À propos de cette session
Un panel de cinq personnes intitulé AI vs AI, animé par David-Alexandre Thibaut St-Pierre de Microsoft Canada, aborde le virage IA contre IA en trois blocs : attaque, défense, puis risque et gouvernance. Raymond Daoud, chef de la sécurité chez CGI, et Juliana Zaremba, de BlueVoyant, décrivent des attaquants qui automatisent désormais toute la chaîne, de la reconnaissance à l'exfiltration, citant l'incident Hugging Face et les récents rapports d'Anthropic et d'OpenAI sur les essaims d'agents et le « vibe hacking ». L'avocat Mikel Pearce ajoute que la fenêtre d'exfiltration est passée de plusieurs jours à environ deux heures une fois la chaîne d'approvisionnement compromise. Côté défense, les panélistes plaident pour consolider les outils sur une seule plateforme, notamment celle de Microsoft, plutôt que de multiplier les produits ponctuels, tout en admettant que les défenseurs n'ont pas rattrapé leur retard. L'administratrice Muriel McGrath raconte comment elle pousse ses conseils vers une stratégie IA, une gouvernance des données et une transformation de la main-d'œuvre, cette dernière restant sa plus grande inquiétude. Le panel se termine sur le retard réglementaire : aucune loi canadienne propre à l'IA n'existe encore, ni le projet de loi C-8 ni la Loi 25 ne la couvrent, et les panélistes réclament une responsabilisation des fournisseurs. Le mot de la fin invite à voir ce virage comme une occasion générationnelle plutôt qu'une menace.
When attackers use AI, should defenders respond with AI? This panel will examine the opportunities and risks of artificial intelligence in cybersecurity: attack automation, detection, response, deepfakes, governance, and the new race between offense and defense.
À retenir
- Présumer que le temps de présence d'un attaquant est passé de plusieurs mois à environ deux heures une fois la chaîne d'approvisionnement IA compromise; concevoir la détection et le confinement pour cette vitesse, pas pour un attaquant qui rôde lentement.
- Consolider les outils de sécurité sur une seule plateforme plutôt que d'empiler des produits ponctuels; des outils fragmentés multiplient la surface d'attaque et ne peuvent pas itérer aussi vite que la menace évolue.
- Utiliser l'IA à l'interne pour tester, sécuriser et corriger le code et prioriser les vulnérabilités, afin de libérer du temps aux analystes plutôt que d'attendre que l'IA règle seule le problème défensif.
- Pousser les conseils d'administration à poser quatre questions opérationnelles sur tout déploiement d'IA agentique : que fait-il, peut-on l'arrêter, qui est responsable, et peut-on prédire où il s'en va.
- Suivre de près la responsabilisation des fournisseurs et des plateformes, puisqu'aucune loi propre à l'IA n'existe encore au Canada et que ni le projet de loi C-8 ni la Loi 25 ne couvrent ce risque.
Conférenciers

Mikel has spent nearly 25 years navigating the intricate world of insurance defence and coverage law. While not as adrenaline-fueled as skiing down a double black diamond or surviving a rugby scrum, it requires a similar tolerance for risk and… Lire la suiteRéduire
Mikel has spent nearly 25 years navigating the intricate world of insurance defence and coverage law. While not as adrenaline-fueled as skiing down a double black diamond or surviving a rugby scrum, it requires a similar tolerance for risk and bruises—albeit mostly to the ego. For almost a decade, he’s moonlighted as a breach coach, guiding Lloyd’s syndicates and a variety of domestic and international insurers through the digital equivalent of a house fire, all while maintaining the calm of someone who’s raised three teenagers and never once lost a dog.
His legal toolkit is sharpened by years as in-house counsel, a stint at a forensics firm, and the kind of responsiveness that only comes from being the guy who actually reads the fine print. Mikel’s approach is rooted in compassion—whether he’s helping clients through cyber crises or refereeing sibling disputes over who left the milk out. He’s a lifelong cyclist, skier, and rugby player, which means he’s no stranger to pain, perseverance, and the occasional questionable decision made at high speed.
When not lawyering or coaching breaches, Mikel can be found chasing his dogs, his kids, or the elusive feeling of having finished all his email. We can attest that he brings heart, humour, and a healthy respect for chaos to everything he does.
1
Aurélie Yaombiti
Rédigez une réponse et mentionnez les autres avec @
Demander à Sidekick
Ctrl
/

Muriel holds several corporate director roles, including board chair roles in cybersecurity and data protection, in technology, AI, in governance and in executive talent and culture. She sits on boards of very large public organizations as well as… Lire la suiteRéduire
Muriel holds several corporate director roles, including board chair roles in cybersecurity and data protection, in technology, AI, in governance and in executive talent and culture. She sits on boards of very large public organizations as well as smaller private entities in the financial services, in technology and in the infrastructure, power and energy management consulting industries. As a certified board member (ICD.D), Muriel’s interventions bring value as they stem from her past as a seasoned CEO, P&L executive and technology thought leader. Muriel was the IBM Canadian market leader for Advanced Analytics and AI, she was also a Strategy and Transformation partner at IBM & KPMG. From multinational global to SME international nimble corporations, whether in board roles or executive management, she has guided strategic initiatives in M&A, in technology, in due diligence and security, big data and AI and growth. Muriel is also a certified digital transformation auditor.

As CGI’s Chief Security Officer, I am responsible for overseeing the company’s global enterprise security strategy and establishing global security policies, standards and practices across all security areas, including cybersecurity, information… Lire la suiteRéduire
As CGI’s Chief Security Officer, I am responsible for overseeing the company’s global enterprise security strategy and establishing global security policies, standards and practices across all security areas, including cybersecurity, information security, personnel security and physical security. I am also responsible for CGI’s business continuity programs and supporting activities. I’m honored to work with a dynamic team of security professionals across CGI’s global operations. I welcome the opportunity to have a conversation with organizations interested in learning about our security best practices and with talented professionals interested in becoming part of the CGI family.

Juliana Zaremba is an Alliance and Channel Executive at BlueVoyant, a global cybersecurity company that delivers managed detection and response services to organizations globally, focusing specifically on North America. With over a decade in the… Lire la suiteRéduire
Juliana Zaremba is an Alliance and Channel Executive at BlueVoyant, a global cybersecurity company that delivers managed detection and response services to organizations globally, focusing specifically on North America. With over a decade in the cybersecurity industry - including leadership roles at Difenda, where she owned the Microsoft Global partnership and helped build one of Canada's leading Microsoft-native SOC practices, and Herjavec Group where she led client operations across a growing global security services organization - Juliana brings a practitioner's perspective on how the Microsoft security stack is reshaping how organizations defend themselves.
A recognized voice in the Canadian cybersecurity channel, Juliana has most recently spoken on panels exploring the intersection of AI and cyber operations, bringing that lens to conversations about the future of the SOC

David-Alexandre serves as National Director, Cybersecurity at Microsoft Canada. He leads a team dedicated to supporting Canadian customers and partners, with a mission to strengthen their security posture through the acquisition, deployment, and… Lire la suiteRéduire
David-Alexandre serves as National Director, Cybersecurity at Microsoft Canada. He leads a team dedicated to supporting Canadian customers and partners, with a mission to strengthen their security posture through the acquisition, deployment, and optimization of advanced solutions that integrate cloud computing and generative artificial intelligence.
Drawing on extensive experience managing large-scale cloud deployments, Mr. Thibault St-Pierre is an active participant in professional communities and specialized working groups. He contributes to the development and sharing of best practices in security, compliance, and data governance within cloud environments.
-
David-Alexandre occupe le poste de Directeur National, Cybersécurité chez Microsoft Canada. Il dirige une équipe dédiée à l’appui des clients et partenaires canadiens, dont la mission consiste à renforcer leur posture de sécurité à travers l’acquisition, le déploiement et l’optimisation de solutions avancées intégrant l’infonuagique et l’intelligence artificielle générative.
Fort d’une solide expérience dans la gestion de déploiements Cloud d’envergure, M. Thibault St-Pierre participe activement à des communautés professionnelles et à des groupes de travail spécialisés. Il contribue à l’élaboration et au partage des meilleures pratiques relatives à la sécurité, la conformité et la gestion des données dans les environnements infonuagiques.





