I speak at global security conferences on agentic AI risk, AI security posture management, and what breaks as software becomes agentic — including RSA Conference, Microsoft Ignite, Microsoft AI Tour, and OWASP AppSec Israel, and on AI and security more broadly since early 2023. Keynotes, breakouts, panels, and podcast appearances, in English or Hebrew.
Upcoming
OWASP AppSec Israel 2026 · October 6, 2026
The OpenClaw Bot Knew I Was Attacking It. It Named the Technique. Then It Complied.
An agent correctly identified the attack being run against it, named the technique out loud, and complied anyway. This talk works through what that means for anyone treating a model's judgment as a security control — because recognition is not refusal.
Pavilion 10, Tel Aviv Expo· Israel’s largest application security conference
A co-presented session on securing AI agents in production: discovering the agent footprint, understanding what each agent can reach, and why it almost doesn't matter how capable the model is if you wire it to act on whatever it reads.
Microsoft Ignite 2025 · November 21, 2025 · BRK264
From Risk to Resilience: Secure Your AI Agents with Microsoft Defender
A full breakout on moving AI security from risk assessment to operational resilience — agent discovery, posture, attack path analysis, and runtime protection for agentic workloads with Microsoft Defender.
Protect AI Workloads from Code to Runtime with Microsoft Defender for Cloud
Securing AI workloads across the whole lifecycle rather than at a single checkpoint — from code and model supply chain through deployment to runtime behavior, using Microsoft Defender for Cloud.
Earlier appearances, going back to February 2023 — ten weeks after ChatGPT launched, and before most of this had a name.
Microsoft Defender for Cloud Webinar · July 11, 2024 · Webinar
Microsoft Copilot in Microsoft Defender for Cloud
Sole presenter
A full webinar on applying generative AI to cloud security operations — assisted risk exploration, assisted and automated remediation, and where an assistant genuinely shortens the path from finding to fix versus where it just restates the finding.
Defender for Cloud in the Field, episode 49 · June 7, 2024 · Interview
Security Copilot Integration with Defender for Cloud
Interviewed by Yuri Diogenes
An interview on what changes when an assistant is embedded directly in a security posture tool: the integration scenarios, the access-control questions it raises, and why RBAC is the part most teams underthink.
Leading the Way in AI — Microsoft Reactor Tel Aviv · February 8, 2023 · Panel
AI Visionaries: Pioneers Pushing the Boundaries
Panel with Michael Kolomenkin, Dori Stein, Maya Avisar · moderated by Uri Refael Baum
A panel on where generative AI was actually heading, recorded ten weeks after ChatGPT's public launch and well before the security industry had a vocabulary for any of it.
The Likelihood Collapse: why AI risk management has to change shape
For a decade, cloud security worked by lowering the odds of compromise. AI agents end that, because the exposure is the product. This talk shows why the likelihood half of the risk equation stops being a knob defenders can turn, and what it means to manage blast radius as the primary control.
Every input is an instruction: securing the agent's input boundary
Most successful attacks on agentic systems never touch the model's safety training. They arrive as ordinary content — a repository, a document, a tool response — that the agent reads and acts on. A practical tour of indirect prompt injection and how to classify inputs by provenance rather than format.
Zero day to zero sec: why context beats speed
The window that gave "zero-day" its name has collapsed toward zero. The industry answer is to respond at machine speed. This talk argues that speed is not the defender's binding constraint — context is — and that an automated responder without a pre-assembled picture of your AI estate is only blind faster.
AI Security Posture Management from the ground up
What it actually takes to discover an enterprise AI agent footprint, score its risk, trace attack paths through agent identity and memory, and map the result to the EU AI Act and NIST AI RMF — drawn from building AI-SPM at Microsoft Defender.
Zero trust for AI agents
Standing permissions were survivable when the identity holding them was a human or a deterministic service. They are not survivable for a decision-maker that can be argued with. What real-time, per-task least privilege looks like when the principal is an agent.
Each talk builds on a named framework — read them under Frameworks.
Formats
—Conference keynote (25–45 min)
—Technical session or deep-dive (30–60 min)
—Panel participation and moderation
—Executive and board briefings on AI risk
—Podcast and webinar guest appearances
Booking
Email [email protected] with the event, date, audience, and format. Speaker bio and headshot are on the about page — please use that copy verbatim.
Asaf Nakash is a Principal Product Manager for AI Security at Microsoft Defender, where he leads AI Security Posture Management. He hosts Context Window, a weekly AI security podcast, and has spoken at RSA Conference, Microsoft Ignite, and OWASP AppSec Israel on agentic AI risk.