The Dallas-Fort Worth Chapter of ISC2 is based in the DFW area and serves the counties of the Dallas-Fort Worth Metroplex and North Texas Region. Members include those with security certifications from ISC2 as well as other professionals practicing or interested in information, software, and communications security, and the PUBLIC. Our mission is to advance information security in the DFW area by providing our members and other security professionals with the opportunity to share knowledge, grow professionally, educate others, and collaborate on projects. Our chapter programs provide members a forum to facilitate the exchange of knowledge and ideas, the development of leadership and professional skills, and the advancement of information systems security. We also provide our members with access to a variety of industry resources and educational programs to keep them up to date with the latest advances in technology as well as information assurance.

Agentic GRC: How AI Agents Are Changing the CISO’s Playbook

September 25th, 2026
NOON to 1 PM

(With a few minutes delay and you can join in as soon you are available)

GRC teams have spent years bolting automation onto fundamentally manual processes, automated reminders for manual evidence collection, dashboards built on manually updated spreadsheets. Agentic GRC represents a different model: AI agents that don’t just flag work for humans, but actively execute it, answering vendor and customer security assessments, collecting evidence, managing and updating the risk register, drafting and maintaining policies, and generating reports on demand, in minutes rather than days, without waiting for a human to kick off each step.
This session explores what “agentic” actually means in a GRC context and why it matters now. We’ll cover how autonomous agents can reduce the time spent answering and completing security questionnaires and assessments, continuously monitor and oversee the risk register, keep policy management current as regulations and internal standards shift, and generate board-ready and audit-ready reports on demand instead of through manual, multi-day compilation efforts, all while prioritizing remediation based on risk impact. The conversation will also address where agentic approaches still need human oversight, and how CISOs should think about validation, auditability, and trust when handing meaningful work to an AI agent.
For CISOs and GRC leaders, the payoff is fewer cycles spent on manual coordination and more time spent on judgment calls that actually require a human, faster audit readiness, real-time risk visibility, quick reporting generation, and a compliance program that scales without a proportional increase in headcount.

Key Takeaways for Attendees:

  • What distinguishes “agentic” GRC from traditional automation, and how to tell the difference when evaluating vendors
  • How AI agents are reducing the burden of assessment answering and completion
  • How AI can help manage and oversee the risk register
  • Using agents to draft, maintain, and update policy management as frameworks and regulations evolve
  • Reporting generation: turning raw compliance data into board-ready output without manual assembly
  • How to think about oversight, auditability, and trust when agents are executing compliance-critical tasks
  • Framework consolidation: letting agents map one control across multiple frameworks and how to overcome increasing regulatory requirements

Industry Trends/Challenges to Address:

  • The shift from human-triggered automation to autonomous, agent-driven GRC workflows
  • The growing volume and repetitiveness of vendor/customer security assessments and questionnaires
  • Regulatory complexity and framework proliferation across industries
  • Third-party and vendor risk management at scale
  • Resource-constrained GRC and security teams under growing compliance burden
  • Governance and trust questions raised by handing compliance tasks to AI agents

Mr. Llewellyn Derry is a seasoned IT risk management and cybersecurity executive with over 25 years of experience driving strategic security initiatives across Higher Education, Federal Government, and Global Enterprises. As an experienced Vice President, CISO, Managing Partner, and Board Advisor, he specializes in aligning governance, risk, and compliance strategies with business objectives, ensuring organizations can transform security challenges into market advantages. With expertise spanning cybersecurity leadership, IT governance, risk mitigation, and compliance management, Llewellyn has built a career on fortifying global enterprise digital infrastructures while enabling organizations to grow & scale securely both here in the United States and Overseas.

As the Founder and President of Above Security, he leads a GRC Management and Board Advisory Services firm serving organizations across the U.S., Canada, and the Caribbean. His team leverages over 300 man-years of combined cybersecurity expertise—spanning GRC Management, network and cloud security, risk assessments and penetration testing—to help clients proactively neutralize digital threats. This seasoned executive has played an integral role in assessing, strengthening, and enforcing IT risk postures and policies for organizations seeking to enhance the resilience of their IT infrastructure and their company at large.

Llewellyn’s global business acumen extends across industries, having held key leadership positions at Raytheon, Cisco Systems, AT&T, and Hitachi Systems Security.  He has also taught Cyber Security courses at the Undergraduate and Graduate Level at the University of Dallas, Dallas Baptist University and Hacker University (Israel).  Llewellyn holds an MBA in International Business from the University of Dallas, a Graduate Certificate in Corporate Finance from Southern Methodist University, and a Bachelor’s Degree in Economics and French from Texas A&M University. His professional certifications include C|CISO, CISSP, CISM and C|EH.  

2026_Sept_Webinar Registration
How Did You Hear About The Webinar *

About Us

Our chapter provides members a forum to facilitate the exchange of knowledge and ideas, development of leadership and professional skills, and advancement of information systems security. We also provide our members with access to a variety of industry resource and educational programs to keep our members informed of the latest advances in technology and techniques.