Information Security: Recent Episodes

None

This channel features presentations by leading experts in the field of information security. From application, computer, network and Internet security to access control management, data privacy and other hot topics, you will walk away with practical advice for your strategic and tactical information security initiatives.

View Details

In today's dynamic threat landscape, building a security-first culture is essential for safeguarding an organization’s data. This panel session, featuring Michelle Pruitt, Binta Kindle, Swati Popuri, and Cherie Griffith-Dunn, will explore leadership tactics for fostering a mindset of holistic data protection across all levels of the organization.Key topics include:- Establishing a security-centric organizational mindset.- Best practices for leadership to encourage proactive data protection.- Effective training strategies for promoting security awareness.- Integrating security considerations into AI and digital workflows.- And moreJoin us to discover how to empower your team, regardless of their technical background, to embrace security as a core value and enhance your organization’s data protection strategy.

View Details

The future is uncertain, but many cyber threats are largely predictable. In the cybersecurity arena, our victories make a difference and cause some threats to fade into history. However, our ability to stay ahead of cyber threats has its ups and downs, influenced by numerous factors. Meanwhile, threat actors continually evolve their techniques and approaches.Drawing on more than a quarter century of experience in cybersecurity, industry thought leader Alex Holden invites you to join him on a journey through the evolving threat landscape. We'll examine the latest trends in threat intelligence and advancements in AI, and we'll focus on building the most effective cyber defense strategies as we approach 2025.

View Details

In the ever-evolving landscape of DevOps, the paradigm is now shifting - where security is taking the central stage. With vast surface areas including containers, cloud, repositories and third party components, cyber threats became prominent then ever before in DevOps. Our presentation delves into the evolution from traditional DevSecOps to the advanced elimination of threats in each possible way in every stage of DevOps: Build, Test, Deploy and Operate. Lets see how we can prevent cyber threats with secure cloud architecture, continuous logging and monitoring, required approval processes in place, code scanning along with manual reviews as well ensuring heightened security at every step.In this session, join Jyotirmayee Pradeep Kumar (Vice President - Cloud DevOps at a well-known global bank) as she unravels the stages of elimination of cyber security threats at each phase of DevOps. Topics for discussion include:- DevOps landscape and different stages associated with it.- Surface area of cyber threats in DevOps.- Security breaches within the DevOps framework.- Practical strategies for eliminating cyber threats with shift-left security implementations. - Diverse approaches to automate security integration into DevOps practices.

View Details

The National Institutes of Science and Technology recently launched a new version of their cyber security framework, NIST CSF v2.0 to provide both government organizations and private industry a comprehensive set of cyber security guidelines. Better yet, this version can easily be integrated into existing frameworks and tools. In this session, Hilton analyst Ralph Villanueva will point out how the newly added governance aspect of this framework can boost the detection, respond and recover capabilities of any organization in the event of a cyber-security incident.

View Details

Tune into this session from industry thought leader Vincent Amanyi as he highlights a robust strategy to develop core requirements and step-by-step approach to build a resilient foundation of your insider threat program.Key takeaways:- How to perform environment assessment. - How to establish a clean foundation that is central to your enterprise.- Learn how to benchmark and manage your maturity journey.- Develop the right mix of tool for monitoring.

View Details

In the rapidly evolving landscape of cybersecurity, the ability to effectively detect and respond to threats is paramount for organizations across the globe. Traditional threat intelligence mechanisms have often been reactive, focused on addressing vulnerabilities after they have been exploited. However, with the increasing sophistication of cyber threats and the expanding digital footprint of modern enterprises, there is a critical need to pivot towards more proactive and dynamic strategies.This presentation delves into the latest methodologies and technologies driving the future of threat intelligence. We will explore cutting-edge approaches to data collection and analysis, including artificial intelligence (AI) and machine learning (ML) algorithms, which enable predictive threat modeling and real-time anomaly detection.We will discuss the importance of expanding threat intelligence sources beyond traditional feeds, incorporating open source intelligence (OSINT), social media analysis, and dark web monitoring to gain a more comprehensive view of potential threats. The role of collaborative intelligence-sharing platforms will also be highlighted, emphasizing how they enhance collective defense mechanisms by fostering an ecosystem of shared knowledge and resources.

View Details

Tune into this talk to learn about the integration of Artificial Intelligence (AI) into endpoint detection and response (EDR) systems, focusing on the application of AI-driven behavioral profiling to identify malicious activities. Industry thought leader John Bambenek will delve into the mechanisms by which AI models discern typical from atypical user behaviors, thus enhancing threat detection capabilities. The discussion also will cover the benefits of this holistic approach, including improved detection accuracy and faster response times. Practical case studies will demonstrate the effectiveness of AI behavioral profiling in real-world scenarios, underscoring its significance in the development of robust cybersecurity frameworks.

View Details

Tune into this talk presented by the University of Washington's Deveeshree Nayak as she discusses the importance of advancing application security practices into our technology use. As technology continues to integrate more into our lives, it becomes increasingly important to secure educational applications and platforms. During the session, we will explore various topics such as the current threat landscape, the significance of secure development, case studies, best practices, the role of education in advancing security practices, future trends, and how to form a team to address security vulnerabilities, manage risks and fortify against cyber attacks. Please join to gain insights into advancing application security practices tailored to various sectors' unique challenges and opportunities. Whether you are an educator, IT professional, or administrator, this talk aims to equip all types of attendees with the knowledge and tools needed to strengthen your institution's security posture.

View Details

In an age where artificial intelligence (AI) not only powers innovations but also underpins cybersecurity threats, this session aims to inform and help you prepare against the next wave of digital assaults. This talk will delve into the burgeoning domain where lax API security meets sophisticated AI-driven exploit bots, marking a paradigm shift in how cyber threats are generated and how they must be mitigated.As smaller entities become increasingly attractive targets due to the reduced cost and effort required for attacks, the session underscores the imperative of adopting secure development practices. It posits that the foundation of robust AppSec in this new era lies not in the procurement of cutting-edge tools, but in the diligent application of well-established security principles. Attendees will leave with the following takeaways:- Cost-effective strategies that can fortify applications against the onslaught of AI-powered threats.- Proactive cybersecurity frameworks, with a particular focus on how threat modeling can evolve to address AI-specific vulnerabilities. - Actionable insights into applying frameworks like the NIST AI RMF to AI app development. The session seeks to equip participants with the knowledge and tools necessary to anticipate and defend against not just the threats of today but those of a rapidly approaching future. Designed for security professionals, application developers, and business leaders alike, this talk will offer a blend of humor, real-world scenarios, and practical solutions to navigate the complexities of securing applications in an AI-driven world. Join us to explore how we can turn "advanced threat guesswork" into a strategic advantage, ensuring our digital defenses are not just reactive but predictively aligned with the cybersecurity landscape's evolution.

View Details

In the digital age, APIs are the backbone of digital transformation, powering everything from mobile apps to microservices. However, as the complexity and connectivity of systems increase, so does the attack surface and their vulnerability to cyber attacks. The key to securing these systems lies not just in the application of security measures post-development but in embedding security considerations throughout the Software Development LifeCycle (SDLC). This session, sheds light on the process of threat modeling and showcases its critical role in designing secure and resilient APIs.During this session, we will be covering- The fundamentals of threat modeling.- Integrating threat modeling to API lifecycle. - Case studies and real-world applications. - Tools and techniques for effective threat modeling. - Overcoming common challenges. This session is designed for developers, security professionals, and IT leaders seeking to enrich their API security strategy through the power of threat modeling. By the end of this session, attendees will be equipped with the knowledge and tools needed to implement a robust threat modeling process, transforming their API design process.About the speaker:Elango is CISSP certified and accomplished technology leader with 20+ years of experience building high-performance engineering organizations for high-tech and financial services businesses across multiple geographies. He oversaw several cloud implementations that meet the highest standards of security and compliance for top-tier banks across Singapore, Thailand and the United States.

View Details

Do you have all the parts of zero trust in place to control risk to your crown jewels? If you don't know where to start, you probably need to assess your situation.Using a zero trust readiness assessment you can see what parts of the people, process, and technology triad you already have in place and what you don't. With a readiness assessment you can figure out what to focus on first in order to tackle the remaining parts of the zero trust jigsaw.Zero trust is a model or philosophy of how users and devices access applications and data. Zero trust is not a SKU or a single product, rather it is a more secure way to provide access to data by checking the identity of the user, or application, on a continual basis before allowing the user or application to access sensitive or confidential data, limiting access by network segmentation and dynamic access mechanisms. Remember, the goal is to protect the data and make sure that it remains confidential, maintains integrity and availability.CBTS used the NIST Special Publication 800-207 as the foundation for an assessment to help customers know where they stand with their zero trust journey. The assessment is standards based and does not reference or promote vendor solutions, rather the people, processes, and technologies in place are assessed against 800-207. In this presentation we will review the general components of a zero trust readiness assessment so that you know where you are and how to complete your journey.

View Details

APIs have become essential in today's digital ecosystem, enabling seamless data exchange, connecting applications, and driving innovation. However, as they contain valuable data, APIs can also serve as enticing targets for cyber attacks such as DDoS attacks, SQL injections, and cross-site scripting (XSS). A single API breach can jeopardize sensitive information and affect an organization's reputation, financial stability, and compliance. Therefore, it's crucial to have a robust API security program in place. In this webinar, we will explore the multifaceted landscape of API security and emphasize its pivotal role in modern enterprises' overall cybersecurity posture. We will delve into the foundational components of API security, explain how each relates to the evolving threat landscape, and discuss practical, actionable ways they can prevent cyber criminals from exploiting vulnerabilities in APIs. We will also provide insight into the capabilities of a mature, end-to-end API security program and define practical milestones to empower you to elevate your API security to the next level.Key takeaways from this webinar include understanding how attackers' tools, techniques, and procedures are evolving, learning the components of API security and their respective roles, and taking actionable steps to assess and enhance your organization's API security posture. In addition, we will highlight forward-thinking strategies and how web application firewalls (WAFs) can help detect and block malicious traffic, and how API security solutions can provide comprehensive protection for your APIs and work with WAFs to ultimately protect applications and their data.

View Details

Zero Trust Architecture (ZTA) incorporates many aspects of effective cyber security…but not all of them. There are many elements of information security that are implied in ZTA but are not explicitly stated. These include role-based access control (RBAC), identity management, key management and threat intelligence. Together, constitute the zero trust environment, which must be in place for the architecture to be implemented. ZTA plus these environmental elements are the basis for secure use of information resources, today and as a foundation for future growth. This session presents each of these elements as products to be evaluated, acquired and implemented in order to achieve full zero trust.Learning objectives:- The various security methods that support ZTA but are not included in it. - The value proposition for a fully supported zero trust environment.- The vendor landscape of these supportive methods.- Determining the need for supplemental products and tools.

View Details

In the ever-evolving landscape of DevSecOps, the paradigm is shifting towards a proactive approach known as Zero Trust, redefining how security is integrated into the CICD pipeline. This transformation doesn't simply entail developers assuming more security responsibilities but rather involves a holistic restructuring, where security teams engage in early-stage development.Our presentation delves into the evolution from traditional DevSecOps to the advanced realm of Zero Trust. We explore the principles of "Simple DevSecOps" and "Trust but verify," leading up to the pinnacle of security sophistication: "Zero Trust." In a zero trust environment, every element of the DevOps pipeline undergoes rigorous authentication and authorization, ensuring heightened security at every step.In this session, join Jyotirmayee Pradeep Kumar (Vice President of Cloud DevOps at a well-known global bank) as she unravels the concepts of "Security as Code" and "Policy as Code" as instrumental tools in implementing zero trust. Topics for discussion include:- The foundational principles of DevOps and its evolving landscape.- The pivotal role of security within the DevOps framework.- The benefits and challenges of zero trust in DevOps environments.- Practical strategies for implementing zero trust in the CICD pipeline.- Diverse approaches to integrating zero trust seamlessly into your DevOps practices.

View Details

The rapid adoption of cloud technology by organizations has led to a shift towards both single and multi-cloud environments. Unfortunately, this shift has also resulted in cloud misconfigurations, which are one of the top risks associated in the cloud. Cloud misconfiguration refers to any errors or gaps in the security measures of a cloud environment. We will begin by discussing the root causes of cloud misconfigurations. We will then review case studies of organizations that have suffered data breaches due to cloud misconfigurations, such as Capital One in 2019, eBay in 2014, and World Wrestling Entertainment (WWE) in 2017. Finally, we will then walk through built-in tools provided by AWS, Microsoft Azure, and Google Cloud, that cyber professionals can leverage to mitigate security risks in the cloud. These tools are also known as Cloud Security Posture Management (CSPM) tools.Cloud Security Posture Management tools are automated solutions designed to identify misconfiguration issues and compliance risks in the cloud so that they can be remediated, reducing the risk of successful breaches. We will explore AWS Security Hub, Microsoft Defender for Cloud, and Google Security Command Center, and review how each tool can be used to gain visibility into the current security posture of each respective cloud. Furthermore, we will emphasize how these tools can be applied to determine alignment with relevant regulatory compliance standards and industry-standard benchmarks, as well as identify threats and potential security weaknesses. The key takeaways from this session are:- Most cloud breaches are due to misconfigurations or human errors.- Do not rely on your cloud service provider to secure your data (understand the shared responsibility model).- You cannot protect what you do not have visibility into (CSPM solutions can help).- Cloud security should begin with implementation of cloud governance.

View Details

Organizations are striving for IT sustainability, but having the right foundation in place is imperative to be able to work towards the sustainability goal. Tune into this session presented by industry thought leader Vincent Amanyi as he highlights the fundamentals to establish and jump start the IT sustainability program in your organization. Attendees will learn:- Strategies to design a comprehensive program.- How to identify core factors that drives decision points.- How to develop a benchmarking to manage the program.

View Details

Several cyber insurers have turned the noncompliance tables on their clients with the covenants of their cyber insurance policies. Ironically, these covenants are nothing more than IT security requirements which, with some board and C-suite support and focus, can be fulfilled by the CIO and his team. In this presentation, industry thought leader Ralph Villanueva will draw on his IT security, compliance and cyber security insurance experiences (he is a licensed P & C insurance agent and broker, which includes cyber security insurance) to help the audience avoid these five cyber insurance pitfalls and ensure that if an insurable event occurs, their employers will receive the full benefits of their cyber insurance policy.

View Details

Cyber insurance is a must in today's IT threat landscape, but how do you make the right choice among the vast market of providers? This session, presented by industry thought leader Vincent Amanyi, will detail a comprehensive model of how to to better align your organization assets with the right cyber insurance mix. Key takeaways- Develop strategy to perform health check across your enterprise. - Establish a clear cost-monitoring model across your enterprise.- Develop a mechanism towards a targeted insurance mix for your assets.

View Details

In an era where "cloud-first’ is often mistaken for “cloud-only,”' let’s explore a few often-neglected aspects of ransomware incident preparedness, highlighting the ironic shift in readiness from things we used to do well (or at least often) in the pre-cloud era, but that have been left behind in the present day. This presentation will focus specifically on three critically underappreciated practices that are still useful, and increasingly pivotal, for effective response to ransomware attacks.1.) The significance of "go-to-paper" processes, you know, good old-fashioned manual business continuity (BC) procedures we used to follow when our digital world went dark. We'll explore how these archaic yet surprisingly resilient manual tactics are more than just a trip down memory lane, but necessary steps in ensuring your business keeps running even when screens don’t.2.) Infrastructure backups. We're not just talking about your important data, but the increasingly software-defined and abstracted infrastructure components you rely on. This discussion will strip away the veil of complacency that often shrouds cloud-based systems, revealing the stark realities of shared responsibilities and the need for a more holistic approach to disaster recovery.3.) The practicality of meeting recovery point objectives (RPO) and recovery time objectives (RTO) when relying on offline or internet-based backups. This involves an in-depth analysis of current practices; measuring their actual effectiveness and whether regaining access to data and systems is possible within acceptable time and data loss thresholds.By revisiting these "old" strategies, we propose a renewed, hybrid approach to ransomware preparedness, blending traditional wisdom with modern technological capabilities. This presentation aims to equip organizations with a more holistic and resilient strategy in the face of evolving cyber threats.

View Details

While ransomware prevention is always the goal, what happens when it occurs anyways? Backups or disaster recovery solutions are not enough. Companies need an actual plan on what to do, key steps to take as well as additional options for when primary solutions do not work as expected or simply fail. Key takeaways:- Initial assessment.- Team communication.- What to expect if you do or don’t pay the ransom.- Bringing in third party help.- Recovery processViewers will also learn pivotal prevention steps such as:- Recovery points / Clusters.- Infrastructure safe guards.= Documentation.Join instructor and architect Brian Kirsch as he explores ransomware recovery plans and how they can help brace your company for impact. Because it’s not a question of if, it’s a question of how to bounce back when it does happen.About the speakerBrian Kirsch is an IT Architect and Instructor at Milwaukee Area Technical College, focusing primarily on the virtualization and cloud environments. He has been in information technology for over 25 years and has worked with VMware products for more than 15 years. Kirsch holds multiple certifications from VMware, CommVault, AWS, Brocade, Microsoft and Dell EMC, he also sat on the VMUG Board of Directors for five years helping to guide and shape the user community. Kirsch also provides a direct line of communication from customers to the VMware product architects through the VMware Customer Council and the VMware Inner Circle.

View Details

In the ever-evolving world of cybersecurity, where traditional defenses are becoming less effective against sophisticated threats such as ransomware, CISOs face the challenge of transforming security from a cost center to a business enabler. Tune into hear CEO and industry thought leader Sandra Estok teach how to equip organizations with strategies to combat rising cybersecurity threats , specifically spear phishing and QR code scams & phishing.This session will explore the latest phishing trends and how CISOs can adapt to these evolving threats. We will delve into innovative approaches that go beyond traditional security awareness, focusing on building a strong security culture and mindset where every employee is an integral part of the Cyber-Self-Defense mechanism. Key takeaways will include:- Adapting to New Threats: Understanding the shift in phishing attacks and the necessity of evolving defenses.- Cultural Mindset Shift in Cybersecurity: Moving from mere awareness to ingraining security as part of the organizational culture.- Practical Cyber-Self Defense Steps: Implementing effective, actionable measures to empower employees against cyber threats.This session is designed for CISOs, IT directors, and technical professionals aiming to equip organizations with tools and strategies to not only counteract sophisticated cyber threats but to also leverage cybersecurity as a strategic business asset fortifying defenses against the ever-changing ransomware threat landscape.About the speakerSandra Estok, MBA, GIAC-GSLC, CIPM, international bestselling author, and Founder of Way2Protect®, utilizes her 25-plus years of experience in the Cybersecurity, IT, and Data Privacy industries and her nightmare story to inspire her audience to overcome their fears of the cyber world and protect what matters most against hackers, scammers and Cybermonsters®.

View Details

Let's face it -- cyber attacks such as ransomware are becoming more common and complex. The coming twelve months will bring increasingly aggressive cybercrime activities as malicious actors continue to pivot their ransomware attacks from data encryption to data exfiltration.The question to you is this -- are you doing everything you can to protect your organization from a ransomware outbreak?Join this presentation from TD Bank's Leen Bongale to learn how to ensure your organization is prepared and ready to respond to any ransomware scenario.

View Details

Zero trust is a strategy that defines how to architect your computer network and systems to protect and defend your data from attacks. It operates by assuming that computers, user accounts, software, and applications can be compromised at any time and implements continuous assessment of device posture, user credentials, and application integrity before granting access. Zero trust is not a SKU or a single product, rather it is a more secure way to provide access to data by implementing security controls on the end point, on the network, and in the cloud to ensure only authorized users and applications can access your data. Remember, the goal is to protect the data and make sure that it remains confidential, maintains integrity, and is available when needed. Tune into this this talk from industry thought leader John Bruggeman as he reviews zero trust at a high level and discuss what solutions you can implement to take advantage of this ransomware resistant strategy. Key takeaways regarding solutions for - End point protection. - End user authentication.- Network access controls.- Cloud posture management.

View Details

Multigenerational teams are the mainstream in the workplace. In 2023, we now have five distinct generations in the workforce, encompassing many different work styles and needs. Understanding and navigating these generational differences from Boomers to Gen Z will help enable better communications, leading to more innovative ideas and solutions. Join WiCyS strategic partner Optum as Christopher Mullins, associate director, and Sebastian Berchard, project manager, shed light on embracing the value of multigenerational teams on Tuesday, December 19th at 1pm CT.Unable to attend during the scheduled time? Feel free to register and receive a recording as soon as we wrap!WiCyS can now provide members the opportunity to earn CPE/CEU credits for attending WiCyS live webinars.To earn CPE/CEU credits with the following providers, you must meet the minimum requirements:- GIAC/(ISC)2: Attend for a minimum of 45 minutes or the entirety of the webinar.- CompTIA: Attend for a minimum of 60 minutes or the entirety of the webinar. The webinar topic must relate to the certificate being renewed.Attendees who meet the requirements can email info@wicys.org to receive proof of attendance for submitting CPE or CEU credits with their provider.

View Details

As data collection and analysis become increasingly central to business, research, and governance, protecting sensitive information is more crucial than ever. This session will examine the privacy, ethical, and security challenges involved in analyzing sensitive data such as personal health records, financial information, and other confidential datasets.

Key questions to be addressed include: - How can sensitive data be ethically and responsibly analyzed while still protecting individual privacy? - What technical and policy safeguards are essential when working with sensitive data? How can risks related to re-identification, unauthorized access, and data leakage be mitigated?

This talk presented industry thought leader Donald Farmer will review best practices and frameworks for enabling secure and ethical data analysis across various industries and applications. Expert perspectives on navigating emerging regulations, managing tradeoffs, and aligning analytical objectives with privacy values will be discussed. Attendees will gain critical insights into analyzing sensitive data securely while upholding public trust and mitigating risks.

View Details

Tune into this session from industry thought leader Vincent Amanyi as he explore a 360-degree view for developing a strategy that can easily drive a zero-day attack, while maintaining an ironclad environment.

Key takeaways - Understand the moving parts of your organizational entities. - Establish a an enterprise posture that mirror’s your assets. - Develop a mechanism to manage attack evolution.

View Details

Tune into this session to hear from industry thought leader Vincent Amanyi as he provide a 360-degree view for developing a strategy that can easily drive a zero-day attack, while maintaining an ironclad environment.

Key takeaways - Understand the moving parts of your organizational entities. - Establish an enterprise posture that mirror's your assets. - Develop a mechanism to manage attack evolution.

View Details

The need for structured IR readiness process that addresses both on-premises and cloud environments is clearer than ever before. In this session, an incident responder and cloud security architect will share their personal experiences in defending against nation-state attacks. Through real-life case studies, they will cover best practices for Incident Response methodology and tools that stand the test of nation-state attacks. They will then present how this battle-tested but traditional approach to IR is challenged with the introduction of cloud computing. Finally, they are introducing a a battle-proven framework to enhance your IR capabilities in the cloud.About the speakers:Karl Ots is a cloud and cybersecurity expert, as well as international speaker and trainer, with a broad range of deep Azure expertise. He believes that secure cloud technologies are the key to successful digital transformation. He applies his passion as Head of Cloud Security at EPAM Systems. Karl has been working with Microsoft Azure since 2011 in a variety of forums ranging from large projects to speaking at largest tech conferences, such as Microsoft Ignite. Karl is a Microsoft Certified Trainer (MCT) and a Certified Information Systems Security Professional (CISSP). He is the author of Azure Security Handbook.Aviv Srour has more than a decade of Cyber Security experience. He specializes in defensive security, Incident Response (IR) and organizational information security. Currently he holds the position of Head of Cyber Innovation at EPAM.Aviv has handled hundreds of security incidents, starting back at his days at Israeli Air Force where he led the CIRT team. His hands-on experience with complex security incidents helps him develop an unique view on what is needed from IR readiness processes and how to significantly reduce detection and remediation time.

View Details

In the last 10 years, Azure has become one of the most popular cloud platforms for businesses and organizations of all sizes. As the platform has evolved, so has the threat landscape. To understand the present cloud security landscape and predict the future, let's take a trip down the memory lane!In this session, cloud security expert Karl Ots will discuss how Azure's security controls have evolved over time. Throughout the session, he will share best practices for securing your Azure infrastructure, applications, and data, so that you can build an architecture that stands the test of time.

View Details

The 24x7 threat of a data breach is making more CISOs hyper-focused on securing cloud-resident sensitive data, as this data is a prime target for malicious actors. Its presence poses a huge risk, especially for model-driven organizations with hybrid and multi-cloud environments.  Join Jack Poller (Senior Analyst at ESG), Bernard Brantley (CISO of Corelight), Rahul Gupta (Head of Security & GRC at Sigma), and Amer Deeba (CEO of Normalyze) in an interactive panel as these security leaders share insights on: • Why the security of cloud-resident data is a key concern for CISOs• How enterprises are shifting security strategy with more emphasis on protecting cloud-resident sensitive data • Selecting an effective framework for cloud data security• Top three best practices to help security teams more effective at protecting sensitive cloud data

View Details

What we are hearing from CISOs, Nick Lantuh, Co-founder & CEO of Interpres Security explains, is that cybersecurity has become too costly, complicated, siloed, and requires significant manual engineering to succeed using current methods. These issues dovetail with the competing objectives to secure your organization from large-scale attacks, while simultaneously optimizing costs in today’s budget constrained environment.A threat-centric cybersecurity approach holds the key to resolving many of these issues, in which defense surface management is key. Tune in as Lantuh and an ESG analyst deconstruct this topic in the following Fireside Chat.Additional agenda topics include:• Why defense surface management is needed in today’s security environments• Defense Surface Management concept and origins• Steps organizations can take to validate their security strategies• How continuous monitoring improves the security posture

View Details

PCI Data Security Standard is a global standard for protecting account data. The latest version PCI-DSS v4.0 was finalized last year. This new standard impacts on every organization and company in the world that accepts debit or credit card payment. In this presentation, industry thought leader Ralph Villanueva will leverage his knowledge and expertise in the PCI-DSS standards to discuss its impact on the enterprise endpoints, and provide recommendations on how to use this framework to optimize endpoint security.

View Details

Tune into this session, presented by Boleaum Inc.'s Vincent Amanyi, to learn how to implement a best practice identity access management (IAM) framework that is aligned with your zero trust policies.Attendees will learn how to:- Identify what matters in your enterprise environment. - Develop a strategy with a realistic budget. - Partner vendor's with the right solutions to your environment.

View Details

IT is increasingly costing the earth, in its greenhouse gas emissions, use of raw materials, energy and water, as well as e-waste and more. Businesses and IT leaders need to develop more sustainable ways of working to mitigate the environmental risks of IT expansion. While CSR strategies do help organisations navigate uncertainty, leaders need to understand the connection between them and other key business challenges, such as resilience, business strategy and sustainable IT. In this session, Denis Didier ,Sustainable IT Manager with ISIA will discuss how to leverage change management, collective intelligence and strong leadership to build a sustainable IT strategy that is right for your company. Join this session to explore: • The Impact of ICT in 5 figures and trends• Six steps to make ICT more environmentally friendly• Why sustainable IT can be done both efficiently & profitably

View Details

Space systems provide many critical functions to the military, federal agencies, and infrastructure networks. Space Policy Directive-5 Cybersecurity Principles for Space Systems describes the cyber threat to space systems and the need for these systems to be secure and resilient against cyber-attacks. Cyber defenses for space systems must be implemented in size, weight, and power (SWAP)-constrained, real-time operating environments that cannot tolerate increased latency and other common detrimental side-effects of cyber defenses. In this webinar, WiCyS strategic partner Sandia National Laboratories will discuss these challenges. They have been researching moving target defenses (MTD) to protect space systems against cyber-attacks. MTDs create dynamic, uncertain environments on space systems and can be used to defeat cyber threats against these systems. Furthermore, MTDs do not require the detection of an adversary to mitigate the effects of an attack.Can’t make it during the scheduled webinar? Go ahead and register to receive a recording as soon as we wrap up!

View Details

Cyber attacks are rising against critical infrastructure systems and have serious implications for our national security. In addition, many interconnected systems are becoming increasingly cyber-physical due to modernization efforts. For example, the electric grid has rapidly evolved with smart grid technologies, wide-area monitoring capabilities, and advanced automation. Therefore, it is crucial to understand the impact of multi-hazard events such as cyber-attacks and extreme weather on these cyber-physical systems.In this webinar, WiCyS strategic partner Sandia National Laboratories will discuss approaches for incorporating cyber-physical analysis in electric grid response and defense mechanisms for increased situational awareness, improved response, and resilience. This will include ongoing research and development overviews for cyber-physical anomaly detection, cyber-physical data fusion, cyber-physical mitigation deployment, and characterizing cyber-physical system interdependencies.Can’t make it during the scheduled webinar? Go ahead and register to receive a recording as soon as we wrap up!

View Details

The recent rash of ransomware attacks and evolving cyber security threats make cyber security insurance a necessity, both to protect the company and to reassure clients and investors of the safety of their data. In this presentation, Ralph Villanueva will leverage more than a decade’s IT security and compliance experience, and his intimate knowledge of cyber security insurance as a licensed agent and broker for property and casualty insurance, including cyber security insurance, to discuss how IT leadership can make their company more cyber security insurable.Tune into this webinar to learn:• Relevant information that cybersecurity insurance underwriters need.• Key areas that can affect the company’s cyber insurability.• Actions that the IT leadership can do to make the company cyber insurable.About the speaker:Ralph has been keeping his employers compliant with IT and cybersecurity requirements across numerous and diverse regulations such as the Nevada Gaming Control Board, Payment Card Industry, COSO-Integrated Framework, COBIT and ISO 27001 since 2007, and data privacy since 2017. His more than two decades of internal and IT audit and compliance work in the US and the Asia Pacific region provide him with insights not only in enforcing IT and cybersecurity requirements in light of changing regulatory and technical environments, but also in anticipating and dealing with future. Ralph has also earned numerous certifications such as the ISO 27001LA and ISO 27701LA, CISA and CISM, PCI-ISA and PCIP, CIA and CRMA, CFE, CPA and ITIL. Since 2010, Ralph has regularly spoken at over 40 conferences.

View Details

Very often threat actors and criminals will infiltrate a victim's network days or even weeks before planting malware. How can you detect threat actors before they attack? And how do you monitor your network all time? Do you have someone watching your network on the weekends or over holiday breaks? Many companies not have eyes on glass 24x7 because it’s just too expensive. For the SMB market, it is not cost effective to hire 7 to 10 people to staff your security operations center 24 hours a day, 7 days a week.What does make sense is finding a trusted partner who offers Managed Detection and Response (MDR) to watch your computer network 24 hours a day, 7 days a week. Tune into this session to learn how outsourcing MDR to a reliable managed service provider (MSP) can be beneficial for businesses with $5M in revenue to $500M in revenue. Discover how insured MSP watch your network for signs of a ransomware attack and take on that risk for you. Finally, get some rest on the holiday break knowing that your network is monitored 24 hours a day, 7 days a week.

View Details

Ransomware is a huge concern for many organizations. Ensuring resilience against these attacks requires robust measures. However, those countermeasures need to be in keeping with the organization’s overall security strategy. Zero trust began as a security model for network security but its concepts and value are now recognized as supporting the overall security posture of an organization. Many are using or deploying a zero trust security architecture throughout their security operations. Zero trust concepts can and should be used to prevent or, at a minimum mitigate, the damage caused by ransomware. This webinar will explore how companies can utilize zero trust for effective ransomware defense.Join this discussion to discover:• How ransomware operates which allows it to promulgate within an environment.• The concepts of zero trust that support ransomware resilience.• How an organization can leverage an existing zero trust architecture to specifically address ransomware.• Solutions that support zero trust mitigation of ransomware.

View Details

In this webinar, WiCyS strategic partner Cisco will discuss using Cisco Security portfolio stars: SecureX and WebEx.

During this session, Elena will show us how automation can not only reveal ways of detecting network intrusions, but also help to improve our language, see how it impacts our day-to-day work, and reveal how we can take action to help the most critical part of our company: our people.

Can’t make it during the scheduled webinar? Go ahead and register to receive a recording as soon as we wrap up!

View Details

This session will describe approaches and suggestions for potentially lowering your risk of a breach and how to prepare for when they happen. We will discuss our experiences and practical ideas for consideration to take back to your companies.

Tune in to learn more about these topics: 1. What is the definition of a breach 2. SANS Security Critical Controls – a. CIS Control 1: Inventory and Control of Enterprise Assets b. CIS Control 2: Inventory and Control of Software Assets 3. Starting with the basics 4. Access Control – Knowing your data – Identity Access Management (IAM) 5. Leveraging Threat Intelligence 6. Bonus – Have a plan, practice, table tops

View Details

The cloud landscape is complex with different threats, risks, and vulnerabilities that can overwhelm a business and its security teams. An annual report released by CSA tracks the top concerns reported by security professionals to understand how threats and breaches impact the business.

Organizations must prioritize how cloud security affects the organization, break down recent cyber attacks, and implement controls that protect the organization from future threats. Some of these tools include the Top Threats initiative complements industry tools for a richer business context. IT leaders should also compare industry perception with actual threat data in the Verizon DBIR. Another strategy is to take real-world attacks and use alternative lateral techniques from the MITRE ATT&CK framework. Finally, security leaders can implement cloud security controls with the Cloud Controls Matrix to mitigate business risk and cyber attacks.

Tune into this webinar as Cloud Security Alliance's John Yeoh shows how to use these tools and better communicate cloud security for the business.

About the speaker: With over 20 years of experience in research and technology, John Yeoh has held technical analyst, executive, and board member positions in the industry. He is also a Technical Advisory Council Member for the Federation Communications Commission, Standards Officer for the International Standardization Council, and representative on multiple industry professional consortiums. Yeoh is a published author, researcher, and technologist with areas of expertise in cybersecurity, cloud, and next generation technologies. His works and collaborations have been presented in The Wall Street Journal, Forbes, SC Magazine, USA Today, Information Week, and others.

View Details

According to Foundry, formerly IDG Communications, 92% of organizations currently host some or all of their mission critical applications and IT footprint in the cloud. But cloud environments continue to face a myriad of security threats including misconfiguration, lack of visibility, identity and unauthorized access.

In this panel discussion moderated by Clarify360's Jo Peterson, tune into hear leading experts focus on specific takeaways that you and your team can put in place to now to ensure your cloud footprint is secure for the upcoming year. - Cloud security roadmap; - Cloud security posture management; - Zero trust network access (ZTNA); - SDLC and DevSecOps within the cloud; - The need for centralized platforms; - Increased investment in intelligent security; - Increased investment in certification and cross training of your team.

View Details

Tune into this session and hear a walk-through scope on how to design a responsive playbook that will account for current threats and establish active continuum for security operations center (SOC) team.

Key takeaways: - Define the fundamentals and sync with best practice; - Simplify your messaging and facilitate with actors; - Align your business environment with postmortems.

View Details

This session provides practical advice to establish cybersecurity metrics, Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs). We begin with an explanation of the differences between them and why each are needed. Examples of how to design metrics, KPIs and KRIs are provided. Areas of focus include cybersecurity measurements for all organizations, for processes & functions and in alignment with a control framework. The end game is to measure if processes and controls are functioning as designed.

We also walk through tips for communicating new metrics and go-to-green updates for metrics in red or yellow status. The session includes 22 metrics and seven resources for many more. All of this saves time and can assist with enhancing your program.

About the speaker: Gideon Rasmussen is a Cybersecurity Management Consultant with over 20 years of experience in corporate and military organizations. Gideon has designed and led programs including Information Security (CISO), PCI - Payment Card Security, Third Party Risk Management, Application Security and Information Risk Management. Has diverse cybersecurity industry experience within banking, insurance, pharmaceuticals, DoD/USAF, state government, advertising and talent management. Gideon has authored over 30 information security articles. He is a veteran of the United States Air Force, a graduate of the FBI Citizens Academy and a recipient of the Microsoft Most Valuable Professional award. Gideon has also completed the Bataan Memorial Death March (4 occurrences). He is certified in many programs including CISSP, CRISC, CISA, CISM, CIPP, ITILv3, and NSA-IAM.

View Details

With the post-pandemic work environment taking shape, CISOs must now come to terms with permanently remote and hybrid workforces, the decline of VPNs and perimeter-based security technologies and other inalterable changes. At this “point of no return,” security leaders require an updated roadmap to effectively manage new and improved cyber threats and a user base stretched out across locations doing work with third party and non-sanctioned applications. Attackers are growing sneakier and more sophisticated in penetrating the less defined barriers of the new workforce. CISOs should rethink old strategy and risk models in order to secure their companies in this destabilized post-pandemic world.

Tune into this panel discussion including top experts in the cybersecurity sphere and discover how CISOs and other security leaders can guide their companies into a safer future. Some of the key discussion points will include:

  • Top threats predicted to strike in 2023 and how security leaders can prepare.
  • How to phase out legacy security technologies that may no longer be effective in this post-pandemic work world.
  • The biggest challenges brought forth by hybrid and remote workforces and how to address them.
  • Rethinking and re-organizing your organization’s risk model.

View Details

In today’s rapidly changing world, it’s very easy to lurch from issue to issue without stopping to pause and think strategically about where the issues are coming from and how you can prevent the next one from being a career-defining incident.

In this talk, Quentyn will take a light-hearted view of eight issues he sees frequently today; how they have developed, and how to avoid them keeping you up at night.

View Details

Recent cybersecurity incidents continue to show that public sector entities from local school districts to federal agencies are not immune to cyber threats. These range from ransomware attacks to data breaches involving sensitive student and staff data.

Tune into this webinar that will examine trends, highlight examples, and share best practices for steps to take before, during, and after a cyber incident with a focus on public agencies and officials.

View Details

Cyber attacks are not random acts that affect only a few. They are calculated ambushes that will impact you at some point -- whether you're prepared or not. Join this session as Jim Goldman discusses the state of cybersecurity, the implications of an attack, and what you can do to best mitigate your risk to protect yourself and your business.

About the speaker: Jim Goldman is the co-founder and CEO of Trava, a company created to protect small and medium-sized businesses from the potential damage of cyber threats through risk assessment, security strategy, and cyber insurance. He is a nationally published author and frequently requested speaker and subject matter expert on technical topics and security topics. Prior to founding Trava, he was a faculty scholar at Purdue University where he served as a professor and associate department head. He started a research lab serving the FBI and trust organizations for cloud computing companies that included Salesforce. And while at Salesforce he was responsible for enterprise-wide security governance, risk management, and compliance and built the company's first Security GRC organization.

View Details

What if you could predict, and thus prevent, most security incidents in your organization? While we know 82% of attacks originate from human fallibility, effective risk management requires pinpointing the riskiest users. Fortunately, recent research has revealed the 7% of the workforce responsible for the majority of incidents.

This presentation offers security professionals a new way to think about measuring user risk. Attendees will come away with: • An understanding of how user risk can be quantified with data from security tools; • Examples from leading security teams who’ve improved their organization’s cyber defense; • An approach to the different stages of user-risk management, from feedback to tailored controls; • Methods to mitigate workforce risk by applying risk-appropriate interventions; • Ways to use feedback to build trust and transparency and risk-based controls to enhance security protection; • and more!

View Details

Geopolitical instability and cybersecurity are unavoidably intertwined. Organizations of all types can be at higher risk even if they’re not connected to a conflict. Cyberattacks are a weapon sometimes wielded even against nation-states not directly involved in a conflict. Going into 2023 Russia’s war in Ukraine will bring it with cyberthreats. Other nations too, including North Korea, Russia, China and Iran, are likely to raise organizational leaders’ concerns about security.

This panel will look at the current and near-future prospects for geopolitical conflict, including • The role of cybercriminals in conflicts between nations, such as the Conti and Stormous ransomware groups’ support for Russia in the current Ukrainian conflict; • How nation-states weaponize cyber-attack skills to increase their power in the world; • Where CISOs, CEOs, and other organizational leaders should focus security investments to respond to threats issuing from global conflict. • What tools exist for companies to keep themselves from becoming “casualities” in an international conflict.

View Details

As threat vectors grow in complexity and detail, it is increasingly evident that measures like CISA’s Shields Up are necessary for today’s environment. Between cyber operations as part of the Russian invasion of Ukraine, continually high ransomware payments, gaps in the cybersecurity workforce, and the continued theft of U.S. intellectual property by foreign adversaries -- threats range from the short, medium, and long term. But really, all are tenets of national security.

With such a variety of threats to choose from, it is more important than ever to chart cyber threats and their probability. This talk will discuss the likelihood of different threat vectors, and new threat vectors that are important to monitor in 2023 – especially as they impact the sectors that face the most cyber risk in the new year.

About the speaker: Tatyana Bolton is the Policy Director for R Street’s Cybersecurity and Emerging Threats team. She crafts and oversees the public policy strategy for the department with a focus on secure and competitive markets, data security and data privacy, and diversity in cybersecurity. Most recently, Bolton worked as the senior policy director for the U.S. Cyberspace Solarium Commission focusing on U.S. government reorganization and resilience portfolios. From 2017-2020, Bolton also served at the Cybersecurity and Infrastructure Security Agency as the cyber policy lead in the Office of Strategy, Policy and Plans where she developed strategies for strengthening the cybersecurity of our nation’s critical infrastructure.

View Details

Ransomware continues to be a top security concern for cybersecurity teams, with no signs of abating in 2023. Instead, businesses must learn to live with the reality of expecting to be attacked and taking the right measures to react quickly when it happens. In this keynote presentation, ESG will present its latest findings on the prevalence of ransomware and provide best practices to help organizations make strides toward readiness, develop a plan for response, and recover quickly.

View Details

Why do we do the things we know we shouldn’t, and not do the things we know we should? Take password managers: Most of us know they’re an easy, useful tool that enhances our security, but not enough of us actually use them. What’s the reason behind this? Lisa Plaggemier, Executive Director of the National Cybersecurity Alliance, reveals new research from the Alliance about the public’s attitudes and beliefs about security, as well as potential drivers and barriers towards secure habits.

About the speaker: Lisa Plaggemier is Executive Director at the National Cybersecurity Alliance. She is a recognized thought leader in security awareness and education with a proven track record of engaging and empowering people to protect themselves, their families, and their organizations. Lisa has held leadership roles with the Ford Motor Company, CDK, InfoSec and MediaPRO, and is a frequent speaker at major events including RSA, Gartner and SANS. She is a University of Michigan graduate (Go Blue!) and while she wasn’t born in Austin, Texas, she got there as fast as she could.

View Details

No matter your workspace, you likely rely on open source code.

In this webinar WiCyS strategic partner Google will introduce the open source software ecosystem and how it underpins the security of a majority of software systems today. We’ll discuss the unique types of attacks, the challenges in preventing them, and current progress towards solutions. We’ll close by discussing some pathways for careers and opportunities in open-source security.

Can’t make it during the scheduled webinar? Go ahead and register to receive a recording as soon as we wrap up!

View Details

As cybersecurity experts, our overall goal is to protect the confidentiality, preserve the integrity, and promote the availability of data for authorized use—all without inhibiting the business from meeting its objectives. But what about the times when we must say “no” for various reasons? This interactive session focuses techniques for having a diplomatic “crucial conversation” with the business when a request just can’t be approved.

About the speaker: Tamika Bass is an Information Security professional with more than 15 years’ experience in information security, including information security governance and risk management. Tamika is passionate about improving communication and understanding of information security in the industry. Tamika is an active speaker, college professor and enjoys spending her time educating technical staff on the importance of communicating effectively in the Information Technology space. Tamika holds the following certifications: CISA, CRISC, HCISPP, CBCP.

View Details

Senior management is generally supportive of cybersecurity and lower-level staff do what they’re told to do. Middle management, however, is beset by perverse incentives to sell, sell, sell; cut costs; and do more with less. This leaves them without enough mind-space left to focus attention on cybersecurity.

Tune into this cyber-session to discover tips and ideas covering: --Finding and fixing the middle management weak spots. --The consequences of a cybersecurity culture based on inaction. --Potential solutions, tailored for middle managers, to enhance a cybersecurity culture.

About the speaker: Steve holds certification as a Master Business Continuity Professional (MBCP) as well as a Certified Information Systems Security Professional (CISSP) and a Certified Information Systems Auditor (CISA). He is a specialist in business continuity management, IT disaster recovery planning, and information security and has implemented programs for numerous banks, government agencies, and industrial corporations. Before founding Risk Masters, Steve was with Deloitte & Touche as the leader of their Business Continuity Management practice. In recent years, his focus has been on the resilience of large business and technology environments. He is editor of the multi-volume series, e-Commerce Security, and author of several of the books in the series.

View Details

Security Partners at Adobe provide product teams with guidance needed to help improve overall security posture. They partner with risk management, operational and application security teams to help product teams create unified security roadmaps and provide needed visibility for executive teams. This partnership has helped to elevate security and risk conversations into stronger business value conversations and improve overall risk management across Adobe.

Astrid Bailey, Security Partner Program Owner, will talk about her experience in building this program and scaling it using a tiered model to be effective across 200 product teams at Adobe. She will discuss lessons learned as she and her colleagues: - Worked to get security requests positioned more strategically in product roadmaps. - Made use of automation and standardization to help ensure management and executive teams are getting the information they need to make better security decisions. - Improved the overall relationships between key security team leaders and product team leaders.

The best practices learned in developing this program will be beneficial to any organization looking to strengthen and improve the effectiveness of the relationship between security and other technical teams. Such an effort can help ensure your teams are even more invested in your overall risk management strategy.

About the speaker: Astrid Bailey has been an IT project/program manager for over a decade. She has worked in numerous industries and on diverse efforts such as managing software development teams, coordinating large-scale vendor integrations to support corporate tradeshows, and, most recently, leading several key security programs at Adobe that focus on cross-org collaboration. In 2022, Astrid completed a Master of Science, Information Systems (Cybersecurity Management) at the University of Utah. Additionally, Astrid has her PMP certification and is an Associate of ISC2.

View Details

It's no secret that the cybersecurity landscape is constantly changing, requiring CISOs and security teams to adapt and pivot at a moment's notice. But the security organizations with the strongest foundations will be most able to rise to whatever challenge the future brings. In this panel session, learn about the major initiatives CISOs are planning for in the coming year, changes they are anticipating, and pain points they hope to mitigate.   You'll hear about topics such as: * Changing regulatory needs * Surviving the economic and geo-political environment * Crucial skills development areas * Technology investments * Cyber insurance

About the moderator: Deidre Diamond is the founder and CEO of CyberSN, the largest cybersecurity talent acquisition technology and services firm in the US. Deidre’s leadership style combines 25 years of experience working in technology and staffing, her love of the cybersecurity community, and a genuine enthusiasm for people. She has led large-scale sales and operations and built high-performance teams at Rapid7 and Motion Recruitment prior to founding her own organizations. Deidre has also founded SecureDiversity.org, a non-profit organization working to raise awareness for, and increase the hiring of, women and underrepresented humans in the cybersecurity workforce.

Confirmed panelists: Ozgur Danisman, VP, EMEA Sales Engineering, Forcepoint Brenna Leath, Head of Product Security, sas Dr. Kelley Misata, Founder and Chief Trailblazer, Sightline Security

View Details

In recent years, much attention has been paid to the technology that prevents malware and malicious attackers from wreaking havoc in enterprise systems, especially during the COVID era. Multi-factor authentication? Check. Robust access control? Check. Intelligent firewalls? Check.

Still, a lot of IT enterprise leaders overlook the importance of the IT compliance function in identifying COVID symptoms, especially the “people” aspect of the information technology triad of people-process-technology. In this presentation, Ralph Villanueva will speak about the vital role IT compliance plays in securing the enterprise by identifying these post COVID symptoms, and what enterprise IT leaders can do to harness their valuable expertise and unique role in the organization.

About the speaker: Ralph has been keeping his employers compliant with IT and cybersecurity requirements across numerous and diverse regulations such as the Nevada Gaming Control Board, Payment Card Industry, COSO-Integrated Framework, COBIT and ISO 27001 since 2007, and data privacy since 2017. His more than two decades of internal and IT audit and compliance work in the US and the Asia Pacific region provide him with insights not only in enforcing IT and cybersecurity requirements in light of changing regulatory and technical environments, but also in anticipating and dealing with future. Ralph has also earned numerous certifications such as the ISO 27001LA and ISO 27701LA, CISA and CISM, PCI-ISA and PCIP, CIA and CRMA, CFE, CPA and ITIL. Since 2010, Ralph has regularly spoken at over 40 conferences.

View Details

People are crucial to the success of your cybersecurity culture. With the rate of change in cyber and information Security, we need to start thinking differently about bringing our teams up to speed. This session will discuss some tips and ideas to build a more robust training and learning solution for your security team and create security champions throughout your organization. We will also explore the importance of providing career pathways to encourage growth and career advancement of your current teams and how to attract new talent.

About the speaker: Connie Matthews Reynolds is the Founder/CEO of ReynCon, LLC (REST- ReynCon Educational Services & Training). Her passion drove her to start her own company, to help companies and individuals seek to build more awareness toward soft and technical cybersecurity training and provide professional services to assist organizations in improving their security posture. A believer in the importance of giving back to the community, she is also President, Central Ohio ISSA; founding member of EmpoWE-R Women of InfoSec, named in Cybercrime Magazine's 181 Top Women in Cybersecurity to follow on Twitter and Columbus Business First's Who’s Who to Follow.

View Details

Privacy and compliance teams are under increasing pressure to respond quickly to urgent issues. Whether from senior leadership, regulators, consumers, shareholders, or other stakeholders, the pressure after a cyber or other event can be intense. Pressure is equally high to be prepared for potential incidents. What steps can a company take to have a program that is effective and right-sized to its operations? How can it best prepare for the increasing external, unknown, and uncontrollable risks? Drawing from change and risk management research, this session will share some lessons learned and strategies to help you make the most of your privacy compliance program.

About the speaker: Liisa Thomas is a partner and lead of the Privacy and Cybersecurity practice at Sheppard Mullin. Her clients rely on her ability to create clarity in a sea of confusing legal requirements and praise her “thoughtful legal analysis combined with real world practical advice.” She is the author of two well-regarded treatises: Thomas on Data Breach and Thomas on Big Data, and teaches privacy and security law classes at Northwestern University where she is the recipient of the Edward Avery Harriman Law School Lectureship. She is consistently recognized as a privacy and cybersecurity leader by Chambers, Cybersecurity Docket, Legal 500, Best Lawyers in America and Crain’s Chicago Business. She was recently named to Legal 500’s Hall of Fame for Cyber Law. Liisa received her J.D. from the University of Chicago.

View Details

The adoption of cloud applications and infrastructure combined with increasingly dispersed workers and stakeholders, a variety of devices, and a constantly evolving threat landscape requires comprehensive security planning. As organizations' technical footprints spread, points of entry and potential vulnerabilities increase exponentially. This expert panel will explore how security leaders can develop holistic programs to improve overall security hygiene and posture in a world of technical complexity.

Join us to learn about:

--The growing need for security posture platforms that address the cloud --How to manage security consistently across a variety of environments --Effective inventory and monitoring of assets and applications --The security benefits and challenges of cloud-native applications --Software and tools that help security staff offload mundane tasks --And more.

View Details

The demand for cybersecurity talent continues to grow and an increasing number of community colleges are joining the effort to address this critical workforce need. Join us for an inspiring and informative fireside chat with Ann Johnson, Microsoft Corporate Vice President - Security, Compliance, & Identity @ Microsoft - a former community college student - and WiCyS community college members to learn about their journeys and opportunities for cybersecurity career training and development through the community college pathway. 

This special event is brought to you by WiCyS, Last Mile Education Fund, and the Microsoft Cybersecurity Scholarship Program.

View Details

A proactive approach to cyber threats is imperative today in order to stay ahead of attackers, but threat detection processes are challenging for a myriad of reasons. The landscape is evolving quickly which means there are more technology vendors out there competing for the decision makers’ attention, more acronyms for security professionals to memorize, and a wider skills gap to attempt to fill – which impacts every single person on a security team.

There is no doubt that business leaders want to improve their threat detection and response systems and actions, but the market is confusing, and knowing where to lean in and focus can be overwhelming. Where is the market headed and how can security leaders realistically address threat detection and response today? Delivered by ESG analysts, this keynote presentation will examine the current state of threat detection and response, and where CDR, SOAR, SOCs, threat intelligence platforms (TIPs), and managed services fit in.

Through this presentation, you will walk away with the confidence and insights to help you determine what security tools you need to evaluate to combat threats within your organization.

View Details

Ransomware has evolved drastically in recent years where attacks have gotten bigger, more expensive, and more frequent. However, when it comes to ransomware preparedness within the organization, much remains to be done because organizations still struggle with understanding what protection technologies they should really be considering, how to create a ransomware incident response plan, and who within the organization should be involved in preparing for and recovering from an attack.

ESG surveyed IT and cybersecurity professionals involved with ransomware protection technology and processes to better understand ransomware readiness in the enterprise today and will discuss key research findings in this keynote presentation.

ESG analysts will explore from the following critical questions: • How ready are organizations to defend against, mitigate, and recover from a ransomware attack? • What ransomware readiness programs do organizations have in place? What parts of the business are involved? Have organizations rehearsed them? How do organizations know they are ready? • What types of data recovery capabilities are currently in use across the organization? How often do organizations formally test these capabilities? • Have organizations been the victims of successful ransomware attack(s), and if so, what were the impacts? How did organizations respond, and how successful were the recovery efforts? • What organizations and people are involved in ransomware cyber-resiliency programs? • Have organizations formally assessed individual risks associated with a ransomware attack on specific parts of their operation? • What third-party services do organizations currently have on retainer to assist in the event of a ransomware attack? • What business-risk management strategies do organizations have in place to address cyber-resiliency?

View Details

Tune into this webinar to learn winning strategies to understand the complex, multi-cloud environment. The University of Washington's Deveeshree Nayak will also introduce approaches to address the common threats present in the multi-cloud as well as the roles the multi-cloud serves in different industries.

Viewers will come away from this presentation with a better understanding of: - The overall view of a multi-cloud environment; - The benefits of the multi-cloud; - Approaches to address the threats associated with the multi-cloud across various industries.

View Details

Service downtime is more expensive than ever and ensuring consistent access to mission-critical applications and good end-user experience is essential for customer loyalty and employee productivity. Protecting your revenue-generating services and data from security threats and attacks that may stall the business is not a choice. A lot of newer types of attacks emerge from within the network. Businesses must implement a strategy to ensure network-centric security and observability for threat detection and mitigation.

Join Andy Idsinga, Sr. Strategic Cloud Architect at cPacket, in this informative talk to learn how to de-risk your IT infrastructure and operations.

Learn more about: • Your options to provision a network-centric security and observability practice –i.e., network detection and response (NDR) solution across all three major clouds (Azure, AWS, GCP) • What to expect in your deployment journey and gaining real-time network visibility for vs forensic data for incident response • The key questions and considerations for you and your IT teams in terms of technology and objectives

View Details

Emerging cloud leaders are seeking industry collaboration, best practices, and insights on how to tame the thorny stems of multi-cloud security. Contending with technology, talent and governance challenges, join NetApp's Jyoti Wadhwa, as she shares how leaders can deploy a proven approach to realize the promises of greater efficiency, lower cost, and real-time security of the cloud.

For fellow security practitioners and leaders, she will address both strategic and operational aspects of multi-cloud security ranging on mission critical topics of migrating an organization’s on-premise data center capabilities to developing standardized architectures and leading enterprise-wide adoption. In her discussion, Jyoti will cover 5 leadership strategies to achieve multi-cloud security:

  1. Disentangle the Tech.
  2. Unify the Cloud Team.
  3. Build your Experts.
  4. Update Security Governance.
  5. Effectively Communicate.

View Details

Based on hands-on experiences from a large number of cloud application development projects, Karl has compiled a list of top 5 key security pitfalls that are common across all application types and team sizes. In this session, he will share what these security pitfalls are, why they matter, and how to mitigate them.

About the speaker: Karl Ots is a cloud and cybersecurity expert, as well as international speaker and trainer, with a broad range of deep Azure expertise. He believes that secure cloud technologies are the key to successful digital transformation. He applies his passion as Head of Cloud Security at EPAM Systems. Karl has been working with Microsoft Azure since 2011 in a variety of forums ranging from large projects to speaking at largest tech conferences, such as Microsoft Ignite. Karl is a Microsoft Certified Trainer (MCT) and a Certified Information Systems Security Professional (CISSP). He is the author of Azure Security Handbook.

View Details

In this session, the University of Washington's Deveeshree Nayak will cover why cloud security education is so vital. Additionally, this need for awareness spans all facets of educational and working life from K12 schools, universities and businesses across all different industries.

Viewers will walk away from this presentation with a greater understanding of: 1. What is cloud security? 2. Why it is so important to understand how cloud security works? 3. How implementation and use of the cloud varies in different industries? 4. Why leaders should take the necessary time and energy to educate everyone on cloud and cloud security whether they are in schools, universities or companies.

View Details

In this session, the University of Washington's Deveeshree Nayak will cover the best practices for conducting application security in the cloud as well as the common vulnerabilities cloud-based applications face.

Attendees will come away with knowledge of: 1. What is application security in the cloud? 2. The best practices for application security in the cloud? 3. How to identify the potential vulnerabilities facing application in the cloud and preventative measure to take.

View Details

Since the birth of the Internet, it has been missing a layer of identity protocols that define identifiers for people, organizations and things separate from an application, making identity and access management more and more complicated as enterprises are moving to a multi-cloud strategy and face advancing threats from attackers.

In the presentation, Kaliya Young, widely known as the Identity Woman, is going to introduce some new and emerging Internet identity standards and technologies, e.g. W3C Verifiable Credentials, W3C Decentralized Identifiers, which can help enterprises improve application security significantly at multiple fronts: • Identity and access management across multiple cloud environments; • Workforce and customer identity and access management; • Information/data security management.

View Details

One of the most transformative recent shifts within application development in a cloud context is the rise of IaC -- infrastructure as code technologies like Terraform and CloudFormation. As organizations make more use of IaC, it's important for security organizations to pay attention. Why? Because IaC changes the risk equation -- it introduces some new potential risks, and can help close some existing ones.

This discussion aims to answer these questions: • Why/how IaC requires thinking about security of assets a new way. • Artifacts produced by IaC and how they can help us. • Security “gotchas” and things to watch out for when changing to IaC. • How you can tailor your security program in light of IaC.

Ed Moyle is currently Director of Software and Systems Security for Drake Software. In his 20 years in information security, Ed has held numerous positions including: Director of Thought Leadership and Research for ISACA, Application Security Principal for Adaptive Biotechnologies, Senior Security Strategist with Savvis, Senior Manager with CTG, and Vice President and Information Security Officer for Merrill Lynch Investment Managers. Ed is co-author of Cryptographic Libraries for Developers and Practical Cybersecurity Architecture, and a frequent contributor to the Information Security industry as author, public speaker, and analyst.

View Details

Are you interested in a cybersecurity internship but tired of completing countless applications? We understand how applying to multiple internships that often ask for the same information can be tiresome. If you experience this kind of "application burnout" and related stress from the amount of time spent applying, consider the WiCyS Internship Program! The WiCyS Internship program offers access to internships offered exclusively by WiCyS strategic partners for qualifying WiCyS members.

Join this webinar to learn more about this universal application that acts as a one-stop shop for interested students. The universal application combines a brief internship application and a simple CyberGEN.IQ cyber aptitude assessment. CyberGEN.IQ is designed to uncover innate cyber aptitude without prior knowledge of cybersecurity. Everyone who completes CyberGEN.IQ will have an opportunity to learn how to make the most of the information they receive. This insight can be valuable when assessing personal strengths and making critical decisions along the path leading to a rewarding career path in cybersecurity.

Register for this webinar on September 14th to learn more! Can't make it? Go ahead and register so you can receive a recording as soon as we wrap!

View Details

There was a time when applications were hosted on a traditional computing model. All hardware and software resided in-house. Companies maintained physical servers on-premises in a secure climate-controlled room with a secure level of access. Only Network Engineers were allowed access to application security as it mainly revolved around the network (port, FW) and OS level protection with security-level access to server rooms. But times have changed. Companies now have more to gain with a more layered approach to application security.

Tune into this presentation to hear TD Bank's Application Release Engineer Pankul Chitrav discuss the challenges faced by businesses still using the traditional model and how we can overcome these challenges by implementing a layered security model.

View Details

Become part of a global cyber sisterhood. Develop and enhance leadership skills. Cultivate the culture of inclusion on your institution's campus. Gather fellow cybersecurity students and be empowered by the strength of the community. Have exclusive access to Women in CyberSecurity (WiCyS) offerings. All of this and MORE (seed funding, scholarship opportunities, internships, etc.) by launching a WiCyS Student Chapter.

ATTENTION ALL: faculty or students at a high school, community college, college, university, or technical institution that has a cybersecurity program (small or large). Join the WiCyS Student Chapter team and chapter presidents as they rundown the top ten reasons to launch a chapter with WiCyS. This webinar will have a live Q & A to answer all questions... on the spot.

View Details

Tune into this session to hear cloud expert Dwayne Natwick provide guidance for configuring and managing hybrid and multi-cloud resources within cloud native tools for complete security posture management of your infrastructure. After configuring resources for security posture management, you will learn how to configure vulnerability scans on these resources for next level security posture management.

Key takeaways attendees will learn include: --The evolving types of infrastructure with multiple cloud providers and on-premises architectures. --Options that tools provide for multi-cloud and hybrid infrastructure security posture management. --How to manage security posture through cloud-native tools for the full infrastructure.

About the speaker: Dwayne is a Global Principal Cloud Security Technical Lead/CTO for Atos across Microsoft, AWS, and GCP. He is the thought leader determining trends, developing, advocating, and building business plans for the overall cybersecurity services for this global systems integrator. Dwayne also leads the cloud education portfolio for Microsoft and AWS. In addition to creating curriculum, training, and blog writing, he is a Microsoft MVP and a Microsoft Certified Trainer Regional Lead. Dwayne has spoken at conferences and user groups globally on cloud security, identity security, and data/AI trends. Dwayne has authored books and is a Security Professional Community Manager for Packt Publishing.

View Details

Spreading operations across more than one cloud enables organizations to choose from a variety of cloud services to cut costs, improve operations and improve scalability. However, operating complex environments across multiple platforms requires a comprehensive strategy to handle connectivity, applications, data and security.

In this panel, experts will discuss how organizations can evaluate risks in their own and their cloud service provider environments, as well as technologies and tools that can assist in achieving a comprehensive strategy.

Join us to learn about: --Understanding cloud scope across the organization --Cloud governance frameworks --Pros and cons of centralizing security access and monitoring controls --Multi-cloud management and network security analytics platforms --Cloud security posture management (CSPM) tools that can identify misconfigurations and risks --Tools for cloud compliance monitoring

Moderated by: Evgeniy Kharam, Cybersecurity Architect and Advisor, Podcaster Steve Cobb, Chief Information Security Officer, One Source Eyal Arazi, Senior Product Marketing Manager, Radware

View Details

As cloud adoption across industry verticals increases, hybrid, public, and private cloud infrastructure deployment models grow in use. In order to improve architecture and service resiliency, and to avoid vendor lock-in, one of the common cloud architecture deployment models also includes multi-cloud platforms. Whereas multi-cloud deployment does have its benefits, relying on multiple vendors and clouds increases the attack surface and overall associated risks. Additionally, multiple platforms increases complexity making security even more challenging to design, deploy and monitor.

In this webinar, we aim to highlight following key takeaways for the audience: • Managing multi-cloud security challenges; • Important security controls; • Strategy to manage compliance requirements; • Role of automation; • Logging, auditing and monitoring.

View Details

Organizations are adopting multi-cloud strategies to leverage capabilities of different cloud security providers (CSPs) and to provide flexibility to software development teams. But this brings up challenges for security teams who are responsible for managing security risk and meeting compliance regulations for workloads and applications running in different environments. In this session, ESG Senior Analyst Melinda Marks explores how to supercharge your security to gain the visibility and control you need to scale security programs for multi-cloud environments.

View Details

Market research shows that companies with DE&I (Diversity, Equity, and Inclusion) leadership out-innovate and out-perform their industry peers. WiCyS Strategic Partner, AWS, is invested in DE&I and makes it a mission to better understand what DE&I means and how we can be most impactful to our teams and customers by driving innovative and inclusive technology solutions.

This webinar will be speaking with Amazon DE&I champions. They will reflect on DE&I principles and share how they use them to drive diversity, equity and inclusion in the efforts they lead with their customers, the solutions they architect and innovate, and the peers they work with. AWS DE&I champions will also highlight the impact and success that investing in a DE&I culture has brought to the organization they represent.

Can't make it during the scheduled time? Go ahead and register so you receive a recording as soon as we wrap!

View Details

Cybersecurity has not only become a regular boardroom topic, but may soon be a requirement. If proposed SEC legislation takes hold, all publicly traded companies must have a process in place to disclose cybersecurity incidents and more importantly, must actively identify and manage cybersecurity risks with board of directors’ oversight. This legislation will likely have a trickle-down effect on many private companies as well.

While some organizations have already undergone this journey, we expect that numerous companies are late to the party and haven’t begun to determine what this change means for them. This session will help you develop a game plan to right-size security for your organization by addressing the following key issues:

• Who should fill this role? • Where to start? • The art of incident response and reporting. • What are some of the functionalities the SEC will be looking to include: o Controls to prevent unauthorized access o Monitoring o Measures to detect, mitigate, and remediate cybersecurity threats o Third-party risk management • Coordination with legal counsel and financial advisors.

View Details

At present, Insider threat issues are a significant risk to organizations. In this talk, I will cover the methods of educating employees on mitigating risks from insider threats.

Key Take-Away: • Insider Threat and Types? • Indicators of Insider Threats • Mitigation Techniques to prevent Insider Threats

View Details

Organizations face a constant barrage of cyber threats that could lead to business disruption, intellectual property theft, and reputation damage. But preventing such attacks has become increasingly challenging due to business factors like supporting the remote worker population, connecting IT to third-party partners, and developing new types of applications for digital transformation.

How can CISOs balance the need for aggressive IT initiatives for business enablement while managing and mitigating cyber risk? ESG Senior Principal Analyst and Fellow, Jon Oltsik, will discuss best practices for cyber-threat and breach prevention that can protect and support the business.

View Details

Information Security at Linkedin consists of several teams that work closely to protect the organization from adversaries. In this webinar, WiCyS strategic partner, Linkedin, will provide an exclusive look into these teams, what they do and how they all contribute to achieving their collective infosec mission.

Can't make it during the scheduled webinar? Register to receive a recorded copy.

View Details

Ransomware has plagued a wide range of organizations for several years and instead of getting better it’s getting worse. On the surface it appears the controls organizations are deploying aren’t working. But more correctly, organizations are failing to deploy the right controls. Attend this session to learn how to stop ransomware and all the *wares. You will leave this session with a manageable list of actionable steps to secure your environment and ensure your organization vaults above the cybersecurity poverty line!

About the speakers:

Jon Villanti is the Chief Information Security Officer for Allegiance Bank, a 600-employee, $7.1-billion community bank headquartered in Houston. Jon is responsible for the strategic direction and alignment of the bank’s Information Security Program. He is a former instructor for the SANS Technical Institute, teaching courses on information security, cyber warfare and hacker tactics. Lieutenant Colonel Villanti (Ret) honorably served the United States Air Force for 29 years as a member of the Intelligence Community, F-16 pilot and Cyberspace Operations Officer. Jon holds a B.S. in Business Administration from the University of Vermont and a number of cybersecurity certifications.

Andres Ruz is Chief Information Security Officer at 5 Factor Technology and has over 20 years of global experience in IT and information security. He has an MBA in MIS, a Bachelor’s in computer science and eight certificates in information technology management and information security. He is the founder of the Houston Banking Information Sharing and Analysis Organization (ISAO), where he collaborates with leaders in this sector, helping each other to better protect their companies. He is also the part of the Board of Directors and Sector Chief for the Telecommunications Cross Sector Council (CSC) of the InfraGard with the FBI.

View Details

Tune into this webinar to discover the basics of threat intelligence and how to acquire it. We will also dive into cyber maturity -- what it means and how to best measure it -- as well as the five best steps to improve cyber resiliency. Attendees will also learn the dire consequences that come with deprioritizing cybersecurity in the organization so they can ensure they don't fall victim to a breach.

Audience takeaways: • The value of threat intelligence for organizational security. • Measuring your cyber maturity. • Steps to improve your cyber resilience. • Turn threat intelligence into business intelligence.

View Details

During this exclusive fireside chat, moderated by Jo Peterson, Sonali Shah, will look to address the following topics:

  • Are unsecure applications just plain easy targets maybe even easier than email?
  • What are the top 3 application security challenges organizations face today?
  • Why web applications will continue to be a main vector for external attacks
  • With Open source continuing to grow, what can organizations do to put themselves in a better position in 2023.

View Details

The pandemic rapidly accelerated digital transformation for organizations around the world. Now that the pandemic is behind us, new risks and new threats have emerged in the wake of such rapid and uncontrolled change. This talk will cover what threats to expect for the rest of this year and early next and what can organizations do today to start to get ahead of what’s coming at them.

About the speaker:

John Bambenek is the President and Chief Forensic Examiner for Bambenek Consulting. He began his career 20 years ago at Ernst & Young as a Project Manager and Senior Consultant providing IT architecture services to top Fortune 500 Firms. He has worked in both the public and private sector providing consulting to financial services providers. He is a published author and has contributed to IT security courses and certification exams covering subjects such as penetration testing, reverse engineering malware, forensics and network security. He has participated in many incident investigations spanning the globe including the DNC breach and election-related hacking during the 2016 US Presidential campaign. He has appeared in as an expert in the New York Times, Washington Post and was once on The Daily Show with Jon Stewart.

View Details

A lot is expected of software developers these days; they are expected to be experts in everything despite very little training. Throw in the IT security team (often with little-to-no knowledge of how to build software) telling developers what to do and how to do it, and the situation becomes strained. This silo-filled, tension-laced situation, coupled with short deadlines and pressure from management, often leads to stress, anxiety and less-than-ideal reactions from developers and security people alike. This session will explain how job insecurities can be brought out by IT leadership decisions, and how this can lead to real-life vulnerabilities in software. This is not a talk about “feelings;” this is a talk about creating programs, governance and policies that ensure security throughout the entire SDLC.

No more laying blame and pointing fingers, it’s time to put our egos aside and focus on building high-quality software that is secure. Application security expert Tanya Janca will explore the cause and effect of insecurities and other behavioral influencers and present several detailed and specific solutions that can be implemented at your own place of work, immediately.

About the speaker:

Tanya Janca, also known as SheHacksPurple, is the best-selling author of Alice and Bob Learn Application Security. She is the Director of Developer Relations and Community at Bright Security, as well as the founder of We Hack Purple, an online learning community that revolves around teaching everyone to create secure software. Tanya has been coding and working in IT for over 25 years, won countless awards, and has been everywhere from public service to tech giants, writing software, leading communities, founding companies and “securing all the things.” She is an award-winning public speaker, active blogger and streamer, and has delivered hundreds of talks on six continents. She values diversity, inclusion, and kindness, which shines through in her countless initiatives.

View Details

Once considered an afterthought in software design, in today's cloud-native, app-centric world, application security must be top of mind. Widespread applications usage over distributed and public networks invites a variety of potential threats. Frequent testing and adherence to application security best practices can limit the possibility of unauthorized code being used to steal, share or modify sensitive user information.

This panel of experts will discuss the importance of a comprehensive application security program that incorporates best practices, threat identification and security testing.

Join us to learn about:

--Potential application threats --Program requirements for app security --Implementing app security standards --Using DevSecOps initiatives to improve security --Application security testing methods

Moderator: Jo Peterson VP, Cloud & Security Services at Clarify360

Panelists: Stan Lowe, CISO of Synchronoss Technologies Matt Decapua, Application Security Architect for Travel + Leisure Daniel Shugrue, Lead Product Marketer at Digital.ai

View Details

Malicious actors exploit human nature to get what they want. Technology can help, but it is not going to stop everything. Once a malicious actor is in direct communication with someone in your organization, there is little that your technology can do. This talk covers the fundamental reasons for the necessity of a security awareness program in every organization and provides a model of what it should look like.

Key takeaways include:

--The properties of a good security awareness program

--Security-aware policy

--The limits and value of technical solutions as they pertain to social engineering attacks

About the speaker: Joseph Carrigan is a Software Engineer with over 17 years of software development experience in a broad range of fields including computer and software security, microcontroller development, data migration, data integration, data warehousing and network communication. He has a B.S. (’99) in Computer and Information Science from The University of Maryland, University College and an M.S. (’08) in Computer Science from Capitol College.

View Details

Let’s take a moment to consider your Enterprise Security Program. Is it healthy and functional? Do you have the right people and processes? How are you layering security controls to be most successful? In this session we will discuss the components and management framework that result in a successful Enterprise Security Program. You can expect to learn:

How do the most successful organizations structure their security controls? What are the enterprise strongholds that attackers are actively exploiting? What are some quick wins you can perform to get C-level buy in for furthering your Security Program?

View Details

Measuring the impact of security operations in reducing risk can be incredibly difficult. This challenge is compounded when poor metrics, that do not meaningfully reflect the work done by security teams, mask systemic problems. This is something we must get right to justify ever-growing investments in defensive teams, tools, and process.

In this webinar, discover some commonly accepted security metrics that rarely tell a complete or compelling story and why they fall short. With that, attendees will learn better ways to identify high-quality metrics that tell a better (and more honest) story.

Attendees will leave the session with an understanding of: • What makes a metric useful in defense operations; • Commonly used security metrics and how they hide the truth; • An approach to picking compelling, comprehensive security metrics.

View Details

Covid has seen the SME adopt technology at a fast and furious pace -- but at what cost? With this adoption comes an increase in cybersecurity risks. Cybercriminals have acquired newer and better techniques, but their SME targets have yet to recognize the need for an Enterprise Security Management framework to establish and sustain security for critical infrastructure.

Join BCyber’s Co-Founder & CEO Karen Stephens as she unlocks the mysteries of Enterprise Security Management in 2022 for the SME. Today, through the lens of an SME, you will gain an introductory understanding of: • What Enterprise Security Management is; • Why it is important; • Practical steps on how you can start your journey.

View Details

Cyberattacks are becoming increasingly more sophisticated and, with the human element being instrumental in the large majority of breaches, educating the workforce on security red flags and best practices are critical to safeguarding an organization from attacks. What exactly is it that entices users to engage, and how does Security Awareness Training decondition employees to not fall prey?

In this webinar with WiCyS strategic partner Fortinet, we'll discuss the methods attackers use to fool their targets, the times when a user is more likely to fall for an attack, and how a Security Awareness and Training program can help create a cyber-aware culture.

Can't make it during the scheduled webinar? Go ahead and register to receive a recording as soon as we wrap up!

View Details

Threats like malware and denial-of-service attacks have been around since the earliest days of the internet, and the cybersecurity industry has created generations of threat detection and response tools to identify and remediate them. As security threats continue to evolve and advance, the tools to identify and stop them need to evolve as well.

This panel of security experts will explore how security teams can shift form using reactive to proactive measures, utilizing a host of emerging tools and technologies. Join us to learn about:

--Endpoint-focused technologies such as XDR --AI's role in reshaping threat detection --Threat detection and intelligence services --Security observability tools that improve breach detection --Using tools within a zero-trust framework to limit vulnerabilities

Panelists: Steve Cobb, CISO at One Source Communications Dave Stufflebeam, Principal Sales Engineer at Digital.ai

View Details

Threat detection has become an important consideration for entities of all sizes and verticals. What originally began as logging and security-centric alerting by point products has morphed into a multi-million dollar industry of threat detection and response solutions and services. Offerings are comprised of vendor-agnostic log collection, analytics and correlation capabilities, threat intelligence feeds, and other tools geared towards reducing mean time to detect and respond.

In this session, we’ll review the evolution of log collection and discuss the major components of today’s detection services and solutions. Viewers who are debating whether to outsource their detection and investigation needs or build their own SOC teams and manage their own solution will come away with much food for thought.

View Details

Organizations face a constant barrage of cyber threats that could lead to business disruption, intellectual property theft, and reputation damage. But preventing such attacks has become increasingly challenging due to business factors like supporting the remote worker population, connecting IT to third-party partners, and developing new types of applications for digital transformation.

How can CISOs balance the need for aggressive IT initiatives for business enablement while managing and mitigating cyber risk? ESG Senior Principal Analyst and Fellow, Jon Oltsik, will discuss best practices for cyber-threat and breach prevention that can protect and support the business.

View Details

In the IT world, the word “tool” and “platform” are sometimes used interchangeably, but they mean different things. And in cybersecurity, while it may be impossible to eliminate risks completely, using a platform approach rather than multiple point solutions can offer organizations reduced risk, improved cybersecurity, and better resilience.   This discussion will explore how taking the platform approach to cyber resilience can benefit your organization. Discover how:    * The proliferation of point solutions creates additional vulnerabilities across the IT estate * Point solutions can contribute significantly to an organization’s technical debt * A platform approach can provide convergence of real-time decision making, management, and remediation across IT, compliance, security, and risk using a single pane of glass for one shared source of truth, a unified set of controls, and a common taxonomy that brings together siloed teams from across an organization * And more

View Details

Application security is one of the most important components of an overall security program, yet some organizations struggle to identify and address their application security risks partly because they are not using the right tools to get the job done. The good news is it does not have to be that way. In this conversation, you will learn why traditional tools do not cut it when it comes to application security and why modern applications need modern application security.

You will walk away with expert insights on: * Traditional applications vs. modern applications * The evolution of application security * The emergence of the last stage of this evolution - software supply chain security * The challenges of security scanners with modern software * The future of security scanners

View Details

Software has become the heartbeat of all organizations. It is the IP of businesses today, but building software today is complex and organizations face many challenges as a result. In this conversation, Melinda Marks, principal analyst at ESG and Olivier Gaudin, CEO of SonarSource explore how developers can use Clean Code to deliver more value to the organization.

This Fireside Chat will dig into: * Core problems developers are experiencing today * Using Clean Code to help solve key challenges * Best practices for organizations building their software pipeline * And much more

View Details

The 2022 State of Email Security Report is out and makes it clear that businesses around the world find themselves in the crosshairs of a torrent of new cyberattacks. IT Security teams must evolve to better confront these challenges. In this conversation, ESG security analyst David Gruber and Mimecast’s CTO/CPO David Raissipour explore how organizations can keep pace with the changing threat landscape and more specifically, email attacks.

You will gain insights on: * The most prevalent types of email attacks that businesses need to be concerned about * Human and organizational elements that come into play in preventing email centered attacks * What organizations should focus on when it comes to tools and solutions * And more

View Details

Cybersecurity teams must move faster than attackers when vulnerabilities are disclosed. This is only possible if the attack surface is mapped out continuously. This Fireside conversation explores attack service management, tools that infosec professionals can use to manage risks before attackers discover them, and what threat intelligence indicates about the likelihood of exploitation. Register now and gain insights to help you better mitigate threats.

View Details

The rise in cloud adoption, remote work, and other digital transformation efforts are forcing organizations to adapt how they are managing network security. This is proving to be challenging considering there is no one-size-fits-all approach to network security. Tune into this panel discussion where experts will provide insights on how organizations can use emerging concepts like SASE, next-gen firewalls and zero trust to help enhance their network security strategy.

Moderated by: Melinda Marks, Senior Analyst, ESG

Featuring: Mark Guntrip, Senior Director of Cybersecurity Strategy, Menlo Security Eyal Webber-Zvik, VP, Product Marketing, Cato Networks

View Details

At present, Insider threat issues are a significant risk to organizations. In this talk, I will cover the methods of educating employees on mitigating risks from insider threats.

Key Take-Away: • Insider Threat and Types? • Indicators of Insider Threats • Mitigation Techniques to prevent Insider Threats

View Details

There are many facets to minimising the risk companies face from insider threats. In this presentation, In this talk, cyber security lead Martin Nash will present a self-styled, strategic risk-based approach to managing the insider threat. This approach is easy to break down, easy to understand and, ultimately, easy to implement.

Attendees will come away with the strategic basis for a modular approach to support ongoing and effective risk-based management of the insider threat.

View Details

The social, economic and technological shifts of the past two years prompted cyber attackers to refine their methods, becoming more sophisticated and aggressive. This resulted in the business community suffering a series of high-profile attacks with far-reaching repercussions. Threat actors continue to exploit vulnerabilities across endpoints and cloud environments, and are ramping up use of stolen identities and credentials to bypass legacy defenses.

This panel of security experts will discuss the top threats of the moment and look toward what to expect in the next 12 months. They'll provide best practices and recommendations for security measures that can offer the best level of defense.

Join us to learn about: --The most prevalent attacks today --Emerging attacks that will threaten your business tomorrow --How to take a proactive approach to threat detection --How to prepare for continued global disruption

Moderated by: Tamara Prazak, Senior Director | Appgate

Panelists: Pete Wood, Partner | Naturally Cyber LLP Seema Sewell, Assistant CISO | Office of Enterprise Technology, Maricopa County Greg Kraft, Director- EMEA | OBS Global Ian Goodhart, Director of Security Operations | Maryland Department of Information Technology (DoIT)

View Details

In this session, we will detail how to re-calibrate your CISO strategy to gain traction in your enterprise domain and change the executive perception to accelerate business.

Key Takeaways: • Establish the fundamentals. • Enable a simple message. • Harden your ecosystem.

View Details

Cybersecurity has not only become a regular boardroom topic, but may soon be a requirement. If proposed SEC legislation takes hold, all publicly traded companies must have a process in place to disclose cybersecurity incidents and more importantly, must actively identify and manage cybersecurity risks with board of directors’ oversight. This legislation will likely have a trickle-down effect on many private companies as well.

While some organizations have already undergone this journey, we expect that numerous companies are late to the party and haven’t begun to determine what this change means for them. This session will help you develop a game plan to right-size security for your organization by addressing the following key issues:

• Who should fill this role? • Where to start? • The art of incident response and reporting. • What are some of the functionalities the SEC will be looking to include: o Controls to prevent unauthorized access o Monitoring o Measures to detect, mitigate, and remediate cybersecurity threats o Third-party risk management • Coordination with legal counsel and financial advisors.

View Details

Attackers are trying everything they can to break into your environment. As a result, CISOs need to ensure that they are protecting as much of that environment as possible using people, process, intelligence, and tools and the focus should be in that order. In this discussion, we’ll look these elements and how CISOs can layer them in order to provide the most effective cyber security program.

View Details

At present, Cyberattacks are not limited to any particular industry. Academia and industries must work together to determine solutions to protect the organization from Cyberattacks. This talk will cover the hacks of Academia and Industry partnerships to address Cyberattacks and Cybersecurity skill gaps.

Key Take-Away: • Collaboration Strategies between Academia and Industry to address Cyberattacks • Mitigation Strategies to address Cybersecurity skill gaps • Strategies of community involvement to mitigate cyber attacks

View Details

At present, small businesses face greater impact from cyber attacks than larger businesses. There are many reasons for this which include insufficient implementation of cyber security programs, lack of practicing security culture, staff shortages and ineffective mitigation policies.

Tune into this talk to learn best practices around threat detection and mitigation approaches specifically for small businesses and come away with a better understanding of: - Best threat detection approaches for small businesses; - Mitigation strategies to address cyber attacks; - Resources for small businesses to create, implement and evaluate their threat and mitigation strategies.

View Details

Implementing a Security Operations Center (SOC) for the cloud can be a daunting and overwhelming task. While your SOC is trying to write use cases to detect attacks for every project your business has, how will you also monitor the cloud?

This webinar with WiCyS Strategic Partner, AWS, will talk about an approach to getting started using the MITRE ATT&CK matrix and some AWS native tools.

Can't make it during the scheduled time? No problem! Go ahead and register to receive a recording as soon as we wrap up.

View Details

Endpoint Security can either be the first or the last line of defense. From the beginning, it has primarily been accomplished by adding some type of shielding such as a simple anti-virus program but has since evolved into EDR (endpoint detection and response) and XDR (eXtended detection and response). Ensuring the endpoint is hardened against threats is the most effective mechanism to secure endpoints as the vast majority of breaches are caused by known vulnerabilities that exploit unpatched devices.

This presentation will provide information on how to create peace of mind regarding all your endpoints by increasing overall vulnerability and patch management.

Join this discussion to learn: - Why EDR, XDR, and MDR are not enough for complete endpoint security management; - Understand the overall damage caused by unpatched vulnerabilities; - How to increase overall visibility into the status and behaviors of endpoints and the value this provides to the organization; - Explore how the endpoint security solutions must include all types of endpoints including mobile and virtual; - Ensure all endpoints are up-to-date with patches, how to automate the process, and what to do when they are not; - Encourage collaboration between IT and security teams in regards to endpoint security management.

View Details

As the methods and practices used to attack digital assets become more refined, the security tools to combat the threats must evolve, shifting from reactive to proactive methods. This change means security teams must learn about and assess a slew of acronyms, including endpoint detection and response (EDR), network detection and response (NDR), managed detection and response (MDR) and extended detection. and response (XDR). They also must consider new methods for addressing and preventing alert fatigue, such as using AI or cloud-based services.

In this panel, experts discuss the types of endpoint detection and response available and how to tease out which is best for your organization.

Join us to learn: --Why EDR alone is not enough --How to inventory your endpoints and their protection needs --How to evaluate MDR options including MEDR, MNDR and MXDR --The difference between hybrid XDR and native XDR --Operational benefits of XDR --How SIEM and SOAR compare with XDR

View Details

Endpoint protection alone used to be good enough for companies. But now we have too many alerts, from too many systems along with “the Fog of More” making it more difficult to locate and address security threats.

How do you cut through all these alerts to pinpoint real threats to your environment? Can MDR or XDR actually help you focus on what is important or are these just buzzwords? In this session, we will review real world examples to see how MDR helped a small security team focus their limited time available to cut through the fog and effectively address the critical alerts and incidents in their environment.

View Details

Cybersecurity megatrends -- including zero trust, XDR, a pandemic-induced increase in remote workers, and the move to public cloud -- are influencing the way organizations think about endpoint security. These megatrends add new requirements for endpoint security, while requiring new levels of integration with other core security controls. Further influencing endpoint security strategies is the massive growth and device diversity driven by both mobile and IoT device usage.

In response, IT and security teams are thinking differently about endpoint security platforms, what they must include, and how they fit into the broader security stack. ESG Principal Analyst Dave Gruber will discuss strategies and best practices for modern endpoint security to secure this growing attack surface.

View Details

Cyberattacks against healthcare jumped 42% in 2020 and another 35% in 2021.

Successful cyberattacks disrupt healthcare operations, delay access to clinical services, and lead to significant economic loss. Stolen patient records can be used to commit fraud and identity theft, disrupting patients’ personal lives.

Medical information is an attractive target because it has high economic value on the black market.

If you are interested in protecting patients and the healthcare organizations that serve them from cybercriminals, join WiCyS Strategic Partner, Optum, to learn about the career opportunities in healthcare cybersecurity.

View Details

Join us for an informational webinar for the WiCyS Fortinet NSE 4 Certification Summer Camp

The Fortinet NSE 4 Certification Summer Camp will take 100 WiCyS members through a 10-week self-paced, instructor-supported, training program for Fortinet NSE 4 training and certification. All participating WiCyS members will also receive a free voucher to take their NSE 4 certification, either in person or through remote proctoring.

Fortinet NSE 4 certification is ideal for professionals in technical support, system security administration, and network security administration. It is also valuable to those wishing to transition into these roles. Participants will learn the knowledge and skills necessary to operate and support a next-generation firewall in order to support specific corporate security policies.

View Details

Cloud-native applications are proliferating in even the most traditional IT environments, but the ability to secure these applications and environments has fallen behind. This panel discussion will explore how to make sense of the confusion between cloud security solutions natively included in IaaS providers, Cloud Security Posture Management, and cloud workload protection, especially in light of the increased skills shortage. We will also explore the increased overlap between security and infrastructure teams during a cloud migration, why organisations struggle with continuous compliance during cloud migration.

Moderated by: Melinda Marks, Senior Analyst, ESG

Featuring: Markus Strauss, Head of Product Management, Runecast Matt Hathaway, Chief Strategy & Marketing Officer, TrueFort

View Details

The lockdown forced by Covid-19 accelerated the need for organizations to embrace the cloud. And although the cloud presents new opportunities for all organizations, it also comes with new risks, and considerations and strategies to mitigate these risks.

Infosecurity Europe is back on the ground and running! Live from the show floor, this discussion explores top challenges organizations face when moving to the cloud, best practices for security teams to help overcome those challenges, and key cloud security trends to keep on your radar.

When it comes to moving to the cloud, you can’t defend what you can’t see. Tune in right now for expert insights to help you prevent and respond to threats, and better utilize your security team to focus on the right responsibilities.

View Details

As companies move more applications and data to the cloud, problems increasingly arise. Traditional application security tools typically can't solve these problems, and often even make them worse.

False positives are all-too-common, overwhelming, and often as time-consuming as actual attacks. Join this discussion to learn why traditional security applications are not ideal for the cloud and why modern tools do a better job of preventing and minimizing bottlenecks for app developers.

Gain insights on: • How development and security teams can take advantage of technology’s opportunities and avoid being overwhelmed by its complexity • Why it’s problematic applying traditional tools in the cloud • Deploying security at scale and enabling faster development • Building security into development cycles • And more

View Details

SASE can deliver significant benefits to organizations, but like with any new technology, it’s important to do your homework before embarking on a SASE implementation journey.

Melinda Marks, Senior Analyst at ESG sat down with Mark Guntrip, Senior Director of Cybersecurity Strategy at Menlo Security and Eyal Webber-Zvik, VP of Product Marketing at Cato Networks at Infosecurity Europe to help you map out your SASE implementation with confidence.

Recorded live right from the show floor, listen to this deep dive discussion to learn:

• What organizations can realistically expect today from a SASE approach • Where to get started with SASE • How CISOs can be a champion in the organization again • SASE vs. SSE, and if SASE and zero trust go hand-and-hand • How to use emerging cloud technology to close the skills gap • And more

Moderated by: Melinda Marks, Senior Analyst, ESG

Featuring: Mark Guntrip, Senior Director of Cybersecurity Strategy, Menlo Security Eyal Webber-Zvik, VP, Product Marketing, Cato Networks

View Details

The financial and reputational costs of a data breach can have profound and lasting effects. So, it’s imperative that businesses continually assess the security of their networks and data assets. Join us for this discussion as we explore:

  • The value of threat hunting in a modern detection program
  • The role machine learning and data science play in threat detection and response automation
  • The newest cyber threats, vulnerabilities and breach detection and response insights that will help you to ensure your critical data and assets are protected

Moderated by: Melinda Marks, Senior Analyst, ESG

Featuring: Oliver Rochford, Applied Research Director, Securonix

View Details

The explosion in cloud adoption, digital transformation, and remote work – combined with a never-ending amount of phishing and ransomware attacks – are shaping the evolution of threats. But it’s difficult adapting security strategies to mitigate risks, especially given the varying skillsets that exist within an infosec team, burnout, competing priorities, and a lack of visibility into blind spots.

In this Fireside Chat, Melinda Marks, Senior Analyst at ESG, and Jason Steer, CISO at Recorded Future, explore the top security trends you should keep top of mind, how you can use threat intelligence to stay 10 steps ahead, and much more. Learn:

• How you can mitigate your risk of ransomware • What ‘good’ security needs to evolve to • Threat intelligence use cases • Questions to ask when using threat intelligence • Advice for security teams and key mistakes to avoid • Why you should rehearse your incident response plan • Cybersecurity and the Russia-Ukraine war: Why it’s best to operate from a worse-case scenario POV

View Details

Are you interested in breaking into cybersecurity, but not sure you have all the technical skills? This webinar will empower you to see that YOU have what it takes to break into the industry the non-technical way. This field needs diversity in all skills to fill the ongoing talent gaps, so join this webinar where WiCyS Strategic Partner, Sentinel One, will be sharing the non-technical side to start your Cybersecurity journey.

Can't make it on May 26? Go ahead and register to you receive a recording as soon as we wrap!

View Details

In this presentation, we will discuss broad usage of SSO and automation. Viewers will gain a deeper understanding of: • Use of automation to ease administrative tasks. • SSO best practices. • Governance in a cloud-based environment.

View Details

Addressing security, risk and compliance in higher education is like securing a small city. How can the security office stay on top of both emerging technologies and compliance needs in an environment of decentralization, openness and academic freedom?

Meeting the needs of the community and adding value in advance makes all the difference in the world. In this webinar, viewers will learn: • Princeton’s “zero to 60” moment in establishing security culture; • How a weekly gathering to assess new technologies has increased security and reduced risk to the university; • The origin, current framework, and future of this successful program.

View Details

Our cyber enemies are sophisticated and strategic with clear objectives and lots of resources. To counter their attacks, we need a pragmatic approach to threat and risk analysis to feed our cyber security ecosystem and focus on protecting our most important assets. This session aims to answer these questions: • How can we make cyber security decisions based on threats and risks if we’re not risk experts? • How can we determine who wants to access our information assets and why? • How do we discover what our valuable information assets are, and where they are located? • How do we prioritise our defences, ensuring that our resources are focused to the best effect?

View Details

Data and resource accessibility has come a long way. From private networks to enabling connectivity across the internet to outsourcing them in the cloud. One thing that hasn’t changed is the need to track who is using our resources and viewing our data. The concept of identity has remained one of the cornerstones of security. The ability to identify and control access to cloud-hosted offerings has increased the need for tight security measures that are only effective if we understand “who, what and where”.

In this session we’ll • Outline typical cloud-hosted capabilities; • Identify their user groups and roles; • Look at identity components that are applicable to cloud services; and • Introduce the concept of outsourcing Identity Management as a Service (IDaaS).

View Details

Join WiCyS Strategic Partner, AWS, as they discuss misconfiguration in the cloud, its patterns, threats, and risk to an organization/business. Looking to better understand the shared responsibility model and how we can protect our organizations? This webinar will be going through a use-case exercise and attendees will learn how we can implement the shared model.

Can’t make it to the scheduled webinar? No problem! Go ahead and register to receive a recording as soon as we wrap!

View Details

Digital transformation and the evolution of identity in the workplace -- spurred by decentralization, cloud adoption and remote work -- have exposed the fact that old methods of identity and access management have outgrown traditional security protections, posing major risks. Adaptable and agile security architectures with a spotlight on identity are a necessity to keep employees and their organizations safe.

In this panel, security experts will explore digital identity trends that bolster cloud security, as well as cybersecurity innovations that focus largely on identity, and help them understand the options.

Join us to learn about:

--Open identity standards and interoperability --Identity as a service --Cloud infrastructure entitlement management (CIEM) --Zero trust models --Cloud access security brokers (CASBs)

Moderated by: Yotam Gutman, Director of Marketing, SentinelOne

Panelists: Zain Malik, Senior Product Marketing Manager at Ping Identity Shane Moore, VP of Sales at Forcepoint Norv Leong, Head of Product Marketing at strongDM

View Details

The internet has been missing a layer of protocols addressing users’ identities. As a result, users end up losing ownership and control of their online presence to companies that create and verify identities for them. This leads to major issues, such as identity theft and fraud, and causes huge distress and loss to the users as well as severe penalties for the companies.

Recently, self-sovereign identity (SSI) has emerged, placing users at the center of their identities and data. This movement involves technologists who are building open internet protocols aligned with the SSI principles.

In this presentation, viewers will learn from Kaliya Young and Lucy Yang -- two experts at the forefront of protocol development and adoption -- about: • SSI’s emergence; • The latest developments in SSI protocols; and • Why adoption of SSI protocols is growing around the globe.

View Details

The core tenet of a zero trust strategy is least-privilege access. Yet, organizations continue to rely on user and machine identities that are susceptible to compromise, abuse and misuse, and theft. Risk is compounded by over-permissive, static access rights that provide little to no visibility into who and what is using access and how. Vaguer is how identities should be monitored and protected.

Availability of modern, cloud-managed identity services is widespread. However, organizations have been slow to pivot their security programs from traditional endpoint, network, and SecOps to an approach that focuses on identity orchestration and experiences, which is dynamic and distributed. Where there are no perimeters, a multitude of identity verification services and managed identity services exist. This research-led session will focus on how teams are responding, the identity security controls at play, and the strategies shown to be most effective.

View Details

Cyberattackers are not showing any signs of slowing down -- in fact, cyberattacks are worsening. Several factors are responsible for that with some being directly linked to the global pandemic – thanks, COVID! Infosec teams must change their security practices to address the challenges of today and the future. In this conversation among experts, you will gain insights to help you keep your organization secure in an evolving threat landscape.

Learn how can you limit the impact of future ransomware and supply chain attacks, how you can differentiate cloud security solutions, and more.

Moderated by: Melinda Marks, Senior Analyst, ESG

Featureing: Matt Hathaway, Chief Strategy & Marketing Officer, TrueFort

View Details

IT and infosec teams must think proactively and creatively about their data protection strategies, but getting there can be challenging. In this panel, cybersecurity experts delve into the trends and activities putting data at risk in the enterprise and how you can use emerging technologies to mitigate those risks. Explore key considerations for embarking on a cloud transformation journey or zero trust strategy, common mistakes organizations make as they build out their data security strategy, and more. Use these insights to help you construct a rock-solid data security strategy.

Moderated by: Jack Poller, Senior Analyst, ESG

Featuring: James Christiansen, VP and CSO Cloud Strategy, Netskope David Richardson, VP, Product Management, Lookout

View Details

When it comes to end user cybersecurity and protection, there is no better method to improve cybersecurity than to educate your staff. A well-informed workforce is one of the best tools in the fight against cybersecurity breaches. But let’s be real, how easy is this?

In this panel conversation, industry experts will share their insights on key areas that organizations should address when tackling data security and privacy.

Moderated by: Jack Poller, Senior Analyst, ESG

Featuring: Dr. Chris Pierson, Founder & CEO, Blackcloak

View Details

Most organizations would agree that the greatest cybersecurity risks would cause the most interruption to the business. But how can CISOs and infosec professionals get ahead of potential risks and prioritize those? This conversation will explore how organizations can focus on a risk-based approach to cybersecurity, cybersecurity in the boardroom, and more.

Moderated by: Doug Cahill, VP, Analyst Services, Sr. Analyst, ESG

Featuring: Jonathan Trull, CISO, Qualys

View Details

The rise in cloud adoption, remote work, and other digital transformation efforts are forcing organizations to adapt how they are managing network security. This is proving to be challenging considering there is no one-size-fits-all approach to network security.

Tune into this panel discussion where experts will provide insights on how organizations can use emerging concepts like SASE, next-gen firewalls and zero trust to help enhance their network security strategy.

Moderated by: John Grady, Senior Analyst, ESG Featuring: Nick Edwards, VP Product Management, Menlo Security

View Details

Cloud-native applications are proliferating in even the most traditional IT environments, but the ability to secure these applications and environments has fallen behind.

This fireside chat explores how security organizations can embrace cloud native by automating processes through DevSecOps, considering cloud-native application protection platforms, and more.

Moderated by: Melinda Marks, Senior Analyst, ESG

Featuring: Jonathan Nguyen-Duy. Vice President, Field CISO Team. Fortinet

View Details

Privileged access management (PAM) can be essential for organizations that are growing or have a large, complex IT system. But how do you use PAM to support a zero trust strategy? What are the collateral impacts of a poorly managed PAM strategy? This conversation among Enterprise Strategy Group cybersecurity analysts and industry leaders will explore the role of PAM in zero trust and why strong authentication is the cornerstone of zero trust.

You will learn about the latest breaches and insider threats, emerging trends, cybersecurity best practices, and more.

Moderated by: Dave Gruber, Principal Analyst, ESG

Featuring: Pierre Viljoen, Global Head of Enterprise Technology and Governance, Enterprise Studio by HCL Technologies Clayton Donley, Vice President and General Manager, Identity Management Security Division, Broadcom Software Lee Howarth, Head of Product Management, Identity and Access Management, Broadcom Software

View Details

A network that is compromised behaves differently than a network than it is not. Organizations need to shift their mindset and look for contacts with adversary infrastructure and they need to do so continuously and intentionally. This conversation with experts will explore the need to operate cybersecurity proficiently, how infosec professionals can embrace the mindset change needed to ensure they are helping the business, and more.

View Details

Your Approach to Security Operations Must Evolve

Modern SOCs play an essential role in any organization, and this goes beyond cybersecurity -- it has to do with the business entirely. This includes everything from earning trust from employees and customers to reducing impact and costs a potential breach may incur through data loss, lawsuits, or business reputation damage.

In this panel, experts discuss the tools, techniques, and skills that today’s infosec professionals need for effective security operations and management. Gain insights around what is preventing organizations from building better security detection solutions, why individual growth and certifications are important, and more.

Moderated by: Jon Oltsik, Sr. Principal Analyst, ESG Fellow

Featuring: Joel Vincent, VP, Product and Technology Marketing, Cribl Sean Donnelly, Vice President of Product Incubation, Simspace

View Details

With the huge expansion on the attack surface of an organization and the dynamic growth in the realm of Cybersecurity, employees are tempted to choose the latest and greatest product in the market to make life easier for them. While busy individuals think they are finding a solution to their problem, not assessing the associated security risks can cause more problems than it solves! What vulnerabilities are associated with this new tool? Who should have access to the data? Who should own the application? It is quite common for products from vendors to become compromised.

In this presentation, WiCyS strategic partner, Workday, will talk about how Enterprise Security establishes the relationship and collaborates with various security teams before a technology is approved.

View Details

Tune into this session to learn about the importance of identifying and protecting various types of assets within organizations and how using a multi-layered approach of implementing security solutions can reduce the risk of a potential cyber attacks and threats. Attendees will discover how threat actors locate sensitive information about their targets that can lead to compromising a company and stealing data. Furthermore, viewers will gain hands-on experience in getting started with using popular tools within the cybersecurity industry to identify security vulnerabilities on their systems and network while learning how to secure them. Lastly, viewers will explore the need for developing an incident response plan and creating a team that's well-prepared to catch any security event and handle any incidents.

Key Takeaways: - Understand the need for data protection and defense-in-depth. - Discover how organizations leak sensitive data without knowing. - Get started with identifying potential security vulnerabilities. - Explore the need for incident response planning and procedures - Build an incident response team.

View Details

Businesses are now spending $170.4 billion on information security annually, according to research from Gartner. Despite this huge investment, IBM's annual security report found that the average cost due to a data breach rose from $3.86 million in 2020 to $4.24 million in 2021, the highest in 17 years. Headlines call out the latest victims, including some of the world's biggest corporations. But how can businesses protect themselves when employees are scattered, data is exploding, and devices are proliferating?

In this expert panel, cybersecurity experts will discuss best practices for proactively protecting your organization from the most common threats, and what to do when a breach does occur.

Join us to explore:

-- Preventing breaches from external and internal threats -- Tools and techniques for detection and response -- How the speed of response to a breach can minimize its effects -- Adapting breach protection to hybrid work models -- How modern architectures such as IoT and edge affect a breach prevention strategy

Panelists include: Jeroen Hekelaar, Manager, Solutions Engineering EMEA, SonicWall Carl Leonard, Cybersecurity Strategist, Proofpoint

Sources: https://www.proofpoint.com/uk/resources/threat-reports/state-of-phish https://www.proofpoint.com/uk/resources/e-books/legacy-dlp-crumbles-in-the-cloud https://www.proofpoint.com/uk/resources/threat-reports/state-of-phish https://www.proofpoint.com/us/resources/analyst-reports/gartner-market-guide-insider-risk-management https://www.sonicwall.com/2022-cyber-threat-report/ https://www.proofpoint.com/uk/resources/white-papers/voice-of-the-ciso-report

View Details

This talk will detail how to plan your application ecosystem landscape to withstand multi-layered attack.

Key Takeaways: • Understand which tools are better aligned with your stack. • Apply best practice to develop active simulation exercise. • Review of disaster recovery as monthly initiatives. • Align your business continuity to critical assets.

View Details

Hackers will never stop their attack attempts, and organizations must be aware they could be breached any second! So tune into this presentation to discover: • How to best prepare against those attacks? • What tools to leverage? • How can your security team detect even the latest, more sophisticated foes and, most importantly, how can you respond to their attacks?

Join Dr. Erdal, corporate CISO and president of the Global CISO Forum, to learn how you can master your breach detection learning from real-life examples.

View Details

Today's security operations centers (SOCs) are inundated with an endless stream of alerts, vulnerabilities, and threat intelligence. But the reality is that no matter how large or well-resourced a security operations team, there will always be more work to do. So the next-gen SOC must be calibrated to work smarter, not harder.

In this webinar you will learn: • What are the main inefficiencies in SOC operations. • How to use technology to address the inefficiencies. • How to use people and processes to address the inefficiencies.

View Details

Data breaches increased a staggering 68% in 2021, according to Identity Theft Resource Center's annual report, affecting individuals, municipalities and nation states, businesses large and small, and public utilities and resources. Attacks involving ransomware more than doubled, and the most popular business targets were in manufacturing and utilities. Understanding these trends and anticipating how and why attackers might single out your business operations or employees is critical to mitigation.

This panel of security experts will explore the current state of cybersecurity and how to use threat intelligence and threat hunting to identify risk and avert disaster.

Join us to learn about:

-- The new breed of cyber criminals and why they attack -- The types of breaches your business should fear most -- The best sources of threat intelligence -- How threat hunting and threat modelling can help your business proactively deter attackers -- How to increase security awareness throughout the organization

Panelists include: Michael Pepin, CISSP, Sr. Security Architect, Clumio Carl Leonard, Cybersecurity Strategist, Proofpoint

Sources: Proofpoint 2022 Voice Of The CISO report https://www.proofpoint.com/uk/resources/white-papers/voice-of-the-ciso-report

Proofpoint The Human Factor 2021 https://www.proofpoint.com/uk/resources/threat-reports/human-factor

Verizon Data Breach Investigations Report 2021 https://www.verizon.com/business/resources/reports/dbir/2021/masters-guide/

View Details

The bad news? Data breaches now play a role in ransomware and extortion attacks, espionage, cyber fraud, business-email compromise, and more. The good news? As security vendors and internal security teams up their game, threat actions are converging, and threat actors now have only so many initial attack vectors to break in and do bad things.

You must simplify your prevention strategy to develop an effective means to stop data breaches, regardless of the flavor of attack. But how?

Join Nick Cavalancia to explore how you can elevate your data breach prevention strategy by viewing it through the lens of threat actor actions. Topics will include: • Start with the bad guy and work backwards to strategy. • Focus on initial attack vectors. • Translate threat actions into practical prevention strategy. • Lessons from MITRE’s ATT&CK Framework and industry trends.

View Details

Certain types of unclassified information are extremely sensitive, sought after by strategic competitors and adversaries, and often have legal safeguarding requirements. Controlled Unclassified Information (CUI) is government-created or -owned information that requires safeguards or dissemination controls consistent with laws, regulations and government policies.

Like Personal Data (PD) and Personally Identified Information (PII), CUI is highly-valued information, requiring better understanding by cybersecurity and compliance professionals.

In this presentation, we dive into the essential aspects of CUI, such as • CUI concepts and NIST standards. • The CUI registry, categories and markings. • What cybersecurity and compliance professionals must know to protect CUI.

View Details

Breaches happen by clever and well-armed cybercriminals who use many tactics, techniques, and procedures to infiltrate IT infrastructure, implant malware, and execute attacks. There is a lot at stake, so you need to know as much as possible with little or no delay to minimize adverse consequences.

Network monitoring that pipelines packets from the core network to cybersecurity analysts and analytics is the foundation of detecting and responding. Stealth is an often-used weapon, so monitoring with the highest possible fidelity is necessary to detect increasingly subtle Indicators of Attack and Indicators of Compromise.

This webinar will provide a stepwise plan for achieving faster breach detection and maximizing resilience to cyber risks by showing you how to:

• Instrument any network, physical, virtual, hybrid-cloud, for high-fidelity monitoring to losslessly acquire and reliably deliver network packet data to SOC and SecOps security analysts and the analytics and tools they use • Capture, store, and organize network packet data for use as security evidence • Forensically analyze security evidence to facilitate a rapid and effective response

View Details

As organizations are looking for ways to stay on top of an evolving threatscape, many are looking towards AI to enhance their security strategies and fend off cyber attacks before they happen. In the 2022 CIO and Technology Executive Survey by Gartner, 66% of respondents reported that they expected to increase cyber and information security investments for the next year. More than half of respondents reported that they planned to heavily invest in business intelligence and data analytics.

However some security leaders are cautious about adding artificial intelligence into their security arsenal. Despite rapid advancements in AI, these solutions can also come with their own unique set of drawbacks. Some skeptics say that AI technology is still immature and that there may be simpler, more cost-effective solutions. With all the interest surrounding AI in cybersecurity, it’s important for organisations to establish realistic expectations.

Join this panel to learn more about: - The current state of AI in security - What CISOs and their teams should keep in mind about AI - How AI impacts your workforce strategy - And more!

Speakers: - Dan Lohrmann, Field CISO at Presidio - Earl Duby, CISO at Lear Corporation - Aidan Walden, Director, Public Cloud Architecture & Engineering at Fortinet - Warsamé Ahmed, Co-Founder & CEO at BR[AI|YT.ai

View Details

Cyber threats continue to increase and are impacting almost all aspects of modern life. Ransomware, malicious domains, espionage and digital disruption are the most common attacks of recent times. Understanding how these vulnerabilities and their exploits are changing, provides helpful insights into combatting new threats. Cyber threats change over time, as do the countermeasures that best protect against them like:

• Ransomware • DDoS (distributed denial-of-service) • State-sponsored cyber actors • Social engineering and phishing threats -- increase in sophistication • Data exportation, breaches and insider threat

Key takeaways: • Leverage best practices and frameworks such as NIST & ISO 27001 to manage the threat landscape. • Prompt innovation can help protect against cyber threats. • Build cyber threats awareness and training culture to test it regularly. • Consider the source and validity of information when making decisions.

View Details

With any cyber-threat prevention strategy, organizations must know the assets connected to their networks, whether these assets are vulnerable to exploitation, and which vulnerable assets should be prioritized for remediation actions. These activities are known collectively as security hygiene and posture management. Unfortunately, organizations often manage these fundamental security best practices haphazardly, opening them up to cyber threats or the ever expanding attack surface.

In this keynote presentation, ESG Senior Principal Analyst and Fellow, Jon Oltsik, will share new research and discuss the challenges around security hygiene and posture management to explore what companies can do to both address these challenges and establish best practices.

View Details

Are you a community college educator seeking unique and creative ways to engage your cybersecurity students but need additional funds to make opportunities happen? WiCyS, in partnership with the National Cybersecurity Scholarship Foundation (NCSF), is opening up a Request for Proposals to pilot programs that include engagement with Cyber FastTrack. Tap into your creativity and mobilize your students of all genders for Cyber FastTrack activities, scholarship opportunities, and more while taking your classroom learning experiences to the next level!

NCSF will award 2-3 grants to test novel, scalable outreach strategies that have a high potential to captivate a diverse group of participants in different geographical regions. This RFP is for community college submissions only and this webinar will review the piloted program, plus answer questions along the way!

Can't make it to the webinar on May 12? Go ahead and register, so you receive a recording as soon as we wrap!

View Details

In this talk with WiCyS Strategic Partner, AWS, we will discuss cloud monitoring challenges focusing on observability, threat detection, incident response, and compliance on AWS.

Attendees will learn about multiple AWS-native logging and monitoring opportunities based on the AWS services.

View Details

Jon and Rob are discussing possible cyber attacks stemming from Russia’s invasion of Ukraine.

View Details

Major cyber-attacks are on the rise, introducing never-ending business risks. This webinar with WiCyS Strategic Partner, PayPal, will discuss how organizations could prepare for the next large-scale security incident and improve their response effectiveness. Three members of PayPal's cybersecurity team will use the response to log4j, the critical vulnerability that plagued many companies this past December, as a case study.

Can't make it to the webinar? Go ahead and register to receive a recording as soon as the webinar is complete.

View Details

Simulated Phishing programs are hard to build, easy to destroy, and labor intensive. Tune in as Ms. Epps will present lessons learned from two years of enterprise simulated phishing in the Duke Academic Medical Center including:

• Documentation, executive support, staffing, platform selection and pilot testing. • Phish template tips, entity and user engagement, phish reporting. • Safe-listing and working efficiently with your mail and security teams. • Metrics, program maturity and gamification. • How you know you’re doing it right (or wrong). • Taking it beyond phishing.

View Details

This study explores collegiate eSports student-athletes’ and administrators’ perceptions of student safety/cyberbullying within higher education while also highlighting the correlation to traditional business initiatives and the protection of employees. Specifically it outlines cyber safety, from the lens of minorities, and documents the thoughts of participants who compete, discerning the impact cyber safety has had on their lives. Tactical suggestions for increasing cyber safety and overcoming common cyber threats that may impact individuals and communities of color will also be discussed.

View Details

Let’s face it, cyberattacks such as ransomware are becoming more common and more complex. The coming 12 months will bring increasingly aggressive cybercrime activities as malicious actors continue to pivot their ransomware attacks from data encryption to data exfiltration

The question to you is this: are you doing everything you can to protect your organization from a ransomware outbreak?

Join our session to know the trends in Ransomware in 2022 and to know how to ensure you’re prepared and ready to respond to any ransomware scenario

View Details

Cybercrime has evolved rapidly, and we all need up-to-date response techniques to match. Today's adversaries are targeting suppliers, while leveraging zero-day vulnerabilities and malware-free attacks to evade detection. At the same time, remote work capabilities and the shift to the cloud have greatly increased the attack surface.

How should you respond to modern cybersecurity incidents? More importantly, how can you detect evidence of an intrusion early enough to minimize or prevent damage? In this talk, we will highlight: * New response trends and the changing threat landscape. * Supply-chain incidents such SolarWinds. * Mass zero-day exploits, such as Log4j. * Malware-free attacks and detection strategies. * Incident notification trends.

Join us and get practical strategies for adapting your incident response best practices to reflect today’s increasingly interconnected threat landscape.

View Details

Conducting forensics and incident response for containers and Kubernetes helps you better understand security breaches, meet compliance requirements and recover quickly. On average, containers live less than 5 minutes, so having a cloud native incident response plan is critical.

View Details

The rapid shift to remote and hybrid work has created unprecedented opportunities for cybercriminals to strike organizations across all industries. Companies must be proactive and understand the top threats lurking before they fall victim, costing them monetary and reputational damage. Tune into this expert panel as they explain leading cybersecurity threats facing organizations and what they can do to keep their data, employees and customers safe.

We'll discuss: - How to define and choose and incident response framework - Recent high profile cyber attacks and what we can learn from them - Latest state of ransomware and its new variants - The increase in DDoS attacks

View Details

Cybersecurity attacks are increasing in all sectors, with many of them successful. In many ways, new technology has enabled this by focusing on usability, ubiquitous access and functionality. While cloud service adoption has accelerated in response to the COVID-19 pandemic, we have outsourced many critical services to third parties while failing to properly update security controls and processes.

In this talk, we'll explore some of these new challenges are and how many of them are simply variations on old themes. We'll discuss what you can expect by way of challenges and obstacles in addressing these risks. But most importantly, we will explore what organizations, regardless of size and resources, can realistically do to both reduce the likelihood of breaches as well as responding when they do occur.

Key Takeaways • Why we are in a more precarious situation when it comes to the likelihood of successful cyber attacks and breaches. • Identify unique challenges deriving from both technology advancements and new work models. • Identify old problems reappearing in newer ways i.e. ITAM. • Formulate a high level game plan on breach prevention and how to respond to successful attacks

View Details

What do you do when a third-party vendor has a data breach and exposes your data? In this talk, discover what happened when a third-party vendor was extorted after a ransomware attack, exposing private company data.

1) Do you launch your Incident Response Plan? Do you have an IR plan? Have you tested it lately? Does it cover a third-party data breach?

2) Do you call your Cyber Insurance carrier? Do you have Cyber Insurance? Do they cover this type of incident? What does it cover?

Key takeaways: * Review your IR plan. If you don’t have one, make one. * Review your Cyber Insurance policy. What does it cover? If you don’t have cyber insurance, should you get it? * Review your Risk Registry. Do you have third-party risk identified? If so, does it have the right priority?

View Details

Securing the endpoint is riddled with new challenges as most workforces have moved off premises and face a slew of new threats. Join this panel discussion to hear leading experts and thought leaders share their insights and tips for how companies can protect themselves using both known and newer methods and technology.

We'll discuss: - Redefining the endpoint in 2022 - ZTNA and other emerging security frameworks - The challenge of BYOD devices, IoT devices in the modern workforce - Evolving strategies to protect the endpoint

Panelists include: Ateef Mulla, Regional Senior Solution Engineer & Cybersecurity Expert - SonicWall

View Details

Browsing is now an inherent part of our work and personal lives, from researching, shopping, social media, and accessing SaaS applications. Unfortunately, phishing attacks can strike when users click the wrong link. Ninety-four percent of malware is delivered via email and phishing attacks, making browser isolation an essential part of the Defense in Depth strategy to protect end users. The session will go over key points on how such technology can be used in your organization and why it should be included in your next budget as well as synergies with other products suites like SSE and frameworks such as SASE.

Takeaways: • Use cases for browser isolation. • Achieving ZTNA using browser isolation. • Where browser isolation fits in my environment. • Risks and concerns the use of browser isolation can eliminate.

View Details

Ensuring users have access to only the resources they need, aka least privilege is great. But have you considered granting users only needed access?

This talk will introduce the concept of granting ‘Just-in-Time Access’. Securing an endpoint is more than patching and vulnerability management. Granting access to who, when and what also secures an endpoint. Only when a user needs to connect to a system, can access be granted. Ports such as SSH do not need to be open for the world to connect and probe. Database credentials do not need to last forever.

This approach limits the damage that can be caused by an account -- privileged or otherwise -- by reducing the amount of time an attacker has to gain access to the account, as well as the time they have to move from a compromised account before losing access.

The short explanation for Just-in-Time Access is providing short-term access in real time. It is a relatively new term in the industry and is another way to practice the least privileged best practice.

Key Takeaways: • The benefits to Just-in-Time access for security and operations o Improved visibility o Minimize damage from compromised accounts o Operational efficiency • How SSH can be replaced with AWS SSM sessions o Direct SSH replacement o SSH reverse proxy • How Just in Time Access for database credentials can help o Example: Hashicorp Vault o Example: Akeyless • Resources for learning more

View Details

The zero trust concept has been around for over a dozen years. For a long time it was just an aspiration for companies, but over the past few years it has become a reality. According to a number of surveys, a majority of organizations are working on zero trust projects. While zero trust is primarily regarded as a network security framework, the tenets of zero trust are applicable to all elements of the cyber security stack. This presentation will discuss why and how zero trust can be implemented at the device level. Attending the webinar will provide you with:

o A deep understanding of the components of zero trust; o How a zero trust mindset fosters the development of a zero trust architecture; o The added value of including endpoints into this security framework; o The knowledge required to advocate for the incorporation of a zero trust architecture throughout the security stack.

View Details

Security teams were once able to reliably understand the users, assets, data and applications they needed to protect. Today, current operating models have put workforces and workloads in motion, forcing security architects to rethink and rearchitect modern security strategies.

As adversaries leverage sophisticated attacks that transverse both endpoints and cloud workloads, security teams require more sophisticated controls capable of working together to prevent, detect and respond to advanced threats within a highly dynamic attack surface. This research-led session will focus on how teams are responding, the end-user security controls at play, and the strategies shown to be most effective.

View Details

The Role of the Chief Information Security Officer especially in Gen-Z / Digital enterprises (companies usually born out of the cloud, not more than a decade ago, possibly experiencing a growth spurt) is evolving swiftly. While the CISO still carries the burden of expectations inherited from legacy regulations, standard compliance obligations, and customers on tenterhooks; the path to security is now paved with greater dangers of a wider threat landscape, easily accessible attack vectors, and technology that's developing faster than it can be secured. Today's CISO needs to relook at the strategy to secure this dynamic technology arena which seems to have no boundaries, no trust, and tools that are dime a dozen.

So how does the CISO do it? How does he not give in to the ultimate FUD (Fear, Uncertainty, and Doubt)? Does the solution lie in tools? people? technology?

Here's a set of simple, back-to-basics refreshers on what the CISO needs to REALLY focus on, to sustain, survive and secure the fort.

View Details

Security is at the very top of the list of priorities for corporate leaders, and for a good reason. Data breaches have never been so numerous or severe. There are many areas of digital services that need to be defended, but none are more important than the applications and data in the cloud. Although application layer defense is not always well understood, web application attacks remain the most frequent cause of confirmed breaches. As more business workflows move into third-party cloud services, corporate data is no longer contained within traditional corporate network boundaries. Applications have become the new frontier and security can be incorporated into multiple stages of the software development lifecycle to mitigate application vulnerabilities.

In this talk with WiCyS Strategic Partner, Cisco, viewers will be given an overview of the application and cloud security with topics in Software Development Lifecycle, threat modeling, secure coding practices, common application vulnerabilities, and countermeasures. Organizations must take the threat of insecure web applications seriously and take a risk-based approach to protect data in the cloud. The webinar will conclude with considerations and guidelines related to cloud security.

View Details

Your security team manages risks that affect business units and functions across your entire organization. Security is threaded through every aspect of your business, and your decisions have never mattered more. On a daily basis, you make decisions that affect day-to-day operations, data and system security, executive-level strategy and direction and quite possibly, the future success of your organization. Security leaders straddle the lines of executive, strategic, and tactical decision making, and must be experts at navigating all three of these levels. We're wearing many hats, often switching between them from meeting to meeting, and it's imperative that we can effectively communicate and drive decisions that improve and mature our security efforts across the board.

This session will explore ways to enhance engagement with technical teams, business units and executives alike, while still maturing your security program to be more efficient and effective at managing and mitigating risk. Concepts and topics covered will include:

• The 3 levels of decision making you must navigate on a daily basis and how they impact the rest of the organization • Applying meaningful metrics to demonstrate value to executives and mature program operations for optimal effectiveness Finding program gaps where remediation efforts or SLA compliance is lagging, and taking steps to help affected teams improve and succeed • An example use case from Tenable in how these aligned metrics can demonstrate tangible business value at all levels of the organization

View Details

Attending this presentation will help you ensure security is the foundation of your strategy and create a multi-cloud that increases your flexibility without making you vulnerable to cyber threats. Because, if your organization wishes to keep assets and data safe in the cloud, multi-cloud security cannot be an afterthought!

The term Multi-cloud refers to when a single organization uses more than one public cloud service provider. Multi-cloud is growing in popularity as companies continue to explore the benefits of working with more than one provider. While multi-cloud offers numerous advantages, relying on multiple vendors and clouds also increases the attack surface and overall risk. But it doesn't have to be!

In this presentation you will be introduced to multi-cloud security and the unique security challenges of this cloud computing approach. I will also speak about the best practices you can apply to design and maintain a safe multi-cloud setup.

View Details

We all know that password is the most basic and most popular approach towards securing our devices and applications. Can using passwords alone make us secure? In the current evolving cyber threat scenarios in a world where Zero-day threats are becoming the new reality, having even a strong password is not adequate. So, what are various authentication technologies available to secure our IT Infrastructure? “Passwordless Authentication” is a new buzz in this arena.

_______

Bio: Saurabh Sharma is Chief Information Security Officer (CISO) with Petronet LNG Limited. Prior to joining Petronet LNG, he worked with TCS. He has around 18 years of industry experience. His research interests include Cyber Security, Software Development, Project Management. He is a registered PRINCE2 practitioner, EC- Council Certified Security Analyst (ECSA), Certified Ethical hacker (CEH).

He received B. Tech (IT) from IP University and did MBA in IT Management from Jaipur National University. He is Chartered Engineer (CEng(I)), Fellow at Intuition of Engineers (FIE), Senior Member of IEEE, Life Member of Computer Society of India, Member of Association of Computing Machinery (ACM).

View Details

Advent of 5G is bringing internet technologies to the forefront and more prominence. Turbulent world events are being exploited more and more by hackers all around the world. Hacking is being weaponized and also being looked as a means for monetary gains. In this vulnerable world, how do you chalk out your course for making your platforms and managed services secure. This webcast will provide pragmatic strategies and approaches for this while minimizing your risk to minimum.

View Details

New strains of ransomware are leaving organizations vulnerable and show no sign of slowing down, security teams lack the ability to respond proportionately to an attack, leading to cyber disruption across the organization. This can affect all industries including manufacturing, critical infrastructure, healthcare, or any organization like yours and mine. Join this session to unpack some of 2022 most advanced ransomware threats and their behavior. Also, you can learn how to deploy Agentless Zero Trust Segmentation can fix network flaws from the core for connected OT/IT/IoT and stop lateral threat movement in every stage of the Cyber Kill Chain. If you have concerns about Zero-Day ransomware exploits or are assigned with Zero Trust initiatives, don’t miss this opportunity to learn how you can take autonomous action with 24/7 availability to stop the threat on its track.

This presentation will discuss: • Recent ransomware threat trends, including double extortion and RDP attacks in OT and ICS • How Autonomous Response takes DEFCON action to contain an emerging zero-day attack in rea time with Zero Trust policy enforcement • Fortune 500 manufacturing and ODM subcontractor case studies on how to segment IT and OT networks with Zero Trust agentless segmentation

About Airgap Networks Airgap is the only vendor that offers an agentless segmentation solution that protects your organization against ransomware threats. Airgap's "Ransomware Kill Switch" is the most potent ransomware response for the IT organization. And Airgap’s Zero Trust access controls protect enterprise’s high value assets against cyber threats. Proven and specially designed to protect Manufacturing, Healthcare, and Critical Infrastructure, Airgap Security Platform is the easiest to implement and manage. https://airgap.io

View Details

Are you ready to explore how threat actors think, leverage threat intelligence, and gain experience working within different roles of a cyber defense team?

Join the WiCyS Cyber Defense Challenge made possible by Target. This webinar will introduce this unique challenge that tackles simulated intel-driven scenarios to understand the threat actors behind malicious behaviors.

The multi-tiered program will give WiCyS members a plethora of cyber defense savviness while providing opportunities to win prizes, swag, and WiCyS 2023 conference scholarships!

Join the Target team on March 30, as they review the Cyber Defense Challenge and host a live Q & A.

View Details

Join WiCyS Strategic Partner, SentinelOne, to learn just how important curiosity is to creating a world that is gender-equal. During this webinar, you will not only learn about this curiosity through an interactive discussion but also walk away with tangible next steps you can implement to foster it and use it to advance others around you. #BreakTheBias

Can't make it during the scheduled time? No problem! go ahead and register to receive a recording as soon as we wrap!

View Details

Attending this presentation will help you ensure security is the foundation of your strategy and create a multi-cloud that increases your flexibility without making you vulnerable to cyber threats. Because, if your organization wishes to keep assets and data safe in the cloud, multi-cloud security cannot be an afterthought!

The term Multi-cloud refers to when a single organization uses more than one public cloud service provider. Multi-cloud is growing in popularity as companies continue to explore the benefits of working with more than one provider. While multi-cloud offers numerous advantages, relying on multiple vendors and clouds also increases the attack surface and overall risk. But it doesn't have to be!

In this presentation you will be introduced to multi-cloud security and the unique security challenges of this cloud computing approach. I will also speak about the best practices you can apply to design and maintain a safe multi-cloud setup.

View Details

Considering how much—and frequently—security shifts in the customer landscape, we believe Identity Management is at the epicenter of digital transformation and the next generation of enterprise IT. The changes in identity systems and services over the next five years are expected to be as disruptive as the new business models, applications and ecosystems they are supporting.

In our presentation we will look ahead to the future of identity & access management, talk about specific projections as to where we believe Identity Management will be going over the next five years and describe a model for identity abstraction that provides an extensible services oriented architecture. We include newer disruptive models such as DevOps/microservices in identity systems, cloud-based IAM, self-sovereign identity leveraging blockchain, IoT support, evolving privacy regulations, and new governance and provisioning models.

View Details

Cloud Security Operations teams have a multitude of responsibilities, including vulnerability management, threat management, security and infrastructure configuration and management, as well as incident response. Clearly, they need modern tools to help them manage and make sense of the volume of data and work across their complex environments. However, the fractured and disconnect enterprise security ecosystem makes this difficult or impossible in most environments.

Zero Trust security brings with it the possibility of applying a holistic and unified policy model across these heterogeneous environments. Zero Trust has become mainstream, even being mandated by the recent US Presidential executive statement ordering such an approach for US government agencies. So, how does Zero Trust apply to cloud SecOps environments?

In this fireside chat, two industry experts share their thoughts and insights on this topic. Attendees will learn:

• What is Zero Trust, and how does it apply to Cloud SecOps? • Why automation is critical to a successful Zero Trust program, and even more important for Cloud SecOps • Why Zero Trust policies are so important in cloud environments • Ways in which workload metadata and user attributes are used in Zero Trust policies • How organizations can implement “security as code” with a Zero Trust approach

View Details

Cloud adoption has witnessed exponential growth over the past few years. It provides many advantages for both individuals and organizations.

However, at the same time, many new cyber security risks have arisen due to this rapid growth of cloud adoption. These new security risks can be mitigated by adhering to cloud adoption good practices. One of those steps is monitoring the cloud entities once the workloads have been deployed. Unfortunately, this is perhaps the most overlooked aspect of cloud security, thus enabling Threat Actors to launch Cyber Attacks against deployed workloads.

In this presentation we will discuss:

• Importance of monitoring your cloud entities • How cloud monitoring helps with threat detection • Steps to keep cloud entities safe

View Details

John Christly, VP and CISO at Core Business Solutions joins BrightTalk to discuss some best practices as it relates to protecting your systems and data in the cloud. As more and more companies seek to migrate to the cloud and as data breaches and issues such as ransomware continue to create havoc for companies, the need to protect these systems becomes a major issue that needs careful consideration.

This session will explore solutions to this challenge and offer some best practices that should be deployed to give you, your company, and your customers better piece of mind.

View Details

Data breaches, misconfiguration and inadequate change control, a lack of cloud security architecture and strategy, and insufficient identity and access management were among the biggest security challenges in 2021 for all industries operating in the cloud.

These issues are not unique to any particular industry, but fortunately, they have common solutions. In this panel discussion, we’ll discuss the importance of cloud controls, as well as:

  • What the C Suite needs to know about Cloud Security
  • Why Cloud Security is not an IT problem, it’s a business problem
  • The importance of building a cloud security architecture and strategy
  • Why managing sufficient identity, credential, access, and key policies

Moderated by: Michelle Drolet, CEO, Towerwall

Participants include: Antonio Sanchez, Technical Lead, Product Marketing, Alert Logic Justin Crowley, Principal Sales Enablement Manager, Forcepoint Dor Dali, Director of Information Security, Vulcan Cyber

View Details

According to Statista, a global market and consumer data provider, between 2021 and 2023, the percentage of organizations adopting a multi-cloud strategy will grow for midsize companies from 76% to 84%, and for large enterprises from 90% to 94%.

Cloud providers offer many security monitoring and threat detection options, but what if you subscribe to more than one? Adopting security monitoring tools from each provider can increase complexity and bring significant overhead to security operations teams.

For years, security information and Event Management (SIEM) solutions have been collecting and consolidating data from multiple sources for centralized threat detection. Still, multi-cloud brings a new scenario with different data sources, higher volumes, and unknown threats. How does SIEM have to evolve to adapt to this new reality?

Join Augusto Barros, VP of Solutions and Cybersecurity evangelist, and Brian Robertson, Senior Product Marketing Manager at Securonix, to learn about:

· Why is it hard to perform security monitoring in a multi-cloud scenario? · What are the limitations of traditional SIEMs to support multi-cloud needs? · What do you need to look for in a new approach and architecture that enables the SIEM to be the right solution to detect threats in a multi-cloud world?

Speakers: Augusto Barros was most recently the Research VP in the Gartner for Technical Professionals (GTP) Security and Risk Management group. He has over 20 years of experience in the IT security industry as an analyst and a security architect and officer for large enterprises.

Brian Robertson has over 20 years of experience helping organizations solve critical application delivery, network, cloud, and security challenges working with industry leaders who not only are looking at the challenges of today but are looking at the horizon for the challenges of tomorrow.

View Details

As organizations move to the cloud to reach new heights of productivity and to better serve customers, their security infrastructure is under pressure to reduce risk. Companies face the challenge of securing an ever-changing attack surface across multiple cloud-native applications components including APIs, containers, VMs, serverless functions and open source software. As development teams grow and achieve faster release cycles, companies must scale security with the volume of releases while teams are vastly outnumbered.

Learn more about key trends and best practices to face the current challenges and manage cloud-security risk in this keynote session.

View Details

Interested in the career journey of women in data science? On March 3, join four women from WiCyS' Strategic Partner, Bloomberg, to learn what it took for them to land a job in the industry and their keys to career success.

Can’t make it on March 3? Go ahead and register, so you can receive a recording as soon as we wrap!

View Details

Rapid response is essential to mitigate cybersecurity threats. However, using standalone SIEM and SOAR solutions from different vendors adds unnecessary complexity. In a SOC, where every second counts, a simple, unified UI allows security analysts to speed up detection and response and mitigate threats.

Join Augusto Barros, VP Cybersecurity Evangelist, and Rahul Bakshi, Senior VP of Product Management, for a live discussion on how Securonix's SOAR solution brings security operations into a single pane of glass for end-to-end incident life cycle management. In this session, you will learn:

  • Trends in the SIEM and SOAR markets from the experts
  • How to apply automation effectively to drive SOC efficiency
  • How to simplify security operations and drive down MTTR
  • How to avoid common traps on SOAR implementation

Augusto Barros was most recently the Research VP in the Gartner for Technical Professionals (GTP) Security and Risk Management group. He has over 20 years of experience in the IT security industry as an analyst and a security architect and officer for large enterprises.

Rahul Bakshi is responsible for driving and managing product strategy. Before Securonix, he has twenty years of experience leading high-performing teams across Product, Marketing, and Sales in the SaaS and Security industries.

View Details

According to Identity Theft Resource Center (ITRC) research, the total number of breaches in 2020 have been exceeded by October 2021 - an increase of 17%, with 1,291 breaches in 2021 compared to 1,108 breaches in 2020.

How has remote working impacted your organization's security posture? What lessons can security professionals learn from the recent wave of breaches and what steps can enterprises take to strengthen security in 2022?

This keynote panel of security experts and industry leaders will explore the best practices for breach prevention, as well as share real-life lessons from the frontlines on what works and doesn't work.

Viewers will learn more about: - The reality of data breaches - Why data breach severity is rising - Ransomware attacks and the ongoing threat to businesses - Technologies that help with breach prevention, detection and response - Why security awareness matters and best practices for educating employees to be cyber secure

Moderated by: Jeremy Snyder, Managing Director, Entiviti

Panelists: Willy Leichter, CMO, LogicHub Mike Parkin, Engineer, VulcanCyber Julie Davila, Sr Dir of AppSec, Sophos

View Details

Preventing data breaches has become a key area of focus for most security programs, driven by the news of ever increasing ransomware attacks, intellectual property loss and insider threats. Having a strong Incident Response program is crucial when a data breach occurs, but more and more, we need to get ahead of these attacks and lay strong foundations that can help prevent data breaches before they occur. And beyond that, with that foundation in place, what if we can also look ahead and actually predict which areas of our network environment are most likely to be attacked? It's at this stage where defenders can start to get ahead of the curve, make sound decisions around how to prevent or mitigate risks, reduce the likelihood that these vulnerabilities are exploited and help keep their organization out of the news.

In this talk, we'll discuss: • Fundamental strategies and best practices for shoring up the areas of your environment most often targeted by cyberattackers • How a culture of preparedness can be your strongest line of defense against data breaches • Leveraging threat intelligence sources to predict where attackers may target you next • Ways to prioritize your risk mitigation efforts to quickly and efficiently address weaknesses in the environment

View Details

The route to cybersecurity careers can feel very confusing and unclear. Cyber FastTrack will help rid you of some career trajectory confusion, streamlining your focus and efforts while embracing the power of the WiCyS community along the way! This WiCyS Cyber FastTrack Cohort experience will allow you to learn through CyberStart gamified challenges, network, develop friendships, and advance through scholarship opportunities - all designed to help launch YOU into your cybersecurity career.

View Details

We live in an era where most of our activities are happening online - from working to shopping to learning. This hasn't been unnoticed by cybercriminals, who try to overtake any obstacles and achieve their goals (steal confidential information, deploy ransomware, etc).

Since most businesses have an online presence, it's a common goal for every security team to ensure that company assets remain safe at all times. In order to achieve that, multiple steps have to be taken across all organisational departments which will create a multilayered defence against attacks from adversaries.

This webinar presents a breakdown of common best practices that will help every organisation define, implement and improve their culture, processes and toolsets to prevent future breaches.

View Details

August 2021: Accenture confirmed that Lockbit ransomware operators stole 6 TBs of data from its systems. October 2021: Acer announced that their servers were hacked by Desorden group resulting in exfiltration of almost 60 GBs of data. August 2021: T-mobile said that it fell prey to a sophisticated cyberattack affecting its 40 million customers.

These are examples of some data breaches that happened in 2021. Since last few years, number of data breaches & their impact has been growing, and the trend continued in 2021 as well. The average cost of data breaches in 2021, a whopping $4.24 Million, broke the previous ceiling!

With every passing year, attackers are becoming bolder in their techniques and are targeting organizations with increasingly sophisticated cyber-attacks. Which makes it imperative for organizations to regularly review their cyber security posture and update it to foil the next wave of attacks.

In this presentation, we will share current state of cyber-attacks and discuss the new generation protection mechanisms that can assist organizations in thwarting these attacks.

Some of the key takeaways from this session will be: 1. Why Breach prevention is needed. 2. Attack techniques used in latest data breaches. 3. Different tools/techniques to safeguard against the new age cyber-attacks.

View Details

While the cyber challenges we face today are unprecedented, AI remains one of the best tools we have to confront our present and future cyber threats. In order to ensure our AI systems and the technology that uses our AI are developed responsibly, and in ways that warrant people’s trust, the future of cybersecurity truly depends on investing in diverse cybersecurity teams. Join this webinar with WiCyS Strategic Partner, Microsoft, as they share how we can ensure greater diversity of teams and data as we move closer to future-proofing against biases in tech.

View Details

WiCyS Strategic Partner, Dell, is helping you unlock Ransomware with this webinar on February 3rd. Join us to highlight Ransomware attacks, the hacker groups, and our best bet for the last line of defense.

Can't make it at the scheduled time? No worries! Go ahead and register so you receive a recording as soon as the webinar wraps!

View Details

Mentorship is the catalyst for career advancement. It cultivates a space for cybersecurity students and professionals to make progress in their careers, as mentees, and for mentors to gain long-lasting leadership skills in which allyship and equity shine. Mentoring programs are where crucial conversations are facilitated and personal/professional growth is achieved. This webinar will review the WiCyS mentor/mentee program, what inclusive mentoring is all about, and the WiCyS-integrated CyberGEN.IQ assessment. This unique assessment uncovers mentees’ natural cognitive strengths in cybersecurity, aligning with their career aspirations as they make long-lasting career choices.

View Details

UBA has become a valuable tool for threat detection, but behavior analytics can be used on more than just users. Find out how behavior analytics can be used across your entire stack to help improve threat detection and mitigation.

View Details

Regulations mean well and serve a higher purpose but often lead to overhead costs, complexity, and time-consuming management for any organization. In addition, the difficulty in understanding a regulation, let alone multiple compliance rules, can set your team up for failure before you even start. Meeting compliance requirements often requires cross-collaboration between various groups to achieve a common goal.

So the question is, can we overcome compliance and risk management challenges with automation? What are the pros and cons of automating Governance, Risk Management, and Compliance (GRC) processes?

This presentation will address various techniques available to manage regulatory concerns at scale. You will learn how automating Cybersecurity Risk Management and Compliance can potentially eliminate repetitive procedures, risk of human error, and misinterpretation of regulations. We’ll discuss how automation tools can create a cohesive workflow to achieve efficiency, cut the expense and time to audit from months to weeks. And most importantly, how to do it right to achieve successful outcomes.

View Details

Are you currently in a different field or at an early stage of your career and trying to break into the cybersecurity industry?

Curious about what courses/ certifications you should take or what’s the best way to get started?

Join this panel discussion with WiCyS strategic partner, the LinkedIn Information Security team, as panelists share their own career journey transitions into security, what they’ve learned along the way, and what they value most about candidates.

View Details

According to Gartner, By 2023, 30% of CISOs will be measured on their ability to create value for the business. Part of the value will come in the form of risk management and reduction as well as the ability to communicate that value to key organizational stakeholders.

Organizations across the globe will be navigating new government regulations fast-tracked for cybersecurity standards, the growth of supply chain complexity and associated vulnerabilities, and the scarcity in the cybersecurity talent pool, to name a few of the challenges.

It will become more important than ever that security and IT are aligned with business objectives

In this session, the discussion will focus on the current enterprise security landscape and a discuss ways for IT leadership to proactively mitigate some of the best practices to mitigate and circumvent those risks.

Moderated by: Jo Peterson, VP, Cloud & Security Services, Clarify360

Panelists: Richard Rushing, CISO, Motorola Mobility Jack Roehrig, CSO, BookNook Ken Lawrence, VP Technology Services & Information Security, Partners Federal Credit Union Stan Lowe, vCISO and former CISO, Zscaler

View Details

Data breaches are increasingly on the rise; cyber attacks continue to evolve in sophistication, businesses must remain vigilant and informed and arm themselves with the right tools and strategies to defend themselves when the inevitable happens.

Join this roundtable discussion with security experts to learn more about:

  • Trends in cyber attacks and breaches and what's at risk
  • Prevention best practices
  • Solution recommendations for breach detection and response
  • Key factors for CISO success
  • What's on the horizon for 2022

Moderated by: Michelle Drolet, CEO, Towerwall Panelists: Dan Schaipa, Chief Product Officer, Arctic Wolf Andrew Rose, Resident CISO, EMEA, Proofpoint David Masson, Director of Enterprise Security, Darktrace

View Details

Join WiCyS Strategic Partner, Champlain College Online's Chair of Cybersecurity, Kathleen Hyde, along with Paul Ericksen, Executive Recruiter for ATT, for a live discussion about the College's 2021 national survey, "The Cybersecurity Skills Gap & Barriers to Entry." The survey findings revealed high expectations of past training, lack of diversity and inclusion, and toxic work environments/culture in the field of cybersecurity all contribute to the industry's current skills gap and prevent new workers from entering the field. This live discussion about the current and future landscape of the cyber sector will be followed by a Q&A session.

Can't make it to the session? No problem!

Go ahead and register so you receive a recording as soon as we wrap.

View Details

According to IDG, 92% of organizations currently host their IT environment in the cloud As we approach 2022, some of the most talked about cloud security trends are Cloud Security Posture Management, Zero Trust, SDLC and DevSecOps within the cloud, the need for centralized platforms, and Increased investment in intelligent security. All of these topics factor into a multi cloud compliance strategy.

Moderated by: Jo Peterson, Vice President, Cloud and Security Services, Clarify360

Panelists include: Álvaro R González, AVP Channel Sales and Alliances, Tierpoint Jen Shute Benson, Sr Director Cloud, DevOps and Security, Slalom Tyler Cohen Wood, CISSP and CEO, My Connected Health Luke Babarinde, Principal Architect, Imperva

View Details

AI systems are catalysts for the digital transformation and allow for efficiency gains in enterprises. But they come with a risk and are obvious targets for external attackers. In this presentation, you learn:

• How can you identify and manage your organization’s security risk related to AI? • How can you protect your organization against the most relevant threats? • What should you consider when your AI environment is in the public cloud?

View Details

Technical skills aren’t the only thing you need to get ahead in tech. Join this webinar with WiCyS Strategic Partner, Facebook, as they provide attendees with practical communication tools and soft skills to increase individual impact and complement rockstar technical prowess.

View Details

Just as enterprise organizations are embracing cloud computing, so too are cyber attackers and everyone is justifiably concerned. For all the advantages of the cloud, the framework is not impervious to cyber threats and so security protocols must always be a priority. Yet the myth that cloud is less secure than owned, on-premise security is just that: a myth. A 2020 Gartner forecast stated IaaS workloads would experience 60% fewer security incidents than traditional data centers — at least.

In order to comprehensively deploy a cloud security network, companies must understand the realities of their infrastructures. Identifying the responsibility of the cloud and that of the customer is critical, as is learning what services can be reasonably expected from a leading cloud provider. Only with the right facts can you build a truly secure network.

Join this panel of experts as they discuss the most common myths of cloud security and what you should actually be building your strategy around:

  • Cloud vs. On-Premise Security: Which is easier to target?
  • Is a public cloud more vulnerable than a private one?
  • How automated can — and should — the cloud’s security protocol be?
  • Accessibility: How much is too much?

Moderated by: Michelle Drolet, CEO, Towerwall

Panelists to include: Jessica Charter, EMEA Security Principal, Trustwave Taylor Smith, Senior Product Marketing Manager, Prisma Cloud, Palo Alto Networks Rajesh Agnihotri, Senior Solutions Engineer, Middle East, SonicWall Scott Fanning, Senior Director, Cloud Security, CrowdStrike

View Details

Cloud-native application security involves balancing contradictory requirements: the benefits of cloud services in accelerating development, while at the same time handling security in an adverse environment where there are more attack surfaces and opportunities for data breaches. Today, tools exist that focus specifically on the security and vulnerability posture of cloud workloads. Container and configuration vulnerabilities are identified, and enforcement policies are enacted to protect the workloads if these are operating with such vulnerabilities.

Unfortunately, many security tools do not address the vulnerabilities of APIs. Cloud-native applications expose many internal API services and developers are increasingly using external API services for their applications. Both internal and external API use expose the workload to new vulnerabilities; more strongly, workload security and API security are really two sides to the same coin. This talk specifically focusses on the security problems and vulnerabilities exposed through APIs. Questions we address include:

• What does a developer know about a service before using it? • Does a poorly defined interface expose API service vulnerabilities? • Does the service perform well to begin with? • How does the developer get/maintain an access token? • Do API specs show critical use cases and dependencies? • Can the security impact of an external API service be estimated and managed? • Do the APIs violate the OWASP API top 10? • How can we test against the OWASP API top 10? • Can PII be shared with such services?

We show how SecureCN addresses both sides of the security coin: container workload and API security in one tool, and we present actual issues with a live demonstration of SecureCN.

View Details

According to Verizon's Data Breach Investigations Report, 24% of breaches involve cloud assets. Many of the benefits that cloud services deliver to organizations, such as elastic scalability, and remote accessibility, act as a double-edged sword if abused. Compromised accounts, for example, can be misused, stolen admin credentials or elevated admin privileges can ultimately lead to sabotage, data loss, and exfiltration.

A Forrester study shows that 25% of breaches resulted from internal incidents, and almost half of those were categorized as malicious. Insider threats have evolved, and organizations have more to consider than data leaving the organizations and privileged users.

Join Oliver Rochford, Senior Director, Cybersecurity Evangelist, and Kayzad Vanskuiwalla, Director of Threat Hunting & Intelligence at Securonix, for this talk on risk-based threat monitoring in cloud environments to learn about:

• The need for monitoring threats in the cloud. • How the insider threat is growing as a critical aspect to monitor. • How cloud controls can be abused, using AWS as an example. • Which real-world attacks exploited cloud controls. • How to detect cloud control misuse with UEBA, machine learning, and threat hunting. • What a cloud threat model could look like.

Kayzad partners with our engineering, data science teams, and Fortune 500 customers to continuously assess and evolve our threat-detection, orchestration, and response capabilities. He brings in-depth practical experience researching cloud attack patterns and exploits to build playbooks and automate threat detection.

Oliver has worked in cybersecurity for over twenty years, including as a penetration tester, consultant, researcher, and writer for Securityweek, CSO Online, and Dark Reading. As a Gartner industry analyst, he co-named the SOAR market and worked on the SIEM Magic Quadrant. At Securonix, he works with our users on security operations and threat management topics.

View Details

“Cybercriminals don’t hack in anymore; they log in.”

In today’s data breach reality, 85% of incidents involve the human element and 61% of phishing attacks utilize compromised credentials. The threat landscape and attackers’ methodologies continue to evolve dramatically, and organizations urgently need to examine their email security defenses to remain secure.

Join this session with Egress CEO Tony Pepper and VP of Threat Intelligence Jack Chapman to learn more about:

• The evolving phishing threats targeting Microsoft 365 users • How to equip employees to act as a resilient line of defense against phishing using real-time teachable moments • How to effectively assess and manage your email security posture to remain protected, covering Microsoft anti-phishing solutions, ICES technologies and secure email gateways

View Details

The life of a cybersecurity incident responder is challenging and rewarding – but managing it at the beginning of your career can be a little overwhelming at times. Please join the Director of the Microsoft Detection and Response Team (DART), Elda Tan Seng, and Senior Cybersecurity Consultant, Kate Livingston, to learn about the exciting and fast-paced world of incident response and threat hunting at Microsoft and what it’s like to be an incident responder at the beginning of your career.

View Details

Join us on November 18th to learn how to avoid sophisticated targeted attacks that could cripple your business and inflict physical damage to your critical infrastructure. Using real-world examples of well-known organizations who have felt the significant business impacts from a cyberattack, this webinar will teach you:

When to treat cyber threat as part of your overall enterprise risk strategy. Which cybersecurity framework best suits your organization. How to develop a cybersecurity training and education plan.

View Details

As organizations face several different challenges in 2022 and beyond, preparing for a cyber attack is as important as ever. Businesses face a myriad of cyber threats; from phishing to ransomware, it's imperative that your organization puts in place measures to protect your most important assets.

Join top security leaders for an interactive discussion on how to better secure the enterprise in 2021 and learn more about:

  • Trends in cyber attacks and what's at risk
  • Prevention best practices
  • Solution recommendations for attack detection and response
  • Top threats on the horizon and what's at risk
  • How organisations can take the necessary steps to prepare for the unexpected and build business resilience

Moderated by: Michelle Drolet, CEO, Towerwall

Panelists include: Rapid7 Kelvin Murray, Snr. Threat Researcher, Carbonite + Webroot, OpenText Business Solutions Paul Prudhomme, Head of Threat Intelligence Advisory at IntSights, a Rapid7 Company James Johnson, Cloud & Data Security Specialist, ATG - EMEA, Proofpoint

View Details

Cyber Threats have changed drastically over last three decades. From being a nuisance, they have evolved into 1. A financial instrument for Cyber Attackers, with ransomware being the primary tool in attackers’ arsenal 2. A tool to sabotage operations or exfiltrate sensitive information, using sophisticated attack techniques known as Advanced Persistent Threats (aka APTs)

Attack groups behind APTs are highly sophisticated and well-funded. This enables them to invest heavily in reconnaissance & design attacks before launching them against intended target. Because of this elaborate planning & inherent complexity, such attacks are extremely hard to detect & protect against. As more & more critical infrastructure systems have started utilizing digital technologies, risk posed by APTs has gone up substantially.

In this presentation we will discuss:

• What are APTs • Example of APT attacks • APT attacks against Operational Technology • How to safeguard

View Details

In this webinar, you’ll hear the true story of a latent configuration error that left a Fortune 100 company susceptible to a massive security incident, as told by one of the network engineers responsible for dealing with the aftermath, then fixing the underlying issue.

Learn how your security team can proactively get ahead of the next breach, by leveraging a single source of truth for your network data. We’ll show how to uncover similar latent risks, as well as confirm that every future change keeps the security posture solid.

Hosted by: Brandon Heller, CTO and Co-founder of Forward Networks, and Derick Winkworth, Senior Technical Solutions Architect, Forward Networks

View Details

It is Cisco’s purpose to power an inclusive future for all. This begins in the workplace with a culture that fosters diversity and inclusion. Join us on November 09, 2021, to hear about the role of male allies in helping to foster an environment of diversity and inclusion.

View Details

The threatscape is fast-changing and keeping up with transformation in the cybersecurity space is key to staying ahead of the evolving threats that lie ahead. In fact, according to Cyber Crime Magazine, cyber attacks are now the fastest growing crimes globally. But what will these threats look like in 2022? How will the threatscape have evolved from 2021, and how can we prepare for this change?

From a rise in web application breaches, to an increase in ransomware and phishing attacks, it is clear that 2022 could represent severe disruption for business globally if steps are not taken preemptively to secure your business.

Join us in this session as we discuss:

  • How the role of the CISO will evolve in 2022
  • The shifting threatscape
  • The key trends we expect to see in the year ahead
  • How to address these threats for a more secure enterprise

Moderated by: Stuart Wilson, BrightTALK

Panelists: Michael Yehoshua, VP of Marketing, SCADAfence Stan Davidson, Principal Solutions Architect, EMEA, SonicWall Kevin Eley, VP of Sales, UK and Europe, LogRhythm Jessica Charter, EMEA Security Principal, Trustwave

View Details

The Covid-19 pandemic has brought with it many changes at a speed that few expected, with the most obvious being that technology has burst onto the business centre stage. For the cyber community it will be remembered as the time when “cyber became a business issue” rather than an “IT problem”. As we are now enter the uncharted world of a hybrid work from home/work at the office, we need to revisit the concept of cyber risk - its management, its impacts across business lines and how we need to rethink the traditional held views of seeing it as a cost and perhaps start considering it as a business strength or (dare I say it) a strategic advantage. After all, staying ahead of the breach in 2021 and beyond provides a sound business base to survive and thrive …. And the best way to start is by understanding your risks.

Join BCyber as they host a discussion with Thomas Fikentscher – CyberArk’s ANZ Regional Director, where they will:

● Revisit the concept of cyber risk - how we view in now Vs how we should be viewing it ● Discuss how to make cyber risk management a strategic advantage ● Unpack the relationship between digitisation and risk ● Explore how to identify and address workforce mobility risks, using real world examples ● Explain why staying ahead of the “breach escalation” is just as important as focusing on stopping breaches ... because nothing can guarantee to stop the cybercriminals 100% of the time ● Provide practical tips you can take, to help your business get ahead of breaches now and in the future

View Details

Looking at the threat horizon for 2022, it’s clear that the digital world has moved even closer to the physical world than before. Remote work is the new normal. On the global scale cyberattacks are the fastest growing crime. Threat actors are seizing the opportunity to cause disruption in an industry still navigating the effects of a worldwide pandemic. The good news is organizations are more aware of the risk that poor cyber hygiene presents. In fact, many organizations have started to invest heavily in cybersecurity training and awareness programs to combat cybercrime and prevent breaches from occurring.

In this session we’ll explore: - Current State of Cybersecurity - The Effects of COVID on Cybersecurity - Cybersecurity Risks for 2022 and How to Prevent Them

Moderated by: Jo Peterson, Vice President, Cloud and Security Services, Clarify360 Panelists: Karim Hijazi, CEO and Founder, Prevailion Chuck Brooks, President of Brooks Consulting and an Adjunct Professor on cybersecurity at Georgetown Thomas J. Sweet, Vice President, Cloud Services, GM Financial

View Details

The Cyber Table Top (CTT) process was developed in 2014 to support DoD customers who were overwhelmed by the sheer number of findings produced by traditional cybersecurity scanning tools and checklist processes. These tools and processes identify a very large number of possible vulnerabilities for a system but didn’t provide context for which vulnerabilities might truly lead to potential mission failure. Since budgets are limited, customers need methods of focusing on the most critical vulnerabilities which present the highest risk to their systems. The CTT process is focused on producing actionable cyber vulnerability data in an approachable risk matrix format to enable teams to focus resources. CTTs bring together system developers and maintainers, system users, and expert red teams to execute a multi-day wargame that focuses on the security evaluation of threats that would deny, degrade, disrupt or destroy a system and prohibit users from accomplishing their core mission. By assessing the potential mission impact of vulnerabilities as well as their likelihood/difficulty it provides a way to understand the relative risks of various vulnerabilities and focus the remediation efforts. The CTT process has been used to support DoD system cyber security evaluations in various lifecycle stages from design through long-term maintenance. It has been used to identify and mitigate threats that later were witnessed “in the wild” and caused significant negative impacts to other systems. It has become so popular that an official DoD Guidebook and training course was developed in 2018.

View Details

Diversity and inclusion in the technology industry and workforce do not happen overnight. Hear from trailblazer Michele Guel, who helped pave the way for future generations of women to get involved in technology and cybersecurity. Learn how Michele’s career began, what the technology culture and landscape were like when she started in her career (the hurdles, hoops, and wins); and how to start and stay in cybersecurity, including today’s challenges and career outlook for women in the technology industry.

View Details

During the pandemic, we’ve seen solutions from Zoom, Microsoft, Google, and more rise to try to meet the challenges of this unexpected pandemic and have seen mass adoption and successful use. Unfortunately, there are many gaps where current solutions, such as video and team collaboration apps, can’t come close to replicating the experience of meeting in person.

Enter virtual reality. While once thought of as just a niche gaming product, VR is quickly emerging as a key answer to the question of “how do we meet when we can’t meet in person.” In this session, leading VR/AR analyst Tom Brannen will share his insights on the following:

• Why VR is better for certain types of interactions than traditional meeting tools • How companies using VR today as a collaboration tool • A market overview of VR for business • Challenges in deploying VR • What’s next for VR • What about augmented reality?

View Details

Hear from members of Salesforce's Women in Security group about their traditional, and nontraditional, career paths into cybersecurity. Learn how to navigate the professional security landscape and ways that Salesforce is working to increase equality and representation in the industry.

View Details

SASE is a relatively new networking security architecture that has become incredibly popular as a result of the growth of work-at-home and cloud computing. The network security components are well understood. The ability to provide zero trust using SASE is being established. Additionally, many vendors are working to working to enable SASE capabilities. However SASE includes so much more. The session will provide the listener the following information on how to provide additional security flexibility within a SASE environment: Where SASE is strong and areas where greater security flexibility is required; How SASE is made stronger with Browser Isolation, Web API Protection and Data Security; Specific capabilities that allow SASE to foster data loss prevention; and A perspective on how to incorporate flexibility into SASE efforts.

View Details

The world of work has shifted as now more employees work remote than are in the office. Succeeding in this new paradigm requires a proactive strategy to ensure that employees have the right apps and devices, and that IT is equipped to support the virtual office as it supports the physical office. In this webinar, Metrigy CEO and Principal Analyst, Robin Gareiss, will share the latest research into how organizations equip and manage remote employees to ensure collaboration success.

Robin will answer questions including: • How to ensure high quality voice and video performance from anywhere? • What devices to provision, and how to manage them? • What role should IT play in equipping and managing remote employees? • How to ensure security of applications, regardless of location? • How to ensure collaborative culture for in-office, remote, and hybrid employees? • What applications are required beyond messaging and video?

View Details

When it comes to supporting remote workers, IT leaders are often at odds trying to balance security with convenience and efficiency. How can you provide both a positive, remote working experience and yet maintain, if not improve, your current security posture? In this session, we’ll talk about how collaboration tools are changing how we work in and out of the office with platforms like Microsoft 365.

We will also review how to make on-premises systems and applications operate like they are already in the cloud while potentially improving your security posture at the same time. Our times demand that technology solutions be more intuitive and easier to consume, and IT is tasked with delivering it.

View Details

The Fuel Powering the Workforce of the Future:

In this interactive session, learn how PwC harnessed emerging technology during the pandemic to ensure that their people's wellbeing was prioritised, recruitment was sustained, and the culture continued to positively develop. Case studies include: The application of advanced human performance analytics developed in Formula One to transform the approach to workforce wellbeing. The development of an award-winning virtual environment to support hiring. The application of VR to drive behavioural change As these technologies continue to evolve, how should you ensure that the adoption is trustworthy, responsible and ethical?

View Details

With the expansion of technology in enterprise and the adoption of cloud, it is becoming ever increasingly difficult to maintain a strong foundation when it comes to organizational structure and policy development. CSA's Enterprise Arcthicture mapping to the Cloud Controls Matrix (CCM) helps alleviate much of the unknown in this area. By going over the key domains of this architecture, and showing the audience how to utilize it for multiple benefits to include policy development, roles and responsibilities when it comes to cloud, and managing technology applications and tooling, one will begin to understand the gaps in their own organizational structure and begin to build.

This session will cover: - What is the CSA Enterprise Architecture? - Where do the controls fit in? - Adjusting for policy development and gap analysis - Utilization for organizational structure - Creating ownership across your business - Application and tooling identification

View Details

What do “resilience” and “trust” really mean to today’s IT professional? Too many of the reported attacks over the past 18 months have one thing in common: The affected organizations are completely overwhelmed by the attack. What conditions have to be in place before an organization becomes truly resilient when faced with existential attacks? Join CompTIA’s Dr. James Stanger as he shares insights from working security professionals about resilience skills and best practices, including automation, monitoring, observability, micro-segmentation, and zero trust.

View Details

The majority of breaches each year are caused by lost, stolen, or weak credentials, and that hasn’t changed in over a decade. Learn how cybersecurity professionals came up with a new sign-in standard and what it takes for people to shift to a passwordless experience.

View Details

The Covid-19 pandemic has brought about a perfect storm of challenges for global enterprises regarding cybersecurity. As a surge in cyberthreats has brought ransomware, data breaches and other major security incidents to the top of the corporate agenda, executives are struggling to determine how to build a culture of security in our new hybrid work environments that include more working from home than ever before. As organizations consider what the "new normal" will look like in 2022 and beyond, this panel of security experts will describe what they are doing to enforce pragmatic cybersecurity policies that also enable business - including digital transformation.

We will discuss: 1) Developments regarding end user employee cybersecurity since March 2020. 2) How does employee security training work effectively? What does not work? 3) What tips can strengthen enterprise security culture world-wide? 4) What solutions, such as zero trust architectures, can help in a hybrid work world?

Panel: Dan Lohrmann, CSO and Chief Strategist Security Mentor - (Moderator) Brian Roberts, Enterprise Security Awareness & Training Leader | Lear Corporation Michael J. Riggs Sr., Director, Department of Judicial Information Technology, Supreme Court of Virginia Scott Larsen, Former CISO at Inova Health System (Virginia) - Also, former CSO, Beaumont Health System (Michigan)

View Details

An ethical hacker’s view of the mordern corporate network. Looking through how effective different network hardening methods have been in keeping hackers out, from someone who breaks in for a living. In this talk we’ll look through different methods for securing your networks regardless of where your staff are located – and how to test to see if it’s all working.

Key Takeaways: How to harden systems effectively Practical steps to protect networks (it’s not all patching, passwords, and perimeters!) Alternatives to traditinal security testing methods

View Details

Organizations experienced a massive shift in how they operated when the pandemic sent them into initial lockdown. Longstanding digital transformation plans suddenly kicked into high gear, and we've been "staying the course" ever since. However, everything is likely about to change again, and planning for what's next might be a bigger challenge than we realise due to "perfect uncertainty." In this talk, CISO Jordan Schroeder will cover: The challenges we should be ready for, How to devise a strategy to prioritise those challenges, and Specific risks to consider as we emerge from a pandemic.

View Details

This talk will discuss the new working habits emerging post-pandemic and cover the key risks associated with today’s enterprise ecosystem. It will explain what the board of directors, C-suite and other key stakeholders need to consider when designing and maintaining their security strategies. Mathieu will provide a mix of strategic, technical and operational advice to make it all work for your organization. Audience members will learn about: Post-pandemic working habits and how they disrupt the traditional IT ecosystem New risks that come with new working habits Cyber accountability and why it matters Global privacy frameworks and how to choose one Making cybersecurity a continuous measurable process

View Details

Gartner’s 2019 Architecture on the Secure Access Services Edge (SASE) set the stage for closing the gaps in security created by the distributed environment created with the deployment of Wide Area Networks over public infrastructure (created with IPsec and SD-WAN). This was underlined and emphasized with Forrester’s 2021 paper on the Zero Trust Network Edge. The Forrester paper also directed Enterprises to merge their networking and security teams or ‘Sunset Your Business’. While one could view this statement as hyperbole, in reality it does not go far enough.

• IT Silo’s complicate security and network connectivity • The Zero Trust Architecture (ZTA) requires a risk based approach to protecting data and this involves new ways of thinking about identity, privileged access, segmentation and defense • Enterprises need to migrate to an ‘All of Enterprise’ approach to security and this will involve more than just the network and security teams • IT Culture will need to change and we will explore how to solve both the organizational and technological issues facing Business and IT Leaders today

View Details

Do you want to raise the bar on your team’s security culture, but you don’t hold a senior title? Want to help customers scale security at the organizational level, but they only have one security engineer? In this presentation, we will explore tangible ways that you can scale and enhance your team’s security through collaboration, automation, and escalation through technical and cultural frameworks. We will cover how individual contributors (IC) can utilize ownership and earning trust to make a positive and lasting impact on your organization’s and/or customer's security culture. Participants will leave with a sense of ownership and have a tangible understanding of how to implement security at scale and escalate appropriately.

View Details

Secure Access Service Edge (SASE) has quickly become part of the day-to-day lexicon. But questions abound: What exactly is SASE? Will it make enterprise data more secure? How will organizations secure their data in a cloud-first world when the user and information are completely outside the enterprise boundary? How do SASE frameworks compare to traditional network protection, such as Secure Web Gateway, Next-gen Firewalls, Remote Access, and DLP?

This session breaks down the components of SASE and makes sense of practical implementation in a current technology stack.

View Details

Since 2020, the shift to remote and hybrid working models - and newly distributed employees accessing data from distributed locations - has opened up a need for more stringent and secure network access security models.

This is balanced with the need for remote employees to have access to reliable, low-latency access and connectivity to cloud and data center applications. So what’s the solution?

Join this session to learn more about:

• Best practices for implementing SD-WAN, SASE and ZTNA • Understanding the SD-WAN and SASE ecosystem • How to keep corporate data safe across your network • The future of secure access models, and what to expect over the next 12 months

Moderated by: Simon Ratcliffe, Technology Evangelist, Ensono

Panelists include: Mark Mariani, Senior Product Marketing Manager, BlackBerry Nigel Thompson, Vice President, Solutions Marketing, BlackBerry Heather Paunet, SVP of Products, Untangle

View Details

The pace of emerging technologies has increased significantly, challenging individuals to maintain knowledge of relevant skills and Business Areas to staff programs with the appropriate level of engineering skills needed for optimum performance on contract in a timely manner. Develop strategies that enable a proactive rather than reactive approach, allowing engineers and organizations to stay ahead of the curve to optimize on contract performance and be prepared for future work. Learn about different engineering shapes to determine which shape is most appropriate for you and /or your organization. Broaden your horizons and explore available options that can be used to develop a Personal Development Plan that includes learning new skills and gaining experience using these skills. Don’t miss opportunities – stay ahead of the curve!

Pam Sheary is a Lockheed Martin Fellow with 30+ years of software and systems engineering experience in the Department of Defense (DoD) industry, including 12 years managing International software development efforts. She continues to serve as the Chief Software Engineer on very large government contracts. Pam is a recognized technical leader within Agile / DevSecOps, Quantitative Management, and Risk and Opportunity Management. Pam’s work to establish Enterprise-level Code Quality has been leveraged across various government agencies. Prior to joining Lockheed Martin, Pam served in various Software and Systems engineering roles developing and testing software embedded systems and application development tools with geographically dispersed teams. Pam earned a bachelor’s degree in Computer Science & Mathematics from the University of Pittsburgh with continued graduate studies in Computer Engineering and Web Design /Accessibility. She holds several certifications, including the Scaled Agile Framework (SAFe®) and SAFe® for Government.

View Details

Companies have had to pivot to remote work policies as quickly as possible, with network security often taking a backseat to business continuity. Now, remote working increasingly looks to be a permanent corporate fixture, with Global Workplace Analytics predicting that up to 30% of the workforce will be partially working from home by the end of 2021. Half-baked security protocols can no longer cut it in this new remote reality.

Securing your IT networks is not just a good business practice; it’s critical for any company looking to stay competitive. Proofpoint reports that 88% of global organizations experienced spear phishing attempts in 2019 — and cyber attackers are continually adapting to the new environment. A comprehensive security strategy is more necessary than ever.

Join this panel of experts as they discuss the most critical vulnerabilities of a newly remote system and how to safeguard against cyber threats:

• VPNs and how to choose the right one • Threat Hijacking Attacks: what are they and how to protect against them • Understanding Your Endpoints and building scalable endpoint management • Making Cloud Security work for your organization

Simon Ratcliffe, Technology Evangelist, Ensono Stan Davidson, Principal Solutions Engineer, EMEA Steve Cobb, CISO, OnceSource Michael Jimenez, Senior Product Marketing Manager, Kemp Technologies

View Details

It is now widely known that SMBs are a key target for cyber criminals. They are now seen as the ‘low hanging fruit’ as SMBs generally cannot afford the same investment in cyber security initiatives when compared to larger firms. Unfortunately, as far as the cyber criminals are concerned, anyone on the internet is fair game. Unlike their larger counterparts, a cyber attack on an SMB can be very debilitating and can even cause the business to shut down. SMBs face their own unique challenges when it comes to defending against cyber-attacks. Within this presentation, you will hear about how the Invictus Games in Sydney in 2019 was secured using minimal funding and time as a case study. We will then explore some of the unique challenges faced by SMBs when it comes to cyber security. We will look at how focusing on your core business and risk management helps direct efforts to the right places in a cost effective manner. We will then explore what a typical attack looks like and discuss the basics that need to be covered to provide an SMB with an ability to defend itself from cyber-attacks while avoiding overspend.

View Details

Imposter syndrome often involves experiencing feelings of inadequacy and insecurity, particularly in the workplace. In this session, you will learn about imposter syndrome from the perspectives of four Black women in tech. This includes how to recognize imposter syndrome and actionable strategies that you can take to help you overcome it.

View Details

Do you ever feel like someone is watching you? Do you sense someone is monitoring your every "like" or "dislike?" Do you suspect someone is listening to your conversation? Join in to learn how to increase your online privacy and insights into your privacy rights.

View Details

Cloud is where our data lives, is where code resides, applications run, and decisions are made. With this huge responsibility placed on Cloud, it becomes a rich target for attackers to mime private data, insert malware into code or applications, as well as influence the decisions. This talk will provide an overview of cloud security, with an emphasis on secure design leaning on core building blocks such as Identity Management, storage security, key management.

View Details

On Tuesday 12th October at 13:00 BST, Dan Norman, Senior Solutions Analyst at the ISF will be discussing Human-Centred Security and how to effectively manage behaviour.

In this session we will be addressing: - The vulnerabilities in human behaviour that make them susceptible to manipulation - The key factors that influence security behaviour - Strategies and initiatives to protect the workforce and to effectively manage security behaviour.

Dan Norman is a Senior Solutions Analyst at the ISF, helping ISF Members to manage current and emerging information/cyber risks. Dan’s historical focus has been on threat intelligence and technology forecasting, with emphasis on running cyber security exercises to prepare organisations for future threats. Dan is also the lead author of the human-centred security research series, which leverages psychological theory to understand manipulative attack techniques and identifies how weaknesses in the human mind can lead to security incidents.

View Details

Most security awareness training fails.

Typically, it’s boring, condescending or wrong, and sometimes all three. This webinar has a different approach: calling on principles from sales and marketing, ethical hacking, education theory and creative writing. Learn how your awareness training can generate empathy, tension and emotional investment, enticing your audience to keep watching. Many people prefer reading fiction to academic papers, as humans are naturally drawn to stories.

An engaging, relevant narrative will transform your awareness training from boring to captivating, changing the way your audience thinks and even behaves.

View Details

In recent times, dealing with insider threats has become one of the critical aspects of protecting IT assets of any organization. Traditional security measures tend to focus on external threats and are not necessarily capable of identifying an internal threat. As a result, when it comes to data breaches, around 50% of them have been, directly or indirectly, caused by insiders! In fact, it would not be an overstatement to claim that insider threats are bigger danger to organizational security than any external threats. Insiders have legitimate access to the company’s network and sensitive data, so it is difficult to identify intent behind accessing that sensitive information. This makes it easy, for an Insider to leak the data, either with malicious intent or just by carelessness. In this session, we will cover: - What is Insider Threat? - Types of Insider Threats. - Insider Threat examples. - How to protect against an Insider Attack

Presenters: Sandeep Pimpale, Technical Architect, Quick Heal Technologies Ltd. Himanshu Dubey, Sr. Director, Engineering, Quick Heal Technologies Ltd.

View Details

According to Gartner the endpoint protection platform (EPP) market will have grown by 18.5% in 2021 and continue growing. By 2024, the market will be worth $18.8 up from $8.2 billion in 2019.

It’s estimated that by 2025, more than 60% of enterprises will have replaced older antivirus products with combined EPP and endpoint detection and response (EDR) solutions.

In this session we’ll explore what is driving this corporate behavior as well as:

  • Key Principle of Endpoint Protection
  • Gauging Endpoint Gaps
  • Assessing Endpoint Risks
  • Understanding the New Threat Landscape
  • How Continued Work from Home Raises the Threat Level

Moderated by: Jo Peterson, Vice President, Cloud & Security Services, Clarify360 Thomas Stites, Incident Response Manager at FedEx Services Christopher Elliot, Director, Corporate Security and Security Operations, SoFi Tyler Cohen Wood, CISSP and CEO, MyConnected Health

View Details

In light of accelerated digital business transformation and increasing cyberattacks, enterprises need to implement passwordless authentication that allows their employees to operate with trust, no matter where they are. Passwords have been proven over and over to be weak and ineffective, and while many IT leaders are investing in multi-factor authentication to secure their users, this may not be enough. The business of tomorrow requires end-to-end identity management for users, machines, devices, and digital interactions. Join this webinar with Yubico and Axiad to learn how to take an identity-first strategy to cybersecurity and discuss:

  • Why FIDO2 authenticators are essential as your workforce transitions to cloud-based and mobile applications that are vulnerable to cyberthreats.
  • How PKI can secure your network’s increasing number of machines, such as mobile and IoT devices, and digital interactions including email and document signing.
  • Which authentication solutions are scalable and user-friendly for your growing business needs and your digital-focused hybrid workforce.
  • How streamlined deployment and lifecycle management of your credentials in a unified platform will help transition your cybersecurity infrastructure to passwordless.

Setting Up my Yubikey with Axiad https://www.axiad.com/resources/setting-up-my-yubikey

View Details

5G IoT is the latest in the IoT World. This next generation of mobile technology, with features such as Enhanced Mobile Broadband, Ultra-Reliable Low Latency Communication, and Massive IoT, is set to radically re-shape today’s mobile networks. This webinar aims at depicting the high-level composition of the end-to-end 5G network architecture termed as 5GS (5G System) and Security in this space.

View Details

Thriving through a cloud ransomware attack is no accident. The only way to avoid becoming a ransomware victim is to plan for an attack and take steps to recover before the attack happens. New Cyberattacks Require New Protection Strategies. So in this presentation I will talk about how to build a plan that can be used in the unfortunate event a company finds itself the target of ransomware. Your key takeaways from this session will be:

• Identifying a ransomware attack and assessing the blast radius • Activating the Rapid Recovery Plan • Examining the importance of backup immutability • Recovering Data with precision

Leena Bongale is a recognized industry expert with over 18 years of experience in Information Technology and specializes in Information Security and Management. She is currently Manager of Data Analytics & Governance at TD Bank. Leena is an accomplished consultant, speaker, trainer, writer, and columnist, and has achieved industry certifications including CRISC and SAP BI. Leena regularly speaks, writes and blogs for some of the most recognized tech companies today on topics including cybersecurity, cloud adoption, business continuity, and compliance.

View Details

On Thursday 16th September at 13:00 BST, Benoit Heynderickx Principal Analyst at the ISF will be hosting a live webinar exploring cloud control visibility and how to monitor your cloud controls in a multi-cloud environment.

In this session we will be looking at: - The main challenges faced by security professionals when it comes to monitoring the controls deployed over the multitude of cloud services recently acquired - The various solutions at-hands for cloud controls monitoring and reporting across the whole multi-cloud environment - Future trends leveraging the use of AI techniques for cloud controls monitoring.

Benoit is a principal analyst at the ISF. He is the project lead for the ISF’s Supply Chain suite of products and the research lead for cloud security. Benoit has over 20 years’ experience in information security risk and assurance and has worked across various industries and large organisations. Benoit also has a keen interest in the emerging quantitative techniques in information risk analysis.

View Details

Enterprise cloud infrastructure use continues its torrid growth as organizations embrace cloud compute and storage to supplement their IT strategy. Unfortunately, so too have ransomware attacks. Ransomware itself has undergone its own digital transformation of sorts, with ransomware as a service, aka RaaS, making even the most sophisticated attack campaigns as simple as a button click. Join Rick as we delve into recent ransomware trends and what each of us can do to secure our organization’s hybrid cloud footprint to minimize the probability, breadth, and impact of future attacks.

View Details

Cybersecurity incidents and failures impact critical public infrastructure, national defense, corporate economic interests, and personal privacy. As the magnitude and frequency of cyber events continues to escalate, vendors and agencies are desperately seeking solutions to solve this issue once and for all. In the 1980’s the software development industry was facing similar challenges. That crisis prompted Frederick Brooks to write his iconic paper “No Silver Bullet – Essence and Accident in Software Engineering.” The solutions and technologies detailed in that paper are eerily similar to the “breakthrough” solutions currently proposed for cyber. This presentation examines the “Silver Bullets” of cybersecurity, lessons we can learn from that parallel history, and the essence of challenges that confront modern security practitioners.

Teresa Merklin is a Fellow at Lockheed Martin where she specializes in Cyber Risk Assessment and Engineering for Cyber Resiliency. She is currently attached to the Aeronautics Cyber Range which performs cyber assessment and penetration testing across the complete portfolio of Lockheed Martin aircraft and related systems. She has 30+ years of career experience starting out in embedded software development which slowly morphed into cybersecurity over time. Teresa holds a BSEE from Oklahoma State University, a Masters of Software Engineering from Texas Christian University, and an MBA from the University of Dallas. She holds the CISSP and CSSLP certifications.

View Details

It’s hard to defend against today’s threatscape while securing users, devices, apps, and data and providing quality customer experience. As organisations need to quickly adapt to an evolving threatscape, new compliance regulations, and customer demands, how can they keep security at the forefront of their cloud adoption plans?

Wherever they are in their cloud adoption journey, it remains necessary for organisations to be critical of cloud security blindspots and secure cloud assets. Join this summit to learn more about what your organisation can be doing to better their cloud security strategies.

Join us to learn: - The latest threats targeting the cloud in 2021 and how to stay on top of the evolving threatscape - How to protect your enterprise against ransomware - How to better secure your cloud applications - Why visibility across your cloud environments is key for early threat detection and mitigation

Moderated by: Jeremy Synder, Senior Director of Corporate Development, Rapid7

Participants include: Ateef Mulla, Regional Senior Solution Engineer & Cybersecurity Expert - SonicWall Johannes Wiklund, Vice President, IT & Cyber Security, Somos Chani Simms, Managing Director, MetaDefence Labs Raphael Peyret, VP of Product, Horangi Cybersecurity

View Details

Gartner forecasts that global public cloud spend is forecast to grow 18.4% in 2021 to a total of $304.9 billion --up from $257.5 billion in 2020.

Organizations are prioritizing cloud security in 2021. Work life changes that were introduced in 2020 are here to stay. More and more workloads are moving to the cloud and organizations are shoring up remote work practices in accordance with evolving government guidelines.

In today’s session, we’ll review the top 10 Cloud Security Challenges of 2021.

Moderated by: Jo Peterson, VP, Cloud & Security Services, Clarify360 Panelists include: Kayode Olafunmiloye, Senior Manager, Cloud Security Strategy and Architecture, AMD Stan Lowe, former CISO, Zscaler Joseph South, Sr Cloud Security Engineer, Guaranteed Rate

View Details

Public cloud infrastructure has emerged as the backbone for innovation-driven growth. By embracing the cloud, enterprises can modernise their IT infrastructure and conjure solutions to serve customers digitally in new and innovative ways. Digital transformation & cloud adoption has further accelerated in recent times, as COVID-19 pandemic forced businesses to setup remote working at an unprecedented scale. Public Cloud services enabled fast & smooth migration to “working from home” by enabling connectivity from anywhere and supporting essential services such as video conferencing & real time communication.

This rapid increase in cloud adoption has introduced numerous new security threats and challenges. Also, this has opened up new attack avenues for Cyber Attackers, and subsequently cyber-attacks against cloud installations are only going to increase in time to come.

In this presentation we will discuss: • Cloud security risks & challenges o Multi vector attacks against cloud installations o Cloud jacking due to misconfigurations and using shared software o Among others • Impact of these threats • Preventive measures

View Details

In this talk we will discuss the growing cybersecurity threat to utility firms ( power, oil and gas, railways etc) and compare and contrast the strengths/weaknesses of popular packet-optical transport technologies such as IP, Carrier Ethernet, MPLS-TP and OTN technologies from a network security standpoint.

View Details

On Tuesday 7th September at 17:00 HKT, Dan Norman, Senior Solutions Analyst at the ISF hosted a live webinar to explore the emerging cyber risks that the APAC region may face.

In this session he addressed: - The key political, economic, social, technological, legal and environmental factors impacting APAC - Future cyber and physical threats that will likely emerge over the next 2-3 years - Strategies to mitigate emerging risks.

Dan Norman is a Senior Solutions Analyst at the ISF, helping ISF Members to manage current and emerging information/cyber risks. Dan’s historical focus has been on threat intelligence and technology forecasting, with emphasis on running cyber security exercises to prepare organisations for future threats. Dan is also the lead author of the human-centred security research series, which leverages psychological theory to understand manipulative attack techniques and identifies how weaknesses in the human mind can lead to security incidents.

View Details

5G brings the power to connect billions of new devices and enable their use in new ways. With that comes significant risk. What types of threats does 5G introduce and what should we consider as we start incorporating 5G into our products?

Katie Grzywacz is a Lockheed Martin Associate Fellow and is the chief cyber architect for the LM Space Centers of Excellence. She has 16+ years of experience that includes security engineering and offensive security testing. She is currently researching cyber threat scenarios that apply to a multitude of 5G use cases.

View Details

Advanced threat protection services and solutions are must in today’s business environment to protect data as well and the integrity of a business. Threat actors now have the resources to wage war like never before. Advanced Threat Prevention (ATP is made of several components and functions:

• Continuous monitoring and real-time visibility - Threats are often detected too late. After the damage is done. Monitoring and quick action is a must or you will pay the price in resource utilization and reputation damage. • Context - Monitored threats must contain context for security teams to effectively prioritize threats and organize response. • Data awareness – Having an understanding of data, its sensitivity, value.

View Details

It is very important nowadays to stay up to date with all of the cyber threats that are posing all over the world. It is widely known that there are not enough resources to be found to fill up every Security Operation Center (i.e. SOC). Therefore, many organizations struggle with coping with the massive amount of new type of attacks and generated alerts from their tooling. During this session, you will learn how to hunt (and automate your hunt) for active cyber threats in your environment and contain them using integrated connections to network, endpoint, and cloud products. This session is targeted at SOC management, cyber security engineers, threat hunters, and analysts. It will touch on threat detection, investigation and response. All the code will be made available after the session.

View Details

As emphasized by the recent controversy about quantum supremacy, the quantum computer is already a reality. Although the timing of the arrival of a quantum computer capable of factoring large integers and therefore of breaking most existing public key cryptosystems is still under debate, the risk to our cybersecurity infrastructure is now real and steadily increasing. In order to prepare our cybersecurity framework to the quantum era, and build a Quantum-Safe infrastructure, action must be taken today.

Fortunately, some solutions exist today and are constantly improving. There come in two very different flavours. One is to find new mathematical problems, which should be immune to the quantum computer threat. This is the domain of Post-Quantum Cryptography. The second is to use the peculiar properties of quantum itself to fight against the quantum computer threat. Current solutions are known as Quantum Random Number Generators, which improve the quality of keys, and Quantum Key Distribution, which enable secure distribution of these keys. Quantum Networks and the future Quantum Internet will soon make these solutions usable in a broad context.

In this presentation, we will outline both solutions and focus on the quantum ones.

View Details

Security teams can become overwhelmed with vulnerability reports. A myriad of tools exist that provide all kinds of reporting on suspected vulnerabilities in software. False positives (and negatives) are usually present in the data. For the security team, this can create a situation where more time is spent managing the data and reports than fixing things or helping other teams focus their patching efforts.

In order to triage and focus effort on the greatest risk to the business, a different approach may be needed than the traditional compliance-based ones or systems based on CVSS scores.

In this webinar we’ll start out by defining what exactly the term vulnerability means, how to measure that, and then explore a more risk-based approach.

View Details

The notion that software runs the world and the world runs on software became even more of a reality during the pandemic. In addition to enabling work from home efforts, organizations hit the Fast Forward button on digital transformation efforts in the last 12-18 months. Gartner points out that the global expenditure on enterprise software will grow by approximately 10.8% and be $516.9 billion in 2021

Software applications can be the weakest link when it comes to the security of the enterprise stack

In this session, we’ll explore:

• Current state of application security • Best practice guidance • Importance of a mature application security program

Jo Peterson, Vice President, Cloud and Security Services, Clarify360 Dustin Lehr, Director, Application Security, Fivetran Derek Fisher, VP Application Security, Envestnet|Yodlee Les Correia, Global Head of Application Security, The Estee Lauder Companies Nick Moy, CISSP, GCSA | VP Application Security, Fairway Independent Mortgage Corp.

View Details

You're building an application and need to prove it's secure, and to do that you need to find vulnerabilities and fix them. However, there's so much confusion about what that even means, let alone how to do it right, that it can be an uncertain and overwhelming endeavor. Author Ted Harrington takes you to the front lines of ethical hacking and security research, blending real-world exploit stories with actionable insights in order to help you understand how to break -- and fix -- applications. You'll walk away with practical guidance about how to:

  • Abuse functionality
  • Chain vulnerabilities
  • Choose a testing approach & methodology
  • And much more

View Details

In this "work from anywhere" world, ensuring users can quickly and securely connect to any cloud application they need is critical. To do this, organizations need to transition their network and security strategy to provide secure connectivity for remote workforce. Building your roadmap for the move to SASE cloud offers many benefits. It provides organizations with a path to reducing network and security cost and complexity, while increasing security and connectivity to give your users a better experience, regardless of location.

During this session, Paul Martini, CEO/CTO of iboss, will discuss: • The true enterprise impact of "work from anywhere" • How to reduce of eliminate the need for on-prem proxy appliances and VPNs • The new mindset of security at the edge • 5 steps to consider when migrating to a SASE cloud platform

View Details

The last 12 months have been incredibly turbulent in the cybersecurity world. The move to a hybrid work model has seen many organisations turn their security on its head, with the adoption of security solutions like SASE and Zero Trust. Ransomware has also spiked: according to a new Group-IB report, in 2020 ransomware surged by 150%. As the security landscape evolves and new threats seem to be at every corner, it’s essential to re-evaluate your security posture to ensure that your organisation is as safe as possible.

But what are the key trends thought leaders expect to face this year, and how can we navigate these security threats? Are security teams fully prepared to tackle new risks and breaches?

Join our panel of expert thought leaders as we discuss: - The key cybersecurity trends of 2021, from SASE, ZTNA and beyond - Breach prevention, and how to find the right solution for your organisation - What the ‘new normal’ means for your security teams - Identity-first security, and why it’s so valuable today - And more

Moderated by: Michelle Drolet, CEO, Towerwall

Panelists include: Bharath Vasudevan, VP, Alert Logic David LeBlanc, SecureCloudDB Anne Blanchard, Senior Director, Nasuni

View Details

Cyber attacks on companies, governments and individuals grew significantly in 2020. What can enterprises do to better protect their data? Is breach prevention even possible?

Hear from the experts on what the new normal for organizations looks like, the cybersecurity best practices to adopt and what's in store for the rest of 2021.

The topics up for discussion will include: - Cybersecurity in the new normal - How attackers have take advantage of the pandemic - Critical steps to take on the path to preventing data breaches - Why data protection and cybersecurity should not be separate functions - Best practices and solutions for breach detection and response - Lessons from the field and recommendations for CISOs

Moderated by: Kalani Enos, CEO, KEnos Technologies

Panelists include: Michelle Drolet, CEO, Towerwall Christopher Kruegel, VP Security Services - Network and Security Business Unit (NSBU) at VMware Ido Safruti, CTO & Co-Founder, PerimeterX Chris Arsenault, Principal Solutions Architect, BlackBerry

View Details

Malware or Malinformation. What’s the difference to your Users if threat actors are the ones pulling the strings. Is it the cyber departments’ responsibility to stop malware or to stop any bad data? In this engaging keynote, Eddie Doyle will review the top threat trends of 2020 & make a prediction for 2021 & beyond, with a challenge that the cyber security industry must mobilize into a military-like structure with long reaching tentacles into geopolitical influences that might seek to harm our colleagues.

View Details

Please join us in a panel discussion as we explore the challenges surrounding talent development in the cybersecurity industry from professional development, to recruiting, hiring, and building high-performing teams. Cyber Aptitude and Talent Assessment (CATA) identifies the cognitive overlap between aspiring individuals and master practitioners. Identifying that overlap allows for powerful predictions about future success in a variety of cybersec positions such as offensive, defensive, analytical/forensic, or design/development positions.

You'll leave this talk with a deeper understanding of the scientific rigor that validates and sets the CATA tool apart, how CATA helps the individual cybersec professional (and anyone wishing to become a cyber sec pro) align their career decisions with their innate cyber aptitude, how human resource managers can streamline their talent pipeline, eliminate noise, and find the best possible candidates for their org, and how hiring managers can use CATA to cognitively fingerprint their highest performing teams and develop a talent mapping and succession plan.

View Details

Web APIs that handle critical workflows like login or new accounts creation are constant targets of attacks. Web site owners need to protect these endpoints in order to prevent account takeover as well as the proliferation of fake accounts.

In this presentation, we’ll look through real examples at how attackers evolve their strategies as soon as protections are in place. We’ll also provide some insights into the most effective detection methods in order to counter the evolution and to stay ahead.

And finally, we’ll discuss how the evolution of the Internet ecosystem is affecting the web security world and make the task more complex.

View Details

Cloud desktops help IT teams secure their Windows 10 desktops and applications for medium and large size companies globally. Centralizing and virtualizing the Windows 10 desktop and the applications running on it help control OS and app versioning, patching, deployment, access and with backups – which can be a significant plus against ransomware.

View Details

The cybersecurity industry has seen an investment of over $45 billion in the past 15 years. Hundreds of thousands of jobs in the field remain unfilled amid breach after breach, and the problem has come to a head. It is time for everyone―not just techies―to become informed and empowered on the subject of cybersecurity.

Knowing this, author Dr. Neil Daswani covers some of the largest security breaches and the technical topics behind them such as phishing, malware, third-party compromise, software vulnerabilities, and unencrypted data in his latest book, Big Breaches: Cybersecurity Lessons for Everyone.

In this session, Neil Daswani is joined by Sushila Nair where they’ll discuss: - Effective prevention and detection countermeasures - Meta-level causes of breaches - Crucial habits for optimal security in your organization - and much more!

Whether you are seeking to implement a stronger foundation of cybersecurity within your organization or you are an individual who wants to learn the basics, this webinar will answer your questions and prepare you for the future of cyber security.

This episode is part of Cyber Authors, a new series with Sushila Nair. We welcome viewer participation and questions during this interactive interview.

View Details

Organizations have been moving to the cloud for several years now, but in the last year, our world has forced nearly everyone to leverage the scalability and speed of cloud platforms to support a remote workforce. With so many critical business functions running from these providers, it's imperative to protect our data, systems and assets. But traditional strategies struggle to keep up with the scope and scale of the modern cloud environment, which is forcing a change in how we approach our security assessments and mitigation techniques.

In this presentation, we'll discuss the benefits and challenges presented to many organizations by the sudden move to cloud-based services and a newly remote workforce focused on business continuity, not security. We'll also talk about some of the new ways we must evolve how we approach security and our internal programs to better align with the fast-paced and ever-changing nature of cloud services and assets and protect our organizations effectively, efficiently and at the speed required by today's modern attack surface.

View Details

The CISO community has demonstrated flexibility, tenacity and perseverance throughout the last 18 months.  As the world moves past the pandemic, CISOs are continuing to adapt their organizations.  For many there is a dual mission to enable organization growth as well as a need to prepare and protect for the unforeseen.

What is clear is that most organizations expect disruption, on some level, to continue for the foreseeable future.

In this session, we’ll discuss a five pronged approach with tools and tips to help CISOs prepare:

• Budget and Reserve Budget • Emerging Threat Mitigation • Maximizing Current Technology Investments • Utilization Review to include Optimization and Automation Efforts • Fostering Innovation with Emerging Tech

Moderated by Jo Peterson, Vice President, Cloud and Security Services, Clarify360 Panelists include: Dr Rebecca Wynn, Global CISO & Privacy and Risk Officer Konrad Fellmann, VP and Chief Information Security Officer, Cubic Corporation Jason Thomas, CISO, Cole, Scott, Kissane Sujeet Bambawale, CISO, 7-11

View Details

93% of enterprises already have a multi-cloud strategy in place (Flexera 2020 State of Cloud Report). Multi-cloud security protects data and applications from advanced, sophisticated security threats. Some other benefits include reduced costs and better service delivery. But what are the main multi-cloud security trends you can expect to see in 2021?

Join cloud and security leaders as they discuss: - The benefits of multi-cloud solutions for your security posture - The challenges associated with a multi-cloud strategy and how to navigate and overcome these challenges - The cloud security landscape of 2021

Moderated by: Simon Ratcliffe, CIO Advisor and Mentor, IT Evangelist, Ensono Stephen Archer, Senior Specialist Solutions Engineer (Cloud & Automation), F5 Networks Peter Wood, Partner, Naturally Cyber LLP James Johnson, Cloud & Data Security Specialist - ATG - EMEA, Proofpoint.

View Details

It is very important nowadays to stay up to date with all of the cyber threats that are posing all over the world. It is widely known that there are not enough resources to be found to fill up every Security Operation Center (i.e. SOC). Therefore, many organizations struggle with coping with the massive amount of new type of attacks and generated alerts from their tooling. During this session, you will learn how to hunt (and automate your hunt) for active cyber threats in your environment and contain them using integrated connections to network, endpoint, and cloud products. This session is targeted at SOC management, cyber security engineers, threat hunters, and analysts. It will touch on threat detection, investigation and response. All the code will be made available after the session.

View Details

Endpoint security remains a major challenge for organizations, and in November 2020, Cybersecurity Ventures predicted that global cybercrime costs will reach $10.5 trillion USD a year by 2025. That’s more than triple the amount that it was in 2015. With remote working still very much the norm, and hybrid workforces emerging, it is becoming increasingly difficult to keep track of multiple endpoints and the risk they carry.

With the threatscape continuing to evolve and cyber attacks becoming even more sophisticated, experts are here to share how security leaders can take the complication out of endpoint security.

Join us to learn: - Common endpoint threats from the first half of 2021 - Emerging endpoint threats and what to prepare for going forward - Leading endpoint protection strategies and how they can be integrated into your existing security solutions - And more

Moderator: Masha Sedova, Co-Founder & President, Elevate Security Panelists: Ian Goodhart, Director of Security Operations, Maryland Department of Information Technology (DoIT) Matt Balderstone, Cybersecurity Advisor, CyberArk

View Details

It is very important nowadays to stay up to date with all of the cyber threats that are posing all over the world. It is widely known that there are not enough resources to be found to fill up every Security Operation Center (i.e. SOC). Therefore, many organizations struggle with coping with the massive amount of new type of attacks and generated alerts from their tooling. During this session, you will learn how to hunt (and automate your hunt) for active cyber threats in your environment and contain them using integrated connections to network, endpoint, and cloud products. This session is targeted at SOC management, cyber security engineers, threat hunters, and analysts. It will touch on threat detection, investigation and response. All the code will be made available after the session.

View Details

We all hear about the large-scale data hacks events that have made global headlines recently. But far from the glare of media attention, organizations of all sizes are increasingly being targeted by cybercriminals due to insecure endpoints.

In this session, our panel of cybersecurity experts will share how real-life threat events during the pandemic have forever changed the cyber threat landscape, and strategies for combating new-age threats in the face increasing endpoint visibility and control challenges.

We’ll also share how recent high-profile cyber attacks are still impacting the business world, and what changes organizational leaders can anticipate from recent public hearings and governmental actions.

Michael Kennedy, Co-Founder & CTO, Ostra Cybersecurity Paul Dobbins, Chief Growth Officer, Ostra Cybersecurity Mike Thompson, Cyber Security Incident Response Team - Incident Case Manager - Team Lead, FR Secure Heidi J.K. Fessler, Founder, Innova Law Group, PLLC

View Details

Endpoint security is a balancing act between security and privacy controls, and providing usability to the end user. Endpoint security should be invisible to the user and not get in the way of daily tasks. If we apply too many security controls users will find ways around them effectively removing the control.

View Details

Businesses rely on AI models that transform data into actionable insights. Traditional methods for creating AI models require a lot of data that is collected at some central location. Federated Learning (FL), however, takes a different approach by turning the centralised paradigm on its head and moving models or functions to be executed to where the data is.

As a distributed process that does not require a single depository of data and where different parties can train an AI model without having to share the data, FL can be used in situations where data privacy is paramount.

This paradigm shift is also creating new opportunities to democratize AI, which has the potential to transform the data economy.

Join this month's episode of the Business Intelligence Report with Eric Topham, Co-Founder & Data Science Director at The Data Analysis Bureau, to learn more about how FL works and what opportunities it creates for consumers and enterprises.

Viewers will also hear from the experts about the different use cases for federated learning, especially in the context of customer privacy, regulatory compliance, and integrating siloed data. The topics up for discussion will include: - The emergence of FL - FL, the democratization of data and what this means for Big Tech - How FL can be used as a privacy-preserving technology - Business use cases for FL - How FL can be part of your data strategy

Speakers - Dr. Pedro Baiz, Royal Society Entrepreneur in Residence at Imperial College London and Head of AI at eXate - Max Robbins, CEO of AI Market - Rajeshwar Bhandaru, Enterprise Data Architect at Suez

This episode is part of The Business Intelligence Report original series with Eric Topham, Co-Founder & Data Science Director at The Data Analysis Bureau. We welcome viewer participation and questions during this interactive panel session.

View Details

Cloud trends change with the introduction of new technology and evolving business requirements. When cloud technology first came into the picture, there was both a sense of anticipation and major questions about security. The hyperactive cybercrime industry kept some end users conflicted about adopting cloud technology. Still, the technology has come a long way since its inception in overcoming concerns related to security. As we have seen in the recent years security breaches in large organizations point out that some of these security problems present as data breaches while others deal with access control.

Whatever the issue, it concerns decision makers greatly when making a choice of software or solution. Cloud Security will continue to evolve on several levels.

For more insights into trends in cloud security and the current issues around cloud security and their solutions, join our presentation to understand the Cloud Security Trends and what your organization can do to stay ahead in the game!

About the presenters: Leena Bongale, Manager – Data Analytics & Governance, TD Bank. Leena has extensive IT experience, with specialization in IT Security & Risk Management. Leena has been invited to several virtual conferences to speak on various technical topics round IT Risk & Control. Pankul Chitrav, Sr. Developer, TD Bank. Pankul is a versatile developer, with expertise in .NET, DevOps, Jenkins, Octopus and recently Azure Cloud.

View Details

The migration to the cloud comes with risks and rewards. Understanding the risks early on and addressing them proactively can allow an organization to reap the benefits of the rewards without facing unreasonable risk. To assess risk effectively, organizations should take a top-down approach where they focus on the high value cloud assets first. This session we will discuss the top-down approach and cover:

  • How to define a high value cloud asset
  • How to determine which cloud assets are high value
  • How to assess the risks to high value cloud assets
  • How to develop baseline controls for high value assets

View Details

Cloud adoption is skyrocketing. The Hyperscale providers are reporting double digit increases in revenues. Cloud can be more secure than on premises environments, but the optimal word is can. Cloud security is a shared responsibility model. How business approach their part of the security, management and oversight of cloud is a critical part of the success puzzle.

In this session we’ll explore:

• Biggest Cloud Security Challenges of 2021 • Adopting a Risk Management Framework • A life cycle approach that includes Security by Design and Privacy by Design • Regulatory considerations and cloud privacy • Tools that can help

Jo Peterson, Vice President, Cloud & Security Services, Clarify360) Nicolas Moy, VP Security Engineering, Fairway Independent Mortgage Stan Lowe, Former CISO of Zscaler Jim Fulton, Senior Director of Product Marketing, Forcepoint

View Details

Today’s digital workforce is agile, highly available, automated. Where human and artificial intelligence coincide. Managing the risks of cloud IT services is always changing. This track discusses the evolving workforce and the cloud computing risks these changes bring with it.

Today we’ll discuss;

  1. The 4 different types of connected worker
  2. Cloud visibility
  3. Identity and access
  4. Business risks associated with cloud
  5. Mitigating cloud risks

View Details

No organisation can defend against every conceivable attack in the cloud, thus it makes sense to prioritise threats by the most likely to target your specific business and then make informed decisions on how to prevent and detect those threats.

This webinar will introduce the concepts of Threat and Risk Analysis for cloud security, how to identify the most likely attacks, and how to best focus your efforts and budget to protect your cloud services.

View Details

Cloud adoption has witnessed exponential growth over the past few years. It provides many advantages for both individuals and organizations. However, at the same time, many new cyber security risks have arisen due to this rapid growth of cloud adoption. A conventional risk management framework does not fit well with cloud applications, as those frameworks were designed for applications running in traditional on prem environments.

In this presentation we will discuss:

• New cyber risks that organizations are exposed to when they adopt cloud. • Impact of Cloud breaches. • Techniques used by attackers to breach cloud deployment. • A framework for Cloud Risk Management.

View Details

Working remotely has become the new normal. This, and many other changes organizations adopted last year in response to the pandemic are likely to stay for the long term. According to Gallup, about two-thirds of U.S. remote workers want to continue to work remotely. So, how can organizations continue to support their growing distributed workforce at a time where reports of security threats have increased by 400% compared to pre-pandemic levels? 

Here is where the zero-trust approach to security comes into play. 

Join this month's episode of The (Security) Balancing Act with Diana Kelley and guests as they discuss the emergence of zero trust (“Trust Nothing, Verify Everything”) and what it helps achieve for enterprises in the age of cloud and remote work.

Viewers will learn about: - The evolution of the security perimeter and the shift to zero trust - Why zero trust is an approach and not a product - Zero Trust Network Access (ZTA) vs. corporate VPN - Real-world stories and practical hands-on guidance from people who have deployed a ZTA

Speakers: - Mari Galloway, CEO, Women's Society of Cyberjutsu - Jonathan Nguyen Duy, Vice President, Global Field CISO Team, Fortinet - Bob Rudis, Chief Data Scientist, Rapid7

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

Tackling IT security compliance can be a headache -- but when you add the cloud into the mix, there is an entirely new set of challenges at hand. Cloud compliance is an issue that many organizations are concerned with, so much so that almost nine in ten (86 percent) believe that compliance will be an issue for them when moving systems, applications and infrastructures to the cloud, according to recently released research from Telos Corporation. Additionally, a staggering 94 percent of respondents report that they face challenges with IT security compliance and/or privacy regulations in the cloud. With the sheer amount of companies making the transition to remote work, cloud versus on-premises or legacy infrastructure is rapidly becoming the norm. So how can organizations embrace cloud and overcome compliance concerns?

This session will explore:

  • The costs of compliance and noncompliance in the cloud
  • The very real implications of audit fatigue and how the cloud exacerbates compliance concerns
  • Potential solutions to ease compliance challenges, especially in the cloud

View Details

Endpoint security remains a major challenge for organizations, and in November 2020, Cybersecurity Ventures predicted that global cybercrime costs will reach $10.5 trillion USD a year by 2025. That’s more than triple the amount that it was in 2015. With remote working still very much the norm, and hybrid workforces emerging, it is becoming increasingly difficult to keep track of multiple endpoints and the risk they carry.

With the threatscape continuing to evolve and cyber attacks becoming even more sophisticated, experts are here to share how security leaders can take the complication out of endpoint security.

Join us to learn: - Common endpoint threats from the first half of 2021 - Emerging endpoint threats and what to prepare for going forward - Leading endpoint protection strategies and how they can be integrated into your existing security solutions - And more

Moderated by: Michelle Drolet, CEO Towerwall Panelists: Robert B. Razavi, Sr. Security Advisor, CISO Office, Bombardier John Bambenek, President, Bambenek Consulting and Security Advisor, Netenrich Chase Cunningham, Chief Strategy Officer, Zero Trust Edge

View Details

Considering how much—and frequently—security shifts in the customer landscape, we believe Identity Management is at the epicenter of digital transformation and the next generation of enterprise IT. The changes in identity systems and services over the next five years are expected to be as disruptive as the new business models, applications and ecosystems they are supporting.

In our presentation we will look ahead to the future of identity & access management, talk about specific projections as to where we believe Identity Management will be going over the next five years and describe a model for identity abstraction that provides an extensible services oriented architecture. We include newer disruptive models such as DevOps/microservices in identity systems, cloud-based IAM, self-sovereign identity leveraging blockchain, IoT support, evolving privacy regulations, and new governance and provisioning models.

View Details

So you want to showcase your skills and speak at a technical conference? Great. Your voice matters. Conference organizers highly value new voices, and they are always on the lookout for ways to bring more talent to the stage. The good news is that there are opportunities abound and by submitting to conferences, you're honing in on your expertise, experience and knowledge, creating the most stellar of proposals. Join us for an honest discussion of cybersecurity industry influencers who weren't always used to being accepted when they initially submitted for speaking opportunities. They will share their stories of how they transformed every "no" into a "YES"!

View Details

A security operations center (SOC) is a dedicated site where enterprise information systems (web sites, applications, databases, data centers and servers, networks, desktops and other endpoints) are monitored, assessed, and defended by a team of information security professionals.

This session will give you insight of a SOC from a woman's perspective. You will be taken through some of the challenges faced by many of us today while working in a male dominated field. By the end of this webinar, you will have learned about the day-to-day activities in a SOC, how to manage your work-life balance, and how to acquire the skills that will help you grow in this field.

View Details

SolarWinds Cyberattack came as a wake-up call to many. An attack that most cyber-aware /savvy organizations could not detect for many months. It is a reminder of how an interconnected world can impact us all in a short time. Join Sunil Sharma, Director of Cyber Defense for Middle East’s leading provider of strategic consultancy and tailored information security solutions and services company, Help AG, the cybersecurity arm of Etisalat, to discuss supply chain attacks, techniques, and tactics used by advisories to execute such attacks and strategies to detect and respond to supply chain attacks.

View Details

VERIS, the Vocabulary for Event Recording and Incident Sharing, is a set of metrics designed to provide a common language for describing cybersecurity incidents (and data breaches) in a structured and repeatable manner. VERIS provides cyber defenders and intelligence practitioners with the ability to collect and share useful incident-related information - anonymously and responsibly – with others.

VERIS underpins the annual Data Breach Investigations Report. VERIS and its A4 Threat Model – Actors, Actions, Assets, Attributes – help codify incident-related information for threat modeling, intelligence analysis, breach mitigation, and detection / response improvement.

Key takeaways for this session include: • Understanding cybersecurity incidents through the VERIS lens • Recognizing the VERIS A4 Threat Model: Actors, Actions, Assets, Attributes • Getting started in Threat Modeling with VERIS

View Details

As users cost organizations billions of dollars due to simple errors or malicious actions, organizations believe that they have to improve their awareness efforts to make more secure users. The reality is that it takes a multilayered approach that acknowledges that users will inevitably make mistakes or have malicious intent, and the failure is in not planning for that.

Using lessons from tested and proven disciplines like military kill-chain analysis, counterterrorism analysis, industrial safety programs, and more, join Sushila Nair with author Ira Winkler on how to determine the appropriate countermeasures to implement and prevent cybersecurity breaches and other user-initiated losses. Join now and learn how to:

-Minimize business losses associated with user failings -Proactively plan to prevent and mitigate data breaches -Optimize your security spending -Cost justify your security and loss reduction efforts -Improve your organization’s culture

Business technology and security professionals will benefit from the information provided by these two well-known and influential cybersecurity speakers and experts.

This episode is part of Cyber Authors, a new series with Sushila Nair. We welcome viewer participation and questions during this interactive interview.

View Details

Phishing and ransomware attacks continue to rise, according to Proofpoint’s State of the Phish report for 2020. Organizations in the U.S. are at risk, the increase in remote work due to the pandemic has fueled a spike in attacks, and phishing attempts are up by 14 percent compared to the previous year.

Email continues to be the number 1 delivery vehicle, but other social engineering schemes that rely on social media, voicemail (“vishing"), SMS phishing (“smishing”), and malicious USB drops are also of concern for organizations. Ransom demands are also on the rise, but according to the report, paying the ransom is not guaranteed to work as many companies that paid the ransom failed to receive a decryption key.

Join this month's episode of The (Security) Balancing Act as Diana Kelley and guests discuss why ransomware is surging again, which sectors are most at risk, the threat to enterprises and how it is being used for more than just ransom (ex: distractionware, destructionware, etc). - The rise in ransomware under the cloak of the pandemic - Why email continues to be the channel of choice - The difference between fully automated and human-operated campaigns - How to decide whether or not to pay or not to pay the ransom - Why your backups may not be immune to ransomware - Addressing the threat with best practices

Speakers - Nicole Hoffman, Intelligence Analyst, GroupSense - Courtney Radke, CISO for National Retail, Fortinet - Patrick Lee, Senior Incident Response Consultant, Rapid7

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

Breach detection efficiency is all about consistent monitoring, organization and communication, experience (and expertise), training and proper tooling.

So is mountain rescue.

If you fall in a crevasse, get caught in an avalanche or come off a ridge, your survival depends only on time.

And in a mountaineer's career you know this will happen, as you should know, working in IT Security, that you will be breached.

So let’s be prepared, and learn from 200 years of mountain exploration how to quickly and efficiently get out of a worst case scenarios.

View Details

Smart buildings are the hottest topic of 2021. But the thought of system integrations to make this a reality is enough to give most network security teams heartburn. The planning, design, and implementation of IOT based “smart” buildings can be eased in its complexity, to realize ROI quicker, while ensuring that devices on the network are prevented from endangering the network or each other.

Through exploring lessons learned from successful projects, this session demonstrates how to start in your approach to a practical implementation of Securing a Smart Building, applying an interpretation of Zero Trust. It will cover methods used when security is of the utmost importance, and universal segmentation of threats is a requirement.

View Details

Protecting your organization requires vigilance and skills combined with effective controls and detections, just having a SOC is not enough.

SOCs vary in size, scope and staffing across various industries, outsourced and in-house, they exist to monitor, detect, and respond to evolving threats.

Guarding against failures in the security architecture is not just about selecting the right tools and suppliers, it requires constant validation of your people processes and technology.

Attend this session to learn: · Why SOC validation is crucial in confronting threat evolutions. · The elements of a continuous SOC validation and improvement program. · How continuous and automated red teaming and BAS make SOC validation achievable with existing resources.

View Details

Over 37 billion records were exposed in breach events in 2020 - by far the most records exposed in a single year, according to a recent report by Risk Based Security. How has remote working impacted your organization's security posture? What lessons can security professionals learn from the recent wave of breaches and what steps can enterprises take to strengthen security in 2021?

This keynote panel of security experts and industry leaders will explore the best practices for breach prevention, as well as share real-life lessons from the frontlines on what works and doesn't work.

Viewers will learn more about: - The reality of data breaches - Why data breach severity is rising - Ransomware attacks on the rise (doubling from 2019 to 2020) and the threat to businesses - Technologies that help with breach prevention, detection and response - Why security awareness matters and best practices for educating employees to be cyber secure

Moderated by: Michelle Drolet, CEO, Towerwall Nico Fischbach, Global CTO, Forcepoint Micheal Meyer, Chief Risk and Innovation Officer, MRSBPO Andy Thompson, Research Evangelist, CyberArk Satya Gupta, CTO & Founder, Virsec

View Details

Smart buildings are the hottest topic of 2021. But the thought of system integrations to make this a reality is enough to give most network security teams heartburn. The planning, design, and implementation of IOT based “smart” buildings can be eased in its complexity, to realize ROI quicker, while ensuring that devices on the network are prevented from endangering the network or each other.

Through exploring lessons learned from successful projects, this session demonstrates how to start in your approach to a practical implementation of Securing a Smart Building, applying an interpretation of Zero Trust. It will cover methods used when security is of the utmost importance, and universal segmentation of threats is a requirement.

View Details

This talk introduces the main security pitfalls that every developer needs to know about before writing and shipping code.

A recent non-official proposal of OWASP top 10 helps us better understand what weaknesses our contemporary systems face and how we can manage our daily job to avoid them. The new candidate, SSRF (Server-side Request Forgery), will also be highlighted in more detail.

What you will learn:

  • What are the biggest mistakes we make while writing and shipping code?
  • Why is OWASP top 10 relevant for our daily jobs?
  • How can we avoid the most critical vulnerabilities?

View Details

We are living in Data Age. Most organizations these days, in one form or other, rely on data to drive decisions & run their business. Thus, any data loss would mean considerable business impact to such organizations. Additionally, organizations’ collect certain data from users of their products, which is used for variety of purposes. If this data is lost / stolen, it may pose serious risks for the affected individuals and likely, tarnish the organization’s reputation.

In recent past, we have seen many data breaches across the globe, which have affected organizations of all shapes & sizes. So, it is imperative that organizations take steps to safeguard themselves against data breaches.

In this presentation, we will discuss:

  • Recent data breaches & their impact
  • Attack approaches used by Cyber Attackers
  • Prevention steps to safeguard data

View Details

WiCyS brings together women and supporters from around the world to develop cybersecurity skills with the aim of advancing women in, building equity in and developing minority talent in the field. One of WiCyS’s focuses is bridging the cybersecurity skills gap for female veterans, which is what helped launch the Veterans’ Program. Military career experience aligns well with a job in cybersecurity.

The WiCyS Veterans’ Apprenticeship Program includes paid training and apprenticeship, secure long-term employment, and a litany of possible resources including access to technology and mentoring. This innovative apprenticeship model is DOL-certified and a top-notch gateway to get the support needed to enter into thriving cybersecurity careers. Join this webinar to learn more about the WiCyS Veterans' Apprenticeship Program and see if it's the right fit for YOU! And, as always... we thank you for your service.

View Details

As AI adoption increases and becomes a competitive and operational efficiency advantage, managing AI-related risks poses the top challenge for AI initiatives. Cybersecurity along with AI failures, misuse of personal data, and regulatory uncertainty are also top areas of concern.

View Details

The pandemic and the shift to remote working has strained networks and pushed organizations to speed up their digital transformation journeys. With more users on the network than ever before, security has become a key priority.

Discover how organizations are addressing the security challenges of remote working and the latest trends in network security.

Join this panel of security experts and industry leaders to learn more about: - The impact of COVID on networks and security - The emergence of secure access service edge (SASE) - The need for smart network monitoring technology - New and old threats, and common vulnerabilities - Lessons from the SolarWinds hack - Best practices and recommendations for strengthening security in 2021

Kalani Enos, Kenos Technologies Mike Ichiriu, VP, Zentera Mike Grimshaw, Sre & Security Manager, Moovweb Robinson Delaugerre, Investigations Manager (Computer Security Incident Response Team), Orange Cyberdefense

View Details

When it comes to building or updating your strategy for detecting threats to your business, it is important to know the direction you are headed in.

Many Managed Detection and Response providers align themselves to a very short term strategy that would appear to solve all of your problems, when in fact what is needed is a more pragmatic approach that helps model out the different options you have for gaining visibility and also allowing for an understanding of the impact of limitations specific to your environment (for example a missing data or security event types).

Join our Global Service Area Owner for Managed Detection and Response, Grant Paling, for an insight into how to build a strategic plan for improvements in security monitoring.

Key takeaways:

• Understand the different options for getting started with detection and response (including endpoint, log and network-based approaches).

• Learn how they differ and the pros and cons of different approaches.

• Find out how to model the impacts on visibility when choosing different approaches, and balancing that out against the time to value

• See examples of where we’ve used our Threat Detection Framework to build business cases for expansion and to illustrate the impact caused by challenges from non-security parts of the business.

View Details

Cyber threats are constantly and rapidly changing. With time, as security products have evolved, threat actors have also evolved and have found newer ways of infiltrating networks and hijacking devices. Also, as more and more organizations go through digital transformation, the opportunity for Cyber Attackers is only increasing. In addition, many Critical Infrastructure organizations, across the globe, are going digital; which substantially increases the stakes around successful Cyber Attacks, and has given rise to Nation State backed Cyber Attacks.

In this talk we will discuss some major cyber-attacks of recent times, their motivation, & techniques used. We will also talk about best practices that organizations should adopt to protect against such threats.

Key takeaways from this session:

  • Cyber Attack trends & motivations.
  • Insights into recent noteworthy Cyber Attacks.
  • Protection mechanisms.

View Details

The rapid removal of threats has never mattered more. In our Annual State of Phishing report, we discuss how 2020 saw the emergency of new threat actors, the appearance of some old ones and changes in malware and phishing attacks.

What you will learn:

  • How over 50% of phishing reported by Cofense customers are credential phish
  • An effective phishing defense program enables organizations to quickly reduce risk
  • Tactics used by threat actors to make it to the inbox

View Details

This month's episode of The (Security) Balancing Act will focus on botnets as a growing threat to the enterprise, examples from the real world, and what enterprises can do to better protect against botnet-fueled state sponsored attacks.

Join this interactive roundtable discussion with security experts and industry leaders to learn more about: - How botnets have become a tool for cyber criminals and nation state actors - Real-world examples & known botnet attacks - Nation state ransomware attacks - DDoS attacks - Cyber espionage - ATPs - The trouble with attribution - What enterprises and governments can do to address the threat

Panelists: - Johna Till Johnson, CEO and Founder of Nemertes Research - Derek Manky, Chief, Security Insights & Global Threat Alliances, Fortinet - Craig Harber, Chief Customer Success Officer, Fidelis

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

Phishing attacks related to working from home and the pandemic are on the rise, and email continues to be the primary vehicle. With so much on the line, how are enterprises addressing the risk of email-based attacks? What are the latest trends in email security and how to keep up with the old and new threats?

Join this panel of security experts and industry leaders to learn more about the email security challenges enterprises are facing and the best practices for a stronger, more resilient enterprise:- Amplification of old attacks and email security challenges we will continue to see in 2021:

  • How are organizations dealing with phishing and spear-phishing
  • COVID-related phishing and social engineering attacks
  • Common red flags - how to spot a phishing email from a mile away- Protecting against business email compromise (BEC) attacks
  • Preventing credential theft
  • Lessons from the SolarWinds attack- Best practices for improving email security and protecting the enterprise

Moderated by: Michelle Drolet, CEO, Towerwall Panelists: Rodrigo Araujo, Security Advisor, Bell JP Bourget President, BlueCycle

View Details

With 90% of cyberattacks starting with a human error and phishing attacks having more than tripled since the start of the Covid-19 pandemic, involving and training 100% of staff is becoming a major leverage for companies. In this new deal of cybersecurity, the human brain is often the best (or only) tool to detect these social engineering attacks.

The availability of tools and data are making the hackers' job easier: AI-driven software and social network data are starting to make large scale, individually personalized phishing attacks possible, including through phone or even video calls. Cyberattacks are increasing in sophistication and targeting staff in order to steal information and money or cause mayhem.

In this webinar, we will share our views on:

• Current and future technological trends around email protection • How AI is impacting the potential of massive social engineering attacks • How companies and software vendors are reacting to this trend with innovative training strategies

View Details

Often times, even with the best technology and software, cybersecurity detection and response strategies don’t meet their maximum potential or, worse yet, fail without a team that has the right capacity and expertise behind them.

Join Herjavec Group’s VP of Customer Success, Eric Dowsland as he discusses best practices and strategies for enterprise detection and response programs including layering your security approach, and properly leveraging the MITRE ATT&CK Framework.

Discover how leveraging Managed Security Services (MSS) to support your cybersecurity plan is key to identifying, disrupting, containing, and remediating the onslaught of malware and emerging threats that will occur this year.

View Details

SolarWinds Cyberattack came as a wake-up call to many. An attack that most cyber-aware /savvy organizations could not detect for many months. It is a reminder of how an interconnected world can impact us all in a short time. Join Sunil Sharma, Director of Cyber Defense for Middle East’s leading provider of strategic consultancy and tailored information security solutions and services company, Help AG, the cybersecurity arm of Etisalat, to discuss supply chain attacks, techniques, and tactics used by advisories to execute such attacks and strategies to detect and respond to supply chain attacks.

View Details

Cloud computing, remote work and the increasing use of mobile devices has redefined the network edge. The concept of endpoint security and the strategies used to protect this new perimeter from sophisticated adversaries and advanced persistent threats has evolved as well

We’ll discuss:

• The changing organizational view of the redefined endpoint • Increased attack vectors • Maturing threat detection and response tools • The blurring line between End point security and data security • The move to Zero Trust Network Access

Moderated by: Jo Peterson, Vice President, Cloud and Security Services, Clarify360

Panelists: Stan Lowe, former CISO of Zscaler and former Global CIO of PerkinElmer Doug Saunders.CIO, Sweeping Corporation Christopher Camaclang, Technical Partner Manager - US MSP, Alert Logic

View Details

As organizations are making plans to extend working from home through next summer, what are some things employees and IT teams can do to better protect their devices and networks? Learn more about how endpoint security can be implemented and improved to protect your organization from breaches.

Join this interactive keynote panel with security experts and industry leaders to learn more about: - COVID-19’s impact on home network security - Why attackers are targeting the endpoint - Why your connected devices may be at risk and what to do about it - How to seamlessly integrate your endpoint security with existing solutions - Identifying threats, solutions and breach prevention best practices

View Details

Over last three decades, evolution of Cyber Security & Cyber Attacks has gone hand-in- hand. Whenever one side gains an upper hand, the other comes up with novel ways to move forward. Because of this need for constant evolution, both sides have been at the forefront of new technology adoption. And Artificial Intelligence is no exception.

Cyber Security vendors have been utilizing AI based solutions in their products for a while now. As these solutions mature, the Attackers are gradually finding it harder to bypass the protection. Subsequently, we expect Cyber Attackers to also start utilizing AI for their purposes. Which would require Security vendors to alter their approach.

In this talk we will discuss:

  • Current AI usage in Cyber Security and path forward.
  • Potential use of AI by Cyber Attackers.
  • How Cyber Security would have to evolve to counter the new threat.

View Details

Enterprises are adopting digital transformation with an ever-increasing speed to drive growth through new business models with the advent of digital technologies. Digital transformation has now become a business imperative rather than technology imperative. The rapid adoption of digital transformation also coincides with growing focus on Cybersecurity. Today, due to ubiquitous connectivity, increased device density and digital technologies such as IoT, the threat surface have expanded multifold . The multiplication of devices and the edge-based automation adds to the complexity and need to manage differently. A denial of service, theft or manipulation of data can damage the customer experience and cause significant damage to the brand value, penalty, revenue loss and jeopardize the livelihood and safety of individual stakeholders. Cybersecurity during and post-transformation is key to the success of the digital transformation and also creating compelling customer experience. On the other side, consumers are expecting more and more proactive measures by enterprise for security and any compromise may results into exudes of loyal consumer from the brand. The author intends to take vertical centric and digital transfection centric approach while narrating current state of cybersecurity in those key verticals. It also discusses various practices that today are required to digital transformation more secured and ultimately protect customer experience. Key Take Aways: 1. The Complexity and challenges of Cybersecurity in Enterprises of APAC Region 2. How can trust and resilience-based ecosystem be enabled by enterprise? 3. Cross industry view of Cybersecurity

Presenters: Dr. Neelesh Kumbhojkar, Director Symbiosis International (Deemed University) Pune, India Ajit Paul, Business Transformation Advisor, Digital i2o

View Details

We need to carry out a deep introspection about the current state of the IT and InfoSec rollout and the associated policies. The sequence of doing so is of the utmost importance. We may have to re-engineer the following.

  1. Network Security
  2. Application Security
  3. Operational Security
  4. Information Security
  5. BCP & DR
  6. End-User Education

Computing has seen a significant transformation. The IT services are being utilized and consumed by the end-users in a much different way than before. The stress on the IT managers has increased as they are compelled to allow the much-debated issue of securing and rolling out the BYOD policies. The forced reduction of the headcount & reduced wages has had an adverse impact on the employee’s integrity. Remote users have many peeping toms at home looking at the computer screens. The Home Wi-Fi used by the employees is not secure.

This leads us to analyze the top 10 areas of concern. Parallelly, the outbreak of an undeclared war between the “Cyber Bullies” and the “IT Security Soldiers” is hotter than ever before. We will discuss the strategies that IT Security Soldiers are adopting and the success thereof.

The current perceived threats have created opportunities for the vendors providing the NAC, ZeroTrust, RPA’s, ATP’s, infusion of ML and AI into the Firewalls and perimeter security devices to a large extent. The OS and RDBMS patch updates have taken a front stage and are a priority task for the IT Managers.

We need to draft out an SOP for keeping the IT Infrastructure secured. We need to create “8 Commandments” to have a well-secured IT Infrastructure

There is a human angle to IT Security as well. Only having robust IT InfoSec Policies. The Human Resource department needs to play an important role.

The goals that an IT InfoSec leadership needs to achieve has to be clear, well defined, and meticulously followed.

This presentation will be a snapshot of an end to end journey.

View Details

Mandiant Threat Intelligence assesses with high confidence that the ransomware threat and its associated disruptions and costs will continue to grow in 2021. We assess with high confidence that cyber risks to the pharmaceutical, healthcare, and related industries will remain elevated throughout the coronavirus (COVID-19) pandemic and related vaccine distribution efforts.

We assess with high confidence that actors specializing in specific stages of the attack lifecycle will continue their activities, making sophisticated tactics more accessible to a wider variety of actors and threat activity more difficult to track. We also noted increased volume, sophistication, and diversity in information operations throughout 2020. We suggest that continued evolution will be at least partially driven by detection efforts.

View Details

WiCyS brings together women and supporters from around the world to develop cybersecurity skills with the aim of advancing women in, building equity in and developing minority talent in the field. One of WiCyS’s focuses is bridging the cybersecurity skills gap for female veterans, which is what helped launch the Veterans’ Program. Military career experience aligns well with a job in cybersecurity.

The WiCyS Veterans’ Apprenticeship Program includes paid training and apprenticeship, secure long-term employment, and a litany of possible resources including access to technology and mentoring. This innovative apprenticeship model is DOL-certified and a top-notch gateway to get the support needed to enter into thriving cybersecurity careers. Join this webinar to learn more about the WiCyS Veterans' Apprenticeship Program and see if it's the right fit for YOU! And, as always... we thank you for your service.

View Details

The proliferation of cloud adoption by businesses has opened out a plethora of Cybercrimes conducted by individuals, organizations and even states. The objectives and intents are different for threat actors and the identification of their activities will shed some lights of how can we prevent and detect such malicious acts in our IT infrastructure on cloud. In this connected world where people are more interactive online especially on cloud, businesses have to look deeper and further on how the secure their IT infrastructure against Cybercrimes. The mindset of the IT security team have to shift with more proactive thinking on how to counter such malicious activities with right tools, personnel, trainings and resources. The session will walk through recent cases of cybersecurity attack such as ransomware and data breach, explaining how did the threat actors carried out the works. Attendees shall gain knowledges of how and what to protect for their organizations assets on cloud and build defence against such malicious attacks. Key Takeaways • Understand the objectives of different kinds of attacks. • Tools that malicious actors use. • Use cases – Ransomware and Data breach attack. • Steps that we can take to prevent and detect such attacks.

View Details

The Detection & Response categories of EDR, NDR, XDR & MDR have exploded with popularity recently. But how do all of these categories fit together, and what is their relation to the prevention categories of security controls? This session will present a unified model for how to think about security controls across both Prevention and Detection & Response. We'll look at how the model aligns to the MITRE ATT&CK Framework and give specific examples. The session is meant for both business and technical decision makers and leaders in the IT and Security spaces.

View Details

Phishing and ransomware has been a major issue for globally over the last 18 months in particular. Late 2019 saw a number of ransomware attacks on and this can continued into 2020 and 2021 with the COVID pandemic nationally and globally.

The reasons for the success of the attacks vary, but they are particularily debilitating as it strikes at the heart of any organisation affecting its ability to operate.

With the above in mind, this presentation will focus on discussing three key steps that need to be taken to bolster defences within organisations against phishing and ransomware.

The presentation will define ransomware and then address three key areas to be covered to bolster defences as follows:

  1. How to cover the basics. This is important as with focus on the rights controls, a large portion of the attack surface can be reduced
  2. Understanding the attacks methods and responding with further controls to address any gaps
  3. Getting strategic with your approach so that you can stay up to date with your controls and ensure cyber resilience.

The presentation will also provide a timeline of steps to be taken to mitigate ransomware related risks.

We will conclude the presentation with a discussion on key takeaways as follows:

• Increasing and maintaining your defences is a constant effort • Start with the basics and work your way through to strategy • Manage the change well and stay focused on risk mitigation • The journey can be broken down into three key phases to help you in the process: o Cover the basics o Understand how you are likely to be attacked and bolster your defences o Get strategic – prioritise and address gaps.

View Details

“To know your Enemy, you must become your Enemy.” ― Sun Tzu

Today’s hackers have evolved, in fact they have evolved and and are evolving much quicker than most organisations’ ability to defend themselves.

Hackers today collaborate amongst amongst themselves to build capability and scale so that they continue to stay ahead of the curve. In many respects they are borrowing from existing business models.

Like many businesses they have planned campaigns and their goal is to maximise their Return on Investment (ROI) within the shortest amount of time and the least amount of effort This webinar explores different trends attackers use to get advantage over organisations, what makes an organisation fall to trivial attacks and what we can do to prevent, detect and respond.

View Details

As we know COVID put everyone’s digital transformation plans on hyper speed. The speed and extent of this change has meant that execution was, just do it and we will catch up later.

Add to the mix that regulation around the globe is increasing in Corporate Governance, Security, Privacy, Ethics, Data Governance and 3rd Party Risk management. Business as usual won’t get us there, doubling the number of spread sheets flying around the company is not the answer.

In this session OneTrust will present the Trust Blueprint which provides a new approach in Securing the Modern Enterprise.

View Details

2020 was the year of pandemic and testing immunity of human race. It has also exposed our bookish risk assessment and risk treatment processes. 2021 is the year of redefining strategies for existence. Earlier, organizations were facing direct cyber-attacks, but in recent past, attacks are being simulated from various and multiple sources, such as third-party vendors, service providers etc. Compromise of data and breach of privacy have reached to the alarming levels. CISO’s are facing vivid challenges. CISO’s need to come out of the compliance strategy and move towards business benefits, so that organizations may get safe and secure information system infrastructure. On one hand CISO needs to provide assurance to the senior management on the other hand they should demand for innovation in information security products and services. Takeaway from the webinar: • Information security facets teasing CISO’s in 2021. • How to understand immunity and resilience of the IS infrastructure? • Techniques to have Insight of traffic from within and outside the enterprise network. • How to understand the real state of risk profile of the organization? • Factors needs to be taken into account while defining and designing the KRIs.

View Details

The New Workspace Episode 7

2020 was an intense year for security professionals. The shift to remote working uncovered unforeseen vulnerabilities and called for more stringent security solutions. Distributed workers meant distributed data, and security professionals had to find a balance between enabling wide-scale access to private data, and protecting their organisations from new threats.

However, as we move into 2021, it doesn’t look like it’s going to get any easier for the security world. According to a recent Citrix survey. 93% of US and European business leaders believe cybercrime and big data breaches will present a significant risk to organisations over the next 15 years. But what are these risks, and how can you best prepare your organisation to tackle them?

In this episode, we’ll take a look at what we have learned from security in 2020, and how we are using these lessons to inform security strategies over the next few years. Join us as we discuss: - The top security predictions for 2021 - Security lessons from 2020, and how 2020 changed security forever - The future of security, and what to expect going forward

Panellists: Safi Obeidullah, Field CTO at Citrix Fermin Serna, Chief Security Officer at Citrix Ayman El Hajjar, Course leader Cyber Security and Forensics at University of Westminster

View Details

DevSecOps is security that’s executed by developers and governed by security in a cloud native context. Governance means it’s security's job to make it work well. So, how do you know it’s working? Metrics! But which ones, and where to start? This talk will introduce modern security metrics for governing DevSecOps.

The following metrics will be covered so you can start incorporating them into your own programs:

○ Code Coverage ○ Backlog Burndown: ○ Arrival Rates ○ Survival Rates ○ Escapes Rates

View Details

One of the most difficult things to do for any cybersecurity leader is to build a defensible strategy and business case for investment that can be properly measured and tracked using relevant metrics and data. Today’s security leaders need a broader set of skills and influencing approaches to advance a winning cyber strategy.

Based on a combination of real-world experience, case studies, and research conducted with a targeted set of C-level executives, this session will show the audience how to frame the problems and outcomes they want to achieve, what metrics they should be tracking, and how to ground a cybersecurity investment plan in a business justification.

The session will walk through example business cases for cybersecurity investment, including explanations of the component parts, and how each is related. Attendees will come out of this session with tried-and-tested skills for leading change, for influencing people who know they need a stronger security strategy, but do not always understand why and how to solve the problems specific to the organisation.

Key Takeaways • Understand the components and metrics that make up an effective cybersecurity strategy and business case for investment. • Learn how to articulate cybersecurity outcomes in the language of the C-suite and board. • Understand how to tell a cyber story that leads real strategic change.

View Details

Independent research commissioned by Aura Information Security reveals staff are not as secure as their managers may think. While 62 percent of New Zealand businesses say they carry out security training exercises with their staff, only 37 percent of Kiwis say they have received training on good cyber security practices. Hilary Walton, a security culture expert, digital influencer and CISO of Kordia Group provides her perspective on:

• How to get started, • Do’s and don’t, and • How to build into your security strategy an employee education programme that resonates.

View Details

Organizations are transforming its businesses from brick and mortar model into digital platforms. This transformation initiative provides efficient processing of transactions, competitive advantage and access to global customers.

On the other hand, digitally transformed organizations are exposed to cyber threat actors and their attacks are becoming more pervasive and impactful even to the survivability of these organizations.

Therefore, it is necessary for CISOs to assist the Board and Senior Management in facing these cyber security challenges while meeting fulfilling its Strategic Plan.

View Details

IT leaders are balancing the management of complex and accelerated transformation while planning for unexpected impacts of the future. Today, more than ever, it is critical to build security programs that tackle these objectives while also clearly communicating the overall approach with the CEO and board of directors.

Join this conversation with Robert Herjavec, CEO of Herjavec Group and Shark Tank Investor, and Sanjay Beri, CEO of Netskope as they discuss enabling digital transformation, creating a winning culture and attracting talent, and protecting your data from modern threats.

View Details

Even CIOs and CISOs Have to Sell Sometimes

Every single one of us has to do some selling in their job. Now more than ever, IT and security leaders see the value of being cloud-first — but sometimes others still need convincing. In this episode of “The Reimagine Series,” John Thompson, Chairman of Microsoft, and Former Chairman and CEO of Symantec, joins Sanjay Beri, CEO of Netskope, to talk about technology, cybersecurity, and how the best leaders get others to buy into the strategy and vision needed to execute in today’s complex business environment. Get sage advice from John ranging from his career at IBM to CEO of Symantec, to VC investor with Lightspeed Venture Partners.

Join us for this live discussion as we dive into topics like bringing others along in executing your strategy and vision, how the ever-changing technology and cybersecurity is opening up new opportunities to drive innovation in your organization, and predictions for what’s to come in the technology and cybersecurity landscape over the next decade.

View Details

Mentoring programs can increase knowledge and build skills for future goals and milestones, allowing your workforce to grow their skills organically and create cultures of collaboration and success.

Join Part 1 of our series to learn how to design a mentoring program for women and minorities in security that actually delivers for everyone involved. - Learn from experts on how to design a mentoring program that delivers - Understand how to make mentoring meaningful for your organization - Learn what strategic planning steps are critical to make the plan a success

Speakers: - Virginia "Ginger" Spitzer, Executive Director | ISACA, One In Tech Foundation - Joy Harrison, Director, Leadership Development Center for Excellence | NTT DATA Services - Sushila Nair, VP Security Services, Chief Digital Officer | NTT DATA Services - Kwasi Mitchell, Chief Purpose Officer | Deloitte This is Part 1 of our new series on mentorship produced by BrightTALK. Sign up for Part 2 via the link in the attachments.

View Details

Come learn about Cyber FastTrack, an opportunity to earn scholarships and accelerate your career in cybersecurity, and gain access to free training materials.

View Details

In this session we explore the limitations of traditional security architectures, and explain how Zero Trust is best achieved with a new, open, and identity-centric model – the Software-Defined Perimeter (SDP) – which can significantly improve enterprise security, and finally let organizations bridge the gap between identity and network security. SDP verifies and secures all access to all resources, strictly limits network access, and literally makes network resources invisible to unauthorized users. We’ll explain how SDP avoids the limitations of traditional security architectures, delivers fine-grained network access control in a way that’s tied to each user’s context, and is dynamically responsive to changes in enterprise environments. We’ll conclude with an enterprise case study, showing how one organization obtained technical, business, and compliance benefits.

After this presentation, attendees will: - Understand the core principles of Zero Trust security, and why it’s important to adopt them now - How enterprises can achieve Zero Trust via a Software-Defined Perimeter architecture - See a customer case study of how they’ve used this approach to obtain significant business, technical, and security benefits in the cloud - Understand the ways in which their organization can quickly begin a Zero Trust journey, integrating with and enhancing their existing IT and Security infrastructure

View Details

Considering how much—and frequently—security shifts in the customer landscape, we believe Identity Management is at the epicenter of digital transformation and the next generation of enterprise IT. The changes in identity systems and services over the next five years are expected to be as disruptive as the new business models, applications and ecosystems they are supporting.

In our presentation we will look ahead to the future of identity & access management, talk about specific projections as to where we believe Identity Management will be going over the next five years and describe a model for identity abstraction that provides an extensible services oriented architecture. We include newer disruptive models such as DevOps/microservices in identity systems, cloud-based IAM, self-sovereign identity leveraging blockchain, IoT support, evolving privacy regulations, and new governance and provisioning models.

View Details

Securing the access to cloud data assets has never been more important. According to the latest Verizon DBIR, 73% of cloud breaches involved an email or web application server, while 77% of these cloud breaches also involved breached credentials. What does this mean for enterprise cloud security, especially in the time of COVID19 and remote working?

Join this keynote panel to learn more about: - How the landscape has changed in 2020 - Why attackers are focused on identities - Understanding privileged user behavior and securing identities - Discover how organizations are doing IAM, and what's needed for a more secure enterprise - Best practices and recommendations by the experts

View Details

Join SentinelOne's woman sales leaders as they share their top insights that have guided their business careers!

View Details

The CIA triad’s Integrity pillar is back in the spotlight. Thanks to the biggest cyber attack in history, amplified by hybrid cloud security complexity.

Integrity in software supply chains is now a board level conversation. As software underpins any digital transformation, the importance of ensuring that every line of code is free from tampering by hackers or malicious insiders is paramount.

In this talk we'll cover the depth of technologies supporting objectively provable software integrity. We’ll explore the breadth of deployment models including SaaS, PaaS, IaaS and on-premises software. Finally, we’ll discuss Integrity automation for CloudSecOps, and share best-practices architecture, and operations recommendations to help you mitigate old, and new supply chain risks.

View Details

Instead of the traditional "castle and moat" model of the past, today the security perimeter is being defined around the identity of the person or the device requesting access. What are organizations doing to protect digital identities in the age of breaches? How are the current trends in identity and access management helping address this issue?

Join this interactive roundtable discussion with notable security experts to learn more about: - The shift to identity-centric security - The zero trust mindset - What constitutes strong and effective authentication and authorization - The role of policy orchestration and enforcement - Best practices for protecting identities and managing access across the enterprise

Panelists: - Joseph Carson, Chief Security Scientist and Advisory CISO at Thycotic - Dave Farrow, VP, Information Security at Barracuda - Jeremy Snyder, Sr. Director, Corporate Development, Rapid7

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

The push to remote work in response to the 2020 pandemic pressured many businesses to quickly move to the cloud, often resulting in security decisions being made on the spot. What are the long-term implications for enterprises, the common mistakes made along the way and the ways to overcome them?

Join this panel of experts to learn about the security side of cloud transformation and the best practices for improving cloud security in 2021.

The topics up for discussion during this interactive session will include: - Security considerations when moving to the cloud - Rethinking your threat model - Addressing the complexity of managing hybrid or multi-cloud environments - Governance and compliance considerations - Fostering a robust security culture and tighter collaboration between teams - Best practices and recommendations for moving security operations to the cloud

View Details

As more organizations embrace distributed working environments, we see a rapid acceleration of cloud adoption. However, we notice that this adoption is typically done without a strategic migration plan causing more challenges in already complex environment. Many organizations don’t have a good handle on who should bear a burden of ensuring proper security in the cloud, much less a strong end-to-end vision of what technologies are required to secure their cloud deployments. In this session you will learn about: • The current security challenges in the cloud • How to integrate security throughout the IT life cycle • How to take a holistic, continuous, and defense-in-depth approach to security • Technologies that can help you securely adopt cloud

About Milica Lijeskic: Milica serves a Cloud Security Architect and Compliance Subject Matter Expert at KyberStorm. During her career she has worked across wide range of technologies and industries to implement countermeasures to mission-critical systems hosted in the cloud or on-premises. Her portfolio of work includes the authorship of strategic cybersecurity plans and policies and system architecture designs for federal government agencies and private companies. Her forward looking approach, resourcefulness, and passion for continued education has helped her resolve complex and provide unmatched services to her customers. Milica holds Bachelor’s degree in Business Leadership from George Mason University, as well as a variety of technical certifications: CISSP, Amazon Web Services (AWS) Solutions Architect, and CompTIA Security +.

View Details

Cloud computing is not going anywhere and the demand for Cloud services quadruple as seen in the demand for Multi-Cloud implementation. Multi-Cloud have many advantages but its complexity creates security challenges that consumers and providers should be concerned about. This presentation will take you through the tools you need to enable visibility across the entire platforms through a single view point.

Dr. George Edeh, Assistant Professor Cybersecurity Program, UMGC, Founder, Technology Impact Associates, a Technology Consulting Company:gedeh@teiassociates.com

View Details

On Tuesday 16th March at 15:00 GMT, Benoit Heynderickx Principal Analyst at the ISF will be hosting a live webinar exploring cloud security and a dynamic approach to cloud risk monitoring and reporting.

In this session we will be looking at:

  • Some of the new challenges faced by security and risk function when it comes to monitoring the risks posed by the multitude of cloud services recently acquired
  • The various solutions at-hands for cloud risk monitoring and reporting across the whole multi-cloud environment
  • Future trends leveraging the use of AI techniques for cloud risk monitoring.

Benoit is a principal analyst at the ISF. He is the project lead for the ISF’s Supply Chain suite of products and the research lead for cloud security. Benoit has over 20 years’ experience in information security risk and assurance and has worked across various industries and large organisations. Benoit also has a special interest in the emerging quantitative techniques in risk analysis.

View Details

In this session we explore the threats associated with cloud security, breach monitoring and prevention.

We also explore how organizations can protect themselves both from a denial of service, information leak, data theft.

With all the limitations of traditional security architectures, we explain how a CASB with Unified Information Protection can achieve cloud & data security detection through to remediation.

Significantly improving enterprise security, bridging the gap between cloud and information security.

After this presentation, attendees will: - Understand the core principles of people-centric cloud security, and why it’s important to adopt them now. - How enterprises can achieve a unified, layered defence to cloud and resultant data impact issues. - Understand how their organization can adapt a people-centric cloud security strategy, integrating with and enhancing their infrastructure.

View Details

Cloud computing’s security is an area of concern for organizations all over the world in today’s increasingly remote world. As we have send in the recent years security breaches in large organizations point out that some of these security problems present as data breaches while others deal with access control. Whatever the issue, it concerns decision makers greatly when making a choice of software or solution.

Organizations should take note that these security challenges are well documented. At the same time, each presents its own solution to vulnerabilities found in using cloud computing to meet business challenges and customer demands. In short, if you take the right precautions, cloud computing can be both safer and more satisfying for your business needs.

Our presentation is an introduction to some of the security challenges you can mind while relying on cloud computing for your business. We speak on at least four common concerns and their solutions, i.e Data Breaches, Access Control, Data Loss & Denial Of Service.

View Details

When it comes to cloud misconfiguration vulnerabilities, compliance frameworks and monitoring tools aren’t always going to help you. If you’re using the cloud, odds are your security model is broken. The cloud changed the way hackers think and operate: Rather than targeting an organization and then searching for vulnerabilities to exploit, hackers use automation to scan the internet looking for cloud misconfigurations to exploit.

Once an attacker has access to your environment, they use IAM resources like a network to move laterally, find data, and extract it. We’ve graduated from simple misconfiguration mistakes to techniques bad actors are using today to breach data out from under the most advanced cloud security teams—often without detection.

In this talk, Josh Stella Fugue Co-Founder , CEO and CTO, will put you into the hacker mindset so you can think more critically about fixing your broken cloud security.

Specifically, this talk will cover: - Common cloud misconfigurations that compliance won’t catch - How attackers take advantage of IAM misconfigurations - How to find advanced misconfiguration vulnerabilities and fix them - Strategies for remediation and building security into cloud design

View Details

Over the past year, we have seen a lot of unprecedented changes to our usual way of life with everything and everyone going remote as a result of the COVID-19 pandemic. This has led to various technology disruptions including adoption of multiple cloud environments across the globe. The shift to multiple cloud environments and a fully remote workforce that adds endpoints to access data and networks leads to location-agnostic operations and calls for heightened security that has broken the traditional perimeter-based network security model.

In this session, we will discuss the current proliferation of multiple cloud environments and explore how best to adopt these disruptive multi cloud environments through holistic cloud security solutions and zero trust.

About Bincy Ninan-Moses: Bincy Ninan-Moses is an enterprise technology solutions and cybersecurity subject matter expert (SME) leading Integral’s cybersecurity and cloud computing practices. She works to build Integral’s technical capabilities through innovative solutions and industry partnerships. She has worked for over 13 years in various roles in technology, cybersecurity, research and analysis, and as a technical solutions architect working at the intersection of business and emerging technology. Bincy has published research on national critical infrastructure security, cyber economic incentives, U.S. national and international innovation ecosystems, science and technology (S&T) policy, and S&T prediction markets. She holds a Bachelor’s degree in Electronics and Communication Engineering from Visvesvaraya Technological University, a Master of Business Administration (MBA) degree from Ohio University, and an Executive certificate in Cybersecurity from Harvard University. Bincy is a Certified Ethical Hacker (CEH) and holds professional certifications in penetration testing, cloud computing, and cybersecurity.

View Details

According to the Flexera 2020 State of the Cloud Report, 93 percent of enterprises have a multi-cloud strategy.

In this session we’ll explore some of the critical challenges that a multi cloud environment can present around security such as access, hypercomplexity and reduced visibility.

We’ll review options around: - Cloud Security Frameworks - Multi-Cloud Security Best Practices - Specific Tips to Strengthen Cloud Security Configurations

View Details

We have seen explosive growth in organizations moving applications, services and systems to the Cloud but unfortunately many do not understand how to secure these environments. Numerous IT and Security departments approach security in the cloud as they were securing individual servers in a data center and do not understand how to prevent data breaches or accidental data disclosers. Organizations are also struggling with how to effectively get full visibility into the cloud environment to monitor for malicious activity or configuration errors.

This presentation will focus on how to prevent and detect cloud security incidents including:

  • Cloud Security Threats
  • Review of Cloud Data Breaches
  • How to Prevent Cloud Security Incidents
  • How to Detect Cloud Security Incidents

Attendees to this discussion will come away with an understanding of the threats to cloud platforms and how an organization can develop solutions to effectively prevent and detect cloud data breaches. We will also provide best practices and native cloud solution recommendations to harden and monitor their applications, services and systems.

View Details

If you don’t fix your security vulnerabilities, attackers will exploit them. It’s simply a matter of who finds them first. If you fail to prove that your software is secure, your sales are at risk, too.

Whether you’re a technology executive, developer, or security professional, you are responsible for securing your application. However, maybe you’re uncertain about what works, what doesn’t, how hackers exploit applications, or how much to spend. Or, maybe you think you do know, but don’t realize what you’re doing wrong.

To defend against attackers, you must think like them. Join Ted Harrington, author of HACKABLE: How to Do Application Security Right and learn: - how to eradicate security vulnerabilities - establish a threat model - build security into the development process

You’ll leave knowing how to build better, more secure products, gain a competitive edge, earn trust, and win sales.

This episode is part of Cyber Authors, a new series with Sushila Nair. We welcome viewer participation and questions during this interactive interview.

View Details

This month's episode of The (Security) Balancing Act will look at how the CISO role has evolved in the last few years, what today's expectations are and what it takes to succeed as a CISO.

Some of the topics to be covered during this roundtable discussion with security and tech leaders include: - How has the CISO role evolved over the last few years and what is expected of CISOs in 2021? - CISO vs BISO - How to see ROI on your cybersecurity investment? - How to get the business to understand risk and care about security? - How to keep cyber employees happy. The churn is exhausting and costly for companies, and it’s exacerbated by employee burnout and a “grass is greener” approach.

Panelists - Patricia Titus, Chief Privacy and Information Security Officer, Markel Corporation - Jonathan Nguyen-Duy, Vice President, Global Field CISO Team at Fortinet - Gerald Mancini, Chief Operating Officer of Fidelis Security

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

With organizations moving infrastructure to the cloud at a record pace, building a perimeter wall around your organization is no longer a viable option for securing your data. Cloud computing completely changes the attack surface available to be exploited and can create potential security vulnerabilities for those unaware of what to look for. Fortunately, the data provided by cloud providers can be your best tool for identifying and mitigating threats. We will take a look at how threat hunting changes in the cloud.

View Details

For the 2014-2020 DBIR (Data Breach Investigations Report) timeframe, annually, we see Financial motive underlying breaches between 67% and 86% of the time and Espionage motive as the driver between 10% and 26% of the time. Given their nature (e.g., stealthy tactics, specific targeting), Espionage attacks can be difficult to detect and identify as an actual Espionage-related attack (given scant IoCs and other details). Whereas Financial attacks—if not detected while occurring or soon thereafter—eventually become apparent when money goes missing. At that point, the Financial motive, if not already ascertained, can be determined.

When we look at the VERIS (Vocabulary for Event Recording and Incident Sharing) A4 Threat Model—Actors, Actions, Attributes, Assets—we see similarities with and differences between data breaches involving Financial attacks and Espionage attacks. Join this session and discover:

· how data breaches with Financial and Espionage motives compare · how data breaches with Financial and Espionage motives differ · what can be done to counter either Financial and Espionage attacks

View Details

Due to the fast pace the organizations are using for their digital transformation, cybersecurity excellence is becoming difficult to achieve.

Most organizations need to consider not only a single network to secure, but also mobile developments, hybrid cloud implementation, among many other environments. This also includes a complex software development lifecycle, like DevSecOps, microservices, containers, etc.

Being on the top of the game is hard, so it is better to have a good strategy to be proactive to prevent new attacks (who wants another WannaCry?)

In this talk we will see:

· The best practices to properly defend itself against current threat trends · How to predict a broad number of future attacks · How organizations can be more proactive to prevent the next wave of attacks before they occur

View Details

Your vendors present a real operational risk to your business in 2021. The pandemic drove major shifts in not only how your business operates and partners, but also how your suppliers operate and partner. These systemic changes left unchecked can leave your business at significant risk to real cybersecurity threats.

Join Troy Vennon, Director of Cybersecurity and Trustworthiness at Covail, for a quick session on: 1. The 2021 outlook on supply chain risk and threats 2. How MITRE ATT&CK can help prioritize threats and risks 3. Practical, actionable steps to get you on the right path to managing third-party risk with confidence

View Details

The trouble with the world is not that people know too little; it’s that they know so many things that just aren’t so”. This eye-opening quote by Mark Twain makes one think about the possible misconceptions we might have in our minds.

In our daily life, we use many tools and rapidly adopt innovative technologies to improve our routine. Yet we are being neutral to the risks involved with those tools due to a false belief regarding the attacking vector and potential threats related to those devices.

In this section, we focus and disrupt cyber security misconceptions.

From the digital cameras, that we all use to take photos and our indispensable smartphones, to the newest technologies on the public cloud infrastructures, this session presents our research findings and vulnerabilities on those devices.

The common denominator for those platforms all have weak spots, allowing malicious individuals to take advantages and reach to our data on devices.

Breaking those misconceptions shows that we need to take cyber precautions in order to prevent the potential upcoming attacks.

All vulnerabilities presented on the talk were “responsibly disclosed” and are being discussed publicly after the relevant vendors have applied all patches

View Details

The Challenge - With the worldwide migration to Ecommerce platforms accelerating several years ahead of estimates, coupled with an increased attention to personal privacy and data security needs, The demands on all sizes of E Commerce firms to build in security and privacy as a foundation has taken new relevance and urgency. Between the pressures imposed by regulatory measures addressing Cyber Security and Data Privacy measures like CCPA (California Consumer Privacy Act)-GDPR (General Data Protection Regulations) and the increase and evolution of the Cyber Security threat landscape demands a holistic, segmented and layered 'zero trust' approach. (From Theft of Intellectual Property, Theft of Personally Identifiable Information all the way to ransomware-wiperware destroying a companies very existence.)

The approach REGO Payments Architecture has taken with its partners- From the beginning of the technical design and marketing discussions-due primarily to the sensitive nature of the spirit and decision mantra was the platform MUST comply with COPPA and GDPR Privacy and security mandates. We have taken an 'all hazards; approach to the emerging threat landscape and implemented a few key functions-

Light Stream- Veracode- Armor-

Some bullet points/key takeaways for the audience e.g in this webinar you will learn..... 1-Need for resilience and redundancy 2-Need to have a holistic view of all the parts 3-Cyber Hygiene has never been more important-patches, updates applied and logged. IAM tools in place, restrict admin access, etc. 4-Maintain across all business units the foundation of security and privacy (Not just meet minimum standards or regulatory threshholds but add extra care whenever possible

Panelists: Donald Codling, Advisor & Acting CISO & Chief Privacy Officer at REGO Payment Architectures Mark Vanderbeek, CTO at REGO Payment Architectures Johnny Wong, Director, Solutions Architecture at Veracode

View Details

Dealing with Cyber Security issues in a post pandemic world

2021 may be the year the world starts to overcome a health pandemic, but the effects on how work is undertaken and the consequent evolution of threats to organizations’ information assets have not yet been fully felt.

The shift to distributed working, accelerated by the pandemic, continues to disrupt organizations’ attempts to mitigate risk. The impact for many organizations has been catastrophic as evidenced by the surge in cyber-attacks in the immediate aftermath of the pandemic.

As security teams grapple with updating organization-wide policies, there are multiple implications thrown up by a distributed workforce including Shadow IT, lack of employee awareness, the insider threat of willful employees collaborating with malicious actors et al – all these coupled with the brazenness of the hackers who may well have found an easy back-door entry into an apparently ‘secure’ Enterprise.

Is there a solution to this issue?

This session will cover the following key areas -Enforcing the Enterprise Security Posture to a distributed workforce -The importance of employee accountability & ownership in securing the Enterprise -Identifying & addressing the scourge of the insider threat - malicious cooperation between outside actors & willful employees.

View Details

  • Interactive discussion on: Zero Day Poly morphic Advanced Persistent Threat Deep State Integrated social engineering threat

  • Major Players in State sponsored cyberattacks and Terrorism Russia China North Korea Iran

  • Objectives of attackers Disruption Dis information De-stabilization Denial of Service

  • Key Targets of Attackers Political Institutions Financial institutions Higher Education Apathetical security and arrogant Large Corporations SCADA infrastructures

  • Attack Vectors Telephony SS7 Social Media Portals- Facebook, Instagram, LinkedIn

  • Defense against emerging threats National position on State sponsored Terrorism US DOD response to the threat. We are critically behind the power curve https://www.fifthdomain.com/dod/2018/10/29/inside-the-pentagons-struggle-to-build-a-cyber-force/ Robust Mandatory encryption MFA Cyber security Awareness and Education

Take Aways-Upon completion of this presentation the audience will be able to:

  • Recognize their vulnerabilities with respect to cybersecurity threats

  • Predict and anticipate potential cyberattacks

  • Develop their own comprehensive information security program

View Details

The security industry is awash with products and services designed to protect you and your business from attack. There is a great deal of chatter about new and emerging threats which can keep us up at night, suggesting a need to have the latest technology to ensure we stay safe. This presentation considers the threat landscape for the coming year and suggests that perhaps concentrating less on predictions of what may happen and concentrate on what we know we can protect today is a sensible way forward.

In this webinar you will learn

  1. The big security threats of 2021

  2. How these threats can target organizations

  3. A view on what you can do today to protect yourself from attack

View Details

Malware or Malinformation. What’s the difference to your Users if threat actors are the ones pulling the strings. Is it the cyber departments’ responsibility to stop malware or to stop any bad data? In this engaging keynote, Eddie Doyle will review the top threat trends of 2020 & make a prediction for 2021 & beyond, with a challenge that the cyber security industry must mobilize into a military-like structure with long reaching tentacles into geopolitical influences that might seek to harm our colleagues.

View Details

If the idea of automating breach response fills you with a sense of uneasiness, you’re definitely not alone. But the flipside of doing everything manually isn’t ideal either – and can actually bring more risk to a situation, especially during a major incident. During this session, Sam and Jess (aka The Real Housewives of Automation), will explain where, how and when automation can help you investigate and respond quickly, accurately, and without creating a LinkedIn profile updating moment.

Here’s what we’ll be discussing:

-End to end automated vs manual response – a look into a real breach through two different lenses -The machines are our friends – how automation will help your team thrive -Raging alongside the machines – how to get the right balance -Investigation and response automation – where to start and how to finish

View Details

For a fire to spread, it needs oxygen. For a ransomware infection to spread, it needs privileged access. In this webinar, we’ll detail how several organizations stopped ransomware attacks by revoking administrator access from their Windows servers and workstations. In one example, the IR practitioners were able to revoke administrator rights across ~6000 servers in under six hours — without disrupting ongoing business operations. Learn how containing it so quickly allowed the organization to downgrade the intrusion from a major breach to a minor incident. Join Paul Lanzi, Co-founder and COO of Remediant as he discusses, in the context of the real incidents he has worked on, the role of privileged access (specifically 24x7 administrator rights) in the spread of attacks and how revoking these rights can be the fastest path to containment and attacker eviction. The webinar will cover the technical aspects of this new approach, but is equally useful for those without a deep background in Windows security.

View Details

In 2019, the United States had 1,473 data breaches with over 164.68 million sensitive records exposed. In the first half of 2020, there were 540 reported data breaches, according to Statistica. What can we apply from 2020? How can enterprises better protect against a data breach in 2021? Hear from the experts and learn the best practices around faster breach detection and response.

Join experts and thought leaders for a roundtable discussion on the tools and policies that make breach prevention possible and the solutions that can help keep your networks secure and make it easier to detect and deal with intruders.

We’ll discuss: - Lessons from the biggest breaches in 2020 - How to prepare for the inevitable and have a plan in place for during and after the breach - Types of attacks enterprises need to prepare for - Threat modeling and risk management - Best in class solutions and recommendations for security teams - Staying sane in the SOC and strategies for dealing with stress and alert fatigue

Panelists: Muhammad Ahmad, Head Information Security | CISO at FINCA Microfinance Bank Limited, Pakistan JP Bourget, President, BlueCycle, and Entrepreneur in Residence at Lytical Ventures Mike Lloyd, CTO at RedSeal Ste Watts, Head of Security Operations at Aldermore Bank Matt Clemens, Senior Director of Field Security Engineering at Digital.ai

View Details

Cybersecurity is often expensive, time-consuming and can have catastrophic consequences if done wrong. From scams designed to steal money to attacks designed to disrupt business and bring production to a halt, attackers have been upping their game continuously.

In the meantime, the security vendor's marketing departments relentlessly try to sell the latest and greatest "solution" to our problems with catchy ideas and the latest trends and buzzwords. Do we really need AI-enabled, ML-enhanced, multi-disciplinary, automated threat hunting cloud-connected, quantum controlled, blockchain-processing toasters in our organizations? Marketing departments sure think so. Sadly, all of this buzzword bingo has drawn attention away from securing the basics in favor of more technology, which requires more trained cybersecurity professionals to manage and really don't reduce our risk in any meaningful way.

This session will focus on 7 low-cost, but vital fundamental security principles that are being overlooked, resulting in significant breaches and disruption in small, medium and global organizations alike.

View Details

We’re all trying to protect constantly changing network environments without enough people, and with too many tools – all while we face attackers who are persistent and automated. Dr. Mike Lloyd, RedSeal CTO, draws on his background in epidemiology and modern cybersecurity, as well as his study of history, to show how others have dealt with such challenges, and extracts practical lessons you can use to decrease complexity and increase digital resilience.

View Details

Software and Data systems in most people’s companies are complicated and tend to grow organically. This organic growth can make it difficult to know what/where/how your assets need protecting. Come join me for a cup of coffee while I share the strategies I use through stories from the field on how to help you threat model your environment and take a proactive step to breach protection.

Problem to be Solved: How do I know what to protect?

Solution: Have coffee with your managers and use three simple question to threat model the assets they control.

Delivery: Sharing three stories from my work as a SOC manager, Analyst and Threat Hunter as examples of why to threat model, and how easy it can be.

The Stories:

  1. The case of the lost donor list.

a. Third Party Vendor Compromise

  1. What does the FBI and Web shells have in common?You.

a. Unpatched Servers.

  1. What was stolen?

a. Ransomware and mystery assets.

View Details

Phishing and other human-facing social engineering tactics remain the primary vectors of successful attacks. The transition to remote work greatly expanded the attack surface and opened new vectors for campaigns.

Organized cybercrime groups commonly use zero-day attacks to avoid detection. They typically compromise user credentials, so they can move across your organization to get to your most precious data.

How can you detect zero-day events without constant rules updates and rewrites and sifting through mountains of false positives?

How do you achieve infinite scale without an endless number of events to triage?

David Swift will discuss the top ten use cases and three keys to finding security threats in any environment using behavioral analytics. You will learn:

-The critical threat detection techniques to identify zero-day and malicious activity from both outside attackers and internal users. -Five indicators that combine known threats and machine learning to identify compromises. -Key log sources needed to solve the compromised user dilemma and how to detect misuse and malware. -Primary use cases across industries such as Manufacturing, Healthcare, Energy, and Financial Services.

David Swift is a 15-year veteran of SIEMs, UEBA, SOCs and a security evangelist.

View Details

Security leaders at high-growth startups and major enterprises alike are asking themselves, “How do I level up my program this year?” Economic uncertainty, a global pandemic, and rising customer expectations make this question even more complex.

Join Ray Espinoza, Chief Information Security Officer at pentesting company Cobalt, as he draws upon years of experience managing infosec programs at eBay, Workday, Amazon, and Cisco as well as working with heads of security at both large and small businesses. Ray will draw upon his time spent “in the trenches” to tackle common CISO pain points around program planning and execution.

Specific topics which he will explore include the following:

-How the concept of “security maturity” differs for companies of varying size -- and how to measure progress. -The characteristics and practices that define more mature security teams. -Professional blunders that yield tangible learnings, and strategies for avoiding common pitfalls (including basic breach prevention). -The advent of pentesting 2.0, and how it fits more neatly into agile development lifecycles.

View Details

2020 was the worst year on record for breaches. E.g. there were 2,935 publicly reported breaches in the first three quarters of 2020. According to a recent report from Risk Based Security, the number of records exposed in 2020 was up to 36 billion. 

What can enterprises learn from this and do to better protect their data? Is breach prevention even possible?

Hear from the experts on what the new normal for organizations looks like, the cybersecurity best practices to adopt and what's in store for the rest of 2021.

The topics up for discussion will include: - Cybersecurity in the new normal - How attackers have take advantage of the pandemic - Critical steps to take on the path to preventing data breaches  - Why data protection and cybersecurity should not be separate functions - Best practices and solutions for breach detection and response - Lessons from the field and recommendations for CISOs

Moderator: Ashton D'Cruz, Director, CAO, CGO, CISO & Head - CC&S Governance, NatWest Markets Plc, INDIA

Panelists: Allen Ohanian, CISO, Department of Children & Family Services Nir Shafrir, VP, Global Field Engineering and Customer success at Nyotron Andrew Kempster, Principal Consultant Incident Response/Digital Forensics at Trustwave

View Details

Handling of security breaches is vital – but what assurance do you have that you will even notice one in a timely manner? And if you do, will you have everything in place to make an informed decision and respond?

In this talk, we’ll: -Cover off all the basics – who to involve, where to look, and how to tie your activities together. -Consider how to rapidly progress your knowledge from detecting ‘something’ to building rapid and informed understanding of a breach. -Analyse the activities required before you hit the ‘response’ stage from the highest level.

View Details

Endpoints are the most targeted entity by Cyber Attackers. As per this survey by Ponemon institute, 68% of the organizations have experienced endpoint attacks, of which 80% were unknown threats / zero days. And the average patch gap to respond to these attacks was 97 days!

Cyber attackers are always identifying newer avenues to infiltrate organization’s networks. In current times, as more and more organizations go through rapid digital transformation, the opportunities available for Cyber Attackers are at an all time high; and they are pulling out all stops to leverage that Organizations need to have robust protection mechanisms to minimize the possibility of a successful Cyber Attack against their network. At the same time, they must be prepared for a successful breach. In this talk we will discuss the approaches that organizations can adopt to detect and respond to successful breaches in their environment.

Key takeaways - Major Security threats- Zero-day attacks, APTs, Trojans - Why Breach Detection is needed - Various tools & techniques that can be adopted for Breach Detection

View Details

2020 showed us that there is no silver bullet. Everyone is getting attacked. We will discuss what makes the hackers be one step ahead of all defense systems and how Cyber 2.0 brings a new method of defense being one step a head of the hackers.

View Details

With the increasing globalization of business, the international flow of data is creating unique complexities in developing and maintaining effective global compliance solutions in security and privacy. This presentation will explore impactful regulatory frameworks, including the EU's General Data Protection Regulation, and the California Consumer Privacy Act, drawing parallels and identifying differences. Ultimately, the talk will provide attendees with effective solutions to proactively comply with global regulatory requirements in both privacy and security and prevent privacy and security breaches.

View Details

This presentation presents breach management having two requirements, controlled and uncontrolled. Today, the CSIRP is a mythological beast. Theses two requirements of breach management are the reasons for the myth. The missing first step was found as evidenced by participating in audits and jobs. Why planning for the breach is necessary. Key people, identified by name in contract or law, are to be the principle agents of notification. Identifying responsible parties for both of the two requirements is one problem. Find out the other problems.

View Details

Recently we have seen significant and wide-reaching cybersecurity breaches making headlines. William Ehgoetz, Senior Threat Hunter at ActZero / IntelliGO leads our Threat Hunting team and deals first-hand with the fallout of such events. In this webinar, he will focus on things you can do proactively to overcome such concerns, both on your own, or with external help - so that you can rest assured, there is no need to panic.

The webinar will cover; - Why blind panic won’t help & why you need to trust in your cybersecurity program - How employee education, training, and having an incident response plan in place helps - Some of the more effective / proactive options (e.g Software Restrictions Policy) and other advice he gives our MDR clients - How integrating threat hunting into an organization’s existing security capabilities offers proactive protection against adversaries

View Details

Both human behavior and business priorities are often left unconsidered when cybersecurity teams plan policies, procedures, or security awareness strategies and education. Employees are experiencing learning fatigue, having to complete mandatory trainings without regard to their role or risk-based profile – and worse, without significant results on the organization’s overall risk profile. Business leaders may view cybersecurity as a roadblock rather than as an innovation enabler. To measurably improve information security behavior and your human-based risk, stop training and start engaging your stakeholders and employees. Learn how to leverage awareness resources to improve all areas of your security function, including policy, procedure and technology implementations. Most importantly, consider a Security by Design approach to cybersecurity, to build in risk thinking from the onset, enabling global innovation with confidence and engaging with employees to build a relevant security mindset into everything they do.

In this webcast, we will discuss:

Messaging appropriately tailored for business stakeholders to understand why and how cybersecurity should be incorporated into every aspect of the company Engaging your awareness resources to be the public relations and marketing department for your CISO and CIO The difference between awareness, education and training Socialization of policies, procedures and new technology Elements of a successful awareness program and security culture

View Details

The average ransomware spreads as follows: (1) attacker phishes their way onto an employee workstation.; (2) attacker extracts admin credentials from employee’s workstation and (3) attacker uses admin credentials to move laterally.

So why were admin credentials present on an employee’s workstation? JD Sherry of Remediant explores the role of administrator privileges in a breach and how securing 24x7 admin rights can sustainably prevent the spread of a breach beyond the first point of intrusion. 24x7 administrator access on endpoints can be used by attackers to spread ransomware and move from one machine to the next. This is an important concept to understand because

  1. A lot of 24x7 administrator access exists and each account creates a point of exposure. For example, Remediant sees that the average employee workstation has 480 admins with 24x7 access to it
  2. This access is business justified (needed by systems administrators, IT helpdesks) and spreads over time
  3. Easy for attackers to find: These accounts are easy targets for attackers because they are easy to find, provide powerful access and always available
  4. Not easy for security teams to fix: Finally, 24x7 access is very hard to find and clean up for security or IT operations teams

It’s no wonder 74% of breached organizations admit to the involvement of a privileged account.

View Details

As security practitioners, we recommend a balanced approach to enable better business outcomes while adequately protecting digital assets from unauthorized use and malicious attacks.

But what is the right balance?

Even though companies spend significant amounts money and expend precious resources to protect their business, the impact of data breaches have only increased. Time and time again we read reports that, regardless of how much time, money and resources are expended, organizations continue to be impacted by nefarious and malicious actors.

Is there a better way?

I contend that taking a data-centric approach to improving your security program will also have the benefit of significantly reducing the impact of future security breaches. In fact, a properly deployed and managed enterprise Data Protection Program can help you prevent breaches.

Is it that simple?

Although vendors have done a good job of simplifying the deployment and management of their tools, deploying these solutions in the context of a complex enterprise is nontrivial. For example, what is the best way to integrate the tools so that there are adequate layers of security to protect the asset without adding unnecessary complexity.

In this webinar you will learn to : Understand what is a data-centric security approach Prevent breaches with a data-centric approach Operationalize your enterprise data protection program Select and prioritize data-centric security tools

View Details

In this webinar, I will be sharing the necessity of Cyber Hygiene which can help organizations in preventing Cyber Breach. This could be a 1-dollar solution to a million-dollars cyber breach. Most of the organization are now focusing on latest cybersecurity tools/solution to better plan, monitor, and respond to cyber breach but they still lack in fundamentals to secure the organizational assets including humans factor. Before we invest in advanced solutions like AI, Threat Intelligence, XDR, SOAR, etc., fundamentals need to be corrected. One of the items is CIS controls to start with. Join this webinar to learn more about these and start practicing them before it's too late.

View Details

When it comes to security, the “softer” skills of governance, designing good architecture, and embedding good change management often get forsaken in favor of tools and quick implementations. However, embracing these items should be at the core of your cloud security strategy. In reviewing the OWASP Top 10 and the MITRE ATT&CK® framework for cloud, many of the attack vectors could be reduced through good governance and change management hygiene. Join this session to take a look at native tools within cloud environments that will help show your “soft side”.

View Details

Supply Chain Risk Management doesn’t need to be complex or resource intensive. A well-designed approach to your risk strategy can save you time, money, and headache.

In this webinar, Security Assessment Specialist Brandon Ritze will share: 1. The key building blocks to an effective risk strategy 2. Common pitfalls organizations make that should be avoided 3. Practical, actionable steps to get you on the right path to managing third-party risk with confidence

View Details

2020 was the year that third-party risk management was put under a microscope. How will this change third-party risk management in the year to come?

Tune in to our fireside chat with industry leaders from SecurityScorecard and CybelAngel as they discuss their top 5 predictions for Third-Party Risk Management in 2021, and how to stay ahead of the risks!

Speakers: ● Drew Wilkinson, VP Professional Services and Customer Success at SecurityScorecard ● Camille Charaudeau, VP Marketing & Product Strategy at CybelAngel

View Details

So much of what we discuss within SNIA is the latest emerging technologies in storage. While it’s good to know about what technology is coming, it’s also important to understand the technologies that should be sunsetted.

In this webcast, you’ll learn about storage technologies and practices in your data center that are ready for refresh or possibly retirement. Find out why some long-standing technologies and practices should be re-evaluated. We’ll discuss:

•Obsolete hardware, protocols, interfaces and other aspects of storage •Why certain technologies are no longer in general use •Technologies on their way out and why •Drivers for change •Justifications for obsoleting proven technologies •Trade-offs risks: new faster/better vs. proven/working tech

After you watch the webcast, check out the Q&A blog at https://bit.ly/3aGyeUK

View Details

In this round table, we bring together three vastly different perspectives on the same problem to see where we are, what we can do about it, and what our future looks like. Our round table discussion includes the vendor, customer, and researcher perspective. While each of us experiences the problems we face differently by seeing our vulnerabilities and opportunities from different viewpoints we can find the best possible solution.

We will begin by discussing how we got here and what today’s threat landscape looks like with respect to email-centric threats. We will then explore the raft of mitigation techniques available, where they work… and where they don’t. We will also look at the system writ large, and explore the impact systemic changes, such as the shift of business mail to O365, are likely to have on attackers. Finally, we will discuss how we see things changing in the future: what will the conversation in five years look like?

At every point in this discussion, our focus is on engaging a diverse set of views and pointing out practical steps that defenders can take to provide the most cost-effective and pragmatic solutions to protect their users from a threat that is only going to grow.

In this webinar you will learn: • How to think about the email vector the same way the attacker does: it’s about the people, not the medium • What attacks we see today and why they work • How to build a comprehensive strategy that helps secure the messaging channel • How to measure and prove to your boss you built a comprehensive strategy that helped secure the messaging channel • How we think these kinds of attacks will change in a coevolutionary system

View Details

There’s something refreshing about starting a new year. What’s not so refreshing is facing new security risks. To fortify your approach and learn a few must-take steps, join us to hear how a panel of experts is approaching cloud security in 2021.

SecureCloudDB Founder Aaron Klein will moderate a candid conversation with expert security leaders Tim Sandage of AWS, Mike Hughes of Prism RA, Jeff Collins of Lightstream, and Tyler Kennedy of Rewind as they discuss:

  • Emerging cloud security trends
  • The biggest security threats facing organizations
  • Strategies to prevent or stop an attack
  • Actions that you should take today
  • Regulations to watch out for
  • Considerations for CISOs using the public cloud

This panel will offer practical advice about emerging threats and recommended counters for anyone who is responsible for navigating security in the cloud. Come with questions as live audience Q&A will wrap up the session.

View Details

Despite the recent rise of workplace chat and instant messaging apps as a result of the pandemic and the shift to remote working, email continues to be the primary method of business communication for many organizations. Email is also still very commonly used by attackers. In fact, according to Verizon's Data Breach Investigations Report, around 96% of phishing attacks arrive by email. What can enterprises do to strengthen email security in 2021?

Join this panel of security experts and industry leaders to learn more about: - New and persisting email security threats - What's at stake and what organizations can do to better protect their employees and data - Phishing fears and employee training in COVID times- Addressing business email compromise attacks- Best practices and solutions for protecting the enterprise from email-based threats

View Details

Other than eliminating humans, what are the best practices for reducing business email compromise?

Join this session to learn how to:

  • leverage the cloud
  • take advantage of SaaS security features
  • implement email security controls, monitor and respond to incidents, and
  • empower your workforce to be the first line of defense

Presented by Sean Letona, Director of Professional Services at Abacode, Inc.

View Details

The SolarWinds Hack and response is creating new cyber security science and awareness of survivorship bias. Since Dec 13th, 2020 DHS/CISA has issued elaborate, regularly updated guidance to all government agencies and private sector organizations on how to respond, contain, recover and mitigate unprecedented and immeasurable insider data breach risk posed by the Russian Intelligence APT29 group. To address newly discovered stealth operations and privileged identity exploits, MITRE has also concluded new techniques need to be defined and added to their popular ATT&CK framework. We will review key CISA guidance to both Organizational Leaders and SOC teams, sharing new best-practices and suggested new ATT&CK techniques for threat hunters, compliance groups and DFIR practitioners.

About Valentin Bercovici: Val is founder and CEO at Chainkit, democratizing trust throughout digital transformation. Previously, Val was co-founder, now senior advisor at Peritus.ai, focused on AIops via machine learning. A Cloud, Big Data & DevOps pioneer, Val was a founding member of the governing board at the Cloud Native Compute Foundation (CNCF), the Linux Foundation’s home for Google’s Kubernetes, and most popular open source project. Val has enjoyed a long leadership career. Previously, at NetApp/SolidFire, he launched multibillion-dollar storage and compliance products, created the competitive team and strategy, directed new research investments for the NetApp Data Fabric roadmap, and served as SolidFire’s CTO. A pioneer in the cloud industry, Val led the creation of NetApp’s cloud strategy and introduced the first international cloud standard to the marketplace as CDMI (ISO INCITS 17826) in 2012. Val advises numerous data-driven start-ups and is passionate about improving diversity within the tech industry. He has several patents issued and pending around data centre applications of augmented reality and data authenticity.

View Details

Working from home has caused many firm’s attack surface to grow exponentially overnight. Where there might have been three locations prior to the advent of COVID19, there could now be 300 or 3,000.

Many firms are concerned with this and have shored up their security around remote access significantly. But what if the risk was still located inside their network. From careless staff to rogue employees, the consequences your business could face if tampered by an insider are unfathomable.

Research has suggested that 75% of all breaches could be avoided by better management of third party access and insider threats.

The principles of Zero Trust and least privilege is a method by which each employee is provided access to just what is needed for their job and nothing more.

The term “Zero Trust” was coined by Forrester Research analyst and thought-leader John Kindervag, and follows the motto, “never trust, always verify.” His ground-breaking point of view was based on the assumption that risk is an inherent factor both inside and outside the network.

Come hear some practical examples of how to get started utilizing zero trust in your organization to protect yourself from internal risk of employees and third parties accessing your network.

View Details

The COVID-19 Pandemic has amplified cybersecurity concerns particularly related to the cloud. Threat actors have recognized a unique opportunity to exploit pandemic-related vulnerabilities through social engineering attacks, business email compromise, work from home or other remote weak points. This results in increased risk and occurrence of ransomware attacks and data breaches that can disrupt or totally compromise organizations’ ability to conduct business. These security incidents can also subject victims to liability for violations of privacy and data breach notification laws. Join this webcast as SNIA experts will discuss: • Changing threat landscape due to COVID • Recent attacker exploits • Common security failures and their consequences • Data Protection (Mounir) o Strategies to combat malware o Minimizing ransomware risks • How emerging technologies (5G, IoT, AI, etc.) expand the threat landscape

After you watch the webcast, check out the Q&A blog at https://bit.ly/3qp2j0B

View Details

Dealing with the threats from insiders who have administrative privilege in your systems is a challenge enough, but how do you handle the risk that comes from vendors and other third parties such as contractors who need privileged access? These are usually trusted vendors and have undergone some vetting but it isn't usually as rigorous as your internal processes and your visibility into their employee’s background and activities within your systems can be opaque. We will go over why this kind of access represents an outsized risk to security and compliance, the challenges of managing these “Inside-Outsiders” and give some best practices to make sure that their access is as secure, compliant and efficient as your internal employees.

About Tony Howlett: Tony Howlett is a published author and speaker on various security, compliance, and technology topics. He serves as President of (ISC)2 Austin Chapter and is an Advisory Board Member of GIAC/SANS. He is a certified AWS Solutions Architect and holds the CISSP, GNSA certifications, and a B.B.A in Management Information Systems. He has previously served at CTO for Codero, a managed cloud hosting provider and CTO of Network Security Services, a security and compliance consulting firm, as well as founding InfoHighway Communications, one of the nation’s first high speed internet access providers. Tony is currently the CISO at SecureLink.

View Details

The 2020 US presidential election is behind us, but the key cybersecurity issues surrounding election integrity could linger for years to come. From ransomware attacks on local governments, to the untamed spread of disinformation, to experimenting with online voting apps and the myriad of vulnerabilities uncovered across election infrastructures, cybersecurity had never before taken such a central place in the national conversation as it did in 2020.

So, what have we learned in the aftermath? And how can we apply it to better protect upcoming elections as well as enterprises, customers and employees?

Join this interactive panel with security experts and tech leaders to learn the biggest lessons from the election from a cybersecurity and privacy standpoint. Discover what went down, what could have gone better and how to prepare for the midterm elections in 2022.

  • Can we build a hack-free election
  • Does misinformation on social sites impact how people vote and what can be done to stop the spread
  • What was new this time and what should security leaders keep in mind for their organizations
  • Would it be safer if we brought the voting process online or in app
  • Can nation state actors change voter rolls or polling data
  • What the biggest election threats mean for industry
  • Key takeaways for cybersecurity leaders

Panelists: - Jim Richberg, Public Sector Field CISO at Fortinet - W. Curtis Preston, Chief Technical Evangelist, Druva

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

The MITRE ATT&CK framework has become an excellent way for security professionals to understand and describe threats. However, most of the time, it is used to describe the actions of external threats.

But what about the insider threats? According to Forrester, 25% of breaches resulted from internal incidents, and almost half of them were malicious. In the past few years, insider threats have evolved in several aspects from how sensitive data leaves the organization to ways in which privilege access gets misused, creating risks for organizations to mitigate. The proliferation of cloud applications and the current remote work setup make tracking and protecting sensitive data extremely challenging.

Can we use the MITRE ATT&CK framework to help us describe, understand, and finally detect and protect against insider threats? If the framework often describes and supports threat detection of external threats, does it also help deal with insider threats? What organizations should expect from this exercise, and what do they need to do differently to achieve the desired results?

Join Augusto Barros, VP of Solutions at Securonix, to learn about:

• How insider threats have evolved and the new challenges they present? • How the MITRE ATT&CK framework supports threat detection practices? • How the MITRE ATT&CK framework can also help to address the issues related to insider threats?

Augusto Barros was the Research VP in the Gartner for Technical Professionals (GTP) Security and Risk Management group. He has over 20 years of experience in the IT security industry as an analyst and a security architect and officer for large enterprises.

View Details

This webcast, Tackling Insider Threat with Open Source Intelligence (OSINT), will demonstrate how OSINT can be leveraged to help identify and prevent insider threat.

Rachel will discuss the critical role OSINT can play in effective business risk management, specifically in managing insider threat.

In particular, Rachel will describe how companies can make more informed decisions about the people they employ and do business with by embedding OSINT within their recruitment and screening purposes, thereby minimising the risk of taking on high risk personnel.

Rachel will also discuss how OSINT can be used to understand an individual’s vulnerability to being an unconscious insider by, for example, inadvertently clicking on a link to a malicious website through a specifically targeted email.

Lastly, the webcast will examine the way in which organisations are using continuous OSINT methods combined with machine learning to identify and alert them to early indicators of insider threat, for example negative attitudes towards work, excessive spending, or a close association with a competitor. Indicators which when fused with other information regarding an individual such as a change in working hours or excessive data extraction, can start to build a picture of risk.

Key takeaways: - The principles of OSINT - The types of freely available information on people and companies - The value OSINT brings to business risk management, specifically in managing insider threat - How OSINT can be embedded within recruitment processes to help prevent companies taking on high risk personnel - How understanding a company’s and individual’s online footprint can help reduce the harm caused by unconscious insiders - How machine learning and continuous OSINT methods can help detect insider threat and provide an early warning of potential harm

View Details

Join SonicWall expert John Aarsen as he goes through the anatomy of social engineering attacks to demonstrate how people are manipulated into performing actions or divulging confidential information. These attacks have become more frequent and aggressive as attackers attempt to exploit the circumstances surrounding COVID-19. In the case of both users and organizations, overconfidence can lead to complacency, allowing such attacks to succeed. That’s why it’s crucial that you consider social engineering as your company builds its boundless cybersecurity strategy.

View Details

Threat actors are clever adversaries who prey on human error in your employee workforce to execute successful cyberattacks. They use social engineering to trick your teams into giving them access to your files and network. That’s why having a team of experienced security analysts on your side that work 24/7 is a crucial defense. When you’re up against real people who are targeting your employees, the solution isn’t a computer program but other people who know to combat these attackers.

Join Randy Pargman, Senior Director of Threat Hunting and Counterintelligence at Binary Defense and former FBI Computer Scientist, in this discussion that covers real stories from his experience with attacks targeting employees, how attackers attempt to deceive analysts, and ways to educate your workforce to defend against these attacks.

In this webinar you will learn: - How threat actors target employees - What next steps cyber criminals take to continue their attacks - Examples of attacks on businesses - Ways that an experienced SOC can combat these attacks

View Details

Improve your relationship with your developers and auditors, protect your environment, and go from frenemy to friend through streamlined processes and automated detective and corrective controls.

This session will cover tips on ways to address human error elements for development within your Google Cloud environment.

View Details

In this webinar, Changiz will cover:

  • Description of cyber attacks and statistics from known and published attacks
  • The most common types of attacks including phishing, ransomware, DDOS, Drive-By-Downloads, Dumpster Diving
  • Why cyber attackers target people to set their attacks such as human senses, feelings, emotions, etc. with examples such as affection, kindness, greed, political and religious views, financial and employment needs
  • Examples of common attacks such as phishing, social engineering, social media attacks, etc. and how they target those human senses
  • Distinguishing the fake communications from the real ones
  • Solutions and the importance of the SETA (Security Education, Training, and Awareness) programs for individuals and organizations

View Details

In today’s world of intense cybersecurity awareness, the daunting task of securing your workforce while employees are working from home can be very overwhelming. To address this issue most Information Technology and Information Security staff focus on digital factors, but it is important to not overlook the human factors.

The biggest human factor in Cyber Security is human behavior and the issues that result directly and indirectly from how we think, behave, and act. In this presentation I will cover the most common digital and non-digital threats I have encountered that are designed to take aim at exploiting human nature and are designed to “steer” how we act and react, as well as common mistakes in configurations and policies that can drastically impact any organizations “readiness” to protect against cyber attack. The goal of this presentation is that by the end of it you will be in a much better place of understanding the threats you and your organization face, and what you can do to resolve these issues through unified threat management, utilization of a multilayer cybersecurity approach, automation platforms in the cloud, and end user education.

View Details

Ransomware-as-a-service and big game hunting: Gain a basic understanding of the two most popular Ransomware extortion methods used by Ransomware gangs and employed to create a product to extract revenue from the victims (customers). See for yourself how to gain a foothold and understand a shift in defense posture in order to prevent catastrophic Ransomware damage.

Join this webinar to learn more about Ransomware as a business model that needs to be understood in the proper context. In that context, you are the product.

View Details

Every year top security companies, industry thought-leaders, and tech media publications come out with their predictions for the upcoming year, and every year Dan Lohrmann publishes his roundup of these security industry reports, forecasts, themes and trends.

This BrightTalk webinar will dig into the 2021 prediction report in detail.

In addition to counting down (and referencing) the top 21 security prediction reports from the leading vendors, this webinar will examine: - Where is their agreement on what’s coming next? - Where is their major disagreement? - Where will cyberattacks come from next? - Which vendors have the best reports (and why)? - Who are the award-winners for most creative, most likely, most scary and other security industry predictions?

We'll discuss security and tech predictions on Covid-19 and working from home as well as major security incidents such as attacks on global events (like the 2021 Olympics), cyber incident response and much, much more.

We will take your questions at the end, and may even ask you to vote for your favorite predictions (or offer one of your own to share.) Join us now!

View Details

This webcast discusses the Human errors factor of cybersecurity. Organizations often focus on the processes and technology and leave out the Human aspect. Many industries embrace Human factor programs in addressing challenges and cybersecurity can learn a lot from these programs and utilize them to improve security and reduce risks.

During this webinar we will discuss; HFACS-Cyber, the need for Human Factors Programs in Cybersecurity, targeting human risk factors, and the business value of Human Factors.

Participants will take away the following: 1. The importance of including Human Factors 2. The risks removed once you include Human Factors 3. The business value and some tips on how to obtain executive support for such a program

View Details

With a greater number of organizational activities relying on technology, the focus on how to protect the use of technology is primal for all organizations. Institutions are right to focus on external threat actors to safeguard their assets. But more importantly, it is imperative that the internal structures of organizations are tuned into the strategies used to protect their activities and assets. An overwhelming majority of cyber breaches are as a result of human actions within the organization. That is a fact.

Conventional defenses are bound to fail due to the human element in the process of securing organizational infrastructure. Human behavior is only predictable to some extent. A recent report by Cyberchology notes that 80% of companies see an increased cybersecurity risk resulting from the human factor as a major challenge during the COVID-19 pandemic.

The Human Factor, therefore cannot be ignored as we formulate strategies to secure organizational infrastructure.

In this presentation, we will attempt to cover the following questions: • What is “The Human Factor?” • By the Numbers – Why should we worry about this Factor • Strategies to mitigate the Human Challenges • Case Studies

View Details

Humans are the primary target for Cyber Attackers. Most cyber-attacks against businesses start by luring humans into making errors and thus allowing attackers a foot inside the target organization’s network. Impact of such attacks can range from monetary loss to even shutting down of businesses

In this presentation, we will discuss why human errors cause so many breaches, and how security solutions are bypassed in these cases? We will also look at the story behind human error and address them to improve employee cyber behaviour in an organization

Key takeaways: - Why cyber attackers target humans - Impact of human errors - How such attacks bypass Cyber Security solutions - Steps that organizations can take to address the gaps - Make employees your best defence against Cyber Attacks

View Details

Cloud migration is at the peak, and so the data breaches are in the cloud. The most common culprit of these breaches are human errors like improper security controls, misconfigurations etc. Complexity of security controls in public cloud providers and presence of multiple cloud providers within an organization makes it almost impossible for humans to do flawless deployments.

This webinar presents case studies on high profile data breaches that happened due to human errors. In order to tackle human errors from cloud operations, the human factor needs to be completely removed.

In this webinar you will learn how security control, operations and auditing can be baked into the deployment pipeline and make the pipeline as the only gateway for service operations.

It will discuss implementation challenges and other considerations of the deployment pipeline to achieve complete immutability of deployment.

View Details

Organizations are keenly aware of the existential threat that cyber risks now pose. The authors of the CISO Desk Reference Guide, Bill Bonney, Matt Stamper, and Gary Hayslip, grasp that reality and use their many years of experience to provide practical advice about how to function effectively in this role.

The unique multi-author approach of the CISO Desk Reference Guide has produced a wealth of insight into the complex and challenging role of the Chief Information Security Officer, a role that increasingly anchors organizational risk management in all things cyber and digital. It's essential reading for both aspiring and incumbent Chief Information Security Officers. The CISO Desk Reference Guide (Volumes 1 & 2), help fill a critical gap in the ever-evolving information security common body of knowledge.

In this session, the authors, Bill Bonney, Matt Stamper, and Gary Hayslip, are joined by Sushila Nair where they discuss:

-The evolving CISO role and how best to embed it in the organization -Fundamentals like data classification and controls -Advice on tools and techniques -Different perspectives on the foundations of organizational cybersecurity -and more!

This episode is part of Cyber Authors, a new series with Sushila Nair. We welcome viewer participation and questions during this interactive interview.

View Details

Digital storage is a critical technology for professional Media and Entertainment (M&E). With the Covid-19 pandemic much M&E work went remote, enabled by cloud based services and private and public cloud storage. NVMe SSDs and emerging memories are assuming increased use in high resolution, high frame rate, high dynamic range video content workflows. Between 2019 and 2025, about a 3X increase is expected in the required storage capacity in the industry and a 3.4X increase in storage capacity shipped per year. Cloud storage capacity for the M&E industry will increase 13X between 2019 and 2025.

This webinar looks at the trends driving demand for digital storage in all parts of the M&E industry, with data from the 2020 Digital Storage in Media and Entertainment report from Coughlin Associates presented by Tom Coughlin, who also serves as the volunteer Education Chair for the SNIA Compute, Memory, and Storage Initiative.

View Details

Cloud Adoption is on the rise again. According to IDG’s 2020 Cloud Computing Survey, 59 percent of respondents said their organizations would be mostly or all in the cloud within 18 months. Cloud changes our approach on so many levels—new technology, new shared responsibility model and new cybersecurity considerations

In today’s session, we’ll explore 6 ways CISOs are navigating the cloud: - Securing an extended perimeter - Upskilling the team - Balancing Risk Management in Third Party Relationships - Defining the Shared Roles in a Shared Responsibility Model - Enhancing Visibility - Taking Advantage of Automation

Moderator: Jo Peterson, Vice President, Cloud and Security Services, Clarify360 Speakers: Brian Campbell--VP, Cyber Security Architect, Veeam Software Mike Goldgof--Senior Director, Product Marketing at Barracuda Carl Eberling-- CIO/CISO- Forcepoint

View Details

Cyberthreats are viewed as a significant risk to organizations. They are capable of disrupting core operations and inflicting serious damage to brands and reputations.

A study by Cybersecurity Ventures predicts these crimes will cost the world $6 trillion a year by 2021.

Join this panel discussion to: - Review today’s expansive attack surface and the various ways bad actors penetrate networks - Discuss existing and emerging cyber threats - Understand policies, tools and best practices used to protect organizations as new threats emerge - Explore the roles that user training and education, skill development and governance play in defending against threats

Panel: Jo Peterson, VP Cloud & Security Services, Clarify360 (moderator) Adarsh "Adi" Pradeep, Cybersecurity Consultant Brad Moldenhauer, CISO, Americas, Zscaler Dr. Richard Ford, CTO, Cyren Homayun Yaqub, Global Security Strategist, Forcepoint

View Details

This talk will address how we need to develop and configure systems and software to eliminate common forms of malware and exploits. It is an engineering challenge that requires substantial change in tools and how we write applications and operating systems and how we design hardware. None of it is rocket science, but the pieces must be put together.

Viewers will learn about: - Attack vectors and hidden risks - How to build better dams, rather than trying to patch every leak and crack

Do we want our dams to be strong and safe, or is it more important to ensure that we can easily blow up the dams of any opponents, even if ours will break too? As a society increasingly living downstream of the dams, building better dams is a matter of survival.

Presented by a 20+ year security pioneer and inventor of SSH (Secure Shell, the de facto standard for system administration) and the principal author of NIST IR 7966 (guidelines for managing SSH access).

View Details

This session is Part 10 of the PCI Dream Team series on BrightTALK.

Our panelists are some of the top PCI QSA’s in the country, with decades of combined PCI and card processing experiences. They’ve seen it all: the good, bad and ugly; and lived to tell the tale.

Join Ben Rothke, David Mundhenk, Arthur Cooper, and Jeff Hall for an interactive Q&A session, and get answers to your most vexing PCI questions. No PCI question is out of bounds.

View Details

The nature of software is that security vulnerabilities exist, and need to be eradicated. Once you find those vulnerabilities (as Ted taught in his last talk - link in Attachments), next you need to fix them. But developers are already overloaded, deadlines are looming, and there just isn't time to add remediation work. However, if you don't fix the vulnerabilities, you've wasted the money, effort, and time invested in finding them in the first place -- all while leaving a vulnerable system unnecessarily exposed.

How is a busy team to handle this conundrum?

In this talk, author Ted Harrington extracts insights from his book Hackable in order to teach you how to deal with all of this. You'll learn how to: - Prioritize Vulnerabilities by Severity - Remediate Vulnerabilities - Verify Remediations ...and more!

View Details

It seems like everything is moving to the cloud these days and vendor access management systems are no exception. It may seem to be counterintuitive to put systems that grant vendors and their reps access to on-premise systems in the cloud, but the truth is that more and more enterprise data and systems are already located there. There are also numerous other benefits to be gained such as better scalability, faster disaster recovery, and believe it or not, better compliance and security. There are also some caveats where a cloud deployment may not make sense for your vendor access management platform. We will go over all of these and answer any questions you may have regarding third-party risk management (TPRM) and the cloud. Key takeaways from this session include:

• Why Third Party Risk Management is a key part of enterprise security and compliance • Benefits of a cloud based TPRM system • Downsides/Caveats of a cloud based TPRM system

Cover Slide: Attached separately

Presenter Bio: Tony Howlett is a published author and speaker on various security, compliance, and technology topics. He serves as President of (ISC)2 Austin Chapter and is an Advisory Board Member of GIAC/SANS. He is a certified AWS Solutions Architect and holds the CISSP, GNSA certifications, and a B.B.A in Management Information Systems. He has previously served at CTO for Codero, a managed cloud hosting provider and CTO of Network Security Services, a security and compliance consulting firm, as well as a founder of InfoHighway Communications, one of the nation’s first high speed internet access providers. Tony is currently the CISO at SecureLink.

View Details

Many enterprise applications are shifting, if not already, to subscription (opex) models. This is largely in the form of vendors now offering Software as a Service (SaaS) to customers. Customers, in many cases, need no longer worry about maintaining the infrastructure necessary to host licensed software due to the widespread adoption of SaaS.

Despite the numerous benefits SaaS offers, there are inherent cyber risks that need to be understood and considered. Customers transfer ownership of maintaining the infrastructure, platform, and software to the vendor, but this does not transfer the risk along with it.

In this talk, we’ll take an in-depth look at the following topics and discuss best practices and recommendations:

  1. How SaaS may introduce additional cyber risk to your organization.
  2. Effective means to assess SaaS vendors for cyber risk to your organization.
  3. Common traps and oversights in SaaS vendor risk assessments.

View Details

Tackling IT security compliance can be a headache -- but when you add the cloud into the mix, there is an entirely new set of challenges at hand. Cloud compliance is an issue that many organizations are concerned with, so much so that almost nine in ten (86 percent) believe that compliance will be an issue for them when moving systems, applications and infrastructures to the cloud, according to recently released research from Telos Corporation. Additionally, a staggering 94 percent of respondents report that they face challenges with IT security compliance and/or privacy regulations in the cloud. With the sheer amount of companies making the transition to remote work, cloud versus on-premises or legacy infrastructure is rapidly becoming the norm. So how can organizations embrace cloud and overcome compliance concerns?

This session will explore:

  • The costs of compliance and noncompliance in the cloud
  • The very real implications of audit fatigue and how the cloud exacerbates compliance concerns
  • Potential solutions to ease compliance challenges, especially in the cloud

View Details

The Cloud Data Management Interface (CDMI™) International Standard is intended for application developers who are implementing cloud storage systems, and who are developing applications to manage and consume cloud storage. It documents how to access cloud storage namespaces and how to manage the data stored in these namespaces. In this webcast we’ll provide an overview of the CDMI standard and cover CDMI 2.0:

•Support for encrypted objects •Delegated access control •General clarifications •Errata contributed by vendors implementing the CDMI standard

After you watch the presentation, check out the Q&A blog: https://bit.ly/3a8ohPX

View Details

Earlier this year many companies experienced an incredible shift to fully remote work almost overnight, in response to the COVID-19 pandemic. This accelerated the “digital transformation” journey for many companies compressing what was a multi-year timeline into a few months and making 2020 different than any other previous year. In this episode we’ll explore how the balance between security, privacy and productivity was tipped this year, and what can we expect to see in 2021 as some, but not all, organizations head back to office work with a post-pandemic mindset.

The audience will hear from CISOs and Security Directors about how this year was different, what they're going to do differently going forward, and what they expect (or have already seen) as organizations get back to pre-COVID levels.

Topics covered: - 2020 in review - The hard lesson that a mobile workforce is not the same as a remote workforce - How the attack surface expanded and what CISOs are doing to ensure risk doesn’t expand too - How digital transformation sped up and what they meant for security, privacy and productivity - During the speedy journey to the cloud - what mistakes were made? - Lessons learned that will be carried forward for security teams - What CISOs are doing to prepare for whatever 2021 may bring

Panelists: - Mark Weatherford, Chief Strategy Officer and Board Member, National Cybersecurity Center - Amir Shaked - VP, R&D, PerimeterX - Ted Harrington, Executive Partner, Independent Security Evaluators [ISE]

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

Many organizations struggle with digital transformation and cloud computing particularly when implementing a framework to meet their compliance requirements. In this session, we will discuss a framework and operational approach to support you to move your business forward delivering quality services balancing cost and risk.

View Details

Today, data in the public cloud is often encrypted at rest in storage and in transit across the network, but not while in use in memory. Organizations that handle sensitive data such as Personally Identifiable Information (PII), financial data, or health information need to mitigate threats that target the confidentiality and integrity of either the application or the data in system memory.

In this webinar, experts from the Confidential Computing Consortium (CCC) will define confidential computing, discuss how businesses are using Confidential Computing to protect against data breaches today, and review the ecosystem of solutions and open-source projects available to enable applications to make use of Confidential Computing.

Key topics covered in the webinar include: ● The Confidential Computing definition and comparison to related technologies ● Key properties of Trusted Execution Environments (TEEs) to look for ● Threats mitigated by Confidential Computing technologies ● Utilization paradigms: using application SDKs vs. runtime deployment systems ● The ecosystem available to support Confidential Computing application development ● Common real-world use cases for Confidential Computing

Seth Knox, VP of Marketing, Fortanix (Outreach Chair) (Linkedin https://www.linkedin.com/in/sethknox/, twitter @seth_knox) Dave Thaler, Software Architect, Microsoft (TAC Chair)

View Details

We all know that consumer and businesses are dramatically increasing the consumption of cloud based Information Technologies; either infrastructure, applications, services or even cybersecurity. The move to a cloud-based IT is unstoppable, with another wave of changes coming as 5G becomes more of an actual reality. While we have a new slew of acronyms and technologies coming our way (XDR, NDR, SaSe, etc) many companies struggle to address cloud from a cybersecurity perspective. In this webinar we will address key elements to be taken into consideration:

  • Full understanding on what cloud consumed IT means end to end, specially in the world of hybrid cloud
  • Provide security for the cloud consumed infrastructure, applications and services
  • Keeping a security posture that included traditional and cloud consumed IT. Key priorities and where to start
  • Providing security from the cloud itself
  • What is the role of the big cloud providers (aka AWS, Microsoft and Google) as they doubled down their efforts in cybersecurity
  • Looking ahead. How will (true) 5G impact cloud cybersecurity as the underlying telecommunications industry undergoes a major shift

Miguel Carrero, Cybersecurity Executive and Board Member, Siemplify, WireX Himanshu Raval, Director, Strategy and Growth of Cloud Security,CISCO.

View Details

In a recent report, the Cloud Security Alliance (CSA) outlined the top 11 threats to cloud computing for 2020. Data breaches, misconfiguration and inadequate change control, a lack of cloud security architecture and strategy, and insufficient identity and access management were among the biggest security challenges for all industries operating in the cloud.

These issues are not unique to any particular industry, but fortunately, they have common solutions. It’s clear that protecting public cloud assets is key. COVID-19 pandemic was a major accelerant for organizations to quickly move forward with the migration of business infrastructure and applications to the cloud.

Cloud Controls and Breach Prevention are top of mind for IT leadership and team alike.

In this panel discussion, we’ll discuss the importance of cloud controls and breach protection during this accelerated move to the cloud

  • What the C Suite Needs to Know about Cloud Security
  • Why Cloud Security is not an IT problem, it’s a business problem
  • The Revenue and Brand ROI of Preventing Data Breaches
  • Real productivity results from correcting misconfiguration and inadequate change control
  • The importance of building a cloud security architecture and strategy
  • Why managing sufficient identity, credential, access, and key policies
  • Cross Training and Upskilling your team

Moderated by: Jo Peterson, Vice President, Cloud & Security Services, Clarify360

Dr. Anton Chuvakin, Head of Solution Strategy, Google Cloud Amir Shaked, VP R&D PerimeterX Tina Gravel, Senior Vice President, Appgate Charles Johnson, Cybersecurity Advocate, Anitian

View Details

As companies gain more cloud maturity, they learn that their 2 core security tool sets for on-premise infrastructure no longer apply. Additionally, they get the most value by changing their operating patterns. In this talk, we’ll talk about lessons learned in embracing cloud-native security practices, and discuss implications for changing tool sets around cloud security.

View Details

Adopting to Secure the Mobile Workforce

The shift to a widespread corporate mandate for employees to work from home has dynamically altered the threat landscape and how security applications and integrations are delivered. Data is more pervasive than ever. The expansive footprint of where data is accessed and stored, results in an ever evolving and growing attack surface. Our disrupted social normal has created one of the most nourishing environments for adversaries to target with phishing attacks, ransomware, and vulnerability exploits. Nearly 70% of attacks originate from the endpoint due to insufficient visibility, policies, and controls around the mobile work force.

Are you implementing the proper defense in depth strategy with a Zero-Trust mindset to thwart attacks even at your weakest links? Digital sprawl has reached new heights in this new pandemic world and it’s important we focus on adapting to these new circumstances to keep our businesses safe and the outcomes they provide for social entitlement. Learn how your business can begin to work in a way to reduce operational strain of security and answer the question of how we can effectively secure our employees. Attendees will learn the following: 1. Understand what your attack surface resembles in this current work from home climate. 2. Identify best practices that can help assess your current security posture and take actionable results to invoke change. 3. Which technologies can supplement your governance model to secure your business and employees.

View Details

Not a day goes by in the cybersecurity industry without hearing about a talent shortage, skills gap, and necessity for training. A recent survey conducted by the Enterprise Strategy Group (ESG) and the Information Systems Security Association (ISSA) of cybersecurity professionals shows that 70 percent believe their organization has been impacted by the global cybersecurity skills shortage. We spent time talking to a number of people from human resources, managers, vendors, universities and end-users to get their perspective on cybersecurity skills, type of roles, and overall business needs.

We discovered, it’s not just about skills gap, but also the communications gap between what employers think they are looking for and the talent that is available to them. During this discussion, dynamic experts from various organizations will share the following:

• The needs across the technology vendors and end-user organizations, the education variance, and how to accommodate for the requirements and demands across the entire industry. • Most common type of roles to be fulfilled and the drivers behind the role types. • How we can make security built into the fabric of our culture, no matter the organization.

Moderated by: Leah McLean, Head of Business Development and Marketing, Cyber Future Foundation https://www.linkedin.com/in/leahrmclean/

Panelists: Malcolm Harkins, Chief Trust Officer, Cymatic https://www.linkedin.com/in/malcolmharkins/ Mary Chaney, Esq, CISSP, CIPP/US https://www.linkedin.com/in/marynchaney/ Diana Kelley – CTO and Founding Partner, SecurityCurve https://www.linkedin.com/in/dianakelleysecuritycurve/ Ryan Clarque, Senior Manager, Global Cybersecurity at Levi Strauss & Co

View Details

In the security and technology world, we rely so heavily on buzz words to explain our work that others feel like we are magicians working spells that they will never be able to do.

Saying, "Due to issues with our security posture, the APT manipulated a well-known CVE to breach our cloud-native-applications." Might as well be: "The Death Eaters were able to use a port key to enter our environment and effectively cast the Avada Kedavra spell."

Instead, we could say, "An attacker used a known flaw to gain access to our environment and brought down our servers."

In this session, we will come to understand that security for our cloud environments can be simple to understand, yes even for muggles. That is, if we focus on the root cause of all cyber attacks: unauthorized spells, wait, I mean unauthorized code.

View Details

There is a new wave of cognitive services based on video and image analytics, leveraging the latest in machine learning and deep learning. In this webcast, we will look at some of the benefits and factors driving this adoption, as well as explore compelling projects and required components for a successful video-based cognitive service. This includes some great work in the open source community to provide methods and frameworks, some standards that are being worked on to unify the ecosystem and allow interoperability with models and architectures. Finally, we’ll cover the data required to train such models, the data source and how it needs to be treated.

However, there are challenges in how we do this. Many archives were analog and tape based which doesn’t stand up well to mass ingestion or the back and forth of training algorithms. How can we start to define new architectures and leverage the right medium to make our archives accessible whilst still focusing on performance at the point of capture?

We will discuss:

•New and interesting use cases driving adoption of video analytics as a cognitive service •Work in the open source arena on new frameworks and standards •Modernizing archives to enable training and refinement at will •Security and governance where personal identifiable information and privacy become a concern •Plugging into the rest of the ecosystem to build rich, video centric experiences for operations staff and consumers

After you watch the video, check-out the Q&A blog: https://sniacloud.com/video-analytics-qa/

View Details

The 2020 elections in the U.S. have been historic in numerous ways. With more email-in voting than ever before and very close results for the U.S. President and Congressional races, there is plenty to discuss about security.

Was there voter fraud? Were the people, process and technology changes sufficient in states? How can we rebuild trust in elections? What is the future of voting in America?

Join us for this interactive discussion with audience Q/A.

This panel is part of the CISO Insights original series on BrightTALK with hosts Dan Lohrmann & Earl Duby. We encourage audience questions and participation.

View Details

Every day we see news of cyber-attacks. We get the impression that they may only be affecting larger companies, but this is far from the truth. In fact, the statistics clearly show that smaller companies are also being targeted. Cyber-attacks are not diminishing, and sadly whatever the size of your company, you are a target in today’s connected world. But despite this, many businesses are not prepared, technically or operationally to deal with the impact of cyber-attacks made against them.

In this talk we look at the steps that all companies, small or large can take to mitigate and deal with cyber-attacks, as well as incident response and the human elements that feature in an attack. We also cover the key areas of cyber breach management and examine it from an attacker, organisational and customer perspective, revealing the impact not only your organisation but to others in your value chain.

View Details

The global security as a service market size is expected to grow from USD 11.1 billion in 2020 to USD 26.4 billion by 2025, at a Compound Annual Growth Rate (CAGR) of 18.9% during that time period. Driven by a cloud-based delivery model, options abound for organizations in areas such as application security, data security, identity and access management, infrastructure protection and integrated risk management to name a few. These options include off the shelf security as a service products as well as those provided and managed by an MSSP.

In today’s session we’ll explore these 5 key points: 1. Security budgets and priorities in a post Covid-19 world 2. When to outsource 3. Selecting an MSSP 4. Tools, Tools and More Tools 5. Upskilling your team

View Details

2020 has seen many Cyber Attacks using the COVID-19 pandemic as the central theme. For most part though these have been the same attacks that have existed since the last few years; just the packaging was changed.

We expect the real cyber security repercussions of changes brought in by the COVID-19 pandemic to be felt in 2021. In this talk we explore what the repercussions might be and what we can do to prepare and protect ourselves against them.

We will cover: - Major Cyber Attack trends of 2020 - What can be expected to continue in 2021 - Potential repercussions of COVID-19 induced changes and new attack types in 2021

View Details

This session will focus on specific technical, legal and policy responses to ransomware attacks.

Join to learn more about: * History of Ransomware * Most common forms of Ransomware * Costs of Ransomware and Mitigation * Ransomware Insurance * Ransomware prevention * Ransomware training and education * Legal Issues in Ransomware Payment (with October 2020 developments) * Ransomware mitigation * Threat intelligence and investigation in ransomware cases * Ransomware inoculation * Disaster recovery in ransomware

View Details

Perhaps you are like the 200 CISOs who shared their insights in the security leaders report, which revealed that organizations are using 57 separate security tools with 27% claiming they’re running a staggering 76 or more security products.

These tools aren’t necessarily making your organization less vulnerable. In fact, many organizations find that they’re often flying blind when it comes to security.

Join this session to learn: • Valuable techniques to optimize your cyber spend and offer risk balanced, cost effective security solutions for your organization • Key insights into the decision-making process to gain better visibility and control over your assets, attack surface and cyber defense posture • How to clearly define the business requirements and control objectives that should be driving your solution options and purchasing decision that will drive the most attractive ROI for your business and stakeholders

View Details

The year 2020 has accelerated organizations' digital transformations, particularly cloud migrations and the development of remote work capabilities. This rapid change has drastically altered the way that we work and consume data--creating exciting new paradigms, but also bringing new risks along with it. This session will analyze the security breaches that have occurred so far in 2020, and will discuss what defenses would have been vital for the prevention of these attacks. We’ll examine which security projects should be the “tip of the spear” in 2021 to help you reduce your attack surface, as well as look to the future to predict how the attack landscape may continue to change.

Sushila Nair is on the board of the GWDC, the Greater Washington, D.C. Chapter of ISACA and plays an active role in supporting best practices and skills development within the cybersecurity community.

Sushila has worked as a Chief Information Security Officer for ten years and has twenty years’ experience in computing infrastructure, business and security. Sushila has consulted in many diverse areas including telecommunications, risk analysis, credit card fraud, and has served as a legal expert witness. She has worked with the insurance industry in Europe and America on methods of underwriting e-risk insurance based on ISO27001.

She has published numerous articles in the computing press on risk and security, and has spoken at Segurinfo, CACS, TechMentor, FinSec and many other global technical events on diverse subjects ranging from managing risk to designing security baselines.

View Details

The 2020 U.S. presidential election has brought cyber security to the forefront for many in the U.S.

From shedding light on disinformation campaigns aimed at disrupting the election, to testing voting machines and pentesting online voting apps, to raising awareness around the risk of ransomware and other attacks to local governments, voter registration databases, poll books and election reporting websites - security researchers and practitioners have been raising red flags throughout the election cycle.

Join this episode of the Election Hacking series to learn about: - The 2020 election takeaways from a cybersecurity viewpoint: What went down, what could have gone better and how to better prepare for the midterm election in 2022 - What the biggest election threats mean for your industry and organization - What have we learned and will it change anything in time for 2022 - Post-election cybersecurity lessons for tech leaders

Panelists: - Lee Imrey, Security Strategist at Splunk - Harrison Morris, PhD Candidate Georgia Tech researching the intersection of Cybersecurity and Cognitive & Brain Sciences - Mick Baccio, Security Advisor, Splunk

Moderator: David Morris, Executive Director at Digital Risk Management Institute

This episode is part of the Election Hacking Original series examining the threats to democratic elections, the technologies used to power and hijack elections, and what's needed to educate and empower voters before Election Day.

View Details

In modern analytics deployments, latency is the fatal flaw that limits the efficacy of the overall system.  Solutions move at the speed of decision, and microseconds could mean the difference between success and failure against competitive offerings.  Artificial Intelligence, Machine Learning, and In-Memory Analytics solutions have significantly reduced latency, but the sheer volume of data and its potential broad distribution across the globe prevents a single analytics node from efficiently harvesting and processing data.

This panel discussion will feature industry experts discussing the different approaches to distributed analytics in the network and storage nodes.

View Details

When it comes to deception technology, the industry is evolving beyond simple honeypots to a more automated, scalable, and effective approach.

Join this episode of The (Security) Balancing Act to discover how deception technology can be used by organizations to detect, investigate and respond to malicious intruders. How does deceiving the attacker save your company and buy you time?

During this episode, we'll go over: - What is deception technology and what does it help with? - How does it work? (e.g. Deception decoys, lures, honeytokens, traps, grids) - Is your organization ready to adopt deception? - What do you need to do before you buy the technology / build it in-house? - Key benefits of using deception for threat hunting - What else can deception be used for? - Deception use cases - The role of AI in deception (e.g. dynamic deception)

Panelists: - Chris Roberts, vCISO, Researcher, Hacker, Consultant, Devils Advocate - Christina Fowler, Chief Cyber Intel Strategist at MITRE Corporation

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

Are you moving or growing in the IaaS Cloud? The scale and pace with which this industry moves is both exhilarating and terrifying. There are broad implications for security in the cloud that are just starting to scratch the surface of things to come.

In this talk, we will explore: - Security principles that stay the same & what changes in the cloud - How you can leverage Infrastructure Compliance Automation - How you can quickly get to the root of security problems - by analyzing contextual risk and evaluating your overall posture instead of just looking at a generic set of security controls

After all, a great security program should be more than a checkbox. It's all about context, priority, and environment.

About Adarsh Pradeep: Adarsh or "Adi" is a veteran professional who has built his career on pure-play cybersecurity. He has worked exclusively in critical infrastructure industries such as aviation & finance and has worn almost every security-related hat(not too common) in the book. This gives him a nuanced, technical yet business friendly approach to security that is hard to beat. Adarsh also holds a B.S. Degree in Information Technology and Assurance from George Mason University.

About Joseph Hale: Joseph or "Joe" is a tech-leader and open-source expert. He has ingenious solutions to almost every problem you can think of and has helped architected and then built out massive high-performing middleware and cloud apps for numerous enterprises. His primary expertise lies in DevOps and Cloud Operations, but his ability to break down complex systems gives him great insight into security as well. He's also a huge math and statistics nerd. Joseph holds dual B.S. degrees in Computer Science and Mathematics from Dallas Baptist University.

View Details

Perhaps you are like the 200 CISOs who shared their insights in the security leaders report, which revealed that organizations are using 57 separate security tools with 27% claiming they’re running a staggering 76 or more security products.

These tools aren’t necessarily making your organization less vulnerable. In fact, many organizations find that they’re often flying blind when it comes to security.

Join this session to learn: • Valuable techniques to optimize your cyber spend and offer risk balanced, cost effective security solutions for your organization • Key insights into the decision-making process to gain better visibility and control over your assets, attack surface and cyber defense posture • How to clearly define the business requirements and control objectives that should be driving your solution options and purchasing decision that will drive the most attractive ROI for your business and stakeholders

View Details

The global security as a service market size is expected to grow from USD 11.1 billion in 2020 to USD 26.4 billion by 2025, at a Compound Annual Growth Rate (CAGR) of 18.9% during that time period. Driven by a cloud-based delivery model, options abound for organizations in areas such as application security, data security, identity and access management, infrastructure protection and integrated risk management to name a few. These options include off the shelf security as a service products as well as those provided and managed by an MSSP.

In today’s session we’ll explore these 5 key points: 1. Security budgets and priorities in a post Covid-19 world 2. When to outsource 3. Selecting an MSSP 4. Tools, Tools and More Tools 5. Upskilling your team

View Details

In multinational organizations, risk, governance, and compliance professionals frequently present relevant risk profile information to mixed groups of stakeholders. For smaller companies, this may mean bringing in third-party partners and sharing plans with them. The challenge is describing the risk profile and associated tasks in a way that all parties understand their role in managing the threat landscape and the risk exposure/risk position of the company.

Is communication with the board my main obstacle to overcome? Is there an easier way to help me prioritize where to focus? What can I do to keep my threat landscape and risk profile agile?

We will discuss how to articulate risk in ways to highlight the status and the risk profile as well as the shared responsibilities in managing that risk. This includes both the strategic and operational aspects of cyber risk management, tying risk to business objectives as well as operational activities.

Attendees will learn: - What communication techniques work better than white papers and reports - How to visually link business objectives to cyber risk profiles - How to approach building a value chain from objectives to actions to accountability

If you are building your business case for cyber security investment, this is the webinar to watch to get some great ideas on techniques to help you articulate your risk position and actions to a wider variety of people in the organization.

View Details

Cybercrime flourishes in an economic downturn, and as more organisations adopt digitalisation and move operations online, their need to protect data and critical assets increases.

We live in an uncertain world where budgets and resources are tight, yet the need to manage information risk and establish resilience has never been more important.

On Thursday 12th November, 09:00 GMT, Alex Jordan, Senior Analyst at the ISF will be exploring eight cyber challenges in an uncertain world and how the ISF Aligned Tools Suite 2020 equips you to respond.

This webinar will help you answer questions such as:

‒ How do you prioritise when resources are under pressure? ‒ How do you determine a manageable level of information risk? ‒ How do you assure your supply chain? ‒ How do you manage compliance across multiple standards?

View Details

Malu will define the challenge behind responding to a data breach in the right way to avoid fines wherever possible. Companies are not ready with the appropriate skills, processes and tools to efficiently comply with Privacy Regulation. This talk will arm you with foundational information to create your Breach Response plan.

Main Point: This presentation is a practical Data Breach Response Toolkit.

Take away’s will include: - A practical notification plan - A practical communication plan - Why you need DPIA’s

View Details

This session will focus on specific technical, legal and policy responses to ransomware attacks.

Join to learn more about: * History of Ransomware * Most common forms of Ransomware * Costs of Ransomware and Mitigation * Ransomware Insurance * Ransomware prevention * Ransomware training and education * Legal Issues in Ransomware Payment (with October 2020 developments) * Ransomware mitigation * Threat intelligence and investigation in ransomware cases * Ransomware inoculation * Disaster recovery in ransomware

View Details

The client-side or the front end of web applications, aka ‘digital user experience,’ actively ingests customer/user information at data input points that can include very sensitive information.

As the web front-end code runs on unmonitored and untrusted devices, spyware, malware and other malicious actors leverage client-side security flaws and third-parties to steal credentials, financial transactions and payment card data to conduct fraud.

Speakers: Ivan Tsarynny CEO and Co-Founder of Feroot Security David Mundhenk Principal Security Consultant for Herjavec Group Tabitha Gallo Principal Security and Privacy Consultant in the Advisory Services team at Herjavec Group

View Details

Incident response policies (IRPs) are a foundational block for security operations (SecOp) teams. But many SecOps teams haven't updated their IRPs since migrating their workloads to the cloud, and enabling many of their employees to work from home (WFH).

What should an IRP for the cloud era look like? This webinar provides a blueprint for crafting a customized IRP for the new working paradigm of internet, cloud, and mobile (ICM). Participants will learn:

  • The key elements of an IRP
  • How an IRP needs to change for a cloud environment
  • How cybersecurity analytics and automation can improve an organization's incident response time

View Details

Every day we see news of cyber-attacks. We get the impression that they may only be affecting larger companies, but this is far from the truth. In fact, the statistics clearly show that smaller companies are also being targeted. Cyber-attacks are not diminishing, and sadly whatever the size of your company, you are a target in today’s connected world. But despite this, many businesses are not prepared, technically or operationally to deal with the impact of cyber-attacks made against them.

In this talk we look at the steps that all companies, small or large can take to mitigate and deal with cyber-attacks, as well as incident response and the human elements that feature in an attack. We also cover the key areas of cyber breach management and examine it from an attacker, organisational and customer perspective, revealing the impact not only your organisation but to others in your value chain.

View Details

Tee has over 17 years experience as a CISO for major organisations including UK Government / Public, Start-ups, Financial Services, Legal, Travel / Hospitality, Energy, Mining, Consultancy, Technology, Healthcare, and Civil Engineering sectors.

Join this webinar and learn how to: 1. Stay Cool, Calm and Collected in any incident 2. Set up an Emergency Team 3. Plan (Cascade plans - Group | Local | Department) 4. Keep It Simple 5. Continually Update / Improve 6. Prepare Comms – PR | Marketing. Single Point – Internal | External – Client / Supplier / Regulatory and Client, Supplier contact list

View Details

Crypto is everywhere. And if used properly can help organizations of all sizes better protect their digital assets, reduce their attack surface and reduce costs. However, if done improperly, crypto can increase risk and give a false sense of comfort.

With the rapid expansion of work from home and its dependence upon the cloud and remote access solutions, properly applied encryption can significantly improve an organization’s security posture, reduce the cost of regulatory compliance, and improve their ability to respond to threats. However, this rapid growth in the use of remote collaboration solutions, many of which were deployed hastily and outside an organization’s normal authorization to operate (ATO) process, have added cyber risk from both regulatory actions and nefarious threat actors.

Yes, there are a number of ways to mitigate these risks, but I contend that expanding current use of encryption is a cost-effective way to reduce an organization’s attack surface while minimizing risk from regulatory actions and fines.

Although vendors have done a good job of simplifying the deployment and management of their tools, deploying these solutions in the context of a complex enterprise is nontrivial. For example, it is fairly straightforward to encrypt your Azure stored files. However, this same process is more complex for a regulated entity that must hold its own keys. It is also fairly straightforward to encrypt traffic (aka data in transit). But how does an organization know which traffic cannot be encrypted due to monitoring and regulatory requirements?

In this webinar you will learn: - What are the necessary pieces to support typical use cases - When and when not to use encryption - Where can crypto be used - Who are some of the leading vendors in the enterprise crypto space - How to cost effectively deploy cryptosystems without adding risk and impacting productivity

View Details

The year 2020 has accelerated organizations' digital transformations, particularly cloud migrations and the development of remote work capabilities. This rapid change has drastically altered the way that we work and consume data--creating exciting new paradigms, but also bringing new risks along with it. This session will analyze the security breaches that have occurred so far in 2020, and will discuss what defenses would have been vital for the prevention of these attacks. We’ll examine which security projects should be the “tip of the spear” in 2021 to help you reduce your attack surface, as well as look to the future to predict how the attack landscape may continue to change.

Sushila Nair is on the board of the GWDC, the Greater Washington, D.C. Chapter of ISACA and plays an active role in supporting best practices and skills development within the cybersecurity community.

Sushila has worked as a Chief Information Security Officer for ten years and has twenty years’ experience in computing infrastructure, business and security. Sushila has consulted in many diverse areas including telecommunications, risk analysis, credit card fraud, and has served as a legal expert witness. She has worked with the insurance industry in Europe and America on methods of underwriting e-risk insurance based on ISO27001.

She has published numerous articles in the computing press on risk and security, and has spoken at Segurinfo, CACS, TechMentor, FinSec and many other global technical events on diverse subjects ranging from managing risk to designing security baselines.

View Details

As organizations face several different challenges in 2020 and beyond, preparing for a cyber attack is as important as ever. Businesses face a myriad of cyber threats; from phishing to ransomware, it's imperative that your organization puts in place measures to protect your most important assets.

Join top security leaders for an interactive discussion on how to better secure the enterprise in 2021 and learn more about:

  • Trends in cyber attacks and what's at risk
  • Prevention best practices
  • Solution recommendations for attack detection and response
  • Top threats on the horizon and what's at risk
  • How organisations can take the necessary steps to prepare for the unexpected and build business resilience

View Details

Cyber threats continue to increase and cyber attacks are accelerating in frequency as well as the damage they cause. Each attack leads businesses to implement new and ever more sophisticated technologies to defend themselves. Despite spending ever increasing amounts, most businesses appear to be as vulnerable as ever.

This webinar discusses cyber risk and why that should form the foundation of your security approach. Understanding your risk profile and what is important to your business allows you to focus on the issues that matter most to you. The results provide the basis for your business to implement cost effective strategies that are practical and pragmatic and ultimately are bespoke to you.

In this webinar you will learn: 1. How to understand cyber risk in the context of the business 2. How to identify what matters to you 3. How to use the above in order to achieve cost effective cyber security

A former partner at KPMG LLP and BDO LLP. A certified security and data privacy professional with extensive experience gained across consulting, advisory and audit roles

George has over 20 years’ experience in technology risk, information security and privacy. He works with clients to help them understand their risk appetite, their overall security exposure and the specific issues that matter to them. He helps clients achieve cost effective security, including alignment with regulatory and other compliance and certification standards.

View Details

Cybercrime is at an all-time high.

Businesses in the UK are under the constant threat of cyber security attacks, and there is an increasing risk of losing your data, money, and even the business itself. Hackers are experts at choosing vulnerable targets. Learn about the risks and best methods of defence by joining our security briefing with experts from the police, TiG and Guildhawk.

In this briefing you will: - Hear how other businesses have been targeted - Understand the risks through real-life examples - Learn how to implement some simple defence strategies - Have the opportunity to ask questions

View Details

Threats abound and barely a day goes by without a new cyber-attack causing security professionals to reassess their controls and consider new technology to bolster their defences.

This webinar discusses current attack trends from the perspective of The University of Edinburgh, a world-leading research-intensive University. It is suggested that attack trends are not that different to those we have previously faced, and our efforts should focus less on the headline grabbing events and more on the daily basics of good cyber hygiene.

In this webinar you will learn: 1/. Real cyber-attack trends as seen from The University of Edinburgh 2/. How attack trends influence a security awareness program 3/. Promoting good cyber hygiene and improving the security posture

Garry Scobie is the Deputy Chief Information Security Officer for The University of Edinburgh. He is a Certified Information Systems Security Professional and ITIL Expert. He regularly presents on computer security including sessions on Ransomware, Mobile Security and Cyber in the Movies. Prior to this he was responsible for Microsoft Windows server infrastructure and Active Directory. He has a particular interest in vulnerability assessment and penetration testing and promoting security awareness.

View Details

With the current threat landscape evolving at a rapid pace and based on everything that has happened throughout 2020, businesses need to take a more proactive approach to cybersecurity in 2021.

Join this panel of security experts and industry leaders to learn more about: - 2020: The year of COVID, remote working and breaches - Biggest lessons from 2020 and the path forward - New threats on the horizon - Strategies for dealing with ransomware, phishing attacks - Recommendations for CISOs for the year ahead

View Details

2020 has seen many Cyber Attacks using the COVID-19 pandemic as the central theme. For most part though these have been the same attacks that have existed since the last few years; just the packaging was changed.

We expect the real cyber security repercussions of changes brought in by the COVID-19 pandemic to be felt in 2021. In this talk we explore what the repercussions might be and what we can do to prepare and protect ourselves against them.

We will cover: - Major Cyber Attack trends of 2020 - What can be expected to continue in 2021 - Potential repercussions of COVID-19 induced changes and new attack types in 2021

View Details

What keeps CISOs up at night? What challenges are they facing on a daily basis? And what opportunities are they seeing in the industry?

Join experts from leading security organisations as they discuss strategies, solutions and technologies CISOs use in the face of on-going security challenges:

  • Strategies for breach prevention
  • Strategies for making the most of AI technology and human talent
  • New technologies on the horizon
  • Security strategy recommendations

View Details

Neurodivergent people have unique abilities and skills that make them particularly successful in cybersecurity jobs. Learn how tech companies like IBM are building neurodiversity programs and leveraging the untapped neurodivergent talent pool to help fill a cybersecurity skills shortage and make their teams more diverse and inclusive.

Join a dynamic duo -- Diane Delaney and Megan Roddie -- as they talk about neurodiversity and cybersecurity at IBM. Diane Delaney is IBM’s Neurodiversity Program Manager, and Megan Roddie is a Cyber Threat Researcher at IBM and co-founder of IBM’s Actually Autistic Task Force. Together, they will talk about the importance of having neurodivergent teams. Diane will discuss how to attract and retain neurodivergent talent, and the importance of having diversity on a cyber team. Megan will discuss how her abilities as an autistic person have helped her be a successful cyber threat researcher, and how other organizations can attract and retain neurodivergent talent. For those looking to build skills, Diane and Megan will discuss how neurodivergent talent can begin building skills and training in cyber to land a job in high-tech.

View Details

Already a popular platform, WhatsApp, the Facebook-owned smartphone instant messaging service, posted the biggest gains due to COVID-19 according to Tech Crunch. Learn why this ubiquitous messaging app could be a security risk and what you need to know to secure WhatsApp. In this session, you’ll discover: + How metadata and message data storage expose you to critical risk + Why the legal agreement should give you pause + Why WhatsApp is an effective platform for spreading disinformation + How the phones and humans using them increase your vulnerability + How to increase secure use of the app and mitigate your risk + Why WhatsApp leveraged by sophisticated threat actors

Speaker: Cosimo Mortola is a senior intelligence analyst at GroupSense. Cosimo previously tracked threat actors at MassMutual, and Russian disinformation and associated threat activity at FireEye. Cosimo is fluent in Russian, French, and Italian.

View Details

Whether traveling by car, plane or train, it is critical to get from here to there safely and securely. Just like you, your data must be safe and sound as it makes its journey across an internal network or to an external cloud storage device. It's well known that data is often considered less secure while in motion, and attackers are finding increasingly innovative ways to compromise data in flight. And the risks associated with data in transit are dependent on the security measures that are in place. So how do you adequately protect data in transit?

In this webcast, we'll cover what the threats are to your data as it's transmitted, how attackers can interfere with data along its journey, and methods of putting effective protection measures in place for data in transit. Included in this webinar will be:

•What you should expect to happen to secure data in transit; what are the trade-offs •What transport layer security protocols (SSL, TLS, etc.) are best for protecting data in transit? •Different encryption technologies and their role in protecting data in transit •Which criteria should be used? •How do you know which encryption to use? •What’s applicable to different workloads? •Best practices for data protection in transit

Join us on a journey to provide safe passage for your data by registering today!

After you watch the webcast, check out the Q&A blog: https://bit.ly/2VXPD3e

View Details

Theresa Payton, leading cybersecurity expert and first female Whitehouse CIO, discusses her book "Manipulated: Inside the Cyberwar to Hijack Elections and Distort the Truth."

Theresa Payton tells battlefront stories from the global war being conducted through clicks, swipes, internet access, technical backdoors and massive espionage schemes. She investigates the cyberwarriors who are planning tomorrow’s attacks, weaving a fascinating yet bone-chilling tale of Artificial Intelligent mutations carrying out attacks without human intervention, “deepfake” videos that look real to the naked eye, and chatbots that beget other chatbots.

In this session, Theresa is joined by Sushila Nair where they will take a look inside the Cyberwar to hijack elections & distort the truth.

Join this webinar and learn: - About our new era of hacked elections and non-stop disinformation campaigns - From battlefront stories the effect of cyber conflict and its risks - Who are the cyberwarriors who are planning tomorrow’s attacks - The attacks of tomorrow including Artificial Intelligent mutations, “deepfake” videos that look real to the naked eye, and chatbots that beget other chatbots - To build a plan so that individual citizens, big tech corporations, governments and the international community can push back

This episode is part of Cyber Authors, a new series with Sushila Nair. We welcome viewer participation and questions during this interactive interview.

View Details

The pressure is on to maximize - possibly reduce - your IT spend, but you know that cybersecurity is critical. As many as 60% of hacked small and medium-sized businesses go out of business after six months. But, how much is right to spend? This 30-minute live discussion between Alex Nette, one of the leading cybersecurity experts for small-medium businesses, and Michael Cardman, a results-oriented financial expert will help you determine: + What are the must-haves for your 2021 cybersecurity budget? How do you calculate what to spend? + Given your business and your systems, applications and software, what’s the right approach for you? + How do you do more with less?

This webinar draws on years of experience in working with business and IT professionals to help them craft the right spend strategy. Both Alex and Michael will provide a number of best practices for you to consider, but also show you the behind the scenes tools they’ve used for years! See what happens when IT and cybersecurity gets real with a CFO.

View Details

No one ever expects it to happen to them. But with ransomware and cybercrime on the rise, it’s more likely than ever to discover that ransomware has locked down your system and cybercriminals are holding your data hostage. Kurtis Minder, an expert ransomware negotiator, advises executive teams when their worst cybersecurity nightmares come to life. Join us for an interview with Kurtis as we discuss:

  • What most people don’t realize about ransomware and the cybercriminals that run these exploits
  • Immediate do’s and don’t if your systems are being held captive
  • How to limit potential damage like data loss, overpaying threat actors, tarnished brand reputation, and compliance violations
  • Team Event: who to involve and when

View Details

It's well known that security is not just a technology problem, but a people problem too. In this session we'll examine the latest ways that bad actors can exploit information found online about your team, and use it to weaponize their email against the business. We'll also explore the ways that businesses can protect themselves and when necessary fight back.

In this webinar we will: - Examine some of the latest uses of social engineering in phishing and spear phishing campaigns - Explore some options to manage the risk - Take a look at how we can protect the business when our defensive mechanisms fail

Daniel Clayton has been responsible for building and delivering global operations for the National Security Agency (NSA), the Government Communications Headquarters (GCHQ), Rackspace and Bitdefender over a 30-year career.

As VP of Global Support and Services, he is responsible for Bitdefender’s global operations in support of customers, including the strategy, service delivery and oversight of Services and Support Operations, including the Security Operations Center, Customer Success Operations and associated engineering functions.

View Details

Other than eliminating humans, what are the best practices for reducing business email compromise?

Join this session to learn how to:

  • leverage the cloud
  • take advantage of SaaS security features
  • implement email security controls, monitor and respond to incidents, and
  • empower your workforce to be the first line of defense

Presented by Sean Letona, Director of Professional Services at Abacode, Inc.

View Details

There are an estimated 1.5 billion people working remotely due to COVID-19 and email is one of the ways businesses are communicating and staying connected with customers, employers and vendors. Ransomware, phishing and email exploits are continuing to rise. According to Security Magazine, over 96% of all security attacks begin with an email.

Today’s panel will focus on: - the current state of email security and tools, - best practices for email safety, resilience planning, brand protection and thoughts on training

View Details

Aligning the need for Cyber defense technology has to be with business goals that define the problem statement today, the impacts to the business, and how the investments not only mitigate those risks but will include an ROI in the Security Roadmap Strategy.

In this webinar you will learn how to: - identify and articulate those gaps convincingly - make implementation quick to keep the C-suite audience interested - do Defense in depth for threats presented via email - maintain and continually monitor a defense in depth strategy - demonstrate ROI to C-suite/stakeholders

Sawan Joshi – Information Security Executive | Speaker | Blogger Qualifications held – CISM, TOGAF, CND, CYSA+ GDPR Practitioner, ISO 27001 LI, MCSE x3 AWS Architect www.linkedin.com/in/sawanjoshi www.sawanjoshi.com

View Details

COVID-19 has slowed the economy down, but hackers are busy as usual—looking to take advantage of the pandemic to breach systems, steal data, and profit by holding both systems and data hostage.

More than 51% of the organizations have been impacted with Ransomware in the last 12 months.

What is your defense strategy? How do you fight against the most potent lateral threat propagation within your network during outbreak? In the virtual session, learn how Zero Trust isolation provides the best defense against Ransomware. It’s time to get to the root causes in your network and introduce the agentless Zero Trust Isolation platform that protects your organization even if your endpoints are breached, even if you have vulnerable and unpatched applications, and even if you are operating legacy and insecure protocols.

View Details

Companies accelerate software development and release new features that delight their customers and help them gain market share in large part through leveraging open source code. Nearly all modern applications are built at least in part with open source code, yet recent research by Veracode revealed that 70% of applications have open source security flaws. With the third-party code introduced by developers directly as they build an application comes vulnerabilities introduced indirectly. Use of open source libraries helps developers and sparks innovation - the security threat comes with a lack of awareness into whether open source vulnerabilities are impacting applications.

Attendees will learn what open source software is, understand risks that open source software introduces, and how their organization can mitigate these risks with secure code and improve overall security.

View Details

Security teams can become overwhelmed with vulnerability reports. A myriad of tools exist that provide all kinds of reporting on suspected vulnerabilities in software. False positives (and negatives) are usually present in the data. For the security team, this can create a situation where more time is spent managing the data and reports than fixing things or helping other teams focus their patching efforts.

In order to triage and focus effort on the greatest risk to the business, a different approach may be needed than the traditional compliance-based ones or systems based on CVSS scores.

In this webinar we’ll start out by defining what exactly the term vulnerability means, how to measure that, and then explore a more risk-based approach.

View Details

You're building an application and need to prove it's secure, and to do that you need to find vulnerabilities and fix them. However, there's so much confusion about what that even means, let alone how to do it right, that it can be an uncertain and overwhelming endeavor. Author Ted Harrington takes you to the front lines of ethical hacking and security research, blending real-world exploit stories with actionable insights in order to help you understand how to break -- and fix -- applications. You'll walk away with practical guidance about how to:

  • Abuse functionality
  • Chain vulnerabilities
  • Choose a testing approach & methodology
  • And much more

View Details

According to Verizon’s 2020 Data Breach Investigation Report (DBIR), over 80% of hacking-related breaches involved the use of lost or stolen credentials - and approximately 35% of all breaches were initiated due to weak or compromised credentials.

Last year, we kicked off The (Security) Balancing Act series with a panel of identity experts to help us understand the landscape. Join us for this 1 year check-in to learn what has changed for organizations in the last 12 months and the security implications of shifting to a more remote workforce.

  • 2020 vs 2019: Key changes & challenges for cybersecurity
  • How work from home has opened the door to attackers
  • Regulatory updates that may impact identity management programs
  • Why attackers are focused on credentials and authentication systems
  • What businesses can do to keep track of all endpoints, manage identities and privileged access, protect their data and maintain compliance

Panelists: - Aidan Walden, Director, Public Cloud Architecture & Engineering at Fortinet - Shareth Ben, Executive Director, Insider Threat & Cyber Threat Analytics at Securonix - Doug Simmons, Principal Consulting Analyst, Managing Director, Consulting at TechVision Research

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

Web applications continue to be a popular vector for cyber attacks. According to the most recent Verizon Data Breach Investigations Report (DBIR), 43% of breaches analyzed in the report targeted web application vulnerabilities, more than double the number from last year. What does this mean for businesses in the era of remote working?

Join this interactive keynote panel to learn more about: - How the shift of valuable data to the cloud, including email accounts and business-related processes has opened the door to attackers - The impact of COVID-19 on enterprise security posture - The role of compromised credentials in breaches - Application security challenges and the path forward - Best practices for a more secure enterprise

View Details

For many enterprises, the logic that controls the sensitive data flowing through their applications, or the high-value transactions these applications enable is decentralized. As more digitization is pushed through in the midst of a global health crisis, this application centric approach to securing sensitive information and transactions, protecting user privacy, and granting appropriate access without friction is threading the proverbial needle. OAuth is great at securing repeatable use cases, but today’s enterprise needs are much more dynamic, where different resources require different security mechanisms. Machine learning and artificial intelligence help make all access scenarios dynamic, and contextual.

In this webinar, attendees will learn: - Enabling contextual intelligent access security for your applications - Externalize and centralize authorization policy - Easily translate business rules into security rules - API level security to discover, detect and block threats

View Details

A single breach is all it takes to wipe out years of your business’ hard-earned reputation and profits. From basic email scams and intellectual property theft to sophisticated ransomware attacks, there is an extensive list of threats that put your business in jeopardy. Defense in Depth is a strategy that includes multilayered protection against current and emerging threats. Gustavo will provide guidance and recommendations on how to best defend your infrastructure against malicious actors, mapping this layered approach to the NIST Cybersecurity Framework.

In this webinar you will learn: - Threat landscape in today’s Cyberworld - Functions of the NIST Cybersecurity Framework - Tools that will help you to achieve a layered approach - Combining them together to achieve maximum efficiency

View Details

The COVID pandemic is changing the threat landscape for security teams. With the multitude of home devices, from smartphones to TVs to thermostats and others, home networks are more vulnerable. Bad actors see this weakness and are using the home VPN as another attack vector into the corporate network. Airgap Networks is striving to help Security teams adapt quickly to this changing environment.

In the session, we will demonstrate how to control access policies between devices and ensure secure access to employee/partner-facing applications for the modern enterprise with protocol-agnostic and agentless remote access security enforcement.

View Details

Putting the Pieces Together: A Primer on Breach Prevention addresses the critical elements that every organization needs to follow to establish a sound proactive stance on securing their environment against compromise and breach.

In this webinar you will learn how to assemble the right elements of your information security and network operations capability to establish a solid foundation for monitoring and protecting your network. Blend the tried and true with new capabilities such as AI and SOAR to provide actionable monitoring and protection rather than the typical re-actionable content you have been used to.

View Details

Connected devices are everywhere. More than 83 million U.S. households have at least one smart device, according to a study by the Consumer Technology Association. In fact, U.S. households own an average of 11 Internet-connected devices, according to a study from Deloitte, including seven with screens to view content (e.g. smartphones, tablets, laptops, TVs). 

With so many devices on the home network, how is security keeping up? What is needed to make device security easier and faster?

Find out why attackers are targeting internet-connected devices, some common attack vectors, and what to do to reduce the risk of breach at the endpoint.

Join this panel of security experts to learn more about the security risks connected devices pose to your home and office, and what can be done about it: - Connected devices - the gateway for attackers - The likelihood that you or your company will be breached via connected devices  - Steps to mitigate the risk of breach - What is needed to close the gap in device security - Best practices for protecting your smart home from online threats

This panel is part of National Cyber Security Awareness Month (NCSAM) 2020.

We welcome and encourage audience participation and questions.

Speakers: Chris Hazelton, Director of Security Solutions, Lookout (Moderator) Brandon Hoffman, CISO, Netenrich Rick Moy, Vice President of Marketing, Tempered Networks Jack Mannino, CEO, nVisium

View Details

As organizations are making plans to extend working from home through next summer, what are some things employees and IT teams can do to better protect their devices and networks? Learn more about how endpoint security can be implemented and improved to protect your organization from breaches.

Join this interactive keynote panel with security experts and industry leaders to learn more about: - COVID-19’s impact on home network security - Why attackers are targeting the endpoint - Why your connected devices may be at risk and what to do about it - How to seamlessly integrate your endpoint security with existing solutions - Identifying threats, solutions and breach prevention best practices

View Details

Breach protection and detection is an ever-evolving challenge for security experts. While there is no catch-all solution when it comes to protecting sensitive data, there are resources you can take advantage of to put your organization in a better position to prevent data breaches.

Join us for an interactive discussion on easy, tactical and strategic steps your organization can take to prevent or minimize a data breach.

We will cover: - Necessary safeguards needed to prevent data breaches. - Better understanding of the environment your organizations data resides. - How to develop a Response Plan tailored to your organization.

Steve Cobb is One Source’s Chief Information Security Officer (CISO) bringing more than 25 years of leadership consulting surrounding IT infrastructure, cybersecurity, incident response, and cyber threat intelligence. Since joining One Source in 1995, Steve has been responsible for providing strategic IT consulting, delivering an increased organization efficiency and security for our customers. Prior to One Source, he was a Senior Security Engineer with Verizon Managed Security and a Senior Escalation Engineer with Microsoft. Steve serves on several CISO boards and a frequent presenter at conferences such as InfoSecCon, Cyber Defense Summit, and others. Steve attended UNC-CH, but left early to start his own IT company, and ultimately received his degree in Business from East Carolina University. Steve and his wife have two daughters and a son.

View Details

As countries and organizations struggle with the global pandemic in 2020 and its aftermath, the adoption of digital and emerging technologies will accelerate due to the need for businesses to adapt and adjust to the new norm. Digital technologies have already start to transform industries. They offer improved solutions that changes our lives in how we do our work and live. The wheels of digital transformation were set in motion in the mid-2000s when the mobile and internet of things were gathering widespread adoption. With the advent of emerging technology amidst Industry 4.0 (and 5.0), it poses certain cybersecurity challenges as security may not be designed or planned in the new technology development and implementation. The quickened pace of technology adoption and digital transformation will open gaps in the organizations’ digital fabric that can lead to data breaches either intentional or unintentional. Just as digitalization brings opportunities for productivity gains and innovation in products and service offerings, it also exposes the organization to increased cyber threats.

The online world that we live in has increased the risks for organizations as our data may be exposed to a breach because of the increased attack surface. Organizations needs to take steps to create a defensible cyber infrastructure in their digital transformation journey. The talk will cover the steps that organizations need to take to ensure that cybersecurity is weaved into the organizations’ DNA. Some best practices will be discussed as well as examples on how they can be implemented. The talk will end with some key take-aways to build a defensible cyber organization and security program.

View Details

Protecting your crown jewels against insider threats

SAP Applications are at the heart of many of the biggest organizations in the world, supporting the most critical business processes and holding the crown jewels of the business. Because of diverse factors that include complexity, criticality of the data, regulations and customizations, securing SAP Applications against threats is a difficult task, but can be achieved with the right level of engagement. Many companies rightfully focus on outsider threats but may be blind to risks and gaps that could leave their SAP system vulnerable from internal attacks.

Join me to learn how to protect your organization's crown jewels from insider threats that could have a significant impact to areas including: ● Critical configurations, deployment of projects and new systems ● Keeping up with SAP security notes and patches, including those acknowledged as a critical US-CERT by the Cybersecurity and Infrastructure Security Agency (CISA) ● Protecting business processes from bad business outcomes I will provide a high level overview and steps for creating a baseline cybersecurity program that incorporates protecting SAP Business-Critical Applications from insider threats.

Key learnings: 1 - Steps towards building a foundational SAP cybersecurity program that bridges the gap between your SAP Security, IT Security/SOC and SAP Operations teams. 2- How to consume threat intelligence from SAP that helps the organization prioritize and remediate risks to the business. 3- Top 3 things to do immediately to significantly improve the overall security posture of your organization.

View Details

Managing the risks against the most threatened resources within the organization.

The never-ending fight between good and evil actors continues unabated and is as dynamic as ever. Successfully resolved and mitigated attacks trends from yesterday against malicious actors keep coming back in different forms.

Traditional attack vectors, are morphing into different variations which are difficult to detect. Organizations and users are falling for some of these new attack trends with their tacit approval and opening up new attack vectors.

Rapid development in Cloud services has brought new attack vectors which organizations also have to consider in their Cyber Security Risk Management program.

Here are some fundamental questions to resolve as we try to mitigate these new attack trends. 1. What is the impact of covid-19 on recent attack trends? 2. What is the impact to our organization when we fail to educate our users? 3. How can we better manage these new attack trends? 4. What is the most vulnerable attack vector for these new attack trends?

In this Webinar, we will review some of the attack trends that organizations should be aware of and how to manage them.

View Details

So far, 2020 has been a challenging year for everyone. COVID-19 and the push for a more remote workforce have left many organizations vulnerable to the risk of a cyber attack. With IT and security teams struggling with the challenges created by remote access attackers are rushing in to capitalize on the chaotic environments created by the pandemic. 

Application security is becoming increasingly important. According to the Verizon 2020 DBIR, there has been an increase in cyber attacks on web applications, both in terms of percentage and in the raw number of breaches.

So, what else is on the horizon for 2021?

Join this panel of security experts and industry leaders to learn more about: - The COVID-19 impact on organizations and trends in recent cyber attacks - Phishing, ransomware, DDoS and other cyber threats - Why web applications are a top target for attackers - Lessons from the front-lines and recommendations for dealing with a cyber attack - What organizations need to prepare for in 2021 - How best to enable teams and secure the enterprise

View Details

In this talk, I will be focusing on the importance of Risk in Cyber Security. As we all know Risk Assessment is important in the present time, and with data, we have the potential to predict our future.

Risk in Cyber security plays a vital role and we require Cyber Security practitioners who have solid domain knowledge on risk assessment, vulnerability management, network security, pen-testing, identity management, and other subject knowledge of information security.

In this talk, attendees will learn the risk perspective of Cyber Security and how they can pursue a career in security while continuing their passion for technology in various majors including Criminology, Computer Science, Information System, Business, Liberal Arts, etc.

View Details

Cyber attackers are known to leverage global & local events to design their attacks. Whether it is a global phenomenon such as ongoing COVID-19 pandemic, or a sporting event such as cricket world cup, cyber attackers utilize interest in these events to propagate malware. In this presentation, we will discuss certain cyber-attack trends which coincided with major events in India over the last 5 years. We will also discuss advancements in security technologies to tackle the ever-evolving cyber-attack landscape.

This webinar will cover: - India specific major events of last 5 years & evolution of Cyber Attacks around them - Contrast with global Cyber Attack trends during that time - Security approaches to protect against latest cyber-attack trends

View Details

This session will focus on global cyberattack trends in cybersecurity and its quickly evolving nature at the intersection of IOT, Privacy and regulatory environments. It will include trends involving the shared responsibility model between businesses and consumers as it relates to cybersecurity, the convergence of recent regulatory legislation as it relates to security, privacy and IOT, and impact of state sponsored cybersecurity attacks on society, businesses and individuals.

Audience Takeaways: - Learn about future trends as it relates to cybersecurity attacks and the human impact - Understand the role of businesses on the front lines of cybersecurity (and WFH) - Find out what every leader needs to know about cybersecurity

View Details

The proliferation of connected devices at home and in the workplace has opened the door to attackers, who often find poorly protected IoT devices as easy targets and entry points.

This panel of security experts and industry leaders will explore the security risks that connected devices pose for individuals and organizations in the U.S. and what can be done to secure devices, deter attackers and overall minimize the risk of breach. - How connected devices have changed the game from a cybersecurity perspective? - Why connected devices are easy targets for attackers - Other cyber threats to be aware of when it comes to connected devices - What you can do to secure your devices at home and at work - Understanding the risk of breach - Best practices & how to #BeCyberSmart

This panel is part of National Cyber Security Awareness Month (NCSAM) 2020.

We welcome and encourage audience participation and questions.

Speakers: Terence Jackson, Chief Information Security Officer, Thycotic (Moderator) Rick Holland, CISO, Vice President of Strategy, Digital Shadows Mark Lynd, Head of Digital Business - CISSP, ISSAP & ISSMP, NETSYNC Dirk Schrader, Global VP of Product Marketing & Business Development, NNT

View Details

Women are increasingly finding a career in healthcare IT. According to a recent article in Healthcare Finance News, women make up 66% of all entry-level healthcare employees and 30% of C-suite positions in healthcare IT.*

Our panelists are challenging the ecosystem—transforming the information technology space in healthcare, driving improved patient care, and leading with a purpose.

Join us for an open and honest hour-long conversation with influential women in healthcare information and technology who are leading the way to a more diverse and enriched community. Gain a better understanding of the challenges and opportunities that these female executives have experienced as they have navigated their careers. Learn from them how they are leading their organizations to digitally transform and serve their patients in more effective ways. Discover how they see the healthcare ecosystem evolving to achieve more diversity and balance in the workforce.

Webinar host pureIntegration is an IT consulting services firm, led by a team of 53% women and minorities.

*Reference: https://www.healthcarefinancenews.com/news/women-healthcare-hold-most-manager-positions-lack-minority-representation-persists

View Details

Why Securing Cloud-Based Email Requires a Different Approach

Email gateways including Proofpoint, Mimecast, and Barracuda were designed to protect on-premises email servers, but when you moved your email to the cloud, it revealed five vulnerabilities that continue to expose your users to attacks.

It's why companies are switching from gateway vendors. Come learn how the migration to Office 365 and Gmail necessitated an evolution in how to secure cloud email, and why Secure Email Gateways are not the right answer.

View Details

By popular demand, the CISO Insights series is back in October for National Cyber Security Awareness Month with a new episode on securing connected devices.

Join this interactive Q&A discussion with CISOs to learn more about: - Why connected devices are a popular target for attackers - Steps for easy cyber hygiene at home and at work - Building a security culture together - CISO recommendations & best practices

Speakers: - Dan Lohrmann, CSO & Chief Strategist, Security Mentor, Inc. - Earl Duby, CISO, Lear Corporation - Keith Hollender, former CISO; Partner, Global Cybersecurity Practice Lead at MorganFranklin Consulting - Adam Ford, CISO of Illinois

This panel is part of National Cyber Security Awareness Month (NCSAM) 2020.

We welcome and encourage audience participation and questions.

View Details

Today’s cloud-native workloads run as heterogeneous APIs and services in a highly distributed manner. As the infrastructure layer is getting more mature, hardened and robust, threats are moving deep into the application layer.

This session goes through the updated Top 10 threats that are prevalent in the cloud-native environment, specifically as it relates to data in transit, and talks about mechanisms to detect and protect against them.

View Details

Cloud provider and/or Cloud consumer have to consider cloud security best practices. But with the rise of public clouds, we have started focusing on putting all eggs in one basket. In this session, we will discuss what are security hygiene tasks you should discuss as a cloud provider and/or consumer.

View Details

Every year tens of thousands of individuals are getting recruited by cybercriminals for legitimately looking jobs of reshipping clerks, accounting specialists, and many other positions. This year, due to the pandemic, these work-from-home jobs got a new level of legitimacy and unprecidented demand. We will examine current schemes for stolen goods re-shipment, charity scheming, money laundering, and more. What your organization should be aware of, how you are impacted, what you should be doing to stay ahead of this ever-changing networks of money and goods mules.

View Details

Cloud Adoption is on the rise again. According to IDG’s 2020 Cloud Computing Survey, 59 percent of respondents said their organizations would be mostly or all in the cloud within 18 months. Cloud changes our approach on so many levels—new technology, new shared responsibility model and new cybersecurity considerations

In today’s session, we’ll explore 6 ways CISOs are navigating the cloud: - Securing an extended perimeter - Upskilling the team - Balancing Risk Management in Third Party Relationships - Defining the Shared Roles in a Shared Responsibility Model - Enhancing Visibility - Taking Advantage of Automation

Moderator: Jo Peterson, Vice President, Cloud and Security Services, Clarify360 Speakers: Brian Campbell--VP, Cyber Security Architect, Veeam Software Mike Goldgof--Senior Director, Product Marketing at Barracuda Carl Eberling-- CIO/CISO- Forcepoint

View Details

Zero Trust security represents a transformation of security principles, technology, and processes which can effectively address today’s IT and threat landscape, and help organizations securely embrace the cloud. Zero Trust not only overcomes the shortcomings of traditional security tools and technologies, it provides a unified policy model and set of enforcement points across a heterogeneous technology landscape.

This is important, because cloud environments, for all their power and promise, do utilize a different set of security technologies, tools, and models compared with the traditional on-premises infrastructure. While there are often very compelling business and technology drivers to adopt the cloud, from a security perspective these changes bring with them a new set of challenges.

The good news is that a Zero Trust approach – utilizing the open, modern Software-Defined Perimeter (SDP) security architecture – is entirely achievable, and brings enormous security and operational benefits. As such, not only can embracing Zero Trust improve enterprise security, it can act as a secure bridge to the cloud.

In this session, we’ll define Zero Trust as a set of principles, and explain how the Software-Defined Perimeter - which verifies and secures all access to all resources, and strictly limits network access – avoids the limitations of traditional security

We’ll explain how an SDP implementation delivers fine-grained network access control, in a way that’s tied to each user’s context, and is dynamically responsive to changes in Cloud environments. We’ll make this concrete with a customer case study, showing how one enterprise obtained technical, business, and compliance benefits from deploying this solution as part of their Cloud migration.

View Details

So you've deployed your cloud-native application in production. And you've put in place network policies and security & compliance solutions to ensure that your applications are protected and compliant.

What if I told you that your data might still be leaking out? What if your applications are still talking to unsanctioned domains and CnC sites? What if your use of cloud services are getting compromised? What if rogue insiders with access to credentials are misusing your environment or stealing info? What if I told you that you still have a number of risky security holes and blind-spots in your environment that you are not aware of?

This session talks about the effective strategies -- of how to detect and mitigate against intrusions and risks from lateral breaches, egress breaches, cloud services breaches, in your environment and how to mitigate them -- so you can focus on productivity and business continuity.

View Details

Misconfigurations are the leading cause of cloud breaches. As the Security Leader of your organization does your strategy properly address these challenges? Do you know what to discuss with the Senior leaders of you business? This presentation covers the considerations and some tips on how to relate these risks to the Leadership.

Take aways: 1. Considerations when selecting cloud solutions 2. Tips on how to communicate with Leadership 3. How to evaluate the shared security responsibilities that come with cloud solutions

View Details

We have seen explosive growth in organizations moving applications, services and systems to the Cloud but unfortunately many do not understand how to secure these environments. Numerous IT and Security departments approach security in the cloud as they were securing individual servers in a data center and do not understand how to prevent data breaches or accidental data disclosers. Organizations are also struggling with how to effectively get full visibility into the cloud environment to monitor for malicious activity or configuration errors.

This presentation will focus on how to prevent and detect cloud security incidents including:

  • Cloud Security Threats
  • Review of Cloud Data Breaches
  • How to Prevent Cloud Security Incidents
  • How to Detect Cloud Security Incidents

Attendees to this discussion will come away with an understanding of the threats to cloud platforms and how an organization can develop solutions to effectively prevent and detect cloud data breaches. We will also provide best practices and native cloud solution recommendations to harden and monitor their applications, services and systems.

View Details

This episode of the Election Hacking Original series will explore the impact of social media platforms on democratic elections, with a special focus on the 2020 U.S. presidential election.

Join this panel to ask your questions and learn more about: - Has anything changed since 2016 and how - What can we learn from examples of other elections around the globe when it comes to the spread of disinformation - How has disinformation been used to suppress voting - What's new on the threat landscape for November - What is the likelihood of a cyber attack against elections

Moderator: David Morris, Executive Director at Digital Risk Management Institute

This episode is part of the Election Hacking Original series examining the threats to democratic elections, the technologies used to power and hijack elections, and what's needed to educate and empower voters before Election Day.

View Details

Securing the access to cloud data assets has never been more important. According to the latest Verizon DBIR, 73% of cloud breaches involved an email or web application server, while 77% of these cloud breaches also involved breached credentials. What does this mean for enterprise cloud security, especially in the time of COVID19 and remote working?

Join this keynote panel to learn more about: - How the landscape has changed in 2020 - Why attackers are focused on identities - Understanding privileged user behavior and securing identities - Discover how organizations are doing IAM, and what's needed for a more secure enterprise - Best practices and recommendations by the experts

View Details

CISO Strategies for the Cloud: Key Factors to Consider when Building a Successful Cloud Strategy addresses the critical information security elements that every organization needs to consider as part of their Cloud Strategy. This presentation brings together experts in Information Security, Cloud Architecture, and Big Data Analytics to provide the attendee with the information they need to put a secure cloud strategy in place today.

View Details

Cloud adoption is becoming and essential part of an organization’s competitive survival. This talk will provide guidance for the CISO organization is what to expect and how to stay in step with an IT organization tasked with rapid cloud migration. It is a new landscape and new challenges to governance, risk and compliance. Be part of the cloud journey and not left behind.

View Details

Join this episode of The (Security) Balancing Act for an insider's view of life on the front lines of cybersecurity.

This panel will look into what it's like to work in and manage a Security Operations Center (SOC), as well as share best practices for keeping your team of front-line defenders sane, empowered and happy, and your organization secure.

The topics up for discussion during this episode include: - What kind of people are best suited for work in a SOC? - What kind of training / certifications / skills are needed to be successful? - How to handle alert fatigue and analyst overload? - Is automation (ML & AI) the answer? - What do you do when IOCs aren't enough? - Hunters vs. responders, what's the difference? - How the pandemic is impacting security operations? - Building a healthy team culture and managing self-care in the age of breaches - What's needed to make life easier for these front-line cyber defenders

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

CISO Strategies for the Cloud: Key Factors to Consider when Building a Successful Cloud Strategy addresses the critical information security elements that every organization needs to consider as part of their Cloud Strategy. This presentation brings together experts in Information Security, Cloud Architecture, and Big Data Analytics to provide the attendee with the information they need to put a secure cloud strategy in place today.

View Details

The last 10 years have not just changed our applications and systems, but our entire businesses. Digital Transformation has been a key part of most large enterprise’s strategy, fueled by cloud services, mobile devices and ubiquitous connectivity, this is transformation continues to evolve. In the scramble to transform, cloud applications and cloud platforms became commonplace and with security struggling to cope, this led to an explosion of new tools, systems and procedures.

Where Digital Transformation leads, Digital Risk follows, raising concerns about exposure from the existing cyber-security controls and their assumed risked models. Even these relatively modern approaches are starting to show their age, again struggling to stay ahead of the transforming cloud and network models.

In a continually transforming environment, where agile is king, cloud comes first, apps are server-less, networks borderless, buildings don’t matter and employees are working everywhere, cyber-security must also transform.

Our cyber-security thinking and approach must adapt to cater for this new risk reality and cut across both the business and technology silos. This is fundamentally changing the paradigm that cyber-security instrumentation, controls and people are working under.

In this talk, we will explore how cyber-security organizations can navigate this change to deliver the security and risk out comes their leaders, users and customers expect.

View Details

Cloud adoption is increasing across Asia Pacific, but there is still a way to go for hybrid and private cloud adoption. At the same time, organizations are facing unprecedented security challenges. 

Join this panel with APAC security experts and industry leaders to learn more about: - The rise in APAC cloud spending - Is APAC ready for the hybrid cloud? - Common security gaps APAC organizations need to keep in mind - The impact of COVID19 and remote working on enterprise security - Rethinking cybersecurity for ever-expanding cloud environments

Speakers: Kobus Dippenaar, Director & Digital Transformation Implementer, The Practitioners Limited (Moderator) Naveen Singh, Solutions Engineer, Cloudflare Srinivas Josyula, Senior Director and IT BUH, DST Worldwide Services Veritas Speaker TBD

View Details

Countries, Cities and Companies have all traversed down the path of digitization in the hope of delivering on-demand services. In the case of enterprises, digital transformation has been engineered to drive process improvements, deliver newer customer experience, and biz model reengineering to capitalize on emerging trends

At the centre of this transformation has been public cloud infrastructure, which has emerged as the backbone for innovation-driven growth. By embracing the cloud, enterprises can modernize their IT infrastructure and conjure solutions to serve customers digitally in new and innovative ways. Digital transformation & cloud adoption has further accelerated in recent times, as COVID-19 pandemic forced businesses to setup remote working at an unprecedented scale. Public Cloud services enabled fast & smooth migration to “working from home” by enabling connectivity from anywhere and supporting essential services such as video conferencing & real time communication

This though exposes organizations to previously unseen cyber security risks. The increased attack surface alongside limited security capabilities, when it comes to public cloud, means organizations are more vulnerable than ever. To mitigate the risks, organizations must adopt a "assume breach" mentality and build a strong security culture within the organization

In this talk I will discuss: Cloud security risks & challenges Some examples of vulnerabilities and how they have been used in attacks Assume breach mentality and how to use it to protect cloud workloads The need for Zero Trust. Made for the cloud! Security is everybody's business

View Details

Increasing cyber attacks are standing testimony to the fact that the best of technologies & traditional approaches for securing the network have not provided requisite protection from hackers. The increase in cloud adoption has only led to expansion of the threat landscape.

Zero Trust framework has been touted as the silver bullet for some time now. At best, it has provided the guiding principles but mostly has been found wanting in implementation scenarios. While the promise & aspiration has been long understood, Enterprises struggle on where to start and how to implement.

This webcast covers the practical scenarios, challenges & approach on how best to embark on the Zero Trust journey for Enterprises and in particular cutting out the Clutter & Noise around the much hyped concept.

View Details

Cloud Migration Journey in Financial Institutions/Banks has been adapting the cloud services and is becoming the first choice due to its scalability, elasticity, cost-saving, reduced overhead, and Pay as you go model. But for financial institutes/Banks, they have more focus on privacy, security, confidentiality, and integrity of customer & financial institution.

Join this session as we discuss:

• Different aspects of Cloud migration throughout its journey while keeping our risks appetite within limits. • Common threats including data breaches, data loss, DDOS, insider threats, shared responsibility, and risk of insufficient due diligence/care throughout its life. • Continuous risk management strategy • Why financial institutes/banks are slow/reluctant in moving their customer/core data to cloud. • Legal & Regulatory aspects while dealing with cloud and mitigating the associated risks.

View Details

Companies need immediate rethink on transfer data to the United States since the Privacy Shield transatlantic pact is declared invalid. The Court of Justice of the European Union found that the Privacy Shield does not meet the GPDR requirements and cannot ensure a level of protection.

We will discuss how to achieve compliant pseudonymization, including protecting not only direct identifiers but also indirect identifiers and additional attributes, while still preserving the data’s utility for its intended use.

We will also discuss different international privacy standards, the new Schrems II, clarify pseudonymization and other data privacy techniques.

We will also discuss • Data privacy and working remotely • That GDPR does not apply to data that is no longer identifiable • Pseudonymization used nationally, as well as for trans-border communication • Pseudonymization use cases for privacy protection of personal health information • Re-identification attacks, full and partial • Extracting new information out of an anonymous or pseudonymous database through re-identification • Linkage mechanisms • The data de-classification process and workflow • Pseudonymization services best practices and trustworthy practices for operations • Policy framework for operation of pseudonymization services • When to use pseudonymization and/or anonymization

View Details

The nature of software is that security vulnerabilities exist, and need to be eradicated. Once you find those vulnerabilities (as Ted taught in his last talk - link in Attachments), next you need to fix them. But developers are already overloaded, deadlines are looming, and there just isn't time to add remediation work. However, if you don't fix the vulnerabilities, you've wasted the money, effort, and time invested in finding them in the first place -- all while leaving a vulnerable system unnecessarily exposed.

How is a busy team to handle this conundrum?

In this talk, author Ted Harrington extracts insights from his book Hackable in order to teach you how to deal with all of this. You'll learn how to: - Prioritize Vulnerabilities by Severity - Remediate Vulnerabilities - Verify Remediations ...and more!

View Details

Please join us for a special 2020 Hacking The Election episode where we will go beyond the traditional bits and bytes of hacking the upcoming election.

In this episode we will explore the other side of Hacking The Election; the Human side, covering such topics as:

  • Manipulating the electorate
  • Seeding mistrust in the election process and results among the voters
  • Fermenting anger and disenfranchisement
  • Polarizing the electorate

A soft preview of what's to come in the November election.

Panelists: - Neal O'Farrell, Founder at The PsyberResilience Project - Barak Engel, CEO, EAmmune - Harrison Morris, PhD Candidate Georgia Tech researching the intersection of Cybersecurity and Cognitive & Brain Sciences

Moderator: David Morris, Executive Director at Digital Risk Management Institute

This episode is part of the Election Hacking Original series examining the threats to democratic elections, the technologies used to power and hijack elections, and what's needed to educate and empower voters before Election Day.

View Details

Protection against cyber threats is recognized as a necessary component of an effective risk management approach, typically based on a well-known cybersecurity framework. A growing area to further mitigate risks and provide organizations with the high level of protection they need is cyber insurance. However, it’s not as simple as buying a pre-packaged policy.

This webcast will provide an overview of how cyber insurance fits in a risk management program. It will identify key terms and conditions that should be understood and carefully negotiated. Cyber insurance policies may not cover all types of losses, so it is critical to identify what risks and conditions are excluded from a cyber insurance policy before you buy.

Join this webcast to learn: •General threat tactics, risk management approaches, cybersecurity frameworks •How cyber insurance fits within an enterprise data security strategy •Nuances of cyber insurance – exclusions, exemption, triggers, deductibles and payouts •Challenges associated with data stored in the cloud

After you watch the webcast, check out the Q&A blog: https://bit.ly/36ijYzI

View Details

Many years ago we decided that protecting our data just behind username and password authentication is a bad idea. Yet today, we are still heavily relying only on this technology. And, in turn, cybercriminals rely on stolen credentials to enter our realm to wreak havoc. Let’s take a look at how your credentials are valued today, how they are stolen and abused. Then let’s discuss available safeguards including not only MFA but other viable defenses for our society that still holds on to its P@ssword1!

View Details

In our remote work world the ability to understand who is accessing what and when, is becoming blurred. Employees had access to more resources that are virtual, ad-hoc, or even sitting on their kitchen table. Yet breaches continue to rise so effectively authenticating and auditing each aspect of work is a must for organizations as we continue to adapt. For most organizations, the piece of IT infrastructure that is responsible for this is their directory, acting as the main authentication mechanism to access any aspect of work.

In this talk we will look at the modern directory in the remote work world and how insights across different authentication logs combine together for a cohesive story and immediate action.

Presented by: Chase Doelling, Director Strategic Alliances and MSP Partnerships, JumpCloud Michelle Michael, Sales & Marketing Manager, Sennovate

View Details

In the age of data collection and targeting by the campaigns, what can we learn from Gen Z? When it comes to data sharing, privacy and security awareness, what has changed in the population mindset since 2016? Are the lessons from the Cambridge Analytica scandal still applicable today? A soft preview of what's to come in the November election.

Moderator: David Morris, Executive Director at Digital Risk Management Institute

This episode is part of the Election Hacking Original series examining the threats to democratic elections, the technologies used to power and hijack elections, and what's needed to educate and empower voters before Election Day.

View Details

The internet has enabled the perpetration of crimes at huge distances with impunity. But defenders can inspect network traffic for signs of malicious activity and where it originates.

This session examines how we can use the MITRE ATT&CK framework to codify and share intelligence on attacker behaviors derived from network traffic analysis. We will look at how traffic is collected, stored and analyzed. We provide an overview of tools for analysis of network packets and flows, and explain how these tools can help us identify the malicious use of non-standard protocols, protocol abuse, tunneling, port scanning, lateral movement, command and control, and data ex-filtration. We will also discuss automated detection of suspicious traffic using signature-based, behavior-based, rule-based, and anomaly-based algorithms. Finally, we will introduce Security Onion, a Linux distro similar to Kali Linux, but for defenders.

View Details

Due to some conflicts related to the responsibilities expected from the CISO structure, it is very difficult to find the right balance to really implement a DevSecOps culture. Some even say that fully shift-left is unreachable.

In this presentation we will: - Go deep on these twisted expectations - Understand how to achieve the perfect balance on the shift-left approach

About the speaker: Rodrigo holds a Master’s Degree in Computer Science and has more than 12 years dedicated to the IT industry, embracing challenges with his clients and helping them during their Digital Transformation journey.

View Details

Sacrificing data security for faster innovation is one of the main causes of tension between cybersecurity and IT professionals on the one side and DevOps teams on the other. So, how should organizations bridge this divide and what do they need to implement?

Join this exclusive keynote panel to learn more about: - Why securing DevOps pays off in the long run - Shifting left: What is it, how it works and why your organization needs it - How to make security an integral part of the DevOps process - DevOps security checklist - Recommendations for tools and workflows that enable better security

Panel: Rachel Veal, IT & Security Program Manager, Ad Hoc (moderator) Ido Safruti, Chief Technology Officer, PerimeterX Josh Kirkwood, Solution Engineering Manager, CyberArk Max Heinemeyer, Director of Threat Hunting, Darktrace

View Details

COVID-19 has accelerated the move to the cloud. Organizations have been propelled into a new paradigm. The cloud offers many advantages and some challenges in a work from anywhere environment. This session focuses on how to leverage the strength of the cloud whilst reducing risk and increasing governance.

Join this session to learn about:

  • Tactical steps to get immediate risk reduction and lower operational cost
  • Leverage conditional access and stop shadow IT
  • Manage multiple clouds from a technical and cost perspective
  • Leverage automation whilst addressing the risks posed by bots and scripts
  • Bring governance into your cloud environment
  • Build a security roadmap for controls
  • Use Zero Trust to secure the work from home model

View Details

According to new research from Risk Ledger, 60% of security breaches originate in the organization's supply chain; including third party vendors and applications. No matter what business an organization is in, supply chain security and resilience must be factored into business planning to ensure secure, ongoing operations even during times of crisis and disruption.

Join this panel to learn more about: - Types of supply chains (hardware, software, services) - Common vulnerabilities in the supply chain - Assessing where your security gaps lie and addressing the risk - Impact of the COVID-19 pandemic on supply chain security - Recommendations for improving security in your supply chain and your risk management program - Benefits of Supply Chain Risk Management (SCRM) - What is the Cybersecurity Maturity Model (CMM), and how it can improve supply chain security - Solutions and approaches that can improve supply chain security

This episode is part of The (Security) Balancing Act original series with Diana Kelley. We welcome viewer participation and questions during this interactive panel session.

View Details

As the world continues the work-from-home initiative in order to combat the COVID-19 threat to humanity, organizations must also consider that threat actors (hackers, Advanced Persistent Threats, etc.) may take this opportunity to exploit existing vulnerabilities normally mitigated in an office environment behind a firewall, as an example, but not necessarily mitigated in a Telework environment. This presentation will discuss the following topics

  • Discuss the recent rise Threat Actor exploits of Telework applications, and provide a means of ‘visibility’ by organizations to detect, analyze and remediate threats attempting to exploit vulnerabilities.

  • Visibility into emerging threat capabilities to introduce ransomware and malware into a remote computer/mobile device. Example: COVIDLOCK ransomware on Android smart phones and how to detect and remediate.

  • How VPN is only a step in the right direction towards accessing and transmitting secure, sensitive data. How additional applications and best practices can assist organizations to maintain Confidentiality, Integrity and Availability (CIA) in the near-immediate term.

  • The advantage of educating employees on the dangers associated with working remote, and whether use of personal devices versus company-provided devices are viable options.

  • How Software as a Service (SaaS), Infrastructure as a Service (IaaS) providers can assist your organization in maintaining effective CIA in a Work From Home environment. The presenter will also discuss limitations and the often overlooked Shared Responsibility.

View Details

Cybercrime is at an all-time high.

Businesses in the UK are under the constant threat of cyber security attacks, and there is an increasing risk of losing your data, money, and even the business itself. Hackers are experts at choosing vulnerable targets. Learn about the risks and best methods of defence by joining our security briefing with experts from the police, TiG and Guildhawk.

In this briefing you will: - Hear how other businesses have been targeted - Understand the risks through real-life examples - Learn how to implement some simple defence strategies - Have the opportunity to ask questions

View Details

Cloud security remains a challenge for enterprises, especially in the new post-COVID-19 reality of 2020 and the shift to remote working. What are the new threats on the horizon and compliance considerations to keep in mind?

Join this interactive panel of cloud security experts and industry leaders to learn more about: - New and old cloud security threats to keep in mind - Why visibility is key for cloud security - Know your cloud: Who is accessing what and when? How was their identity verified? - Privileged identities and what's needed for secure privileged access - Compliance challenges and considerations - Best practices for securing your data in the cloud

Speakers: Diana Kelley, Cybersecurity Field CTO, Microsoft Andy Givens, VP Solutions Engineers, North America, CyberArk Manav Khanna, Senior Director of Product Management Identity & Access Management, Thales Tim Bach, Vice President of Engineering, AppOmni

View Details

Following international arrests of some cyber criminals, online criminal markets are adding security features to protect themselves from cops and additionally devising new means to continue prying on users and companies’ data in order to further their criminal behaviour.

This session will provide some insight on: - The means the cyber criminals are using to obtain the information they need, and - The steps businesses and individuals alike can take to protect themselves.

At the end of this session, the participants will take away: - Three key information the cyber criminals are after - Cyber criminals and their targets - Steps businesses (and individuals) can take to protect themselves from cybercrime

About the speaker: Stella is an experienced, performance driven and result oriented Certified Information Systems Auditor (CISA) with over 13 years experience providing consulting services in SAP Security and Controls, Governance Risk and Compliance, IT Risk Management, and Auditing in public and private sector under her consulting firm Ellar Consulting Inc. She has also been involved in various cybersecurity initiatives which motivated her to start Syberficial in order to help those intimidated by CyberSecurity get acquainted with the topic.

During the course of her career Stella, an MSc. holder in Business Applications of Computer Science has worked with stakeholders at various levels including C-level executives and senior leadership to create policies and procedures, develop strategies and deliver solutions to meet business objectives.

When not occupied with security tasks, Stella being a fitness enthusiast and avid runner, likes to spend her time working out or on the running trail. She has completed a good number of half and full marathons and has it on her bucket list to run all six world major marathons.

View Details

Cyberthreats are viewed as a significant risk to organizations. They are capable of disrupting core operations and inflicting serious damage to brands and reputations.

A study by Cybersecurity Ventures predicts these crimes will cost the world $6 trillion a year by 2021.

Join this panel discussion to: - Review today’s expansive attack surface and the various ways bad actors penetrate networks - Discuss existing and emerging cyber threats - Understand policies, tools and best practices used to protect organizations as new threats emerge - Explore the roles that user training and education, skill development and governance play in defending against threats

Panel: Jo Peterson, VP Cloud & Security Services, Clarify360 (moderator) Adarsh "Adi" Pradeep, Cybersecurity Consultant Brad Moldenhauer, CISO, Americas, Zscaler Dr. Richard Ford, CTO, Cyren Homayun Yaqub, Global Security Strategist, Forcepoint

View Details

Organizations are affected by changes in the external environment. The ongoing COVID-19 pandemic has demonstrated our vulnerabilities. Companies are stretched financially and operationally as they have to adjust to a new business model. Many countries have implemented lockdowns and restriction on travel and logistics. Employees are working from home and some businesses have shut down if they cannot remodel their services. Past major events such as the terror attacks in beginning of this century, the hacks of critical infrastructure in the last decade, major data breaches in the last 20 years, global financial markets crash in 2008 and others have impacted many countries and companies that are not prepared.

As most of our systems and processes depends on digital technologies, it leaves us open to cyber attacks. We need to be prepared for the next external change that may leave us vulnerable to an attack. In the presentation some of the ways to increase our cyber resilience will be discussed. Cybersecurity must continuously evolved and be proactive. It must be top down and bottom up. The governance of Operational Technology and Information Technology needs to be holistic and seamless to prevent gaps in the environment. Just as important is the situation awareness on the ground and the control mechanism to bring to management attention when things go wrong or are likely to. In the presentation, some of the best practices of Cybersecurity to address the problems will be covered.

Presenter Biography: John Lee is the Managing Director of Global Resilience Federation Asia Pacific. He manages the Operational Technology Information Sharing Analysis Centre (OT-ISAC). It is a membership driven community with organizations from public and private sectors managing OT critical assets and infrastructure. He has more than 20 years of experience in Information Security and ICT industry having managed teams in APAC and Middle East for MNCs.

View Details

The rapid growth in infrastructure to support the real time and continuous collection and sharing of data to make better business decisions has led to an age of unprecedented information access and storage. This proliferation of data sources and of high-density data storage has put volumes of data at one’s fingertips. While the collection of large amounts of data has increased knowledge and efficiencies for businesses, it has also made attacks upon that information—theft, modification, or holding it for ransom--more tempting and easier. Cryptography is often used to protect valuable data.

This webcast will present an overview of applied cryptography techniques for the most popular use cases. We will discuss ways of securing data, the factors and trade-offs that must be considered, as well as some of the general risks that need to be mitigated, including:

•Encryption techniques for authenticating users •Encrypting data—either at rest or in motion •Using hashes to authenticate/ Information coding and data transfer methodologies •Cryptography for Blockchain

View Details

Worldwide, regulations are being promulgated and aggressively enforced with the intention of protecting personal data. These regulatory actions are being taken to help mitigate exploitation of this data by cybercriminals and other opportunistic groups who have turned this into a profitable enterprise. Failure to meet these data protection requirements puts individuals at risk (e.g., identity theft, fraud, etc.), as well as subjecting organizations to significant harm (e.g., legal penalties).

This webcast highlights common privacy principles and themes within key privacy regulations. In addition, the related cybersecurity implications are explored. Lastly, the session will probe a few of the recent regulations/laws to outline interesting challenges due to over and under-specification of data protection requirements (e.g., “reasonable” security).

After viewing this webcast, attendees should understand: •How privacy and security is characterized •Data retention and deletion requirements •Core data protection requirements of sample privacy regulations from around the globe •The role that security plays with key privacy regulations •Data breach implications and consequences

After you watch the webcast, check out the Q&A blog: https://bit.ly/2FXnB3p

View Details

Being left at the payment altar is not easy.

PCI DSS requirements 6.1 and 6.2 address the need to keep systems up to date with vendor-supplied security patches in order to protect systems from known vulnerabilities. But what do you do if you have an in-scope application and it is no longer supported by the vendor?

Many payment applications, gateway and software are long past end-of-life, yet still processing cardholder data. Can such a setup be PCI compliant?

This PCI Dream Team webinar will detail the issue, challenges dealing with unsupported hardware/software, and suggest strategies for compensating controls.

Our panelists are some of the top PCI QSA’s in the country, with decades of combined PCI and card processing experiences. They’ve seen it all: the good, bad and ugly; and lived to tell the tale.

Join Ben Rothke, David Mundhenk, Arthur Cooper, and Jeff Hall for an interactive Q&A session, and get answers to your most vexing PCI questions. No PCI question is out of bounds.

View Details

What is penetration testing anyways? It's probably not what you think it is. You're building an application and need to prove it's secure, so you go get some penetration testing. But what are you actually getting?

In this talk, author Ted Harrington takes you to the front lines of ethical hacking and security research, blending real-world exploit stories with actionable insights in order to help you understand what penetration testing is, what it isn't, how to tell the difference, and determine what you might actually need. You'll learn how hackers break applications, and you'll walk away with practical guidance about how to: - Abuse functionality - Chain vulnerabilities - And much more

About the Speaker: Ted Harrington is the author of HACKABLE: How to Do Application Security Right, and the Executive Partner at Independent Security Evaluators (ISE), the company of ethical hackers famous for being the first to hack the iPhone. He’s overseen security research hacking medical devices, password managers, and cryptocurrency wallets. Ted has helped hundreds of companies fix tens of thousands of security vulnerabilities, including Disney, Amazon, Google, Netflix, Adobe, Warner Brothers, Qualcomm, and more. For his stewardship of security research that Wired Magazine says “wins the prize, hands down,” Ted has been named both Executive of the Year [by American Business Awards] and 40 Under 40 [by SD Metro].

View Details

More mid-to-smaller companies are being targeted by cyber attackers with ransomware. According to a recent report, the average-sized company impacted has decreased from 2018 to about 650 employees in 2019. This trend will likely continue.

Join Troy Vennon, who leads the Ohio security community of CISOs and security managers (ISAO), for a discussion about protecting your company with practical steps and tight budgets. Troy will discuss how knowing how vulnerable your company is to ransomware helps you better protect from it. You will learn from this discussion: + Top 3 steps your security team can take to protect your network on a budget + How to find, prioritize and close vulnerabilities that expose you to ransomware + What best practices other companies are deploying to defend their enterprise from attack

View Details

As the 2020 U.S. presidential election draws near, let's take a look at the top cyber threats campaigns are facing this election cycle and what can be done to address them.

The lessons can easily be applied to the private sector and enable organizations to take steps toward better security.

Join this panel to ask your questions and learn more about: - Domain spoofing - Email threats - Information warfare - Cyber attacks

Speakers: - Mick Baccio, Splunk - Frank Snyder, Yubico - Lance James, Unit 221B

Moderator: David Morris, Executive Director at Digital Risk Management Institute

This episode is part of the Election Hacking Original series examining the threats to democratic elections, the technologies used to power and hijack elections, and what's needed to educate and empower voters before Election Day.

View Details

Cyberattacks attributed to foreign governments have been on the rise for years, many against organizations all over the world. These attacks try to steal online account information, infect computers, and compromise the safety of networks. Targets of these attacks include think tanks, university staff, government employees, and even members of organizations focused on human rights issues.

As these attacks increase in prevalence and sophistication, organizations are taking notice of the threats posed by hostile state actors and state-sponsored cybercriminal groups.

So, how can businesses protect against them?

Join today's episode of The (Security) Balancing Act with Diana Kelley to learn whether your business should be concerned about nation state attacks and what to do about it.

The topics up for discussion will include: - State actors & rise in cyber crime - How the attackers get in - A review of recent nation-state campaigns - How does this impact organizations across different verticals (Financial vs Healthcare vs Government) - How industry and law enforcement are responding to these attacks - How AI and ML may change cybercriminal tactics - How to deal with threats from criminals and hostile states

Panelists: - Etay Maor, Chief Security Officer, IntSights - Matt Rider, International Engineering Director, Rapid7

We welcome viewer participation and questions during this interactive panel session.

View Details

Any organization’s security depends on its ability to rapidly detect and respond to emerging threats across your cloud and on-premises environments. Yet, attack methods and strategies evolve constantly, making threat detection an always-moving target. If you are a CISO or key stakeholder and would like to learn ways to monitor, detect, and secure your environment, you should attend this webinar. You will learn • Collecting Security Events • Reviewing Log data • Performing Analysis • threat intelligence from the Open Threat Exchange® (OTX™) • Managed SOC - An effective and efficient way to compliment your Cyber Security team • AlienVault Case Study

View Details

Hackers attack every 39 seconds and their attacks are becoming more and more sophisticated. Gone are the days where simply keeping your anti-virus up to date and locking down your perimeter will protect you from the bad guys. This talk will focus on how prevention and detection has changed over the years. Building off the premise that there is no “silver bullet,” this talk will blend the tried and true techniques of years past with new technologies to guide the listeners down the path to knowing how to blend them into a new mousetrap for our new normal.

View Details

Traditional Breach Prevention and Detection are now insufficient capabilities without the organization’s ability to respond to new Privacy Regulations and the everchanging landscape of Cybersecurity Governance. A firm must be ready to respond to a data breach and avoid the penalties.

While traditional organizations continue to align cybersecurity breach prevention and detection through the lens of cybersecurity frameworks and certifications such as ISO 27001 and NIST 800-53 as examples, the Privacy regulations are forcing firms to pivot how they integrate Data Governance strength to protect themselves from the damages of breaches not only to their firms but to avoid fines and reputational damage that can cost millions of dollars.

This presentation is a practical Data Breach Readiness pathway to mitigate data breach RISK and FINANCIAL impact to your firm while increasing consumer trust.

Take aways will include:

  • A practical and proven approach to assess breach response readiness
  • How to start integrating your cyber-defense program with data governance so breach readiness and response can be effective
  • Tools and tips to get Privacy Breach Ready
  • The role of a Defensible Narrative

Malu brings more than 25 years of industry expertise in Government, High Tech Manufacturing, Retail and Executive Digital Solutions advisory across every functional vertical. Her portfolio of experience includes deep technical product leadership, strong drive for Quality & Operational Excellence, Product Innovation and simplification, Cybersecurity & Privacy (GDPR/CCPA), Process and People leadership across business units and IT. Malu has served as Board Member to multiple organizations focusing on Cloud Digital Transformation, Operational Excellence, Cybersecurity, GRC & Privacy.

Malu is President and Founder of Cryptopn, LLC. An executive advisory firm that has delivered Cybersecurity and Privacy Strategy to multiple Fortune 500's and startups.

View Details

According to Digitalguardian.com, a data breach at U.S. firm in 2019 cost an average of $8,19 million, an increase from $7.91 million in 2018, and more than twice the global average.

The number of data breaches is growing as well. Statisa reports a 14% increase in the number of breaches in 2019 over 2018 figures. So how can we guard against them? While there is no one and done solution for solving security challenges, Risk Reduction is a key element

In this session we’ll discuss both the educational and technical approaches to data breach risk reduction:

  • Types and Causes of a Data Breach
  • Consequences of a Breach
  • Data Breach Response Plan and Breach Notification Plan
  • Method for Evaluating Risks and Harm
  • Breach Prevention Tactics

Moderated by: Jo Peterson, Vice President, Cloud and Security Services, Clarify360 Panelists: Tyler Cohen Wood, Executive Director Cyber Workforce Program CyberVista Stephenie Southard, CISO of BCU Rich Thompson, VP Sales Engineering, BlackBerry

View Details

Join us for an interactive discussion on how deception technology can provide early detection of a breach and significantly improve an organization's capabilities to quickly and accurately defeat attackers. We will cover:

  • Faster detection of threats at a lower cost
  • Collecting specific threat intelligence on if and how you are being targeted
  • Reducing false positives and not missing alerts
  • Detecting insider threats

Speaker bio - Steve Cobb, CISO at One Source Steve Cobb is One Source’s Chief Information Security Officer (CISO) bringing more than 25 years of leadership consulting surrounding IT infrastructure, cybersecurity, incident response, and cyber threat intelligence. Since joining One Source in 1995, Steve has been responsible for providing strategic IT consulting, delivering an increased organization efficiency and security for our customers. Prior to One Source, he was a Senior Security Engineer with Verizon Managed Security and a Senior Escalation Engineer with Microsoft. Steve serves on several CISO boards and a frequent presenter at conferences such as InfoSecCon, ISSA, Cyber Defense Summit, and others.

View Details

Breach protection and detection is a central challenge for security experts who are tasked with protecting an enterprise. In addition, the endless effort to protect business assets does not lead to certainty.

It is difficult to prove that defensive efforts are effective and ready for real life attacks.

In this presentation, you will learn how the collaboration between a Threat Intelligence Team and a Red Team led to a revolutionary change in security posture and provides an effective method to evaluate and improve the prevention and detection of compromises.

In this session you will explore - A method to identify gaps in breach protection and detection - The challenges around endpoint protection and DLP - Enhancing logging and monitoring by adding context - Building a trusted environment

View Details

Opportunity is the cause of cyber crime, take away the opportunity and take away the crime.

Threat actors collaborate, conspire and acquire targets with impunity - just below the surface of what we see on the internet every day. Often referred to as the Deep Web or Dark Web, these virtual meeting places hide cybercriminals, insiders, terrorists and activists from plain view. How do you become proactive and get visibility into the forums and communication channels where 'bad actors' hatch their plans? This session will dispel the mystery of the dark web, discuss how the virtual underground operates and provide guidance on how organisations can gain visibility into these environments to help inform and manage their business risk. Join BCyber as they host a discussion with intelligence expert, Brett Williams, Flashpoints Lead Solutions Architect, where we will provide an:

  • Understanding and dispelling the myths of the deep and dark web
  • Overview on how cybercrime works and how illicit actors operate
  • Update on key trends being seen in first half of 2020, for example, COVID threats, extortionist ransomware and more
  • Example from real-life, covering content from virtual illicit communities, like forums, marketplaces, chat services etc
  • Actions that you can do to gain external visibility for your organisation to better manage business risk

View Details

With the increase in mobile and smart devices, we've expanded the threat landscape not only against threats to steal information, but for threats that have real physical risks. For instance, recent research by Google Project Zero and Volexity showed sophisticated attacks against both Android and iPhone devices that were targeted at Uighur Muslims and Tibet. Victims of this malware are targeted for persecution by the government of the People's Republics of China.

This talk will cover not only these attacks in specific, but in how threats are emerging that use new technologies which are being used to create physical threats to its victims and what that means for enterprises, SMBs, and society at large.

Takeaways:

  • Technical discussion on mobile surveillance techniques and malware.
  • Cover real-world instances where such cyber attacks have led to physical harms.
  • Discuss practical techniques to begin to mitigate such threats.

View Details

As the number and frequency of malware attacks continue to increase, we look at the threats, vulnerabilities and risks factors associated with malware attacks and how to keep your organizations secure.

Join this keynote panel with security experts as they discuss malware trends, strategies and tools for better security in 2020:

• The most prevalent threats in 2020 • Identifying the latest malware delivery tools and techniques • Developing a modern defence strategy and empowering your users • Malware strategy best practices

Speakers: Joseph Carson, Chief Security Scientist, Thycotic (Moderator) Pedro Uria, Director of PandaLabs, Panda Security Jack Mannino, CEO, nVisium Stan Lowe, Global Chief Information Security Officer, Zscaler John Aarsen, SE - Benelux and Nordics, SonicWall

View Details

Enterprise tech has transformed over the past decade, bringing improvements not only in elasticity & efficiency but especially security. Ten years ago, vulnerabilities were the easiest path into systems, but operating systems and software have become more secure through better practices, consistent updates, & leading-edge security solutions. As tech evolved, so have the exploits, which now leverage human error more than ever; capitalizing on misconfigurations or leveraging tactics like social engineering - as a primary path to compromise.

In this presentation, Luke will chronicle the evolution of malicious attacks over the last ten years and demonstrate how the security industry has responded through the implementation solutions that address the ever-changing nature of data breaches.

The presentation will address:

· Lessons learned from ten years of exploitation evolution · Why modern threats are effective even though there are more security tools on the market than ever before · Changes companies can make now to build stronger defenses

Luke began his cybersecurity career in the US Navy, where he trained to conduct offensive security operations for the Department of Defense. He participated in daily computer network exploitation missions in support of national intelligence requirements and in support of protection against foreign nation-state sponsored hackers. After separating from the United States Navy, he joined the start-up company, IronNet Cybersecurity. Luke conducted penetration tests and vulnerability assessments, while also providing product development support and threat hunting capabilities. Following his time at IronNet, Luke worked as a Director in security consulting at Ankura Consulting Group, where he specialized in red teaming, penetration testing, intelligence gathering, threat hunting, digital forensics, and technical writing. Luke has a M.S. degree from Eastern Michigan University and is CISSP, OSCP, and CEH certified.

View Details

As an information security professional your knowledge of ransomware as well as the tactics & techniques to detect & respond effectively are critical to your organization. Data breaches threaten organizational financials and reputations. Strengthen your security through the use of actionable intelligence. Attendees will hear about:

  • What is Ransomware?
  • Leveraging Architecture Components to Detect & Respond to Ransomware
  • Ransomware Scenarios & Solutions
  • Tips to Protect Your Organization

View Details

Every time there is a major crisis I feel like the cybercriminals should cut us a break and yet every time it seems like they double down. You may recall over the years when a major natural disaster, health crisis or social issue dominate the news there are a flood of crisis related phishing campaigns using the topic as a pre-text for launching an attack.

Using popular topics and references is a key way that attackers can increase the probability of getting someone to click on their phishing lure to launch something like a ransomware attack. In this talk will cover some of the ways we can prepare for the next calamity.

• Phishing detection and defense practices • Techniques for ransomware prevention • Training your employees to be resistant to Social Engineering techniques

Join us for a discussion on how to prepare both your people and security infrastructure for the next wave of attacks. The cybercriminals are phishing – let’s talk about how to stop your employees from clicking on the bait.

Bios: · Tony Lauro is Director of Technology & Security Strategy for Akamai Technologies. Over the past seven years Tony has worked with Akamai’s top global clients to provide application security guidance, architectural analysis, web application and adversarial resiliency expertise. · Steve Winterfeld is our Advisory CISO. Before joining Akamai, he served as CISO for Nordstrom bank and Director of Incident Response and Threat Intelligence at Charles Schwab. Steve focuses on ensuring our partners are successful in defending their customers and determining where we should be focusing our capabilities.

View Details

An increased awareness about privacy issues among individuals. In many countries, databases containing personal, medical or financial information about individuals are classified as sensitive and the corresponding laws specify who can collect and process sensitive information about a person. The financial services industry has rich sources of confidential financial datasets which are vital for gaining significant insights.

However, the use of this data requires navigating a minefield of private client information as well as sharing data between independent financial institutions, to create a statistically significant dataset. A major challenge that many organizations faces, is how to address data privacy regulations such as CCPA, GDPR and other emerging regulations around the world, including data residency controls as well as enable data sharing in a secure and private fashion.

We will present solutions that can reduce and remove the legal, risk and compliance processes normally associated with data sharing projects by allowing organizations to collaborate across divisions, with other organizations and across jurisdictions where data cannot be relocated or shared. We will review solutions that are driving faster time to insight by the use of different techniques for privacy-preserving computing including k-anonymity and differential privacy. We will discuss multi-party computation where the data donors want to securely aggregate data without revealing their private inputs. We will also review industry standards, implementations, key management and case studies for hybrid cloud (Amazon AWS, MS Azure and Google Cloud) and on-premises.

View Details

We often don’t realize the full impact of cyber crime, which then relapses us into repeating the same mistakes. Even large companies do not completely understand how their data and services are being abused. I want to take you on a journey of observing credit card fraud and abuse from stealing a credit card to trafficking of stolen goods. Learning about these vectors of abuse will help you and your organization to mitigate a number of common attacks and abuses.

View Details

With email security breaches constantly making headlines, it is crucial for organisations to be ahead of the curve. Join this interactive panel of industry experts as they discuss the latest trends in email security and how to prevent becoming the next international headline.

Join this Q&A panel to learn more about:

  • Emerging trends in email attacks
  • How to stay on top of the latest threats
  • Best solutions to protect your organization

Moderator: Michael Thoma, Principal Consultant at the Crypsis Group Panelists: Arif Hameed, Senior Director, Client Security at Equifax Lior Kohavi, Chief Strategy Officer and EVP for Advanced Solutions, Cyren Chris Wallace, Chief Information Security Officer

View Details

To defend against phishing, your organization needs to understand the key trends and top threats. Cofense’s Intelligence Team spends every day analyzing phishing threats including credential theft, ransomware campaigns, and more. Learn about the top threats that define today’s phishing landscape and how to defend your organization against them.

  • See what tactics are successfully evading secure email gateways and reaching enterprise end users.
  • Learn what is trending when it comes to malware delivered via phishing, including ransomware.
  • Receive tips for ensuring your phishing defense strategy is proactive and well-coordinated.

View Details

Join us for an interactive discussion on innovative methods used to deliver ransomware and new tactics attackers are using to gain a foothold and deliver their payloads. We will cover:

  • New strategies and tactics cybercriminals are using
  • Steps of a ransomware attack - what you may be missing
  • Ransomware in 2020 and into the future - what you need to know now

Speaker bio - Steve Cobb, CISO at One Source Steve Cobb is One Source’s Chief Information Security Officer (CISO) bringing more than 25 years of leadership consulting surrounding IT infrastructure, cybersecurity, incident response, and cyber threat intelligence. Since joining One Source in 1995, Steve has been responsible for providing strategic IT consulting, delivering an increased organization efficiency and security for our customers. Prior to One Source, he was a Senior Security Engineer with Verizon Managed Security and a Senior Escalation Engineer with Microsoft. Steve serves on several CISO boards and a frequent presenter at conferences such as InfoSecCon, ISSA, Cyber Defense Summit, and others.

View Details

As in-house security becomes increasingly complex and costly, organizations are in need of a reliable and safe security provider. Join industry experts as they discuss the latest trends in SEaaS, including:

-Why your organisation needs to move towards SEaaS -The different models of security as a service - SEaaS solutions and strategies

Stephanie Olsen, Customer Trust Manager, Product & Application Security, Netflix & WiCyS Silicon Valley Affiliate President Sailaja Kotra-Turner, CISO John Frazier, Chief Operating Officer, Synoptek Jeremiah Dewey, VP Managed Services, Rapid7

View Details

Are you interested in learning how YOU can build securely on AWS? Join us for the AWS Security Jam learning series - a hands-on, team-oriented, gamified learning experience which will enable you to leverage a wide range of AWS security services. If you get excited about securing workloads in the cloud, come and challenge your skills while learning new techniques. AWS will host three Security Jam sessions (beginners, intermediate, and advanced), so join us for all three or pick the session most relevant to you. We will have a number of AWS experts virtually available to discuss ideas, provide guidance, and help your team get through any challenges.

View Details

Choosing which cybersecurity projects to implement is more challenging than ever. Cyber risk changes daily and budgets are changing too as the COVID-19 pandemic continues to unfold. Register to see why leading companies are using a data-driven approach to make better decisions about which projects to prioritize, and learn how modeling risk helps optimize cyber spend.

Join us to learn: + What’s changed in how companies look at risk remediation and ROI pre- and post-COVID + Why the prioritization of cyber spend is more important than ever + How to take a data-driven approach and what data you need to get started + Why modeling is important and how you can do this easily (demo)

View Details

Join us for an informative webinar on how IT managers and small security teams can prevent ransomware from infecting their company’s networks. Ransomware on the rise and no longer focused only on large enterprise (average-sized company impacted in 2019 around 650 employees). Organizations with small security teams or that leverage their IT teams to manage security need help to protect from the growing wave of cybercrime. Here’s what to expect from our webinar on ransomware: - How to identify where you are exposed so you can fix your vulnerabilities - Why and how to segment your network and identity management programs - What kind of a response and recovery process you need in place

View Details

Find out what happens…when intel analysts stop being polite…and start getting real.

Today’s typical enterprise security team subscribes to at least four, often more, intelligence feeds, which analysts must comb through to find relevant information for operationalization. As a result, most threat intel has become “yet another tool to manage.” It’s simply not practical to expect every security organization to be able to hire threat intelligence analysts to make sense out of the feeds. Vendors need to deliver “threat-analyst-in-a-box” capabilities, so intelligence can be operationalized with minimal intervention.

In this session, a blue-chip panel of cyber threat experts will discuss the state of current threat intel offerings, and dive into the future of this space to help you understand how it will evolve to meet the needs of enterprise security teams. They will discuss how the next generation of threat intelligence will conform to the conventions of government intelligence operations, where the right information goes to the right people and systems in the right form factor.

Attendees will learn:

​Why general-purpose threat intelligence won’t cut it and how it needs to be customized to each organization’s risk profile.

What enterprises need to do to make the market mature in this evolving industry.

​How to take the right approach to threat intelligence and big data.

View Details

By popular demand, this CISO Insights webinar is a follow-up to the immensely successful sessions held in March and May. The webcasts (links in Attachments): "Coronavirus Actions and Risks for Tech and Security Leaders" & "Back to the Office – Or Not? Next Steps in Pandemic Technology Response" were viewed thousands of times, and numerous attendees asked for this update.

Join this roundtable discussion to learn more about: - Back to the office timing, decisions, strategies and tactics on the ground - Quick Sector updates for government, manufacturing and healthcare - Unemployment fraud - Noticeable spike in phishing in June (related to civil unrest/Anonymous?) - Team chemistry through the lockdown (how has onboarding been) - Revenue loss impact on teams (downsizing? How has off-boarding been accomplished?) - Overall CISO mental health through the quarantine and civil unrest

Speakers: - Dan Lohrmann, CSO & Chief Strategist, Security Mentor, Inc. - Earl Duby, CISO, Lear Corporation - Vinod Brahmapuram, CISO, State of Washington - Scott Larsen, CISO, Large healthcare provider

View Details

Remote working has been a growing trend for the last few years, especially in the tech sector. However, the COVID19 outbreak has really pushed businesses to adopt or accelerate their remote integration plans. How has this affected security? What are the steps companies need to take to better protect their remote workforce?

Join this episode as we explore the security challenges in the time of COVID, why a strong security culture is important, and what steps to take today. - What are the security challenges associated with remote working - Examples of changes in cyber-attacks during COVID - Managing patching, VPNs, and backups for large and small remote workforces - How to maintain auditability and visibility - How to enable and keep your remote team secure - ​Tips for training end users to help themselves - Why a strong security culture matters now more than ever

Panelists: - David Sherry, CISO, Princeton University - Lee Imrey, Cybersecurity Advisor, Splunk - Nathan Howe, Head of Transformation Strategy, EMEA, Zscaler

This episode is part of The (Security) Balancing Act series with Diana Kelley. Viewers are encouraged to ask questions during the live Q&A.

View Details

About this webinar: Join the Women's Society of Cyberjutsu for a conversation with our distinguished leadership professionals Margot Halstead and Sarah Moffat to explore the different strategies and tactics towards transitioning into a leadership role. This seminar will focus on the common challenges with this transition focusing on the specific tendencies and habits women encounter through this transition.

About Margot Halstead Margot's work focuses on helping leaders realize their greatest potential by identifying how they are potentially getting in their own way. She has coached, written and published articles, as well as designed and delivered 100’s of team and leader development programs for and with a diverse spectrum of organizations. Margot is an engaging facilitator noting the key to her success has been the ability to relate to all members of the team, forge immediate trust and connection, and relate the goals of the team to desired business outcomes. She has developed and delivered courses, workshops, and presentations on leadership transitions, emotional intelligence, communication skills, management, mentoring, executive presence and handling difficult people.

About Sarah Moffat Sarah is a talent development expert, and both an 'ideas person' and strategic initiator. Sarah’s passion is working with people, strengthening the culture of learning and leadership development, and finding new ways to engage, empower, and excite learners. When leading teams, Sarah employs transformational and servant leadership to engage them and create space for team members to build their strengths and contribute in a way that brings fulfillment and job satisfaction. Sarah has more than 15 years in talent development with a B.S. in Psychology, and is an Independent Certified Coach, Trainer, and Speaker with the John Maxwell Team.

View Details

Matt Linton, a member of Google's Detection and Response team and Niru Ragupathy, a member of Google's Offensive Security team pair up to showcase how red and blue teamers can learn from each other. They walk through a hypothetical attack from start to finish, at each step switching between the point of view of Attackers and Defenders to highlight what each side sees and does, showcasing what makes each side rewarding and fun.

View Details

We are committed to racial equity within WiCyS and the cybersecurity profession. Join us for a candid conversation on what it means to be an ally for the BIPOC cybersecurity community. Jessica Robinson will host a Q&A session to share more about her experience in infosec through the lens of race and gender and how we can all be allies.

View Details

As an information security professional knowledge of cloud security and cyber-attack tactics and techniques is critical to protecting your organization. Data breaches threaten organizational financials and reputations. Strengthen your security through the use of actionable intelligence. Attendees will hear about:

Cloud Common Body of Knowledge

Cyber Attack Tactics & Techniques

Tips to Protect Your Organization

View Details

This Election Hacking episode will explore the recent wave of SIM swap attacks in the context of MFA compromise, account hijacking and data theft ahead of the 2020 election.

Can SIM swapping be used to target and steal identities of high-value individuals in the 2020 elections (e.g. campaign staff, influencers, local election officials)?

Join this panel to learn more about: - Why attackers are focusing on identities - SIM swap attacks and two-factor authentication - Phishing - most commonly used for SIM swapping - Other ways attackers can get the victim's info - What can be done to protect digital identities - Early SIM-swapping attack warning signs

Speakers: - Allison Nixon, Chief Research Officer at Unit 221B - Cody Hussey, Security & Privacy Advocate, Solutions Engineer at Yubico

Moderator: David Morris, Executive Director at Digital Risk Management Institute

This episode is part of the Election Hacking Original series examining the threats to democratic elections, the technologies used to power and hijack elections, and what's needed to educate and empower voters before Election Day.

View Details

Gartner predicts that by 2021, over 75% of midsize and large organizations will have adopted multi-cloud or hybrid IT strategy. The corporate perimeter has been redefined.

In this session, we’ll discuss:

Six major cloud security threats along with risk mitigation and avoidance tactics Best practices to help secure cloud deployments Shared Responsibility Model for Cloud Security

Speakers: Jo Peterson, Vice President, Cloud and Security Services Stan Lowe, Global Chief Information Security Officer, Zscaler Tyler Cohen Wood, Cyber Security Expert, Former Senior Intelligence Officer Mark Lynd, Head of Digital Business at NetSync Paul Love, SVP Chief Information Security & Privacy Officer, Co-Op Financial Services

View Details

One of the basic principles in information security is the Principle of Least Privilege. The idea is simple: give every user and system the minimal amount of access required to perform their tasks - yet every day security practitioners struggle with the balance of access and security. This talk analyses how privilege escalation occurs as a result of overreaching permissions, the various tooling and strategies used to achieve this goal, and the challenges involved with the creation of such tooling.

View Details

Cloud security remains a challenge for enterprises, especially in the new post-COVID-19 reality of 2020 and the shift to remote working. What are the new threats on the horizon and compliance considerations to keep in mind?

Join this interactive panel of cloud security experts and industry leaders to learn more about: - New and old cloud security threats to keep in mind - Why visibility is key for cloud security - Know your cloud: Who is accessing what and when? How was their identity verified? - Privileged identities and what's needed for secure privileged access - Compliance challenges and considerations - Best practices for securing your data in the cloud

Speakers: Diana Kelley, Cybersecurity Field CTO, Microsoft Andy Givens, VP Solutions Engineers, North America, CyberArk Manav Khanna, Senior Director of Product Management Identity & Access Management, Thales Tim Bach, Vice President of Engineering, AppOmni

View Details

Is your organization aware of the main differences in data regulations around the world?

Join this panel of industry leaders for an interactive Q&A roundtable to get a comprehensive look into the different data privacy and security requirements. The panel will also discuss what to expect in 2020 and beyond.

Viewers will learn more about: - What's new on the data privacy and compliance landscape - Main differences between data regulations around the world and what this means for your organization - Expert recommendations regarding best tools and practices for achieving and maintaining compliance - The future of data privacy - What to expect in 2020 and beyond

Mali Yared, Practice Director, Cybersecurity and Privacy, Coalfire (Moderator) Robert Razavi, Senior Security Architect CTO Office, IBM Canada Baber Amin, CTO West, Ping Identity Lori Robinson, Sr. Director, Product & Market Strategy, SailPoint Elliot Dellys, Director, Strategic Consulting, Trustwave

View Details

The growth of cloud service is expected to reach $623.3 billion by 2023. Current world events are accelerating cloud adoption as costs are being driven down within corporations and cloud adopters. With this unprecedented growth bringing opportunities, it is also bringing risks. These risks affect your data, security, privacy and touch upon all parts of a business. This session examines some of the areas which affect security, privacy and compliance in the cloud. We will go through various areas of a cloud platform and service to highlight where potential risks could lie. During the talk we will look at what evidence and actions may be needed to manage risks and assure privacy and compliance in the cloud. We will also touch upon some of the regulations that are driving privacy and security in the cloud and will interpret these into practical and meaningful measurements to allow you to assess a cloud supplier based upon your specific needs for data protection and security for a given jurisdiction, service or product.

View Details

In Singapore, the Government launched an app using short-distance Bluetooth signals to connect one phone using the app with another user who is close by. It stores detailed records on a user's phone for 21 days decrypt the data if there is a public health risk related to an individual's movements.

China used a similar method to track a person's health status and to control movement in cities with high numbers of coronavirus cases. Individuals had to use the app and share their status to be able to access public transportation.

The keys to addressing privacy concerns about high-tech surveillance by the state is de-identifying the data and giving individuals control over their own data. Personal details that may reveal your identity such as a user's name should not be collected or should be protected with access to be granted for only specific health purposes, and data should be deleted after its specific use is no longer needed.

We will discuss how to protect privacy sensitive data that is collected to control the coronavirus outbreak.

View Details

There have been countless insider threat breaches recently, it’s no surprise that research suggests that up to 60% of cyberattacks are due to insider threats. With so much at stake, it's vital for organizations to protect against insider threats.

Join this interactive panel of industry experts as they discuss:

  • How to protect your organisation from insider threats
  • Latest technologies and solutions
  • Benefits of early and timely detection

Arun Kothanath, Chief Security Strategist, Clango (Moderator) Shahrokh Shahidzadeh, CEO, Acceptto Eitan Bremler, Co-Founder & VP Corporate Development, Safe-T John Pepe, Regulatory Technology and Counsel, Proofpoint Jeremiah Dewey, VP of Managed Services, Rapid7

View Details

The destruction of hard perimeters, the rise of remote work and mobility, and increasingly hybridized infrastructures push identity to the center of enterprise security. Join us as we discuss identity-centric security in a multicloud environment, and concrete steps you can take towards that goal.

View Details

Phishing is one of the most common tactics used by attackers; in fact, according to the 2020 Verizon Data Breach Investigations Report, 22% of all breaches involved phishing, and 81% of cyber-espionage attacks were the result of phishing. Using email, attackers trick victims into handing over or compromising sensitive information such as user names and passwords, or downloading malware. How can organizations avoid being reeled in to phishing scams? Multi-factor authentication, or MFA.

“Don’t Feed the Phish! How organizations can use MFA in the fight against phishing”, will provide a behind-the-scenes look at how phishing attacks are launched, the damage they can cause, and how to mitigate that damage using Idaptive’s Next-Gen Access Platform and adaptive MFA.

Key Takeaways:

Gain a deeper understanding of how phishing is being used by cybercriminals to compromise organizations, especially in the area of compromised credentials and passwords

Learn how multi-factor authentication (MFA) can be used to fight phishing and why it’s such an essential tool for thwarting attackers Understand the security, ROI, extensibility and cost benefits of Idaptive MFA

View Details

Global commerce was in transition before the pandemic. Now, businesses are accelerating their digital aspirations and work will never be the same. Mobility has raised business productivity, but it’s brought its share of issues, as well. One of the biggest challenges is the need to provide complete, consistent security across devices that you may not own.

• How do I control in one place the security and identification of all devices connecting to my network?

• How can I address the challenge of managing security in a world where cloud computing, mobility and the Internet of things are eroding the network perimeter?

• How can I provide Data Privacy and Data Security and be compliant with GDPR and local regulations?

• How do I give support engineers access to my organization's admin portal, provides Internet security, web security, firewalls, sandboxing, SSL inspection, antivirus, vulnerability management and granular control of user activity in cloud computing, mobile and Internet of things environments?

• How can I provide automated threat forensics and dynamic malware protection against advanced cyber threats, such as advanced persistent threats and spear phishing.

• How can I repurpose the existing WiFi and create key metrics of the deployment and visitors use and integrate data with existing CRM tools?

• How do I dissociate and secure the use of my network among daily guests, consultants, employees and IOT devices?

We will discuss how a cloud-based proxy and firewall can route all traffic through its software to apply corporate and security policies.

View Details

In order to effectively use cryptography to protect information, one has to ensure that the associated cryptographic keys are also protected. Attention must be paid to how cryptographic keys are generated, distributed, used, stored, replaced and destroyed in order to ensure that the security of cryptographic implementations are not compromised.

This webinar will introduce the fundamentals of cryptographic key management including key lifecycles, key generation, key distribution, symmetric vs asymmetric key management and integrated vs centralized key management models. Relevant standards, protocols and industry best practices will also be presented.

After you watch the webcast, check-out the Q&A blog at: https://bit.ly/3dcnpId

View Details

IoT initiatives are exploding. Nemertes has found that companies with successful IoT initiatives are increasing both the number of projects and the device count, with growth that ranges up to 100%+ year over year.

Scaling these initiatives requires scaling not only the IoT solutions, but also the infrastructure and cybersecurity environments in which they operate. As enterprise technologists begin to apply next-generation cybersecurity approaches like zero-trust, they need to think seriously about how to automate the control and management of their cybersecurity and infrastructure.

The answer? Automation. Successful organizations are more likely to automate earlier, more aggressively, and more comprehensively—with dramatic improvements in performance, security, and reliability.

Find out why automation is critical to securing, managing, and scaling IoT—and what best practices can help ensure success in implementing it.

View Details

Almost overnight COVID-19 upended everyday life as we knew it. A risk that we didn’t even know we faced took center stage both personally and professionally. In this webinar, learn how businesses’ approach to cyber risk management changed in 2020, including: - What’s driving cyber risk mitigation decisions today—and what’s very different than it was on January 1 - Important factors to consider when re-prioritizing your cyber mitigation initiatives - Factoring in systemic or cascading risk to measure cyber risk across an entire company portfolio - Innovative ways to manage and communicate risk

View Details

Ransomware, ransomware, ransomware. Why are our current endpoint defenses so inefficient? We will take three leading endpoint security (antivirus) products and demonstrate live how ransomware developers use trivial techniques to bypass all of them. Often a single line of code is all that’s needed to render antivirus ineffective and all data lost.

NOTE: This webinar is applicable to technical audience only. We will be digging right in the source code and compiling ransomware on the fly.

Presenter: Nir Gaist, founder & CTO of Nyotron, is a recognized security expert and ethical hacker. Nir has worked with and pentested some of the largest Israeli organizations, such as banks, police and the parliament. He also wrote the cybersecurity curriculum for the Israel Ministry of Education.

View Details

One of the most important aspects of security is how to protect the data that is just “sitting there.” How easy is it to get to? Who can get to it? If someone does get access to the data, can they read it? What are the potential risks of the wrong people reading the data? These are just a few of the questions that we try to answer when we go through the process of securing data.

Contrary to popular belief, however, securing “data at rest” is not simply encrypting the data. While it is true that data encryption plays a major role in securing “data at rest,” there are several other factors that come into play and are equally as important – if not more so.

For this webcast, we’re going to talk about those other factors (Encryption is deserving of its own, specific webcast). We will present the end-to-end process to securing “data at rest,” and discuss all the factors and trade-offs that must be considered, and some of the general risks that need to be mitigated, discussing:

• How requirements for “data at rest” differ from “data in flight” • Legal and regulatory reasons to protect (or delete) data at rest • Where and how data could be attacked • Understanding the costs of ransomware • How to protect cryptographic keys from malicious actors • Using key managers to properly manage cryptographic keys • Strengths and weaknesses of relying on government security recommendations • The importance of validating data backups... how stable is your media?

After you watch the webcast, check out the Q&A blog at: https://bit.ly/2CWbh1J

View Details

The world has changed, and so has your threat landscape. Join us for a discussion on how cyber attacks have pivoted their tactics and targets. From the latest on phishing kits to video threats, our experts will explore how changes in motives and targets is disrupting and increasing our threat landscape. Learn how to reframe your understanding of your threat profile and better defend and respond to these attacks.

Our featured experts for this webinar include Richard Stiennon, chief research analyst at IT-Harvest and Kurtis Minder, CEO of GroupSense, GroupSense is a digital risk management company that delivers customer-specific intelligence. Here’s What Will Be Discussed:

1) Threat actors are adapting their tactics and targets 2) Changes in motives and targets are disrupting and expanding the threat landscape 3) Understanding your threat profile to create a better cyber defense strategy.

View Details

In the fight against COVID-19, countries are taking urgent actions to address the crisis. Some are turning to tech to find solutions for containing the spread of the virus. Digital contact tracing, in particular, is gaining a lot of traction. For example, Apple and Google recently announced a rare collaboration to jointly facilitate contact tracing within their mobile platforms for public health monitoring applications. So, what does this mean for privacy?  While some efforts are being made to preserve user privacy, like not tracking user location or collecting other identifying information, digital contact tracing can still reveal more user information than necessary.

Join this panel of security and privacy experts lead by Chenxi Wang to learn more about the different implications associated with digital contact tracing, how it is being used around the world, and the long-term effects of COVID-rushed decisions.

Speakers: - Chenxi Wang, Founder & General Partner of Rain Capital - Vishwanath Raman, Lead, Privacy Technologies, Oasis Labs - Michelle Dennedy, CEO Drumwave - Tom Pendergast, Chief Learning Officer, MediaPRO

View Details

Crippling ransomware attacks are on the rise and U.S. cities are falling victim at alarming rates. The public sector is especially vulnerable because state and local governments tend to have outdated computer systems and maintain sensitive data which is highly desirable to attackers.

Join this episode of the Election Hacking series to learn more about the ransomware threat to state and local governments and what this means for the 2020 U.S. presidential election. - The year of ransomware - How cities and states are coping with the scourge of ransomware - The ransomware dilemma: Pay the ransom or fight the infection - How AI is enabling - and helping fight - ransomware attacks - Ransomware as a threat to democracy

Moderator: David Morris, Executive Director at Digital Risk Management Institute

Panelists: - Lee Imrey, Cybersecurity Advisor, Splunk - Brett Foy, Global Vice President, Engineering, Datrium - Lance James, CEO of Unit 221B

This episode is part of the Election Hacking Original series examining the threats to democratic elections, the technologies used to power and hijack elections, and what's needed to educate and empower voters before Election Day.

View Details

Encryption has been used through the ages to protect stored secrets, authenticate messages, communicate secretly in broad daylight, and even to check that messages were properly transmitted and received without tamper. Now, it’s often our first go-to tool for making sure that data simply isn’t readable to prying eyes, ears or AI bots.

But how does encryption actually work, what makes it tick, and how is it managed? How do we ensure compatibility? How do we protect the keys; i.e., “Who will guard the guards themselves?”

It’s a big topic that we’re breaking down into three parts: Encryption 101, Key Management 101, and Applied Cryptography.

Join us on May 20th for the first encryption webcast: Storage Networking Security: Encryption 101 where security experts will cover:

•A brief history of Encryption •Cryptography basics •Definition of terms – Entropy, Cipher, Symmetric & Asymmetric Keys, Certificates and Digital signatures, etc. •Introduction to Key Management

After you watch the webcast, check out the Encryption 101 Q&A blog at https://bit.ly/2ZGMisl

View Details

Smaller businesses have a common problem when it comes to cybersecurity - limited expertise, resources and budget.

The board is asking for, clients are demanding to know whether the company is secure, IT team can't articulate the cybersecurity program, because there isn't one.

Cybersecurity is sometimes an afterthought for a start-up, or delegated to one engineer. There's a tendency to think of cybersecurity as a set of tactical, technical implementations to cover obvious threats rather than a business problem.

We'll discuss the role of the CISO in terms of providing the leadership and strategy for a cohesive, risk based program. Ideally, the role is not a technician.

With an ever-evolving threat landscape and a growing business, where does a business start to build and maintain an affordable program? We'll discuss a baseline program, technologies required, focusing on fewest technologies for maximum benefit.

This episode is part of The (Security) Balancing Act series with Diana Kelley. Viewers are encouraged to ask questions during the live Q&A.

View Details

As the world continues the work-from-home initiative in order to combat the COVID-19 threat to humanity, organizations must also consider that threat actors (hackers, Advanced Persistent Threats, etc.) may take this opportunity to exploit existing vulnerabilities normally mitigated in an office environment behind a firewall, as an example, but not necessarily mitigated in a Telework environment. This presentation will discuss the following topics

  • Discuss the recent rise Threat Actor exploits of Telework applications, and provide a means of ‘visibility’ by organizations to detect, analyze and remediate threats attempting to exploit vulnerabilities.

  • Visibility into emerging threat capabilities to introduce ransomware and malware into a remote computer/mobile device. Example: COVIDLOCK ransomware on Android smart phones and how to detect and remediate.

  • How VPN is only a step in the right direction towards accessing and transmitting secure, sensitive data. How additional applications and best practices can assist organizations to maintain Confidentiality, Integrity and Availability (CIA) in the near-immediate term.

  • The advantage of educating employees on the dangers associated with working remote, and whether use of personal devices versus company-provided devices are viable options.

  • How Software as a Service (SaaS), Infrastructure as a Service (IaaS) providers can assist your organization in maintaining effective CIA in a Work From Home environment. The presenter will also discuss limitations and the often overlooked Shared Responsibility.

View Details

Every company in the world is being forced to digitize their customer and supplier interactions while enabling flexible work from home patterns. Just like trying to change a tire on a car going 60MPH, businesses are forced to adapt quickly because of today’s state of business. Hackers are licking their chops as more digitization happens quickly CIOs and IT Teams are more vulnerable than ever.

Join us as our security experts discuss the following cyber-attack trends and recommended strategies for better security in 2020:

  1. The Digital Data Attack Surface
  2. Cloud / Endpoint Visibility Challenges
  3. De-Risk Data in the Cloud
  4. Incorporate CyberSecurity into Risk Management
  5. Six Practical Steps to beat Hackers

View Details

In this session you are going to hear about application security and open source software. A review of how open source software grows and how vulnerabilities are created. Vulnerabilities in open source software increase the risks of exploitation, it is critical then to understand the dynamics of how open source software is built and to have a plan in place to reduce risk. A security plan around visibility, early stage in the development lifecycle and policy governance.

Open source sparks innovation, it provides bug fixes and security fixes, the solution is not to stop using open source software. All new technologies from AI and Machine Learning to Virtual Reality, self-driving cars and robotics are built in the open, so there’s no turn back. The best approach is to keep up with the progress in open source, to shift-left and automate application security.

This session will provide: -Insight into how open source software works and grows -How to address security for open source components -How to keep up with constant changes and new vulnerabilities

View Details

Firewalls and IPSs don’t replace but rather complement each other’s roles in securing the parameter, yet some are insisting that analytics, analysis, and Machine Learning are meant to replace each other when it comes to situational awareness. This Session will help explore how these concepts complement each other to help achieve better situational awareness.

View Details

Welcome to the world of IoT (Internet of Things) as more and more devices get connected online. With weak or almost no security these devices can easily become a victim, be turned into a BOT which can then be controlled and used to participate in a DDoS (Distributed Denial of Service) attack or turn systems into bricks along with the data.

This session walks you through the reality check on the risks and threats that IoT devices introduce to the business and what you can do to reduce the risks. A best practice approach to an IoT Risk Assessment.

  • What are the biggest risks from IoT devices?
  • What are the biggest threats from IoT devices?
  • Best Practices in reducing the risks
  • Future of IoT Security

View Details

A few months ago, security vendors were offering up cyber threat predictions for 2020 and product roadmaps indicating how solutions were evolving to address the shifting threat landscape. Market research firms were sharing revenue projections and providing guidance to end-user organizations intended to help them solidify their security strategy and budgets for the year. And then along came the coronavirus.

The rapid on-set of a global pandemic has changed both the threat landscape and what organizations should be spending their security budgets on, almost overnight. An all-remote workforce opens the door to new opportunities for malicious activity by bad actors; stealing passwords and data is easier, and critical business applications are at greater risk as employees attempt to access both on-prem and cloud-based apps from home.

In this webinar, Identity and Access Management (IAM) experts from Sennovate and Idaptive will address the role IAM and adaptive multi-factor authentication (MFA), in particular, can play in both enabling and securing the remote workforce. Adaptive MFA, based on the oh-so-important principles of Zero Trust—“never trust, always verify”—holds the keys to dramatically reducing risk and improving compliance, no matter where an organization’s employees are in the world. Best of all, adaptive MFA improves user productivity and happiness, while reducing IT and helpdesk overhead.

Attendees will gain an understanding of: the new or increased threats caused by the surge in remote workers; the critical role that IAM and adaptive MFA can play in filling any security gaps that may still exist across a far-flung labor force; and the benefits of adaptive MFA, including improved user productivity and job satisfaction, and reduced IT and helpdesk burden.

Speakers: Vishnu Varma, Sr. Director, Product Management, Idaptive Senthil Palaniappan, Founder & CEO, Sennovate Inc.

View Details

With constantly changing physical and technological environments, companies and individuals are encountering the most difficult time in history to develop and maintain Resilience. As we to continue to build smart cities and smart nations, connecting our cloud-based networks to Internet-of-things (IOT) devices and other operational technologies, our lives are being impacted more and more and we have rapidly increasing risk, by virtually expanding our threat surface.

With 83% of enterprise workloads being hosted in cloud-based environments, today's leaders are being exposed to extreme challenges in understanding and addressing the intangible risks that could cripple an organizations entire supply chain in real-time.

In order to combat this growing threat, Greg Tomchick and his team at Cyber Defense Labs empower organizations to adopt a proactive approach to minimizing the connected risks across the enterprise, while meeting or exceeding regulatory requirements.

Be sure not to miss this important conversion on what you can do to protect your corner of cyberspace, build operational resilience in the cloud and how we can work together to address this important issue as we voyage through 2020.

View Details

May 2020 marks the 2nd anniversary since EU's General Data Protection Regulation (GDPR) came into effect. How has the world of regulations changed in the last two years, and what else can we expect on the privacy and compliance landscape?

Join the PCI Dream Team as they celebrate GDPR's 2nd birthday - while social distancing from home - with a fun and insightful Q&A discussion on all things GDPR, CCPA & PCI DSS.

Grab a seat, eat some cake and bring us your toughest compliance-related questions.

Our panelists are some of the top PCI QSA’s in the country, with decades of combined PCI and card processing experiences. They’ve seen it all: the good, bad and ugly; and lived to tell the tale.

View Details

In today’s multi-cloud and hybrid environments, CISO's are struggling to secure assets, manage security policies across clouds, monitor and mitigate risks, while also supporting the business. How are CISOs solving the challenge of complexity?

Join this panel of experts to learn how to simplify cyber risk management as well as maximize the value of your team and technology. - Risk scoring and security controls - How to identify risks for organizations and their third-party vendors - How to prevent, detect, and respond to, privacy and network security incidents - Best of vulnerability and risk management in a multi-vendor environment - Best practices and use cases across industries

Speakers: Kalani Enos, Partner/VCISO/Threat Analysis, Immersion Security (Moderator) Terence Jackson, Chief Information Security Officer, Thycotic Rick Holland, CISO, Vice President Strategy, Digital Shadows Joseph Carson, Chief Security Scientist, Thycotic

View Details

As the cyber threat landscape continues to evolve, organizations worldwide are increasing their spend on cybersecurity technology. We have a transition from 3rd party security providers into native cloud security services. The challenge of securing enterprise data assets is increasing. What’s needed to control Cyber Risk and stay Compliant in this evolving landscape?

We will discuss evolving industry standards, how to keep track of your data assets, protect your sensitive data and maintain compliance to new regulations.

View Details

As assumption is the mother of all mistakes, the blind believe that everyone will do the right thing every time the needs to be revisited as it gives both a false feeling of safety and creates blind spots. This session will discuss how to build an understanding of your network, how to integrate it in your security practice, and how to identify deviations from that understanding.

View Details

With exponential growth in Cloud technology adoption, there are emerging security and privacy threats that need to be managed. The law is almost always playing catch up with technology advancements and regulators across the globe are starting to drive changes to bring more accountability and transparency in Cloud Privacy. It started with the GDPR and there is a lot more regulation to come.

This session looks at some of the emerging international compliance regulation and considers the impact on Cloud Privacy. It factors costs and benefits and seeks to determine if it is the regulators or consumers of Cloud services that are the driving force behind the demands for more accountability and transparency. We discuss buyer, supplier and organisational behaviour and ask the question, will the drive for Cloud Privacy ultimately lead organisations to profitability or is Privacy just another cost of doing business in the modern world?

About the speaker:

Paul, is often described as the missing link between legal, business and technology as he is one of the few people to bridge the gap in compliance, translating complex legislative requirements into privacy and security deliverables as well as delivering successful privacy and training programs.

Paul specialises in cloud privacy and has many years of international experience working in regulated and non-regulated industries, working on compliance projects and programs. He is a Certified Information Privacy Professional (CIPP/E), a certified international DPO (University of Maastricht) a Certified Cloud Auditor and is also certified in Cloud Security (CCSK).

View Details

Examination of the threats and advances of malware in 2020. New techniques from existing threat groups and emerging trends. Examination of popular botnets, attack techniques, and current defenses.

View Details

As the number and frequency of malware attacks continue to increase, we look at the threats, vulnerabilities and risks factors associated with malware attacks and how to keep your organizations secure.

Join this keynote panel with security experts as they discuss malware trends, strategies and tools for better security in 2020:

• The most prevalent threats in 2020 • Identifying the latest malware delivery tools and techniques • Developing a modern defence strategy and empowering your users • Malware strategy best practices

Speakers: Joseph Carson, Chief Security Scientist, Thycotic (Moderator) Pedro Uria, Director of PandaLabs, Panda Security Jack Mannino, CEO, nVisium Stan Lowe, Global Chief Information Security Officer, Zscaler John Aarsen, SE - Benelux and Nordics, SonicWall

View Details

Zero trust assumes any user or system that accesses the network, services, applications, data, or systems starts with zero trust basically meaning no access to anything. To gain authorized access, trust must be earned by the prospective user through verification and security controls.

The Principle of Least privilege which helps enforce a Zero Trust approach is intended to prevent “over-privileged access” by users, applications or services to help reduce the risk of exploitation without impacting productivity or involving the IT help desk. It may help to think of least privilege by its other name - least authority - as it provides only enough authority for an entity to complete the job at hand. The least privilege model can also help curtail costs and increase efficiency.

Join this webinar to understand how to maximize the benefits of least privilege, and learn just how much “privileged access” is too much. Join Thycotic’s Chief Security Scientist Joseph Carson and learn more about: • The Principle of Least Privilege • Realities of the Zero Trust Model • Best practices to get back in control

View Details

As the United States enters a new phase in Covid-19 response, how are businesses and governments responding? What lessons have been learned, and what next steps are organizations taking? How can technology and cybersecurity mistakes be avoided?

Join this webinar for the latest coronavirus playbook roundup and recommendations on how to address the next phase of the outbreak. Learn the scope of the unprecedented challenges organizations are currently facing. Hear from industry leaders on how they are addressing the COVID-19 security and technology challenges.

By popular demand, this webinar is a follow-up to the immensely successful BrightTALK session held on March 13 at the beginning of this emergency. That webcast (link in Attachments): Coronavirus Actions and Risks for Tech and Security Leaders, was viewed thousands of times, and numerous attendees asked for this update.

Topics will include: - Policy, technology and process steps to take today to protect your workforce and organization. - Lessons learned from more staff working from home (telework)? - What mistakes can be avoided as staff prepare to go back to offices –and how?

We will close with a Q/A session with the audience.

Speakers: - Dan Lohrmann, Chief Security Officer & Chief Strategist at Security Mentor Inc. - Earl Duby, CISO at Lear Corporation - Vinod Brahmapuram, CISO at State of Washington Government - Scott Larsen, CISO of a large healthcare provider

View Details

Have you ever wanted to know what is involved in a particular Cybersecurity role? If yes then join us at the WSC for a conversation with a Cybersecurity SOC analyst

Host: Connie Blaney

Guest: Afton Bell

The Unconventional Approach Afton Bell is a Cybersecurity Analyst located in Austin, TX. Her path to cybersecurity was a bit unconventional but she’s always had a passion for security. Afton was born and raised in East Orange, NJ. She started flying single-engine aircraft at the age of 12, only a few months before the tragic events of 9/11. She saw the change of the aviation world as they started to enhance security measures across the country’s airports. In 2011, she earned 2 undergraduate degrees in Aviation Technology from Purdue University in West Lafayette, IN. After graduation, Afton followed her drive for security with a focus in IT and earned a Master of Professional Studies in Homeland Security from Penn State University in 2014. In 2017, Afton decided to shift from working in physical security management and earned multiple CompTIA certs to pursue her dream career of cybersecurity. She began working as a Configuration Lab Technician in Chicago to gain valuable experience before moving to Austin, TX for an analyst position. She recently started working as a Cybersecurity Security Operations Center Analyst for a large government entity with a focus in SIEM as of February 2020. Afton often volunteers to mentor young women interested in STEM during events in Austin and is very eager to continue to grow and evolve in such an exciting industry.

View Details

In Singapore, the Government launched an app using short-distance Bluetooth signals to connect one phone using the app with another user who is close by. It stores detailed records on a user's phone for 21 days decrypt the data if there is a public health risk related to an individual's movements.

China used a similar method to track a person's health status and to control movement in cities with high numbers of coronavirus cases. Individuals had to use the app and share their status to be able to access public transportation.

The keys to addressing privacy concerns about high-tech surveillance by the state is de-identifying the data and giving individuals control over their own data. Personal details that may reveal your identity such as a user's name should not be collected or should be protected with access to be granted for only specific health purposes, and data should be deleted after its specific use is no longer needed.

We will discuss how to protect privacy sensitive data that is collected to control the coronavirus outbreak.

View Details

With the 2020 U.S. presidential election on the horizon, what are the biggest cybersecurity threats our democracy is facing? How well is the election infrastructure prepared when it comes to cybersecurity, and what are some steps to take today to strengthen the security posture?

Join this panel to learn more about: - The current government threat landscape - Which threats can we expect to see in the next few months? - Why visibility into the security posture of election infrastructure is key - What's needed to ramp up security quickly? - Recommendations for enhancing election security

Speakers: - Mick Baccio, Security Advisor, Splunk - Dave Klein, Sr. Director of Engineering and Architecture, Guardicore - Allison Nixon, Chief Research Officer at Unit 221B

Moderator: David Morris, Executive Director at Digital Risk Management Institute

This episode is part of the Election Hacking Original series examining the threats to democratic elections, the technologies used to power and hijack elections, and what's needed to educate and empower voters before Election Day.

View Details

Digital transformation - we hear about it all the time, but what does it really mean for security? As organizations transition users, applications, workloads, and data from on-premise into the cloud to improve agility and competitiveness - how does that change their security landscape and threat model? And how can organizations address the challenge of protecting both legacy on-premise systems, while at the same time, also having to secure dynamic multi-cloud-based environment?

Join today's episode to learn about the reality many organizations are facing when it comes to juggling on prem and multi-cloud security, what the key differences are and how to address them for your organization. The panel will also discuss the following topics:

  • What are the differences between Cloud Security vs On-Premise Security and why do they matter for organizations in 2020?
  • Can we normalize our security posture across the legacy and hybrid/multi-cloud environments?
  • Is it possible to improve security as part of a digital transformation program?
  • What kind of cyber hygiene do we need to practice? What should be added and what can be taken off security teams' plates?
  • Where does DevOps (or DevSecOps) fit into all of this?
  • Are cloud security failures the customer's fault?
  • What is SASE and how will it impact your organization?

This episode is part of The (Security) Balancing Act series with Diana Kelley. Viewers are encouraged to ask questions during the live Q&A.

View Details

This is a Special Edition episode in the Election Hacking series on BrightTALK.

The Coronavirus outbreak (or COVID19), has redefined every aspect of our lives from the way we work, play, and receive emergency services.

Remote interactions may be the new normal. How will this "new normal" affect our election process and what are the ramifications from a cybersecurity point of view?

Will we be voting remotely in an electronic fashion and if so, what are the threats, vulnerabilities, and weaknesses? What can be done to prepare for a secure voting process?

Panelists: - Lance James, CEO of Unit 221B - Steven Teppler, Partner at Mandelbaum Salsburg P.C.

Moderator: David Morris, Executive Director at Digital Risk Management Institute

Join this special episode of the Election Hacking Series as we discuss this timely and critical issue.

View Details

The rapid shift to a remote workforce has put an unprecedented amount of pressure on our IT resources; however, our security experts must remain hyper-vigilant in response to bad actors who look to exploit this shift. Micro-segmentation protects organizations’ networks against lateral movement of threats inside a cloud or data center environment to reduce the risk of a security breach. It uses software overlay or network virtualization technology instead of installing multiple physical firewalls. This capability to quickly and easily segment is a key control as our work environments become more and more agile and dispersed. Join our expert panel in this free webinar to ask your questions and learn about:

• What is micro-segmentation • How, when and why you should use micro-segmentation as a key security control • How zero trust segmentation can be rapidly extended from the data center and cloud to protect users and admins on remote desktops and laptops • Common hurdles for implementing micro-segmentation • How to manage change in a micro-segmented network

View Details

New forms of ransomware attacks such as Ryuk, Bitpaymer and DoppelPaymer are asking for seven figure payments, for example a medical practice was asked for a 3.5 million ransom payment. Ransomware malware variants have become more sophisticated, and this presentation will walk through case studies about techniques, tactics and procedures observed by real threat actors.

Cyber Vaccines, such as the Dridex Cyber Vaccine, will be introduced as a method of removal and enterprise resilience measures like system hardening to prevent lateral movements will be discussed.

View Details

Will AI (whatever the “A” stands for?) ever replace humans for Automation and Threat Detection?

The advances in technology especially with AI (Artificial Intelligence) is being both embraced and feared. Automation is the key to organizations being scalable and assisting with the skilled resource shortage in the cybersecurity industry though will AI ever fully replace humans, and will it eventually be GOOD AI versus BAD AI when it comes to cyberattacks. Could humans simply become a spectator when it comes to the future cyberattacks? This webinar will look into all those questions and possible outcomes.

Join Joseph Carson from Thycotic to take a journey from the present and into the future of AI & Humans, can we coexist together?

Key Takeaways: What are the current capabilities of AI today in Threat Intelligence? Can AI prevent cyberattacks? Will AI replace humans for Cyber Defense or Offensive capabilities? Future of AI & Humans, can we coexist together?

View Details

As organizations adopt modern development technologies including Microservices, APIs and adopt DevOps & CI/CD practices the old ways to implementing QA and application security no longer work.

In this session, we will introduce new methodologies and solutions that enable companies to assure the quality and implement application security into their DevOps practices and insure high quality solutions with DevSecOps by design.

Speakers: - Gadi Bashvitz, President & CCO, Neuralegion - Aseem Bakshi, CEO, Webomates - Ulf Mattsson, Head of Innovation, TokenEx

View Details

The world is becoming increasingly connected in the digital age that is setting upon us and there is no turning back. The huge opportunities from the IT and OT convergence enable new services and increased productivity. At the same time with greater connectivity there is also greater risks to organizations because of this increased threat surface. A new approach to defend against cyber attacks is needed to keep pace with other business changes and evolving threats. Artificial Intelligence and Machine Learning technologies may present a solution to this problem.

The webinar will cover: - Why the digital economy is not cyber secured - Cyber Security Strategic choices - The threat Intelligence life cycle - Threat detection and incident response: the future - Summary

About the presenter: John Lee is the Managing Director for the Global Resilience Federation Asia-Pacific office. He is managing an Information Sharing Analysis Centre for Operational Technology operators. He had past roles in Information Security, GRC and Operations working for MNCs covering APAC and Middle East. He is the immediate past President of the ISACA Singapore Chapter. He had also taught various cybersecurity certifications from ISACA and ISC2. He is a certified APMG trainer for ISACA.

View Details

For decades, security teams have been training employees on the risks of falling for phishes. Despite this, phishing still continues to be a top risk for many organizations and continues to grow in the age of Covid-19. Now more than ever security teams and numerous security awareness studies have seen the limitations of using training to change behaviors in our employees. This talk will focus on how to leverage learnings from behavioral science and psychology to motivate employees to be the best defenders they can. We will walk through examples of how principles like social proof, rewards, gamification, and case studies have been successfully used to improve phishing resiliency. We will then walk through how organizations can implement these approaches to change behaviors like reducing clickthrough, increasing reporting, and driving adoption of MFA.

View Details

As an information security professional knowledge of the trends, tactics and techniques facilitate a powerful tool against malicious actors. Data breaches threaten organizational financials and reputations.

Strengthen your security through the use of actionable intelligence. During this attendees will hear about:

  • Incident Response Trends
  • Cyber Attack Tactics & Techniques
  • Tips to Protect Your Organization

View Details

The world is changing, and the cybersecurity world is too. The cybersecurity strategy we had 18 months ago is no longer good enough.

In this talk, we will propose 3 things that need to change to create a strategy for the current and future environment.

*El mundo está cambiando y el mundo de la ciberseguridad también. La estrategia de ciberseguridad que teníamos hace 18 meses ya no es lo suficientemente buena.

En esta charla, propondremos 3 cosas que deben cambiar para crear una estrategia para el entorno actual y futuro.*

View Details

Technical detection is now just the starting point for a series of exercises which will see the entire business work together to identify what happened and to mitigate the results.

In this session, you will learn:

  • How EDR and MDR are morphing into BDR
  • Why BDR is a challenge for the whole business
  • How technology can help, and how it doesn’t

In this 30 minute webinar Ade will discuss how the world of cyber-security detection and response is changing, fast. From IT and technical analysts to the CEO via HR, this is a problem for the whole business to solve together.

View Details

While cyber attacks come from all directions, the majority of them originate on endpoints. In this webinar UJ Desai, Director of Product Management at Bitdefender will discuss why organizations are still struggling with endpoint security, and will explore the five critical elements of endpoint security that will allow organizations to effectively defend endpoints from both common and advanced cyber attacks.

View Details

Incredibly, 90% of all Security Breaches originate with a Phishing Email and most all breaches trace back to human error. In spite of this reality, businesses spend relatively little time and money on training and testing employees' ability to recognize and prevent the most common Cyber Criminal points of entry.

In a survey conducted by Mimecast, only 45% of organizations provide mandatory Security Awareness Training and of that, only 6% do it monthly. With all we know about learning behavior and corporate culture, how do we get better at raising awareness levels, lower risk, and delivering training in a manner that works?

In this talk, Craig Sandman of Symbol Security, and Security Awareness Practitioner Jonathan Osmolski will walk you through the current realities of Security Awareness, both the Cyber Criminal environment, and what a CISO and Security team has to navigate through in order to execute a program. They also touch on some Security Awareness Specifics, like how to successfully execute meaningful Security Awareness Training and how often should you be training your employees. Join us and find out how you can ensure success in your organization!

View Details

According to The Cost of Insecure Endpoints report from Ponemon Institute, ineffective endpoint security strategies are costing these organizations $6 million annually in detection, response, and wasted time

Endpoints are the new network perimeter. Attackers know this. Endpoint threats pose a significant risk to organizations large and small. A report by IDC shares that that 70 percent of cyberthreats actually originate from endpoints. As the bad actors become more sophisticated so should your end point strategy.

Redefine the concept of “endpoint” Learn why the Global endpoint market is due to double by 2026 Understand effective security measures needed to protect endpoints Get tips for a unified endpoint security strategy that can help you stay ahead of bad actors.

Moderated by: Jo Peterson, Vice President, Cloud and Security Services, Clarify360 Panelists: Tom Gorup, VP, Security & Support Operations, Alert Logic Wade Woolwine, Principal Security Researcher, Rapid7 Juergen Bayer, Product Consultant - Security, HP

View Details

What do oBike, a bicycle rental company, Instagram, and the IRS have in common? Answer -- hackers used APIs to access their customers sensitive information forcing these organizations to announce breaches. Although these API attacks were exposed, most API-based attacks go undetected these days – particularly attacks that used compromised credentials.

This webinar will discuss API cyberattack examples and the techniques used by hackers to breach APIs. It will also review how AI-based security ​solutions can effectively stop these attacks and provide deep visibility into your API sessions for forensic and compliance reporting. Topics covered in this webinar include: - API cyberattack trends - Review of recent API attacks - How to monitor and protect your API activity - How to detect and block API attacks on your data/apps (live demo) - How to deliver reports with detailed traffic insight for any API - Best practices for securing APIs

View Details

Cyber security is a hot topic as the world has witnessed a rapid increase in cyber-attacks, data breaches, data leaks and espionage. Governments are taking cyber security seriously, increasing investment in both defensive and offensive capabilities, and introducing regulations to support legal frameworks.

Unfortunately, cyber-attackers don't sleep or take vacations and this means you must be prepared and ready at any time during the day or night.

Join this webinar to learn about the following: - Which cyberattack is most likely the one that will hit you? - What are the top threats in 2020? - What are the latest threats?

View Details

The Coronavirus pandemic has changed the world. Most organizations are scaling their “Work from Home” employee base from zero to 100%. And many organizations are in the midst of rolling out technology required to support their employees, clients, partners, and constituents.

Join Zoom, Microsoft and NTT DATA in this panel discussion as we explore how to collaborate, communicate and conduct business more securely and efficiently during this new paradigm of “distance working.”

Speakers: Sushila Nair, Security Offer Leader, NTT DATA Steve Ross, Partner & Technology Strategist, Microsoft Gary Sorrentino, CTO, CISO, Zoom Shamlan Siddiqi, CTO, NTT DATA

View Details

The cyber landscape is changing rapidly, so does the attack vectors and attack techniques. Organizations today rely mostly on Security Information and Event Management (SIEM) solution alone to help them detect and respond to cyber-attacks. Often there are blind spots in the sensor grid that let the advanced attacks slip through the cracks. Even though when an organization detects an attack, the response takes too long to protect the crown jewels.

In this session, you will learn about:

  • Techniques used by advanced attackers
  • Common pitfalls in threat detection and response
  • Threat detection and response challenges
  • Ways to improve an organization's threat detection and response capability

View Details

Existing APT and Ransomware solutions only address specific parts of the kill chain, making them ineffective at completely stopping APT and Ransomware attacks. Powered by multiple levels of implementation of machine learnings on malware, DGA and other attack behaviors, We will explore holistic approaches that addresses every step of the kill chain making it the only fully integrated security solution with NGFW, EDR and MDR today that can accurately detect and mitigate APT/Ransomware attacks from network to endpoints.

View Details

The world is becoming increasingly connected in the digital age that is setting upon us and there is no turning back. The huge opportunities from the IT and OT convergence enable new services and increased productivity. At the same time with greater connectivity there is also greater risks to organizations because of this increased threat surface. A new approach to defend against cyber attacks is needed to keep pace with other business changes and evolving threats. Artificial Intelligence and Machine Learning technologies may present a solution to this problem.

The webinar will cover: - Why the digital economy is not cyber secured - Cyber Security Strategic choices - The threat Intelligence life cycle - Threat detection and incident response: the future - Summary

About the presenter: John Lee is the Managing Director for the Global Resilience Federation Asia-Pacific office. He is managing an Information Sharing Analysis Centre for Operational Technology operators. He had past roles in Information Security, GRC and Operations working for MNCs covering APAC and Middle East. He is the immediate past President of the ISACA Singapore Chapter. He had also taught various cybersecurity certifications from ISACA and ISC2. He is a certified APMG trainer for ISACA.

View Details

Carbon Black recently found that 84% of UK organisations had suffered one or more data breaches in the past year. Effectively cybersecurity is critical for ensuring the success of your business in the digital age.

In this webinar, ThreatAware CEO Jon Abbott explores the problems that cybersecurity professionals have faced over the past year and how these are likely to evolve in 2020. He draws on his twenty years of experience, including as founder of MSP Priority One, to examine how cyber threats develop and how business cybersecurity needs to grow to meet new challenges.

From comprehensive asset management to compliance with international standards, proficient cybersecurity requires you to juggle a vast number of tools and processes. Jon’s presentation will look at the way in which innovative technology can increase visibility and reduce complexity when it comes to cybersecurity management, to allow your business to embrace positive risk in 2020.

Key takeaways - The biggest risks cybersecurity professionals faced in 2019 - How these risks are likely to evolve moving forward into 2020 - What tools allow businesses to embrace new technologies securely

View Details

Despite our advances in medical science, humans are still vulnerable to newly developed virus such as COVID-19.

One thing we know today about coronavirus: it can be extremely contagious even if patients have shown no sign of symptoms. This is remarkably similar for IT security. For example, most ransomware remains dormant for weeks or months until activated.

While the infected hosts are not causing any damages, they are busy infecting other systems. IT organizations only have knowledge of ransomware that are reported by PC or server users. This discussion borrows the lessons learned from center for disease control, such as detection, quarantine, and tracking down “patient zero”, and demonstrate the importance of AI & machine learning in security with the best practices for cybersecurity professionals, helping organizations to understand their current threat landscape, perform impact analysis, improve their security posture.

View Details

Online fraud is a growing and constantly evolving epidemic so it’s important to learn how to safeguard your business online.

This presentation will include some strategies and tips for preventing online fraud by sharing a fraud prevention plan that focuses on ad fraud, order fraud and chargebacks

View Details

As cybersecurity vulnerabilities and breaches continue to make headlines and put organizations reputation at stake, it’s important to ask “What would a CISO do?”

Join this interactive panel of industry experts as they discuss:

  • Top threats to look out for in 2020
  • Key factors for building a successful CISO strategy
  • Selling your security strategy
  • Why your entire organization should be up to date on cybersecurity

Moderator: Paul Brennecker QSA, Head of Operations at 3B Data Security

Panelists: John Lee, Managing Director, GRF Asia Pacific RV Raghu, Director Versatilist Consulting India Pvt Ltd & Director, ISACA Germaine Tan, Director of Threat Analysis, Darktrace

View Details

With the new decade bringing the biggest threat to humanity in terms of COVID19 and its cascading global impact, the ask of the CISO is evolving and the CISO will have a much larger role to play in the enterprise and be truly asked to sit at the big table.

By listening to this session, participants will:

a) have a view of how the changing world looks for the CISO b) understand what the CISO can do to remain relevant in this new world

View Details

Remote work is quickly becoming the new normal and criminals are taking advantage of this chaotic situation.

The EU Agency for Cybersecurity's providing guidance for the huge increases in the number of people working remotely, using tele-health it is vital that we also take care of our cyber hygiene.

Viewers will learn more about: - How to use encryption, controlling new storage of regulated data and data sharing in this new situation. - Anonymization leaves personal data open to re-identification, which exposes firms to GDPR non-compliance risks. - How are the HIPAA rules changing in this situation? - GDPR prescribing pseudonymization and how is that work. - How is CCPA changing the rules? - How to secure wi-fi connections preventing snooping of your traffic and fully updated anti-virus and security software, also on mobile phones. - How important files can be backed up remote or locally. In a worst case scenario, staff could fall foul of ransomware for instance. - What apps are secure to use in this new era? - Should we use MFA, PW managers or local PW management?

We will also discuss how to use the CERT-EU News Monitor to stay updated on the latest threats and check the following basics.

View Details

The COVID-19 Coronavirus pandemic provides cyberattackers with opportunities to wreak havoc. The key to thwarting their attacks is knowing how they are leveraging the crisis for their nefarious purposes. And whom better to ask than experts who know how threat actors think and operate?

Join us for a community webinar with three renowned whitehats who will predict the attack vectors and tactics blackhats will use to take advantage of the fact employees are struggling with fear, uncertainty and isolation while working from home. You will gain invaluable insight into the attacker’s mindset and learn how to harden your organization’s defenses.

Panelists: Chris Roberts is one of the world's foremost experts on counter threat intelligence and vulnerability research within the information security industry. Robert was part of Attivo Networks, LARES, Acalvio Technologies, among others.

Rod Soto is a Security Researcher and co-founder of HackMiami and Pacific Hackers conferences. Rod spent over 15 years in IT and security in organizations like Akamai, Splunk and JASK. He is a frequent speaker at cybersecurity conferences.

Nir Gaist, founder & CTO of Nyotron, is a recognized security expert and ethical hacker. Nir has worked with and pentested some of the largest Israeli organizations, such as banks, police and the parliament. He also wrote the cybersecurity curriculum for the Israel Ministry of Education.

Ira Winkler is the Lead Security Principal for Trustwave. He has designed and implemented security awareness programs at organizations around the world. Ira began his career at the National Security Agency as an Intelligence and Computer Systems Analyst.

View Details

The stream of near constant data breaches has left consumers desensitized to the news their information was lost or stolen. We’ll discuss issues around complacency both in consumers and enterprises such as how long the customer cares after a breach occurs, whether data loss is as negatively impactful to an organization’s reputation as it used to be, and how breach fatigue benefits hackers.

View Details

AI-generated fake videos, or deepfakes, are becoming more common, more convincing and easier to create. In the era of social, technically manipulated videos can spread like wildfire.

This is a particularly sensitive issue in today's politically charged environment. With the 2020 U.S. presidential election on the horizon, foreign interference in elections is a real problem and social media the perfect gateway for sowing misinformation, discord and mistrust.

Can deepfakes impact the outcome of elections? How easy are they to spot, and do you need a tool for that?

Join this episode of the Election Hacking series to learn more about the emergence of deepfakes and what can be done to mitigate its impact on elections. - The current state of deepfakes - How deepfakes can be used in misinformation campaigns - Use of deepfakes in cyber crime - Social media and the spread of fake videos - How tech companies are addressing the scourge of deepfakes (Facebook, Twitter, YouTube)

Panelists: - Lance James, CEO of Unit 221B - John Bambenek, VP for Security Research and Intelligence at ThreatSTOP - Dean Nicolls, VP of Global Marketing, Jumio

Moderator: David Morris, Executive Director at Digital Risk Management Institute

This episode is part of the Election Hacking Original series examining the threats to democratic elections, the technologies used to power and hijack elections, and what's needed to educate and empower voters before Election Day.

View Details

The new normal during the current COVID-19 crisis is changing every aspect of the business world. It is also affecting how QSA’s deal with PCI assessment.

A QSA for the most part has to be on-site for a PCI assessment, how are they do to that when they can’t get to the site?

On this webinar, The PCI Dream Team will: - Provide an overview of the PCI DSS requirements to be on-site - Discuss strategies to perform PCI assessments when being on-site is now impossible - Answer any specific questions to deal with this predicament - Detail work at home issues and concerns

View Details

The world needs more people in infosec. There are currently about 2.8 million cybersecurity professionals, but roughly 4 million more are needed to close the skills gap.

So, how are organizations addressing this shortage? What are some of the things organizations are doing when it comes to attracting and retaining cybersecurity talent, but also balancing the workload for the security teams they already have.

Join today's episode to learn more about the challenges and solutions when it comes to balancing the security workforce. - Security skills shortage: Myth vs. Reality - Top challenges for security teams - Addressing burnout and analyst fatigue - How machine learning can help - Areas where people are better than AI - Building a security culture - Removing obstacles and attracting new talent

This episode is part of The (Security) Balancing Act series with Diana Kelley. Viewers are encouraged to ask questions during the live Q&A.

Panelists: - Chris Calvert, Co-Founder & VP Strategy at Respond Software - Larry Whiteside, Jr., Veteran CISO & Cybersecurity Thought Leader; Co-Founder & Interim President - ICMCP - Gary Hayslip, CISO, Softbank

View Details

COVID-19 pandemic has not only changed our lives but immediately changed our corporate threat profiles by extending our cyber attack surface and increasing our exposure to all kinds of attacks from authentication to human error. Transitioning to a remote workforce directly and significantly impacts your defensive protections. Practical changes can reduce the risk exposure while also minimize unneeded disruptions and fire drills during this turbulent time. In this webinar, we will discuss important cyber threats to consider and provide actionable advice on how to reduce your risk.

View Details

In the midst of the Coronavirus pandemic, our society is struggling to adjust to the necessary and unexpected changes. In the information security space, we are prepared for many things, but dealing with a pandemic crisis leaves many unprepared.

Cybercriminals operate on a different level and are ahead of the game taking advantage of the global crisis with many others joining their ranks. We will discuss critical issues facing information security during this crisis.

We will also review what you need to know, what you need to be concerned about, and the steps to take today to get your organization more secure and prepared to minimize the potential impact the crisis.

View Details

How are state and local governments responding to COVID-19? What are private sector companies doing now? From public health actions to directives for staff, what emergency response steps and risks should be considered?

Join this webinar for the latest coronavirus playbook roundup and recommendations on how to address the outbreak. Learn the scope of the unprecedented challenges organizations are currently facing. Hear from industry leaders on how they are addressing the COVID-19 outbreak.

Topics will include: - Policy, technology and process steps to take today to protect your workforce and organization. - How are orgs dealing with more staff working from home (telework)? - What mistakes can be avoided –and how?

We will close with a Q/A session with the audience.

Speakers: - Dan Lohrmann, Chief Security Officer & Chief Strategist at Security Mentor Inc. - Earl Duby, CISO at Lear Corporation - Scott Larsen, CISO at a large healthcare provider

View Details

An important part of RSAC 2020 focused on Business-Critical Application Security and we're seeing a transformational shift in technology. The enterprise architecture we used to know is changing. Cloud application development is accelerating and diversifying where many organizations have virtual machines, containers, and now serverless applications running in the cloud, transforming code into infrastructure. Microservices make a lot of sense for scale and development agility, but if everything is talking to everything else via APIs, it’s likely that there are many (and I mean many) application vulnerabilities. Additionally, API security is new, so processes are likely immature, and API security sits somewhere between application developers, DevOps, and cybersecurity, leading to organizational and skills challenges. We will organize this chaos from RSAC and discuss Security in The API Ecosystem.

Security is morphing to a hybrid model for distributed policy enforcement across cloud-based environments. At the same time, organizations want central policy management for the whole environment.

Join this webinar to learn more about what attendees found interesting at RSAC USA 2020: - Emerging Privacy Issues - The Human Factor - Advancements in Machine Learning - Security in App Development - Trends from the Innovation Sandbox - New Standards and Regulations - Security for The API Economy

View Details

A little discipline goes a long way when moving to the public cloud.

Attend this talk by SEC Consult America's CEO Kelly Robertson as he discusses what applications are appropriate to move to a public cloud infrastructure and what questions do you need to ask.

Six considerations of this session:

  • Security
  • Compliance
  • Data Protection
  • Choosing a Cloud Provider
  • Workload Analysis
  • Incident Response

About Kelly Robertson:

I'm a senior executive with 30 years of professional Information Security Experience in the Silicon Valley. I worked mainly for large enterprises for the first 15 years, then started Zisher InfoSec, a security consulting firm. In 2017, Zisher InfoSec became part of the SEC Consult organization and I am presently responsible for the SEC Consult organization in the Americas.

Information Security spans all aspects of the technologies that mankind relies upon and also has a huge impact on digital citizens. I have been fortunate to have worked in 30 countries in the past 20 years across many disciplines, technical vectors and market segments. I believe that the work that we do in this career field is essential to the human race and I hope that my contributions have made a positive difference. A great deal of my focus is in mentoring information security professionals, as individuals and groups through education programs, presentations and publications.

View Details

Securing Cloud and SaaS

Cyber attacks are growing daily, broadening in scope and the costs of a breach are skyrocketing. And here is the kicker, every industry from financial service to healthcare, to government to manufacturing are in the cross hairs. Even the great Warren Buffet recently said that every company is at risk.

Yes, The Oracle of Omaha is talking tech!

Cyber criminals have expanded every company’s attack surface by attacking networks, cloud, chips, IoT, mobile devices, applications and API’s. They are relentless. And now the regulators are beginning to pass state level regulations that will eventually hold all of our feet to the fire. Add all of this up and the future points to reality that every single company, regardless of size or industry, will need to do much more to protect themselves and their customers.

This presentation will cover: - Cyber Risk Management - How to mitigate risk - Show real life case studies - Six best practices to explore for your business

About the speaker: Tony Pietrocola is President of Agile1. Agile1 is an intelligence-driven CyberSOC protecting critical network infrastructures from cyber threats. Agile1’s CyberSOC technology is built on a proprietary Machine Learning engine, which analyzes end-point security data in real time allowing us to detect and respond to threats 24X7, before a breach proliferates.

Tony serves on the board of EBO Group, Inc (acquired by Timken) and Metisentry and is a Board Member of Northern Ohio InfraGard Members Alliance. He holds a Bachelor of Science in Finance from the University of Toledo.

View Details

Cybersecurity monitoring is designed to complement, mirror and support your business operations. To create a data leadership position and innovation for your customers, the appropriate cybersecurity policies and solutions need to be in place that fit your specific business model. You need to be thoughtful about assembling a cybersecurity team configured to serve your specific company needs.

We will discuss how companies are designing their data leadership strategies based on cybersecurity requirements, looking at their internal staffing, technology sourcing and selection of 3rd party providers. Infrastructure expert, Dr. Alea Fairchild will be sharing industry trends based on Ecosystm research findings on cybersecurity solution selection.

Join this webinar to hear Alea, joined by David Spencer from IBM Security, discuss how to profile your company’s cybersecurity requirements to seek out the best advisors, skill sets and MSSP solution providers to work with your own business model in a cyber secure manner.

They will explore how organizations can develop a fit for purpose cybersecurity strategy that grows with them in resilience while meeting the challenge of maturing security programs to scale with their business.

Key Takeaways:

  1. Guidelines to grow a data leadership strategy in a non-highly regulated business.
  2. Five essential questions to ask as you screen potential cybersecurity solution providers.
  3. Why cyber resiliency is a more logical goal than being cyber secure.

Speakers: Dr. Alea Fairchild, Principle Advisor, Infrastructure & Cloud Enablement at Ecosystm and Director at The Constantia Institute sprl David Spencer, Associate Partner, Cloud Resilience and Availability, IBM GTS

View Details

Black hat actors continue to escalate the attack surfaces brought on by opportunities in emerging and matured technologies in Cloud, Internet of Things, Machine Learning, Artificial Intelligence. Several frameworks exist for managing Cyber Risks.

This presentation will answer these questions:

  • How does your organization frame responses to these threats?
  • What approach works best for your organization?
  • What key elements make up an effective Cyber Risk Program?
  • Which of these elements should be top priority?
  • How dynamic is your Cyber Risk Management approach?

View Details

Common understanding of Internet of Things (IoT) includes smart devices, such as mobile phones, smart appliances, CPE networking devices and industrial sensors. However, the time is coming when dumb devices, such as tools, lab supplies, assembly parts, household items will join the IoT. If you are worried about IoT security now, imagine the scale and the magnitude of implications when the entire physical world gets included into the attack surface.

In this presentation we will describe a practical use-case, illustrate the limitations of current methods and discuss the ways to address them.

About the speaker:

Misha Nossik is a serial entrepreneur and technology executive with over 25 years of experience in new product development for the Cloud, Cybersecurity and IoT sectors. He is a co-founder and CEO of Haystack Magic, an IoT SaaS for enterprise physical asset tracking.

Previously, he was a co-founder, CTO and VP R&D of CloudLink, a cybersecurity startup acquired by EMC in 2015. Before that he was a founder and CEO of Thintropy, an early VDI vendor, which was acquired by SIMtone (f.k.a. XDS). He co-founded Solidum Systems, a network processor pioneer, acquired by IDT Inc. In 2001 he co-founded and chaired the Network Processing Forum. Misha has earned his MSc in Applied Mathematics at MIIT in Moscow. Misha is an avid skier and an active instrument-rated pilot.

View Details

The email threat landscape is constantly evolving. How are organizations staying up to date on all the email-based cyber threats?

Join this panel of security experts and industry leaders as they discuss the latest trends in email security and how to prevent becoming the next news headline. Learn how to protect your organization from spam, malware, and phishing attacks.

  • Emerging trends in email attacks
  • Why email security is a key CISO priority in 2020
  • The human element of security
  • Solutions and best practices for protecting your organization

Moderator: Chris Hazelton, Director of Security Solutions, Lookout

Panelists: JP Bourget, Founder, Director, Chief Security Officer, Syncurity Jonathan Lee, Senior Product Manager, Menlo Security Ondrej Krehel, Digital Forensics Lead, CEO and Founder, LIFARS

View Details

Companies are at risk when transitioning from traditional on-premise applications and infrastructure to cloud computing solutions.

It is critical that security and compliance be addressed in the cloud environment. Failure to ensure appropriate security and address compliance requirements may ultimately result in higher risks, costs and potential loss of business. Highly regulated companies should take a comprehensive approach to data privacy, security and compliance before moving systems to the cloud. This includes:

  • Understanding the challenges of compliance on premise versus the cloud
  • What security standards should be adopted in the cloud
  • Demonstrating compliance: how to establish and maintain data privacy, security, and compliance in a cloud environment

View Details

Hybrid Cloud is the new normal for the modern Enterprise. Information Security departments have accepted that the perimeter is no longer defined by the network and that data protection is central to this new paradigm.

Are software-defined data controls across clouds and data centers weaker than traditional perimeter defenses? Not necessarily. In some cases they are actually stronger.

This talk is about the opportunities presented by today’s tools and how these apply to compliance. In particular how continuous compliance is now possible. We will also outline how this changes GRC processes and the role of security compliance in DevOps aka DevSecOps.

Topics covered include:

• What is Compliance and what should be included? • Compliance Frameworks and Standards. • What can we measure and test? • How to tie together hybrid cloud compliance • Access Controls, Infrastructure, Data and Policies • DevSecOps • Continuous Compliance

About the speaker: Darrin Nowakowski has 25 years experience working in Cyber Security in Canada and internationally. He has extensive experience as both a practitioner and strategist with a focus on providing Security Architecture, Penetration Testing, Cloud, Web and Mobile Security as well as Executive Consultation, Security Program Development, Strategies and Roadmaps, Risk management and demonstrated leadership. As a founder and senior leader, President and CISO, for Star Circle Security, Darrin managed a consulting practice through strong client relationships in the Financial, Public, Telecommunications and Retail Sectors. Mr. Nowakowski is currently working as the Director for Client Services of the Greater Toronto Area Cyber Security Practice for CGI.

View Details

Cloud compliance could be difficult if you are a multinational or in some cases if you have clients in different states, how can you address all the compliance requirements without losing your time redoing work, in this webinar we will describe the basic points you need to develop in order to be ready to comply with different regulations, audits or annual reviews.

About the speaker:

Juan Carlos Carrillo is a Security & Privacy professional with IT Management experience of more than 20 years in high tech industry. He has large expertise doing business with technology solutions to financial companies. Throughout Juan Carlos' career, he has developed extensive knowledge with software, hardware, consulting and professional services.

Juan Carlos has a Masters in Finance graduated from ITESM in Mexico, a B.S. in Computer Systems Engineer from UVM in Mexico, He is certified as an Information Privacy Professional (CIPT), Certified as an Identity and Access Administrator (CIAM) and Certified in Cloud Security (CCSK).

View Details

The California Consumer Privacy Act (CCPA) went into effect on January 1st 2020, yet there is still confusion and uncertainty regarding this data regulation, especially for businesses operating in a post-GDPR world.

Are you familiar with the CCPA's privacy requirements? Is your organization ready for the most far-reaching data privacy regulation in the U.S. to date? 

Join this panel of privacy experts for an interactive Q&A session to learn more about how CCPA will impact your organization, as well as dive into the main differences between CCPA and GDPR. - The CCPA privacy requirements- CCPA checklist beyond deadline day - Data mapping: how and why it is important for CCPA and GDPR - Data Subject Access Requests  - Other key similarities and differences between GDPR vs. CCPA - The future of privacy and compliance in 2020 and beyond

Speakers: - Guy Cohen, Strategy and Policy Lead, Privitar - Lisa Hawke, VP Security and Compliance, Everlaw - Joanne Furtsch, Director, Privacy Intelligence Development, TrustArc - Laura Koulet, Vice President, Head of Legal & Privacy, Tapad

View Details

Suited to both buyers and sellers of cloud computing services, this webinar will cover some of the key regulatory aspects that are relevant in the specialized niche of cloud computing. We will first define what we mean by cloud computing, and then get into some of the specifics related to the rules and regulations surrounding it. In particular, we will focus on:

  • Responsibilities of buyers and sellers of cloud computing services
  • Rules and regulations that both parties must be aware of and adhere to
  • How to deal with and handle some of the common issues and challenges that often arise in such outsourcing arrangements/relationships
  • Roles, risks and responsibilities associated with cloud computing in small and large corporations
  • How to simplify and streamline compliance with regulations when outsourcing to cloud compliance service providers

While it is impossible to cover every risk and regulation applicable to cloud compliance, participants in this talk will walk away with a fundamental understanding of some of the risks and challenges, as well as benefits, of cloud computing, and in particular will have a better understanding and frameworks to determine the extent (if at all) to which cloud computing is justifiable for specific functions/procedures within their organizations, with particular emphasis on the risks associated with non-compliance due to such things as: incomplete/unclear communication, incomplete/unclear understanding, incomplete/unclear due diligence, and incomplete/unclear oversight/audits.

This will be generalized advice, and our goal will be to focus on understanding the general policies and principles associated with cloud compliance, and so we will address some of the broad regulatory issues and challenges using specific situations and regulations as illustrative examples.

View Details

Cloud technology is revolutionising the way we work and communicate.This rapid advancement in technology has created sophisticated cyber threats. As the Cloud technology matures, so have the user expectations – there is an increased demand for trust and transparency.

This session will look at how the technology revolution has led to increased regulation and how cloud service providers can use this opportunity to turn compliance into a competitive advantage.

About the speaker:

Krishna Iyer, Director, PwC UK - Krishna is a Director in the UK Assurance Practice, focussing on emerging technology assurance. Krishna is an active blogger and has written various thought leadership on cloud security and compliance in the cloud, including a paper on ‘the role of Internal audit in auditing cloud’ for the ICAEW.

View Details

Multi-cloud adoption is on the rise, but the challenge of securing organizations against cyber attacks remains.

Discover the cost of data breaches in 2020, as well as the technologies CISOs are using for keeping track of their assets, assessing and managing cyber risk and mitigating threats against the enterprise.

Join this Q&A panel of experts as they discuss: - CISO priorities in a multi-cloud environment - Biggest threats to the enterprise - How to assess and mitigate cyber risk - Technologies powering security - Best practices and recommendations for a more secure organization

Speakers: Jeremy Snyder, VP of Business Development & Corporate Development, DivvyCloud (moderator) Christopher Romano, Senior Consultant, Mandiant Sol Cates, VP of Technical Strategy, Thales Nathan Howe, Director of Transformation Strategy, ZScaler

View Details

Many enterprises are leveraging multicloud deployments to get the best-of-breed features from many different providers. Hybrid cloud and multicloud have brought capability to businesses to be able to cover all aspects of their IT needs. However, they have also brought complexity in security requirements.

Usually, IT and security professionals mitigate any security concerns by creating a trust boundary between:

  • The cloud and the user accessing via the internet

  • The cloud and users accessing the enterprise network in hybrid architectures

  • What is being missed is inter-cloud security considerations, potential threats, disparate support teams and governance.

In this webinar, Neil Briscoe will share real-life examples, highlighting potential issues and offering solutions for you to ensure your hybrid cloud and multicloud environments are fully secured.

About the speaker:

Neil Briscoe, co-founder and CTO at Cloud Gateway, has 20 years’ experience in IT, working across multiple sectors for leading companies including PepsiCo, Asda, Capita, Aviva and the Ministry of Justice where he was responsible for leading architecture and delivery.

Neil focuses primarily on open source technologies, infrastructure automation, network architecture and design. As CTO at Cloud Gateway, he continues to drive product development through technical direction for existing, new and future problem spaces whilst leading innovation in the hybrid connectivity space, with the aim of enabling organisations of all sizes to harness the power and flexibility of hybrid cloud. His innovative approach to secure, hybrid networks has seen him earn the highest of industry recognised accolades.

Neil is also a Cisco Certified Network Expert (CCIE), widely recognised as the hardest/highest network certification available in the market.

View Details

The inaugural episode of the Election Hacking series will introduce the topic of who, how and why the upcoming 2020 election will be hacked.

Join this interactive Q&A session to learn more about election hacking, its impact, the various stakeholders, and what if anything, can be done.

Our unique panel of individuals will bring diverse perspectives to this topic.

  • Cameron Koffman, who, if elected, would be the youngest candidate since Theodore Roosevelt running for the NY State Assembly
  • Tinatin Japaridze, former United Nations correspondent for the Russian and Ukrainian media, with expertise in bi-lateral US-Russian relations on cyber security.
  • Lance James, CEO of Unit 221B and noted cyber security expert who has assisted various law enforcement and government agencies on some of the most highly publicized hacking investigations.

Moderator: David Morris, Executive Director at Digital Risk Management Institute

View Details

Security is becoming an integral part of the M&A decision making process. In this talk, we will discuss what Google Security worries about when we acquire or start a company and how different roles within the security organization work in synchronization to make the overall integration secure and successful.

Ruchi is a Sr Security Engineering Manager at Google where she manages an organization whose mission is to secure Acquisitions and Alphabets. In her role, she leads security engineering and technical program management functions. Prior to joining Google, she spun up the Subsidiary Security Program at Amazon and managed the product roadmap for AWS Identity and Access Management and AWS Key Management services. Ruchi has worked at Deloitte and Touche LLP and Ernst and Young, where she helped clients implement security solutions ranging from Identity and Access Management (IAM), Security Information and Event Management (SIEM) to Network Security Products. She has over 13 years of experience in Security.

View Details

Security leaders are increasingly basing their decisions on metrics to justify spending, quantifying risk, and demonstrating value to the executive suite. This panel of leaders will discuss how they are awash in dashboards, charts, and KPIs of little to no value and what they’ve done to develop contextual, impactful, actionable metrics.

View Details

Join us as we review social engineering tactics and attack methods. Learn about the latest trends in social engineering, the risk to your organization's cybersecurity and what steps to take to mitigate it.

Viewers will learn more about: - How social engineers exploit human behavior - Most common types of social engineering attacks - New in phishing, baiting, tailgating and more - Managing access and insider threats

This episode is part of The (Security) Balancing Act series with Diana Kelley. Viewers are encouraged to ask questions during the live Q&A.

View Details

Security threats mutate and lately they are becoming more bold than ever. What is driving this pattern? We will examine new patterns in ransomware, phishing, and data exposures that are greatly affecting our security posture as well as provide better guidelines for mitigating these threats.

View Details

Cyber security is a hot topic as the world has witnessed a rapid increase in cyber-attacks, data breaches, data leaks and espionage. Governments are taking cyber security seriously, increasing investment in both defensive and offensive capabilities, and introducing regulations to support legal frameworks.

Unfortunately, cyber-attackers don't sleep or take vacations and this means you must be prepared and ready at any time during the day or night.

Join this webinar to learn about the following: - Which cyberattack is most likely the one that will hit you? - What are the top threats in 2020? - What are the latest threats?

View Details

2019 was the worst year to date for data breaches. Phishing, misconfiguration mistakes, third party risk, and insider threats continue to plague organizations across industry verticals. So, what are some proactive approaches organizations can take to address old and new security threats in 2020?

Join this panel of security experts and industry leaders to learn more about: - The biggest threats to the enterprise in 2020 - What keeps CISOs up at night - How to stay ahead of the threats - Proactive security strategies and best practices - Avoiding misconfiguration mistakes and minimizing the risk of insider threats - Solutions available today and what to expect in the near future

Speakers: Jo Peterson, Vice President Cloud Services, Clarify360 (Moderator) Tyler Cohen Wood, Cyber Security Expert, Former Senior Intelligence Officer, Private Consultant Carlos Valderrama, SOC Director, Proficio Athar Awan, Cyber Security Consultant, Security Solutions Consultants Etay Maor , Chief Security Officer, InSights

View Details

A lot of organizations are trying to implement some kind of segmentation in their data centers. Different approaches to segmentation deployment have exposed many challenges. During this talk approach to segmentation at the edge will be considered. When implementing segmentation at the edge disruption to existing infrastructure is minimal and performance of the network is improved. Attendees will learn about this new software defined segmentation at the edge approach benefits.

View Details

Third parties continue to be a rising cause for costly breaches. Approach mitigating these costs through basic board game strategies: identify an organization's third party landscape, observe threat movements, and strengthen internal resources.

View Details

The cybersecurity industry is flooded with tools that protect different aspects of your network, your supply chain, your critical data. In this webinar, ThreatAware CEO Jon Abbott will examine how to identify the most effective tools for your organisation, available on the market today. Furthermore, he’ll explore how consolidating the information they provide makes their power even greater.

Key takeaways - How to identify the tools that will best suit your organisation’s cybersecurity needs - How cybersecurity tools can complement each other to produce better quality information - How to effectively use data collated in a single pane to best protect your organisation

View Details

This webinar will be a deep dive into what went wrong that we know of, but more importantly, focus on lessons learned. Elections are "must succeed" events, and these failures highlight several emerging issues with the application of technology into new areas. The lessons that can be learned here have broad application to not just election security, but technology and its use in civic society as a whole.

View Details

The Security Operations Center was born from its parent, the Network Operations Center, inheriting its philosophy, structure, methodologies and even roles. The SOC, of course, has been evolving over the last few years but only by updating old concepts, technologies, processes and roles coming from the NOC.

In 2020 is when we're going to start the SOC Revolution, being independent from its parent, creating its own model (new roles, new technology and new processes), being proactive instead of reactive, risk and threat-based and becoming even more strategic: a business loss safeguard and growth enabler for all the organizations globally.

View Details

With the proliferation of the Internet of Things, IoT devices are often added into enterprise environments without due consideration for the security and privacy risks they pose to the business. Oftentimes, IT security teams do not have full visibility into how many IoT devices are connected to the network. This creates security gaps, as IoT devices are notoriously vulnerable to hacks and attacks.

Join this interactive panel experts to learn about how enterprises can enhance endpoint, and therefore IoT security.

Attendees will learn more about: - IoT and today's enterprise - What's on your network? How do you evaluate IoT devices? - Why visibility is key - Controlling access to your IoT environment - Vendor risk and holding vendors accountable for their IoT equipment - Areas for automation and where to reduce your IT security team's involvement - Patching and upgrading - Expert recommendations for enhancing IoT security

Speakers: Peter Wood, Partner, Naturally Cyber LLP (Moderator) Terence Jackson, CISO, Thycotic Brian Russell, IoT Working Group Co-Chair, Cloud Security Alliance (CSA) Alexandre Blanc, Director of Security, Adaware (an Avanquest company)

View Details

The rapid rise of breach response capability as an absolute necessity has GDPR to thank/blame. But what should have been an extension of every organisation's existing incident response / disaster recovery program, is now an excuse to reach into your pockets. Like everything in security, breach response is not complicated - or even difficult in most cases - it just has to be 'appropriate'.

In this webinar you will learn that: -Breach response is not a product, and it's certainly not a technology, it's a collection of procedures; -If you don't have decent incident response, breach response is pointless; -Most organisations trying to sell you breach response out of the gate are doing you no favours -Asking the right questions is your responsibility!

View Details

Many businesses have put tremendous effort in automating processes and security controls that protect their data. However, in the case of a disaster, your business continuity plan (BCP) likely relies on manual processes that may open a side door to threat actors and leave your business and data more vulnerable than before.

Learn the things you should be considering as part of your BCP to help keep your data protected.

View Details

In today’s business landscape it is important to take a proactive approach to security rather than a reactive approach. Join leading security experts as they discuss the safest ways to protect your organisation in 2019 and beyond.

Join this Q&A panel to learn more about:

  • Key organisational benefits to practising proactive security
  • Technologies powering security
  • Best practices and recommendations for a more secure organization

Speakers: Roselle Safran, President, Rosint Labs (Moderator) Sean Webb, Information Security Manager, Patriot One Technologies Inc. Michelle Drolet, CEO & Co-Founder, Towerwall Michelle McLean, VP Marketing, StackRox Chris Calvert, VP of Product Strategy, Respond Software

View Details

Monetizing, managing, and securing patient health data that has been de-identified is common practice for research purposes. But, recent studies have revealed that current de-identification methods may not provide sufficient protection when that same anonymized data falls into the hands of cybercriminals.

Gabe Gumbs, Chief Innovation Officer for Spirion, will discuss the implications of re-identification attacks and how to increase protections that limit the disclosure of personally identifiable information.

View Details

Join this webinar as we discuss the foundational processes and tools associated with very successful security programs that also prevent serious incidents and events to lower the overall costs of a breach.

Learn how prevention is the “secret sauce” to lowering costs!

View Details

Most businesses fail or suffer significant losses not because they have experienced a breach but because they are unable to respond to a cybersecurity incident promptly and effectively. They simply do not have the information or the metrics in place to help contain, reduce, and remediate rapidly evolving, sophisticated threats to today’s enterprises. This webinar will look at the costs today of cybersecurity and lessons learned from past data breaches.

Join this webinar to learn: - Where the costs from Cybersecurity comes from? - What can be done to reduce such costs?

View Details

Guardicore, Cybertech Tel Aviv 2020 1-2-2 Interview - Sharon Besser, VP Business Development & Shay Nehmad, Tech Lead and Open Source Software Developer

View Details

Akamai, Cybertech Tel Aviv 2020 1-2-1 Interview - Yael Daihes, Data Science Team Lead

View Details

Cyber Armor, Cybertech Tel Aviv 2020 1-2-1 Interview - Shauli Rozen, CEO and Co-Founder

View Details

Cyberbit, Cybertech Tel Aviv 2020 1-2-1 Interview - Sharon Rosenman, VP Marketing

View Details

Symantec a division of Broadcom, Cybertech Tel Aviv 2020 1-2-1 Interview - Omer Yair, Endpoint Team Lead, Symantec

View Details

Nelysis, Cybertech Tel Aviv 2020 1-2-1 Interview - Sagi Dotan, VP Sales EMEA

View Details

Odix, Cybertech Tel Aviv 2020 1-2-1 Interview - Dr. Oren Eytan, CEO & Co-founder

View Details

C2A Security, Cybertech Tel Aviv 2020 1-2-1 Interview - Michael Dick, CEO

View Details

Siemplify, Cybertech Tel Aviv 2020 1-2-1 Interview - Nimmy Reichenberg, CMO

View Details

SmartEye, Cybertech Tel Aviv 2020 1-2-1 Interview - Dexter Caffey, CEO

View Details

Ayehu, Cybertech Tel Aviv 2020 1-2-1 Interview - Gabby Nizri, Founder & CEO

View Details

Cybint, Cybertech Tel Aviv 2020 1-2-1 Interview - Dan Hakimi, SVP Business Development

View Details

Alcide, Cybertech Tel Aviv 2020 1-2-1 Interview - Amir Ofek, CEO

View Details

Verint, Cybertech Tel Aviv 2020 1-2-2 Interview - Gilad Zahavi, Director of Cyber Threat Intelligence

View Details

Morphisec and Microsoft, Cybertech Tel Aviv 2020 1-2-2 Interview - Netta Schmeidler, Morphisec & Dan Michaelson, Microsoft

View Details

Waterfall is based on the concept of sequential software development—from conception to ongoing maintenance—where each of the many steps flowed logically into the next.

Join this webinar presentation to learn: - Why DevOps cannot effectively work in waterfall - How to use DevOps tools to optimize processes in either development or operations through automation

We will also discuss what is needed to support full DevOps optimization and create a Secure Agile Development process.

View Details

IBM Security, Cybertech Tel Aviv 2020 1-2-1 Interview - Anthony Aurigemma, Vice President, IBM Security Europe

View Details

The emerging DataOps is not Just DevOps for Data. According to Gartner, DataOps is a collaborative data management practice focused on improving the communication, integration and automation of data flows between data managers and consumers across an organization.

The goal of DataOps is to create predictable delivery and change management of data, data models and related artifacts. DataOps uses technology to automate data delivery with the appropriate levels of security, quality and metadata to improve the use and value of data in a dynamic environment.

This session will discuss how to add Security in DataOps and DevOps.

View Details

The General Data Protection Regulation (GDPR) has been making far more influence on the privacy landscape online than expected since its enactment by the European Union (EU) on May 25th, 2018.

Google and Facebook, two of the most powerful digital platforms, were heavily scrutinized and penalized with hefty fines for their non-compliance in the European market. GDPR has also driven many countries, such as Japan, Brazil, and South Korea, to follow suit by strengthening their privacy laws. All 50 states in the United States have also joined the camp by amending their privacy laws - albeit to varying degrees - to make privacy breach reporting mandatory.

Most notably, the State of California developed its own GDPR-style privacy law called “California Consumer Protection Act” (CCPA) and will enact in January 2020. Moreover, two federal privacy bills were recently submitted to the Congress aiming to be the very first federal-level, comprehensive privacy law in the U.S. Canada is no exception in this privacy-aware trend. The ruling liberal party made clear that modernizing privacy legislation to protect citizens online will be one of the party’s priorities.

This presentation will talk about current trends in privacy field in terms of regulatory requirements in the U.S., Canada, and Europe, discuss what to expect in 2020, and what to do to make sure that all the organizations and institutions are compliant with applicable laws and regulations in their jurisdiction.

View Details

Too often, Information Security means technical point solutions. This approach leaves enterprises exposed and management and customers disillusioned.

Join us to learn:

  • Why security programs remain on the margins of business adoption in spite of heightened threats and acknowledged need
  • Why security by technology alone is a dead end
  • The secret sauce for a vibrant, effective information security program

View Details

As organizations evaluate their de-identification and data minimization practices to satisfy an expanding landscape of regulatory obligations there are a number of factors to consider. Various technologies will be considered as part of a data-centric security strategy for de-identifying and securing sensitive information such as statistical tools, cryptographic solutions, suppression, pseudonymization, generalization, and randomization. Further, we will examine the capability of these technologies to preserve business utility within a Zero Trust data security model.

Listen to this session and you will take away:

• An understanding of the definition of de-identification as it relates to international and industry privacy regulations, including the difference between pseudonymization and anonymization • A strategy for balancing privacy and security concerns with business needs, such as evaluating and prioritizing risk • How various methods of de-identification can help meet the privacy requirements of applicable compliance obligations

View Details

The PCI Dream Team is back for another interactive Q&A session.

Join us with your toughest questions and learn more about the various Payment Card Industry (PCI) standards and requirements, with a focus on PCI DSS v4.0.

Our panelists are some of the top PCI QSA’s in the country, with decades of combined PCI and card processing experiences. They’ve seen it all: the good, bad and ugly; and lived to tell the tale.

Join Ben Rothke, David Mundhenk, Arthur Cooper, and Jeff Hall for an interactive Q&A session, and get answers to your most vexing PCI questions. No PCI question is out of bounds.

Speakers: - Ben Rothke, Senior Information Security Specialist at Tapad - David Mundhenk, Senior Security Consultant at Herjavec Group - Jeff Hall, Senior Consultant with Online Business Systems - Arthur Cooper "Coop", Senior Security Consultant at NuArx

View Details

Join well-known women in privacy and cybersecurity for an exclusive keynote panel on ransomware and IoT threats to healthcare data, and steps to take in 2020 to better secure it.

Viewers will also learn about Google’s Project Nightingale, as well as have the opportunity to ask questions during the live webinar.

Speakers: - Debra Baker, CISSP CCSP, Host and Technical Program Manager at RedSeal - Ellie Daw, Research Scientist at Crimson Vista, Inc. - Michelle Finneran Dennedy, CEO at DrumWave - Karen Schnell, Cybersecurity Business Architect and Adjunct Professor in Computer Science - Anna Kirkland Smith, Data Scientist, MetLife

This keynote panel is part of International Data Privacy Day 2020 and will be available Live on January 28th, as well as an on-demand.

Data Privacy Day is an international effort to create awareness about the importance of respecting privacy, safeguarding data and enabling trust.

View Details

The Payment Card Industry Data Security Standard (PCI DSS) and the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework share the common goal of enhancing data security. This session maps PCI DSS to the NIST Framework and discuss how to align security efforts to meet objectives in both PCI DSS and the NIST Framework.

PCI DSS is focused on the unique security threats and risks present in the payments industry

The NIST Framework provides an overarching security and risk-management structure with security Functions, Categories, and Subcategories of actions. These Subcategories reference globally recognized standards for cybersecurity.

Both PCI DSS and the NIST Framework are solid security approaches that address common security goals and principles as relevant to specific risks.

We will discuss how the NIST Framework identifies general security outcomes and activities, and how PCI DSS provides specific direction and guidance on how to meet security outcomes for payment environments.

This session will also discuss the interesting attribute based access control (ABAC) as a logical access control methodology where authorization to perform a set of operations is determined by evaluating attributes associated with the subject, object, requested operations, and, in some cases, environment conditions against policy, rules, or relationships that describe the allowable operations for a given set of attributes. This session also provides considerations for using ABAC to improve information sharing within organizations and between organizations while maintaining control of that information.

View Details

Webinar Take-Aways:

  • What millennials think about privacy and What’s their expectation?
  • Diversity in Privacy in 2020
  • Impact on Criminology and Criminal Justice System in Privacy.
  • Career in Privacy

About the Speaker: Deveeshree Nayak Faculty, School of Engineering & Technology (SET) University of Washington, Tacoma

Disclaimer: My views in this webinar are my own.

View Details

With sensitive data residing everywhere, organizations becoming more mobile, and the breach epidemic growing, the need for advanced data privacy and security solutions has become even more critical. French regulators cited GDPR in fining Google $57 million and the U.K.'s Information Commissioner's Office is seeking a $230 million fine against British Airways and seeking $124 million from Marriott. Facebook is setting aside $3 billion to cover the costs of a privacy investigation launched by US regulators.

This session will take a practical approach to address guidance and standards from the Federal Financial Institutions Examination Council (FFIEC), EU GDPR, California CCPA, NIST Risk Management Framework, COBIT and the ISO 31000 Risk management Principles and Guidelines.

Learn how new data privacy and security techniques can help with compliance and data breaches, on-premises, and in public and private clouds.

View Details

Companies today are increasingly aware of their privacy compliance obligations, including the emerging requirements from recent regulations like GDPR and California's CCPA. Most companies that invest in a privacy compliance uplift spend time on policy revisions, data subject rights tooling, training, and data discovery. But after the first rush of compliance activities, the challenges of privacy operations evolve:

  • How do you get beyond point in time compliance into managing repeatable processes?
  • What existing teams and operations should privacy leverage right away, and how should this change over time?
  • How do you prioritize updates to your data subject rights tooling, whether you've custom built or outsourced?
  • How do you avoid privacy fatigue?

This webinar will cover common areas where privacy compliance can "get stuck," and discuss ways to successfully operationalize a growing privacy program at the speed of business.

Presenter Info: Adrienne Allen, Head of Security GRC and Privacy, Coinbase

View Details

Too often, Information Security means technical point solutions. This approach leaves enterprises exposed and management and customers disillusioned.

View the presentation to learn:

• Why security programs remain on the margins of business adoption in spite of heightened threats and acknowledged need • Why security by technology alone is a dead end • The secret sauce for a vibrant, effective information security program

View Details

As organizations evaluate their de-identification and data minimization practices to satisfy an expanding landscape of regulatory obligations there are a number of factors to consider. Various technologies will be considered as part of a data-centric security strategy for de-identifying and securing sensitive information such as statistical tools, cryptographic solutions, suppression, pseudonymization, generalization, and randomization. Further, we will examine the capability of these technologies to preserve business utility within a Zero Trust data security model.

Listen to this session and you will take away:

• An understanding of the definition of de-identification as it relates to international and industry privacy regulations, including the difference between pseudonymization and anonymization • A strategy for balancing privacy and security concerns with business needs, such as evaluating and prioritizing risk • How various methods of de-identification can help meet the privacy requirements of applicable compliance obligations

View Details

Companies today are increasingly aware of their privacy compliance obligations, including the emerging requirements from recent regulations like GDPR and California's CCPA. Most companies that invest in a privacy compliance uplift spend time on policy revisions, data subject rights tooling, training, and data discovery. But after the first rush of compliance activities, the challenges of privacy operations evolve:

  • How do you get beyond point in time compliance into managing repeatable processes?
  • What existing teams and operations should privacy leverage right away, and how should this change over time?
  • How do you prioritize updates to your data subject rights tooling, whether you've custom built or outsourced?
  • How do you avoid privacy fatigue?

This webinar will cover common areas where privacy compliance can "get stuck," and discuss ways to successfully operationalize a growing privacy program at the speed of business.

Presenter Info: Adrienne Allen, Head of Security GRC and Privacy, Coinbase

View Details

US Cyber Command has undergone a significant shift in strategies away from defense and deterrence to engagement and forward disruption. We’ll discuss whether offensive cyber actions deter or invite retaliatory attacks, impacts to private industry (both positive and negative), and whether enterprise security offices should take offensive measures and if so – how far should we go?

View Details

Webinar Take-Aways:

  • What millennials think about privacy and What’s their expectation?
  • Diversity in Privacy in 2020
  • Impact on Criminology and Criminal Justice System in Privacy.
  • Career in Privacy

About the Speaker: Deveeshree Nayak Faculty, School of Engineering & Technology (SET) University of Washington, Tacoma

Disclaimer: My views in this webinar are my own.

View Details

The General Data Protection Regulation (GDPR) has been making far more influence on the privacy landscape online than expected since its enactment by the European Union (EU) on May 25th, 2018.

Google and Facebook, two of the most powerful digital platforms, were heavily scrutinized and penalized with hefty fines for their non-compliance in the European market. GDPR has also driven many countries, such as Japan, Brazil, and South Korea, to follow suit by strengthening their privacy laws. All 50 states in the United States have also joined the camp by amending their privacy laws - albeit to varying degrees - to make privacy breach reporting mandatory.

Most notably, the State of California developed its own GDPR-style privacy law called “California Consumer Protection Act” (CCPA) and will enact in January 2020. Moreover, two federal privacy bills were recently submitted to the Congress aiming to be the very first federal-level, comprehensive privacy law in the U.S. Canada is no exception in this privacy-aware trend. The ruling liberal party made clear that modernizing privacy legislation to protect citizens online will be one of the party’s priorities.

This presentation will talk about current trends in privacy field in terms of regulatory requirements in the U.S., Canada, and Europe, discuss what to expect in 2020, and what to do to make sure that all the organizations and institutions are compliant with applicable laws and regulations in their jurisdiction.

View Details

How has the compliance landscape changed in 2020? Is your organization aware of the main differences in data regulations around the world?

Join this panel of industry leaders for an interactive Q&A roundtable to get a comprehensive look into the different data privacy and security requirements. The panel will also discuss what to expect in 2020 and beyond.

Viewers will learn more about: - CCPA is now in effect and what this means for you - The main differences between GDPR and CCPA - Best tools, practices, required policies and cultural game changers for commercial and government environments - Other data regulations on the horizon - Recommendations for 2020

Speakers: - Dr. Christopher Pierson, CEO & Founder, BLACKCLOAK - Shahrokh Shahidzadeh, CEO, Acceptto - Michelle Drolet, CEO, Towerwall - George Wrenn, CEO & Founder, CyberSaint Security

This Q&A panel is part of Privacy Month.

View Details

When GDPR first arrived, some companies addressed it by implementing data privacy measures solely for their EU data subjects — only to have to go through the same exercise for California residents when CCPA came along. With major data privacy laws now in effect on both sides of the Atlantic and more on the way (possibly including U.S. federal legislation), organizations must adopt a holistic approach to managing personal data in an ethical, compliant manner.

Join the data privacy experts from Primitive Logic to explore data management strategies for achieving and maintaining readiness for CCPA, GDPR, and other current and future privacy regulations.

You will learn:

  • Why traditional master data management (MDM) can lay the groundwork for multi-regulation readiness, but won’t make you compliant on its own
  • How to address common threads in data privacy legislation while maintaining flexibility to adapt to future requirements
  • How to build a single source of truth for personal data as a cornerstone of your data privacy strategy
  • Governance strategies for adapting to “triggers” in maintaining data privacy readiness

View Details

With sensitive data residing everywhere, organizations becoming more mobile, and the breach epidemic growing, the need for advanced data privacy and security solutions has become even more critical. French regulators cited GDPR in fining Google $57 million and the U.K.'s Information Commissioner's Office is seeking a $230 million fine against British Airways and seeking $124 million from Marriott. Facebook is setting aside $3 billion to cover the costs of a privacy investigation launched by US regulators.

This session will take a practical approach to address guidance and standards from the Federal Financial Institutions Examination Council (FFIEC), EU GDPR, California CCPA, NIST Risk Management Framework, COBIT and the ISO 31000 Risk management Principles and Guidelines.

Learn how new data privacy and security techniques can help with compliance and data breaches, on-premises, and in public and private clouds.

View Details

The GDPR principle of storage limitation determines that personal data must be erased (or anonymised) when 'no longer necessary'.

As such, data controllers must embed appropriate technical and organisational measures into operations, to allow for the periodical review of personal data and to the erasure (or anonymisation) of any 'non-necessary' data, thus achieving compliance with GDPR's data storage requirements.

An overview on the impact of the 'storage limitation' principle on organisations' operations will be undertaken, considering:

  • Storage limitation (structured, unstructured data);
  • Data minimisation (data collection, data hygiene);
  • Time limitation (retention policies, procedures and time schedules);
  • Risks of non-compliance (Data subject rights, data breaches).

This session will thus provide a holistic and pragmatic framework-based approach to storage limitation and its ongoing compliance.

Presenter: Virgilio Lobato Cervantes holds an LLB Honours degree in Law and a Master of Arts degree in International Tourism and Aviation Management. He is a certified Data Protection Officer by the University of Maastricht (ECPC-B DPO). Currently pursues a Doctorate degree in law at the University of Reading. Virgilio’s research focus is in EU data protection and privacy law.

England and Wales Qualified Paralegal Lawyer, member of the Professional Paralegal Register (PPR Tier 3) and the Institute of Paralegals (Q.Inst.Pa.), specialised in Data Protection and Privacy Law, Virgilio presently takes on the role of Data Protection Compliance Manager at Countrywide PLC, the UK’s largest property services group.

View Details

The PCI Dream Team is back for another interactive Q&A session.

Join us with your toughest questions and learn more about the various Payment Card Industry (PCI) standards and requirements, with a focus on PCI DSS v4.0.

Our panelists are some of the top PCI QSA’s in the country, with decades of combined PCI and card processing experiences. They’ve seen it all: the good, bad and ugly; and lived to tell the tale.

Join Ben Rothke, David Mundhenk, Arthur Cooper, and Jeff Hall for an interactive Q&A session, and get answers to your most vexing PCI questions. No PCI question is out of bounds.

Speakers: - Ben Rothke, Senior Information Security Specialist at Tapad - David Mundhenk, Senior Security Consultant at Herjavec Group - Jeff Hall, Senior Consultant with Online Business Systems - Arthur Cooper "Coop", Senior Security Consultant at NuArx

View Details

Every year the top security companies, industry thought-leaders and tech media publications come out with their predictions for the coming year. And every year Dan Lohrmann publishes his roundup of these security industry reports, forecasts and trends.

This BrightTalk webinar will dig into the 2020 report in detail.

Link to the report: https://www.govtech.com/blogs/lohrmann-on-cybersecurity/the-top-20-security-predictions-for-2020.html

There is huge career value for technology and security professionals who understand where the cybersecurity industry predictions, and you can read about those benefits in this CSO Magazine article: https://www.csoonline.com/article/3021951/why-more-security-predictions-and-how-can-you-benefit.html

In addition to counting down (and referencing) the top 20 security prediction reports from the leading vendors, this webinar will examine: - Where is their agreement on what’s coming next? - Where is their major disagreement? - Where will cyberattacks come from next? - Which vendors have the best reports (and why)? - Who are the award-winners for most creative, most likely, most scary and other security industry predictions?

We will discuss security and tech predictions on AI, autonomous vehicles, cloud solutions, cyberthreats, ransomware, IoT, malware, multi-factor authentication, business priorities, data breaches, spending, new vulnerabilities to watch for, mobile threats, 5G, new announcements, major security incidents, government contracts, election security, attacks on global events (like the 2020 Olympics), cyber incident response and much, much more.

At the end, we will take your questions on all of this, and may even ask you to vote for your favorite predictions (or offer one of your own to share.)

Join us.

View Details

Join Bob Canaway, CMO, Privitar & Guy Cohen, Strategy & Policy Lead, Privitar as they discuss all things privacy and what to expect from the CCPA.

Bob and Guy will share, amongst other things, unmissable insights into:

  • What data is covered by the CCPA
  • What the key privacy provisions in the CCPA are
  • What the CCPA means for security
  • Predictions for what the CCPA in practice will mean

View Details

This Session will be the first in a series on Threat Hunting. This kick-off session will introduce the concept of Threat Hunting as there is a lot of confusion about this important activity. Specifically, we will cover what it is, how it is performed, its’ role and some of the best Tools to use as a Threat Hunter.

View Details

In this talk, we will discuss the portion of cybersecurity known as ‘market access’. We will dive into what market access requirements are and what they mean for cybersecurity professionals as well as to the world. We will go over the different types of market access requirements as well as discuss from a geopolitical standpoint where cybersecurity is moving in this space and what we are expecting to happen in the near future.

We will breakdown the most common/popular market access requirements and discuss the security domains that are tested as well as the most common security best practices covered. We will cover both the differences and similarities in cloud and on-premises based cybersecurity market access requirements as well as go into the different cybersecurity requirements per business need (i.e. financial, medical, etc.).

We will also go through who specifically is involved in influencing and creating these global market access requirements, the specific technical and business requirements that go into these regulations, the specific types of businesses, users, or governments affected, as well as what these market access requirements satisfy in the global cybersecurity landscape, and what they are lacking in the current market. We will map out the global viewpoint of cybersecurity market access certifications, attestations, regulations, and accreditations as well as dive into what the typical engagement process looks like, and how the overall cybersecurity posture of what is being tested is determined.

In summary, this is meant to be a technical discussion on cybersecurity certifications/attestations/regulations/accreditations from the global perspective to take a deeper look at what we are seeing from different countries and where we are seeing trends emerge from key influential regulating bodies. Some market access requirements we will go into are ISO 27001, SOC2, C5 (Germany), SecNumCloud (France), R226, Common Criteria, and many more.

View Details

The 2019 Infosecurity ISACA North America Expo and Conference was held in New York City’s Javits Convention Center on November 20-21. With more than 50 sessions spanning 5 tracks, this conference offered the best-in-class educational content ISACA members and certification holders depend on, plus unprecedented access to leaders in the security industry.

Join Ulf Mattsson, Head of Innovation at TokenX for a conference recap webinar on the biggest takeaways from this year's event.

View Details

Remember WannaCry - the ransomware attack that two years ago infected Windows devices across 150 countries and resulted in an estimated damage of $4B?. We now know that WannaCry was completely preventable. Microsoft had issued a patch two months prior to the attack. If you think WannaCry was bad, brace yourself: We have discovered a technique that attackers may use to deliver ransomware that most organizations have no way to detect or prevent.

This webinar will cover a Windows evasion technique called “RIPlace” that, when used to maliciously alter files, bypasses most existing ransomware protection technologies. In fact, even Endpoint Detection and Response (EDR) products are blind to this technique, which means these operations will not be visible for future incident response and investigation purposes.

The technique leverages an issue at the boundary between a Windows design flaw and improper error handling of an edge-case scenario by filter drivers of security products. While not a vulnerability per say, the technique is extremely easy for malicious actors to take advantage of with barely two lines of code. RIPlace abuses the way file rename operations are (mis)handled using a legacy Windows function.

We will review existing ransomware detection methods, the workflow of a typical ransomware and provide a live demo of RIPlace bypassing a number of anti-ransomware technologies.

Presenter: Nir Gaist, Founder and CTO of Nyotron. Nir Gaist is a recognized information security expert and ethical hacker. He has worked with some of Israel’s largest public and private sector organizations, such as the Israeli Police, the Israeli parliament and Microsoft’s Israeli headquarters. He also wrote cybersecurity curriculum for the Israel Ministry of Education. Nir holds patents for the creation of a programming language called Behavior Pattern Mapping (BPM) that enables monitoring of the integrity of the operating system behavior to deliver threat-agnostic protection.

View Details

In today's world of IT, a robust safeguard service is required for identifying and managing applications from a single point to spot trends and see patterns that are out of the ordinary. SIEM (System Information and Event Management) is a managed security service used to gather information from end-user and even specialized security equipment like firewalls and antivirus systems. Security information and event management (SIEM) software gives security professionals both insight into and a track record of the activities within their IT environment.

While SIEM technology has been around for more than a decade, it’s become a critical component of a comprehensive security strategy in today’s threat environment.

Topics for discussion include: - Evolution of SIEM. - Best practices from expertise. - Next generation SIEM – UEBA and SOAR - SIEM solutions for some common SOC pains. - Integrating AI and ML.

Speakers: Geethanjali Natarajan, Security Solutions Lead at Sennovate Inc Saumya Saxena, Software Engineer at Sennovate Inc

View Details

Technical detection is now just the starting point for a series of exercises which will see the entire business work together to identify what happened and to mitigate the results.

In this session, you will learn:

  • How EDR and MDR are morphing into BDR
  • Why BDR is a challenge for the whole business
  • How technology can help, and how it doesn’t

In this 30 minute webinar Ade will discuss how the world of cyber-security detection and response is changing, fast. From IT and technical analysts to the CEO via HR, this is a problem for the whole business to solve together.

View Details

As organizations mature on their DevOps adoption journey, adopting Continuous Integration and Continuous Delivery (CI/CD) automation, and breaking down organizational silos, application delivery and infrastructure provisioning speed is being accelerated. The next challenge now being exposed is the lack of agility in delivering Data into non-production environments.

Development and Testing require the availability of relevant data in the production-like Dev and Test environments on demand, to ensure rapid testing and validation of each Build. Data is however difficult to provision and deliver on demand. This results in Data Friction being the impediment to true ‘flow’ through application delivery pipelines. Other than the inherent cost and time it takes to provision and store data instances, there is also the risk that exponentially increases as more and more instances of Data are provisioned in multiple non-production environments.

As Dev-Test teams deliver faster and leverage more environments across parallel development streams, the number of non-production Data instances is typically several orders of magnitude higher than Production instances, increasing the exposed surface area. The ask hence is to be able to provision and deliver production-like Data instances, on-demand, as, when and where Dev-test practitioners need them in non-prod environments, while securing the Data at the same time.

In this session Sanjeev Sharma, VP and Global Practice Director for Data Modernization will discuss practices large enterprises need to adopt, across Process, Technology and People in order to be able to Provision, Deploy, Manage, Govern, and Secure Data in Application Delivery Pipelines, addressing Data Friction and Data Security challenges that may be impeding DevSecOps adoption.

View Details

Carbon Black recently found that 84% of UK organisations had suffered one or more data breaches in the past year. Effectively cybersecurity is critical for ensuring the success of your business in the digital age.

In this webinar, ThreatAware CEO Jon Abbott explores the problems that cybersecurity professionals have faced over the past year and how these are likely to evolve in 2020. He draws on his twenty years of experience, including as founder of MSP Priority One, to examine how cyber threats develop and how business cybersecurity needs to grow to meet new challenges.

From comprehensive asset management to compliance with international standards, proficient cybersecurity requires you to juggle a vast number of tools and processes. Jon’s presentation will look at the way in which innovative technology can increase visibility and reduce complexity when it comes to cybersecurity management, to allow your business to embrace positive risk in 2020.

Key takeaways - The biggest risks cybersecurity professionals faced in 2019 - How these risks are likely to evolve moving forward into 2020 - What tools allow businesses to embrace new technologies securely

View Details

Current schemes are insufficient in addressing the growing security risks and cybersecurity concerns that disrupt companies from all walks of life.

In this session we will explain some machine learning (M/L) and data mining (DM) techniques in cybersecurity and vulnerability analysis and discovery. We will explore trends, perspectives, and prospects in the field of machine learning to cultivate an understanding of how ML/DM help to advance the cybersecurity footprint. Data is a coveted commodity for businesses, and everyone needs to understand what steps can be done to automate and innovate the hardening on their data and infrastructure. We will discuss key significant advancements that have been accomplished in machine learning in addition to challenges that exist and future areas for improvement and study. Lastly, we will discuss the three types of cyber analytics and how to combat false alarms and mitigate against cybersecurity intrusion detection problems. We will discuss some cybersecurity intrusion case studies, limitations and challenges that lie ahead.

Key Takeaways:

  • Machine learning can help modernize and advance businesses to run more efficiently and promptly mitigate cybersecurity attacks; which, add-value for businesses on all fronts to protect their company propriety information and customer personal data.

  • Gain insight to machine learning and how it applies to cybersecurity field.

  • Understand how behavior analysis approach can help understand client behavior.

  • Build a better understanding of ML/DM strategies including limitations and advancements.

  • Challenges businesses face with current objectives and how machine learning can innovate previous strategies.

View Details

Join this panel of security experts as they discuss the newest security solutions and strategies utilizing Artificial Intelligence and Machine Learning:

-Best practices for improving security -Why your organization needs to be using AI and ML -How to take security to the next level

Moderator: Michelle Ruyle, CEO & Founder, Optimized Channel Panelists: Jennifer Galvin, Field Alliances Enablement, Okta Roselle Safran, President, Rosint Labs Ian Hassard, Director of Product Management, Arctic Wolf Networks

View Details

Cybersecurity policies meant to protect sensitive information are often misunderstood, avoided, or circumvented by employees. Employees don’t like to be inconvenienced by the extra steps necessary for protection that to them seem unnecessary. This can be compounded by a complex cybersecurity environment with multiple competing standards that seem similar but have unique approaches, naming conventions, and acronyms.

This session will discuss how to solve these challenges by creating cooperative compliance. Cooperative compliance starts by understanding the entire risk environment based on the NIST SP 800-171 Framework, a foundational minimum for confidentiality and integrity. Using the NIST framework and straightforward messaging for employees, cooperative compliance communicates the reasons for cybersecurity inconveniences and protection.

Key takeaways: •Define cooperative compliance •Define and describe the cybersecurity foundational minimum •Describe communication strategies •Provide practical approaches based on the foundational minimum •Comment on useful tools, techniques, and approaches

About the speaker: NTT DATA Federal Services, Chief Technology Officer, Nat Bongiovanni is a US Navy veteran with over 35 years’ experience. Mr. Bongiovanni’s broad IT background allows him to view IT challenges through multiple lenses-- analyst, architect, manager, software developer and cybersecurity expert.

Nat has spoken extensively on cybersecurity, software and policy development. He recently spearheaded a team of cyber experts to develop a cybersecurity solution to protect network assets and data from internal vulnerabilities.

Nat’s experience comes from practical application and valuable lessons learned across a diverse set of clients including, the Office of the Secretary of Defense, Defense Intelligence Agency, the Department of the Interior CIO, the U.S. Securities and Exchange Commission, Blue Cross Blue Shield, and Enterprise Rent-A-Car.

View Details

The temptation to buy a technology to fix a security hole is almost overwhelming. Most vendors know this, and will happily exploit it if you let them. The fact is that very few organisations are even doing the basics yet, without which new technology will be no more effective that the Last-Generation.

Technology cannot fix a broken process, it can only make a good process better.

About the speaker: David has almost 20 years experience in areas of Information / Cybersecurity, including Regulatory Compliance, Secure Architecture Design, Governance Frameworks, Data Privacy & Protection, FinTech and Sustainable Innovation.

As Project Lead for several Fortune / FTSE ‘Enterprise Class’ clients, David has performed hundreds of on-site security and compliance assessments for merchants and service providers globally.

Currently focused on helping organisation unify their security programs with EU regulatory compliance regimes, including GDPR & PSD2.

View Details

Attracting, developing, and retaining women in cyber top talent fields (continuation on the March WiCyS Conference Keynote).

Dr. Dawn Beyer is a Lockheed Martin Senior Fellow. She has over 30 years of experience covering information security, information assurance, security engineering, cybersecurity, systems engineering, military intelligence and operations, risk assessments, strategy, and policy development and execution. She provides consultation to research and development, proposal, program, and operations and maintenance teams. She also provides guidance, direction, leadership, training, and mentoring to Engineers.

Dr. Beyer provides leadership with visibility into cyber strategy, workforce talent, technology, capabilities, risks, policy, and opportunities. At Lockheed Martin, Dr. Beyer is the Cyber Fellows Action Team Chair. She also engages in industry exchanges and Co-chairs the National Defense Industrial Association Cybersecurity Division and is a member of the INCOSE Systems Security Engineering Working Group. She is also a board member with the Women in CyberSecurity (WiCyS) Board of Governors.

Dr. Beyer is a retired Air Force Intelligence Officer with 24 years of service and has performed additional responsibilities as an Information Systems Security Manager, Computer Systems Security Officer, Communications Security Manager, Operations Security Manager, and Emissions Security Manager.

Dr. Beyer earned her Ph.D., M.S., and B.S. in Information Systems. She maintains the following certifications: Project Management Institute’s Program Management Professional (PMP)®, (ISC)2’s Certified Information Systems Security Professional (CISSP)® and Certified Secure Software Lifecycle Professional (CSSLP)®, and ISACA’s Certified Information Security Manager (CISM)®.

View Details

Pcysys CEO Amitai Ratzon, sits down with Blackstone CISO, Adam Fletcher, to discuss the increasing need to automate security validation and this activity’s place in the enterprise security program.

In this discussion, Adam will share the reasons for backing the automated penetration testing platform, PenTera with funding, after running it on their network and how it differs from breach and attack simulation products.

View Details

As the number of data privacy laws and regulations increases globally, organizations need to take a proactive approach to data privacy and security, rather than reactive.

Join this interactive panel of industry experts to learn more about:

  • How to bake privacy and security into your processes
  • Best Practices for achieving regulation compliance
  • How to mitigate risk with data loss protection technologies and solutions
  • Are we closer to a Privacy-and-Security-by-Design reality
  • How to protect your organization from insider threats
  • Recommendations for Improving Data Management and ensuring Data Protection

Panellists Richard Agnew - VP EMEA - Code42 Steve Wright, CEO and Partner, Privacy Culture Limited Bill Mew, Founder and Owner, Mew Era Consulting

Moderated by Allan Boardman, CGEIT Certification Committee Member, ISACA

Data Protection, Data Breach, Regulations, Compliance, Proactive Security, Data Privacy Security Strategy, GDPR, Data Governance, IT Security, Breach Prevention, Risk Management

View Details

Join security experts as they review the past 12 months and discuss security strategies, solutions and tools for success in 2020 and beyond.

Discussion topics will include:

  • The key factors CISOs should consider for their cybersecurity strategy
  • The current and future threatscape
  • Platform Security for 2020
  • Technological solutions that make CISOs' lives easier
  • How organizations are coping with the shortage of qualified security workforce
  • How CISOs can better communicate their strategy to the board

Panellists Richard Agnew - VP EMEA - Code42 Ray Ford, Founding DPO, GDPR Associates Rita Bhowan, IT Security Manager, The Law Society

Moderator to be Mark Chaplin, Principal, ISF

Security Strategy, CISO, Cyber Security, IT Security, Best Practices, Skills shortage, Network Security, Cyber Defence, Breach Prevention, Data Security, Email Security, Vulnerabilities, Cloud Security

View Details

We will discuss the Good, the Bad and the Ugly of Role Based Access Control. We will review access control in systems where multiple roles are fulfilled and compare MAC, DAC and RBAC.

We will present the "next generation" authorization model that provides dynamic, context-aware and risk-intelligent access control. We will discuss Identity Management, Data Discovery, AI, policy-based access control (PBAC), claims-based access control (CBAC) and key standards, including XACML and ALFA.

View Details

The upcoming PCI DSS version 4.0 will include many new or revised requirements and compensating controls will be removed It will include support for a range of evolving payment environments, technologies, and methodologies for achieving security. PCI DSS v4.0 further supports the use of different new technologies. The new validation option gives organizations the flexibility to take a customized approach to demonstrate how they are meeting the security intent of each PCI DSS requirement. This customized approach supports organizations using security approaches that may be different than traditional PCI DSS requirements.

Through customized validation, entities can show how their specific implementation meets the intent and addresses the risk. Unlike compensating controls, customized validation will not require a business or technical justification for meeting the requirements using alternative methods, as the requirements will now be outcome-based.

We will discuss how PCI DSS v4 may impact:

  • Implementation of the new “Customized Controls”
  • Cloud implementations
  • Compliance cost
  • Changes in liability
  • Relation to the 49 new US State Laws
  • PII and PI privacy
  • Measure data re-identifiability for pseudonymization.
  • Apply data protection to discovered sensitive data

View Details

All organizations face ongoing threats from phishing attacks, insider threats, and other trajectories. It is evident that no organization will be able to hire or afford enough cyber security to mitigate or intercept every risk. Security strategy has to start with building a culture in which every employee is responsible for information security. A culture that imbues employee with the training and situational awareness to identify and respond (or not respond, as the case may be) to incoming threats. This webinar explores ways to move beyond everyday security awareness to an integrated security culture.

View Details

The insider threat continues to top all IT security threats. Conventional threat prevention measures primarily consist of annual security training and inserting security early into a project/product lifecycle to ensure incorporation throughout the design. However, these methods have stagnated in mitigating the largest category of insider threat: unintentional/non-malicious.   This presentation provides anecdotal and empirical evidence via a real-life use case,metrics, and testimonials of soft skills as essential characteristics for a modern organization’s security evolution.  Specifically, it addresses the universal reality of internal-organization perceptions of security. New soft skill methods are then offered to overcome communication barriers with internal and external business/technology partners while also promoting a continual working relationship. The result of these improved relationships is project teams viewing security as an essential team member during all phases of an application/product lifecycle, plus the increased security of applications/products released. Secondary gains include maximizing cooperation and collaboration, creating opportunities to teach security concepts and proactively build security into the team’s processes and procedures, and fostering a team’s willingness to self-report security findings and vulnerabilities. As a whole, these behaviors exemplify a security culture that prevents and mitigates the unintentional/non-malicious insider threat.

View Details

The CISO position is now a multifaceted role that encompasses technical capabilities, legal/GRC requirements, and personnel and project management - all while not losing sight of the main objective: business enablement. This webinar will discuss what is important today for both new CISOs who are building their nascent security programs and seasoned CISOs who are maturing their established security programs.

Topics covered will include:

  • Strategic initiatives that are top of mind for security leaders
  • Optimal combinations of in-house and outsourced talent
  • Technology essentials and non-essentials
  • Communicating reports, metrics, and other pertinent information to stakeholders

View Details

In cyber security the strategic goals are often clear, while the methods to achieve those goals is anything but. This webinar introduces Damrod’s Cyber Strategic Framework that applies military analysis to cyber security challenges. Aimed at security teams trying to implement high level goals in the real world, this talk focuses on effects based planning that integrates disparate elements of IT and security into a cohesive package. Defending the network is about more than technology. Analysis and leadership are critical elements of an effective cyber defense. You will leave this webinar better equipped to develop the tactics that make strategy a reality.

View Details

Join this interactive webinar as we discuss using advanced PII/PI discovery to find & inventory all personal data at an enterprise scale.

Learn about new machine learning & identity intelligence technology, including: - Identify all PII across structured, unstructured, cloud & Big Data. - Inventory PII by data subject & residency for GDPR. - Measure data re-identifiability for pseudonymization. - Uncover dark or uncatalogued data. - Fix data quality, visualize PII data relationships - Automatically apply data protection to discovered sensitive data.

View Details

Find out what's trending in BrightTALK's IT Security community and the challenges keeping security professionals up at night.

Join John McCumber, Director of Cybersecurity Advocacy at (ISC)², Dan Lohrmann, Chief Strategist & Chief Security Officer at Security Mentor, Inc., and Marija Atanasova, Content Strategist from BrightTALK for an interactive Q&A session to learn more about:

  • Key challenges for security professionals
  • Insights from the (ISC)² 2019 Cybersecurity Workforce Study
  • What to expect in 2020 and beyond
  • Events in the community

View Details

What keeps CISOs up at night? What challenges are they facing on a daily basis? And what opportunities are they seeing in the industry?

Join experts from leading security organizations as they discuss strategies, solutions and technologies CISOs use in the face of on-going security challenges:

  • Strategies for breach prevention
  • Strategies for making the most of AI technology and human talent
  • New technologies on the horizon
  • Security strategy recommendations

Moderated by: John Bambenek, VP Security Research and Intelligence at ThreatSTOP, Inc. Thomas J. Harrington, Associate Deputy Director (Retired), Federal Bureau of Investigation; Managing Director and Chief Information Security Officer (Retired), Citi, Strategic Advisory Board, Securonix Michal Jarski, Territory Manager, Tenable Yotam Gutman, Community Manager, Cyber Marketing Pros

View Details

This presentation will discuss the current sprawl of different firewall and micro-segmentation appliances and software agents and present an approach on how to solve this challenge.

Today different firewalls and micro-segmentation tools and agents are deployed for network zones, bare metal servers, virtual machines and container environments. This implementation of many disparate security tools creates operational and security problems. To eliminate these challenges, new approach will be introduced which moves services security to the server edge.

New architecture approach to distributed firewalls and micro-segmentation will be elaborated on. Benefits of new edge services security will be demonstrated. Attendees will learn how to take control and implement security at the server edge.

View Details

Businesses are reinventing themselves, leveraging technology and data to optimize and find new streams of revenue. This session will look backwards over the last year and discuss the threat landscape. We will then look into the future and examine the impact of digital transformation and how that is impacting threats and risk. Finally, We will examine how the enterprise can build security and resilience into the business of tomorrow.

View Details

Join this keynote panel with security experts as they discuss the biggest threats organizations are facing and their strategies for better security in 2020: - The threat landscape in 2020 - Key priorities for CISOs - Best practices for improving security

Speakers: - Jo Peterson, VP Cloud Services at Clarify360 - Jessica Bryar, Global Account Manager at Masergy - Wade Woolwine, Director, Managed Services, Rapid7 - Jeff Barto, Trust Strategist, DigiCert

View Details

Tools and solutions are not always technology. This webinar introduces techniques from military wargaming to cyber conflict. You will learn how to identify your assets, assess threats, and allocate defenses. Wargaming is a vital tool to test theories and improve responses by visualizing the ebb and flow of detection, protection, response, and recovery.

View Details

With the increase in mobile and smart devices, we've expanded the threat landscape not only against threats to steal information, but for threats that have real physical risks. For instance, recent research by Google Project Zero and Volexity showed sophisticated attacks against both Android and iPhone devices that were targeted at Uighur Muslims and Tibet. Victims of this malware are targeted for persecution by the government of the People's Republics of China.

This talk will cover not only these attacks in specific, but in how threats are emerging that use new technologies which are being used to create physical threats to its victims and what that means for enterprises, SMBs, and society at large.

Takeaways:

  • Technical discussion on mobile surveillance techniques and malware.
  • Cover real-world instances where such cyber attacks have led to physical harms.
  • Discuss practical techniques to begin to mitigate such threats.

View Details

The threat landscape continuously evolves and adapts, requiring organizations to have a high level of security visibility. Join industry experts as they discuss which threats need to be on your radar and how to prepare for them:

-The threat landscape in 2020 -Best practices and recommendations for a more secure organization -Solutions and strategies for 2020 and beyond

Michelle Drolet, CEO, Towerwall (moderator) Griff Jones, Director, Damrod Analysis Mark Forrest, CEO, Cryptshare AG Nathan Wenzler, Technical Security Director, Tenable Zoë Rose, Ethical Hacker

View Details

We’ve all heard of the increasing sophistication of the threatscape, that attackers have the top malicious tools at their disposal to run havoc in any network they deem worthy. But what does that really mean? And how does it affect your network and cyber defense strategy?

Join Pcysys Head of Research, Alex Spivakovski, for a live demonstration of some of the top hacking techniques threatening enterprises today and how to test for them. See how the smallest misconfigurations in the network can lead to catastrophic outcomes or be remediated with ease. This is an opportunity to get acquainted with the evolving world of continuous cyber testing.

Some of the topics we’ll cover:

  1. Live demonstration of top hacking techniques threatening enterprises today
  2. Top breachable vulnerabilities in 2019 and how to reveal them in your network
  3. A sustainable way to incorporate automation in your security validation practice to stay one step ahead of the attackers

View Details

This session will discuss what attendees learned at The ISSA International Summit 2019, held on October 1-2 at in Irving/Dallas, TX.

Learn from one of the presenters at this conference and what cybersecurity professionals got to share and learn from the leaders in the industry.

Over the last 30 years ISSA international has grown into the global community of choice for international cybersecurity professionals. With over 100 domestic and international chapters, members have world wide support with daily cyber threats that are becoming increasingly intricate and difficult to prevent, detect, and remediate.

View Details

Join this live interactive Q&A session with Sherelle Farrington, Cloud Security Solutions Architect, Fortinet, where we'll be tackling key topics such as:

  1. How can we change security from a blocker into a digital innovation enabler?

  2. Isn’t a diverse, disparate mix of platforms a security nightmare?

  3. Can security even keep up with these dynamic, agile environments?

  4. How do we shift towards a more proactive, risk-focused approach?

  5. What impact are these evolving technologies having on overall infrastructure design?

View Details

As network architectures move to the cloud, knowing how to secure them is vital.

Join experts in this live video panel as they discuss all things virtual and cloud networking - from security, network virtualisation, and beyond.

Topics include:

  • Micro-segmentation and securing your application infrastructure

  • Readying today's hybrid and private cloud networks for tomorrow

  • SD-WAN, IoT and Edge computing: how they are changing the cloud network landscape

Panellists: W. Curtis Preston, Chief Technical Evangelist, Druva Hadar Freehling, Cloud Security Solutions Architect, VMware Sherelle Farrington, Cloud Security Solutions Architect, Fortinet Bob Ghaffari, GM, Enterprise & Cloud Networking Division, Intel Corporation

Moderator David Welch, CTO, House of Brick

View Details

Join this live interactive Q&A session with W. Curtis Preston, Chief Technologist, Druva where we'll be tackling key questions including;

  1. What are the data protection requirements of a hybrid cloud environment?

  2. Does a private cloud environment require a different type of data protection system?

  3. What are the advantages and disadvantages of protecting data using the cloud?

  4. Isn't it more secure to store your backups on-premises?

  5. What about the physics of using the cloud for backup? How do you backup and restore large amounts of data?

View Details

Cloud and Cybersecurity Series [Ep.6]: Next-Generation Cybersecurity: Policy Process and Organization

Resources are finite. So deploying them wisely is what differentiates successful cybersecurity organizations from those that are less successful. Find out how these successful cybersecurity organizations are structured, what policies they have in place, and what strategies they do—and don’t—follow to protect their enterprise organizations.

View Details

Are you experiencing these common challenges in your cloud security program?

There is no question that the way we work has changed with the rise of cloud and the widespread access to mobile devices. This shift in how we work requires us to also shift how we think about security when it comes to the cloud.

Join our panel of C-Level security leaders in a discussion on common obstacles CISOs encounter when moving to the cloud and how you can overcome them.

Topics covered include:

  • Tackling privacy regulations
  • Protecting your company's sensitive data
  • Shifting your existing security strategies to be more cloud-focused

The panel: - Dan Mellen, Global Managing Director, Accenture (MODERATOR) - Robert Scheutter, CISO, Valvoline - Lamont Orange, CISO, Netskope - Nate Smolenski, Director Enterprise Security, Netskope

View Details

Cloud and Cybersecurity Series [Ep.5]: Application Security Meets Multicloud

Enterprises are developing and buying applications to run everywhere: across multiple clouds, multiple data centers, desktops, mobile devices, and IoT devices. In a multicloud environment, IT needs to take a multipronged approach to securing applications.

We'll how organizations approach securing their applications for the multicloud, ranging from changes in the development process to the embrace of security technologies including IAMaaS, microservice authentication, and enterprise secure cloud access and policy enforcement (ESCAPE).

This webinar presents data from Nemertes' in-depth research study of 335 organizations in 11 countries across a range of vertical industries.

View Details

Insider threats can wreck your network, your business, and your company's reputation. But stopping malicious or simply incompetent insiders from doing damage isn't just an exercise in analyzing where the damage came from. Insider Threats aren’t just malicious employees. They can run the gamut from incompetent to accidental to theft. Join Ryan Lai, EVP of Professional Services at Nisos, as he discusses the wide-ranging complexities of an insider threat investigation.

View Details

Software defined storage, or SDS, is growing in popularity in both cloud and enterprise accounts. But what makes it different from traditional storage arrays? Does it really save money? Is it more complicated to support? Is it more scalable or higher-performing? And does it have different networking requirements than traditional storage appliances?

Watch this SNIA webcast to learn: •How software-defined storage differs from integrated storage appliances •Whether SDS supports block, file, object, or all three types of storage access •Potential issues or pitfalls with deploying SDS •How SDS affects storage networking •Scale-up vs. scale-out vs. hyperconverged vs. cloud

After you watch the webcast, check out the Q&A blog http://bit.ly/SDS-Q-A

View Details

In this webinar, we will talk about how to get started as a Women in CyberSecurity (WiCyS) Student Chapter and share ideas on activities, funding, sustainability, competitions, and resources.

View Details

AI and ML are playing an outsize role in myriad fields. However, in cybersecurity, it hasn’t had the same share as in several other areas, despite high potential and a growing need. The security companies have been focused more on the core problems and industry experts generally tend to believe that AI will make further foray into various aspects of the security ecosystem. In this webinar, we will discuss the role of AI in different realms of security products and services, such as identity & access management, malware detection and incident response & forensic analysis.

Key takeaways: - How should enterprises look at leveraging AI to improve their security posture - Which areas are more likely to see higher adoption of AI and where vendors should place their bets - What challenges have to be overcome for broader adoption of AI

Speakers: MuckAI Girish, Chief Business Officer, Appnomic and CEO, Muck.AI Rohini Kasturi, Chief Development Officer, Pulse Secure

View Details

Machine learning platforms are one of the fastest growing services of the public cloud. ML, an approach and set of technologies that use Artificial Intelligence (AI) concepts, is directly related to pattern recognition and computational learning. Early adopters of AI have now rolled out cloud-based services that are bringing AI to the masses.

How are AI, deep learning, machine learning, big data, and cloud related? Can machine learning algorithms enable the use of an individual’s comprehensive biological information to predict or diagnose diseases, and to find or develop the best therapy for that individual? How is Quantum Computing in the Cloud related to the use of AI and Cybersecurity?

Join this webinar to learn more about: - Machine Learning, Data Discovery and Cloud - Cloud-Based ML Applications and ML services from AWS and Google Cloud - How to Automate Machine Learning


Join BrightTALK's LinkedIn Group for IT Security Insights: http://bit.ly/2IsbauU

View Details

This session will take a practical approach to IT risk management and discuss multi cloud, Verizon Data Breach Investigations Report (DBIR) and how Enterprises are losing ground in the fight against persistent cyber-attacks. We simply cannot catch the bad guys until it is too late. This picture is not improving. Verizon reports concluded that less than 14% of breaches are detected by internal monitoring tools.

We will review the JP Morgan Chase data breach were hackers were in the bank’s network for months undetected. Network configuration errors are inevitable, even at the largest banks as Capital One that recently had a data breach where a hacker gained access to 100 million credit card applications and accounts.

Viewers will also learn about: - Macro trends in Cloud security and Micro trends in Cloud security - Risks from Quantum Computing and when we should move to alternate forms of encryption - Review “Kill Chains” from Lockhead Martin in relation to APT and DDoS Attacks - Risk Management methods from ISACA and other organizations

Speaker: Ulf Mattsson, Head of Innovation, TokenEx


Join BrightTALK's LinkedIn Group for IT Security Insights: http://bit.ly/2IsbauU

View Details

Artificial Intelligence, machine learning, and deep learning are the raves in network security. It's perceived as the only practical approach to staying ahead of today's cyberthreats.

The various steps used by Artificial Intelligence is not so different than a physician’s approach to treating a patient. You must first understand the patient (or device), monitor and assess that all organs (or components) are behaving as intended, and proactively treat (or remediate) viruses and other harm.

In this session, Dr. May Wang will explore: - The latest advancements in AI for IoT security using healthcare as an example - The top security threats to healthcare organizations and how to address them.

View Details

With the increasingly connected world revolving around the revolution of internet and new technologies like mobiles, smartphones, and tablets, and with the wide usage of wireless technologies, the information security risks have increased. Both individuals and organizations are under regular attacks for commercial or non-commercial gains. The objectives of such attacks may be to take revenge, malign the reputation of a competitor organization, understand the strategies and sensitive information about the competitor, simply have fun of exploiting the vulnerabilities. Hence, the need to protect information assets and ensure information security receives adequate attention.

In this session, Dr. Umesh Rao Hodeghatta will discuss: - How AI and Machine Learning can be applied in detecting, predicting and preventing cyber security / information security vulnerabilities - The benefits of using Machine Learning and AI - Tools available to perform the same.

View Details

The chief problem with cybersecurity is that most of our tools and workforce is geared to waiting for adverse events, detecting those events (sometimes months after the fact), investigating the breach that has already occurred, and then cleaning up. This slow and reactive process ensures breaches happen and security staff us overwhelmed under the noise.

This talk will focus on automation and machine learning techniques that can proactively identify threats seen in the wild based on the latest academic research. This techniques allow organizations to identify suspect infrastructure before it is used to attack them. The key to making this work is infusing machine learning with knowledge of how actual attacks work and the threat landscape. Machine learning without intelligence is merely gussied up mensa math exercises.

It isn't enough to know what the attacker will use to attack, however. Armed with this knowledge, organizations now need to safely automatically block these attacks before they occur so breaches never happen to begin with. The goal of automation must be to stop attacks before they are launched, not merely speeding up incident response. Several case studies will be discussed showing how this all can work together in the real world.

Takeaways: - How to use machine learning and why it is essential to use strong intelligence to create models - Techniques to use automation to block attacks before they are launched against a victim organization - Cost-effective and safe ways to whitelist and blacklist infrastructure to insure against false positives

View Details

Time and talent are key factors in preventing a data breach. Join Vectra, the leader in AI powered Network Detection & Response (NDR) to explore how enterprises are evolving their security capabilities to become more agile, efficient, and dramatically reduce attacker dwell time through the application of AI.

Join this session to learn: - How should we balance defensive controls against a need to build detection and response capabilities? - How is cloud adoption impacting security architectures? - What roles should automation play within security operations?

View Details

What does it mean to be protected and safe? You need the right people and the right technology. This presentation is going to go into the broad introduction of security principles in general. This will include some of the main aspects of security, including defining the terms that you must know, if you hope to have a good grasp of what makes something secure or not. We’ll be talking about the scope of security, including threats, vulnerabilities, and attacks – and what that means in real storage terms. In this live webcast we will cover:

•Protecting the data (Keeping “the bad” out) •Threat landscape, Bad actors/hackers •Attack vectors, attack surfaces, vulnerabilities •Physical security issues •Layers of protection (encryption – last line of defense) •Remediation after a breach/incident

After you watch the webcast, check out the Q&A blog: http://bit.ly/2JQ1s5L

View Details

As the average monetary cost of a malware attack continues to increase and currently costs an organization an average of $2.4 million, it is essential to be up to date on detection and prevention best practices. Join leading industry experts as they discuss the biggest security threats and how to detect and prevent them:

-New on the threat landscape -How to deploy automated threat detection -Breach prevention best practices

Speakers: Diana Kelley, Cybersecurity Field CTO, Microsoft (moderator) Michelle Drolet, CEO, Towerwall Peter Dougherty, CISSP, CEO, MantisNet

View Details

Will AI (whatever the “A” stands for?) ever replace humans for Automation and Threat Detection?

The advances in technology especially with AI (Artificial Intelligence) is being both embraced and feared. Automation is the key to organizations being scalable and assisting with the skilled resource shortage in the cybersecurity industry though will AI ever fully replace humans, and will it eventually be GOOD AI versus BAD AI when it comes to cyberattacks. Could humans simply become a spectator when it comes to the future cyberattacks? This webinar will look into all those questions and possible outcomes.

Join Joseph Carson from Thycotic to take a journey from the present and into the future of AI & Humans, can we coexist together?

Key Takeaways: What are the current capabilities of AI today in Threat Intelligence? Can AI prevent cyberattacks? Will AI replace humans for Cyber Defense or Offensive capabilities? Future of AI & Humans, can we coexist together?

View Details

Today’s cybersecurity teams face unrelenting attacks, adversaries of increasing sophistication, mounting responsibilities, and technologies that produce overwhelming amounts of data. Ideally organizations could address these challenges with a comprehensive team of talented cybersecurity practitioners, but in reality most organizations struggle to find potential employees due to the cybersecurity workforce shortage. This talk will discuss ways to deal with the enormous demand, but scarce supply, of cybersecurity professionals.

Topics covered will include: - Low-cost ways to improve the skill sets of security team members - Strategies for streamlining security operations - Augmentation approaches for security programs of different sizes and maturity levels

View Details

In a world facing a shortage of skilled security professionals, organizations are turning to AI and machine learning-based solutions to combat today's threats.

Join this panel of security experts as they discuss the role of people and machines in cybersecurity: - The current state of AI, threats and security workforce - Why is human error a top cybersecurity risk for organizations - Which tasks can be automated, and where do we need human talent when it comes to security - Ways to apply AI and ML to boost cybersecurity - What NOT to do when it comes to AI and security

Speakers: - Kalani Enos, Founder & CEO, kenos Technologies LLC (moderator) - Jim Rigney, Principal Consultant, Hybrid Pathways - Trevor Pott, Director of Product Marketing, Juniper Networks

View Details

Too often, when I tried to learn cybersecurity in a classroom lab, I found that it existed in a sphere of ideal conditions: we were given the perfect command on the perfect target to get the perfect results on that target. As it turns out, the real world has less than ideal conditions, so I wasn’t sure how my education was going to translate to the real world. That’s when I discovered cyber competitions. In the CTF’s I began to play, I found that there were no wrong ways to get a right answer and I was finally able to hit the ground running in a way that felt like I was preparing for the workforce. Just over a year into my career, I can say that Cyber CTF’s prepared me better than any classroom experience could. Join me on Wednesday, October 2nd to find out how this newbie took her skills from #N00bSec to #Cyber-Champion using CTF’s!

View Details

What's new in data privacy and security? Discover how the compliance landscape is changing in 2020 and what organizations are doing - or should be doing - to prepare.

Join this panel of experts for an interactive Q&A session to learn more about what's coming up on the horizon in 2020 regarding data privacy and security, and the steps you can take today.

Viewers will learn more about: - Data regulations and deadline dates to be aware of - Privacy in the cloud - How to build trust through privacy - Recommendations for 2020 - The CCPA checklist

Speakers: - Dr. Christopher Pierson, CEO & Founder, BLACKCLOAK - Shahrokh Shahidzadeh, CEO, Acceptto - Michelle Drolet, CEO, Towerwall - George Wrenn, CEO & Founder, CyberSaint Security

This Q&A panel is part of National Cyber Security Awareness Month.

CyberAware #BeCyberSmart

View Details

Cloud and Cybersecurity Series [Ep.4] Next-Generation Cybersecurity - Technology Foundations

The bad news? Threats evolve. Bad actors continue to improve their games. The good news? Cybersecurity technology is also evolving and improving. This webinar drills down into the emerging technologies that successful cybersecurity organizations are deploying to protect their firms. Find out what works, what's a waste of resources--and how to deploy the technologies that work.

View Details

As enterprises begin to implement services from more than one cloud provider, security professionals need to know what to do to keep their organization safe.

Join this webinar to learn about the best practices in a multi-cloud environment and get to know about:

• Managing Identities • Securer logins and ensuring Stronger Authentication • Managed Access Control • Security Monitoring and Maintenance • Managed SoC – SIEM/SOAR options

Presented by: Senthil Palaniappan, CEO and Founder, Sennovate Inc.

Speaker overview: • Over 25 Years of Industry Experience • Specializes in Identity and Access Management, Infrastructure and Integration • Consulted with various fortune companies

View Details

Join Sonrai Security CTO & Co-Founder Sandy Bird present multiple IAM configuration options available on AWS, Azure, & GCP that can deliver strong application security or a breach nightmare

Organizations of all sizes are harnessing the operational and cost benefits of public cloud. Unfortunately, cloud platforms like AWS, Azure, and GCP provide a wide range of identity and access management (IAM) based configuration options, that can be disastrous if not properly architected. During this webinar, you will learn the benefits and risk trade-offs of multiple public cloud IAM configuration options including:

  • Organization/Account-wide privilege
  • Privilege delegation & escalation (by user or role)
  • Service-based & in-line privilege
  • Understanding of IAM policy best practices and conflict resolution

Enterprises building in public cloud must ensure their security programs tightly control trust relationships that can be configured from IAM options to ensure adherence to the principles of least privilege and the segregation of duties. Public cloud IAM capabilities can be highly effective to build secure applications when done well. However, they can lead to a disastrous breach when poorly configured.

View Details

Identity is rightfully billed as a central point of protection in the perimeter-less world. The emergence of zero trust, after all, is about WHO can access WHAT data rather than WHERE they can access any data. At the same time, establishing and continuously verifying identity relies heavily on that same data. Whether provisioning new devices, authenticating users or leveraging behavioral analytics for step up authentication, data protection and integrity are critical to a functional zero trust environment. The emergence of machine learning and the risks of programmatic bias due to insufficient or poorly curated data add additional nuances to the conversation.

In this presentation, we will take a tour of the symbiotic relationship between identity and data. Join us as we discuss how identity can enable data protection in a multi cloud environment and how data protection and classification enable sound identity decisions.

View Details

How should we prepare for this new brave world where many 3rd party security providers disappeared into cloud providers? This will greatly impact many 3rd party security vendors, organizations and investors.

Cloud transformations are accelerating. By 2020, cloud will increase by 157% and on-premises ’traditional’ IT infrastructure will decrease by 54%, according to 452 Research, 2018.

We will cover how many security solutions will change, including: - WAF – Web Application Firewalls - SIEM - Firewalls - Encryption - Tokenization - Key Management - AV – Anti Virus - Network - And more...


Join BrightTALK's LinkedIn Group for IT Security Insights: http://bit.ly/2IsbauU

View Details

Kubernetes is the new cloud OS, and enterprises are rapidly migrating existing applications to Kubernetes as well as creating new Kubernetes-native applications. However, Kubernetes configuration management remains complex, and due to this complexity, most implementations do not leverage Kubernetes constructs for security. In this session you will learn:

  • Key Kubernetes constructs to use for properly securing application workloads in any cloud
  • How to manage Kubernetes configurations across multiple clusters and cloud providers
  • How to audit and enforce enterprise-wide Kubernetes best practices

View Details

With sensitive data residing everywhere, organizations becoming more mobile, and the breach epidemic growing, the need for advanced identity and data protection solutions has become even more critical.

Join this webinar to learn more about: - Data Protection solutions for the enterprise - Trends in Data Masking, Tokenization and Encryption - New Data Protection Standards from ISO and NIST - The new API Economy and how to control access to sensitive data — both on-premises, and in public and private clouds - The llatest developments in IAM technologies and authentication


Join BrightTALK's LinkedIn Group for IT Security Insights: http://bit.ly/2IsbauU

View Details

For busy development teams and information security professionals, it can be challenging to keep pace with DevOps code and cloud migration whilst staying on top of security. As we look at the 'shift left' approach and wok to locate defects early in the SDLC, Simon Roe, AppSec Product Manager at Outpost24 will discuss the pitfalls you may face when migrating to cloud and how to overcome them.

View Details

Cloud and Cybersecurity Series [Ep.3]: Succeeding in the Multicloud

With most IT work being done in the cloud, what does it mean to be successful and what are the characteristics of highly successful cloud enterprises?

We'll dig into the what it means to be successful in the cloud and what successful organizations do more of (and less of) than their less successful peers. We'll look across technologies adopted, organizational and operational practices, and vendors embraced.

This webinar presents the highlights of Nemertes' in-depth research study of 335 organizations in 11 countries across a range of vertical industries. Later episodes will discuss security topics as well as focusing in on application development and security.

View Details

As organizations are forced to adapt to the world around them, the amount and severity of threats continues to increase. In order to ensure security in the cloud, it is vital to protect and maintain IT systems and devices in the office and remotely. Join this panel of industry experts as they discuss cloud cyber hygiene strategies and solutions, including:

  • Cloud security protocol best practices
  • Strategies for cloud security success
  • IT Security hygiene in real time
  • Tools and technology to ensure cloud hygiene

Moderator: - Ed Moyle, General Manager and Chief Content Officer, Prelude Institute Speakers: - Nathan Burke, CMO Axonius - Raef Meeuwisse, ISACA Expert Speaker & author Cybersecurity for Beginners

Join BrightTALK's LinkedIn Group for IT Security: http://bit.ly/2IsbauU

View Details

Cyber-attacks have cost the financial services industry more than any other sector, especially due to the extremely sensitive data and assets that they are gatekeeping.

Join this panel to learn: -What is the current state of the cybersecurity in financial services? -Why is cybersecurity more of a business risk than a technology issue? -Best practices for detecting and preventing threats

Robert Prigge, President, Jumio Tony Fish, Founder, AMF Ventures Steven Holt, Practice Lead - EMEIA FS Cybersecurity, EY Cheri McGuire, Group Chief Information Security Officer, Standard Chartered Bank

View Details

The interplay of Humans and Machines in AI-based Automation

Machine learning systems are now routinely performing complex tasks at unparalleled levels of performance across a wide range of applications. However, mission-critical applications such as those in financial services have a minimum tolerance for errors and error correction. Resultantly, the design of machine learning-based systems for such applications requires unprecedented levels of oversight and adaptability.

An optimal system has the right level of interplay between humans and machines. Onfido employs a large number of machine learning models to deliver scalable, secure and frictionless identity verification for their clients, whilst giving clients accurate data they need to remain KYC compliant—so ensuring their models deliver real-world results is business-critical. In this interview we talk with Mohan Mahadevan, VP of Research at Onfido, to learn about how the constraints on these applications, the tradeoffs in an optimal system, and what the future looks like.

Mohan Mahadevan, VP of Research, Onfido Tony Fish, Founder, AMF Ventures

About Mohan

Mohan is an expert in computer vision, machine learning, AI, data and model interpretability, previously leading research efforts at Amazon as Head of Computer Vision and Machine Learning for Robotic Applications. He has over 15 patents in areas spanning optical architectures, algorithms, system design, automation, robotics and packaging technologies. As Onfido’s VP of Research he leads Onfido’s team of specialist machine learning engineers and is focused on ensuring their systems work both in the lab and the real world.

View Details

In this session, we'll discuss various approaches to managing multi-cloud security,

Presented by: Jeremy Snyder, VP Business Development & International Strategy Jeremy has been in SaaS since 2002 and in the cloud since 2010. His career has been 5 startups (3 co-founded) and Amazon Web Services. Jeremy's been with DivvyCloud since 2016 and has worked with cloud customers in 4 continents to improve their security posture. Jeremy has a BA in Linguistics from the UNC and an MBA from GMU. Jeremy has lived in 5 countries and speaks more than 5 languages. Jeremy once went 3 days without seeing another human (although he saw dozens of reindeer) and another time got kicked off a train in central Sweden.

View Details

Join Sonrai Security CTO & Co-Founder Sandy Bird present why a zero-trust security program is critical to public cloud platforms like AWS, Azure, & GCP

Applications built on a public cloud requires a security model based on trust relationships between consumers of data and the data itself. Public clouds like Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) all provide the ability to build applications with strong Identity and Access Management (IAM) policies.

Unfortunately, the numerous IAM configuration options can quickly turn a unique opportunity to build security into applications into a security nightmare. Enterprises building in public cloud must ensure their security programs tightly control trust relationships to ensure adherence to the principles of least privilege and the segregation of duties. During this webcast you will learn:

  • A historical perspective on zero trust
  • Why the foundation of zero trust is critical for applications built in a public cloud
  • The potential risk that can be introduced by public cloud IAM configuration options
  • The importance of baselining and monitoring trust relationships in public cloud
  • Highlights of different public cloud IAM models

View Details

According to Forrester's Cloud Security Solutions Forecast 2018 to 2023 report, the global spend for cloud security technologies will reach $12.7 billion by 2023, mostly driven by financial services organizations. This spend likely won't flow into a single vendor, as organizations are increasingly relying on several options for securing their clouds.

Join this keynote panel of experts to learn more about the biggest trends in cloud security, as well as the best practices for securing your multi clouds: - Crucial steps companies should be taking as they move data and processes to multiple cloud environments - Understanding the shared responsibility model in the context of infrastructure-as-a-service (IaaS), software-as-a-service (SaaS), and platform-as-a-service (PaaS) - Protecting and planning for the future

Moderator: - Jo Peterson, Vice President, Cloud and Security Services, Clarify360

Panelists: - Manon Buettner, CEO & Co-Founder, Nuvalo - Michelle Ruyle, CEO & Founder, Optimized Channel - Fred Streefland, Chief Security Officer (CSO) for North & East-Europe (NEEUR), Palo Alto Networks - John Aarsen, Benelux & Nordics Solutions Architect, SonicWall

Join BrightTALK's LinkedIn Group for IT Security: http://bit.ly/2IsbauU

View Details

The California Consumer Privacy Act (CCPA) is going into effect on January 1, 2020, making it America’s first-ever state data privacy law. It is also the most far-reaching privacy regulation in the U.S. to date.

Join this panel of experts for an interactive Q&A session to learn more about what businesses need to do to prepare for CCPA. Attendees will also learn about the CCPA checklist, as well as dive into: - GDPR vs. CCPA - Which organizations need to plan for CCPA compliance - What to do to avoid the risk of fines - How to develop a strategy and start implementing tools to achieve compliance - More privacy legislation on the horizon

Speakers: - Guy Cohen, Strategy and Policy Lead, Privitar - Lisa Hawke, VP Security and Compliance, Everlaw - Joanne Furtsch, Director, Deputy Data Governance Officer, TrustArc - Laura Koulet, Vice President, Head of Legal & Privacy, Tapad

View Details

Seeking a SOC? The Time is Right!

If you're like most enterprise security professionals, you know you need a security operations center (SOC). But should you build out your own, engage a third party, or take a hybrid approach? This webinar provides you with the answers. Nemertes helps you make that decision, based on objective data from our research studies. And we provide a detailed playbook and roadmap for taking action.

View Details

This Lockheed Martin presentation introduces the concepts of career pivots for women who are contemplating or executing a pivot as well as anyone who might have the need to navigate a career pivot in the future. Keys to successful career pivots are identified and the general steps to be performed are described. Specific considerations for pivoting into careers in cybersecurity are also provided.

View Details

Cloud and Cybersecurity Series [Ep. 2]: Mastering Multicloud - Architectures, Organizations, Building Blocks

In 2019 the balance tipped, and for the first time the majority of enterprise IT workloads are running in the cloud, not in a data center.

Enterprise IT staff need to stop thinking of cloud solutions as islands of function and special cases and begin to think of pulling it all together into a cohesive multicloud. We'll lay out the major categories of tools and systems and how they fit together, and at the organizational structures and operational practices needed to support multicloud operations.

This webinar presents the highlights of Nemertes' in-depth research study of 335 organizations in 11 countries across a range of vertical industries. Later episodes will discuss cloud organizations and operational practices, and success metrics and best practices for cloud organizations.

View Details

Technical detection is now just the starting point for a series of exercises which will see the entire business work together to identify what happened and to mitigate the results.

In this session, you will learn:

  • How EDR and MDR are morphing into BDR
  • Why BDR is a challenge for the whole business
  • How technology can help, and how it doesn’t

In this 30 minute webinar Ade will discuss how the world of cyber-security detection and response is changing, fast. From IT and technical analysts to the CEO via HR, this is a problem for the whole business to solve together.

View Details

Cloud & Cybersecurity Series [Ep.1]: Success Metrics, Best Practices & More

What does it take for enterprise cybersecurity teams to "up their games" to the next level of cybersecurity? What does it mean to be a "successful" cybersecurity organization, and what technologies and practices does it take to become one?

This webinar presents the highlights of Nemertes' in-depth research study of 335 organizations in 11 countries across a range of vertical industries.

We separated the best from the rest, and took an in-depth look into what made the most successful organizations that way. Participants will come away with best practices, tools, technologies, and organizational structures that contribute to success. Most importantly, they'll learn how to measure cybersecurity success--and their progress towards it.

View Details

In this webinar from Women in CyberSecurity (WiCyS) and the Security Industry Association (SIA), cybersecurity consultants Min Kyriannis (Jaros, Baum & Bolles) and Valerie Thomas (Securicon) will explore the important relationship between cybersecurity and physical security.

Drawing lessons from real-world threats and attacks, our speakers will look at how cybersecurity vulnerabilities can be used to compromise physical security systems and why cybersecurity of IT systems depends on controlling physical security. We’ll discuss why CSOs, IT leaders, cybersecurity professionals and vendors/service providers all need to be paying attention to the cybersecurity of physical systems, and we’ll discuss what it means to drive security convergence at both strategic and operational levels, and how new technologies like AI factor into today’s converged security models.

Key Focuses: •How to evaluate and improve the cybersecurity of cyber-physical systems •How threat actors are targeting cyber weaknesses in physical security systems •Why security convergence matters and what the relationship between cybersecurity and physical security teams can look like •How new technologies like AI are evolving security

Key Topics: Cybersecurity, Physical security, Security convergence, Hacking, Hackers, cyber-physical systems, Security management

View Details

The most important function of an application security program is effectively fixing flaws once they’re discovered. But the speed of that fix rate matters — the time it takes for attackers to come up with exploits for newly discovered vulnerabilities is measured in days, and sometimes hours. Yet our most recent State of Software Security report found that one in four high and very high severity flaws aren’t addressed within 290 days of discovery.

Improving your fix rate is critical, but the sheer volume of vulnerabilities present in most organizations’ application portfolios makes it necessary for them to make daily tradeoffs between security, practicality, and speed.

This might seem like an insurmountable problem, but our data also presents hopeful glimpses at potential prioritization and software development methods that could help organizations reduce risk more quickly. In this session, we’ll share some steps and best practices that will start lowering your fix rate.

This session is part of Veracode's "Your AppSec Game Plan" Summit.

View Details

It’s more common than you think that organizations and brands have more web apps than they realize. In fact, Veracode customers often find roughly 30 per cent more applications than they knew about. With one project Veracode worked on for a high street bank in the UK, they discovered 1,800 websites that had yet to be logged.

There are a number of reasons unknown or unlogged web applications continue to live in your portfolio. For example, through M&A activity, more than just a company or brand is acquired – you also acquire their web assets. Further, the digital landscape is decorated with marketing promotional sites meant to attract attention. And the very thing meant to draw attention to your brand and boost your bottom line is the same target attackers go after to infiltrate your organization.

Join this session to learn how to uncover unknown web applications in your portfolio to ensure their security from cyberattackers.

This session is part of Veracode's "Your AppSec Game Plan" Summit.

View Details

Open source frameworks have changed the business world in profound ways. They’ve ushered in a level of speed, innovation, and convenience that significantly alters the IT equation. With large numbers of developers and others contributing to a project, it’s possible to advance and evolve software in ways that wouldn’t have been imaginable in the past. What’s more, this form of open collaboration benefits everyone by making software available at a lower cost point — and sometimes even at no cost.

Make no mistake, open source software libraries are here to stay – and they can introduce new and sometimes dangerous risks to an enterprise. The use of open source code increases the number of users affected as well as the number of exposure points. It’s vital to have a strategy and framework in place to manage open source libraries and components. Otherwise, the road to digital transformation will likely be paved with frustrations, problems, and even failures.

Open source software risks revolve around three key areas: visibility, security, and governance.

In this session we will help you understand these factors and how to formulate a stronger cybersecurity strategy that protects you from open source risk.

This session is part of Veracode's "Your AppSec Game Plan" Summit.

View Details

One of the most powerful things an organization can do to improve its security posture is to cultivate security-mindedness in its developers. Security and development teams often feel at odds with one another and yet they share a common goal: to put quality code into production. Bringing these teams into closer contact gives them a deeper understanding of each other’s pressures, priorities, and processes.

Developers are well-positioned to address application security. By designing applications with security in mind, and finding and fixing flaws early in the software development lifecycle, developers shift security left. In doing so they both lighten the burden on the security team and reduce unplanned work for themselves down the road.

An interested developer—given the right direction, encouragement, and tools—can become an effective security champion.

Join this session to learn how to identify the right developers for this role and how to best train and support them over time. Your security champions will advocate for security as a non-negotiable component of code quality and in turn foster security-mindedness in their peers, amplifying security knowledge across the organization.

About the speaker: Ryan O’Boyle is a Principal Security Researcher at Veracode, and a certified ScrumMaster. Prior to joining Veracode, he helped create the internal penetration testing team at Fidelity Investments, where he was focused not only on finding vulnerabilities but helping engineers fix them and avoid them altogether.

This session is part of Veracode's "Your AppSec Game Plan" Summit.

View Details

Although there are a variety of application security technologies, there is no silver bullet. You need to gather the strengths of multiple analysis techniques along the entire application lifetime — from development to testing to production — to drive down application risk. Each testing type, from static to dynamic to software composition analysis and manual pen testing, has different strengths and weaknesses and are better in different scenarios, but you won’t be effective without taking advantage of them all.

Join this session to understand the strengths and weaknesses of the different AppSec testing types, how they work together, and how to get started.

This session is part of Veracode's "Your AppSec Game Plan" Summit.

View Details

The demands of modern software development and the rise of DevOps are shifting security left into the early phases of the development lifecycle. Companies that navigate this significant cultural, organizational, and technological change well are outpacing their competitors. But where to begin?

In this session, we will describe five essential steps for shifting security left:

1) Make security autonomous from day one. 2) Integrate as you code. 3) Avoid false alarms. 4) Create security champions. 5) Maintain operational visibility.

Equipped with this guidance you can begin to make the changes that will transform application security into a responsibility that is shared by development and security and that continues once applications are in production and operation. By shifting security left, you unburden your security team, empower your developers to write better code from the start, and deliver stronger, better applications than your competitors.

This session is part of Veracode's "Your AppSec Game Plan" Summit.

View Details

Join us for this webinar that will demonstrate how your organization can adopt best practices for vulnerability management, threat intelligence and cyber risk management that previously had been beyond your means. For various reasons - tight budgets, lack of skills or resources, or a focus on other priorities - most companies perform vulnerability, threat and risk management in a very tactical way. Join Troy Vennon, Director of Security Innovation at the Columbus Collaboratory, for this session outlining how the combination of cloud-based vulnerability management, threat analysis and risk assessment, bundled with expert reporting and guidance for your specific IT environment, will cost-effectively transform your security operations from the tactical to the strategic.

View Details

Intelligent Customer Engagement Series [Ep.2]: Top 5 'Must-Haves' for Your Next-Generation Contact Center

Contact centers are changing--drastically and swiftly. If you're not keeping pace--or exceeding it--you'll be at a competitive disadvantage.

Learn what successful companies are doing with areas such as agent experience, interaction channels, and emerging technologies.

Based on Nemertes' brand new, detailed, Customer Experience research study with 518 organizations, this webinar will explain the five crucial items that must be on your priority list to ensure your contact center is positioned to deliver successful customer experiences.

View Details

Join us for this webinar presenting the benefits of networking with your industry peers to share intelligence about threats and vulnerabilities. In today's environment where the threats seem to intensify, it's critical to know who to trust. During this session, Troy Vennon, Director of Security Innovation at the Columbus Collaboratory, will outline the benefits of an Information Sharing and Analysis Organization (ISAO), explain how you can benefit from joining an ISAO even if you're already part of an ISAC, and provide an example of how collaboration around cyber threat data can enable your organization to efficiently identify and neutralize the most prolific and potentially harmful threats out there.

View Details

Running SoC on-premise is highly complex and expensive. This calls for expertise (for example -Firewall, DNS, Network analyst, Active Directory Domain, IAM), and well preparedness to handle unique situations. This is key in protecting any organization's digital assets. It becomes imperative for starter companies to build the credibility success factor to stay competitive as against large enterprises. This raises the question of how you would leverage various security products, to build a true Security Operations Center (SoC) yet delivered as a Service.

Register for this webinar and you will learn about:

SoC as a Service, and its Importance Key Components of SoC - Asset Discovery, Threat detection, Vulnerability Assessment, Behavioral Monitoring Rapid Incident Response & Event Investigation Better Risk & Compliance Management Role of AI/ML to simplify the process Choosing SoC as a Service vs Build your own SoC Things to consider while choosing SoC as a Service provider

About the speakers:

Senthil Palaniappan, CEO & Founder at Sennovate Inc. - Over 25 Years of Industry Experience in Information technology - Specializes in Information Security, Identity and Access Management, Infrastructure and Integration - Consulted with various fortune companies

Kumar K, Lead Solution Architect at Sennovate Inc. - Over 18 years of industry experience - Specializes in various Identity and Access Management products including oracle and various cloud products - Vast experience in building custom solutions with Oracle Access Manager.

View Details

It is beyond the ability or willingness of the world’s governments to protect and secure information technology. What role then can the private sector play in making cyberspace safer? Can private enterprises do anything to strike back at attackers, curtailing their freedom of action and raising the costs of malicious activity?

Consisting of academics and industry experts, this panel will explore the potential for active cyber defence to impede and deter malicious activity and the conditions under which it could be conducted responsibly.

Speakers: - Griff James, Director at Damrod Analysis - Wyatt Hoffman, Research Analyst, Cyber Policy Initiative at Carnegie Endowment for International Peace - Will Lymer, Chief Growth Officer at Loki Labs

View Details

This talk will address how we need to develop and configure systems and software to eliminate common forms of malware and exploits. It is an engineering challenge that requires substantial change in tools and how we write applications and operating systems and how we design hardware. None of it is rocket science, but the pieces must be put together.

Viewers will learn about: - Attack vectors and hidden risks - How to build better dams, rather than trying to patch every leak and crack

Do we want our dams to be strong and safe, or is it more important to ensure that we can easily blow up the dams of any opponents, even if ours will break too? As a society increasingly living downstream of the dams, building better dams is a matter of survival.

Presented by a 20+ year security pioneer and inventor of SSH (Secure Shell, the de facto standard for system administration) and the principal author of NIST IR 7966 (guidelines for managing SSH access).

View Details

Trying to navigate the stormy seas of multi-factor authentication (MFA) to find the “killer app” both you and your organization can use to bolster security? In this webinar, we look at:

  • The various factors of authentication
  • Factor vs “steps”
  • Considerations in choosing a factor
  • The various technologies that people are using
  • What seems to be working

Whether you’re pondering Near Field Communication (NFC) ninja tech for your smart phone, or those new biometric doo-dads that verify you based on the smell of your ears (really), we can help you sort out what might work for you and what would be crazy to implement. And as a bonus: this tech will all keep you far safer that your plain old password ever did.

View Details

Securing the networks from attackers remains a key challenge in 2019. With billions of people affected by data breaches, governments and businesses are continuing to spend more time and money trying to better protect against cyber attacks.

Join this panel of experts as they discuss the biggest threats to enterprise networks and how to better protect against them: - Top threats to network security - Watering hole attacks: Explanation and examples - Microsegmentation and lateral movement prevention - How to improve the security of network infrastructure devices - Real time breach detection: Myth or reality? - Steps to take to better secure your networks

Speakers: - Kalani Enos, Founder and CEO, kenos Technologies LLC (moderator) - Greg DeBrecourt, Cyber Security Manager, Aerovironment - Gavin Millard, Vice President of Product Marketing, Tenable - Peter Wood, Partner, Naturally Cyber LLP

View Details

Measuring the effectiveness of a security program can be a challenge for most organizations. After all, when you do everything right, nothing happens. No email outages, no denial of services impacts and no data breaches. Measuring nothing doesn’t really tell you much, and it certainly doesn’t give you insight into where you’re still vulnerable and could be attacked by a malicious actor. Vulnerability Management (VM) tools have been a mainstay tool for any security program, and they generate a wealth of information about what assets are most at risk from outside threats, but the information isn’t always put to best use by most organizations.

In this session, we’ll look at the common metrics mistakes most organizations make with their VM efforts, as well as more relevant and actionable metrics that will help you get a better understanding of your security posture against today’s threat landscape.

· Learn how vulnerability information is critical to boosting good threat intelligence against common attack chains · Identify metrics that are commonly used by nearly every organization, but don’t deliver any real value to your organization · Discover ways to frame vulnerability data into meaningful, actionable metrics that give a more true sense of the risks to your assets · Understand ways to improve your VM program to build more relevance into your threat intelligence efforts

View Details

Misconfigurations aren’t simply inconvenient errors but serious security threats. According to Gartner, 99% of all firewall breaches will be caused by misconfigurations by 2020 and misconfigurations made OWASP’s latest list of Top 10 most critical web application security risks.

A single change to a network device can have far-reaching effects on your business and create security holes for cybercriminals, impact your regulatory audit, and even cause costly outages that bring your business to a standstill! This is true whether on-premise or in the cloud.

In this webinar, Avivi will present several examples of common misconfigurations, including device changes, business application connectivity changes, and data center migrations. He will also reveal specific techniques to help you avoid misconfigurations.

Watch the webinar to learn how to:

•Monitor cloud services to take a proactive stance against misconfigurations •Understand and map your entire network before you make a change •Understand the impact of changes to your entire hybrid network •Proactively assess the impact of a change to ensure it does not break connectivity, affect compliance or create a security hole •Use network management automation to avoid common misconfigurations •Avoid common mistakes when making changes to your network security devices

View Details

This talk will explore the challenges of defining security policies for hybrid and multi-cloud implementations. The attendees will see the new components needed for hybrid cloud security policies. The considerations of what content is needed for multi-cloud security policies will be listed. The clear advantage of workload context will be used to show how security policy can be created for cloud-based workloads. Security policy for dynamic movement of workloads to different cloud environments such as AWS, Azure, Google Cloud, and private clouds will be explored. Ideas on how to properly create a security policy for dynamic workload movement will be presented.

Attendees will see that the role of IP in a multi-cloud security policy is diminishing or even presenting an obstacle. Hybrid and multi-cloud security policies introduce a new paradigm in security, and presentation attendees will learn how to embrace it.

View Details

For years organisations have relied on perimeter-based security strategies to protect and secure their networks. As the workplace becomes increasingly fluid, it is clear that relying solely on perimeter-based security is no longer suitable.

Join this exclusive panel of industry experts as they discuss: • Where traditional perimeter-based security models fall short • Notable cyber attack methods and how to protect against them • Strategies for improved network security and how to implement them

Speakers: - Jo Peterson, VP Cloud Services, Clarify360 (moderator) - Tina Gravel, SVP Global Channels, Cyxtera - Adrian Taylor, CTO, ITC Secure - Josh Frantz, Lead Security Consultant, Rapid7

View Details

The terms security and cyber (short for cybersecurity) are often used interchangeably, referring to the profession narrowly defined as a team of professionals who leverage technologies and processes to defend an organization’s systems and networks from attack. However, this narrow use of security sells the field short – there are in fact a number of key functions under the security umbrella, one of which is cybersecurity, all of which are essential to the success of the organization. Some such functions are: physical security, fraud prevention, privacy, business continuity, disaster recovery, and risk management, although there are still more. And though the security field is defined by the technical “hacker” persona, people with backgrounds, skills, and interests of a wide variety have all found success under the umbrella of work in the security field.

Join our webinar to hear from several of Equifax’s women leaders who have come to security from different educational backgrounds, former careers, and interests, but who share a passion for challenging work, career growth, and personal excellence. Learn about their career journeys that led them to security, how they apply their interests and training to their current work and future professional goals, and hear the advice they have for the next generation of women in security. Bring your questions, too, and participate in this lively interactive discussion!

View Details

The PCI Dream Team is back for another interactive Q&A session.

With hundreds of different requirements, the various Payment Card Industry (PCI) standards can be overwhelming. While the PCI Security Standards Council has provided lots of answers, the devil is often in the details.

Our panelists are some of the top PCI QSA’s in the country, with decades of combined PCI and card processing experiences. They’ve seen it all: the good, bad and ugly; and lived to tell the tale.

Join Ben Rothke, David Mundhenk, Arthur Cooper, and Jeff Hall for an interactive Q&A session, and get answers to your most vexing PCI questions. No PCI question is out of bounds.

Speakers: - Ben Rothke, Senior Information Security Specialist at Tapad - David Mundhenk, Senior Security Consultant at Herjavec Group - Jeff Hall, Senior Consultant with Online Business Systems - Arthur Cooper "Coop", Senior Security Consultant at NuArx

View Details

Organizations are realizing the necessity to treat security as a first-class citizen instead of an after-thought. When it comes to DevOps, organizations are now including security at every step of the development and deployment lifecycle.

Join experts from the industry to learn more about: - Security challenges and vulnerabilities - DevOps vs DevSecOps: What's the difference? - How to make disjointed security and DevOps teams work effectively - DevOps security scans - Steps to better application security

Speakers: - Rick Moy, CMO, Acalvio Technologies - Dr. David Brumley, CEO & Co-Founder, ForAllSecure - Connor Gilbert, Product Manager, StackRox - Jay Beale, CTO & COO, InGuardians

View Details

How are organizations handling security for their multiple clouds and applications? Join cloud and security leaders in an interactive discussion to learn about: - Multi-cloud reality - Addressing your cyber risk - Managing vulnerabilities, detecting breaches and responding to incidents - Automating security tasks across multiple clouds and applications - Recommendations for improving enterprise cloud security

Speakers: - Raj Mallempati, COO, CloudKnox Security - Chris Schueler, Senior Vice President of Managed Security Services, Trustwave - Tim Choi, VP, Product Marketing, Proofpoint - Nathan Wenzler, Senior Director of Cybersecurity, Moss Adams

View Details

Through their win in the 2016 DARPA Cyber Grand Challenge, ForAllSecure challenged the way application security testing is thought and approached.

Join Dr. David Brumley, CEO and Co-Founder of ForAllSecure, as he shares his observations on shifts in software security trends before and after the DARPA CGC. He'll dissect how these trends came to be and share his predictions how they will impact the software security industry.

Speakers: Frank Downs, Director/SME Cybersecurity Practices, ISACA Dr. David Brumley, CEO & Co-Founder, ForAllSecure

View Details

Abstract: More than 99% of all targeted cyberattacks rely on users to activate them. It is evident that people need to be at the center when building a robust cybersecurity approach in the era of highly sophisticated attacks.

Join BrightTalk for a live interview with Tim Choi, the VP of Product Marketing at Proofpoint, as we discuss the key findings of the threat landscape for 2019 and share practical tips on how CISOs can build a truly people-centric cybersecurity strategy.

View Details

Most IT roles tend to involve long hours and high stress levels, but with breaks between projects. The reality of a cybersecurity professional, however, is that their job is never fully complete. Much like an air traffic controller or a law officer, just one oversight can result in detrimental consequences. The constant pressure of identifying new threats, contending with persistent adversaries around the clock, and assessing how third parties and introduction of new technologies may impact risk is psychologically taxing. Furthermore, it may weaken the enterprise cyber resiliency.

Join this Q&A interview live from Black Hat to learn more about:

  • Burnout in cybersecurity
  • The effect of AI and behavioral analytics on burnout
  • Industry shortage of security expertise and how to address it
  • How to alleviate day-to-day cybersecurity stress

Speakers: Frank Downs, Director/SME Cybersecurity Practices, ISACA Chris Schueler, Senior Vice President of Managed Security Services, Trustwave

View Details

Organizations are evolving beyond the traditional, reactive approach to privacy and data security to thinking proactively. Are we closer to a Privacy-and-Security-by-Design reality?

Join this panel of experts to get the answer to all of your privacy, security and compliance questions. Viewers can learn more about: - Effects of GDPR: One year later - How businesses are preparing for CCPA - Best practices for achieving and maintaining compliance - How to bake privacy and security into your processes - What to expect in the next 12 months

Speakers: Joseph Carson, Chief Security Scientist, Thycotic (Moderator) Debra Farber, Independent Privacy & Security Advisor Nathan Wenzler, Senior Director, Cybersecurity, Moss Adams James Chappell, Co-Founder & Chief Innovation Officer, Digital Shadows

View Details

As the Internet of Things continues to grow, so do the security and privacy risks and vulnerabilities associated with IoT devices on enterprise networks. Organizations worldwide are looking to assess and manage their risk, implement basic cyber hygiene, and improve their security posture. Discover the best strategies for achieving security at every level, including IoT. Join this interactive panel with industry experts to learn more about: - Impact of IoT on enterprise security - How to assess the IoT risk - Most common IoT vulnerabilities and how to address them - Recommendations for improving IoT security

Speakers: - Chris Morales, Head of Security Analytics, Vectra (Moderator) - Jason Soroko, CTO of IoT, Sectigo - Todd Weber, Chief Technology Officer, Optiv - Rudolph Araujo, VP Marketing, Awake Security

View Details

Today's digitally connected businesses require multi-layer defense against rising and more sophisticated web-based threats across websites, devices, infrastructure, and cloud.

Join this interactive 1-2-1 discussion where IoT security expert, Jason Soroko, will share how to deal with IoT security challenges.

Join us, live from Las Vegas as we learn about: - How identity plays a role in IoT security - The role of trust models to enable third party device interoperability - If three is a way to secure a digital identity for devices that do not have a hardware secure element such as a TPM - The latest IoT device security legislations - Determining if IoT connected devices in your operations infrastructure are secure

View Details

IoT security has become a critical priority for enterprise information technology security teams. Devices with sensors and the automated processes that connect them are prime targets for attackers seeking to take advantage of insecure code and low-level vulnerabilities.

Join us for an exclusive interview LIVE from Las Vegas during Black Hat to learn more about the current state and challenges for IoT security, the areas for automation, and how regulations are affecting the future of IoT and IoT security.

Viewers will also learn about: - How is security different for industrial control systems and IoT - How traditional IT security principles differ in the IoT space - IoT security certifications consumers/enterprises should be aware of - How important is continuous penetration testing - Is encrypting IoT data important and how

Broadcast LIVE from Las Vegas during Black Hat 2019

View Details

It’s hard to express the scale of today’s cyber threat landscape, let alone its global impact. We can tell you that there were nearly four million DDoS attacks around the world in the last six months, and that attack frequency grew by 39 percent. Or that the NETSCOUT ASERT team saw 20,000 unique samples per month from just one family of IoT malware. Or even that it can take only five days from the discovery of a new attack vector to the availability of tools for the script-kiddie designed to exploit that vulnerability.

These numbers, while startling, don’t fully convey the impact of that steady drumbeat of new threats. Cybercrime has entered the mainstream of our culture to an unprecedented extent, and it is here to stay.

Join this video interview live from Las Vegas during Black Hat to learn more about: - The big trends in DDoS - New attack vectors found in the past six months and what this means for device and software security - What enterprises can do to protect themselves

View Details

Cybersecurity executives and leaders are not the only cybersecurity experts feeling the pressure to do more with less in the age of the widening cyber skills gap. Cyber security practitioners, already at a disadvantage in the asymmetric battle for the fate of their company’s and customers’ networks, have much to teach the rest of us about how organizations can overcome the shortfall.

Join Danny Slack, Senior Manager for FireEye Managed Defense, as he talks about stories and strategies from the cyber defender’s perspective.

View Details

Digital Transformation, 5G and the Internet of Things are creating wider and deeper opportunities and risks for technology and business organizations to pioneer and navigate. These new boundaries are difficult for organizations to get visibility into and contain threats across them. In a the new world of micro services, serverless computing, software defined infrastructure and Multi-Cloud, old enterprise threat and vulnerability models must transform.

Learn how to achieve consistent and continuous monitoring across your entire infrastructure, as well as within the services and providers you rely on. Getting early, accurate warning into the risks that threaten applications and infrastructure is critical.

Learn why Security and DevOps / Infrastructure teams need to lean into and how to do it at scale.

Speakers: - Rick McElroy, Principal Security Strategist, Carbon Black (Moderator) - Neil Thacker, CISO, Netskope - Hardik Modi, Senior Director, Threat Intelligence, NETSCOUT - Shahrokh Shahidzadeh, CEO, Acceptto

View Details

What do CISOs need to be successful at their job? Discover the challenges CISOs are facing and the ways they are solving them.

Join security experts as they discuss the strategies, processes and technologies CISOs use to protect their organizations in the age of breaches: - What keeps CISOs up at night - Strategies for breach prevention - Strategies for making the most of AI technology and human talent - Coping with analyst fatigue - Threats on the horizon - Recommendations for strengthening security

Speakers: - Deidre Diamond, CEO & Founder, CyberSN - Alyssa Miller, Manager, Information Security Solutions Practice, CDW - Martin Holste, Cloud CTO, FireEye - Mike Weber, Vice President, Coalfire

View Details

As cyber security continues to evolve into a business priority, having conversations at the highest levels about how to address security threats becomes crucial. Hear from CDW’s Alyssa Miller as we discuss why it is so important for the CISO to have a place in the board room and ways the CISO can encourage this interaction and improve their effectiveness in working with the Board of Directors.

We’ll discuss common challenges and new ways to address those challenges ensuring the CISO is positioned to become that trusted advisor for the organization.

Join us as we discuss: - The importance of discussing cyber security strategies at a board level - What challenges prevent cyber security from being a regular topic for the board - Approaches that CISOs may employ to help gain visibility with the board and more!

View Details

Organizations are increasing their spend on cloud security solutions (up to $12.7 billion by 2023). What are the biggest challenges for businesses when it comes to securing the cloud, the solutions they are increasingly turning to, and the best practices needed to improve security overall?

Join this panel of experts to learn more about the current state of cloud and what organizations are doing to secure it. Attendees will learn about:

  • Moving to the multi-cloud
  • What's the deal with Infrastructure-as-a-service (IaaS), software-as-a-service (SaaS), and platform-as-a-service (PaaS)
  • Compliance challenges and how to overcome them
  • Common sense tips for cloud security
  • Recommended tools and solutions
  • Words of wisdom from the experts

Speakers: - Tim Woods, VP Technology Alliances, Firemon - Raef Meeuwisse, ISACA Expert Speaker & author Cybersecurity for Beginners - Nathan Burke, CMO, Axonius - Ed Moyle, General Manager and Chief Content Officer, Prelude Institute

View Details

Passwords are increasingly ineffective and organizations and governments are turning to biometrics for authentication, cyber security and even national security.

Join this panel of experts as they discuss the rise of biometric technology and its impact on privacy and security for users, consumers and organizations.

  • The current state of authentication
  • Are biometrics safer than passwords
  • Top biometric technologies that could kill passwords
  • Privacy implications and the risk of breach
  • Safeguarding biometric data
  • The future of data privacy and security

Speakers: - Dr. Ann Cavoukian, Distinguished Expert-in-Residence, Privacy by Design Centre of Excellence Ryerson University - Dr. Christopher Pierson, CEO & Founder, BLACKCLOAK - Shahrokh Shahidzadeh, CEO at Acceptto

View Details

Insider threats involving stolen or compromised credentials are a persistent issue for organizations worldwide. Whether it's a breach caused by a external vendor accessing an organization's systems, an organization's data being accessed by attackers that have breached a vendor, or an organization's own employees falling victim to phishing or other attacks, the risk of breach is bigger than most organizations realize.

Join this panel of experts to learn about strategies and best practices for dealing with insider threats, breach prevention and improving your organization's overall security posture.

Some of the topics up for discussion include: - What's new in breaches - Addressing the human factor - Insider threats and managing privileged access - Security awareness in the age of cyber attacks - Words of wisdom from the experts - Best practices for improving security

Speakers: Dan Lohrmann, Chief Strategist & Chief Security Officer, Security Mentor Joseph Carson, Chief Security Scientist, Thycotic Rick Holland, CISO, Digital Shadows Shlomi Gian, CEO, CybeReady

View Details

Personal data privacy will be the most prominent issue affecting how businesses gather, store, process, and disclose data in public cloud. Businesses have been inundated with information on what recent privacy laws like GDPR and CCPA require, but many are still trying to figure out how to comply with them on a practical level. Many companies are focusing on data privacy from the legal and security side, which are foundational, but are missing the focus on data.

The good news is that these data privacy regulations compel businesses to get a handle on personal data — how they get it, where they get it from, which systems process it, where it goes internally and externally, etc. In other words, the new norms of data privacy require proactive data management, which enables organizations to extract real business value from their data, improve the customer experience, streamline internal processes, and better understand their customers.

Join this interactive webinar to learn more about: - The latest trends and strategies for securing sensitive data in cloud and the enterprise - How to discover and capture your data inventory - What’s needed to prevent a data breach by securing your critical data and protect your reputation

View Details

For security operations centers (SOCs), threat intelligence can be overwhelming and distracting or it can be a powerful asset that improves SOC efficiency and effectiveness.

Join this presentation to learn how to make the most out of threat intelligence and productively apply it to all the key functions of SOC operations – prevention, detection, and response. Attendees will learn a framework for using threat intelligence in the SOC as well as processes that can be readily incorporated into workflows.

About the Speaker: Roselle Safran is President of Rosint Labs, a cybersecurity consultancy that provides operational and strategic direction to security teams, leaders, and startups.

View Details

Cyber Threat Intelligence (CTI) analysis and investigation is critical to identifying, tracking and efficiently countering threat actors and adversarial techniques. In this webinar, we will dive into the Golden Chickens threat actor family uncovered and show you how to rapidly identify and derive actionable intelligence for this threat actor. In this presentation, you will see:

In depth overview of this emerging threat actor and their primary targets The analytic methodology that led to the uncovering of this threat actor Drive this analysis of complex and multifaceted adversaries Understand the steps that can be taken to identify and mitigate this and other related threat actors

Speakers: Chaz Hobson: Senior Threat Intelligence Analyst, QuoLab Daniel Young: IR Lead and Senior Sales Engineer, QuoLab

View Details

This webinar examines the imperative to introduce greater agility into threat response. There are too many orthodoxies dictating cyber standards, limiting an organisations ability to move quickly once threats to standards and services are identified.

This webinar will provide an insight into new methods for threat response that focus on lean methods to speed responses and deliver an improved security posture for the organisation.

View Details

According to a recent FBI report, cyber crime cost organizations $2.7 billion in 2018. Business email scams that targeted wire transfer payments accounted for almost half of that.

How are businesses protecting against cyber crime? What are the best practices when it comes to cyber crime prevention, breach detection and data security in general?

Join this panel of experts from the industry as they discuss the latest trends in cyber crime and how organizations can get a step ahead of attackers. - New in cyber crime - Is ransomware still a threat? - Biggest priorities when it comes to cyber threat prevention - Tips from the front lines of security - Tools, technologies and policies that make security professionals' lives easier

Speakers: Chris Roberts, Chief Security Strategist, Attivo Networks Nathan Wenzler, Senior Director of Cybersecurity, Moss Adams Ali Golshan, Co-Founder & CTO, StackRox Kevin Sheu, Vice President, Product Marketing, Vectra

View Details

The world of hacking remains a mystery for many. In this webinar, our 6point6 Cyber Lab ethical hackers will demystify hacking by running a live demo and will discuss tips on what you can do protect yourself from hacks.

Speakers: Orson Mosley, Cyber Security Researcher, 6point6 Cyber Lab Naz Markuta, Cyber Security Researcher, 6point6 Cyber Lab

View Details

The average cost of a malware attack on a company is $2.4 million, according to Accenture. Organizations need to ensure they are following cybersecurity best practices in order to mitigate risk.

Join this interactive Q&A panel to learn more about: • What’s new on the threatscape • The latest hacking tools, strategies and methods and how to protect against them • How to implement proactive strategies rather than reactive • Recommendations for improving security and steps to take today

Speakers: Robin Smith, Presales Consultant, Gospel Technology Bob Rudis, Chief Data Scientist, Rapid7 Monique Becenti, Product & Channel Marketing Specialist, SiteLock Trevor Pott, Product Marketing Director, Juniper Networks

View Details

The Gartner Summit 2019 agenda featured five comprehensive programs to cover your security and risk management key priorities and challenges. Digital transformation continues to challenge the conventions of information risk and security management. It requires a coherent digital security program based on a clear vision and strategy. Businesses have been inundated with information on what recent privacy laws like GDPR and CCPA require, but many are still trying to figure out how to comply with them on a practical level.

The new Verizon Data Breach Investigations Report (DBIR) provides perspectives on how Criminals simply shift their focus and adapt their tactics to locate and steal the data they find to be of most value.

Gartner includes data ethics and privacy on their list of the top 10 strategic technology trends of 2019, placing it on the same level as AI-driven development, blockchain, and edge computing. Many companies are focusing on data privacy from the legal and security side, which are foundational, but are missing the focus on data.

The cloud, SaaS applications, and user mobility are powerful enablers of digital transformation, but many IT organizations are grappling with legacy network and security architectures that haven't evolved in decades. In the era of Cloud 3.0, companies are re-imagining business processes from and for the cloud. With these new opportunities comes a new cybersecurity reality for IT leaders in a hybrid, multicloud world. At a minimum, cloud computing breaks into 3 primary layers: SaaS, PaaS and IaaS.

This presentation will explain primary security controls. You’ll learn how to take a strategic approach to risk, improve business and data resilience, build digital trust and implement a new generation of continuously adaptive security strategies. Cloud security remains a top priority. This presentation summarizes the problems, recommended processes, and new product types to address key issues.

View Details

Personal data privacy will be the most prominent issue affecting how businesses gather, store, process, and disclose data in public cloud. Businesses have been inundated with information on what recent privacy laws like GDPR and CCPA require, but many are still trying to figure out how to comply with them on a practical level. Many companies are focusing on data privacy from the legal and security side, which are foundational, but are missing the focus on data.

The good news is that these data privacy regulations compel businesses to get a handle on personal data — how they get it, where they get it from, which systems process it, where it goes internally and externally, etc. In other words, the new norms of data privacy require proactive data management, which enables organizations to extract real business value from their data, improve the customer experience, streamline internal processes, and better understand their customers.

Join this interactive webinar to learn more about: - The latest trends and strategies for securing sensitive data in cloud and the enterprise - How to discover and capture your data inventory - What’s needed to prevent a data breach by securing your critical data and protect your reputation

View Details

As more and more organizations are getting breached, executives are finally paying attention to cybersecurity and data protection. What are the biggest challenges for businesses when it comes to securing the enterprise?

Join this panel of experts to learn more about the current state of breaches, how organizations of all sizes are coping, and what CISOs are prioritizing this year.

Attendees will learn more about: - Who is most at risk of being breached - How to prevent a breach or minimize its impact - How long it takes to detect a breach - Best practices for investigation and remediation - Words of wisdom from the experts

Speakers: - David Morris, Managing Partner, Morris Cybersecurity - Nick Vigier, CxO Advisor, Coalfire - Kalani Enos, Founder & CEO, kenos Technologies

View Details

Trying to navigate the stormy seas of multi-factor authentication (MFA) to find the “killer app” both you and your organization can use to bolster security? In this webinar, we look at:

  • The various factors of authentication
  • Factor vs “steps”
  • Considerations in choosing a factor
  • The various technologies that people are using
  • What seems to be working

Whether you’re pondering Near Field Communication (NFC) ninja tech for your smart phone, or those new biometric doo-dads that verify you based on the smell of your ears (really), we can help you sort out what might work for you and what would be crazy to implement. And as a bonus: this tech will all keep you far safer that your plain old password ever did.

View Details

Most people associate DDoS with large scale volumetric attacks. This is far from reality. Many organisations subjected to DDoS attacks are therefore unlikely to identify them or mitigate them because they simply don’t know what defences work against the huge range of attack vectors out in the wild.

DDoS is much more than experiencing degraded performance; and the operational response is as important as the technology in place to attempt to prevent the attack. Unfortunately most vulnerability management program focus on scanning and penetration testing and simulating genuine DDoS attacks is seldom on the agenda. Resilience against Denial of Service should be as prominent in IT Networks as safety is in the automotive or airline industry.

Have you ever tested your system defences and response capability?

View Details

Cybersecurity affects us all. Malicious actors are constantly scanning vulnerable systems of companies across all sectors, and healthcare organizations are a particularly attractive target. They are often responsible for the safety and security of confidential patient records, which is valuable information for malicious hackers. While the use of innovative technology in healthcare is on the rise, the industry faces tremendous risks from cyber threats due to this growing attack surface and the prevalence of dated medical hardware and software across the supply chain. This session will discuss the IoT threats facing the healthcare sector, as well as strategies for managing and mitigating threats. 

Join this webinar to learn about: - Why the healthcare industry is a highly-targeted industry for cyber attacks - What Internet of Things (IoT) technology is and how it’s being leveraged for crime - Why legacy medical hardware and software exacerbates IoT-based risks - How to manage and mitigate IoT risk in the healthcare sector

View Details

The Internet of Things is expected to grow to 30 billion devices within the next two years. This means more security and privacy risks that organizations will need to address. Learn how businesses are dealing with their IoT risk, the best practices cybersecurity professionals are recommending, and get the answer to your most pressing IoT security questions.

Join this interactive panel to learn more about: - How the rise of IoT is impacting your organization's security - Cybersecurity threats and most common IoT vulnerabilities - Assessing your organization's IoT risk - Best practices for minimizing your cyber risk - Words of wisdom: Steps to better security and what you can do today

With: Michael Goldgof, Senior Director, Product Marketing, Barracuda Kalani Enos Founder & CEO KEnos Technologies LLC Nathan Wenzler, Senior Director of Cybersecurity, Moss Adams

View Details

Internet of Things (IoT) products proliferate the market today. They manifest in different forms – from a pacemaker inside a human body, to an oil and gas rig monitoring device in the remotest locations on the planet. IoT products are usually made up of small hardware devices (gateways and nodes) deployed in the field, supported by much larger software stack in the form of mobile and cloud-hosted applications that complete the product ecosystem picture.

In our presentation, we discuss threats against industrial and consumer IoT products. We demonstrate how it is possible to use cheap, publicly available hardware and open source software tools to break into Zigbee-style Wireless Sensor Networks to compromise the confidentiality and integrity of IIoT platforms (think, turning life-saving vaccines into lethal chemicals!). On the consumer IoT front, we show - with simple Android applications, how we are able to exploit vulnerabilities in Bluetooth and BLE flows. We conclude with an analysis of why such vulnerabilities occur, and how we can reform existing SDLC practices to make them relevant for next-generation technologies.

View Details

This keynote is designed to address the seemingly overwhelming collection of security concerns with which today’s leaders contend:

  • Do you struggle with designing and implementing a security program that effectively achieves the goals outlined in your security mission?
  • Are you interested in better understanding how hackers think, how they operate, and how to defend accordingly?
  • Do you struggle to know where to invest resources in order to best deliver security to your organization?
  • Are you concerned about your organization suffering a security incident under your watch?
  • Are you seeking more certainty that by investing resources into a given security approach, that investment will deliver the outcomes you seek?
  • Do you have the appetite and capacity for change?

If any of this describes you, this is the keynote for you! An engaging blend of research-based issue analysis combined with storytelling, this keynote seeks to empower today’s security leaders, teaching attendees how to:

  • Implement a 3-phase action plan, based on years of practical experience in security research and security consulting, designed to help equip leaders to deal with modern attackers.
  • Define and implement a threat model.
  • Differentiate between assessment methods.
  • Understand level of attacker intensity.
  • Challenge conventional wisdom

View Details

As IoT devices continue to evolve in different ways, connecting (even more) the physical with the cyber world, the adversaries continue to evolve methods for compromising them for different purposes.

Based on their nature and the tasks they need to perform, the common general characteristics of IoT devices are:

  • They are very minimalistic,
  • They have limited resources,
  • Most of them are battery-based
  • They interact with other devices
  • They are connected to the cloud for different reasons
  • They have special RF protocols

IoT use cases (as listed below) have a lot of security challenges that haven’t been addresses properly because of the devices’ constrains, the limited budget the contractors have (cause the solutions have to be “cost-effective”) and the priority is always functionality, thus sacrificing security, therefore exposing our society to massive risks.

  • Smart City
  • Smart Manufacturing
  • Autonomous Vehicles
  • Critical Infrastructures

This is why we need to work on detecting threats in a structured way, taking into account that once attackers access to the IoT network, they won’t have much limitations moving around that network and even jumping to other networks, including IT network. When adversaries compromise IT networks, they are affecting business but when they compromise IoT devices, they can compromise our lives.

In this webinar I’m going to propose a methodology that can be applied to enhance IoT network security by mitigating IoT cyber risks using MITRE ATT&CK Framework..

View Details

Welcome to the world of IoT (Internet of Things) as more and more devices get connected online. With weak or almost no security these devices can easily become a victim, be turned into a BOT which can then be controlled and used to participate in a DDOS (Distributed Denial of Service) attack like the one that has targeted Dyn bringing popular websites like Netflix, Twitter, Amazon, AirBnb, CNN and the New York Times to their knees and offline. This session walks you through the reality check on the risks and threats that IoT devices introduce to the business and what you can do to reduce the risks.

  • What are the biggest risks from IoT devices?
  • What are the biggest threats from IoT devices?
  • Best Practices in reducing the risks
  • Future of IoT Security

View Details

Risk agnostic approaches to adopting emerging technologies are eating business for breakfast, IoT too is garnering its fair share! Unlike most other technologies, IoT adds a new dimension of less understood cyber-physical risks.

This sessions seeks to scratch the surface on strategies for assessing business technology risks in adopting IoT.

View Details

As the world becomes increasingly connected, we have become more vulnerable to IoT threats and attacks. Having a comprehensive and strong security strategy in place is vital to organisational success.

Join this exclusive panel of industry experts as they discuss: - IoT Security Maturity Model - Trends in cyber-attacks and breaches affecting the IoT - How to proactively prevent breaches and attacks - New in IoT Security - Security Strategy recommendations for CISOs

Panelist confirmed: - Deral Heiland, IoT Research Lead, Rapid7 - Sandy Carielli, Director of Security Technologies, Entrust Datacard

View Details

This session will explain how the world’s leading mobile operators are using the GSMA’s IoT security guidelines and assessment process to deliver trusted and robust IoT products and services to their partners and customers.

The presentation will explain the commercial benefits and long-term value that was realised by following industry best practices, and how IoT companies can overcome security challenges themselves to implement new processes and address IoT security concerns.

View Details

Bug bounty hunter and cool nerd, Jasmine Jackson will kick off our newest webinar series #SheSpeaksTech with a short talk on " Thrill of the Hunt: My Leap into Bug Bounties.

Join this webinar series for a quick starter talk with women in cybersecurity. Each webinar will explore a new tech topic by a newbie speaker. She will deliver the first 20 minutes of her 1 hour talk and open to feedback on topic, delivery and tips. Check out (https://womenscyberjutsu.org/page/SHESPEAKSTECH) for more on SheSpeakTech or to register for your 30 minutes to shine.

View Details

Tomorrow's businesses need a simpler and more scalable way to increase the resiliency of global application infrastructure, without slowing innovation, today.

Join this interactive 1-2-1 discussion where EMEA Chief Technology Officer, Paul Farrington (CISSP, MBCS) will share how leading businesses are;

  • Improving the level of security awareness and addressing the skills deficit
  • Enabling developers to fix flaws and prevent new ones
  • Prioritising and triaging the most exploitable flaws
  • Automating application security
  • Providing software development leaders with really useful security metrics
  • Incentivising secure development as part of their culture

This session will show you how architects and developers are making smarter choices in designing secure software. You will also learn how to report success, and investment justification, to the board whilst setting realistic expectations throughout the software development lifecycle and not just at the destination.

View Details

How can enterprises shift from a reactive approach to privacy and data security to being proactive and closer to privacy-and-security-by-design? Join this panel of experts to get the answer to all of your privacy, security and compliance questions.

Viewers can learn more about: - Effect of GDPR: One year later - How are enterprises instituting changes to achieve and maintain compliance - Challenges to achieving compliance in an IoT world - How to bake privacy and security into your processes - Best practices for data protection and privacy from the ground up

Panellists Bill Mew, CEO,The Crisis Team Ilias Chantzos, Senior Director, Government Affairs, Symantec

Moderated by Allan Boardman, CGEIT Certification Committee Member, ISACA

View Details

With today's enterprises leveraging around 1000 applications and multiple clouds, application security is becoming a key area of focus. Application security testing is being integrated into the DevOps process early on, while automation, speed and coverage and becoming critical to the success of DevSecOps programs.

Join this interactive panel of industry experts to learn more about: - Why application security is critical - Key principles for building application security into DevOps - Best practices for leveraging automation - Speed vs Security: Where do you draw the line? - Recommendations for improving security in 2019

Panellists Paul Farrington, EMEA CTO, Veracode Keith Batterham, CTO - CISO - DevSecOps Evangelist Moshe Lerner, SVP Product Strategy & Corporate Development, Checkmarx

Moderated by Yotam Gutman, Founder & Community Manager, Cybersecurity Marketing Community

View Details

The increased complexity of software and the need to keep up with fast-paced release cycles create new types of risk in the form of Software Exposure.

Join this interactive 1-2-1 discussion where product strategist and industry expert, Moshe Lerner will share insights including;

  • Why you should consider software security as non-functional issue?
  • What are the key challenges for managing software security in general and in DevOps environments?
  • Best of breed vs Best of suite – Which is the right approach?
  • The difference between interactive application security testing (IAST) and dynamic application security testing (DAST)? Can IAST replace DAST?
  • How to manage and reduce application security risk at scale

Moderated by Yotam Gutman, Founder & Community Manager, Cybersecurity Marketing Community

View Details

Join this interactive 1-2-1 discussion where Field Chief Technology Officer, Nicolas Groh will share;

  • Challenges businesses are facing today with regards to security and compliance in the cloud
  • Improvements that can be made today to ransomware prevention, detection, and recovery
  • Long-term security and compliance strategies
  • Quantifiable outcomes businesses can expect to see with a unified system of records

Moderated by Paige Bidgood, EMEA Community Lead - IT Security & GRC, BrightTALK

View Details

Cloud security is a key challenge for today's data-driven businesses.

Join this interactive 1-2-1 discussion where Principal Security Analyst, Carl Leonard will share insights on;

  • What are the top cyber threats and trends to look out for in 2019?
  • Why are businesses continuing to suffer data breaches?
  • How are businesses securing themselves as they embrace digital transformation?
  • What is secure SD-WAN? Why is it increasingly important to businesses with distributed office locations?
  • What are the most important security solutions for businesses wishing to safely adopt cloud services?

Moderated by Raef Meeuwisse, ISACA Expert Speaker and co-author of "How to Hack a Human: Cybersecurity for the Mind"

View Details

External and internal threats continue to pose a challenge for security professionals worldwide. How are businesses preparing against attacks like phishing, ransomware, and social engineering?

Join security experts from the industry to learn more about: - The most prevailing cyber threats businesses face in 2019 - Lessons from cyber attacks and strategies for protecting against them - Solutions for faster breach detection and response - Why network visibility is key - Recommendations for improving enterprise security

Panellists Richard Agnew, VP EMEA, Code42 Carl Leonard, Principal Security Analyst, Forcepoint John Scott, Head of Security Education, Bank of England Adenike Cosgrove, Cybersecurity Strategist, Proofpoint

Moderated by Raef Meeuwisse, ISACA Expert Speaker and co-author of "How to Hack a Human: Cybersecurity for the Mind"

View Details

Today's CISO faces a myriad of challenges when it comes to securing the enterprise. From budgetary concerns and vendor confusion to dealing with the chronic lack of cyber talent, to addressing the disappearing security perimeter, CISOs are looking for ways to automate security operations and leverage AI to do more with existing teams and fewer tools.

Join security experts across the industry for an interactive discussion on: - What keeps CISOs up at night - Strategies for breach prevention - Strategies for making the most of AI technology and human talent - Coping with analyst fatigue - Threats on the horizon - Recommendations for strengthening security

Panellists David Boda, CISO, Camelot Group Darren Thomson, CTO - EMEA, Symantec George Patsis, CEO, Obrela Security Industries Martin Mackay, Senior Vice President - EMEA, Proofpoint

Moderated by Yotam Gutman, Founder & Community Manager, Cybersecurity Marketing Community

View Details

Watch the exclusive interactive interview with ISACA, Certified in the Governance of Enterprise IT (CGEIT) Certification Committee Member, Allan Boardman at Infosecurity Europe 2019.

Questions asked;

  • I saw that ISACA released the 2019 State of Cybersecurity research – The report states that attack vectors remain largely the same, but that cybercrime may be vastly underreported. Why is this?

  • The ISACA research also states that only 1 in 3 cybersecurity leaders have high levels of confidence in their cybersecurity team’s ability to detect and respond to cyberthreats. The highest levels of confidence came from teams that report directly to the CISO, and the lowest levels came from teams that report to the CIO. What do you think this tells us about these different roles in organizations - what reporting structures are better, and what could be done to boost awareness and confidence in the cyber team?

  • Let’s talk about what’s happening in the threat landscape. What are the biggest tech challenges keeping business leaders up at night?

  • And similarly, what are the biggest business challenges and threats keeping leaders up at night?

  • What advice do you have for new professionals? What are the most important skills they should acquire for career success?

ISACA Certifications- Global Prestige, Global Influence

ISACA’s globally respected certification program has been a central driver of the organization’s impact over ISACA’s 50-year history. Click on the attachments tab below to view an infographic that explores the prestige and influence of ISACA's respected certification program, highlighting ISACA certification-holders who have reached prominent positions in the industry.

View Details

Join this interactive 1-2-1 discussion where information security expert, George Patsis will share how to;

  • Align cybersecurity function with organisational and business strategy
  • Meet regulatory and compliance requirements
  • Deal with breaches in an ever-changing technology landscape
  • Create valuable reports

During this session, you will learn how to identify, predict and prevent cyber threats, in real time.

Moderated by Yotam Gutman, Founder & Community Manager, Cybersecurity Marketing Community

View Details

Watch this interactive interview with Solutions Marketing Director, Seth Goldhammer at Infosecurity Europe 2019.

LogRhythm is a world leader in NextGen SIEM, empowering organizations on six continents to successfully reduce risk by rapidly detecting, responding to and neutralizing damaging cyberthreats. The LogRhythm platform combines user and entity behavior analytics (UEBA), network traffic and behavior analytics (NTBA) and security automation & orchestration (SAO) in a single end-to-end solution. LogRhythm’s Threat Lifecycle Management (TLM) framework serves as the foundation for the AI-enabled Security Operations Center (SOC), helping customers measurably secure their cloud, physical and virtual infrastructures for both IT and OT environments. Built for security professionals by security professionals, the LogRhythm platform has won many accolades, including being positioned as a Leader in Gartner’s SIEM Magic Quadrant.

View Details

More than 99% of all targeted cyberattacks rely on users to activate them. It is evident that people need to be at the centre when building a robust cybersecurity strategy in the era of highly sophisticated attacks.

Join our EVP, EMEA, Martin MacKay at this live interview as he discusses key findings from the threat landscape and gives some practical tips on how CISOs can build a truly people-centric security strategy.

We'll discuss: - Today's most notorious cyber threats and trends. - How the attackers are changing tactics to target specific people in your organisation and how to protect against these threats. - CISO's role in changing company culture towards security risks and awareness and some tips on changing user behaviour to reduce risk.

View Details

Effectively protecting critical data in the cloud is a key challenge for today's data-driven businesses.

Join this interactive 1-2-1 discussion where Cloud Access Security Broker (CASB), Dave Barnett will share insights on;

  • Why and how today organisations are protecting data in the cloud.
  • What are the main risks inherent in the adoption of cloud services?
  • Where the key challenges are in protecting data in the Cloud?
  • What to look for when selecting cloud security for your organisation

Moderated by Alex Hilton, Chief Executive, Cloud Industry Forum

View Details

Join this interactive 1-2-1 discussion where network security and IP networking solutions expert, Patrick Grillo will share how to deal with security challenges as networks evolve including cloud-based resources and SD-WAN.

Key themes to be explored include;

  • Why security should never be treated as an afterthought
  • The impact of new technologies/techniques on existing security infrastructure/practice
  • How to develop/maintain a consistent security practice beyond technology
  • How to get C-suite commitment and build the right organizational structure

This session showcases the need for security continuity by connecting a number of disparate concepts, for example how the Cloud services and SD-WAN are related.

Moderated by Yotam Gutman, Founder & Community Manager, Cybersecurity Marketing Community

View Details

The ever-growing Internet of Things continues to pose security and privacy threats. How are businesses managing the risks associated with IoT devices on their networks? What are the best strategies for achieving basic security and cyber hygiene?

Join this interactive panel with IoT and security experts to learn more about: - Impact of IoT on enterprise security - How to assess the IoT risk - Most common IoT vulnerabilities and how to address them - Recommendations for improving IoT security

Panellists Jason Soroko, CTO of IoT, Sectigo Andrew Hollister, Chief Architect & Product Manager, LogRhythm Wallace Sann, VP Global Systems Engineering, Forescout Technologies Nigel Stanley, CTO - Global OT & Industrial Cyber Security CoE, TÜV Rheinland Group

Moderated by Yotam Gutman, Founder & Community Manager, Cybersecurity Marketing Community

View Details

The cloud strategy of today's enterprise spans across multiple clouds and hundreds of applications. Point security solutions no longer work, so enterprises are turning toward a more orchestrated approach to achieving security and compliance in the cloud.

Join cloud and security leaders in an interactive discussion to learn about: - Key security and compliance challenges associated with a multi-cloud strategy - Recommendations for managing and automating security across multiple clouds and applications - The future of cloud - Improving enterprise security in an ever-changing threat landscape

Panellists James Hughes, Field CTO, Rubrik Dave Barnett, Head of CASB, Forcepoint EMEA Patrick Grillo, Senior Director - Security Solutions, Fortinet

Moderated by Alex Hilton, Chief Executive, Cloud Industry Forum

View Details

Today's digitally connected businesses require multi-layer defence against rising and more sophisticated web-based threats across websites, devices, infrastructure, and cloud.

Join this interactive 1-2-1 discussion where IoT security expert, Jason Soroko, will share how to deal with IoT security challenges.

  • How to determine if IoT connected devices in your operations infrastructure are secure
  • What is the difference between symmetric tokens, PKI based certificates and device identities?
  • What is the role of trust models to enable third-party device interoperability?
  • What are some methods to provision a device with a x509 certificate?
  • How to secure a digital identity for devices that do not have a hardware secure element such as a TPM?

Moderated by Yotam Gutman, Founder & Community Manager, Cybersecurity Marketing Community

View Details

Any merger or acquisition poses daunting challenges to IT leaders. Not only are they tasked with integrating people, processes and technology in the shortest possible time frame, they must also remain vigilant about addressing the added cybersecurity risks.

Join this interactive 1-2-1 discussion where systems engineering expert, Wallace Sann will share how to minimise the cybersecurity risk factor in M&A including;

Who are the key decision makers in the M&A process and what are the different/new challenges they’re facing? What has historically been the risk focus for acquiring companies, and how is that focus changing? How can companies as a whole minimize cyber risk and protect themselves during the M&A process? Are there any opportunities for IT teams to reduce cyber risk during an M&A? What does Forescout recommend companies do in order to enhance their cybersecurity posture when preparing for an acquisition? With the explosion of IoT devices across industries, should there be more concern around connected devices during an acquisition?

View Details

The Financial Services industry has a big target on its back when it comes to attacks by cyber criminals. How can financial institutions keep precious customer data safe whilst utilising technology to equip themselves with the tools to prevent fraud and financial crime?

Join this panel to hear:

  • Lessons learned from recent breaches and hacks
  • AI-powered strategies to protect your financial institution
  • The unique security challenges of incumbent organisations vs. FinTechs
  • Best practices to fight fraud and financial crime

Joshua Bower-Saul, CEO, Cybertonica Andy Ramsden, Global Solution Sales Lead – Mobile Authentication, G+D Mobile Security GmbH Nicolas Muhadri, CEO, Stream Mind Ruth Wandhöfer, Partner, Gauss Ventures

View Details

A discussion of how various facial detection and recognition systems operate, the privacy risks associated with different levels of identification, and the impact under GDPR. Facial recognition technology can help users organize and label photos, improve online services for visually impaired users, and help stores and stadiums better serve customers. At the same time, the technology often involves the collection and use of sensitive biometric data, requiring careful assessment of the data protection issues raised. Understanding the technology and building trust are necessary to maximize the benefits and minimize the risks.

Equally relevant is the need to expand stakeholders’ awareness and understanding of the many types of facial scanning systems, as well as the impact of accuracy differences among the many systems available today.

It is important to understand the distinctions between facial detection systems (which, when properly designed neither create nor implicate any Personally Identifiable Information) with full-scale facial identification programs (matching a person’s image to a database in order to identify the individual to a store clerk or stadium employee who otherwise wouldn’t recognize them).

The consumer-facing applications of facial recognition technology continue to evolve, and the technology will certainly be used in new ways in the future, and the legislative environment under GDPR must consider how such uses should be implemented to protect consumer privacy rights.

View Details

One year since GDPR was introduced, many of us are wondering what the future will hold. We recently hosted an in-person event with well-known legal counsel Tim Hickman, Partner at White & Case as he walked us through how it has affected the way businesses go-to-market.

With his background and extensive knowledge on the topic, Tim discussed what you can do next to minimize risks and ensure business growth, current privacy regulations and more.

View Details

This year has seen an eruption of new data protection bills and laws, as many countries follow Europe's lead in enacting their first, or stronger, data protection laws. For many global organisations a fracturing of data protection law poses a costly compliance burden and many would like to enforce one standard across their operations. But to what extent are these countries responses similar? Is there a new global standard, and if so is it the GDPR? To what extent do these changes overlap, and what trends not seen in the GDPR are emerging too?

This talk will explore how the world of data protection has changed since the GDPR was passed last year. In particular it will look at how the US policy landscape is changing and the extent to which GDPR concepts are coming through. The US is undergoing enormous change, with the CCPA coming into effect next year, various proposed federal bills, amendments to sector bills, and 16 state level bills all being debated. The talk will highlight some similarities between these various bills and amendments, as well as some of the areas of divergence. It will also draw on other changes, such as the emergence of data localisation laws in China, Indonesia, and India, and some of the laws closer to the GDPR such as Brazil.

View Details

On the anniversary of GDPR, we will take a look at the current state of privacy and security, and dive into how organizations are addressing these challenges.

Viewers will learn more about: - Effects of GDPR: One year later - Is GDPR just a checkbox for businesses - Are we closer to a Privacy-and-Security-by-Design reality - Other regulation on the horizon - How is CCPA different from GDPR - Best practices for achieving and maintaining compliance

Join this panel of experts to get the answer to all of your privacy, security and compliance questions.

Speakers: - Elena Elkina, Partner at Aleada Consulting (Moderator) - Reuben Thompson, VP of Technology at Gospel Technology - Matt Walmsley, Head of EMEA Marketing, Vectra Networks - James Chappell, Founder and Chief Innovation Officer, Digital Shadows

View Details

The world is waking up to the fact that you need both strong security systems in place and privacy technology to ensure comprehensive data protection.

To achieve this goal, CTOs, DPOs and CISOs have to work in unison. There is no privacy without security. But security alone is not enough to protect your customer’s sensitive data. Strong privacy protection helps to unlock data for new purposes and makes the job of the security team a lot easier.

Find out how the two work hand in hand with Privitar’s Senior Privacy Engineer Lee Bonham.

Join this session to learn:

  • How robust security controls are not enough to protect your data fully

  • How the focus is shifting from the perimeter to implementing privacy controls on the data itself

  • How privacy technologies and access controls work hand-in-hand to ensure your data is protected

View Details

Data Protection might be a serious legal and business requirement, but that’s no reason not to have some fun doing it. Join Rowenna Fielding as she gives advice on protecting individuals privacy and establishing an acceptable risk position, using illustrations from the British comedy group ‘Monty Python’s Flying Circus.

View Details

Since the rollout of The General Data Protection Regulation (GDPR) in 2018, companies worldwide have had to implement new policies and procedures to protect data. Join leading compliances and security experts as they discuss why data protection is at the heart of GDPR compliance.

Join this interactive Q&A panel to learn more about: - What GDPR means for data management - GDPR requirements around data collection and governance - Best Practices for achieving compliance - Recommendations for improving Data Management and ensuring Data Protection

Speakers: - Melanie Turek, Fellow & Vice President, Frost & Sullivan (Moderator) - Christopher Pierson, CEO & Founder, BLACKCLOAK - Michelle Drolet, CEO & Co-Founder, Towerwall - Ilias Chantzos, Senior Director, Global Government Affairs & Cybersecurity, Symantec

View Details

One year after GDPR, the presentation will explore whether the provisions introduced are sufficient to deal with the challenges of big data and algorithms. Ivana will present a clear roadmap for organisations deploying AI covering governance, privacy and ethics harms and algorithmic impact assessments.

View Details

In the panic leading up to May 25th 2018, many organisations did one of three things:

  1. Hired a lawyer first;
  2. Hired a data security expert first, or
  3. Absolutely nothing.

All of these approaches are wrong, and regardless of the size/type of your organisation, the first steps were exactly the same; Go find your data.

In this presentation we will simplify the process of achieving GDPR compliance so that anyone can get started.

View Details

Unless your organization handled classified information, it was once generally considered “good enough" to protect email with little more than a basic password. When spam floods hit, we all collectively understood that we needed to do a bit more in order to protect the sanity of email traffic (not to mention the sanity of our users). Fast-forward to the current threatscape, where protecting business email is mission critical, but the tools and techniques are tricky to understand, deploy and support with adequate staff training. There is a lot more we can and should be doing, but it can be challenging to navigate the security maze.

In this webinar we’ll discuss a variety of techniques and technologies you can use to improve your email security to meet new threats:

  • Filtering unwanted/malicious email traffic
  • Why you need encryption on both the message- and network-level
  • Using more robust authentication options than just a password
  • How you can use authorization to decrease spoofed messages
  • Decreasing the risk of damage from software vulnerabilities
  • Creating a culture of security to help identify and thwart phishing

Many of these strategies can be useful for protecting your own personal email account or traffic. But as an administrator of a company email infrastructure, there are quite a few other things you can do to meaningfully increase security, which don’t require you to shell out big bucks on fancy new products.

View Details

The 2019 Verizon Data Breach Investigations Report, now in its twelfth year, is an industry benchmark for information on cybersecurity threats and vulnerabilities. Each year this report looks at tens of thousands of security incidents and confirmed breaches. Join our all-women panel of experts for the first look at some of the key findings of the 2019 report to understand and what it all means.

View Details

Find out what's trending in BrightTALK's IT Security community and the challenges keeping security professionals up at night.

Join Wesley Simpson, COO of (ISC)², Dr. Christopher Pierson, Founder & CEO of BLACKCLOAK and Marija Atanasova, Sr. Content Strategist from BrightTALK for an interactive Q&A session to learn more about: - Topic trends & key insights - What security professionals care about - Events in the community - What to expect in Q2 2019 and beyond

View Details

With hundreds of different requirements, the various Payment Card Industry (PCI) standards can be overwhelming. While the PCI Security Standards Council has provided lots of answers, the devil is often in the details. Our panelists are some of the top PCI QSA’s in the country, with decades of combined PCI and card processing experiences. They’ve seen it all: the good, bad and ugly; and lived to tell the tale.

Join Ben Rothke, David Mundhenk, Arthur Cooper, and Jeff Hall for an interactive Q&A session, and get answers to your most vexing PCI questions. No PCI question is out of bounds.

Speakers: - Ben Rothke, Senior Security Consultant at Nettitude - David Mundhenk, Senior Security Consultant at Herjavec Group - Jeff Hall, Senior Consultant at Wesbey Associates - Arthur Cooper "Coop", Senior Security Consultant at NuArx

View Details

Tune into this session to learn how to determine if you have the right people with the sharpest skills defending your organization through the use of a Cyber Training Range.

Learn what are Persistent Cyber Training Range Environments, the benefits and value of a Cyber Training Range and how they help you answer the question ARE WE READY TO DEFEND AGAINST THE NEXT ATTACK?".

View Details

Has hybrid cloud reached a tipping point? According to research from the Enterprise Strategy Group (ESG), IT organizations today are struggling to strike the right balance between public cloud and their on-premises infrastructure. In this SNIA webcast, ESG senior analyst, Scott Sinclair, will share research on current cloud trends, covering:

•Key drivers behind IT complexity •IT spending priorities •Multi-cloud & hybrid cloud adoption drivers •When businesses are moving workloads from the cloud back on-premises •Top security and cost challenges •Future cloud projections

The research will be followed by a panel discussion with Scott Sinclair and SNIA cloud experts Alex McDonald, Michelle Tidwell, Mike Jochimsen and Eric Lakin.

View Details

In this presentation we will give an overview of the current state of the power of an endpoint in the modern enterprise; and how modern advancements make the need for adversarial testing even more critical.

Other topics to be covered: - New/modern consumer products - Increases in privacy & increased exfiltration options - Employee Trust & BYOD - State of endpoint monitoring - Controls Validation vs. Adversarial Testing

View Details

While cyber attacks come from all directions, the majority of them originate on endpoints. In this webinar UJ Desai, Director of Product Management at Bitdefender will discuss why organizations are still struggling with endpoint security, and will explore the five critical elements of endpoint security that will allow organizations to effectively defend endpoints from both common and advanced cyber attacks.

View Details

Join security experts and practitioners for an interactive discussion on how to better secure the enterprise in 2019: - Top threats on the horizon and what's at risk - Cyber defenses and your employees - Basic cyber safety recommendations to protect against social engineering, phishing and email cyber attacks - Use cases and examples - Actions to take today to protect your employees and enterprise from cyber criminals - What to expect in 2019

Speakers: - John Bambenek, VP Security Research & Intelligence, ThreatSTOP - JP Bourget, Founder & Chief Security Officer, Syncurity - Jan Liband, CMO, SlashNext

View Details

The largest threat of organisational breach occurs at the Endpoint level. Hacks, phishing, malware and untrained end users are a constant risk that need safeguards and monitoring to protect individuals and businesses with strong IT security. Small changes to your endpoints can drastically improve your protection. However, when you manage one or more businesses and need to implement and maintain these changes across multiple machines or environments, different complications will arise.

Join Webroot’s Threat expert as he discusses topics such as:

· Malware Miners Information Stealers Ransomware · End user education · Best policies and settings for your Endpoints · Endpoint monitoring

View Details

Globalization and division of labor has allowed multi-national corporations and businesses to focus on their core capabilities while outsourcing all various ranges activities form legal services, IT services, marketing, etc... these trends will continue to gain speed as global markets become much more efficient.

Proliferation of suppliers has also rapidly increased emerging threats such as privacy, data sharing and cyber risks. The key takeaway for audience in this presentation will be over all discussion of dimensions of supplier risks and how to holistically develop a proper comprehensive supplier report card that includes financial and cyber data.

View Details

Measuring the effectiveness of a security program can be a challenge for most organizations. After all, when you do everything right, nothing happens. No email outages, no denial of services impacts and no data breaches. Measuring nothing doesn’t really tell you much, and it certainly doesn’t give you insight into where you’re still vulnerable and could be attacked by a malicious actor. Vulnerability Management (VM) tools have been a mainstay tool for any security program, and they generate a wealth of information about what assets are most at risk from outside threats, but the information isn’t always put to best use by most organizations.

In this session, we’ll look at the common metrics mistakes most organizations make with their VM efforts, as well as more relevant and actionable metrics that will help you get a better understanding of your security posture against today’s threat landscape.

· Learn how vulnerability information is critical to boosting good threat intelligence against common attack chains · Identify metrics that are commonly used by nearly every organization, but don’t deliver any real value to your organization · Discover ways to frame vulnerability data into meaningful, actionable metrics that give a more true sense of the risks to your assets · Understand ways to improve your VM program to build more relevance into your threat intelligence efforts

View Details

User and Entity Behavioral Analytics (UEBA), when properly implemented, can be incredibly valuable: it can provide security teams with a new lens through which to detect, investigate, and respond to evolving security threats. However, there is a lot of hype in the world of AI, and not enough real use cases or concrete recommendations. This webinar aims to help correct this, with real world use cases and learnings from the past five years of deployments at Interset.

In this presentation, attendees will:

  • View real-world case studies showcasing objectives and results from deploying UEBA
  • Understand the role of human expertise and use cases to drive and quantify model development
  • Review the most effective data sets for UEBA
  • Learn about the analytical approach that helps effectively produce results and reduce noise in your UEBA system

View Details

Global cybersecurity analyst Liviu Arsene will discuss how advanced threat detection and visibility into the overall cybersecurity posture of an organization can help prevent data breaches, by placing under the scope some of the most recent and notorious data breaches and cyberattacks.

View Details

As cyber attacks become increasingly common, it is vital for organisations to be armed with the most effective tools and knowledge to prevent, detect and respond to cyber threats.

Join this interactive Q&A panel with top security experts across the ecosystem to learn more about:

  • Trends in Advanced Threat Detection & Vulnerability Management
  • How to use analytics to fight against cyber attacks – patching, detection and response
  • What are the common mistakes made when it comes to Advanced Threat Detection implementation
  • Best practices and recommendations for improving your security posture

Panel moderated by: Michele Drolet, CEO, Towerwall

Panelists: Wade Woolwine, Director of Managed Services, Rapid7 Ajay Uggirala, Sr. Manager, Product Marketing, Juniper Networks O'Shea Bowens, CEO & Founder, Null Hat Security Paul Crichard, Security CTO, BT Global Services

View Details

This webinar will introduce the latest and larger security breaches around the world, and will show the attendees several ways and tips to stay safe and keep the most piece of information secure, their private information.

Also they will find what to do in case of been victim from a security or data breach.

View Details

Often the building blocks for a CTI program can be laid without the need for teams to spend a lot of money. In this session, we'll look at how Free and Open Source Software (FOSS) technologies and OSINT (Open Source Intelligence) can be leveraged to bootstrap a CTI program.

The primary benefits of leveraging FOSS tools are (a) Agility - rapidly test tools to identify what works best for the organisation, (b) Identification of potential process gaps, (c) Implementation of "interactions" between key teams and (d) Being part of the broader FOSS/CTI community.

View Details

What is cyber threat intelligence, and how can organizations leverage it to identify threats and potential malicious activity in advance? Discover the best ways organizations can arm themselves with actionable threat intelligence to block cyber attacks or mitigate their impact.

Join this panel of experts to learn more about: - Cyber threat intelligence: What it is and how you can use it - What's new in phishing, banking trojans, Mirai, ransomware - Emerging threats and what to do about them - Best practices for a more secure enterprise

Panel moderated by: Griff James, Director, Damrod Analysis Ltd. Panelists: Michelle Drolet, CEO, Towerwall Nathan Wenzler, Snr. Director, Moss Adams Chris Morales, Head of Security Analytics, Vectra Networks

View Details

Cloud application development is accelerating and diversifying where many organizations have virtual machines, containers, and now serverless applications running in the cloud, transforming code into infrastructure. Microservices make a lot of sense for scale and development agility, but if everything is talking to everything else via APIs, it’s likely that there are many (and I mean many) application vulnerabilities. Additionally, API security is new, so processes are likely immature, and API security sits somewhere between application developers, DevOps, and cybersecurity, leading to organizational and skills challenges. We will organize this chaos from RSAC 2019 and discuss Security in the new API Ecosystem.

Join this interactive webinar to learn more about: - What security people should talk about instead - The Human Factor - Advancements in Machine Learning and AI - Security in app development and the API economy - News in quantum computing and multiparty computing - Trends in innovation and cloud security - New standards and regulations

We will also discuss: - How IT Audit can be automated to meet new requirements from for Agile Development and cloud - How IT Audit can learn more about new controls and technologies - How IT Audit can be involved early in the DevOps planning phase - How Artificial Intelligence can be used in IT audits to expand beyond sampling

View Details

Driven by demands for increased speed, automation and efficiency, organisations are about to face a period of significant technological upheaval. Digitisation promises much, and development of the next generation of technologies will bring significant benefits to business and society. To survive in the digital world organisations will have to adapt. To thrive, they will need to evolve. Exploiting digital interconnectivity, competing in the digital arena while understanding the implications of a digital cold war will all become business as usual challenges for industry over the coming months and years.

In this webinar, Steve Durbin, Managing Director, ISF will identify the key changes to the digital landscape over the next two years, focusing on emerging threats and means of mitigating their impact.

View Details

Find out what's trending in BrightTALK's IT Security community and the challenges keeping security professionals up at night.

Join Wesley Simpson, COO of (ISC)², Dr. Christopher Pierson, Founder & CEO of BLACKCLOAK and Marija Atanasova, Sr. Content Strategist from BrightTALK for an interactive Q&A session to learn more about: - Topic trends & key insights - What security professionals care about - Events in the community - What to expect in Q2 2019 and beyond

View Details

Small businesses are the low-hanging fruit of the cybercrime world. Operating a small business is tough work and requires the small business owner to be skilled in many areas of business, finance, tech, customer service, sales, fulfillment, and so on. Cybersecurity is only a part of what SMB owners needs to know about in order to successfully run their business. However, the cybersecurity portion is often overlooked. As hackers and attackers are looking for people to scam and steal from, they look for the easiest targets first.

In this webinar, audiences will learn more about: - The risks and real costs of ignoring your data security - How it can cause you to go out of business - Simple steps to take immediately to help improve your security

Be sure that you have a good grip on understanding what you need to do when it comes to protecting your small business from these threats.

And as an added bonus, you'll receive some valuable resources that you'll be able to use in the future as you discover, plan, and implement new security strategies in your own small business. Be #SmallBizCyber smart about your small business!

View Details

Most security solution buyers assume they’re protected against known malware. Numbers like 99.9% are common in vendors’ marketing materials. Hence, efficacy conversations tend to focus instead on the solution’s performance against the unknown, zero-day threats. However, with between half a million and one million new pieces of commodity malware created every day, how are antivirus solutions keeping up? Where is this database of signatures, hashes, reputation and behavior stored for over a billion of known pieces of malware? Is the 99.9% number an illusion or reality?

In this webinar we will leverage a study of three leading antivirus products against 60,000 pieces of known new and old malware. The results will surprise you...

Does the ILOVEYOU virus from the year 2000 still pose a threat? You’ll have to join this webinar to find out.

View Details

There is an increasing need to provide evidence of cyber capability to provide confidence to regulators, boards, shareholder and other interested parties. In addition to providing confidence, there is also a requirement to provide evidence following a cyber security breach.

In order to provide this evidence we must develop international standards to allow business to provide the it in a consistent manner. The supplier industry must help to promote these standards with the support from governments and regulators.

No all of the requirements for security are the same, there is therefore a need to create a process providing this evidence from basic cyber hygiene through to Critical National Infrastructure. The companies must be suitably accredited and the individuals must have appropriate credentials and experience.

Importantly the cyber security industry must move from simply being providers of advice to providing opinions. This will mean the industry must move to being accountable. This will in turn help to professionalise the industry.

Key takeaways: Need to provide evidence of cyber capability to regulators, boards, shareholder and other interested parties. Evidence following a cyber security breach is essential, but unstructured International standards developed by supplier industry with support from governments and regulators. Evidence required from basic cyber hygiene through to Critical National Infrastructure is different. *Cyber security industry must move from advisory to accountability, this is a massive change!

View Details

Today, most C-suite and boardroom discussions on cybersecurity are based on gut feelings and incomplete data. Many CIOs and CISOs are quite uncomfortable in these meetings, mainly because they know that they only have a vague idea about the enterprise’s overall cybersecurity picture and are forced to pretend they know what’s going on.

If a major cybersecurity incident happens, some senior executive becomes the scapegoat. Everyone agrees to increase cybersecurity spending and tighten things up. Then the cycle continues, but nothing really changes. How can we all do better?

Join Gaurav Banga, Founder and CEO of Balbix as he discusses: - Behind-the-scenes deliberations in the board room - Challenges in understanding and measuring the enterprise security posture - What a mature and cyber-resilient security posture looks like - How you can get there

Gaurav Banga, PhD is the founder and CEO of Balbix, and he also serves on the boards of several companies. Before founding Balbix, Gaurav was the co-founder and CEO of Bromium and led the company from its inception for more than five years. Earlier in his career, Gaurav served in various executive roles at Phoenix Technologies and Intellisync Corporation. He was also co-founder and CEO of PDAapps, which was acquired by Intellisync in 2005. Gaurav started his industry career at NetApp. He has a doctoral degree in computer science from Rice University. He is a prolific inventor with more than 60 patents.

View Details

Join automation expert Joe Schreiber as he shares his experiences automating himself out of a job (in a good way), and discusses where to start and how to avoid risk.

Joe will present his five steps and answer questions from the audience on how to:

  • Collaborate with the rest of your team on automation
  • Organize your multi-vendor toolbox and use APIs to ensure success
  • Empower your teams to write reusable, value-driven code
  • Leverage modern applications in containers, microservices, and serverless environments

View Details

For the last 2 decades, technology security was delegated to the IT team. It was role specific and designated for one small subsection of the IT team. That mentality and way of thinking must change.

A paradigm shift is required for the whole organization. Every part of the organization contributes to the success or failure of the organization. Creating a security culture is not a one-time event, it is a new way of talking and acting.

Join this webinar with Heather Stratford, CEO of Stronger.tech to: - Understand the steps that need to happen to create this culture - See where your organization is on the scale of creating a Strong Security Culture - Learn why creating a security-minded culture is an essential part of the "new" requirements for a CIO.

View Details

In this webinar, we will be talking about not only the cost of data breaches but also impact of breaches and lesson learned for businesses, trends to reduce the risks and finally conclusion about how to prevent data breaches.

View Details

Successful security programs explain the situation, the risks, and the options available in a way that is both simple and true. Damrod draws on military analytical frameworks to develop map models that accurately depict the cyber terrain and guide the generation of a series of overlays. These build to create an Effects based plan suitable for Governance, Risk, and Compliance needs.

Join this webinar for an introduction to the cyber-as-conflict model developed by Damrod.

View Details

Cybersecurity, much like safety, cannot be achieved - it is an ongoing process that changes and adjusts to respond to the threat landscape, business needs and resources. As essential a cybersecurity strategy is to the enterprise, so is the implementation of it.

Join us for an interactive Q&A panel with security leaders to learn more about how to operationalize cybersecurity.

Topics up for discussion: - Making information security relatable - Building security programs - Defining your cybersecurity strategy - Translating your cybersecurity strategy into a risk management plan - Operationalizing your cybersecurity strategy - Using the maturity capability model for measuring success

Moderator: Michelle Drolet, CEO, Towerwall Panelists: Amy McLaughlin, Director of Information Services, Oregon State University Ariful Huq, Director of Product Management, Aporeto

View Details

There is too much fear and derision from the old guard of cybersecurity. Big breaches are used as justification for sales pitches and pedestals to mock the victims. While it is undeniable that cybercrime continues to grow, and future of cyber conflict is contested, there is good cause to think we are doing better than we imagine.

And that we can win in the future.

No competitive team enters a contest with a ‘let’s catch up’ mentality. Leaders inspire us to victory. CISO’s need to fill to role of champion and present a positive message – ‘we can win’.

Join this talk with industry thought leaders as we discuss the state of the conflict and emergent tactics from AI to insurance that promise to re-define cyber defence.

Moderator: Griff James, Director, Damrod Analysis Ltd Panelists: Wyatt Hoffman, Senior Research Analyst, Cyber Policy Initiative, Carnegie Endowment for International Peace Alan Mears, Associate Director, Risk Advisory, Deloitte LLP Gina Yacone, Cybersecurity & Threat Intelligence Consultant, Agio

View Details

While the board ‘get cyber’, questions remain around embedding cyber risk management into business strategy execution. For many CISOs, strategy alignment represents the best opportunity to engage with the board and ensure a business-driven approach to managing cyber risk.

So how should business leaders develop, update and execute business strategy with so many cyber-related implications? How can organisations meet their business goals, against a backdrop of increasing cybersecurity costs, greater regulatory scrutiny and increased frequency and magnitude of data breaches?

In this webinar, Mark Chaplin, Principal, ISF will discuss the significance of aligning security strategy with business strategy. Mark will draw on executive engagement, exploring the essential factors for success and highlighting the pitfalls to avoid.

View Details

What threats can we expect to see in 2019, and how do we make sure we're prepared?

Join Bitdefender Director of Threat Research and Reporting, Bogdan Botezatu to discuss research-based predictions on the biggest threats of 2019. He'll walk through the future of cryptojacking, advanced persistent threats (APTs), network-level exploits, IoT attacks, and others and provide recommendations on the industry's best defenses against these threats.

View Details

Join us for this webinar that will present an advanced data science approach to detecting anomalous behavior in complex systems like the typical corporate network that your IT Security team is trying to defend. Generalized anomaly detectors, without tuning for a specific use case, almost always result in high false alarm rates that lead to analyst alert fatigue and a detector which is effectively useless. In this session, Brenden Bishop, Data Scientist at the Columbus Collaboratory, will present an open source tool and best practices for building specific, repeatable, and scalable models for hunting your network’s anomalies. Through iteration and collaboration, defenders can hone in on interesting anomalies with increasing efficiency.

View Details

Join us for this webinar that will recommend how to deal with your “big data” problem when dealing with the massive volume of raw, unprocessed data points from your network security sensors. Hint: don’t start with the data and attempt to drill down to the problem. Instead, as Slava Nitikin, Data Scientist from the Columbus Collaboratory will explain, you must start by the defining problem, building a threat model, and then focusing on the corresponding signals in your sensor data. We will walk through the use case for an Active Directory password spraying attack to demonstrate how to define and apply appropriate filters to your security data for faster detection, more accurate threat scoring and more effective security overall.

View Details

Presented by WiCyS and SIA...

This webinar from Women in CyberSecurity (WiCyS) and the Security Industry Association (SIA) will present the findings of The Cybersecurity Imperative research project produced by WSJ Pro Cybersecurity and ESI ThoughtLab and sponsored by SIA. We will share insights into how 1,000-plus organizations around the globe measure their cybersecurity preparedness and how they are preparing for future cyber threats.

In this 45-minute program, we’ll also share a new tool that allows you to compare your own organization’s preparedness to the aggregated data of study participants.

Expect to Learn: •Current threats organizations are facing •Cyber risk management approaches •Where organizations plan technology and staffing investments for cybersecurity •The impact of cybersecurity “maturity” •The costs of cybersecurity breaches

Presenters: •Marilia Wyatt (WSJ Pro Cybersecurity) •Lou Celi (ESI ThoughtLab) •Kim Landgraf (Security Industry Association / SIA Women in Security Forum)

Interviewer: •Taly Walsh, Executive Director (WiCyS)

View Details

Are traditional awareness raising campaigns (e.g. CBT, phishing simulations) affording sufficient protection against ever evolving cyber-attacks? With human errors being the #1 cause of security incidents and data breaches, it is now a CISO imperative to tackle behavioural change and effectively manage the human risk. This recognised need reflects the acceptance that how the workforce behaves is dependent on the shared beliefs, values and actions of its employees, and that this includes their attitudes towards cybersecurity.

Key topics covered in this presentation: • People-related challenges and frustrations the industry is facing • Why a new approach to awareness and culture is required • Innovative approaches adopted by leading organisations

Your organisation can only be secure if you make people your strongest defence. Attend this session to discuss how to turn your human risk into your biggest advantage in cyber security!

Flavius Plesu: A business-focused cyber security leader, Flavius has held senior security positions both within the public and the private sector and has lead a number of enterprise-wide security transformation programmes, in complex global organisations. Passionate about solving real industry problems, cultivating and building teams to deliver on the organisation’s mission, values and goals.

Alongside his role as a Head of Information Security at Bank of Ireland UK, Flavius is also one of the Founders of OutThink, a team of CISOs and security practitioners who are changing the way in which organisations engage with their employees to shape behaviours and manage human risk in the context of cyber security.

View Details

Global cybersecurity analyst Liviu Arsene will discuss the response and mitigation steps organizations should take while in the midst of an attack. He'll share best practices for combatting the attack, as well as steps that should be taken to notify clients, assess damage, and learn from the breach to build defenses against future attacks.

Liviu Arsene is a global cybersecurity analyst for Bitdefender, with a strong background in security and technology. Reporting on global trends and developments in computer security, he writes about malware outbreaks and security incidents while coordinating with technical and research departments. His passions revolve around innovative technologies and gadgets, focusing on their security applications and long-term strategic impact. When he's not online, he's either taking something apart or putting it back together again.

View Details

Organisations today need to be agile, and dynamic in responding to the most advanced cyber threats, and although automation has it's place in improving SOC efficiencies, human intelligence is still one of the most important aspects in effective incident response.

In this session learn more about the journey to Intelligent orchestration and how leveraging it in an uncertain world can empower your organisation.

View Details

Organisations are constantly under threat with over two-thirds of them experiencing data breaches in 2018. As a result, preparedness and resiliency are paramount to protecting an organisation’s information from cyber attacks.

Business leaders and their security teams can improve their ability to handle cyber attacks by running cyber security exercises. These exercises should help the organisation identify areas of improvement in people, process and technology, reducing the impact should a real cyber attack occur.

In this webinar Daniel Norman, Research Analyst, ISF will share how organisations should approach running internal cyber security exercises to support breach identification, prevention and response.

View Details

Cybercrime has evolved from random activities being carried out by individuals into a billion dollar illegal industry that continues to grow. How is cybersecurity keeping up with the rise of cybercrime?

Join this panel of security experts to learn more about: - Trends in cybercrime and lessons learned in 2018 - The cost of data breaches - Rise of cryptojacking and ransomware - Who are the players who make up the world of cybercrime (e.g. programmers, distributors, fraudsters, etc.) - The CISO vs the cybercriminal - Best practices for protecting your business

Speakers: - Michelle Drolet, CEO, Towerwall - Michael Thelander, Director of Product Marketing, Venafi - William Peteroy, Security CTO, Gigamon - Kalani Enos, Founder & CEO, kenos Technologies (Moderator)

View Details

Small and medium-sized businesses are major targets for cybercriminals. To stay safe, today’s businesses must understand the different types of cyberattacks they may encounter and implement strong cybersecurity practices.

Register for this 30-minute webinar on the key threats businesses faced this year and what's upcoming in 2019 to get details and tips that will help you keep your business and clients safe. Our Threat expert will be discussing ransomware, banking Trojans, phishing and all the crypto-crime that’s wreaking havoc on IT pros.

Book your place and get some key insights, including:

· 2019 Threat Landscape Predictions · Observed business trends (how businesses worry about the wrong threats) · Where stolen data/information ends up · Long term effects of data theft

View Details

Selecting a vendor partner (or partners) is one of the most critical decisions enterprises will make on their IoT journeys. The right partner makes all the difference: enterprises with top-ranked partners report greater success in generating revenue, cutting costs, and optimizing business processes via IoT. • Who are the right providers? • What are the critical factors to consider in selecting one?

This webinar reviews the provider landscape and highlights critical selection factors for companies of all sizes and industries.

View Details

A new study has updated the ratio of women to men in the cybersecurity workforce – from 11% to 20%. Yet more than 300,000 cybersecurity jobs are unfilled today, a number that is exponentially growing into the millions. Let's do something to move the needle to 50% women in cybersecurity!

Women in CyberSecurity (WiCyS), a non-profit organization with deep roots in academia, government and industry, is driving to increase recruitment, retention and advancement of women in cybersecurity.

During this engaging webinar for diversity recruiters and women in various stages of cybersecurity careers, we will interview two WiCyS Board Members who offer stats and important guidelines for recruitment and retention of women in cybersecurity.

Featuring: Dr. Janell Straach, Chairman of the Board, WiCyS - Director, Center for Engaging Women in Cybersecurity, University of Texas Dallas

Dr. Costis Toregas, Treasurer, WiCyS - Director, Cyber Security and Privacy Research Institute, George Washington University

Interviewer: Taly Walsh, Executive Director, WiCyS

View Details

Join RSA Conference Director of Content Curation and four Program Committee Members for a panel discussion about the topics they’re most excited about at RSA Conference 2019. Plus, some hints at the big discussions to take place in areas like Blockchain, security strategy and more:

  • Is Blockchain bulletproof?
  • Are there technical risks related to cryptocurrencies?
  • How to assess the coverage and gaps in your security portfolio
  • The theme of “acceptance” in security strategy
  • Exciting sessions in our Hackers & Threats track from chipset to containers, as well as smart contracts
  • Closing the enterprise gaps when it comes to moving to the cloud

You’ll have a chance to ask questions during this live webcast. Join us for this exclusive preview of what you’ll hear about at RSA Conference 2019, March 4-8 in San Francisco.

Britta Glade, Director Content & Curation, RSA Conference Wendy Nather, Director, Advisory CISOs, Duo Security Rich Mogull, Analyst & CEO, Securosis Diana Kelley, Cybersecurity Field CTO, Microsoft Ryan Berg, Fellow, Alert Logic

View Details

"In the age of breaches, enterprises are looking to understand the security and compliance risks associated with data stored in, and accesible from, cloud applications so they can better prepare should the unthinkable happen. With data and workloads moving to the cloud, securing the enterprise is more critical than ever.

Join cloud, security and compliance experts as they discuss: - How to proactively analyze security risk from the business perspective - What you need to know about your data, and how to ensure it is compliant when in the cloud - How to automate security policy changes - Top challenges for CISOs and CIOs - Achieving security and compliance across multiple clouds - Steps to take today"

Presenters Benny Czarny, CEO and Founder, OPSWAT Tzach Horowitz, Pre-Sale Director, Cybergym Ariel Zeitlin, CTO and co-founder, Guardicore Diana Kelley, Cybersecurity Field CTO, Microsoft

View Details

Making sure security is included at every step in the software or application development lifecycle is key in the age of breaches, data leaks and third party security risks.

Join experts from the industry to learn more about: - Security challenges and vulnerabilities - DevOps vs DevSecOps: What's the difference? - How to make disjointed security and DevOps teams work effectively - DevOps security scans - Steps to better application security

Panellists Ran Ilany, CEO, Portshift Bar Hofesh, CTO, NeuraLegion Ory Segal, CTO, PureSec Guy Dagan, Cofounder and Partner, Consienta

View Details

With cyber attacks and breaches on the rise, cyber resilience is becoming an area of focus for C-suite executives worldwide. It is no longer a question of "if" a breach will occur, but "when," and organizations are looking to include cyber resilience as part of their business continuity and disaster recovery programs.

Join security and business continuity experts as they review: - Threats to cyber resilience and business continuity - Lessons from Wannacry (ransomware) and NotPetya (wiper) attacks - Attack trends and business preparedness - Steps for enterprises to take today

Panellists Aviv Cohen, CMO, Pcysys Ariel Koren, CTO, SNDBOX Israel Levy, CEO, Bufferzone Security Eddy Bobritsky, Founder & CEO, Minerva Labs

View Details

According to a recent study, having a lack of influence in the boardroom is a key reason why 84% of CISOs in North America believe there is no way to avoid a data breach. How are CISOs addressing the ever-growing cyber threat landscape, disappearing security perimeter and the chronic lack of skilled security professionals? What do they need to communicate and how, to get the board on their side?

Join security experts across the industry for an interactive discussion on: - What keeps CISOs up at night - Strategies for breach prevention - Strategies for making the most of AI technolofy and human talent - Coping with analyst fatugue - Threats on the horizon - Recommendations for strengthening security

Panellists Noam Erez, co-founder and CEO, XM Cyber Aviv Grafi, CEO and co-founder, Votiro Guy Dagan, Cofounder and Partner, Consienta Avivit Kotler, CISO - Head of Cyber Security & Business Continuity, Clal Insurance Kobi Freedman, Co-founder & CEO, IDRRA

View Details

The Internet of Things is set to reach 50 billion connected devices by 2020, according to a recent Cisco report, making them an attractive target for cyber criminals who can easily use them get inside networks of organizations worldwide. Once in, attackers can easily take over and control IP-enabled devices to extract data or implant malicious code.

Join IoT and security experts to learn more about: - Unique challenges of securing IoT systems - IoT and AI: Threats, attack trends and recommendations for basic cyber hygiene - Proactive security strategies to stave off the threat of IoT cyber attacks

Panellists Ari Eitan, VP of Research, Intezer Udi Solomon, CEO & Co-Founder, ShieldIoT Moshe Shlisel, CEO and Co-Founder, GuardKnox Guy Dagan, Cofounder and Partner, Consienta

View Details

Cyber threats continue to rise as organizations are embarking on their digital transformation journeys. The continued rise in cyber attacks is a key concern for CISOs in their efforts to protect the enterprise from financially motivated cyber criminals, as well as insider threats.

Join security experts as they discuss: - New on the threat landscape - Notable cyber attack methods and strategies and how to protect against them - Areas for improvement - Solutions for network visibility, breach detection and response - Recommendations for improving security and steps to take today

Panellists Elad Schulman, CEO, Segasec Yoram Salinger, CEO, Perception Point Mille Gandelsman, CTO and co-founder, Indegy Guy Dagan, Cofounder and Partner, Consienta Kenneth Schneider, VP Fellow, Symantec

View Details

Strategies to Keep You and Your Privacy Program Focused and Sane

Are the new and ever-changing data protection laws stressing you out? Feeling overwhelmed by the tidal waves of compliance requirements? Don’t know where to start? Take a deep breath.

We’ll share 5 key strategic steps to help get you and your privacy program focused and release the overwhelm. Leave this webinar feeling grounded and ready to tackle the data protection obstacle courses of 2019.

Jackie Wilkosz is a Manager at Aleada Consulting, where she advises clients on privacy, data protection, and information security issues. Jackie cultivates dynamic client partnerships to provide practical, actionable advice. She has specific expertise in human resources privacy and building multi-jurisdictional compliance programs.

View Details

Consumers are increasingly concerned about the privacy of their personal data, and businesses are starting to pay attention. Privacy came into focus in 2018, not only because GDPR went into effect following months of hype, but also because of the steady stream of high-profile hacks and breaches, as well as media attention on how some of the biggest tech companies have been harvesting, storing and sharing user data.

On Data Privacy Day, join the experts to learn more about: - Why your business strategy should include data privacy - Data protection regulations around the world - The biggest data privacy events in 2018 - What to look out for in 2019

Speakers: - Christopher Pierson, Founder & CEO, BLACKCLOAK - Alyssa Coley, Associate, Aleada Consulting - Sarah Squire, Senior Technical Architect, Ping Identity

View Details

Everybody knows IoT is the wave of the future. But what are successful organizations doing differently when it comes to their IoT initiatives? Are they saving more? Generating new revenue and lines of business? Or increasing operational efficiency and other metrics?

This webinar unveils the secrets of top-performing companies when it comes to IoT initiatives. You'll learn how they plan for, design, secure, and operate their IoT initiatives--and how they track the benefits.

View Details

What threats can we expect to see in 2019, and how do we make sure we're prepared?

Join Bitdefender Director of Threat Research and Reporting, Bogdan Botezatu to discuss research-based predictions on the biggest threats of 2019. He'll walk through the future of cryptojacking, advanced persistent threats (APTs), network-level exploits, IoT attacks, and others and provide recommendations on the industry's best defenses against these threats.

View Details

The biggest threat to any organization is it’s own people, particularly when they have access to its most sensitive data. This talk is about limiting the internal threat through RBAC and segregation of duties, and how to implement these using Active Directory.

Helen has a masters in electronic engineering, specializing in machine learning. She moved into Cyber Security at 10x Future Technologies, a fintech start up founded by the ex-CEO of Barclays Anthony Jenkins. She is now working with 6point6 to provide SME services to HM Government, designing and building a number of Cyber Security tools.

View Details

Learn how the role of Chief Information Security Officer (CISO) has changed in the age of data breaches and high-profile cyber attacks.

Join well-known CISOs at the top of their game for an interactive discussion on: - How the role of CISO has changed in the last few years - Hiring and retaining a CISO - Top challenges for CISOs - Dealing with stress & pressure associated with the role - How to keep your security team happy - Tools, technology and policies CISOs swear by - What keeps CISOs up at night - Why leadership buy-in is essential to boost cybersecurity - Future trends and predictions

Speakers: - Gary Hayslip, CISO, Webroot - Mark Weatherford, Chief Cybersecurity Strategist, vArmour - Dan Lohrmann, Chief Strategist & CSO, Security Mentor - Amos Stern, CEO, Siemplify

This exclusive CISO webinar originally aired during National Cyber Security Awareness Month (NCSAM).

View Details

Every organization has a strategy – sometimes this is explicitly stated within various organizational documents and other times the strategic objectives are held within the minds of executive leadership. CISOs today are struggling to find the right words and narrative to set the tone from the top. How do you properly extract the right type of information from your organization that will help you build a consensus and influence with your top-level management?

As a CISOs, you need to acquire a new set of skills while maintaining your technical trench warfare knowledge (Frameworks, SIEMs, DLP, MDR, etc..). In this presentation, Max Aulakh (CEO) will present broad range of skills that are needed for the next CISO. We will also examine behaviors of some of the well known CISOs in our industry and how they interact & build influence to gain consensus.

View Details

Start the new year on the right foot by investing in yourself and improving your leadership skills. Join Glenn Richardson, coach and executive consultant, in this webinar that will explore the principles of leadership. We will review practical tips, supported by real-world examples, from an experienced, successful leader who specializes in coaching and developing new and emerging leaders. Gain confidence in your ability to learn and lead, and, if you’re already in a leadership role or approaching a new position with leadership expectations - congratulations! Join us on this webinar to develop a plan for continue learning, improvement and career advancement.

View Details

Data breaches are on the rise and getting their fair share of media attention. It is no longer a question of "if", but "when" an organization will get breached. So, how are organizations preparing for the inevitable?

Join this roundtable discussion with security experts to learn more about: - Trends in cyber attacks and breaches and what's at risk - Prevention best practices - Solution recommendations for breach detection and response - Key factors for CISO success - What's on the horizon for 2019

Speakers: - Griff James, Director, Damrod Analysis Ltd. - Michelle Drolet, CEO, Towerwall - Liam Brown, Cyber Risk Specialist, Lockton Companies

View Details

Not every business can afford to employ a dedicated CISO and some businesses will assign the role of a CISO out to another member of management without any understanding of the role.

Here comes the Virtual CISO, someone who spends time in your business from an externally business who manages your security and countless others all at the same time. Someone who takes feeds of information from real sources and has to process them to make sense of them then has to adapt this knowledge to each business they manage.

View Details

What will 2019 bring for the security landscape? How many Marriott-like breaches should you expect? What new types of attacks are you likely to see, and what can you do now to prepare for them? Nyotron’s team of security experts will have the answers for you during our December 19th live webinar.

Making informed predictions first requires thinking back on 2018 with a critical eye. We will review a few of the most significant vulnerabilities and data breaches that made national headlines, from the City of Atlanta to Meltdown and Spectre, to the Marriott debacle and why the healthcare industry appears unable to defend itself. Our panel will also discuss the issues and trends they expect will dominate 2019, including adversarial artificial intelligence (AI) and destructive attacks on ICS.

We will wrap up with ideas on how you can make an effective case for additional security budget and how to educate yourself about the changing threat landscape (and to get those CPE’s before the year’s end).

View Details

Everyone talks about IoT, and many organizations are implementing it and reaping the business benefits. But even those who have had IoT projects deployed for years may not have a comprehensive architecture and framework in place to help guide technology decisions and streamline operations.

Join Nemertes CEO Johna Till Johnson as she reviews the IoT architecture and framework and shares guidance gleaned from leading-edge clients and research study participants.

View Details

Discover the cyber security attack trends that will shape your security planning and budgets for 2019. Discover what's new on the threat horizon, how businesses are coping and the key areas for improvement. Learn about the latest technologies enabling stronger and more resilient enterprises.

Join this keynote panel of security experts and industry veterans as they discuss: - New on the threatscape - Cyber attack trends seen in 2018 - Addressing your cyber risk - How to prepare for 2019 - Security strategy and making the most of your security dollars - New leaps in technology - Best practices and recommendations

Speakers: - Sushila Nair Sr. Director Security Portfolio, NTT DATA Services - Topher Chung, Director of Security Engineering, OneLogin

View Details

Join Interfocus and Cylance for this webinar outlining the workplace productivity gains that your business can realize through an integrated and unified platform delivering both IT asset management and endpoint security. Most IT teams today suffer from "alert fatigue" from the growing number of devices on their network, and spend on average 5-13 hours a week cleaning up compromised endpoints. Scott Scheferman from Cylance and Masataka Hashiguchi from Interfocus will demonstrate how automation and prevention is worth a pound of cure on your endpoints.

View Details

Companies are increasingly moving to an architecture based on microservices and containers, as part of an overall move to DevOps, Agile, and cloud-first development.

But are they taking the right steps to secure those containers?

This Webinar provides a feature-functionality comparison of the leading providers of container security, and provides guidance for enterprise developers in launching their container security initiatives.

View Details

This webinar is part of the 2019 Trends and Predictions series on BrightTALK.

Join top security leaders for an interactive discussion on how to better secure the enterprise in 2019: - Top threats on the horizon and what's at risk - Cyber defenses and your employees - Basic cyber safety recommendations to protect against social engineering, phishing and email cyber attacks - Use cases and examples - Actions to take today to protect your employees and enterprise from cyber criminals - What to expect in 2019

Speakers: - John Bambenek, VP Security Research & Intelligence, ThreatSTOP - JP Bourget, Founder & Chief Security Officer, Syncurity - Jan Liband, CMO, SlashNext

View Details

The modern user is pushing the limits and testing all borders, and they want as few restrictions as possible. To make sure the organisation’s security needs are met in this mix we can utilise feature like Microsoft Azure Active Directory Identity Protection for extended identity protection, and Azure Information Protection (AIP) for data protection.

By analysing user risk and detecting suspicious activities, we can make sure annoying security features doesn’t appear before they are necessary.

With AIP we can help our users secure their information and limit the chances of leaking important information by accident. AIP also gives us unique insight into how our users are working with information, where our sensitive information is, and also who has access to it.

Understanding features and possibilities, and how they can match up against the ever-changing threat and temptations out there are essentials in any security strategy.

Speakers: - Olav Tvedt, Principal Cloud Solution Architect, Innofactor Norway - Pål-Erik Winther, Principal Cloud Solution Architect, Innofactor Norway

View Details

Most cyber professionals spend much of their time, effort and budget on protecting their corporate networks from an attack or breach. However, the reality is that most corporate data these days no longer lives only inside the perimeter of the network.

Every business now uses the cloud to store and process data. Every business also shares data with its supply chain. Employees store data on their laptops and mobile devices and set up complex, unmanaged shadow IT networks of cloud apps and microservices. They email data within and outside the organisation, sometimes to the wrong recipient in error. The number one cause of data breach by far is our employees and human error, not failures of cybersecurity. Defending our network is no longer enough, so how can we defend our data?

It all starts by reframing how we think about cybersecurity. This webinar explains why you need to beyond your networks to protect the thing that matters most — your data.

Jeremy Hendy, CEO, RepKnight Jeremy is the chief executive officer at RepKnight. Jeremy has 30 years’ experience in high technology industries, working at companies like Texas Instruments, Symbionics and Cadence. Prior to joining RepKnight in 2016, he was VP of sales and marketing at Cambridge-based Nujira. He holds a degree in electronic engineering from the University of Liverpool.

View Details

Globalization and division of labor has allowed multi-national corporations and businesses to focus on their core capabilities while outsourcing all various ranges activities form legal services, IT services, marketing, etc... these trends will continue to gain speed as global markets become much more efficient.

Proliferation of suppliers has also rapidly increased emerging threats such as privacy, data sharing and cyber risks. The key takeaway for audience in this presentation will be over all discussion of dimensions of supplier risks and how to holistically develop a proper comprehensive supplier report card that includes financial and cyber data.

View Details

A sound defence needs more than technology. Alongside advancements in machine learning and artificial intelligence, there remains a vital role for human insight and ability. At heart, cyber is a field of conflict – a contest over access to data. To allocate resources effectively and win that fight, defenders need consider the attacker’s perspective. Only by understanding what is under threat and what the likely attacks are can defenders allocate defences effectively.

Ideal for technical leaders explaining priorities to non-technical managers, this webinar discusses how to understand, assess, and defend against cyber-attack using widespread offensive techniques to discuss how best to develop defensive strategy.

View Details

Hacking is a lucrative business. Like any other line of work, there are business drivers that lead to natural surges in activity. Just as retailers rely on holiday shopping season to remain in the black, malicious actors are spending time right now gearing up for Breach Season. Pondurance research shows a massive uptick in intrusions during the months of February-April, in some cases, 80-90%. This means now is the time that hackers are busy doing reconnaissance and infiltrating networks.

Pondurance Founder Ron Pelletier will discuss: · Breach Season basics: who is affected and what to expect · The main drivers causing the intrusions and breaches? · Pre-season tactics and strategies to prepare · What companies can do to reduce the likelihood of occurrence · Review of last year’s top threats and predictions for 2019

Ron Pelletier, Founder, Pondurance With more than 17 years of information security and business continuity experience, Pondurance Founder Ron Pelletier brings seasoned expertise in all areas of risk advisory, incident response and forensic investigations. His training as a U.S. Army commissioned officer equipped him with problem-solving and risk analysis capabilities well-suited for the tech world. His vast experience in enterprise risk and security includes a wide range of industries and organizations ranging from Fortune 500 to small, non-profit groups.

Ron is certified in multiple disciplines relating to information and asset protection including Certified Information Systems Security Professional (CISSP), Certified Information Systems Security Manager (CISM), Certified Business Continuity Professional (CBCP), Certified Information Systems Auditor (CISA), Certified Computer Forensics Examiner (CCFE), and Certified Ethical Hacker (CEH).

View Details

Planning on doing business overseas? Establishing a new office in a foreign land, or selling online to consumers in a new country? When going over company requirements for working in your new neighbourhood, don’t forget to review corporate privacy practices.

When it comes to privacy, expectations, safeguard minimums and rights of the data subject can vary between jurisdictions. From Canada and the United States, the European Union with its new GDPR, Japan, Australia, even between China and Hong Kong, there’s no single set of global standards. Fortunately however, many privacy legislations do contain common ground. There are also ways to proactively account for the differences.

Information and Privacy Professional Victoria McIntosh presents a taste of privacy across the globe, with some of the ways businesses can prepare in dealing with data across borders.

View Details

What is targeted ransomware? Are you susceptible? What can you do to defend against it?

View Details

Organisations in 2019 will be increasingly faced with a hyper-connected world where the pace and scale of change – particularly in terms of technology – will accelerate substantially. Business leaders need to develop cutting-edge ways to deal with new regulation, advanced technology and distorted information.

In this webinar, Steve Durbin, Managing Director, ISF will discuss the threats organisations will be facing in 2019 and how business leaders and their security teams can address them. The emerging cyber threats to lookout for include:

-The increased sophistication of cybercrime and ransomware -The impact of legislation -The myth of supply chain assurance -Smart devices challenge data integrity

About the presenter

Steve Durbin is Managing Director of the Information Security Forum (ISF). His main areas of specialism include strategy, information technology, cybersecurity and the emerging security threat landscape across both the corporate and personal environments.

View Details

Current forensic evidence is indicating that Ransomware, Extortion, and Phishing Attacks are the top attack vectors penetrating companies today. Although not as wide-spread, intellectual property theft and disgruntled employees is causing significant loss for many organizations as well. Given the scarcity of talent and resources, learn tips and actionable insights from the forensic lab on what you can do to protect your organization from these most prevalent threats.

View Details

Analysis shows that human actions are overwhelmingly at the heart of many data breaches, and cyber attackers are actively seeking to exploit this to compromise target systems.

If global organisations and nation states with their considerable resources and budgets are struggling to stem the flow of data breaches from this threat, what hope do ordinary businesses have of protecting themselves in 2019 and beyond?

Join us for a comprehensive and insightful webinar from Daryl Flack, CIO and Co-Founder of BLOCKPHISH, who will use examples drawn from real attacks to reveal why, if you invest in your staff, you can be more confident in your ability to be resilient to cyber-attacks.

View Details

Cyber attacks on businesses, organizations and critical infrastructure becoming the norm in 2018. Massive breaches are constantly in the news and consumers are demanding stricter data and privacy protections. Cybersecurity has never been more important to organizations, and the investment in security technology has never been greater.

CISOs are in the spotlight, and are looking to build the best strategy to secure their organizations, customers and users.

Join top security experts for an interactive Q&A panel discussion on: - The key factors CISOs should consider for their cybersecurity strategy - The current and future threatscape - Platform Security for 2019 - Technological solutions that make CISOs' lives easier - How organizations are coping with the shortage of qualified security workforce - How CISOs can better communicate their strategy to the board

Panelists: Israel Barak,CSO, Cybereason Dario Forte, CEO, DFLabs

Panel moderated by: Amar Singh, Founder & CEO, Cyber Management Alliance

View Details

Digital identity authentication can be challenging to do effectively. Join us to learn about the evolution of biometrics technologies, from those that determine who you ARE in the digital realm, to behavioral biometrics that determine your identity based upon what you DO and how you do it. Ehab Samy, Vice President of Product Management for Plurilock, will map which digital identity management mechanisms are best suited for particular environments including law enforcement, airport security, health care, and the workplace.

View Details

In this session we will look at where the line is drawn between data privacy and cybersecurity. - What are the primary cybersecurity responsibilities that support effective data privacy and what falls outside of the cyber remit? -When does a suspected breach become notifiable under regulations such as the European GDPR? - What are the key tips for managing data breaches?

This session will feature a range of security and privacy experts, interactive audience voting and questions from the audience will be encouraged.

View Details

This webinar will explain the background of the Asia Pacific Economic Cooperation Cross-Border Privacy Rules ("APEC CBPR") framework, who is participating, and how it works, as well as how it hopes to improve privacy protections while facilitating cross-border data flows.

Join this webinar to learn about the recent and possible future developments with cross-border trade and privacy in Asia, such as the Comprehensive Progressive Trans-Pacific Partnership ("CPTPP") and Regional Comprehensive Economic Partnership ("RCEP") free trade agreements, both of which have e-commerce provisions addressing cross-border data. It will also talk about what companies should do if they want to participate in and benefit from this framework.

View Details

Cyber attackers are becoming more sophisticated and data breaches are on the rise. According to a recent report, over 4.6 billion records were breached in the first half of 2018, showing a 133% increase compared to last year.

With sensitive, personal and confidential data being at risk of ending up in the hands of cyber criminals, enterprises of all sizes are looking to strengthen their security in 2019.

Join this exclusive keynote panel of industry experts as they discuss: - Trends in cyber attacks and breaches - Who is at risk - How to prevent breaches, data theft and future cyber crime - Advances in authentication - New in identity and access management - Security awareness and training - Best practices for securing the enterprise

Speakers: - Sushila Nair, Sr. Director Security Portfolio, NTT DATA Services - Derek Hanson, Sr. Director Solutions Architecture & Standards, Yubico -Rebekah Moody, Fraud & Identity Director, ThreatMetrix -Ian Spanswick, VP Professional Services EMEA,ThreatMetrix

View Details

Join security experts from Columbus Collaboratory to learn how to elevate your network’s cybersecurity defenses by identifying and remediating the most critical vulnerabilities. We will discuss best practices for vulnerability scanning, managing the seemingly overwhelming volume of scan data, data visualization techniques, and how combining vulnerability data, threat data and asset classification is critical to prioritizing your remediation efforts when resources are scarce and time is of the essence.

View Details

Risk management in banks has gone through a silent revolution. Banks had to solve the problems and questions asked post-crisis and then rationalize and move to more enterprise wide models. Today, a three pronged revolution of regulation, technology and new sources of risk mean banks must re-imagine risk and compliance. With platformification, increases in computing power and cloud come the opportunities to deliver more agile processes, more real-time insights and more accurate predictions. But data quality remains king. What are CIOs top considerations when deploying more open api driven risk platforms? Can risk management securely live in the cloud? How can banks move the needle by collaborating with the fintech ecosystem?

Rupert Nicolay, Worldwide Services Architect, Microsoft Zannettos Zannettou, Principal Technology Consultant, Finastra

View Details

Warning - This webinar is only for informational purposes. We do not condone or encourage any malicious activity. The knowledge you gain from this webinar should be used to protect your own infrastructure and web applications.

PCI-DSS needs no introduction. The Payment Card Industry Data Security Standard applies to any organisation accepting credit card details in some way or the other. This webinar is going to share some of the latest techniques cyber criminals are using to break web applications.

Join us to learn how they are doing this and what you should do to protect your organisation and compliance status.

View Details

This webinar is part of BrightTALK's coverage of the 15th National Cyber Security Awareness Month (NCSAM).

Join CISOs and other security leaders for an interactive discussion on how to better secure our critical infrastructure: - Top threats on the horizon and what's at risk - Key vulnerabilities & how advancements in technology have changed the game - Threat intelligence & what needs to be improved now - What government agencies can learn from the private sector about cybersecurity - Recommendations for protecting critical infrastructure from attacks and subversion by online adversaries - What to expect in 2019

Speakers: - Dan Lohrmann, Chief Strategist & Chief Security Officer (CSO), Security Mentor - Chris Morales, Head of Security Analytics, Vectra Networks - Dave Klein, Sr. Director, Engineering & Architecture, GuardiCore

View Details

This webinar is part of BrightTALK's coverage of the 15th National Cyber Security Awareness Month (NCSAM).

Learn how the role of Chief Information Security Officer (CISO) has changed in the age of data breaches and high-profile cyber attacks.

Join well-known CISOs at the top of their game for an interactive discussion on: - How the role of CISO has changed in the last few years - Hiring and retaining a CISO - Top challenges for CISOs - Dealing with stress & pressure associated with the role - How to keep your security team happy - Tools, technology and policies CISOs swear by - What keeps CISOs up at night - Why leadership buy-in is essential to boost cybersecurity - Future trends and predictions

Speakers: - Gary Hayslip, CISO, Webroot - Mark Weatherford, Chief Cybersecurity Strategist, vArmour - Dan Lohrmann, Chief Strategist & CSO, Security Mentor - Amos Stern, CEO, Siemplify

View Details

As more corporate data moves to the cloud, the new challenge is to efficiently manage security in both the cloud and on premises. How are organizations coping and what are the solutions they should be employing?

Join this keynote panel of security and cloud experts as they discuss: - Cloud security challenges today - Extending network security to the cloud - Security policy management in the cloud - Security automation - Best practices and recommendations for improving your enterprise security posture - Future trends in cloud security

Speakers: - Dave Klein, Sr. Director Engineering & Architecture, GuardiCore - Prof Avishai Wool, CTO & Co-founder, Algosec - Fred Streefland, Chief Security Officer North & East-Europe (NEEUR), Palo Alto Networks

View Details

Organisations increasingly rely on cloud services, motivated by the benefits of scalability, accessibility, flexibility, business efficiencies and reduced IT costs. However, there are several security implications that organisations need to address, including the challenge of verifying identity and managing access to cloud services.

Cloud services bring added complexity to identity and access management, exacerbated by the distribution of data across a myriad of applications accessed by users from multiple devices and locations. Failure to adequately implement user authentication and access control in the cloud can be exploited by attackers to gain access to users’ credentials, manipulate systems and compromise data.

In this webinar, Senior Research Analyst Dr Emma Bickerstaffe and Principal Analyst Benoit Heynderickx will discuss identity management, access control and user authentication in the cloud environment, and consider how organisations can effectively tackle this security concern.

View Details

This keynote panel is part of Cloud Month on BrightTALK.

Join this keynote panel of security and cloud experts as they discuss: - The most prevalent security risks and challenges and how to contend with them - Your cloud strategy and how it affects your overall security posture - How to extend network security to the cloud - Areas for automation - Best practices on how to secure your enterprise in 2019

Speakers: - Sushila Nair Sr. Director Security Portfolio, NTT DATA Services - Diana Kelley, Cybersecurity Field CTO, Microsoft - Yonatan Klein, Director of Product, Algosec

View Details

Discover what's trending in the IT Security community on BrightTALK and how you can leverage these insights to drive growth for your company. Learn which topics and technologies are currently top of mind for security professionals and decision makers.

Tune in with Dave Klein, Senior Director of Engineering & Architecture at GuardiCore and Marija Atanasova, Senior Content Manager for IT Security at BrightTALK, to discover the latest trends in the community, the reasons behind them and what to look out for in Q4 2018 and beyond. - Top trending topics in Q3 2018 and why - Key events in the community - Content security professionals care about - What's coming up in Q4 2018

Audience members are encouraged to ask questions during the Live Q&A.

Speakers: - Dave Klein, Sr. Director of Engineering & Architecture, GuardiCore - Jay Beale, Principal Security Consultant, CTO, and COO, InGuardians - Marija Atanasova, Sr. Content Strategist, BrightTALK

View Details

Identifying a user through fingerprints, facial recognition or iris scanning is simply not enough for today's digital age. Join us to learn about the shift from point-in-time identification to behavioral biometrics and how it is impacting today's workforce. Ehab Samy, Vice President of Product Management for Plurilock, will explore game-changing practices in continuous authentication and identity management to control access to physical spaces, applications, and government services.

View Details

This webinar is part of BrightTALK's coverage of the 15th National Cyber Security Awareness Month (NCSAM).

Discover the basic cyber hygiene practices your organization should have in place to drastically reduce your risk exposure.

Join well-known CISOs at the top of their game for an interactive discussion on: - How to achieve basic cyber hygiene - Best practices for minimizing your cyber risk - Cybersecurity awareness & employee training - Ethical hacking - Cyber insurance

Speakers: - Gary Hayslip, CISO, Webroot - Joseph Kucic, CSO, Cavirin Systems - Dan Lohrmann, Chief Strategist & CSO, Security Mentor

View Details

This webinar is part of BrightTALK's Privacy Insights Series and National Cyber Security Awareness Month (NCSAM).

With the proliferation of the Internet of Things into every sphere of our lives, it's now more important than ever to understand the security and privacy risks associated with connected devices. With smart home devices, office tools, children's toys, even medical devices being vulnerable to cyber attacks, becoming cyber aware should be a key priority for everyone.

Join privacy and cyber security experts for an interactive panel roundtable discussion on: - The privacy and security vulnerabilities and risks stemming from IoT devices - The basic safety measures you can deploy to protect your home and workplace against cyber threats - Best practices for privacy and security safeguards - What to do in the event of a breach - What the future of privacy looks like

Speakers: - Elena Elkina, Partner at Aleada Consulting - Parnian Najafi Borazjani, Senior Analyst, FireEye - Ondrej Krehel, Digital Forensics Lead, CEO & Founder, LIFARS - John Bambenek, VP Security Research & Intelligence, ThreatSTOP

Audience members are encouraged to send questions to the speakers to be answered during the live session.

View Details

It is beyond the ability or willingness of the world’s governments to protect and secure information technology. What role then can the private sector play in making cyberspace safer? Can private enterprises do anything to strike back at attackers, curtailing their freedom of action and raising the costs of malicious activity?

Consisting of academics and industry experts, this panel will explore the potential for active cyber defence to impede and deter malicious activity and the conditions under which it could be conducted responsibly.

Speakers: - Griff James, Director at Damrod Analysis - Wyatt Hoffman, Research Analyst, Cyber Policy Initiative at Carnegie Endowment for International Peace - Will Lymer, Chief Growth Officer at Loki Labs

View Details

Discover the latest trends in cyber crime, your organization's vulnerabilities, and how to go about preventing, detecting and responding to a breach.

Join this interactive Q&A panel with top security experts across the ecosystem to learn more about: - Trends in breaches and cyber attacks - What to do (and not to do) after a breach - What's new on the threatscape - Best practices and recommendations for improving your security posture

Speakers: - Heather Stratford-Geibel, CEO of Stronger.tech - Sushila Nair, Sr. Director, NTT DATA Services - John Matthews, CIO, ExtraHop

View Details

Felicity will discuss what steps, methods and techniques that your organisation could employ to stay One Step Ahead of the Hacker.

Felicity has spent her life immersed in technology and is passionate about ensuring companies build Resilience right into the core of their strategy and architecture. She understands the importance of Transformation into the Digital World as well as the risks of not having services available. Felicity started her career as a hacker, and has worked for technology giants for over 25 years, in that time she has worked and advised Companies, Governments and Standards bodies on the emerging IT trends and ensuring integrity and sustainability is baked into the heart of IT.

Felicity has a wealth of expertise and experience throughout her career and her insights and perspective are refreshing. She also is an advocate of driving STEM skills in to the younger generation and is an active mentor and coach to the next generation of technologists.

Felicity lives in Winchester with her family, three dogs and not enough motorbikes.

View Details

How can Blockchain improve trust, security, and compliance? Can the decentralised nature of this technology be the missing piece in solving cybersecurity challenges?

Listen in to this panel of security luminaries where they will discuss: -Key considerations for leveraging the blockchain in the age of GDPR -What sort of infrastructure must be in place to ensure a secure environment? -Is the blockchain itself secure? -How do you build a trust network around the blockchain? -What are some of the cybersecurity challenges that can be mitigated and managed by the blockchain?

View Details

Does your organization have a data breach response plan? Discover the best practices for breach response and how to strengthen your organization's cyber resilience.

Join this interactive Q&A panel with top security experts as they discuss: - The latest trends in data breach protection - Who's most at risk - How to detect breaches faster - What to do and not to do when it comes to breach response - Recommendations for CISOs for improving security

Speakers: - Michelle Drolet, CEO, Towerwall - Dave Klein, Sr. Director Engineering & Architecture, GuardiCore - Matthias Maier, Technical Evangelist, Splunk - Mike Trevett, Director, UK&I, FireEye

View Details

With the ever-increasing frequency and sophistication of security threats to organisations, business leaders need to have a comprehensive data security strategy to protect themselves. Information security practitioners have to think and plan beyond existing protection capabilities that are aimed at preventing threats only. Today's cyber security strategies need to protect an organisations mission critical assets in a way that is:

‒ balanced, providing a mixture of informative, preventative and detective security controls that complement each other ‒ comprehensive, providing protection before, during and after threat events materialise into security incidents ‒ end-to-end, covering the complete information life cycle.

This will enable organisations to match the protection provided with the sophistication of threats to such mission critical information assets. This webinar will look at past and present models and share ideas on how organisations can ‘future proof’ their strategies to combat next generation threats.

In particular in this webinar, Nick Frost, Principal Consultant at the ISF will discuss what actions can be taken to identify your most critical information assets, and how a modern day cyber security model needs to focus on prevention and detection of a data breach, and how to respond to a breach in order to reduce damage to brand and reputation.

View Details

With the change in the data protection laws, in the UK, SME businesses must start to embrace the need for a cyber security strategy. No longer is “cyber security” an elitist term that fills the corridors and board rooms of large enterprises.

As part of BrightTALK's Data Breaches and Effective Response Summit, we will look to dispel this misconception and help SME business owners understand what they can do to begin to protect and help mitigate the risk of a Cyber Attack against them.

This webinar will cover the following topics: - What are the fundamentals that SMEs should be putting in place - Case Studies: Learning from previous data breaches - Proportionately remediating against gaps in security - Taking some practical steps to get you started

View Details

During this presentation, Felicity will demonstrate how to mitigate the impact that data breaches has on affected businesses and individuals.

Felicity has spent her life immersed in technology and is passionate about ensuring companies build Resilience right into the core of their strategy and architecture. She understands the importance of Transformation into the Digital World as well as the risks of not having services available. Felicity started her career as a hacker, and has worked for technology giants for over 25 years, in that time she has worked and advised Companies, Governments and Standards bodies on the emerging IT trends and ensuring integrity and sustainability is baked into the heart of IT.

Felicity has a wealth of expertise and experience throughout her career and her insights and perspective are refreshing. She also is an advocate of driving STEM skills in to the younger generation and is an active mentor and coach to the next generation of technologists.

Felicity lives in Winchester with her family, three dogs and not enough motorbikes.

View Details

You've got firewalls, antimalware, next-generation endpoint security, and NAC. You're rolling out CASB and analytics, and extending protection to cloud, mobile, and IoT resources. But how does it all come together?

This webinar reveals what a next-generation security architecture looks like--and which technologies, and vendors, should be part of it.

View Details

This webinar is part of BrightTALK's Privacy Insights Series.

Join privacy and cyber security experts for an interactive discussion on: - What is Privacy and why should you care - Why all of a sudden everyone cares about Privacy - User/Customer expectations and reality - Data breaches prevention and notification - Crafting your Privacy Policy - Best recommendations for organizations

Speakers: - Elena Elkina, Partner at Aleada Consulting - Bret Fund, CEO of SecureSet - Dr. Pierre-Andre Maugis, Data Scientist, Privitar

Audience members are encouraged to send questions to the speakers to be answered during the live session.

View Details

The scope of the 435 pages of the EU’s General Data Protection Regulation (GDPR) is vast and has raised the specter of excessive, unforeseen and unintended compliance consequences for companies around the world. In order to ensure individual privacy in the digital realm, there are numerous enterprise security requirements imposed by these regulations with significant compliance concerns, notification requirements and the potential for excessive penalties for non-compliance. Join Interfocus Technologies and security expert Richard Stiennon from IT-Harvest for an overview of GDPR’s implications on your security practices from a people, process and technology point of view. We will review the requirements for and processes to secure your endpoints, monitor and report on malicious user activity, and identify and trace where personal data resides in your network.

View Details

Dark Cubed conducted extensive testing and determined that many IoT “smart home” device manufacturers have failed to implement basic security protections in the design, development, and production of their products such as electrical plugs, light bulbs and security cameras.

Join CEO Vince Crisler for a live webcast as he discusses:

· The creation and operation of the closed testing environment to simulate smart devices in a real-world home

· The integration of Dark Cubed’s platform to capture and examine traffic patterns and message contents between each device, its back-end infrastructure and its Android app

· Detailed port communications profiles, Nmap scan findings, infrastructure port reviews, man-in-the-middle assessments, Android app permissions and profiles, and privacy policy reviews for these light bulbs, cameras, and electrical outlets

Learn more here: www.thestateofiotsecurity.com

View Details

What new security requirements apply to Persistent Memory (PM)? While many existing security practices such as access control, encryption, multi-tenancy and key management apply to persistent memory, new security threats may result from the differences between PM and storage technologies. The SNIA PM security threat model provides a starting place for exposing system behavior, protocol and implementation security gaps that are specific to PM. This in turn motivates industry groups such as TCG and JEDEC to standardize methods of completing the PM security solution space.

View Details

Michelle Drolet CEO of Towerwall will be discussing the need for developing a solid Incident Response Program and doing Tabletop exercise throughout the year. An Incident Response Plan (IRP) will ensure information security incidents, once identified, will be handled and communicated appropriately. Consistency of how incidents are handled and communicated is paramount to a successful incident response.

The IRP provides a quick, organized, and effective response to computer-related and physical security incidents. The IRP’s mission is to prevent a serious loss of information, information assets, property, and customer confidence by providing an immediate, effective, and informed response to any event involving your information systems, networks, workplace, or data.

Security incident response is an organized approach to address and manage activities during and after a security breach. The goal of security incident response is to handle any information security incident in an organized and effective manner that limits damage to the organization and reduces recovery time and cost.

View Details

Security professionals accept the paradigm of “more protection equals more false positives (FPs)” as a fact of life. The tighter they make the “screws” of the security policies in their DLP, Web or Email Gateways, UEBA, application control/whitelisting and AV tools, the higher the likelihood something benign is misclassified as malicious. That’s why it is not uncommon to see false positive rates exceed 5% using the most aggressive settings.

What if we were thinking about this wrong? Can we break this correlation between more security and more FPs?

During this webinar we will briefly review the definition of false positives, false negatives, true positives and true negatives, as well as the history of “more protection = more FPs” paradigm. Then we will turn the paradigm on its head and discuss how more protection can actually mean fewer FPs.

About the Speaker Nir Gaist, Founder and CTO of Nyotron, is a recognized information security expert and ethical hacker. He started programming at age 6 and began his studies at the Israeli Technion University at age 10. Nir has worked with some of the largest Israeli organizations, such as the Israeli Police, the Israeli parliament and Microsoft’s Israeli headquarters. He also wrote cybersecurity curriculum for the Israel Ministry of Education. Nir holds patents for the creation of a programming language called Behavior Pattern Mapping (BPM) that enables monitoring of the integrity of the operating system behavior to deliver threat-agnostic protection.

View Details

Join this post-Black Hat panel as we look at the biggest trends and cyber threats covered during the Black Hat Conference 2018 in Las Vegas.

Tune in for an interactive Q&A panel with industry experts across the security ecosystem as they discuss: - What are the biggest threats to security in 2018? - Key steps to take today to better secure your critical data assets - Top technological advancements powering security - CISO strategy in the age of breaches

Speakers: - Charles Tendell, Renown Cybersecurity Expert, Certified Ethical Hacker & Host of "The Charles Tendell Show" - Eddie Lamb, Managing Director, Cyber Security at 6point6 - Other Panelists TBA

The session is being brought to you in partnership with ITSPmagazine.

View Details

How do you go about defending a community that instinctively resists change and has the power to thwart you? You can try to alter human behavior, approach the problem through unobtrusive methods, or step aside and let a calamity educate the workforce. Since the last option isn’t really on the table while you are on the clock, a combination of the first two is the most likely approach. In this talk, we go through some readily implementable methods for narrowing the attack surface of your healthcare institution.

About the Speaker: Ian Schmertzler is the President and CFO of Dispel, a cyberdefense firm that specializes in building traceless, encrypted communications networks within which teams and datasets can operate free from targeted attack. He also has a sense of humor, which is a necessity in cyberdefense. Ian holds an MSc. in Industrial Engineering from Georgia Tech, and a BA from Yale.

View Details

Robin Smith reviews the progress and impediments to transforming UK health care services in the age of AI.

A specific focus is placed on the recent report by the UK-based Reform think tank and their 16 recommendations to overhaul current approaches to AI implementation.

The session also review two cases studies on how AI is beginning to transform information protection.

View Details

With increased security and privacy regulations such as the new EU GDPR, it is becoming more important to reduce the dwell time of incidents to be able to report those breaches in the required time. For example GDPR requires you to report them in 72 hours.

In this webinar, we will discuss how Security Analytics can help you do that including getting you ready for preventing, detecting and responding to breaches.

Join us to know how Security Analytics as a Service can give you a better insight to your threats as well as optimize your compliance costs.

View Details

Digital transformations have been increasing at a very high rate and are changing drastically traditional business models. Adding more convenience, businesses are expanding their attack surface without often being aware.

A shared-responsibility model misunderstood or misinterpreted leads to recent major cyber attacks or hacks. An S3 bucket exposed, or else, the risks are not addressed at all in some cases.

In this presentation, I discuss how to undertake a cloud transformation, and what are the security and privacy concerns that need to be addressed before even taking the decision of moving to the cloud or choosing a cloud service provider.

I define the steps where security and privacy must be considered within the decision-making process and the transformation. Lastly, I help businesses achieve a digital resilience with tips and clear best practices achieved through real-life examples and case studies.

The objective is to identify fundamentals that would help to address cloud risks in alignment with security requirements and legislation limitations.

View Details

Join this panel of industry experts as they share their experiences and thoughts on one of biggest security conferences in the world, Black Hat in Las Vegas, along with their expectations from this year's event.

Tune in for an interactive Q&A panel with some of the biggest names in infosecurity to learn more about: - What can security professionals learn during Black Hat week - Must-attend events and why - What's new on the cyber threatscape - Advances in technology - AI: Hype vs Reality - Common sense advice for CISOs - How to keep your employees cyber safe

The session is being brought to you in partnership with ITSPmagazine.

View Details

Threat Hunting is a complicated and often misunderstood cybersecurity activity that if properly used can add tremendous value to your cybersecurity posture.

In this session you will learn: What is Threat Hunting? When do I use it? What will it tell me? How do I use it? What are the legal implications?

Learn from the following leading experts: Juanita Koilpillai: Chief Technology Advisor, Digital Risk Management Institute Mark Rasch: Chief Legal Council,Digital Risk Management Institute Andrew Johnston: Associate Consultant,Mandiant

View Details

Innovation is the key to survival in today's Digital economy. Providing fresh content in new ways to broader markets is expanding the attack surface. The adoption of DevOps, cloud proliferation and enterprise IoT has added significant challenges to understanding your Cyber Risk.

In this webinar Casey Reid, Principal Security Engineer at Tenable will talk about: - Why there no such thing as "Secure" - How the "Race to Zero" is killing your productivity and increasing your Cyber Risk - How "Chasing the Zero Day" could be a big waste of time - What it takes to be Risk focused: Going from Zero to Hero

About the Speaker: Casey Reid is a Principal Security Engineer at Tenable, responsible for helping enterprise customers reduce their Cyber Exposure and strengthen their Vulnerability Management program. He is an energetic, outspoken, problem solver and hobby hacker with over 15 years of diverse technical experience. When he's not learning new technologies or hacking in his lab, he is competing at local CrossFit competitions and Obstacle Course Races such as the World's Toughest Mudder.

View Details

It's become a truism among cybersecurity professionals that there are two types of companies: those that have been hacked and those that will be. If cyber incidents are inevitable, what can organizations do to pro-actively minimize the impact on their operations? This session addresses considerations for organizations addressing cyber-risk at the strategic level.

View Details

It is beyond the ability or willingness of the world’s governments to protect and secure information technology. What role then can the private sector play in making cyberspace safer? Can private enterprises do anything to strike back at attackers, curtailing their freedom of action and raising the costs of malicious activity?

Consisting of academics and industry experts, this panel will explore the potential for active cyber defence to impede and deter malicious activity and the conditions under which it could be conducted responsibly.

Speakers: - Griff James, Director at Damrod Analysis - Wyatt Hoffman, Research Analyst, Cyber Policy Initiative at Carnegie Endowment for International Peace - Will Lymer, Chief Growth Officer at Loki Labs

View Details

Discover the trends in security analytics technology and how leveraging threat intelligence can help organizations on their journey to cyber resilience.

Join this interactive Q&A panel with top security experts across the ecosystem to learn more about: - What's new on the threatscape - How to leverage security analytics to investigate and hunt modern threats - How cyber threat intelligence helps organizations understand their risk of external threats - CISO recommendations for improving security

Speakers: - Anupam Sahai, Vice President of Product Management, Cavirin - Setu Kulkarni, VP Product & Corporate Strategy, WhiteHat Security - Yiyi Miao, VP Products, OPSWAT

View Details

Cybercriminals are constantly innovating ways to infiltrate your organization, and steal your valuable data. With an ever expanding attack surface, security professionals are struggling to secure the enterprise.

Join this roundtable discussion with top security experts to learn more about: - What's new on the cyber threat landscape - Why cyber threat intelligence Is more critical than ever - How to prevent and protect against breaches - What tools and approaches should security teams use - Why network visibility and actionable data about attackers is key - Best practices and expert recommendations on improving your enterprise security

Speakers: - Sushila Nair, Sr. Director, NTT DATA Services - Sergio Caltagirone, Director of Threat Intelligence, Dragos - Chris Sestito, Director of Threat Research, Cylance - James Felix Ignacio, Founder & CEO, JFI Cyber Solutions

View Details

Running a security operations is not a simple undertaking. It takes skilled staff, technology, processes and procedures and loads of practice. In addition, actionable contextual threat intelligence is key when it comes to ensuring the SoC and its teams are affective in early detection of attacks.

The key word here is EARLY detection. Join Amar Singh and his special panelists as they discuss some of the key pillars of threat intelligence and how to make them work in any SoC environment.

View Details

Cybersecurity professionals do a great job when it comes to understanding, and mitigating, technical and functional risk.

But CEOs and board members tend to think in terms of business risk. This webinar shows cybersecurity professionals how to articulate requirements in business terms. With that knowledge, they can build the case for cybersecurity tools, staffing, and initiatives in a way that business professionals will understand--and fund.

View Details

Although overused, Next Generation Security still means keeping up with the challenges of securing today’s networks. The fundamental rule of keeping up with those challenges is having both a vision and an architecture that provides the foundation, regardless of how the market or the threats themselves change.

This session will focus on what is needed in an evolving security architecture to provide Next Generation Security in a constantly changing environment.

View Details

Join this webinar to hear from past students and current champions discuss how the SANS CyberTalent program is changing lives and closing the workforce gap. The cybersecurity workforce gap can be partly solved through increasing diversity. Organizations like SANS CyberTalent and the WSC are reaching into communities throughout Maryland and the US searching for professionals with technical appitude but new to cybersecurity.

These academies are designed to help qualified veterans and women receive training and certifications to quickly and effectively launch careers in cybersecurity. The Immersion Academy is an intensive, accelerated program designed for completion in six to eight months, depending upon program selected. The program is at NO COST to the students selected.

Come listen to learn: • What the selection process includes and important application tips • Understand what kind of training is provided (length and format) • Hear from a recent graduate who will share her experience • How this training academy and related certifications can help your career

View Details

With hundreds of different requirements, the various Payment Card Industry (PCI) standards can be overwhelming. While the PCI Security Standards Council has provided lots of answers, the devil is often in the details. Our panelists are some of the top PCI QSA’s in the country, with decades of combined PCI and card processing experiences. They’ve seen it all: the good, bad and ugly; and lived to tell the tale.

Join Ben Rothke, David Mundhenk, Arthur Cooper, and Jeff Hall for an interactive Q&A session, and get answers to your most vexing PCI questions. No PCI question is out of bounds.

Speakers: - Ben Rothke, Principal Security Consultant at Nettitude - David Mundhenk, Senior Security Consultant at Herjavec Group - Jeff Hall, Principal Security Consultant at Optiv Security - Arthur Cooper "Coop", Senior Security Consultant at NuArx

View Details

In the past few years manufacturers have been taking products that have existed for years or decades already and decided to put computers in them and connect them to the Internet. From cars, to smart home devices like Echo, to smart meters, to elevators, there has been orders of magnitude more devices that are now connected.

The problem is that, in most cases, you can't make any real changes to them so how do you apply controls and maintain the security of your network with thousands of these devices now being connected that you may not even be able to log in to? There are perceptions of what threats these devices can pose, but there are life-safety risks that are not adequately addressed.

View Details

The business model around many IoT devices leads naturally to a situation where many can be exploited by malicious code to create botnets with minimal opportunity to monitor them.

Even though there are companies which are taking action, the existence of any “defector” from a secure standard creates problems. Coordinated government action, at least incorporating kitemarks, is needed. But the nature of software could mean that even that is a forlorn hope.

About the Speaker: Charles Arthur is the author of Cyber Wars: Hacks That Shocked the Business World, published by Kogan Page. He is a journalist who has been writing about technology, science and medicine for over 20 years, most recently as technology editor at The Guardian from 2005-2014 and previously from 1995-2004 at The Independent. He lives in Essex.

View Details

The IoT landscape is exploding, with predictions of more than 20 billion connected objects worldwide by 2020. But protecting and securing data, devices and services in this dynamic, ever- expanding landscape presents significant challenges. Many of today’s connected objects do more than simply provide information at your fingertips – they can make use of sensitive data, gather information and even impact the physical world. Because of this, there is a need for ubiquitous end-point security, regardless of the use case, to prevent devices from becoming a platform for attacks.

To be able to trust today’s digital services and devices, the IoT ecosystem needs to be built on a proven security foundation. Years away, right? Wrong. GlobalPlatform Specifications are readily available to the IoT community today, to protect service providers, device manufacturers and consumers on the edge.

In this presentation GlobalPlatform, will provide an overview of: - The increasingly urgent need for robust security in IoT objects and the principles that must be addressed if the IoT market is to fully evolve; - The value that GlobalPlatform specifications and frameworks deliver to IoT stakeholders to address their security and privacy concerns; - How GlobalPlatform’s new Device Trust Architecture framework empowers all actors in the value chain to seamlessly deliver, and securely manage, digital services and devices.

View Details

With an increase of IoT adoption and a 99% connectivity by 2020, users, including businesses of IoT technology must consider the impact on privacy and security of those new gadgets. In fact, we are exponentially increasing our risk surface, in alignment with the growth of connected end points.

Did you ever asked your manufacturer, are you adopting a Privacy and a Security By Design approach?

Nowadays, with the data breaches on the first page of all magazines, we clearly are doing it all wrong, and are unable to protect our systems and data properly.

How are we going to tackle the challenges of an interconnected complex ecosystem, interacting with billions of ''gadgets'', across networks and systems?

In this talk, you will hear from one of the advocates of cyber security inclusion and diversity, how to prepare or get yourself cyber ready in an era of unknown threats.

View Details

The internet of everything is around us whether we like it or not. Organisations are increasingly relying on IoT for all aspects, making the need for auditing IoT increasingly critical.

Join this interactive webinar to: - Understand current and potential IoT usage - Appreciate the concerns that will need to be addressed - Establish audit considerations for IoT - Learn how to conduct IOT audits based on a framework approach.

View Details

This webinar will explore the end-to-end IoT architectures that are in use today. This will be done from a security perspective, itemizing the vulnerabilities that are present at each level of the architecture.

Kevin McNamee of Nokia's Threat Intelligence Lab will then take a detailed look at actual exploits of IoT vulnerabilities from field cases over the past couple of years. The webinar will conclude with a summary of actions that can be taken to reduce the risk of cyberattack and subsequent compromise of IoT devices.

About the Speaker: Kevin McNamee heads up Nokia's Threat Intelligence Lab. This lab analyzes thousands of mobile malware samples each day to create the detection rules that power Nokia’s network based malware detection system. Previously at Alcatel-Lucent he was director of Security Research with Alcatel-Lucent's Bell Labs, specializing in the analysis of malware propagation and detection. He has had speaking engagements at RSA, BlackHat, SECTOR, (ISC)2, Virus Bulletin and BSides.

View Details

Artificial Intelligence, machine learning, and deep learning are the raves in network security. It's perceived as the only practical approach to staying ahead of today's cyberthreats.

The various steps used by Artificial Intelligence is not so different than a physician’s approach to treating a patient. You must first understand the patient (or device), monitor and assess that all organs (or components) are behaving as intended, and proactively treat (or remediate) viruses and other harm.

In this session, Dr. May Wang will explore: - The latest advancements in AI for IoT security using healthcare as an example - The top security threats to healthcare organizations and how to address them.

View Details

How do hackers infiltrate organizations through IoT connected devices? What can be done to prevent the next attack via an IoT device? Why can a weakened link in the IoT chain lead to compromised digital assets? The Internet of Things (IoT) is bringing convenience to consumers and process optimization to businesses, but it comes at a cost. Exploding onto the IT scene and the consumer world, it has created endless opportunities for a super-connected environment. But IoT could also signal the next security crisis. IoT formed a rising tide of shadow IT and a new frontier to data security vulnerabilities, in an ever-expanding attack surface.

By joining this webinar with XM Cyber’s Security Expert, Amit Waisel, you will learn about the perils of an expanding attack surface and what can be done to prevent an APT attack via an IoT connected device. We will dive into hard core questions including: - How an ever-expanding IoT attack surface is creating multiple opportunities for the perfect attack vector to digital assets - Why an innocent aquarium thermometer, defibrillator or printer is a possible gateway to disaster - Steps you can take to avoid a potential crisis

About the Speaker Amit Waisel is a Senior cybersecurity Engineer at XM Cyber. He is a seasoned data security expert with vast experience in cyber offensive projects. Prior to XM Cyber, Amit filled multiple data security positions in the Israel intelligence Corps. He graduated from the Open University with a BSc. in Computer Science and is currently completing a MSc. degree in Computer Science at Tel Aviv University.

View Details

To succeed with innovation at speed, IT organizations must accelerate their release velocity - and do it with greater quality, security, and availability! Enter DevOps! For most organizations, the transition to DevOps starts small, in a single team or a new project with cobbled-together open source solutions with security often an afterthought, leading to an extensive threat landscape.

To scale effectively, deploying daily or hourly (or even more frequently) requires organizations treat security as a first-class citizen – engaged in all aspects of the development and deployment lifecycle.

Robert will share market trends, tips and techniques to incorporate security into the complete DevOps lifecycle – delivering DevSecOps.

View Details

It is critically important to know how cyber criminals target their victims, what you can do to reduce the risk and make it more challenging for the attackers who steal your information, your identity or your money.

This session explains how outside attackers or malicious insiders can exploit vulnerabilities using examples such as a compromised email account password that escalates into a full-blown breach of network security and how a light bulb almost stopped Christmas from happening.

  • This session describes the anatomy of a privileged account hack
  • The risks of introducing IoT for ease of use but sacrificing security
  • We will show how cybercriminals target their victims
  • What you can do to reduce your risk and prevent abuse of your critical information assets

View Details

Internet of Things devices are built with cost & convenience in mind, not security. This makes them easy targets for cybercriminals looking to exploit their vulnerabilities and infiltrate your systems. With IoT adoption on the rise, organizations are looking for ways to improve security at all levels and limit the damage IoT-powered cyber attacks can cause. The stakes are even higher for the Industrial Internet of Things (IIoT).

Join this interactive Q&A panel with top security experts across the ecosystem to learn more about: - IoT as a gateway to your systems - Key factors for building a successful security strategy encompassing the IoT & IIoT - Threats targeting the IoT / IIoT - Industrial threat detection and response - Recommendations for improving security

Speakers: - Mark Weatherford, Chief Cybersecurity Strategist, vArmour - Robert M. Lee, CEO, Dragos - Jennifer Minella, VP of Engineering and Security, Carolina Advanced Digital

View Details

Small businesses face great threats from cyber attackers every day, and do so with a fraction of the resources that mid-sized companies and large corporations have at their disposal. A small business’s network, its customer data, and its intellectual property is just as critical to its operation as a firm 100 times its size, but it lacks the skills, the processes and the technology to keep pace with ever-present cyber threats and defend itself. Join us for this session where Dark3 experts will outline how small businesses can protect themselves effectively by taking advantage of the confluence of cloud-based technologies, scalable automation and enterprise-grade cybersecurity expertise.

View Details

Join security expert Kalani Enos for an interactive Q&A webinar on the latest trends in IoT security. Discover how effective IoT threat modeling and data privacy affects your organization.

Viewers will learn more about: - Current IoT challenges - How businesses are and are not recognizing security and IoT - How IoT Threat Modeling is imperative for businesses who utilize, or plan to utilize IoT products and services within their organization - Data Flow Diagrams and specific use cases where IoT Security is necessary - IoT Security requirements from a regulatory / data privacy perspective

View Details

Security is an important aspect of IoT and especially Industrial IoT systems (short: IIoT). It is not yet fully championed as shown by a number of incidences which became publicly known.

One particular facet of the IIoT security challenge is given by the fact that widely used security solutions from the IT domain cannot be just copied-and-pasted to IIoT – due to differences in given constraints and needs.

Join this webinar presentation to learn more about: - The IIoT security challenge - In-depth look into the architectural approaches to IIoT Security - Emerging solutions, as well as standards for IIoT security

About the Speaker: Oliver Pfaff is a Principal Key Expert at Siemens, serving the technology field IT-Security at Corporate Technology. Oliver’s work concerns security in distributed systems. Oliver‘s current projects address the security-enabling of Industrial Internet-of-Things as well as Operational Technology systems and products.

View Details

Discover the latest trends in cyber attacks targeting the Internet of Things and how to protect your connected devices and networks from cyber criminals.

This interactive panel will explore in detail: - The top IoT vulnerabilities - The biggest cyber threats on the horizon - What keeps CISOs up at night - The best practices when it comes to building a resilient enterprise

Speakers: - Joseph Carson, Chief Security Scientist, Thycotic - Robin Smith, Security Futurist/ Coriel Security - Robert E. Stroud, CGEIT, CRISC; ISACA Past Board Chair and Director; Chief Product Officer, XebiaLabs

View Details

Join us for this 45 minute webinar on 7th June at 10am UK that will ensure that your Business is Seamlessly Up and Running in Minutes. Understand how Ultimate Damage Limitation for Cyber-Attacks is Achieved through Business Continuity within Software-Defined Storage.

Reasons to attend:

Severity of cyber-attacks are judged by the length of time critical systems, data and applications are down. The ability to have a Business Continuity and Disaster Recovery enabled infrastructure mitigates the risk, offering zero downtime, zero Recovery Point Objective, and seamless rollback in time to the point before the attack hits.

Joining the webinar equips you with 3 essential skills for damage limitation:

Learn how to:

  • Implement multi layered protection that offers
  • Achieve additional resiliency with disaster recovery to the Cloud and 3rd Site
  • Rollback to the point immediately before the attack

Your host for the meeting, Garry Carpenter has immersed himself in all things business continuity for the past few decades and is one of the leading UK authorities in the field.

View Details

Data breaches are on the rise, affecting millions of people around the world. With personal information exposed to cyber criminals and up for sale, the impact of a breach can continue to haunt its victims for months, and even years to come.

Join top security experts for this interactive Q&A panel as they discuss: - The current (broken) state of security and the role identity plays in cyber-attacks - Zero trust framework: Guiding principles and paradigms - The massive rethink underway that redefines security to follow identity - What you can do today to adopt a Zero Trust model and reduce risk through the power of next-gen access - Recommendations for prevention of data breaches

Panelists: - Amar Singh, CEO & Founder, Wisdom of Crowds, Cyber Management Alliance - Barry Scott, CTO – EMEA, Centrify - Nick Bilogorskiy, Cybersecurity Strategist, Juniper Networks - Raef Meeuwisse, ISACA Expert Speaker & author Cybersecurity for Beginners

The session will be streamed LIVE from London from the Infosecurity Europe conference.

View Details

IoT, IIoT, OT... It is likely that for many of us these acronyms are confusing. The fact is that traditional industrial environments, such as utilities and production, have started a digital transformation process which harness these and other technologies to become more efficient, automated and competitive.

Within this transformation from a well-defined and well-controlled industrial ecosystem to a dynamic and open one, lurks a shift in the security challenges, needs and solutions/architecture.

This session will focus on the technologies and challenges digital transformation introduces in industrial environments and how Fortinet’s Security Fabric is deployed in such an environments to provide the required security infrastructure and posture, including demonstration of some simplified use cases.

View Details

For many organisations, it will be a legal requirement to have a Data Protection Officer. Even if you may not have a legal requirement, it will be useful to have a person responsible for Data Protection.

Join this presentation to learn more about: - Challenges faced by organisations on deciding whether they should have a DPO - How to choose a DPO (full time or consultant) - The expectations from the role