Speaking

I speak at global security conferences on agentic AI risk, AI security posture management, and what breaks as software becomes agentic — including RSA Conference, Microsoft Ignite, Microsoft AI Tour, and OWASP AppSec Israel, and on AI and security more broadly since early 2023. Keynotes, breakouts, panels, and podcast appearances, in English or Hebrew.

Upcoming

OWASP AppSec Israel 2026 · October 6, 2026

The OpenClaw Bot Knew I Was Attacking It. It Named the Technique. Then It Complied.

An agent correctly identified the attack being run against it, named the technique out loud, and complied anyway. This talk works through what that means for anyone treating a model's judgment as a security control — because recognition is not refusal.

Pavilion 10, Tel Aviv Expo· Israel’s largest application security conference

Conference talks

Microsoft AI Tour, Tel Aviv · June 30, 2026

Protect Your AI Agents with Microsoft Defender

A co-presented session on securing AI agents in production: discovering the agent footprint, understanding what each agent can reach, and why it almost doesn't matter how capable the model is if you wire it to act on whatever it reads.

View the session

Microsoft Ignite 2025 · November 21, 2025 · BRK264

From Risk to Resilience: Secure Your AI Agents with Microsoft Defender

A full breakout on moving AI security from risk assessment to operational resilience — agent discovery, posture, attack path analysis, and runtime protection for agentic workloads with Microsoft Defender.

Watch the recordingPublished by Microsoft Events

RSA Conference 2025 · April 2025

Protect AI Workloads from Code to Runtime with Microsoft Defender for Cloud

Securing AI workloads across the whole lifecycle rather than at a single checkpoint — from code and model supply chain through deployment to runtime behavior, using Microsoft Defender for Cloud.

Watch the recordingPublished by Microsoft Security

Webinars, panels & interviews

Earlier appearances, going back to February 2023 — ten weeks after ChatGPT launched, and before most of this had a name.

Microsoft Defender for Cloud Webinar · July 11, 2024 · Webinar

Microsoft Copilot in Microsoft Defender for Cloud

Sole presenter

A full webinar on applying generative AI to cloud security operations — assisted risk exploration, assisted and automated remediation, and where an assistant genuinely shortens the path from finding to fix versus where it just restates the finding.

Watch the recordingPublished by Microsoft Security Community

Defender for Cloud in the Field, episode 49 · June 7, 2024 · Interview

Security Copilot Integration with Defender for Cloud

Interviewed by Yuri Diogenes

An interview on what changes when an assistant is embedded directly in a security posture tool: the integration scenarios, the access-control questions it raises, and why RBAC is the part most teams underthink.

Watch the recordingPublished by Microsoft Security

Leading the Way in AI — Microsoft Reactor Tel Aviv · February 8, 2023 · Panel

AI Visionaries: Pioneers Pushing the Boundaries

Panel with Michael Kolomenkin, Dori Stein, Maya Avisar · moderated by Uri Refael Baum

A panel on where generative AI was actually heading, recorded ten weeks after ChatGPT's public launch and well before the security industry had a vocabulary for any of it.

Watch the segmentPublished by Microsoft Reactor

Talk topics

The Likelihood Collapse: why AI risk management has to change shape

For a decade, cloud security worked by lowering the odds of compromise. AI agents end that, because the exposure is the product. This talk shows why the likelihood half of the risk equation stops being a knob defenders can turn, and what it means to manage blast radius as the primary control.

Every input is an instruction: securing the agent's input boundary

Most successful attacks on agentic systems never touch the model's safety training. They arrive as ordinary content — a repository, a document, a tool response — that the agent reads and acts on. A practical tour of indirect prompt injection and how to classify inputs by provenance rather than format.

Zero day to zero sec: why context beats speed

The window that gave "zero-day" its name has collapsed toward zero. The industry answer is to respond at machine speed. This talk argues that speed is not the defender's binding constraint — context is — and that an automated responder without a pre-assembled picture of your AI estate is only blind faster.

AI Security Posture Management from the ground up

What it actually takes to discover an enterprise AI agent footprint, score its risk, trace attack paths through agent identity and memory, and map the result to the EU AI Act and NIST AI RMF — drawn from building AI-SPM at Microsoft Defender.

Zero trust for AI agents

Standing permissions were survivable when the identity holding them was a human or a deterministic service. They are not survivable for a decision-maker that can be argued with. What real-time, per-task least privilege looks like when the principal is an agent.

Each talk builds on a named framework — read them under Frameworks.

Formats

Booking

Email [email protected] with the event, date, audience, and format. Speaker bio and headshot are on the about page — please use that copy verbatim.

Asaf Nakash is a Principal Product Manager for AI Security at Microsoft Defender, where he leads AI Security Posture Management. He hosts Context Window, a weekly AI security podcast, and has spoken at RSA Conference, Microsoft Ignite, and OWASP AppSec Israel on agentic AI risk.