# RMISC 2026 Recap: Twenty Years In — Who's Holding the Leash? Page: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/rmisc-2026-recap-twenty-years-in-who-s-holding-the-leash Text version: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/rmisc-2026-recap-twenty-years-in-who-s-holding-the-leash.md Podcast: [Cyberside Chats: Cybersecurity Insights from the Experts](https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591) Published: 2026-07-07T10:30:00+00:00 Episode link: https://www.chatcyberside.com/e/rmisc-2026-recap-twenty-years-in-%e2%80%94-whos-holding-the-leash/ Audio file: https://mcdn.podbean.com/mf/web/bybtfvc93kzbhmuz/EP80_-_RMISC_recap_Audioazmh4.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/rmisc-2026-recap-twenty-years-in-who-s-holding-the-leash Duration seconds: 1172 ## Resource The Rocky Mountain Information Security Conference just celebrated its 20th anniversary in Denver — and the anniversary edition told us exactly where the industry's head is at. In this quick-hit recap, Matt Durrin and Todd Stewart break down the biggest themes from three days at the Colorado Convention Center: agentic AI moving into the SOC (and the “circuit breaker” conversation about how to rein it in), state-level AI regulation getting real with the Colorado AI Act and updated CCPA audit rules, and deepfake extortion graduating from awareness slides to full tabletop simulations — including LMG's own hands-on deepfake extortion lab from the conference floor. Plus: post-quantum jitters, CMMC 2.0 lessons from the assessment trenches, the 31% attrition problem, and five actionable takeaways for IT and security leaders. Key Takeaways for Leaders 1. Put a leash on your AI agents before they need one. If you're deploying agentic AI in the SOC or business workflows, define kill switches, escalation thresholds, and human-approval gates now. The circuit-breaker conversation at RMISC made clear that rollback plans are being written after incidents, not before. 2. Inventory your shadow AI. Employees are already wiring AI agents and coding assistants into production workflows without approval. Run a discovery exercise this quarter — you can't govern what you haven't found. 3. Treat AI regulation as a state-level problem, not a federal one. The Colorado AI Act and updated CCPA audit requirements were front and center. Map which state laws touch your operations and assign ownership — waiting for federal harmonization is a losing bet. 4. Exercise deepfake extortion before it happens to you. Deepfake-driven fraud and extortion have graduated from awareness-slide material to tabletop… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/rmisc-2026-recap-twenty-years-in-who-s-holding-the-leash/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/rmisc-2026-recap-twenty-years-in-who-s-holding-the-leash.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.