#StayHappening
Wed Sep 16 2026 at 08:00 am to 04:30 pm UTC-04:00

Appalachia Advance - 5th Annual CyberTech Conference

  • Hershey Lodge · Hershey
  • From USD 50.00
Appalachia Technologies Publisher / Host Appalachia Technologies
Share
Appalachia Advance - 5th Annual CyberTech Conference
Advertisement
A full-day in-person event packed with practical information from industry thought-leaders, including general and breakout sessions.
About this Event

Appalachia Technologies is excited to present Appalachia Advance 2026, a full-day CyberTech Conference focused on Governance, Risk, Compliance (GRC), AI Security, and Cybersecurity.

Our 5th annual in-person event brings together nationally-recognized experts and Appalachia's highly-certified staff to deliver cutting-edge insights on the most pressing challenges facing organizations today.

This year's program features:

  • Keynote address from a leading cybersecurity authority
  • General sessions covering strategic GRC, AI governance, and cybersecurity topics for all attendees
  • Technical breakout sessions for IT practitioners, security professionals, and technical leaders
  • Leadership/Executive breakout sessions for business owners, C-suite executives, and compliance leaders
  • Interactive workshops and real-world case studies
  • Networking opportunities throughout the day

The event runs from 8:00 AM to 6:00 PM at the Hershey Lodge in Hershey, PA, and includes breakfast, lunch, and a networking happy hour.


Event Photos
Event Photos
Agenda

🕑: 08:00 AM
Breakfast & Registration
🕑: 08:45 AM - 09:00 AM
Welcome
🕑: 09:00 AM - 09:45 AM
General: Compliance Implementation in Practice: A CMMC Case Study

Info: Real-world compliance implementation from three perspectives: the client going through it, the technology partner implementing it, and the assessor evaluating it. CMMC is the case study, but the roadmap applies to any framework: SOC 2, HITRUST, HIPAA, PCI, and beyond. Learn what compliance actually looks like and how to prepare your organization.


🕑: 09:50 AM - 10:30 AM
General: When AI Starts Acting: Governing What AI Systems Are Allowed to Do
Host: Diane R. Jones

Info: AI is rapidly evolving from tools that generate outputs to systems that can propose and carry out actions through APIs, workflows, and enterprise systems. As that shift happens, governance can no longer rely primarily on model behavior, testing, or guardrails. The critical question becomes:
What should we know before letting our AI act?
This session introduces a system-level control model for controlling consequential AI actions before they execute. It examines how authority, actions, context, and evidence can be evaluated at runtime, and why those decisions must be enforced through a boundary.
Using recent examples and established security principles, the session will show how organizations can move from hoping AI behaves to designing systems that govern the consequences AI can create.


🕑: 10:30 AM - 10:50 AM
Break
🕑: 10:50 AM - 11:30 AM
Breakout (Technical): The Password is Dead: Identity-First Security
Host: Brian Bronstein

Info: Passwords remain the weakest link in cybersecurity. This session demonstrates why identity-first security through passwordless authentication, multi-factor authentication, and privileged access management creates a stronger security foundation. Includes live demo of passkey authentication.


🕑: 10:50 AM - 11:30 AM
Breakout (Leadership): How to Calculate AI ROI: Separating Signal from Hype
Host: Chris Swecker

Info: Every small business owner has heard the AI pitch, and most have also heard (or lived) the disappointment when it doesn't deliver. This session cuts through both the hype and the cynicism with a plain-language look at what the actual research says about AI return on investment: why "hours saved" is often a fake metric, why the real value shows up as unlocked capacity rather than headcount cuts, and how to avoid the costly mistakes bigger companies have already made so you don't have to repeat them. You'll leave with a simple framework for evaluating AI tools in your own business, no technical background required.


🕑: 11:30 AM - 12:15 PM
Lunch
🕑: 12:25 PM - 01:10 PM
Keynote: Your Next Employee Doesn't Have a Pulse: Zero Trust as the...
Host: Dr. Chase Cunningham

Info: ...Architecture for Secure AI Adoption

Every company is hiring right now - most just don't know it. AI agents are entering with credentials and sensitive access, deployed the way no human employee ever would be: no manager, background check, offboarding, or activity log. The result is an explosion of non-human identities that traditional security models were never built to govern.

Dr. Chase Cunningham argues zero trust is the architectural framework that makes AI adoption survivable—not a product category. Drawing on MGM, Change Healthcare, and the $25M Arup deepfake, he shows valid credentials masking abnormal behavior is the core failure mode AI multiplies at machine speed, and why controls must sit outside the model.

Every principle comes in two builds: enterprise-grade for SOC/IAM teams, and a three-control version for mid-market teams without them. Attendees leave with one scalable roadmap - an enterprise maturity path and a 90-day starter plan.


🕑: 01:10 PM - 01:40 PM
General: SOC 2 & HITRUST: Choosing the Right Compliance Framework
Host: Josh Bantz

Info: Independent SOC 2 audit explained: what the five Trust Services Criteria prove (and don't prove), Type I vs Type II decision-making, why organizations pursue certification, and how SOC 2 impacts customer relationships and competitive positioning. Panel featuring audit firm and service provider perspectives, with real RFP examples.


🕑: 01:45 PM - 02:20 PM
Breakout (Technical): AI-Powered Security Automation: Hands-On Workflows
Host: Jimmy Lloyd

Info: Learn how to build practical, low-code security automation workflows using AI and n8n. This hands-on session covers IOC enrichment with multi-source threat intelligence (OTX, VirusTotal, AbuseIPDB), container vulnerability management with CVE scanning, canary token deception for intrusion detection, multi-agent offensive security pipelines, tool-augmented pentesting with AI agents, AI-assisted static code analysis (SAST), differential DAST monitoring, and continuous threat hunting mapped to MITRE ATT&CK. From IOC scoring to autonomous pen-test agents, you'll walk away with practical security automation you can implement.


🕑: 01:45 PM - 02:20 PM
Breakout (Leadership): Third-Party Risk Management (TPRM)
Host: Jimmy Armour

Info: Vendor and supply chain risk management framework balancing traditional TPRM fundamentals with AI-era considerations. Covers vendor governance policies, contract requirements, continuous monitoring, and how AI changes third-party risk (data usage rights, model transparency, subprocessor AI dependencies).


🕑: 02:20 PM - 02:40 PM
Break
🕑: 02:40 PM - 03:20 PM
General: GRC as a Team Sport: Breaking Down Organizational Silos
Host: Diane R. Jones

Info: GRC (Governance, Risk, Compliance) is everyone's responsibility, not just "the security team's problem." This panel shows how IT, Finance, HR, Legal, Operations, and Leadership each play a role in GRC. Focuses on breaking down organizational silos and building cross-functional collaboration.


🕑: 03:25 PM - 03:55 PM
Breakout (Technical): The Top 10 Security Controls That Matter Across Every Au
Host: Lynnanne Bocchi
🕑: 03:25 PM - 03:55 PM
Breakout (Leadership): Translating Cyber Risk into CFO Language
Host: Derek Dowhower

Info: Security risks feel abstract until you translate them into dollars, probabilities, and business impact. This conversation teaches leadership how to quantify cybersecurity risk so they can make informed decisions about what to fund, what to defer, and what risk to explicitly accept. Learn how to calculate expected annual loss, measure technical debt interest rates, quantify Shadow AI risk, and build a risk acceptance framework. Move from "IT says we need this" to "Here's the expected loss if we don't, here's the cost to fix it, so what's the business decision?"


🕑: 04:00 PM - 04:30 PM
General: AI Conference Summary + Quick Wins
🕑: 04:30 PM - 06:00 PM
Happy Hour + Networking
Advertisement

Event venue & nearby stays

Hershey Lodge, 325 University Drive, Hershey, United States

Tickets USD 50.00
Concerts, fests, parties, meetups — all the happenings, one place.

Discover more events by tag

Ask AI if this event suits you

Keep the plans coming

More events in Hershey

Hershey is happening.

See everything else that’s on — concerts, markets, comedy and more.