMs with company data. Bans fail; layered response (discover, sanction, restrict, train, monitor, escalate) is the only durable model.
AI in the SaaS stack — Vendors quietly enabling AI features in tools you already own, altering data flows, retention, and liability without contract changes. SOC reports are becoming AI governance documents.
AI‑enabled social engineering — Deepfake voice, polished BEC, and scalable pretexting. Defenses are procedural: callback verification, two‑person rule, phishing‑resistant MFA, and AI‑era awareness training.
AI governance & acceptable use — A layered operating model from board‑level risk appetite down to tooling and telemetry. Insurance carriers are introducing broad AI exclusions across D&O, E&O, and management liability.
Agentic AI & commerce — Cryptographic payment mandates hold, but agents can still be steered into harmful purchases via prompt injection. Authorization ≠ judgment.
AI in M&A diligence — Where AI hides inside acquisition targets and how to evaluate maturity as both risk and upside.
AI in the software lifecycle & non‑person entities — Prompt injection in code, CI/CD agent hijack, and unmanaged agent identities that require lifecycle management like privileged users.
Key Takeaways:
- AI risk is already present in your environment.
- Authorization is not the same as good judgment.
- Governance is primarily process, not technology.
- Visibility is the correct starting move — then build a 30‑60‑90 day plan and readiness tier model provide a concrete path forward.
- A technical appendix covers indirect prompt injection anatomy, self‑propagating AI malware detection, CISA BOD 26‑04, and a NIST CSF 2.0 / NIST AI RMF mapping.
Date: Tuesday, July 21, 2026
Time: 5:30 PM – 7:00 PM (Presentation starts at 6:00 PM)
Location:
Hackers
Guild PGH - 2247 Babcock Blvd - Pittsburgh, PA 15237
RSVP on MeetUp: Pittsburgh ISSA July Meeting | Meetup (https://www.meetup.com/steel-city-infosec/events/315579899/)
If you would like to submit an idea for a presentation, please send us an email to Contact@PittsburghIssa.org.
Click here to see our past schedule of Presentations and speakers.