Keynotes · Panels · Podcasts · CISO roundtables · Workshops — worldwide, on-site or remote
Gaurav Sengar speaks on AI and cybersecurity, defense-supply-chain compliance (CMMC) and EU regulation (NIS2) from a rare vantage point: a CISA-certified practitioner who runs a live 24/7 security operations center and compliance programs across four continents.
Why organizers book Gaurav
- Practitioner, not pundit — he runs a working multi-country SOC and real compliance engagements; every talk is built on production war stories, current attack data and numbers his firm publishes openly.
- Credentialed — CISA (ISACA), 12+ years across cybersecurity, IT audit and compliance.
- A perspective nobody else has — the CMMC specialist for defense suppliers outside the United States; ask him what US compliance looks like from Stavanger, Doha or Nagoya.
- Audience takeaways, not slideware — attendees leave with free tools they can use the same day: the SPRS Score Calculator, the CMMC Cost & Roadmap Planner and the CMMC Cost Index.
Talk topics
1. Machine-speed attacks, machine-speed defense: AI on both sides of the SOC
What AI-driven attacks actually look like from a live SOC, and where AI genuinely works in defense today — alert triage, detection engineering, evidence automation — versus where it is still marketing. Includes real metrics from a production 24/7 operation.
2. Adopting AI without opening a new attack surface
A governance playbook for executives: data exposure, prompt and model risk, shadow AI, vendor due diligence — mapped to the frameworks you already answer to (ISO 27001, NIS2, SOC 2). Practical controls, not policy theatre.
3. CMMC from the other side of the ocean
US defense compliance lands on machine shops in Japan, engineering firms in the Gulf and software suppliers in Europe — companies with no local CMMC ecosystem. ITAR and US-persons restrictions, remote assessments, enclave scoping, and what certification really costs (from the published CMMC Cost Index).
4. NIS2 is an operations problem, not a paperwork problem
Why Article 21 measures and 24-hour incident reporting break companies that treat compliance as documentation — and how to build the operational muscle (monitoring, response, evidence) that makes NIS2 a by-product instead of a project.
5. Controls, not documents: compliance as engineering
Twelve years of audits distilled: why audit-passing paperwork and actual security diverge, what a CISA looks for, and how to build compliance that would survive both an assessor and an attacker.
Where he has appeared
Gaurav has appeared on cybersecurity podcasts and industry panel discussions, and speaks regularly at CISO events and cybersecurity meetups. He also hosts ITSECOPS’ own public CMMC webinar series.
Formats and logistics
- Formats: keynote (20–45 min), panel, fireside chat, podcast, half-day executive workshop, CISO roundtable.
- Audiences: CISOs and security leaders, defense-supply-chain executives, MSP owners, boards needing an AI-risk briefing, developer and student communities.
- Locations: based in Stavanger (Norway) and Greater Noida (India); speaks worldwide, in person or remote.
- Languages: English and Hindi.
Short bio for event programs
Copy-paste ready: Gaurav Sengar is a CISA-certified cybersecurity and compliance expert and founder & CEO of ITSECOPS, a security-first IT operations company running 24/7 security operations and compliance programs across four continents. He is known as the CMMC specialist for defense suppliers outside the United States and publishes free industry tooling used by contractors worldwide. He speaks internationally on AI and cybersecurity.
Book Gaurav
E-post info@itsecops.cloud with your event, date and audience, or use the contact form. Media and interview requests welcome.
More background: full bio of Gaurav Sengar.