Breaking
SecurityDeveloping Story

ASM Summit Takes Aim at Blind Spots

SecurityWeek's Attack Surface Management Summit runs today, with sessions on asset visibility, SBOMs, red teaming, and AI-driven defense.

··2 hours ago·3 min read
a woman sitting at a desk using a laptop computer
Photo by Walls.io on Unsplash

Security teams spend much of their time defending assets they know about. The harder problem is the ones they don't. That gap is the focus of SecurityWeek's 2026 Attack Surface Management Summit, which the publication describes as taking place today from 11AM to 3PM as a fully immersive virtual event.

According to the event announcement, the summit brings together what it describes as a large community of cyber defenders to explore how organizations can identify, understand, and reduce risk across what it calls an increasingly complex digital attack surface.

What the summit covers

The published agenda centers on the building blocks of a modern ASM strategy. According to the announcement, sessions will examine the essential components of that strategy, the push for continuous asset discovery and inventory, and the role that red teaming, bug bounty programs, and penetration testing play in strengthening enterprise defenses.

The event page frames the core question for attendees: how security teams continuously discover, classify, prioritize, and monitor digital assets and cloud services, and how they turn greater visibility into what the announcement calls meaningful risk reduction.

The session lineup

The announcement lists a mix of talks and demonstrations. Among the named sessions:

  • Beyond Attack Surface Visibility: Proving What Attackers Can Actually Exploit
  • You Can't Secure What You Can't See: SBOM, AIBOM & Software Supply Chain Risk – Dr. Allan Friedman
  • What Actually Is in Your Attack Surface?
  • Modernize Your Attack Surface Management: Machine-Speed Defense with the Wiz Red Agent
  • Horizon3 NodeZero Autonomous Attack Chain Demo
  • Wiz Demo

The agenda also includes networking and a virtual expo hall.

Visibility versus proof

One session title stands out for its framing: proving what attackers can actually exploit. The pairing of visibility with exploitability is a recurring theme in the listed agenda, which moves from cataloging assets to testing whether a given weakness is genuinely reachable.

That is a different question from whether an asset appears in an inventory. The announcement's description of the event emphasizes both discovery and the offensive techniques used to validate exposure.

Software and AI supply chain risk

The session led by Dr. Allan Friedman pairs software bills of materials with AI bills of materials, grouping software supply chain risk under one heading. The title itself signals that the inventory conversation is not limited to servers and endpoints.

The other listed sessions address the practical question of what actually sits in an organization's attack surface and how to modernize management of it. The presence of two vendor demonstrations — one from Wiz and one from Horizon3 — reflects the expo-hall format of the event.

How to take part

The event is described as fully virtual and runs from 11AM to 3PM. The announcement directs readers to register to attend and to view the full agenda for session details.

SecurityWeek's coverage notes that the event is produced by SecurityWeek and that the announcement was published under its SecurityWeek News byline. The publication also promotes a Daily Briefing newsletter for cybersecurity threats, trends, and expert insights.

What attendees are expected to take away

According to the event description, the sessions are built around how security teams discover, classify, prioritize, and monitor digital assets and cloud services. The throughline across the listed talks is the movement from raw visibility to what the announcement calls meaningful risk reduction.

That includes the use of red teaming, bug bounties, and penetration testing as part of enterprise defense programs, as well as continuous asset discovery and inventory as ongoing practices rather than one-time audits.

Why it matters

For security leaders, the agenda is a reminder that attack surface management is less a product category than a set of practices spanning discovery, classification, prioritization, and monitoring. The sessions on exploitability and supply chain risk suggest the field is being asked to answer harder questions than whether an asset is known to exist — namely whether it can actually be used against the organization. Teams that treat asset inventory as a checkbox may find the summit's framing uncomfortable, while those already investing in continuous discovery and validation will recognize the direction the conversation is heading.

#attack surface management#security summit#vulnerability management#supply chain#red teaming

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories