The future of technology is not arriving in a predictable order. Artificial intelligence is changing how organizations operate, cybersecurity threats are becoming more sophisticated, and regulatory requirements are evolving alongside technologies that did not exist when many current frameworks were designed. For professionals working across IT, cybersecurity, privacy, risk, and compliance, staying prepared means going beyond theory. It means understanding how emerging challenges may unfold and developing the ability to respond to them in practice.
That is one of the ideas at the heart of the #PECBConf26, taking place in Rome from October 5-8. Among the conference program, two workshops will take a particularly interactive approach to the future: one focused on the offensive and defensive dimensions of AI security, and another designed to challenge participants to think beyond today’s assumptions and into the road to 2030.
AI is rapidly becoming part of security operations, business processes, and decision-making. But as organizations integrate AI into increasingly critical environments, a new question becomes unavoidable: what happens when AI itself becomes part of the attack surface?
This question will take center stage in the workshop “Offensive & Defensive AI Security: Prompt Injection, AI-Driven Threat Hunting, and Reverse Engineering,” led by Matija Verić, Founder of MIT poslovni procesi, Ethical Hacker, and NIS2 Expert.
The workshop will explore AI security from both sides of the equation: understanding how attackers can exploit AI systems while examining how defenders can identify, investigate, and mitigate those threats.
Participants will dive into areas including prompt injection, AI-driven threat hunting, and reverse engineering, exploring the practical security implications of technologies that are increasingly becoming embedded in organizational environments. These concepts will be brought to life through hands-on demonstrations and practical exercises using RangeForce Labs, giving participants the opportunity to experience real-world AI security scenarios in an interactive environment.
The workshop’s offensive and defensive perspective is particularly relevant as organizations move from experimenting with AI to deploying it in real-world environments. The goal is not simply to understand what AI can do, but to understand how it can fail, how it can be exploited, and how security teams can prepare for those scenarios.
For cybersecurity professionals, ethical hackers, security leaders, and anyone responsible for protecting AI-enabled environments, this workshop offers an opportunity to look at AI security through the eyes of both the attacker and the defender, while gaining practical experience through RangeForce Labs.
While one workshop will take participants deep into the technical realities of AI security, the second will take a broader view of the future.
Following the energy, engagement, and unexpected turns that made Rinske Geerlings’ workshop a standout experience last year, we are bringing her back to the PECB Conference 2026 for another challenge.
“The Road to 2030: Technology Surprises & Regulatory Shifts No One Saw Coming: A Live Team Scenario Challenge”.
Rinske Geerlings, Managing Director at Business As Usual will once again put participants at the center of the action, turning future uncertainty into a live team challenge where thinking ahead, adapting quickly, and making the right decisions will matter.
Rather than simply discussing predictions, the workshop will challenge participants to respond to them.
The premise is simple: the technology and regulatory landscape of 2030 may look very different from what organizations expect today. New technologies may emerge faster than anticipated. Existing technologies may evolve in unexpected directions. Regulations may shift in response to new risks. And organizations may find themselves dealing with scenarios that were difficult to predict or prepare for in 2026.
For executives, technology leaders, risk professionals, compliance specialists, and cybersecurity decision-makers, this perspective is increasingly important. The regulatory and technological landscape is already changing rapidly, with developments such as NIS2, DORA, and the EU AI Act reshaping how organizations approach risk, governance, resilience, and accountability.
By looking toward 2030, the workshop encourages participants to think beyond today’s requirements and consider what happens when technology and regulation move in directions organizations did not anticipate.
Although the two workshops approach the future from very different angles, they share a common purpose.
One takes you inside the surface of the attack, the other takes you into the future. Both ask the same fundamental question: Are we prepared for what comes next?
Join us in Rome and be part of this experience.