Diana Kelley

CISO, Noma Security

Diana Kelley is the Chief Information Security Officer (CISO) at Noma Security, bringing decades of cybersecurity leadership to the role. Her career spans positions as Cybersecurity CTO at Microsoft, Global Executive Security Advisor at IBM Security, GM at Symantec, VP at Burton Group (now Gartner), and CISO at Protect AI, among others. Diana serves on the boards of WiCyS, the Executive Women's Forum (EWF), InfoSec World, and CyberFuture Foundation, and volunteers with organizations including CompTIA, ACM, and Sightline Security. She is co-author of Practical Cybersecurity Architecture and Cryptographic Libraries for Developers, an instructor on LinkedIn Learning, and a former lecturer in Boston College's cybersecurity master's program. A sought-after keynote speaker, Diana hosted the #1 BrightTALK original series The (Security) Balancing Act. Her recognition includes the 2023 Global Cyber Security Hall of Fame, AuditBoard's Top 25 Resilient CISOs (2024), EWF 2020 Executive of the Year, SCMedia Power Player, and a spot on Cybersecurity Ventures' 100 Fascinating Females Fighting Cybercrime. She is also a Founding Member of OWASP AIVSS and has served as EWF Conference Chair since 2021.

Diana Kelley

Sessions / 2026 / 2 talks

  • If you would not hand an intern your credentials, payment data, and production access, do not hand them to an AI agent without understanding the risk. Agentic systems do more than generate content. They take action across tools, data stores, and workflows with delegated authority. That shifts the trust boundary, expands identity and data risk, and stretches governance. This session explores practical controls security teams can apply now.

  • As AI agents become more autonomous, organizations face both unprecedented opportunities and emerging risks. Organizations need trusted agents not only to drive productivity but also to defend against emerging AI-powered threats. So why aren’t more agents in production? This panel unpacks the key technical, organizational, and trust barriers, and explains why success requires buy-in beyond security, spanning CIOs, developers, and product teams. We’ll close with what it takes to run agents safely at scale: governance, monitoring, and controls that build trust in real-world deployments. As AI agents become more autonomous, organizations face both unprecedented opportunities and emerging risks. Organizations need trusted agents not only to drive productivity but also to defend against emerging AI-powered threats.

Ready to take this stage?

The next edition is programmed by practitioners. Tell us what you built and what you learned.

Apply to be a speaker