[1 CPE] The Good, the Bad, and the Ugly of Vetting Applications

  Presented by Eric Walters • Chief Information Security Officer, Burns & McDonnell

What level of access are applications requesting and then receiving directly from your employees? Is the security team aware? Has the risk been quantified? Who is looking at the application Terms and Conditions or the End User License Agreement? Is the access overly permissive? What happens if the application vendor is hacked? Can the attacker access your data? Is the vendor liable?

Eric Walters, CISO and Director of IT Operations at Burns & McDonnell, will discuss these and many more perils and pitfalls of vetting applications and plugins.

Eric Walters is a seasoned information technology leader with over 25 years of security experience. He is capable of translating IT details into executive-level business decisions. Eric believes good compliance does not mean good security, nor does good security mean good risk management. Passionate for employee development. His experience includes healthcare compliance, software development, information security program management, cyber security managed services, global transition operations, infrastructure cloud operations, enterprise architecture, and document management, and is a retired Marine Officer.

[1 CPE] Disrupting the Means to Prevent the End: A Guide to Detecting Ransomware

  Presented by Red Canary

Ransomware has been a dominant cybersecurity threat for the better part of the last decade. However, it doesn’t walk alone. It’s almost always the eventual payload delivered by earlier-stage malicious software or activity. Luckily, if you can detect the threats that deliver the ransomware, you can stop the ransomware before it arrives.

In this talk, we’ll extensively reference Red Canary’s 2022 Threat Detection Report, examining the malware and other malicious tools that adversaries often use to deliver ransomware. While the specific trojans and strains of ransomware may change from one attack to the next, adversary tactics, techniques, and procedures are often similar across campaigns and threats. By developing robust detection coverage for the techniques adversaries abuse most often, rather than focusing on individual threats, security teams can achieve defense-in-depth against the many threats that leverage those techniques and the broader trends that dominate the infosec landscape.

Want to learn more about the prevalent adversary techniques and threats that can lead to a ransomware infection? Attendees will leave with:

  • A better understanding of the threats and tools that commonly precede a ransomware infection
  • Guidance on relevant collection and data sources that offer visibility into the threats and techniques that adversaries use to deliver ransomware
  • Actionable information on how security teams can develop the capacity to detect, prevent, and mitigate ransomware and other threats
  • Strategies for testing their ability to observe and detect common threats with free and easy-to-use tools like Atomic Red Team

[1 CPE] Chasing Cloud Security Maturity Amid Constant Headwinds of Change

  Presented by Check Point

Covid and the push to accelerated ‘remote first’ strategies have forced organizations to leverage on-demand cloud infrastructure, often without the proper design, architecture, and security strategy in place to scale safely. In addition, infrastructure as a service providers are innovating very quickly and building high-value services for us to leverage in our application architectures. Lastly, we are challenged more than ever by a lack of mature cloud skillsets available to hire. These factors add up decisions with resources, identities, and access that put our most sensitive secrets at risk. As new and innovative cloud capabilities are introduced, so too are security innovations, both in technology and process.

Grant Asplund, Growth Technologies Evangelist, will discuss the evolution of Cloud security including headwinds, issues, challenges, and concerns companies can expect to be confronted with as they pursue reaching security maturity in the Cloud.

[1 CPE] The State of the Cyber Insurance Market: How to Plan for Uncertain Future

  Presented by Arctic Wolf

Organizations have come to rely on cyber insurance to mitigate the impact of increasingly sophisticated, disruptive, and widespread cyber-attacks. As a result, insurers are issuing more policies, and the amounts of protection available are increasing. In 2020, the global insurance community saw the first cyber insurance program that exceeded $1 billion in coverage.

Join this session to hear why:

  • Insurers are rethinking cyber coverage and claims in the wake of increasingly aggressive cyber-attacks.
  • Businesses are likely to see their cyber insurance premiums increase, or even see some cyber security coverage dropped entirely.
  • Leaders should consider risks and mitigation strategies as they assess their readiness and liability when it comes to breaches or attacks.

[1 CPE] Navigating Today’s Threat Landscape: A Current State of Cybersecurity

  Presented by Fortinet

Join this session for a comprehensive look at the current state of cybersecurity. Today’s ever-evolving threat landscape requires an integrated, automated approach to security. Learn how you can mitigate risk in your organization, optimize your security team’s operations, and gain best practices to integrate and consolidate your security tools; whether you’ve taken a multi-vendor or single-vendor approach.

[1 CPE] Educating Your Guesses: How to Quantify Risk and Uncertainty

  Presented by Novacoast

Asking for a budget and justifying spending in cybersecurity departments can be a difficult task due to limited data and high uncertainty of future events. This talk will dive into quantitative risk analysis as it relates to cybersecurity: how to model uncertain events and understand financial risk. Attendees will see a first-hand demonstration of how quantitative modeling can be used to communicate risk and understand ROI. Attendees will walk away with the tools needed to present cyber risk as a dollar amount that can be easily understood by other business decision-makers at their company.

[1 CPE] 2022 Threat Review

  Presented by Malwarebytes

The Malwarebytes 2022 Threat Review is an annual report on the latest threats, attack trends, and privacy breaches impacting individuals, organizations, and national security. Researchers detail threat intelligence across operating systems and examine how privacy has shifted and the ways that cybercriminals and crimes are evolving. With a stronger understanding of the threat landscape, organizations and individuals can make more informed security and cyber-protection decisions.

[1 CPE] Stopping Attacks, Not Your Business: AI & Autonomous Response

  Presented by Darktrace

With cyber-attackers continuously searching for new ways to outpace security teams, it can lead to a struggle to fight back without disrupting business operations. Join Maxwell Hopkins in this session where he explores the benefits of Autonomous Response as a must-have that goes beyond ‘defense’. Includes real-world threat finds and attack scenarios.

[1 CPE] Building a Modern Cyber Security Program: Zero Trust

  Presented by Sanity Solutions

Join Chad Schamberger, Director of Cyber Security at Sanity Solutions, to discuss key guidelines for incorporating Zero Trust into your existing security posture. In this session, you’ll learn about enabling controls that follow the 7 disciplines of a Modern Cyber Security Program that will establish a Zero Trust Security Model.

[1 CPE] Visibility is Key: What You Need to Know About Cloud Migrations and Security

  Presented by ReliaQuest

The pace of cloud technologies adoption has left security operations teams scrambling to keep up with the change. Many teams are unsure how best to protect their business as sensitive data and assets move beyond the traditional enterprise perimeter.

Is cloud security different from traditional on-premises security and if so, what should you be aware of? How best should you approach it?

We address these questions and more on how best to secure your cloud environment. We will explore recommendations on how best to secure the world’s top cloud platforms and providers including Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure, and multi-cloud environments.