Catherine (Cat) Karow
Cat Karow built security for Apple, the White House, and Fortune 100s. Then her mom got scammed, and she discovered the next cybersecurity frontier wasn't infrastructure. It was human beings.
Jacksonville, Florida, United States
Actions
Cat Karow spent two decades securing some of the world's most complex institutions, including Apple, the White House, Fortune 100 companies, and large-scale research infrastructure. Then her mother became the target of a sophisticated scam, and she realized the biggest security problem wasn't in the systems she was protecting. It was in the people using them.
Today, Cat is the CEO and Technical Co-Founder of ZoraSafe, an AI-powered platform helping individuals identify and avoid scams, fraud, and digital manipulation before harm occurs. Her work focuses on the rapidly evolving intersection of cybersecurity, artificial intelligence, social engineering, consumer protection, and human behavior.
A TEDx speaker, cybersecurity leader, and founder, Cat explores how emerging technologies are reshaping trust, influence, and decision-making in modern society. Her talks examine topics ranging from AI-enabled fraud and human risk to data brokers, behavioral prediction, digital rights, and the growing influence of invisible systems on everyday life.
Cat is a founding member of Hack The Box, a Global Startup Awards North America Regional Finalist, author of *The Shield* cybersecurity publication, and the forthcoming author of *SOLD: How America Built a Legal Market for Human Beings*, a book examining the hidden economy behind personal data.
A self-taught technologist, disabled founder, and former theater performer, Cat brings a rare combination of technical depth, storytelling, and systems thinking to conversations about the future of technology and its impact on people.
Area of Expertise
Topics
Building AI Products for the People Tech Left Behind
What happens when the most powerful technology of our time is designed for the least vulnerable? While enterprise AI accelerates, millions of people—seniors, disabled users, and digital novices—are left without tools that support or protect them. This session explores how to build inclusive, safety-forward AI platforms that adapt to cognitive load, digital literacy, and trust thresholds. Using ZoraSafe as a case study, we’ll examine how to engineer AI products that not only detect threats, but teach and support users in real time. From scam prevention to memory support, this talk is a rallying cry to expand who we build AI for—and how.
Oops, My Grandma Clicked It Again: Real-Life Lessons from the Frontlines of Scam Prevention
Scams are getting smarter. Victims are getting younger- and older. And cybersecurity still hasn’t figured out how to help the people who need protection the most. This talk walks through real-world examples of modern scams targeting seniors, kids, and everyday users- and the security gaps they exploit. It covers emotional attack patterns, where technical tools fail, and how defenders can design systems that actually work in the wild. From failed alerts to AI-powered coaching, attendees will leave with practical strategies for protecting people who don’t live in the SOC.
This isn’t just another phishing talk. It’s a human story with technical insight, actionable tools, and a bit of dark comedy. Because when your mom forwards you a scam email… you respond with architecture diagrams and empathy.
Oops, My Grandma Clicked It Again: Real-Life Lessons from the Frontlines of Scam Prevention
Scams are getting smarter. Victims are getting younger- and older. And cybersecurity still hasn’t figured out how to help the people who need protection the most. This talk walks through real-world examples of modern scams targeting seniors, kids, and everyday users- and the security gaps they exploit. It covers emotional attack patterns, where technical tools fail, and how defenders can design systems that actually work in the wild. From failed alerts to AI-powered coaching, attendees will leave with practical strategies for protecting people who don’t live in the SOC.
This isn’t just another phishing talk. It’s a human story with technical insight, actionable tools, and a bit of dark comedy. Because when your mom forwards you a scam email… you respond with architecture diagrams and empathy.
Play a real (anonymized) scam voicemail
The $10.3B scam economy (FBI IC3 data)
Why seniors are scammer’s #1 target
Kids as the new frontier: fake scholarships, deepfake DMs
Emotional engineering: urgency, shame, false trust
Where Our Tools Fail
Real case study: when antivirus didn’t help, but a chatbot did
UX breakdown: pop-up warning ≠ protection
Building better: AI coaching, empathy-driven design, gamified training
Red team flips: how you can simulate real scams without being evil
What We Can Do Right Now
Teaching scam spotting like a life skill
“Human-centered threat modeling” explained
Top 5 defensive principles for real-world users
Live demo: calm, clear alert vs. fear-based warning
Open-source checklist: Scam Shield Starter Pack
Audience handout (PDF or QR): “How to explain this talk to your family”
Everyone has a grandma, parent, or friend who’s fallen for a scam. Covers real AI and security tooling while grounded in empathy.
Scamware and the Human Firewall: Protecting People in the Age of Generative AI
As generative AI floods inboxes, messaging apps, and phone calls with ultra-realistic deepfakes and synthetic scams, a new form of cybercrime is emerging: scamware. And most security tools aren’t built to stop it—especially for non-technical users like seniors, students, or frontline workers. This talk explores how cognitive overload, emotional manipulation, and AI-powered deception are rapidly becoming the new threat vector—and how we can defend the human layer with behavioral modeling, real-time education, and digital empathy. Blending cybersecurity with design thinking, this session introduces a fresh approach to digital defense—one that treats users not as the weakest link, but as the first responders of the AI era.
When AI Fails the Vulnerable: Risk, Responsibility, and the Real-World Impact of Overlooked Users
Too often, AI risk conversations center around data leakage or model bias- while ignoring the real-world consequences for those most exposed: seniors, disabled users, and non-technical individuals. This talk examines the human cost of AI design that assumes high literacy, digital fluency, or perfect attention. With case studies from scam victims and AI-driven deception, we’ll spotlight failure points in design and deployment- and offer design principles for systems that adapt to human vulnerability instead of punishing it.
Learning Objectives:
Examine how current AI design patterns fail high-risk user populations
Learn principles of inclusive, safety-first AI UX
Build awareness of ethical gaps in real-world AI deployment
The Phish Is the Payload: Reconstructing the AI Fraud Stack Behind the Message
Security investigations often begin with the artifact the victim noticed: a phishing email, fraudulent text, cloned voice, fake support call, or payment request.
That artifact is usually not the attack. It is the payload produced by a larger operational stack.
Before contacting a victim, attackers can combine breached records, brokered identity data, public sources, social graphs, household relationships, property data, behavioral signals, and recent life events. Generative AI, voice cloning, spoofing infrastructure, automated messaging, and channel switching can then convert that intelligence into a campaign designed to establish trust, survive suspicion, and move the victim toward payment or account compromise.
This session reconstructs a realistic AI-enabled fraud operation from target discovery through monetization. We will map the attacker’s data sources, enrichment workflow, identity construction, pretext generation, persuasion logic, delivery infrastructure, trust transitions, and payment path.
A controlled demonstration will show how fragmented personal data can be transformed into an adaptive impersonation campaign, then trace the technical and behavioral artifacts defenders can observe at each stage.
Attendees will leave with a repeatable Human Exploit Chain model for investigating beyond the visible lure, distinguishing capabilities genuinely introduced by AI from older tactics made faster and cheaper, and identifying defensive choke points before the victim reaches the point of no return.
Session format
Conference session
Level
300: Advanced
Session duration
45 minutes
Technical content
OSINT and commercial-data acquisition
Entity resolution and identity enrichment
Relationship and household graph construction
Target selection and vulnerability signals
Synthetic identity and pretext generation
Voice-cloning workflow and limitations
Caller-ID spoofing and communications infrastructure
Cross-channel campaign orchestration
Payment coercion and monetization paths
Detection artifacts and intervention opportunities
Threat modeling for human-targeted operations
Demonstration
A safe, controlled reconstruction using a synthetic target profile:
Assemble fragmented identity data
Build a relationship graph
Generate and adapt a fraud pretext
Produce a synthetic identity artifact
Move the campaign across channels
Map telemetry and interruption points
No live victim data, criminal services, or operational abuse infrastructure will be used.
Attendee takeaways
Reconstruct AI-enabled fraud beyond the email, text, or call that triggered the investigation
Map attacker inputs, tooling, dependencies, trust transitions, and observable artifacts
Identify opportunities to disrupt targeting, impersonation, delivery, and monetization before loss occurs
Why it is new
The contribution is not another overview of AI scams. The session models fraud as a connected technical and behavioral system, showing how lawful data, compromised data, communications tooling, generative systems, and payment infrastructure combine into one operational chain.
Speaker notes
This session is vendor-neutral and contains no ZoraSafe product demonstration. It draws from documented fraud patterns, threat research, consumer cases, social-engineering analysis, and direct experience building human-centered fraud defenses.
AI Theater in Security: How to Tell What’s Real, Rebranded, and Useless
Security teams are being sold AI-powered everything: AI SOC analysts, AI threat detection, AI automation, AI copilots. But how much of this represents genuine capability?
This talk examines:
- Common AI-washing patterns in security products
- Rebranded classical ML
- LLM wrappers around existing workflows
- AI summarization marketed as automation
- Rule engines labeled as AI
We also provide:
- Technical evaluation frameworks
- Questions to ask vendors
- POC testing strategies
- Red flags in demos and documentation
This session aims to provide practitioners with a practical, technical approach to evaluating AI claims in security tooling.
Security teams risk making major investments based on marketing claims. This talk helps practitioners evaluate AI claims with technical rigor.
The Human Attack Surface: How Behavioral Data Became Critical Infrastructure
For decades, cybersecurity focused on protecting computers.
We built firewalls for networks, EDR for endpoints, IAM for identities, and entire industries dedicated to defending digital infrastructure.
But while security teams were protecting machines, another infrastructure was quietly being built.
Data brokers collected behavioral data. Advertising platforms optimized engagement. Recommendation engines learned attention patterns. Social media platforms refined persuasion systems. Together, these industries created an unprecedented capability: the ability to predict, influence, and target human behavior at scale.
AI did not create this system.
AI plugged into it.
Today, attackers can leverage behavioral intelligence, identity simulation, voice cloning, emotional optimization, and hyper-targeted persuasion in ways that were previously impossible. The result is a fundamental shift in the threat landscape. Human behavior itself is becoming an attack surface.
This session examines how decades of data collection, behavioral analytics, advertising technology, and machine learning converged to create what may be the largest human-targeting infrastructure ever assembled. Drawing from cybersecurity, fraud operations, social engineering, and AI systems, we will explore how influence became programmable and why defenders need to rethink what it means to secure people in the age of prediction.
The next major attack surface may not be networks, endpoints, or identities.
It may be human behavior itself.
Session Type: Conference Session / Security Research / Emerging Threats
Target Audience:
Security researchers, threat intelligence teams, fraud investigators, red teams, blue teams, AI practitioners, privacy researchers, and security leaders.
Technical Level:
Intermediate
Preferred Length:
45 minutes
Topics Covered:
Behavioral targeting
Data brokers
Human risk
Social engineering
AI-enabled manipulation
Fraud infrastructure
Trust systems
Security strategy
Originality:
This talk presents a novel framework connecting behavioral data ecosystems, AI systems, social engineering operations, and cybersecurity threat models. It introduces the concept of the Human Attack Surface as an emerging category of security risk and examines how behavioral infrastructure is increasingly being leveraged for offensive operations.
Media Availability:
Yes
Village Track Suitability:
Yes, particularly for AI, Privacy, Human Risk, Social Engineering, or Threat Intelligence-focused tracks.
The Persuasion Engine: How Human Influence Became Computable
For decades, cybersecurity focused on protecting information.
At the same time, an entirely different industry was solving a different problem.
Advertising platforms learned how to capture attention.
Data brokers learned how to profile behavior.
Recommendation systems learned how to optimize engagement.
Machine learning learned how to predict decisions.
Then generative AI arrived.
Suddenly, the ability to understand people, predict people, target people, and persuade people began converging into a single operational stack.
This session argues that we are witnessing a fundamental shift in the threat landscape: persuasion itself is becoming computable.
Modern attackers no longer need to guess who to target, what to say, when to say it, or how to build trust. Increasingly, those decisions can be informed by behavioral data, optimized by machine learning, generated by AI, and delivered across coordinated channels at scale.
Drawing on examples from fraud operations, social engineering campaigns, data brokerage, behavioral targeting, and AI-enabled deception, this talk examines how influence is evolving from an art into an engineering discipline.
The result is not simply better scams.
It is the emergence of programmable persuasion as a security problem.
Attendees will leave with a new framework for understanding how behavioral intelligence, AI systems, and influence infrastructure are reshaping both offensive and defensive security.
Session Type:
Security Research / AI Security / Human Risk / Emerging Threats
Technical Level:
Intermediate
Audience:
Security researchers, threat intelligence teams, fraud investigators, red teams, blue teams, AI practitioners, security architects, and cybersecurity leaders.
Topics Covered:
Social engineering
Behavioral targeting
Data brokers
AI-enabled persuasion
Human risk
Threat modeling
Fraud operations
Influence systems
Original Contribution:
This talk introduces the concept of computable persuasion as an emerging security paradigm. Rather than treating fraud, social engineering, behavioral targeting, AI-generated content, and influence operations as separate domains, it presents them as components of a unified persuasion stack that increasingly functions as an operational capability.
Preferred Length:
45 minutes
Village Track Suitability:
AI, Threat Intelligence, Human Risk, Social Engineering, Privacy, an
The Human Exploit Chain: How AI Turns Personal Data Into Precision Fraud
Fraud is usually analyzed at the moment of contact: the phishing email, cloned voice, fraudulent text, or urgent call. By then, the attack is already underway.
Modern social engineering begins earlier, with breached data, brokered profiles, identity resolution, relationship mapping, behavioral signals, and vulnerability discovery. Attackers combine this intelligence with generative AI, voice cloning, spoofed identities, and automated messaging to create personalized, adaptive campaigns.
This session introduces the Human Exploit Chain, a framework for mapping AI-enabled fraud from data collection and target selection through identity simulation, persuasion, multi-channel coordination, payment coercion, and repeated victimization.
Attendees will learn to analyze these campaigns as connected systems, separate new AI capabilities from accelerated old tactics, and identify practical defensive intervention points.
Session Type: Technical Conference Session / Cybercrime Research / Emerging Threats
Preferred Track: Cybercrime, AI and Cybersecurity, Threat Intelligence, Fraud, Human Factors
Technical Level: Intermediate
Preferred Duration: 45 minutes, with optional Q&A
Target Audience:
Security researchers, threat intelligence teams, fraud investigators, financial security teams, red teams, blue teams, identity specialists, privacy researchers, AI practitioners, platform security teams, and security leaders.
Technical Topics Covered:
• Data acquisition through breaches, public records, data brokers, social platforms, and compromised accounts
• Identity resolution, entity enrichment, relationship mapping, and target prioritization
• Behavioral and vulnerability profiling
• Generative AI-assisted pretexting and adaptive scripting
• Voice cloning, synthetic media, spoofing, and identity simulation
• Cross-channel attack orchestration
• Trust transitions and persuasion mechanics
• Payment coercion, mule networks, account takeover, and victim-list reuse
• Defensive telemetry and intervention opportunities
• Threat modeling for human-targeted attack systems
Original Contribution:
This session introduces the Human Exploit Chain, a security framework that models modern fraud as a connected operational system. Rather than treating phishing, impersonation, voice cloning, data brokerage, social engineering, and payment fraud as separate categories, the framework maps how they combine across seven stages:
Data acquisition
Target enrichment
Vulnerability and timing analysis
Identity construction
Persuasion execution
Channel and payment orchestration
Monetization, reuse, and repeated targeting
Each stage is evaluated through four defensive questions:
• What data does the attacker require?
• What decisions or capabilities can be automated?
• What trust transition must occur?
• Where can the operation be detected, disrupted, or delayed?
The session draws from documented fraud campaigns, cybersecurity and threat-intelligence reporting, consumer scam cases, data-broker practices, social engineering research, and lessons from building consumer fraud-prevention technology.
The presentation is vendor-neutral and will not promote specific commercial products.
First Public Delivery: New for 2026
Media Availability: Yes
Photography: Yes
AI or Theater? How to Test What Security Products Actually Do
Security vendors now promise AI analysts, autonomous detection, intelligent triage, predictive defense, and machine-speed response. But beneath the label may be a rule engine, a legacy model, an LLM summarizer, or a workflow that still depends heavily on human judgment.
This session introduces a practical framework for testing AI claims in security products. Attendees will learn how to separate automation, classical machine learning, generative AI, and genuinely adaptive capability by examining system boundaries, model behavior, decision authority, data dependencies, failure modes, and human intervention.
The talk covers benchmark design, hallucination testing, prompt sensitivity, reproducibility, latency, privacy, ground-truth validation, and adversarial evaluation. It also shows how polished demos can conceal brittle systems, hidden manual work, and narrow operating conditions.
Attendees will leave with a reusable verification matrix for evaluating AI security tools during vendor selection, technical reviews, and proof-of-concept testing.
Session Type: Technical Conference Session / Security Engineering / AI Evaluation
Technical Level: Intermediate
Preferred Duration: 45 minutes
Target Audience: Security engineers, architects, SOC leaders, CISOs, procurement teams, product security teams, AI practitioners, analysts, and technical decision-makers.
Technical Topics:
• Rule engines, classical machine learning, LLMs, and agentic workflows
• Model inputs, outputs, boundaries, and decision authority
• Benchmark and ground-truth design
• Hallucination, nondeterminism, and prompt sensitivity
• Adversarial and out-of-distribution testing
• Human-in-the-loop dependencies
• Data retention, privacy, and model-training exposure
• Latency, scalability, cost, and operational reliability
• Demo manipulation and hidden manual processes
• Proof-of-concept test design
Original Contribution:
This session introduces the AI Security Capability Verification Matrix, a structured method for assessing what an AI-enabled security product actually does, how reliably it performs, and where its claims exceed its demonstrated capabilities.
The presentation is vendor-neutral and does not promote commercial products.
First Public Delivery: New for 2026
Built for Marketing, Weaponized for Fraud: The Data Pipeline Behind Precision Scams
Many targeted scams begin before the phishing email, fake call, or stolen credential. They begin with information collected, inferred, enriched, and sold through legal data markets.
Data brokers, people-search services, public records, advertising data, and breach information can reveal where someone lives, who they trust, what they own, and when they may be vulnerable. Combined, this data becomes operational intelligence for fraud.
This session maps that pipeline from data collection and target selection through relationship mapping, impersonation, and payment coercion. It also introduces a practical framework for assessing when lawful data practices create fraud-enablement risk and where defenders, platforms, financial institutions, and policymakers can intervene before victim contact occurs.
Session Type: Law and Policy / Cybercrime / Data Protection / Emerging Threats
Technical Level: Intermediate
Preferred Duration: 45 minutes
Target Audience: Security researchers, privacy professionals, threat intelligence teams, fraud investigators, financial institutions, policymakers, platform security teams, data governance leaders, and consumer protection professionals.
Topics Covered:
• Data brokers and identity-resolution systems
• People-search platforms and public-record aggregation
• Advertising data and audience enrichment
• Breach data combined with lawful consumer information
• Household, relationship, and social-graph mapping
• Behavioral inference and vulnerability proxies
• Life-event and timing intelligence
• Fraud targeting and impersonation workflows
• Data minimization, deletion, and access controls
• Regulatory and accountability gaps
• Defensive intervention points across the data lifecycle
Original Contribution:
This session introduces the Fraud Enablement Risk Model, a framework for evaluating whether a dataset, enrichment service, or profiling capability materially increases the precision, credibility, or scalability of targeted fraud.
Rather than treating privacy, data brokerage, and cybercrime as separate domains, the session maps how they operate as one connected system.
The presentation is vendor-neutral and grounded in documented fraud patterns, data-broker practices, cybersecurity reporting, and consumer scam cases.
First Public Delivery: New for 2026
Your User Is Under Attack: Designing Products for Fear, Pressure, and Manipulation
Most product teams design for a user who does not exist.
That user is calm, attentive, technically confident, emotionally regulated, and free to make rational decisions. Real users open products while distracted, exhausted, aging, grieving, disabled, financially stressed, or being deliberately manipulated.
In those moments, ordinary product assumptions become dangerous. A confusing warning becomes an ignored warning. A buried recovery path becomes a permanent loss. A “frictionless” experience makes the attacker’s job easier. A feature that works perfectly in testing can collapse when the user is scared.
After two decades building technology and security for organizations including Apple, the White House, and Fortune 100 companies, Cat Karow confronted this failure directly when her mother was targeted by a sophisticated scam. It forced her to rethink how products should behave when users are not merely making mistakes, but operating inside an adversarial environment.
This session introduces the Adversarial User Journey, a framework for designing products around the moments when cognitive load, emotional pressure, urgency, authority, and deception distort normal behavior.
Attendees will learn how to:
• Identify where product flows assume calm and rational behavior
• Model fear, urgency, fatigue, and manipulation as product conditions
• Design warnings that interrupt action instead of decorating it
• Build safer defaults, recovery paths, and trusted escalation
• Test products under pressure, not only under ideal conditions
• Recognize when convenience creates leverage for an attacker
The next generation of product design will not be judged only by how easily users complete a task.
It will be judged by whether the product still protects them when someone else is trying to control what they do next.
1st Track
Product Teams: Leaders, Engineers, Designers & Workflows
2nd Track
Product Lifecycle: AI Augmentation & Automation
Session Format
Conference Talk
Keynote
Fireside Chat
The Product Cost of Being Wrong: What AI Roadmaps Forget to Build
AI features are often justified by the work they eliminate: faster research, instant drafts, automated decisions, fewer manual steps. But every probabilistic product creates new work around the output.
Someone must decide whether the answer is correct, complete, safe, current, and appropriate. Someone must catch the mistake, understand why it happened, repair the damage, and determine whether the system can be trusted again. That burden may fall on the user, an employee, a reviewer, a support team, or no one at all.
This session examines the hidden product cost of AI uncertainty. It introduces a framework for evaluating not only what an AI feature can produce, but everything the organization must build around it: verification, provenance, confidence signals, correction, escalation, reversibility, monitoring, and accountability.
Attendees will learn how to identify features that create more downstream work than they remove, compare AI opportunities by the cost of failure rather than novelty, and recognize when automation is simply relocating labor into review, support, and risk.
The central question is no longer only, “Can AI perform this task?”
It is, “What must the rest of the product become because the machine may be wrong?”
Session Format
Conference Talk
Keynote
Workshop
Target Audience
Product leaders, product managers, founders, engineering leaders, designers, AI teams, security and risk leaders, customer experience teams, and executives responsible for AI product strategy.
Technical Level
Intermediate
Preferred Duration
45–60 minutes
Attendee Takeaways
• A framework for evaluating the true operational cost of an AI feature
• A method for comparing AI opportunities by uncertainty, detectability, reversibility, and consequence
• A way to identify where verification labor will land before the feature ships
• Practical guidance for designing confidence signals, provenance, correction paths, escalation, and recovery
• A clearer standard for deciding when AI should assist, recommend, automate, or stay out of the workflow
Original Framework
The session introduces the Product Cost of Being Wrong framework, which evaluates AI features across six dimensions:
Error detectability
Verification burden
Reversibility
Downstream consequence
Accountability
Trust recovery
The framework helps teams distinguish between AI that creates genuine leverage and AI that merely transfers work from creation into review, correction, support, and risk.
Why This Matters
Most AI roadmaps measure model capability, adoption, speed, and cost per output. They rarely account for the product infrastructure required when outputs are uncertain.
That missing layer often determines whether an AI feature becomes valuable, expensive, dangerous, or quietly abandoned.
First Public Delivery
New for 2027
Commercial Content
None. The session is vendor-neutral and does not promote a product or service.
The Phish Is the Payload: Reconstructing the AI Fraud Stack Behind the Message
Security teams often begin investigating where the victim first noticed the attack: the text, email, cloned voice, fake support call, or payment request.
That is usually the final delivery mechanism, not the operation.
Before contact, attackers may already have assembled breached credentials, brokered identity data, household relationships, public records, behavioral signals, recent life events, and likely sources of authority. Generative AI, voice cloning, spoofing infrastructure, and automated messaging then convert that intelligence into a personalized campaign designed to survive suspicion and move the victim across channels.
This session tears down a realistic AI-enabled fraud operation from target discovery to monetization. We will reconstruct the attacker’s data sources, enrichment workflow, identity fabrication, pretext generation, trust transitions, channel orchestration, and payment path. At each stage, we will map required inputs, tooling, dependencies, observable artifacts, and opportunities for disruption.
Attendees will leave with a reusable Human Exploit Chain model for investigating what happened before the visible lure, separating truly new AI capabilities from familiar tactics operating at greater speed and scale, and designing controls that interrupt the campaign before the victim reaches the point of no return.
Session Format
1-hour technical talk
Topics
AI Security
Social Engineering
Threat Intelligence
OSINT
Fraud and Cybercrime
Threat Modeling
Blue Team
Privacy
What will attendees walk away with?
• A method for reconstructing fraud operations beyond the email, text, or phone call that triggered the investigation
• A seven-stage model for mapping attacker data, tooling, decisions, dependencies, trust transitions, and observable artifacts
• Defensive intervention points across identity systems, communications platforms, financial controls, enterprise telemetry, and consumer protection
Level
Intermediate
Can we record your talk?
Yes. The session may be recorded and published.
First-Time Speaker?
No.
Can you present in person in Huntsville March 20?
Yes.
Workshop Logistics
Not applicable. This is a one-hour conference talk.
AI or Theater? Breaking the Claims Behind “AI-Powered” Security Tools
Security vendors now promise AI analysts, autonomous triage, predictive detection, intelligent remediation, and machine-speed response. But beneath the label may be a rule engine, a legacy statistical model, an LLM summarizer, or a workflow still dependent on human operators.
This session shows how to test those claims.
We will break down the technical differences between rules, automation, classical machine learning, generative AI, and agentic systems, then examine how vendors blur those boundaries in demos and marketing. Attendees will learn how to design practical tests for hallucination, nondeterminism, prompt sensitivity, model drift, hidden human intervention, weak ground truth, out-of-distribution inputs, latency, privacy exposure, and failure under realistic workloads.
The session introduces an AI Security Capability Verification Matrix that teams can use during proofs of concept, architecture reviews, and purchasing decisions. Rather than asking whether a product “uses AI,” the framework asks what decisions the system actually makes, what evidence supports those decisions, how failures appear, and who must intervene when the model is wrong.
Attendees will leave with a repeatable method for separating genuine capability from automation, rebranding, and polished theater.
Session Format
1-hour technical talk
Topics
AI Security
Security Tooling
Security Testing
Architecture
Blue Team
GRC
Machine Learning
Vendor Evaluation
What will attendees walk away with?
• A practical method for distinguishing rules, automation, machine learning, generative AI, and agentic behavior
• Reusable tests for hallucination, nondeterminism, prompt sensitivity, privacy, latency, drift, and hidden human intervention
• A verification matrix for evaluating AI security tools during proof-of-concept testing and procurement
Level
Intermediate
Can we record your talk?
Yes.
First-Time Speaker?
No.
Can you present in person in Huntsville March 20?
Yes.
Workshop Logistics
Not applicable. This proposal is for a one-hour conference talk.
Your Warning Is Technically Correct and Completely Useless
Security teams spend enormous effort detecting threats, then hand the final decision to a frightened user through a banner, modal, push notification, or block page.
“Suspicious activity detected.”
“Do you want to continue?”
“This connection may not be secure.”
The warning may be technically accurate and still fail completely.
Attackers manufacture urgency, authority, fear, secrecy, and cognitive overload. Under those conditions, users do not read security messages the way designers expect. They dismiss warnings, follow the attacker’s instructions, work around controls, or interpret friction as proof that the attacker’s story is real.
This session examines security warnings as part of an adversarial system. We will dissect common warning patterns, map how attackers neutralize them, and trace where responsibility shifts from detection logic to interface design, timing, escalation, and recovery.
The talk introduces the Adversarial Warning Model, a framework for evaluating whether a security control can interrupt action when the user is already under pressure. Attendees will learn how to test warnings against attacker narratives, reduce dangerous ambiguity, design safer defaults, create trusted escalation paths, and measure whether a warning changes behavior rather than merely appears on screen.
A warning that the user ignores is not a completed control. It is an unhandled detection.
Session Format
1-hour technical talk
Topics
Security Usability
Human Factors
Social Engineering
Blue Team
Threat Modeling
Security Architecture
Application Security
Security Awareness
What will attendees walk away with?
• A framework for evaluating warnings under urgency, fear, authority, and attacker coaching
• Practical methods for testing whether security controls interrupt harmful action rather than merely display information
• Design patterns for safer defaults, escalation, recovery, and high-risk decision points
Level
Intermediate
Can we record your talk?
Yes. The session may be recorded and published.
First-Time Speaker?
No.
Your App Is a Weapon: When Product Decisions Become Infrastructure for Harm
Most harmful technology is not built by villains.
It is built by ordinary teams optimizing reasonable goals: engagement, conversion, personalization, retention, growth, and reduced friction.
But product decisions do not stay inside the interface. Recommendation systems shape attention. Targeting systems identify vulnerability. Growth mechanics reward compulsion. Frictionless workflows can make fraud, manipulation, surveillance, and exploitation easier to scale.
This session examines how normal product choices become infrastructure for harm, even when no one on the team intended that outcome.
We will look at how data collection, behavioral prediction, AI-generated content, persuasive design, and automated decision-making can create leverage over users. Attendees will learn how to identify misuse pathways before launch, evaluate who benefits from a feature and who absorbs the risk, and pressure-test product decisions against adversarial use.
The goal is not to stop innovation.
It is to help builders recognize when they are creating a useful feature, and when they are quietly giving someone else a weapon.
This is a vendor-neutral session for developers, product managers, designers, founders, security professionals, data practitioners, and technology leaders.
The talk introduces a practical Product Harm Review built around five questions:
• What new capability does this feature create?
• Who else can use that capability?
• What data or leverage does it expose?
• Which users carry the most risk?
• What happens when the feature works exactly as designed for the wrong person?
The session is designed for 45 minutes of content followed by 15 minutes of Q&A. I am available to present virtually at 8:30 p.m. Eastern.
Built for Everyone, Designed for Almost No One: Who AI Products Leave Behind
AI products are often presented as universal tools, but many are designed around a narrow imaginary user: technically confident, verbally precise, cognitively unburdened, and able to recognize when the system is wrong.
Real users may be aging, disabled, overwhelmed, grieving, frightened, distracted, unfamiliar with technology, or making decisions under pressure. These are often the people who could benefit most from AI, yet they are also the people most likely to be excluded by unclear interfaces, uncertain outputs, inaccessible workflows, and products that quietly transfer verification back to the user.
Drawing from her experience building consumer safety technology after her mother was targeted by a sophisticated scam, Cat Karow examines how AI systems fail when they are designed for capability rather than real human conditions.
Attendees will learn how to identify hidden assumptions in AI experiences, design for users with different levels of confidence and capacity, and build products that remain useful when life is messy, stressful, and deeply human.
Small Print
Session Type: AI / Product Design / Accessibility / Human-Centered Technology
Audience: Developers, product managers, designers, founders, AI practitioners, accessibility professionals, technical leaders, and anyone responsible for building technology for broad audiences.
Technical Level: Beginner to Intermediate
Preferred Format: 45-minute presentation plus 15-minute Q&A
Attendee Takeaways:
Identify the “ideal user” assumptions embedded in AI products
Evaluate how cognitive load, stress, disability, age, and technical confidence affect AI usability
Design clearer confidence signals, recovery paths, escalation options, and safer defaults
Recognize when an AI product is shifting complexity and risk back onto the user
This is a vendor-neutral educational session. It does not promote a product or service.
First Public Delivery: New for 2026–2027
Stop Trying to Make Your Tech Career Make Sense
Technology careers are usually presented as ladders: choose a specialty, collect the right credentials, move through increasingly senior titles, and tell a clean story about how every role led logically to the next.
Many real careers look nothing like that.
They include layoffs, illness, caregiving, lateral moves, unfinished degrees, toxic workplaces, jobs taken for survival, unexpected opportunities, and skills acquired far outside a formal role. Women, disabled professionals, self-taught technologists, founders, and career changers are often encouraged to hide that complexity and manufacture a more conventional narrative.
Cat Karow’s career moved from repairing phones and supporting schools to research computing, cybersecurity, operations, product development, AI, executive leadership, and founding a technology company. The path did not look coherent on paper. The connections between those experiences became her greatest advantage.
This session helps attendees identify the pattern, translation, recovery, and boundary-crossing capital hidden inside a nonlinear career, then turn that experience into a clear and credible professional story.
Small Print
Session Type: Career Development / Leadership / Women in Technology / Entrepreneurship
Audience: Women in technology, career changers, self-taught professionals, founders, disabled technologists, emerging leaders, and anyone whose career does not resemble a traditional ladder.
Technical Level: All Levels
Preferred Format: 45-minute presentation plus 15-minute Q&A
Attendee Takeaways:
Identify transferable forms of career capital across unrelated roles
Build a professional narrative around recurring strengths rather than job-title chronology
Reframe pivots, interruptions, lateral moves, and unconventional experience as evidence of capability
Recognize when being difficult to categorize is a strategic advantage
The session introduces four forms of nonlinear career capital:
Pattern capital
Translation capital
Recovery capital
Boundary-crossing capital
This is a candid, practical, story-driven session rather than a motivational speech or company presentation.
First Public Delivery: New for 2026–2027
The Dashboard Is Green. The Business Is on Fire.
Modern business systems are excellent at proving that work happened.
Cases closed. Approvals completed. Automations succeeded. Tasks resolved. SLAs met. Dashboards glow green.
And yet customers may still be waiting, employees may be building workarounds, exceptions may be disappearing, and the process may be failing everywhere that matters.
This session examines the gap between operational activity and actual business outcomes. It shows how CRM, ERP, workflow automation, and reporting systems can create false confidence when teams measure completion instead of impact.
Attendees will learn how to identify metrics that reward motion without progress, trace where process failures vanish from reporting, and redesign dashboards around customer, employee, financial, and operational outcomes.
The goal is not fewer metrics. It is better evidence.
A green dashboard should mean the business is healthy, not merely that the software completed its assigned steps.
Small Print
Session Type: Business Strategy / Process Optimization / Reporting / Operational Excellence
Preferred Length: 45 minutes
Target Audience: Business analysts, product owners, functional consultants, solution architects, operations leaders, CRM and ERP teams, Power Platform practitioners, customer experience leaders, finance teams, and executives responsible for business performance.
Attendee Takeaways:
Distinguish activity metrics from outcome metrics
Identify where dashboards hide customer pain, employee workarounds, and operational exceptions
Trace a KPI back to the business behavior it rewards
Redesign reporting around outcomes, failure signals, and recovery
Recognize when “successful execution” is masking process failure
Original Framework: The Green Dashboard Audit
The session introduces a five-part review for evaluating whether operational reporting reflects reality:
Activity: What did the system record as completed?
Outcome: What changed for the customer, employee, or business?
Exception: What failed, bypassed the process, or never entered the system?
Workaround: What manual labor exists outside the official workflow?
Consequence: What happened because the process succeeded or failed?
Examples may include:
Service cases closed without the customer’s issue being resolved
Sales activity rising while conversion quality declines
Approval workflows completing while cycle time worsens
Automation runs succeeding while employees quietly correct the results
SLA compliance improving while customer trust falls
Finance and operations dashboards missing rework, exceptions, and downstream delays
Commercial Content: None. This is a vendor-neutral educational session.
First Public Delivery: New for 2026
Your Automation Worked. Your Business Process Failed.
A workflow can execute perfectly and still make the business worse.
The approval routes correctly. The record updates. The notification fires. The case closes. The automation reports success.
But the customer waits longer. Employees create side channels. Important exceptions disappear. Human judgment is removed at the wrong moment. A bad decision simply moves faster.
The problem is not always broken automation. Often, it is a broken process that was automated before anyone examined its assumptions, ownership, failure paths, or real-world consequences.
This session introduces a practical method for determining whether a process is ready to automate. Attendees will learn how to identify hidden judgment, map exception paths, preserve accountability, design escalation and recovery, and measure whether automation improves the outcome rather than merely accelerating completion.
Automation should not make a bad process faster, quieter, and harder to challenge.
Products
Power Platform
Customer Engagement
Finance & Operations / SCM
Business Central
Level
Intermediate
Small Print
Session Type: Power Platform / Workflow Automation / Business Process Design / Digital Transformation
Preferred Length: 45 minutes
Target Audience: Power Platform practitioners, business analysts, developers, functional consultants, solution architects, product owners, operations leaders, CRM and ERP teams, process-improvement professionals, and managers responsible for automation strategy.
Attendee Takeaways:
Determine whether a process should be redesigned before automation
Identify where human judgment, context, and accountability are required
Map exceptions, escalation paths, rollback, and recovery before launch
Separate workflow execution from business success
Detect when automation is moving risk downstream rather than removing work
Original Framework: The Automation Readiness Review
The session evaluates a process across six dimensions:
Outcome: What result is the process supposed to create?
Judgment: Where does interpretation or discretion still matter?
Exceptions: What happens when reality does not match the happy path?
Ownership: Who is responsible for the automated outcome?
Reversibility: Can the action be corrected, rolled back, or escalated?
Evidence: How will the organization know the process actually improved?
Examples may include:
Approval workflows that automate delay instead of reducing it
Service automations that close cases without resolving customer problems
CRM updates that improve data completeness while degrading data quality
Financial workflows that eliminate review at high-risk moments
AI-assisted processes that create hidden verification and exception-handling work
Automations that succeed technically while employees maintain parallel manual systems
Commercial Content: None. This is a vendor-neutral educational session.
First Public Delivery: New for 2026
AI or Theater? A Technical Teardown of “AI-Powered” Security
Security products now promise autonomous analysts, intelligent triage, predictive detection, AI-generated remediation, agentic response, and machine-speed investigation.
But what is the system actually doing?
Behind the AI label may be deterministic rules, classical machine learning, retrieval, an LLM summarizer, a scripted workflow, hidden human review, or a model operating within conditions far narrower than the product demonstration suggests.
This session presents a technical methodology for testing those claims.
We will decompose AI-enabled security systems into their data sources, model boundaries, decision authority, orchestration layers, human dependencies, and failure paths. A demonstration harness will test representative security workflows for hallucination, nondeterminism, prompt sensitivity, adversarial inputs, weak ground truth, out-of-distribution behavior, latency, privacy exposure, and silent dependence on manual intervention.
The session introduces the AI Security Capability Verification Matrix, a reusable framework for determining what a product detects, predicts, generates, recommends, or actually controls.
Rather than asking whether a security product “uses AI,” attendees will learn to ask which decisions the model makes, what evidence supports them, how failures become visible, whether results can be reproduced, and who must intervene when the system is wrong.
Attendees will leave with practical tests for separating genuine capability from automation, rebranding, and polished theater.
Session format
Conference session
Level
300: Advanced
Session duration
45 minutes
Technical content
Deterministic rules versus statistical models
Classical machine learning versus generative AI
Retrieval-augmented generation
Tool use and agentic orchestration
System boundaries and decision authority
Benchmark and ground-truth design
Hallucination and unsupported inference
Nondeterminism and reproducibility
Prompt sensitivity and prompt-injection exposure
Adversarial and out-of-distribution testing
Hidden human-in-the-loop dependencies
Model drift and update risk
Data retention and training exposure
Latency, cost, and failure under realistic workloads
Logging, auditability, rollback, and escalation
Demonstration
A vendor-neutral evaluation harness will test several representative AI-security behaviors, such as:
Alert summarization
Incident classification
Threat prioritization
Recommended remediation
Natural-language investigation
Agentic task execution
The demonstration will intentionally vary evidence quality, prompt wording, attack context, and unavailable ground truth to show where apparent capability breaks.
Attendee takeaways
Distinguish rules, automation, machine learning, generative AI, and agentic behavior
Build realistic tests for hallucination, nondeterminism, prompt sensitivity, privacy, latency, and hidden human intervention
Use the AI Security Capability Verification Matrix during technical reviews, proofs of concept, and architecture decisions
Original framework
The verification matrix evaluates systems across six layers:
Input integrity: What evidence reaches the system, and what can contaminate it?
Model behavior: What is predicted, generated, classified, or inferred?
Decision authority: Does the system advise, approve, initiate, or act?
Failure visibility: How do users know the system is wrong?
Human dependency: What review or correction remains hidden?
Operational consequence: What happens when the output is trusted?
Speaker notes
The session is vendor-neutral. It will not name or ridicule individual products. The focus is a reproducible technical method attendees can apply to any AI-enabled security system.
Your Warning Is Technically Correct and Completely Useless
This session examines security warnings as controls operating at the human-machine boundary, where attackers actively shape how users interpret risk.
Security teams may successfully detect a threat, generate an accurate warning, and still fail to stop the attack.
The alert appears. The user clicks through.
The block page explains the risk. The user disables the control.
The notification says the transaction may be fraudulent. The victim follows the attacker’s instructions anyway.
The failure is often blamed on the user. But attackers actively shape the conditions in which security controls are interpreted. They manufacture urgency, authority, fear, secrecy, cognitive overload, and social pressure. They coach victims around warnings, reinterpret security friction as evidence that the false story is real, and keep the target moving before doubt can form.
This session treats security warnings as controls operating inside an adversarial system.
We will decompose warnings into detection trigger, timing, message, action choices, default behavior, escalation path, recovery path, and measurable outcome. Using realistic attack narratives, we will test how common warning patterns perform when an attacker is present in the decision loop.
The session introduces the Adversarial Warning Model, a framework for testing whether a control interrupts harmful action or merely transfers the decision to a compromised human state.
Attendees will leave able to threat-model attacker coaching, design safer interruption patterns, instrument behavioral outcomes, and treat ignored warnings as failed controls rather than successful notifications.
Session format
Conference session
Level
300: Advanced
Session duration
45 minutes
Technical content
Warning architecture and control decomposition
Human-machine trust boundaries
Attacker-in-the-loop decision modeling
Social-engineering pretext integration
Warning timing and contextual relevance
Default actions and forced friction
Authority and urgency manipulation
Attacker coaching around controls
Escalation and trusted-contact pathways
Recovery and reversible action design
Behavioral telemetry and outcome measurement
Security usability testing under adversarial conditions
Threat modeling at the human decision layer
Demonstration
A controlled interactive comparison of warning designs under the same attack narrative:
Passive informational warning
Standard confirm-or-cancel modal
Contextual explanation
Friction-based interruption
Delayed high-risk action
Trusted escalation
Reversible quarantine or hold
The demonstration will show why technically accurate wording can fail when timing, defaults, attacker presence, and recovery options are poorly designed.
Attendee takeaways
Threat-model warnings with the attacker present in the user’s decision loop
Distinguish notifications from controls that meaningfully interrupt harmful action
Design and instrument safer defaults, escalation, delay, and recovery around high-risk decisions
Original framework
The Adversarial Warning Model evaluates seven dimensions:
Trigger: Was the right risk detected?
Timing: Did the control appear before commitment?
Interpretation: Can the attacker plausibly explain the warning away?
Default: What happens when the user acts quickly?
Friction: Does the control meaningfully interrupt momentum?
Escalation: Can the user reach a trusted source outside the attacker’s narrative?
Recovery: Can the action be delayed, reversed, or contained?
Speaker notes
This is not a security-awareness presentation. It is a technical and behavioral analysis of warnings as security controls. The session is applicable to application security, identity, financial systems, fraud prevention, browser warnings, endpoint controls, consumer security, and enterprise workflows.
Simply Cyber Con 2025 Sessionize Event
BSides St. Pete 2025 Sessionize Event
BSides Orlando 2025 Sessionize Event
Catherine (Cat) Karow
Cat Karow built security for Apple, the White House, and Fortune 100s. Then her mom got scammed, and she discovered the next cybersecurity frontier wasn't infrastructure. It was human beings.
Jacksonville, Florida, United States
Actions
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top