About this session
A five-person panel titled AI vs AI, moderated by Microsoft Canada's David-Alexandre Thibaut St-Pierre, works through three blocks: offense, defense, and risk and governance. CGI chief security officer Raymond Daoud and BlueVoyant's Juliana Zaremba describe attackers now automating reconnaissance, exploitation and exfiltration end to end, citing the Hugging Face incident and recent Anthropic and OpenAI reporting on agent swarms and 'vibe hacking'. Breach counsel Mikel Pearce adds that exfiltration windows have shrunk from days to roughly two hours once an AI supply chain is compromised. On defense, panelists argue for consolidating tooling onto one platform ecosystem, notably Microsoft's fast-iterating security stack, rather than stitching together point products, while conceding defenders have not caught up. Board director Muriel McGrath describes pushing her boards toward AI strategy, data governance and workforce transformation, calling the human element her biggest worry. The panel closes on regulatory lag: no Canada-wide AI-specific legislation exists yet, Bill C-8 and Law 25 do not cover it, and panelists call for accountability from AI vendors. Closing remarks frame the shift as a generational opportunity for security professionals, not only a threat.
When attackers use AI, should defenders respond with AI? This panel will examine the opportunities and risks of artificial intelligence in cybersecurity: attack automation, detection, response, deepfakes, governance, and the new race between offense and defense.
Key takeaways
- Assume attacker dwell time has shrunk from months to roughly two hours once an AI supply chain is compromised; design detection and containment for that speed, not for a slow lurking attacker.
- Consolidate security tooling onto one platform ecosystem instead of stacking point products; fragmented tools multiply attack surface and cannot iterate as fast as the threat evolves.
- Use AI internally to test, secure and patch code and to triage vulnerabilities, freeing analyst time rather than expecting AI alone to solve the defensive problem.
- Push boards to ask four operating questions about any agentic AI deployment: what is it doing, can we stop it, who is accountable, and can we predict where it goes.
- Track vendor and platform accountability now, since no Canada-wide AI-specific legislation exists yet and neither Bill C-8 nor Law 25 covers AI risk.
Speakers

Mikel has spent nearly 25 years navigating the intricate world of insurance defence and coverage law. While not as adrenaline-fueled as skiing down a double black diamond or surviving a rugby scrum, it requires a similar tolerance for risk and… Read moreRead less
Mikel has spent nearly 25 years navigating the intricate world of insurance defence and coverage law. While not as adrenaline-fueled as skiing down a double black diamond or surviving a rugby scrum, it requires a similar tolerance for risk and bruises—albeit mostly to the ego. For almost a decade, he’s moonlighted as a breach coach, guiding Lloyd’s syndicates and a variety of domestic and international insurers through the digital equivalent of a house fire, all while maintaining the calm of someone who’s raised three teenagers and never once lost a dog.
His legal toolkit is sharpened by years as in-house counsel, a stint at a forensics firm, and the kind of responsiveness that only comes from being the guy who actually reads the fine print. Mikel’s approach is rooted in compassion—whether he’s helping clients through cyber crises or refereeing sibling disputes over who left the milk out. He’s a lifelong cyclist, skier, and rugby player, which means he’s no stranger to pain, perseverance, and the occasional questionable decision made at high speed.
When not lawyering or coaching breaches, Mikel can be found chasing his dogs, his kids, or the elusive feeling of having finished all his email. We can attest that he brings heart, humour, and a healthy respect for chaos to everything he does.
1
Aurélie Yaombiti
Rédigez une réponse et mentionnez les autres avec @
Demander à Sidekick
Ctrl
/

Muriel holds several corporate director roles, including board chair roles in cybersecurity and data protection, in technology, AI, in governance and in executive talent and culture. She sits on boards of very large public organizations as well as… Read moreRead less
Muriel holds several corporate director roles, including board chair roles in cybersecurity and data protection, in technology, AI, in governance and in executive talent and culture. She sits on boards of very large public organizations as well as smaller private entities in the financial services, in technology and in the infrastructure, power and energy management consulting industries. As a certified board member (ICD.D), Muriel’s interventions bring value as they stem from her past as a seasoned CEO, P&L executive and technology thought leader. Muriel was the IBM Canadian market leader for Advanced Analytics and AI, she was also a Strategy and Transformation partner at IBM & KPMG. From multinational global to SME international nimble corporations, whether in board roles or executive management, she has guided strategic initiatives in M&A, in technology, in due diligence and security, big data and AI and growth. Muriel is also a certified digital transformation auditor.

As CGI’s Chief Security Officer, I am responsible for overseeing the company’s global enterprise security strategy and establishing global security policies, standards and practices across all security areas, including cybersecurity, information… Read moreRead less
As CGI’s Chief Security Officer, I am responsible for overseeing the company’s global enterprise security strategy and establishing global security policies, standards and practices across all security areas, including cybersecurity, information security, personnel security and physical security. I am also responsible for CGI’s business continuity programs and supporting activities. I’m honored to work with a dynamic team of security professionals across CGI’s global operations. I welcome the opportunity to have a conversation with organizations interested in learning about our security best practices and with talented professionals interested in becoming part of the CGI family.

Juliana Zaremba is an Alliance and Channel Executive at BlueVoyant, a global cybersecurity company that delivers managed detection and response services to organizations globally, focusing specifically on North America. With over a decade in the… Read moreRead less
Juliana Zaremba is an Alliance and Channel Executive at BlueVoyant, a global cybersecurity company that delivers managed detection and response services to organizations globally, focusing specifically on North America. With over a decade in the cybersecurity industry - including leadership roles at Difenda, where she owned the Microsoft Global partnership and helped build one of Canada's leading Microsoft-native SOC practices, and Herjavec Group where she led client operations across a growing global security services organization - Juliana brings a practitioner's perspective on how the Microsoft security stack is reshaping how organizations defend themselves.
A recognized voice in the Canadian cybersecurity channel, Juliana has most recently spoken on panels exploring the intersection of AI and cyber operations, bringing that lens to conversations about the future of the SOC

David-Alexandre serves as National Director, Cybersecurity at Microsoft Canada. He leads a team dedicated to supporting Canadian customers and partners, with a mission to strengthen their security posture through the acquisition, deployment, and… Read moreRead less
David-Alexandre serves as National Director, Cybersecurity at Microsoft Canada. He leads a team dedicated to supporting Canadian customers and partners, with a mission to strengthen their security posture through the acquisition, deployment, and optimization of advanced solutions that integrate cloud computing and generative artificial intelligence.
Drawing on extensive experience managing large-scale cloud deployments, Mr. Thibault St-Pierre is an active participant in professional communities and specialized working groups. He contributes to the development and sharing of best practices in security, compliance, and data governance within cloud environments.
-
David-Alexandre occupe le poste de Directeur National, Cybersécurité chez Microsoft Canada. Il dirige une équipe dédiée à l’appui des clients et partenaires canadiens, dont la mission consiste à renforcer leur posture de sécurité à travers l’acquisition, le déploiement et l’optimisation de solutions avancées intégrant l’infonuagique et l’intelligence artificielle générative.
Fort d’une solide expérience dans la gestion de déploiements Cloud d’envergure, M. Thibault St-Pierre participe activement à des communautés professionnelles et à des groupes de travail spécialisés. Il contribue à l’élaboration et au partage des meilleures pratiques relatives à la sécurité, la conformité et la gestion des données dans les environnements infonuagiques.





