-
20 August 2026
-
08:30
Registration, Coffee & Networking in the Exhibition Area
-
09:00
Welcoming Remarks from Corinium & Chair's Remarks
Sanjeev Gathani - Group Compliance Officer - RV Health
-
09:10
Speed Networking
-
09:15
Strengthening Cloud Resilience
Srividya Subramanian Vidyasagar - Global Head, Cloud and Production Engineering, WRB Tech - Standard Chartered
Speakers
Gurunathan Sekar Head, Cloud Architecture & Transformation, Wealth & Retail Banking Standard Chartered
Srividya Subramanian Vidyasagar Global Head, Cloud and Production Engineering, WRB Tech Standard Chartered -
09:40
Anatomy of a Modern API Attack: Following Every Request from Reconnaissance to Data Exfiltration
Samir Sherif - Global Field CISO - Fastly
Modern API attacks don't rely on a single exploit. They combine automation, business logic abuse and increasingly sophisticated bots to move through cloud-native applications, often without triggering traditional security controls.
Drawing on attack patterns observed across Fastly's global edge network during 2025 and 2026, this session walks through a modern API attack request by request, showing what each layer of the security stack sees, what it misses, and where defenders have the greatest opportunity to stop the attack. Attendees will leave with practical guidance for designing layered API defenses built for today's cloud-native threat landscape.
-
10:05
Can AI See What Your SOC Can’t? Rethinking Cloud Threat Detection
Tan Hwee Cher - Group Head, Information Security & Data Governance - CGS International
-
10:40
Morning Coffee & Networking in the Exhibition Area
-
11:10
Managing Compliance and Security for Third-Party AI and Cloud Services
Dr Martin Leo - Chief Risk Officer - National University of Singapore (NUS)
- Explore strategies for enforcing organisational security and compliance policies with third-party AI and cloud providers
- Understand the challenges of monitoring, auditing, and controlling external services in regulated environments
- Best practices for risk assessment, contractual controls, and vendor oversight
- Learn how to integrate external service governance into broader cloud security and AI governance frameworks
-
11:35
The Defender’s Advantage: Building AI Threat Readiness
Zhihao Tan - Solutions Engineering Manager - Wiz
The Defender’s Advantage: Building AI Threat Readiness explores how organisations can prepare for an evolving threat landscape shaped by artificial intelligence. The session will examine how defenders can gain an advantage by improving visibility across their cloud environment, strengthening security foundations, and using AI to accelerate detection, investigation, and response—helping security teams move from reactive defence to proactive threat readiness.
-
12:00
Panel Discussion
Winning the Cloud Security Battle with Faster Incident Response- How can organisations design effective incident response for multi-cloud environments?
- How can AI and automation be leveraged to detect, respond, and recover faster?
- How can teams prepare for cloud-specific breaches, misconfigurations, or insider threats?
- As organisations adopt MCP and AI agents, how can they balance secure, least-privilege access with optimising AI usage and token costs?
- How can organisations strengthen incident security response by using identity and device context to detect and contain threats faster?
- What lessons can be learned from high-profile cloud incidents?
Moderator
Sanjeev Gathani Group Compliance Officer RV HealthSpeakers
Frankie Shuai VP of Information Security Bitdeer
Roshan Sham Head of Solution Architecture and Delivery Jumpcloud -
12:25
Who Secures the Code That AI Wrote
Gadi Sinai - Regional Director, APJ - Checkmarx
AI is changing how software is built, reviewed, and shipped. While it helps development teams move faster, it also introduces new risks - from AI-generated insecure code to vulnerable open-source components and limited visibility across the software lifecycle.
This session explores why modern AppSec must move closer to code creation, not wait until production or runtime. It will highlight how enterprises can prevent risk earlier, validate every change continuously, and remediate vulnerabilities before they become business exposure.
The discussion will also cover the role of governance in the AI era - and why organisations need a unified AppSec approach that combines automation, visibility, prioritisation, and developer-friendly remediation from code to cloud.
-
12:50
Buffet Lunch & Networking in the Exhibition Area
-
13:50
GenAI in the Cloud: Threat Modelling for LLM-Powered Applications
Abhishek Kapoor - Product Owner - DHL Express
- Explore real-world breaches caused by vulnerabilities in interconnected cloud services
- Understand strategies to assess, monitor, and mitigate third-party and supply chain risks
- Learn how to implement governance, contractual controls, and continuous monitoring for external partners
- Strengthen organisational resilience against multi-party threats while maintaining operational efficiency
-
14:15
State of the Union: From the Trenches
Andrew Latham - Lead Principal Sales Engineer - APJ - Obsidian Security
“What actually gets exploited in AI, third-party, and supply chain — not what the reports say”
Every vendor report this year will tell you what security teams are worried about. I'm going to tell you what actually got exploited. Those are two different lists.
None of this was novel. No zero-days, no exotic AI attacks — just agents nobody inventoried, access nobody revoked, and grants nobody reviewed. The attackers aren't outpacing you. You're just not doing the boring stuff at scale. Fix the boring stuff.
-
14:40
Fireside Chat
Strategic Cloud Resilience: Aligning Security with Executive Risk and Continuity PrioritiesDonald Ong - Senior Assistant Director / Cloud Cybersecurity Programme Office - CSA
- How has cloud resilience shifted from a technical concern to a board-level priority?
- How can cloud security initiatives be aligned with executive goals around continuity, risk management, and regulatory accountability?
- How do leaders translate technical security controls into outcomes executives actually care about?
- What does “resilience by design” look like in modern cloud architectures?
- How should security and technology leaders communicate cloud risk and readiness to the C-suite and board?
Moderator
Jannem Yong VP, Cyber Defence & Resilience MediaCorpSpeaker
Donald Ong Senior Assistant Director / Cloud Cybersecurity Programme Office
CSA -
15:05
Afternoon Tea & Networking in the Exhibition Area
-
15:35
Interactive Simulation
Cloud Security Scenario: Responding to Risk in Real TimeSanjeev Gathani - Group Compliance Officer - RV Health
The Scenario: To be announced on the day
In this interactive session, participants will be presented with a real-world cloud security scenario and asked to work in small groups to assess the risk and develop a practical response strategy.
Each group will consider technical, operational, and organisational impacts before agreeing on a mitigation approach. The exercise reflects real-world decision-making under pressure, uncertainty, and competing priorities.
Groups will then share their findings with the wider audience, enabling comparison
of approaches and encouraging discussion around different risk perspectives and response strategies.
Session Format
Part 1: Group Work (30 minutes)
• Participants will break into small groups (4–6 people per group) to:
• Analyse the scenario and identify key risks or vulnerabilities
• Define immediate containment and response actions
• Consider longer-term remediation and resilience measures
• Highlight any governance, compliance, or communication challenges
• Agree on a clear group response to present back
Part 2: Group Sharing (15 minutes)
Each group will briefly present:
• Their interpretation of the core issue
• Their proposed response strategy
• Key trade-offs or challenges they identified
Hosted by Sanjeev Gathani Group Compliance Officer RV Health -
16:20
Closing Remarks
-
16:25
Close of Cloud Security Singapore 2026
Not Found