Building a Resilient Future: Insights from Our Public Sector Community at .conf26
Industries Dave DonnellyKey takeaways
- Universities like the University of Nevada and LSU are training students in real Security Operations Centers to prepare job-ready cybersecurity talent.
- Government and industry leaders discussed closing the AI trust gap by building security safeguards into AI systems from the start.
- Splunk's Boss of the SOC competition drew heavy public sector participation, helping government and education teams practice defending against real threats.
It was great to see such a strong showing from our public sector partners and leaders at .con26. The energy around driving digital transformation in government was palpable, and the discussions highlighted just how critical our collective work has become. .conf26 focused on driving real-world impact across the public sector by helping agencies maximize their investments in data, security, and AI. This year’s event centered on three critical pillars:
- Turning Machine Data into Agentic Action: Correlating data across domains in real-time to fuel resilient, custom AI-driven operations.
- Defending at Machine Speed: Unifying SOC and infrastructure to enable autonomous, governed threat response across any attack surface.
- Optimizing AI at Scale: Building AI-ready infrastructure that governs agents and controls costs while leveraging AI SRE for autonomous troubleshooting.
Here is a recap of the key themes and takeaways from the public sector track at the event:
- Bridging the Cybersecurity Talent Gap: In his session titled From Classroom To SOC: Creating Job-Ready SOC Analysts With Splunk, Jason Griffin, Manager of Cybersecurity Operations, University of Nevada, demonstrated how they've turned classrooms into high-functioning Security Operations Centers by integrating Splunk Enterprise Security with hands-on training and "Boss of the SOC" (BOTS) competitions. This model provides students with the vital real-world experience needed to transition directly from academics into high-impact security operations roles.
- Developing the Next Generation of Cybersecurity Talent: During the .conf+ Fireside Chat, The Student-Powered SOC and the Next Gen of Workforce, industry leaders including Craig Woolley, CIO at LSU, Lance Neal, Executive Director at Louisiana Optical Network Infrastructure (LONI) discussed how universities are bridging the cybersecurity talent gap by integrating student-powered Security Operations Centers (SOCs) into their curriculum. This model mirrors real-world enterprise environments, effectively combining academic rigor with operational demands to produce job-ready professionals prepared for today’s complex threat landscape.
- Navigating the AI Trust Gap: This session explored how to build an agentic enterprise from the perspective of a CIO, CTO, and CISO. During the discussion, the panelists drew from their experiences to weigh the realities of agentic AI implementation, including best practices, what is driving success, and where organizations are facing the most significant challenges. The session centered on the "AI trust gap," specifically addressing how leadership can implement robust security guardrails to maintain compliance without sacrificing the speed and agility required for meaningful innovation. The panel emphasized that trust must be baked into the design phase of any AI implementation. By prioritizing a security-first strategy, agencies can successfully scale their agentic capabilities while ensuring the safety of sensitive citizen data and maintaining operational transparency.
- BOTS 11: Splunk once again held its Boss of the SOC (BOTS) 11 at .conf26. BOTS is a premier blue-team simulation designed to help security professionals sharpen their investigative skills using the full Splunk security suite. The event is a significant hub for government and education leaders, with about 25 percent of all participants representing the public sector. This competition provides a unique opportunity for these teams to build digital resilience and collaborate on defending against the latest sophisticated threats in a hands-on environment.
- Strengthening the Public Sector Community: Beyond the technical sessions, the networking opportunities were a major highlight for many attendees. Whether at the welcome reception, happy hour or Search Party social event, connecting state and local IT leaders allowed for a valuable exchange of best practices, proving that we solve these complex challenges much faster when we work together.
- Commitment to Resilient Infrastructure: The focus on building resilient, future-proof networks remained a core pillar of our presence this year. It’s clear that public sector organizations are prioritizing long-term stability to ensure that essential services remain uninterrupted, regardless of the threat landscape.
Let’s Keep the Conversation Going
I would love to hear which of these takeaways resonated most with your agency’s current priorities. Please reach out if you’d like to discuss how we can tailor these AI and security strategies to meet your specific mission requirements.
Related Articles

Trickbot Detections: Threat Research Release, July 2021

Introducing Splunk Add-On for Splunk Attack Analyzer & Splunk App for Splunk Attack Analyzer
