It Ain’t Done ‘Til It’s Automated: Security at the Speed of DevOps

  Presented by Check Point

Have you been tasked with implementing Zero Trust Network Access but are unsure of how to go about it? Are you confused about how to achieve “minimum access”? Are you struggling with employing “continuous adaptive risk & trust assessment” on your network? If so, attend this session. Learn how to deploy an open, multi-vendor Enterprise security framework that gives security and IT teams an integrated way to gain visibility, control, and advanced threat defense. See how security prioritization and machine learning helps organizations leverage existing third-party solutions to better protect investments and implement proactive risk controls.

First Quarter of Containment

  Presented by Malwarebytes

All of us are living in the new Work from Home normal caused by the rapid transmission and spread of COVID-19. While people everywhere have been worried about stopping the spread of COVID, malicious threats have not only continued to propagate but they have exploded in new and interesting ways. During this presentation we will review some of the more creative ways hackers have targeted business and individuals during the age of Work from Home and some ways to protect yourself from them.

Zero Trust and the Flaming Sword of Justice

  Presented by Cisco

Security breaches pervade the headlines. What was seen as a rare instance just 5 years ago now seems to occupy the daily news cycle. A lot of these data breaches are made possible due to missteps and misconfigurations. There are many security issues introduced into website authentication mechanisms that further compound the security issues in addition to enforcing bad behavior by the end users. Security debt is a real problem for the vast majority of organizations in the world today and the attackers will utilize this to their advantage. In addition to keeping system hygiene at the front of the mind, defenders need to focus on proper network zone segmentation or, as it is a more popular term these days, zero-trust networks. The old conceptual style of a castle wall and moat to defend a network was deprecated several years ago. As a result of the dissolution of the traditional perimeter, a stronger focus has to be placed on the strength of authentication, authorization, and trust models for the users.

The antiquated notion of an information security practitioner running through the office brandishing their flaming sword of justice above their heads screaming “thou shall not pass” has at long last reached the denouement. Whether you are responsible for the security in a financial organization or one that makes teddy bears it is necessary to adapt and learn to trust, but verify.”

Cyber AI and Geopolitics: Managing Tomorrow’s Cyber Risk

  Presented by Darktrace

Against a backdrop of escalating geopolitical tensions and an ever-evolving threat landscape, the risk of cyber-attacks to governments and the private sector alike has never been higher. Join Darktrace’s Director of Strategic Threat, Marcus Fowler, and Americas CISO, JR Tietsort to discuss this new era of cyber-threat and how Cyber AI can help defenders regain the upper hand.

This speaking session will include a Q&A with our experts, and explore:

  • How nation-state attacks are changing
  • How organizations can respond to the classic balance of security and productivity
  • How organizational maturity in risk management is maintained whilst ensuring cyber defense

How Application Security Can Help You

  Presented by Trend Micro

With an ever-changing cloud landscape, securing your applications has become a layered approach. When cloud evolution first started, putting your data in the cloud did not seem secure. Now we have redundant and backup data stored around the world. Applications access this data from many different infrastructures and with serverless as the next frontier, developers don’t need to spin up their own infrastructure. Securing these applications is challenging from an IT perspective, especially when there is no visibility into developer code.

In this session, we’ll be discussing the cloud road map and how to secure applications to benefit both the developers and IT professionals.

Digital Transformation: The ASU University Technology Office Story

  Presented by Chris Richardson • Deputy CIO of Development, Mobility, and Smart Cities • ASU

COVID-19 has accelerated digital transformation to a point we thought we’d reach in 2025. But the groundwork for such a leap was laid some time before at the ASU University Technology Office. Deputy CIO IT Development, Mobility and Smart Cities, Chris Richardson, will share how the culture of innovation at UTO, and its agile mindset, represent an exciting new definition of digital transformation.

Chris Richardson is the Deputy Chief Information Officer Development, Mobility, and Smart Cities at Arizona State University, organized as part of ASU’s University Technology Office. Mr. Richardson and his team are responsible for aligning with key stakeholders to lead the strategy, upgrade cycle, new functionality enhancements, and maintenance of a number of Enterprise applications across the diverse landscape of ASU; key applications to note include myASU, eAdvisor, uAchieve, Salesforce, and Peoplesoft. In addition to development and business analysis with these and other applications, Mr. Richardson’s team is advancing the landscape and vision of mobile applications and standards, web standards, and a User Experience Center of Excellence.

Chris Richardson recently joined ASU from Honeywell where he held several positions over an 11- year career. His most recent role was Senior Director of IT Service Delivery for the Performance Materials and Technologies business group, global accountability of all application and infrastructure operations for a $12B organization. As Director Service Operations Support of the centralized infrastructure organization, his team supported more than 120,000 employees globally for their Service Desk and desktop support experiences, the identity and access management for their systems, the monitoring of critical infrastructure, and all ITIL process ownership for incident, problem, knowledge, access and event management. He has also held responsibility as Director for Desktop Services, Senior Program Manager, IT Audit Manager, European Manager Co-Sourcing, and Senior Business Analyst in the Transportation Systems business group.

Mr. Richardson has also been responsible for product and web development at his own companies, Tru Realty and ASPACT Schools (no longer in existence), as well as at Talisma Corporation and License Online.

Chris holds a double Bachelor of Science in Zoology and Fisheries from the University of Washington, a Master of Arts in Teaching from the University of Puget Sound, and a Master of Business Administration (MIS, Finance, and Entrepreneurship emphases) from the University of Arizona. During Chris’ working career he has obtained PMP, CIPP, and ITIL Expert Lifecycle certifications; he was also a part of Honeywell’s Pathways, IT Leadership Development, and HITS Leadership IT Functional training programs.

Office 365 Security Best Practices: At the Office, at Home, and on the Road

  Presented by Mimecast

Cyber-hygiene has become a source of great concern of late. And while the Office 365 suite has helped communication and collaboration from multiple location points (at the office, at home, and on the road) there are still security concerns that must be mitigated. In this presentation, we will hear best practice suggestions for remaining safe while using Office 365. First, we’ll talk about security attitudes, then review CISA concerns with Office 365, and finally offer best practice suggestions and thought leadership. This presentation will be driven by J. Peter Bruzzese… cyber-security advisor and 8x awarded Microsoft MVP (Exchange/Office 365).

IoT: Additional Challenges It Poses in a Pandemic-Induced Work Environment

  Presented by Lester Godsey • CISO, Maricopa County

According to SecurityToday.com we will see an estimated 31 billion IoT devices added to the Internet in 2020 and a whopping 75 billion in 2025. While many of these devices are corporate/industrial (IIoT) in nature, there is a very large home/personal IoT market to contend with.

Now that a significant portion business is being done at home and other locations other than the office, what impact are these devices having from a cybersecurity perspective as it relates to:

  • Security vulnerabilities
  • Security controls and awareness, we typically have in corporate networks but lack in home offices
  • What data is leaving corporate systems – inadvertently and purposely
  • Ability to adhere to governmental and industry compliance standards
  • Join us for an in-depth conversation around the ‘normal’ challenges with IoT devices and solutions and how this new paradigm of working from home exacerbates them.

Master the Edge: How to Achieve Context-Aware, Zero Trust Network Access

  Presented by Structured & Aruba

Have you been tasked with implementing Zero Trust Network Access but are unsure of how to go about it? Are you confused about how to achieve “minimum access”? Are you struggling with employing “continuous adaptive risk & trust assessment” on your network? If so, attend this session. Learn how to deploy an open, multi-vendor Enterprise security framework that gives security and IT teams an integrated way to gain visibility, control, and advanced threat defense. See how security prioritization and machine learning helps organizations leverage existing third-party solutions to better protect investments and implement proactive risk controls.

Top 5 Use Cases for Endpoint Protection in Operational Technology

  Presented by VPLS

The Air Gap: A Double-edged Sword

Endpoints are frequently the target of initial compromise or attacks. It can take just minutes, if not seconds, to compromise the endpoints, putting industrial environments at risk. One recent study found that 30% of breaches involved malware being installed on endpoints.

Operational Technology (OT) endpoints are particularly vulnerable given the legacy technology powering environments like our manufacturing plants, power stations, and other critical infrastructure. Many organizations rely on an air gap for cybersecurity to protect their industrial environments.

Unfortunately, the air gap is a double-edged sword. While it may help insulate and shrink the attack surface, like all prevention measures, it is not 100%.

Join this presentation to explore how you can:

  • Stop breaches and prevent data loss and ransomware damage with no dwell time.
  • Eliminate alert fatigue and optimize operations with customizable, standardized incident response processes.
  • Ensure business continuity in the event of a security incident, keeping systems online.
  • Reduce the cost of legacy EDR solutions, enabling response and remediation without negatively impacting business.