
8 Verified Cybersecurity Keynote Speakers in the USA
Updated: Jul 29
Last updated: 29 July 2026.
For US events in 2026, eight currently verifiable cybersecurity keynote options are Bruce Schneier, Rachel Tobac, Eric O'Neill, Robert Siciliano, Theresa Payton, Mark Lynd, Tyler Cohen Wood and Caitlin Sarian. This compiled directory links directly to current speaking or professional evidence so event planners can build a defensible shortlist.
The 2026 Verizon Data Breach Investigations Report says 31% of breaches now start with software vulnerabilities, 48% involve ransomware and 15 attack techniques are being strengthened by generative AI. A keynote should therefore do more than create urgency. It should help the audience make safer decisions after the event.
Who this directory is for.
This directory is for conference producers, association teams, executive assistants, CISOs, learning leaders and corporate event planners booking a cybersecurity keynote in the United States. It covers different audience needs, from board risk and national security to social engineering, fraud prevention, security culture and cyber careers.
This is a compiled directory, not a league table. The order does not imply quality or preference. Each person appeared in the source post and was retained only when current speaking activity or booking availability, a current professional identity and a relevant cybersecurity focus could be checked on 29 July 2026.
No speaker paid to appear here. Jonno White and Consult Clarity have no disclosed commercial relationship with the listed speakers or bureaus. Availability, travel, topics and commercial terms can change, so confirm every detail with the speaker or their authorised representative before contracting.
A quick match by audience need.
Board, policy and public-interest technology.
Bruce Schneier brings a systems, policy and public-interest lens. Theresa Payton connects security, privacy, AI and leadership. Tyler Cohen Wood translates intelligence and enterprise risk for executive audiences.
Human behaviour, social engineering and fraud.
Rachel Tobac specialises in live social-engineering demonstrations and practical defence. Robert Siciliano focuses on fraud, identity and the human decisions attackers exploit. Eric O'Neill uses a counterintelligence story to make insider risk and cybercrime memorable.
AI, executive action and cyber careers.
Mark Lynd focuses on executive decisions where AI, cyber risk and incident readiness meet. Caitlin Sarian focuses on online safety, cyber careers and making security accessible to broad audiences.
The eight verified speakers.
1. Bruce Schneier.
Bruce Schneier describes himself as a public-interest technologist working where security, technology and people meet. His current biography lists roles including Lecturer in Public Policy at Harvard Kennedy School and Chief of Security Architecture at Inrupt. His official calendar shows US speaking dates in 2026, including Las Vegas and Anaheim.
Strong fit for policy forums, security leadership events, technical conferences and audiences that need a wider view of trust, AI, democracy and systems risk. Review his official biography and current speaking events before making contact.
Schneier's line, "Security is a process, not a product", remains a useful test for a keynote brief. The session should connect technology with the decisions, habits and governance that keep working after the room clears. The wording comes from his official essay.
2. Rachel Tobac.
Rachel Tobac is CEO of SocialProof Security and works in social engineering training and testing. Her talks are built around showing how attackers use ordinary human behaviour, public information and realistic deception. Rapid7 listed her in its 2026 Global Cybersecurity Summit program, adding a current event signal to her active company work.
Strong fit for all-staff events, security awareness programs, leadership audiences and conferences where a live demonstration can turn an abstract threat into a practical lesson. Check SocialProof Security and Rapid7's 2026 summit announcement for current context.
3. Eric O'Neill.
Eric O'Neill is a former FBI undercover operative, national security attorney, corporate investigator and cybersecurity strategist. His speaking work uses the investigation that helped expose FBI spy Robert Hanssen to explain insider threats, cyber espionage, trust and proactive security culture.
Strong fit for corporate conferences, association events and executive audiences that need a high-stakes story with clear lessons for everyday behaviour. His official speaking page confirms active keynote work and his official biography explains his current professional background.
4. Robert Siciliano.
Robert Siciliano is a cybersecurity keynote speaker and security awareness trainer whose current programs focus on social engineering, deepfakes, fraud, privacy and identity protection. His approach is deliberately non-technical, with an emphasis on helping employees recognise how their own choices can strengthen or weaken an organisation's defences.
Strong fit for broad employee audiences, financial services, real estate, customer-facing teams and events where jargon would lose the room. His official speaking page lists current keynote programs and booking information.
5. Theresa Payton.
Theresa Payton is CEO of Fortalice Solutions and a former White House Chief Information Officer. Her current speaking material connects AI, security, privacy, digital identity and leadership, with an emphasis on turning complex risks into actions a mixed audience can understand.
Strong fit for executive conferences, government and regulated-sector events, leadership summits and programs that sit between technology and public trust. Her official speaking page confirms current speaking enquiries and her professional focus.
6. Mark Lynd.
Mark Lynd is an AI and cybersecurity keynote speaker and executive adviser who presents himself as a former CEO, CIO and CISO. His current work is aimed at boards and senior leaders making decisions about AI governance, cyber readiness, incident response and cyber insurance.
Strong fit for board, C-suite, public-sector and enterprise audiences that want decision tools rather than a technical threat briefing. His official speaking site shows current topics, audience focus and booking availability. Treat self-reported performance figures as the speaker's own claims and verify any that matter to your selection.
7. Tyler Cohen Wood.
Tyler Cohen Wood is a former US Defense Intelligence Agency senior intelligence officer and former enterprise cyber risk executive. Her current speaker profiles focus on cyber risk, national security, AI, privacy and the practical consequences of an exposed digital footprint.
Strong fit for boards, financial services, healthcare, government-adjacent events and general business audiences that need complex risk translated clearly. Check her current profiles with Keppler Speakers and Speakers Associates for availability and topic details.
8. Caitlin Sarian.
Caitlin Sarian is the founder of Cybersecurity Girl and Cyber Career Club. Her work focuses on online safety, cybersecurity careers, public education and helping more women enter technology. Her official site says she regularly speaks at global conferences, and her current bureau profile lists her as available for keynote enquiries.
Strong fit for workforce development, education, early-career, women in technology and broad public-awareness events. Review Cybersecurity Girl and her current bureau profile before shortlisting.
How to choose between them.
Start with the change you want after the keynote. A board that needs clearer ownership during an incident has a different brief from a workforce that needs to resist social engineering. Write one sentence that begins, "After this session, our audience will", then make every speaker conversation answer that sentence.
Next, check audience level. Ask how the speaker adapts the same topic for technical practitioners, senior executives and general employees. A polished reel can show stage presence, but a recent full-length clip is better evidence of pacing, depth and how the speaker handles transitions.
Then ask for two recent examples involving an audience like yours. Confirm what was customised, which takeaways were used and what the organiser measured afterwards. Do not rely on unnamed praise when a decision depends on sector experience or a specific audience outcome.
Finally, confirm practical details in writing. Cover the event date, US city and time zone, in-person or virtual format, session length, audience size, recording rights, accessibility, travel days, production needs and the process for approving a tailored brief.
A US event planning check.
The United States spans several time zones and long travel routes. A speaker based on the East Coast may need a full travel day for a morning event in the West. Confirm the local start time, arrival expectations and weather-related backup plan before the contract is final.
Ask the venue to test confidence monitors, audio playback, video playback, clickers and internet access in the actual room. Live hacking or social-engineering demonstrations may require a separate network, pre-approved targets and clear consent. Never let an engaging demonstration create a real privacy or security risk.
For an executive audience, share the sector, regulatory context and decision level expected from the room. The NIST Cybersecurity Framework 2.0 now puts more explicit emphasis on governance and enterprise risk. Then NIST Director Laurie E. Locascio described the framework as "a vital tool for many organizations". That is a useful cue to brief the speaker on the leadership decisions, not just the threat landscape.
Measure more than applause.
Choose one immediate measure and one later measure before the event. The immediate measure might be whether attendees can name the three actions the speaker asked them to take. The later measure might be a change in reporting behaviour, completion of a security action, confidence in an incident role or use of a new decision process.
Avoid claiming that one keynote caused a reduction in breaches. Security outcomes have many causes, and a single event is only one part of a broader system. A more defensible question is whether the keynote improved a specific behaviour or decision that the organisation can observe.
If the cyber session sits inside a wider leadership program, Jonno White's background may help you shape the leadership and culture layer around it. You can also compare the global cybersecurity speaker directory, the USA AI speaker directory, the USA association conference directory and the AI ethics and governance directory.
About the author.
I'm Jonno White, a Brisbane-based leadership consultant, keynote speaker and Certified Working Genius Facilitator, certified through Patrick Lencioni's Table Group, and the author of Step Up or Step Out, with more than 10,000 copies sold. I host The Leadership Conversations Podcast and work with schools, corporates and nonprofits around the world.
I am not included in this directory and I do not present myself as a cybersecurity specialist. My role is to help leadership teams turn important ideas into clearer decisions, stronger accountability and practical action. My official About page, ICMI profile and Australian Speaker Bureau profile provide current identity evidence.
If your event needs leadership work around a cybersecurity keynote, you can explore team offsite facilitation or email jonno@consultclarity.org for a written proposal. No pressure at all. The cybersecurity keynote stands on its own, but the right follow-through can help its message become part of how leaders work.
If a role, link or speaking status in this directory has changed, please use the contact details on the About page so the entry can be checked and corrected.