Live sessions, workshops and conferences

Learn from the people who write the detections

Guardian Labs analysts, incident responders and product engineers run live sessions every fortnight — demonstrations on real telemetry, hands-on labs and unscripted question time. Everything is recorded, and every recording is free.

Live and upcoming

Six sessions between now and November

All times shown in your local timezone at registration. Sessions run 45 to 60 minutes unless marked as a workshop; every one ends with open Q&A that is not cut short for time.

Live webinar Threat research Filling fast

Inside the 2026 Threat Report: what the data actually says

Breakout time fell to 41 minutes and 79 percent of intrusions involved no malware at all. Two of the report's lead authors walk through the underlying casework, including the three findings that did not make the printed edition.

Thursday 3 September 2026 · 60 min Dr Nadia Ferreira, Head of Guardian Labs · Marcus Wen, Principal Analyst EMEA & Americas sittings
Register
Live webinar Identity Live demo

Stopping token theft: an adversary-in-the-middle demonstration

We run a real phishing proxy against a lab tenant, defeat push-based multi-factor authentication in under 90 seconds, then show exactly which signals give the replay away and how conditional access plus token binding breaks the chain.

Wednesday 16 September 2026 · 50 min Sofia Grimaldi, Identity Detection Lead Recorded for on-demand release
Register
Hands-on workshop Cloud Limited to 40 seats

Kubernetes runtime defence lab

A three-hour guided lab in a disposable cluster. You will execute container escape, privileged sidecar abuse and a malicious admission webhook, then build and tune the detections that catch each one. Bring a laptop and a terminal; we provide the cluster.

Tuesday 29 September 2026 · 3 hours Jonas Halvorsen, Staff Detection Engineer Counts toward Sentinel Analyst certification
Reserve a seat
Live webinar Compliance

DORA in practice: evidence an examiner will actually accept

Written for financial entities and their critical ICT providers. We go control by control through operational resilience testing, incident classification and the 24-hour initial notification, and show the artefact set that survives scrutiny.

Thursday 8 October 2026 · 60 min Camille Roux, Principal Compliance Advisor Evidence checklist included
Register
Live webinar SOC operations

Autonomous response without losing control: designing guardrails

The hardest part of automation is not the automation — it is the approval model around it. We cover blast-radius limits, staged enablement, reversible actions, change-window awareness and the audit trail your risk committee will ask for.

Wednesday 21 October 2026 · 45 min Aisha Bello, Director of SOC Transformation Playbook templates provided
Register
Live webinar Operational technology

OT security for plant engineers, not just security teams

A session designed to be watched jointly by engineering and security. Passive discovery on Purdue levels 0 to 3, safe protocol parsing, and why change-window-aware response is the only response model a safety instrumented system will tolerate.

Thursday 5 November 2026 · 55 min Tomas Okafor, Kestrel Aerospace · Priya Nandakumar, Guardian OT Practice Customer co-presented
Register
Cannot make the time? Register anyway. Everyone who signs up receives the recording, the slide deck and any detection content within 24 hours of the live session ending, whether they attended or not.

Flagship conference

Guardian Sentinel Summit 2026

Three days in San Francisco, 12–14 October. Two thousand practitioners, forty sessions, and a detection engineering track that is deliberately too technical for a keynote stage. Customer-led content outnumbers vendor content two to one.

Detection engineering track

Twelve deep sessions on analytic design, coverage measurement and tuning at scale.

Live incident simulation

A full-scale breach exercise run in real time across the main hall on day two.

Customer architecture reviews

Book a 45-minute session with a Guardian architect on your actual deployment.

Certification bootcamp

Two-day accelerated path to Sentinel Analyst certification, exam included.

summit-2026 / agenda.overview

Three-day structure

09:00 12:00 17:00 Day 1 — 12 Oct Hands-on workshops Certification bootcamp Day 2 — 13 Oct Keynotes Live simulation Labs Day 3 — 14 Oct Customer sessions Detection engineering track 2,000 attendees · 40 sessions · 26 customer speakers Moscone West, San Francisco · streamed for remote pass holders

On-demand library

Eight recordings, no registration wall

Every session we have run this year, indexed by chapter so you can skip straight to the demonstration. Slides and detection content are linked under each recording.

52 minThreat research

Ransomware Playbooks 2026: the nine affiliates

Tooling, timing and negotiation behaviour for nine active ransomware-as-a-service operations, with the detection logic for each.

Watch the recording
38 minCustomer story

A CISO's parallel evaluation, start to finish

Northbank Financial Group on running two detection stacks side by side for sixty days, and what the comparison revealed.

Watch the recording
61 minDetection engineering

Detection engineering with ATT&CK v17

Building analytics that survive adversary adaptation, and measuring coverage in a way that does not flatter your own tooling.

Watch the recording
44 minCloud

Cloud control-plane attacks explained

How OIDC trust misconfiguration becomes full account takeover, demonstrated live across two cloud providers.

Watch the recording
35 minProduct

Sentinel Q2 2026 release deep dive

Everything shipped this quarter, including the new reasoning traces on autonomous decisions and expanded OT protocol coverage.

Watch the recording
29 minExecutive

Building a SOC automation business case

Turning containment time into currency, with the cost model and the three objections finance will raise.

Watch the recording
47 minIdentity

Identity threat detection: signal to containment

From impossible-travel noise to behavioural baselines that catch session replay from a legitimate-looking network position.

Watch the recording
72 minIncident response

Tabletop exercise: a live recording

An unrehearsed ransomware tabletop with a real executive team, including the decisions that went badly and why.

Watch the recording

On the road

Where to find Guardian in person

We staff booths with engineers rather than product marketing, so bring the awkward architecture question. Book a slot in advance and you will get a named person and a whiteboard for 45 minutes instead of a queue.

San Francisco Amsterdam Singapore Chicago Six events across three regions, October 2026 – February 2027
Guardian conference and event schedule, October 2026 through February 2027.
Event City Dates Our presence
Guardian Sentinel Summit San Francisco 12–14 Oct 2026 Host · 40 sessions
Cyber Defence Europe Amsterdam 3–5 Nov 2026 Booth D14 · keynote
SecOps Summit APAC Singapore 18–19 Nov 2026 Two technical talks
Financial Sector Security Forum London 2 Dec 2026 DORA panel
Healthcare Security Congress Chicago 21–22 Jan 2027 Clinical device workshop
OT & ICS Defence Days Frankfurt 10–11 Feb 2027 Hands-on lab · booth 22

Scroll the table sideways to see every column.

Book a meeting before you travel Engineer time at each event is limited and fills roughly three weeks out. Request a slot and tell us what you want to dig into — architecture, migration, detection engineering or incident readiness.

Recurring programmes

Four series you can subscribe to once

Subscribe to a series and every future session is added to your calendar automatically, with the recording delivered whether you attend or not.

Threat Briefing Live

Monthly, 30 minutes. What Guardian Labs saw in the last four weeks, which adversaries changed tradecraft, and what shipped in response.

First Thursday, monthly

Subscribe to the series

Detection Engineering Club

Fortnightly, 60 minutes. Practitioners present an analytic they built, and the room tries to evade it. Bring your own detection to workshop.

Alternate Wednesdays

Subscribe to the series

Release Radar

Quarterly, 35 minutes. Everything shipped in Guardian Sentinel, why it was built, and what is deprecated — with migration notes.

Quarterly, week after release

Subscribe to the series

Breach Room

Quarterly, 75 minutes. A live tabletop exercise run against a volunteer executive team, unrehearsed, with the incident response lead facilitating.

Quarterly, by invitation

Request an invitation

Registration

Save your seat

One form covers any session, workshop or series. Workshops are capped at 40 participants and confirmed by email within one working day; webinars confirm instantly.

  • Calendar invitation with dial-in details, sent immediately.
  • Recording, slides and detection content within 24 hours of the live session.
  • Live captions and a transcript in English for every session.
  • No sales follow-up unless you ask for it on the form.
Registering a team? Groups of five or more get a private repeat of any session run for your organisation at a time that suits, with your own environment used as the worked example. Talk to us.
Choose a session

Popular sessions run twice so nobody has to join at 03:00.

Your details

Related

Before or after the session

Whitepapers & reports

The written research behind most of these sessions, including the 2026 Global Threat Landscape Report referenced in the September webinar.

Read the research

Case studies

The customer stories our co-presenters tell on stage, with the full metric set and deployment detail written down.

See the outcomes

Security training

Structured certification paths for analysts and awareness programmes for the wider workforce, delivered live or self-paced.

Explore training

New to a topic? Start with the security glossary, or check the datasheets for the specifications referenced in the product sessions.

Prefer a session about your environment?

A Guardian engineer will run a private walkthrough against your architecture, your constraints and your open questions. Sixty minutes, no slideware.