In the post pandemic era, remote employment is the new status quo. Employers are forced to implement and improve the digital workplace by providing productivity tools and accessibility to company resources. In this session, we will share case studies of successful digital workplace implementations, including how to deal with the inherent security risks of expanded accessibility to company resources.
CXO Summit
The Future of IT & Cybersecurity
Speakers
November 9, 2022
Attend this event
Agenda
All times Eastern Time
8:45 AM - 9:30 AM
Registration & Breakfast
10:00 AM - 11:00 AM
Panel
The “New” Workspace
Panelists
Adam Fishman
Strategic Advisor to Small & Mid-Sized Businesses
AMF Advisors
Martin Howard
EVP/IT & IS
Fortium Partners
Kathleen Hurley
CIO
Sage Inc
Aruna Ravichandran
SVP & CMO - Enterprise Networking, AI
Cisco
11:00 AM - 11:35 AM
Keynote
Application Security in a DevOps, Cloud and API World
Security teams are challenged to modernize application security practices in light of accelerating shifts to DevOps delivery models and rapid adoption of cloud-native application designs. Applications built on microservices (e.g. serverless, containers, APIs) and delivered continuously are outpacing application security teams ability to secure them. CISOs need to consider new skills, new touch points and new platforms to maintain a strong security posture in light of these trends and the speed at which they are re-shaping IT.
11:35 AM - 11:50 AM
Networking Break
11:50 AM - 12:45 PM
Panel
Operationalization: Bridging the Divide between Knowledge and Action
Knowledge is power, and yet, knowing is not enough. Security teams are well aware of the vital role played by threat intelligence within the modern security stack. Too often, TI is underutilized, funneled through manual processes to the desks of security analysts and researchers, and not operationalized to drive automated cybersecurity processes and actions.
Why is this knowledge lost in translation on the way to action? Is it due to the overwhelming quantities of data? Is it because of conflicting information? Is it related to concerns about false positives? If we succeeded in operationalizing sensor-driven telemetry data in vehicles to autonomously drive cars, why aren’t we as successful in operationalizing threat intelligence data to drive autonomous cybersecurity actions?
Panelists
Avishai Avivi
CISO
Safebreach
Michael Woodson
Director of Information Security
Sonesta International Hotels Corporation
Cecilia Li
CIO
Urban Edge Properties
Anne Marie Zettlemoyer
CSO
CyCognito
12:45 PM - 1:50 PM
Fireside Chat
Lunch & Fireside Chat
BEC - FBI calls it the $43B* heist. How to tame this beast?
According to the FBI’s recent IC3 report in 2022, exposed business loss due to BEC accounts for > $43B. Why? At the heart of it, the biggest fear is not the technology, it is the potential of human error that could expose your organization to a cyberattack. The majority of CISOs agree that an employee carelessly falling victim to a BEC/phishing scam is the most likely cause of a security breach. Most also agree that they will not be able to reduce the level of employee disregard for information security. How do we guard against human error without limiting employee efficiency and productivity?
Panelists
Devon Bryan
Global CIO
Carnival Corporation
Scott Dillon
CEO, Digital Evangelist, Board Advisor & Investor
Anand Raghavan
Co-Founder & CPO
Armorblox
1:55 PM - 2:50 PM
Panel
Building Security into DevSecOps
Many organizations struggle with how and where to introduce automation and integrations efficiently. Conventional approaches to application security can’t keep pace with cloud-native environments that use agile methodologies and API-driven architectures, microservices, containers, and serverless functions. Application security testing is evolving to meet the speed at which DevOps teams operate. DevSecOps teams are challenged with how to make sense of the noise their AppSec tools generate once they’ve been automated into DevOps pipelines.
Processes and tools are more fast-paced and rely on integration and automation to maintain efficiency throughout the software development life cycle. A new approach to DevSecOps is required addressing a change in the security mindset. How do CISOs achieve this without the buy-in from stakeholders?
Panelists
Leo Cunningham
Former CISO
Flo Health Inc.
Anthony Gonzalez
CISO NA
QBE North America
Nick Diieso
Director, Global Head of Operational Risk
Citi
Jason Stutt
CRO
ArmorCode
2:55 PM - 3:45 PM
Panel
The Greatest Fears?
The biggest fear is not the technology, it is the potential of human error that could expose your organization to a cyberattack. The majority of CISOs agree that an employee carelessly falling victim to a phishing scam is the most likely cause of a security breach. Most also agree that they will not be able to reduce the level of employee disregard for information security. Identity security is business essential for modern enterprises, but the ability to do it effectively has moved well beyond human capacity. How do we guard against human error without limiting employee efficiency and productivity?
Panelists
Shamla Naidoo
Head of Cloud Strategy & Innovation
Netskope
Ben Cody
SVP Product Management
SailPoint Technologies Inc
Anna Thomas
Director Operations & Technology Transformation
Citibank
Scott Dillon
CEO, Digital Evangelist, Board Advisor & Investor
3:50 PM - 4:05 PM
Networking Break
4:15 PM - 5:10 PM
Panel
Security Controls: Measuring Efficacy for the Business Growth
The industry is spending record amounts on cybersecurity tooling, but somehow CISOs still are at times left scrambling to respond to the vulnerabilities like Log4j. Assuming that these types of critical and far-reaching events are inevitable, how can CISOs further improve their organization’s preparedness for future cyberattacks?
This panel will discuss potential strategies for determining the critical security controls - both technology and behavioral - that can minimize cyber-risks and give the organization the competitive advantage to grow and innovate. We will explore frameworks for measuring the efficacy of cybersecurity investments, and KPIs that show the board the investment is safeguarding the company's digital infrastructure for the long term.
Panelists
Scot Miller
SVP & CISO
Mr. Cooper
Susan Koski
CISO
PNC
Alex Shulman
Managing Director, Cloud Security
Ernst & Young
David Geevaratne - NO LONGER W/ COMPANY!!!
SVP of Sales
Uptycs
5:15 PM - 6:10 PM
Panel
Detect Imposters and Rogue Insiders in Business Applications
The risks posed by rogue insiders and external attackers make application detection a massive pain point for enterprises, especially in regards to core business applications. Examples are a fraudster’s takeover of a checking account via social engineering, or a customer service agent modifying an insurance policy to add themselves as a beneficiary, or a salesperson downloading a report of all customers before switching to work at a competitor. This panel will explore the growing need for application detection and the challenges posed by current rule-based techniques.
Panelists
Michael Gross
Manager, Cybersecurity Intelligence
Cleveland Clinic
Laura Deaner
CISO
Northwestern Mutual
Charles Blauner
CISO
Cyber Aegis
Doron Hendler
CEO & Co-Founder
RevealSecurity
6:15 PM - 6:30 PM
Disruptor
The Road to SaaS Governance: Centralize & secure application management
The acceleration of cloud adoption has reached a point where today, 39% of all applications are SaaS. Because of decentralization and a low-friction model of payment and usage, SaaS applications will continue to replace on-prem software rapidly. But with decentralization comes chaos. Governance & management around SaaS is still largely lagging behind. CIOs and CISOs currently don’t have visibility or control, leading to Shadow IT & disjointed IT (SaaS) Ops.
To help IT leaders get a hold of their SaaS stack, we’ll present a full-fledged discovery and management framework that seamlessly integrates control systems for SaaS within the modern IT technology landscape.








