[1 CPE] Educating Your Guesses: How to Quantify Risk and Uncertainty

  Presented by Sara Anstey, Director of Data Analytics and Integration • Novacoast

Asking for budget and justifying spend in cybersecurity departments can be a difficult task due to limited data and high uncertainty of future events. This talk will dive into quantitative risk analysis as it relates to cybersecurity –– how to model uncertain events and understand financial risk. Attendees will see a first-hand demonstration of how quantitative modeling can be used to communicate risk and understand ROI. Attendees will walk away with the tools needed to present cyber risk as a dollar amount that can be easily understood by other business decision-makers at their company.

[1 CPE] Thirty Years of Arguing with Adults

  Presented by Paul Dant, Senior Director of Cybersecurity Research • Illumio

In this talk, you’ll hear hilarious stories from a former child hacker that eerily predict the treacherous security landscape of today. Do you want to know why we’re still losing to ransomware? Attend this talk to find out and get insight into how you can start actually solving security problems and prepare your organization for the inevitable breach.

Paul has been coding and hacking since 1987. As a security researcher, he has performed offensive security testing of facilities ranging from nuclear energy plants to hospitals to tent-pole film sets. He’s presented to countless audiences the realities of cyberattacks, the hacker mindset, and new paradigms to address the potentially life-impacting threats we are faced with today.

He is currently the Senior Director of Cybersecurity Research at Illumio, where he works across industries to help organizations understand how to protect their critical assets in the “assume breach” mentality of zero trust.

[1 CPE] Cyber Security is National Security

  Presented by Kenneth A. Schmutz, Supervisory Special Agent • FBI

Cybersecurity is one of the FBI’s highest priorities. Our strategy is multifaceted. We take aim at the actors, disrupt their operations, and go after their money. One of the most important actions a business can take in preparing for a cyber security incident is to make a cyber incident response plan and include the FBI in that plan. When the FBI quickly engages with a company hit by a cyber-attack, we’re able to share indicators that help network defenders identify malicious activity and intelligence about the actors that inform a company’s decision-making during a crisis. As the cyber threat has evolved over the past 20 years, one thing has remained the same: The FBI is at the center of acting on cyber threat information to provide support to victims and impose costs on cybercriminals.

[1 CPE] Consolidate Tech to Improve Performance and Security

  Presented by Steve Troxel, Public Sector Field Solutions Engineer • SHI & Sophos

A lack of integration between vendors and platforms can make systems less reliable, less secure, and more expensive than they should be. This session will focus on changes in on-premise and cloud-based solutions in IT infrastructure that can allow administrators and systems engineers to reduce the burden of maintaining disparate solutions through effective consolidation and integration. Join Steve Troxel of SHI in discussing how these approaches can help address gaps in IT staffing and facilitate a more strategic focus on the use of technology to the business itself.

[1 CPE] How AI Can Think Like an Attacker

  Presented by Darktrace

In the face of skyrocketing cyber risk, detecting and responding to attacks is no longer enough. Organizations must take proactive steps to prevent threats before they happen and to recover if compromised. In this session, Darktrace unveil an ambitious new approach to security, with core engines powering AI technologies to prevent, detect, respond, and ultimately heal from attacks across all areas of their digital environment. Together, these engines combine to strengthen organizations’ security posture in a virtuous AI feedback ‘loop,’ which provides powerful end-to-end, bespoke, and self-learning solutions unique to each organization.

[1 CPE] Implementing DMARC (Without Getting Fired)

  Presented by Kristen Sanders, Sr Security Advisor • Aquila

DMARC is free and effective, but how do you implement it? Learn about DMARC and how to use it (WITHOUT bringing your email to a screeching halt). This discussion will cover what DMARC is, creating a DMARC record, SPF record, leveraging DKIM, and best practices.

[1 CPE] Privacy and You: A Brief Introduction

  Presented by Christopher Goodrich, CISSP-ISSEP • ISC2 New Mexico

This presentation will be broken out into three sections. First, I’ll provide a brief history lesson, including definitions from an international perspective, and cover the most prominent privacy “rights.” This will be followed by an examination of legislature within the United States and the ramifications of this legal mandate applied to organizations. Finally, I’ll offer a few tips and tricks that individuals should be aware of in their personal lives.

[1 CPE] Security Trends & Predictions

  Presented by Christopher Fielder, Field CTO • Arctic Wolf

In a dynamic cybersecurity landscape and fast-paced market, organizations grapple with ever-changing threats. Uncertainty abounds as they seek to benchmark themselves against their peers and prioritize initiatives. Join Arctic Wolf Field CTO Christopher Fielder as he explores key areas organizations are focusing on, top threat concerns, and responses by established organizations to emerging threats. Leveraging Arctic Wolf research, Christopher further presents five critical security predictions for the next 12 months.

[1 CPE] Fireside Chat: Why the Village of Los Lunas Adopted a Continuous Threat Exposure Management Strategy

  Presented by Ken Ballard, Vice President of FortifyData and Luis Brown, IT Director for the Village of Los Lunas

Join Luis Brown, IT Director for the Village of Los Lunas and FortifyData’s Ken Ballard who will interview Luis on the challenges that led to the decision. This will cover what continuous threat exposure management is and explore the challenges and considerations that Luis was facing in how their IT team can effectively identify and manage cyber risks. Some of the issues include how to get the full picture of attack surface threats with accurate asset identification, integrating risk data from disparate sources, and efficiently managing all of this for the team to respond.

[1 CPE] Go Hack Yourself: War Stories from ~20k Pentests

  Presented by Habibeh Deyhim, Director of Customer Success • Horizon3.ai

In an ecosystem where you know you’re being targeted daily, how can you prove you’re secure? Are you finding and fixing the most critical attack paths, logging the right data, and alerting on the right events? Do you know if you’re ready to respond to an incident and are your security controls configured and integrated correctly? All this effort is supposed to measurably reduce your risk, but is any of it working?

Join Habibeh Deyhim, Director of Customer Success at Horizon3.ai, to learn a proven way to find, fix, and verify that you’re secure. Habibeh will discuss several real-world examples of what autonomous pentesting discovered in networks just like yours. And you’ll hear more about how fast and easy it was to safely compromise some of the biggest (and smallest) networks in the world – with full domain takeover in a little more than a few hours. Learn how you can safely do the same in your own network today!