Loading…

Company: Spacewalk.ai clear filter
Saturday, September 12
 

10:30am CDT

AI Failures in IR: A Field Guide to Filling the Gaps
Saturday September 12, 2026 10:30am - 11:30am CDT
Every security vendor is shipping AI. Every IR team is under pressure to adopt it. And in the middle of a real incident, the gap between what AI promises and what it actually delivers becomes very concrete, very fast.


This talk is a field guide to that gap. Drawing on experience as an incident responder on T-Mobile's CIRT during Salt Typhoon and on the builder side developing AI tooling for IR, I'll walk through the specific ways AI underperforms when a breach is unfolding — hallucinated IOCs and timestamps, confident wrong answers, first-hypothesis lock-in, bias toward threat explanations over innocuous ones, lost evidence chains, context windows that collapse on real forensic data, and agents that can take down your SIEM because nobody throttled them.


For each failure mode, we'll cover why it happens, how to recognize it in tools you're evaluating or already running, and what mitigations actually hold up under incident pressure. Attendees will leave with a taxonomy of AI failure modes in IR, a set of sharp questions to ask any vendor (or internal build team) claiming to solve them, recommendations for how to solve them, and a clearer picture of how AI can augment responders versus where it quietly creates new risks.
Speakers
avatar for Alex Thomson

Alex Thomson

Incident Response Specialist, Spacewalk.ai
Alex has over 30 years of professional experience in cybersecurity, including building and leading SOCs and other secops teams. Most recently, he served on T-Mobile's CIRT — including during the Salt Typhoon intrusion — before joining Spacewalk, where for the past 1.5 years he's... Read More →
Saturday September 12, 2026 10:30am - 11:30am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA
  Talk
 
Blue Team Con 2026
From $0.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.