Skip to content
Patrick M. Hayes

Speaking & Media Archive

Speaking & Media Archive

A record of conferences, keynotes, executive sessions, interviews, podcasts, webinars, and other conversations where Patrick has shared and developed his work.

2026

  1. Global Security Exchange - Where AI Risk Really Lives

    Read description +

    Artificial intelligence is reshaping how organizations operate, make decisions, manage supply chains, and engage customers. Yet many enterprises still evaluate AI risk using control models built for an earlier generation of IT. That disconnect between adoption and oversight has become one of the largest sources of unmanaged enterprise risk. This session addresses that gap directly and reframes AI risk as a governance and assurance challenge that demands executive and board-level attention. Drawing on published research, the session explains where AI risk truly concentrates today. The most significant exposures do not live on endpoints. They emerge in identity systems, cloud architectures, data pipelines, and fragmented governance models that struggle to keep pace with AI adoption. AI changes the structure of risk through opaque decision-making, fragile data dependencies, and automated behavior that operates beyond the visibility of traditional controls. Attendees will leave with a clear understanding of how AI expands enterprise exposure and a practical, maturity-based approach for embedding assurance into enterprise risk programs in a way that is measurable, defensible, and resilient under regulatory pressure.

  2. Keynote Session: When Good Security Decisions Age Badly

    Read description +

    How Temporary Controls become Permanent Risk

  3. Myths and Mythos: Rethinking Security Architecture and the Future of Trust

    Read description +

    Join us on June 18th for the next CAF Quarterly Event, an exclusive session for CAF members featuring expert perspectives on architecture, security, governance, and trust in today's rapidly evolving technology landscape. Panel Discussion: Brice Ominski (Facilitator), Walt Powell, Patrick M. Hayes, Andres Andreu - Myths and Mythos: Rethinking Security Architecture and the Future of Trust This session will challenge conventional thinking around security architecture and explore how trust, governance, and leadership must evolve to meet the demands of modern enterprises.

  4. S5:E126 🎙 LIVE with Patrick M. Hayes Leadership & Success Podcast with Coach BZ

    Read description +

    Patrick has spent more than 30 years helping organizations solve the problems that fall between organizational silos. Throughout his career as a cybersecurity executive, enterprise architect, CISO, strategist, and trusted advisor, he has challenged leaders to rethink how they approach risk, resilience, governance, and business performance. He is the author of: 📚 Integrated Assurance: Unified Risk Strategy 📚 Can We Insure This?: A CFO's Guide to Cybersecurity 📚 Relevant Impact: A Field Guide to Integrated Assurance (upcoming)

  5. Your Security Program Has a Blind Spot. Your Insurer Doesn't.

    Read description +

    Join three industry practitioners for a 45-minute deep dive into the collision of cybersecurity, insurance, and the risk most mid-market companies can’t see. June 9, 2026 | 12:00 p.m. ET / 9 a.m. PT | Live Q&A Your cyber insurance renewal used to be paperwork. Carriers don’t work that way anymore. They’re scanning your environment, comparing what they find to known attack vectors, and pricing your policy based on what they see. If your controls exist on paper but fail under testing, or if you’ve got assets on your network you haven’t accounted for, that shows up at renewal. Most mid-market companies are feeling this but handling it in pieces. Security buys tools. Compliance fills out the questionnaire. Finance writes the check. Those teams don’t compare notes, which means nobody inside the organization can connect what's on the network to whether the controls hold up to what the underwriter sees. That gap has a cost, and it’s usually invisible until the premium spikes or a claim gets denied.

  6. Experiments in Leadership Interview

    Read description +

    AI is transforming cybersecurity faster than ever—but is it making organizations safer or introducing entirely new risks? In this episode of Experts in Leadership, we sit down with Patrick Hayes to explore how artificial intelligence is reshaping the cyber threat landscape, security operations, and executive decision-making. From AI-powered cyberattacks and deepfakes to automated threat detection, governance, and cyber resilience, Patrick shares practical insights on what business leaders, CISOs, and IT teams need to understand as AI becomes embedded in every aspect of the enterprise. Whether you're leading digital transformation, managing cyber risk, or simply trying to separate AI hype from reality, this conversation provides actionable perspectives on preparing your organization for the future. In this episode you'll learn: How AI is changing the cybersecurity landscape The biggest AI-related cyber threats organizations face today How defenders are using AI to improve detection and response The governance and ethical challenges of enterprise AI Practical advice for business leaders adopting AI securely What the future of AI and cybersecurity may look like

  7. ISACA North America Conference

    Compensating Controls: From Compliance Crutches to Strategic Enablers

    Read description +

    Compensating Controls: From Compliance Crutches to Strategic Enablers Compensating controls were once clever workarounds, but in today’s enterprise environments they often linger far beyond their useful life, quietly undermining modernization, resilience, and visibility. This session challenges traditional thinking by reframing compensating controls through the lens of a unified approach to governance, risk, and security architecture. Drawing from real-world enterprise examples, attendees will learn how to transform compensating controls from static exceptions into dynamic, time-bound components that support resilience, agility, and measurable risk reduction. We will explore lifecycle governance, automation strategies, and metrics that ensure these controls evolve in step with threats and business change. Instead of asking, “Does this control meet audit standards?” we’ll ask, “Does this control make us safer, faster, and more resilient?”

  8. Proactively Navigating Cyber Risks

    Read description +

    In this episode, cybersecurity expert Patrick Hayes of Third Wave Innovations discusses the importance of cyber insurance, proactive security measures, and how organizations can better understand and mitigate cyber risks. Learn how MDR, employee education, and strategic planning can protect your business in an increasingly connected world.

2025

  1. SMPTE Technology Conference

    Read description +

    I will be speaking at the SMPTE Technology Conference December 3rd on the topic of Securing Trust in the Age of AI and Autonomous Threats.

  2. Chief Architect Forum

    Read description +

    I recently sat down with Dan Swanson and Brice Ominski for a new session in the Chief Architect Forum and Architecture Leadership Series. We explored what it really takes to build organizations that can adapt without losing integrity. Brice framed the strategic lens from Digital Momentum, where he emphasizes adaptation, assurance, and trust as the next decade’s real differentiators. I shared how Integrated Assurance helps leaders connect risk, architecture, and operations so their organizations can move with confidence rather than caution. Dan tied it together with insights from across the broader CRC Press security landscape. If your enterprise is navigating rapid transformation, wrestling with complexity, or looking for a way to strengthen resilience while still moving fast, this discussion will be worth your time.

  3. RRC Polytech Inspire 2025

    Read description +

    I will be speaking at the Inspire Conference 2025 hosted by RRC Polytech on October 29 in Winnipeg! I will share insights from my new best selling book Integrated Assurance and exploring how IAMM can break down silos across risk, compliance, audit, and security to create a more resilient, holistic assurance framework. If you’re attending, let’s connect! Would love to chat more, share ideas, or follow up after the session.

  4. Caffeinated Risk

    Read description +

    Our next podcast episode for Caffeinated Risk is ready to go tomorrow morning! Doug Leece and I had a great session with Patrick M. Hayes, author of the new book "Integrated Assurance: Unified Risk Strategy". We had a great time with Patrick, dug into why he took this journey to create Integrated Assurance, and did a little reminiscing on past lives and shared travels. It's a great episode folks - head over to Spotify to check out the latest podcast, and don't forget to subscribe so you don't miss an episode!

  5. Cisco Executive Briefing: Building a Resilient Enterprise

    Read description +

    We’re bringing together security and IT leaders for a focused, in-person session on how to: -Unify identity, network, endpoint, cloud, and data. -Simplify operations and reduce tool sprawl. -Streamline detection and response workflows. -Report with clarity and confidence to executives and boards. -Align cybersecurity with business objectives. Featured Speaker: Join Patrick M. Hayes, a veteran security strategist with three decades of experience helping enterprises align cybersecurity, compliance, and IT. All attendees will receive a free copy of his bestselling book, Integrated Assurance: Unified Risk Strategy. A practical guide to building a unified, business-driven security strategy.

  6. Cracking the Code: Cybersecurity Insights with Patrick Hayes

    Read description +

    Dive into Patrick's intriguing career journey from telecom to cybersecurity and discover how Third Wave's groundbreaking approach is helping businesses combat evolving digital threats. Learn why cybersecurity is more than just a technical challenge and explore how organizations can effectively manage risk to support strategic growth. Plus, gain insights into the role of AI in modern cybersecurity and the importance of continuous assessment.

  7. Good Governance Academy: The Next Evolution in Enterprise Security

    Read description +

    The current cybersecurity landscape is defined by fragmentation. Despite the proliferation of frameworks, tools, and regulations, organizations remain vulnerable, breaches persist, silos thrive, and resilience suffers. It’s time for a shift. Integrated Assurance offers a unifying strategy that brings together cybersecurity, risk, compliance, and IT operations into a single, outcomes-driven model. Rather than layering more controls, Integrated Assurance aligns assurance functions with business objectives, enabling proactive risk governance, contextual response, and measurable resilience. In this session, Patrick M. Hayes explores why Integrated Assurance is not just another framework, but a strategic operating model for the future of enterprise security. He examines how assurance must evolve from isolated compliance activity to an embedded, dynamic capability that strengthens decision-making, accelerates trust, and reduces the business impact of cyber threats. Real-world use cases and leadership insights are shared to help executives, architects, and risk leaders adopt this model within their own organizations.