AI security for SaaS scaleups
Description
AI is creating real opportunities for SaaS companies and new security exposure that is easy to underestimate. Our practical, technical working session is for engineering and security leaders who need a clear view of what has changed, what is actually going wrong and what proportionate action looks like at their stage.
Led by Simon Howard, Executive Director of Bastion Security Group, our session cuts through vendor marketing and enterprise-only advice. Simon brings frontline experience from incident-response and offensive-security work, sharing anonymised examples of AI deployments that have gone wrong, the warning signs teams missed, and the remedial work that followed.
You’ll work through real-world examples, test common attack paths yourself, and leave with a better sense of where your product is exposed and what to prioritise next. Roughly a third of the time will be spent in hands-on lab exercises.
We’ll also have short presentations with learnings from security leaders including Grant Anthony (CIO & CISO at Orion Health & HEALWELL.ai) and Ben Wicks (Head of Architecture & Security at Plexure).
What we’ll cover:
The new risks
Understand the emerging vulnerability classes affecting AI systems, including prompt injection, agent tool use and privilege, retrieval poisoning, and model and package supply-chain risks. We’ll also look at how deepfakes are changing the social-engineering landscape.What we’re seeing in the field
Drawing on Simon’s incident-response and offensive-security work, we’ll examine anonymised case studies of AI deployments that went wrong, the warning signs teams missed, and the remedial work that followed.Hands-on testing
Bring your laptop. Part of our workshop is dedicated to lab exercises, where you’ll attempt prompt injection and agent hijacking against live targets, including Lakera’s Agent Breaker challenges. The goal is to assess your own product’s exposure.What to do at your size and stage
Explore what is proportionate for a 30-person company, what to add as you reach 100 people, and what can defensibly wait. We’ll cover open-source tools and practical first steps for reducing immediate, high-impact AI security risks. Plus how to respond to the AI security questions now appearing in enterprise procurement.
Who is it for?
CTOs, CISOs, Heads of Engineering, platform leads and security leads at KiwiSaaS large-member companies ($5m–$200m ARR). Limited to 20 people and Chatham House rules apply.
Date: Thursday 12 November 2026
Time: 9:00am - 12:00pm, with light lunch to follow
Location: Plexure, Level 2, 4 Graham Street, Auckland
Event Type: In Person
Cost: Free for large KiwiSaaS members ($5m+ ARR)
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity





