Security for the Agentic Era: The Cisco + Splunk Guide to Black Hat 2026

Security Olivia Henderson

Key takeaways

  1. Black Hat attendees can explore how Cisco, Splunk, and Cisco Talos are helping organizations secure AI and respond to threats at machine speed.
  2. Visit Splunk at Black Hat for expert sessions, live demos, and hands on guidance for modernizing security operations with AI.
  3. Cisco and Splunk will showcase real time security technologies and help protect the Black Hat event network as the official security cloud provider.

AI is changing the economics of cyber risk. Autonomous agents can now read documents, query databases, invoke tools, send messages, and execute workflows with legitimate authority. At the same time, attackers are using AI to accelerate reconnaissance, vulnerability discovery, exploit development, and evasion. For defenders, the challenge is no longer simply adopting AI. It is building the visibility, trust and enforcement needed to use AI safely while responding at the speed AI makes possible.

At Black Hat 2026, Cisco, Splunk, and Cisco Talos are joining forces to flip the script on attackers. Join the security powerhouse of the agentic era and see first-hand how our expertise, technology and threat intelligence delivers immediate actionable insights that help defenders respond faster and reclaim their advantage.

We are also excited to share that Cisco and Splunk are the official security cloud provider and proud partner of the Black Hat Network Operations Center (NOC).

Keynotes & Workshops You Don’t Want to Miss

Practical Advice to Empower Defenders

Practitioners can stop by Booth 2633 to go deeper in the in-booth theater, where focused sessions turn emerging risks into practical action. Topics span governing AI assets, securing agentic systems, evolving red-team practices, reducing exposure while patches move through change control, and using machine learning to uncover hidden attackers.

Detect and Respond at Machine Speed with Splunk Security

Visit the Splunk Networking Space in Booth 2633 to learn from Splunk Security experts on how to reduce attacker opportunities by operating through faster detection, correlation, intelligence, and response. We’ll have live demos where you can experience hands-on how Splunk Enterprise Security and our latest innovations detect threats accurately, accelerate investigations, and automate response actions. Be sure to join the theater sessions and hear from our technical researchers, practitioners, and leaders about how Splunk is evolving the Agentic SOC.

Splunk and AWS will also highlight how this strategic partnership helps customers connect cloud-native signals, enterprise data, and operational workflows into a more complete view of their environment.

Learn more about how Splunk and AWS are modernizing the SOC with Splunk Enterprise Security for AWS Security Hub Extended.

Black Hat NOC: World Class Enterprise Network Protection

Stop by to see us in the Black Hat NOC and NOC Outpost, an interactive Business Hall experience where attendees can meet the NOC team and explore the technologies defending the event network in real time.

AI Kiosk: Accelerate AI Performance and Vulnerability Detection

Be sure to visit the Black Hat AI Zone at Business Hall booth 4714 for live demonstrations of AI-driven security innovation. Cisco will showcase Fully Automated Prompt Optimization (FAPO), a multi-tenant framework that evaluates and optimizes prompts across isolated projects, and Antares, a family of security-focused small language models purpose-built to pinpoint known vulnerabilities within codebases. Together, these technologies demonstrate how purpose-built AI can help security teams improve applications, accelerate vulnerability discovery, and operate more efficiently.

We look forward to seeing you at Black Hat!

Related Articles

Detecting the Sudo Baron Samedit Vulnerability and Attack
Security
3 Minute Read

Detecting the Sudo Baron Samedit Vulnerability and Attack

Looking for ways to detect and protect against the SUDO Baron Samedit vulnerability (CVE-2021-3156)? Look no further. In this blog we tell you how to proactively detect vulnerable servers using Splunk and also to detect malicious folks who are attempting to exploit this vulnerability for nefarious outcomes!
DevSecOps is Here! Developers and SREs, Meet the SOC Team.
Security
2 Minute Read

DevSecOps is Here! Developers and SREs, Meet the SOC Team.

As organizations strive to enhance the cyber resilience of their operations, the scope of SOC teams is expanding beyond traditional enterprise IT. Find out more in this blog.
DORA will accelerate cloud migration in Financial Services
Security
2 Minute Read

DORA will accelerate cloud migration in Financial Services

The much-anticipated Digital Operational Resilience Act (DORA) is finally here. This Regulation, applicable across the 27 EU Member States, provides a set of guidelines via which financial services organisations will need to prove that they are operationally resilient, i.e, they are able to withstand any unforeseen shocks.