Dwayne's Blog

CornCon 2026: Security Has to Work in the Real World

Davenport, Iowa, is home to the official Guinness World Record holder for the largest spoon collection in the world.

The Mississippi Spoon Gallery holds 38,162 spoons. The collection ranges from souvenir pieces and antique silverware to spoons from around the world. Guinness officially recognized the collection after all 38,162 pieces were counted and cataloged.

A collection that large becomes far more useful when someone knows what is in it, where it belongs, and why each piece is worth keeping. That turned out to be an unexpectedly good setup for CornCon 2026.

CornCon returned to Davenport with 425 attendees. The main conference ran October 2 and 3, following the CISO Executive Summit on October 1. Across talks about AI, critical infrastructure, credentials, agriculture, governance, and security leadership, speakers kept returning to one larger idea.

Security has to work in the real world.

Controls have to survive contact with people. Governance has to survive urgency. Infrastructure has to keep working when failure carries physical consequences. AI systems have to operate inside boundaries that account for what agents can actually do.

The strongest security program is the one people and systems can still use when things get weird.

Making the Enterprise a Harder Target

JD Eger from ThreatLocker opened with “Attack Vectors & AI: How to Make Your Business a Hard Target.”

JD Eger presenting the opening keynote at CornCon 2026.
JD Eger presenting “Attack Vectors & AI: How to Make Your Business a Hard Target.” Photo from my Bluesky stream.

His framing started with attacker economics. Cybercrime is industrialized, and many organizations get hit because they are reachable through the same scalable paths, such as phishing, stolen credentials, and remote access tools, that work against thousands of other victims.

JD's goal was practical: make attacking the organization too slow, too noisy, or too expensive.

AI adds speed to both sides. In one demonstration, an AI system recognized that its instructions increasingly resembled ransomware and continued anyway when told to proceed.

A model can reason about an action and still arrive at a dangerous outcome. Reliable protection comes from controlling what a system can execute, reach, and access before recovery becomes necessary.

Trust May Be Security's Most Important Infrastructure

Robert Wagner followed with one of the most human talks of the conference, “Why Nobody Trusts Us.”

Robert Wagner presenting Why Nobody Trusts Us at CornCon 2026.
Robert Wagner presenting “Why Nobody Trusts Us” at CornCon 2026. Photo from my Bluesky stream.

Robert focused on something most organizations barely measure: do people trust security enough to call? Teams rarely announce they have lost faith. They stop asking, work around slow processes, and solve problems themselves, and the dashboard looks cleaner as those conversations disappear.

He summed it up with one of the best lines of the conference:

“Relationships are resilience infrastructure.”

Trust decides whether incidents get reported early, whether developers ask before inventing workarounds, and whether leaders believe security's numbers. The secure path has to be the fast path, and findings should arrive with options and a recommendation instead of a flat “this isn't secure.”

Robert also encouraged a phrase security professionals often struggle to say: “I don't know. Let me find out.” Trust can grow from investigating a problem together.

Cybersecurity Gets Very Real on a Farm

Kristin King made the consequences of cyber risk physical with “Securing What Feeds Us: How Cyber Risk Reaches the Modern Farm.”

Kristin King presenting Securing What Feeds Us at CornCon 2026.
Kristin King presenting “Securing What Feeds Us: How Cyber Risk Reaches the Modern Farm.” Photo from my Bluesky stream.

Modern farms run on robotic milking equipment, real-time animal data, mobile apps, and GPS. Kristin described a ransomware attack on a robotic dairy parlor. The farm refused the $10,000 demand, but losing real-time herd data cost it a cow and a calf.

Her line for the larger problem was perfect:

“Biology does not have a maintenance window.”

Cows still need food and ventilation still has to work, often on thin margins with no IT staff. Security advice has to fit inside work that already fills every available hour. Her advice: translate, show up, build small, and ask better questions. Security expertise becomes useful when it speaks the language of the people doing the work.

Some Systems Have Consequences You Cannot Restore From Backup

Joshua Corman and David Etue widened that physical-world conversation with “The Army of the 12 Million Chaos Monkeys on Life-Safety Critical Infrastructure.”

Joshua Corman and David Etue presenting at CornCon 2026.
Joshua Corman and David Etue discussing life-safety critical infrastructure at CornCon 2026. Photo from my Bluesky stream.

Chaos Monkey deliberately exercises failure to build resilience. Critical infrastructure is harder. A server can be rebuilt, but a patient, water supply, or community may not recover the same way. Hospitals, military bases, and data centers all depend on water, so one disruption cascades.

Joshua and David pushed for hazard analysis and engineering thinking, including the ability to operate manually when digital systems fail. AI acts at machine speed, and accidents can cause harm without malice. For systems like these, resilience has to exist before the incident.

AI Governance Eventually Reaches the Human Handoff

John Kwarsick's “Who Governs the Agents? The Human Governance Gap in Cybersecurity and AI” turned the discussion toward a problem hiding inside many AI strategies.

“Human in the loop” looks comforting on a slide, but it says little about whether that human can actually take control.

John Kwarsick presenting Who Governs the Agents? at CornCon 2026.
John Kwarsick presenting “Who Governs the Agents? The Human Governance Gap in Cybersecurity and AI.” Photo from my Bluesky stream.

John described agents as software that pursues a goal, picks its next steps, and uses whatever access it holds. When that automation is wrong, can an analyst stop it in time, with the authority and practice to do so? Skills also fade after months of approving recommendations.

His fix is to test the handoff: give an analyst several agent decisions, make one wrong, and see whether they catch it. Oversight is only a real control when people can actually exercise it.

Credential Rotation Starts With Knowing What Exists

Mayank Sethi delivered one of the most directly actionable talks with “From Click Ops to Closed Loop: Rotating 1000+ Database Credentials Without an Outage.”

Mayank Sethi presenting From Click Ops to Closed Loop at CornCon 2026.
Mayank Sethi presenting “From Click Ops to Closed Loop: Rotating 1000+ Database Credentials Without an Outage.” Photo from my Bluesky stream.

The team faced more than 1,000 service accounts across about 150 application teams. Rotating everything at once can break everything, so the work began with inventory: who owned each credential, what depended on it, and when it was last used.

Ownership records were stale. Once owners could see their accounts and last logins, some asked to disable unused ones themselves. About 80 percent of the credentials were rotated within three months.

Mayank's shortest summary may have been the most important:

“Discover before you rotate.”

AI Is Forcing Security to Revisit Old Assumptions

Gadi Evron closed CornCon with “From Security Program Building to Vulnerability Research: Our Narratives and Being AI Native.”

Gadi Evron delivering the CornCon 2026 closing keynote.
Gadi Evron delivering the closing keynote at CornCon 2026. Photo from my Bluesky stream.

Gadi looked at where AI is heading. Autonomous vulnerability discovery is speeding up how quickly flaws are found, and natural language lets citizen coders build software without traditional pipelines.

He argued for securing agents themselves, working toward safe autonomous patching, and preparing for an agentic software supply chain. One line tied it together:

“The agent is now the perimeter.”

An agent's permissions and credentials determine how far a mistake can travel, and automation is compressing the window between discovery and exploitation. The work starts with examining what agents can reach and controlling their most consequential actions.

Security Has to Fit the World It Protects

CornCon covered a remarkable amount of territory for a conference with 425 attendees.

Farms and water systems brought cybersecurity into the physical world. Robert Wagner brought it into relationships. Mayank Sethi brought it into the messy reality of credential ownership. John Kwarsick brought it into the moment a human needs to take control from an agent.

AI appeared throughout the conference, but many of the strongest lessons were much older.

Know what exists.

Understand who owns it.

Limit unnecessary access.

Build controls around real behavior.

Practice recovery before the emergency.

Give people a secure path they can actually use.

Your author also delivered “From Pets to Cattle to Agents: Evolving Identity and Security for Workloads,” looking at how identity has changed as infrastructure moved from individually managed servers to ephemeral workloads and now increasingly autonomous agents. The same evolution raises a familiar question. How should a system prove who or what it is, and how much authority should it receive once that identity is trusted?

Davenport's 38,162 spoons became a world record because someone took the time to know exactly what was in the collection.

Security teams face a considerably stranger collection.

Credentials, applications, infrastructure, people, agents, and dependencies keep accumulating. Every one of them has a history and a purpose. Some have quietly outlived both.

CornCon 2026 showed what happens when security starts examining the whole collection.

↑