googletag.cmd.push(function() { googletag.display('div-gpt-ad-1482431611496-4'); });
Click here to view registration types and pricing (PDF)
Conference Agenda
Filter by registration level:
  • session level iconOpen Sessions
  • session level iconConference Pass
  • session level iconSecureWorld Plus
  • session level iconVIP / Exclusive
  • Wednesday, May 14, 2025
    9:00 am
    [PLUS Course] AI Unleashed: Cybersecurity Strategies for an Autonomous Future
    • session level icon
    speaker photo
    Sr. Cybersecurity Consultant, Wilson Cyber
    Registration Level:
    • session level iconSecureWorld Plus
    9:00 am - 3:00 pm

    Artificial Intelligence (AI) technology enables computers and machines to simulate human learning, comprehension, problem solving, decision making, creativity and autonomy. Applications and devices equipped with AI can see and identify objects, understand, and respond to human language, learn from new information and experience. AI-based applications (a classic example being a self-driving car) can make detailed recommendations to users and experts and act independently, replacing the need for human intelligence or intervention.

    Recognizing the importance of technical standards in shaping development and use of AI, the U.S. President’s October 2023 Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (EO 14110) calls for “a coordinated effort… to drive the development and implementation of AI-related consensus standards, cooperation and coordination, and information sharing” internationally.

    This PLUS Course focuses on how the development of AI capabilities, technologies, and tools impact cybersecurity. Instructor Larry Wilson breaks down the course into four digestible lessons:

    Lesson 1: What Is Artificial Intelligence: Includes an overview of Artificial Intelligence, how AI is used today (case studies), the current / future state of international AI standards.

    Lesson 2: AI Security Threats: How threat actors are using AI to automate stages of the attack lifecycle, including reconnaissance, evasion, privilege escalation, lateral movement, and exploitation.

    Lesson 3: AI Security Standards: (1) Secure Design – risks and threat modelling; (2) Secure Development – supply chain security, documentation, asset and technical debt management; (3) Secure Deployment – protecting infrastructure from compromise, threat or loss, incident management, and responsible release; and (4) Secure Operation and Maintenance – logging and monitoring, update management and information sharing.

    Lesson 4: AI Risk Management Playbook: (1) Govern – policies, processes, procedures and practices across the organization related to the mapping, measuring and managing of AI risks are in place, transparent, and implemented effectively; (2) Map – context is measured and understood; (3) Measure – appropriate methods and metrics are identified and applied; (4) Manage – AI risks based on assessments and other analytical output from the Map and Measure functions are prioritized, responded to, and managed; (5) Roadmap – key activities for advancing the NIST Artificial Intelligence Risk Management Framework.

    Upon completion of the class, attendees will have an up-to-date understanding of AI and its impact on cybersecurity. They will learn what actions organizations should take to benefit from the many advancements available with adopting AI into their security design, development, deployment, operations, and maintenance.

    STUDENT TESTIMONIAL:
    “Mr. Wilson presented an incredibly complex, emerging topic that includes significant risks in such a way that it left me convinced GenAI is just another piece of software. He walked us through defining the technical components, understanding the risks of and threats to these systems, and the security controls to help mitigate them. He wrapped the class by outlining how we may want to develop a program for managing the risks associated with AI, and did it with a wealth of practical knowledge, relatable personal anecdotes, and a ton of thoughtful research. Best class of SecureWorld Boston 2025!”
    Andrew F. Powell Jr., Information Security Director, Williams College

    9:00 am
    [PLUS Course] Implementing the NIST Cybersecurity Framework, Including 2.0
    • session level icon
    speaker photo
    Cyber Risk Analyst, Cyber Risk Opportunities LLC
    Registration Level:
    • session level iconSecureWorld Plus
    9:00 am - 3:00 pm

     

    Have you ever wondered how to actually use the NIST Cybersecurity Framework and apply it to your business or organization?

    In this course, you will get an inside look at how cybersecurity, information technology (IT), and business professionals use the NIST Cybersecurity Framework (CSF) Version 2.0 to understand and actively manage their risk posture.

    You will begin by learning the fundamentals of the NIST Cybersecurity Framework, including:

    • What are the components of the framework?
    • Why is the framework is valuable?
    • What type of organizations can use the framework?

    Then, you will dive deeper into the framework to fully understand the Framework Core, the Framework Tiers, and the Framework Implementation Profile.

    You will also review various case studies from diverse organizations across the globe, including critical infrastructure organizations, technology companies, governmental organizations, and others.

    Finally, we will spend the majority of this course walking you through how to implement this framework within your own organization by conducting a Cyber Risk Mapping (CR-MAP). This CR-MAP of your organization will aid you in identifying your weaknesses and creating a remediation plan to achieve higher levels of security by minimizing your cyber risk.

    We even include a free bonus digital workbook that helps you conduct a step-by-step Cyber Risk Mapping at the conclusion of the course.

  • Thursday, May 15, 2025
    7:30 am
    Registration open
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    7:30 am - 4:15 pm
    Location / Room: Registration Desk

    Come to the Registration desk in the lobby to check-in and get your badge. SecureWorld staff will be available throughout the day if you have any questions.

    8:00 am
    Exhibitor Hall open
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    8:00 am - 4:15 pm
    Location / Room: Exhibitor Hall

    Your opportunity to visit our solution vendor partners, whose sponsorship makes SecureWorld possible! Booths have staff ready to answer your questions. Look for participating Dash For Prizes sponsors to be entered to win prizes.

    8:00 am
    Advisory Council Roundtable Breakfast (VIP / Invite only)
    • session level icon
    Rightsizing InfoSec: Finding the Balance Between Risk, Budget, and Impact
    speaker photo
    VP, Global Information & Product Security, Pindrop
    Registration Level:
    • session level iconVIP / Exclusive
    8:00 am - 8:45 am

    In an era of tightening budgets and expanding threats, how do CISOs ensure their security programs are neither overbuilt nor under-resourced? This closed-door roundtable brings together security leaders to share how they’ve approached “rightsizing” their InfoSec programs—aligning risk tolerance, business objectives, and available resources. From rationalizing tools and staffing to communicating trade-offs to the board, join your peers for a candid conversation on doing more with what you’ve got—while keeping security outcomes front and center.

     

    8:00 am
    Association Chapter Meetings
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    8:00 am - 8:45 am

    Participating professional associations and details to be announced.

    8:00 am
    Benchmarking Your Cybersecurity Framework
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    8:00 am - 8:45 am

    Measuring one’s cybersecurity framework against others in the same industry, or even outside of their vertical, can provide valuable insights into areas to improve or adjust.

    8:45 am
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    8:45 am - 9:00 am
    Location / Room: Exhibitor Hall

    Visit the Exhibitor Hall to network with attendees and connect with our vendor sponsors and association partners.

    9:00 am
    [Opening Keynote] Cross-Industry CISO Perspectives: Securing Critical Systems in a World of Complex Cyber Risks
    • session level icon
    speaker photo
    Principal, CI5O Advisory Services LLC
    Registration Level:
    • session level iconOpen Sessions
    9:00 am - 9:45 am
    Location / Room: Keynote Theater

    Cybersecurity is no longer a one-size-fits-all challenge. In this opening keynote, a panel of CISOs from diverse industries will share their unique strategies for protecting their organizations in an increasingly complex cyber risk environment.

    With each industry facing distinct challenges, from regulatory hurdles to advanced threat actors, this session will explore how CISOs approach risk management, incident response, and resilience.

    Join us for an engaging discussion on how industry-specific insights, collaboration, and innovation are shaping the future of cybersecurity and fortifying critical infrastructure in the face of new and emerging risks.

    9:45 am
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    9:45 am - 10:15 am
    Location / Room: Exhibitor Hall

    Visit the Exhibitor Hall to network with attendees and connect with our vendor sponsors and association partners.

    10:15 am
    Stronger Together: The Power of Cyber Threat Intelligence Sharing in Cybersecurity
    • session level icon
    speaker photo
    Chairman of the Board, Oil and Natural Energy Information Sharing and Analysis Center (ONE-ISAC)
    Registration Level:
    • session level iconConference Pass
    10:15 am - 11:00 am

    Threat actors constantly collaborate, share tactics, and leverage intelligence to exploit vulnerabilities. Shouldn’t we be doing the same? This session will explore the critical role of threat intelligence in fostering collaboration among organizations—especially in the Greater Houston area and energy sectors. By sharing best practices, real-world strategies, and compliance considerations, we can strengthen our collective defenses and stay ahead of emerging threats. Join us to discuss how security professionals can work together to protect their organizations, industry, and community.

    10:15 am
    [Panel] Bridging the Gap: The Role of the BISO in Modern Cybersecurity
    • session level icon
    speaker photo
    Head of the Business Information Security Office (BISO), WM
    speaker photo
    BISO, Humana
    speaker photo
    Director, BISO, Leidos
    speaker photo
    Director, IT/OT Security, ConocoPhillips
    Registration Level:
    • session level iconConference Pass
    10:15 am - 11:00 am

    As cybersecurity continues to evolve, so does the need for professionals who can seamlessly connect security initiatives with business objectives. Enter the Business Information Security Officer (BISO)—a critical yet often misunderstood role.

    In this engaging panel discussion, regional BISOs will share insights into their responsibilities, challenges, and the strategic impact they have within their organizations. Whether you’re a technical professional looking to advance your career or an executive seeking to understand the business side of cybersecurity, this session will help demystify the BISO role and its importance in today’s security landscape.

    Attendees will gain:

    • A clear understanding of what a BISO does and how they differ from CISOs and other security leaders
    • Insights into how technical professionals can develop the business acumen necessary to transition into leadership roles
    • Practical strategies for bridging the gap between security and business priorities

    Join us to explore the intersection of business and security—and how mastering both can accelerate your career.

    10:15 am
    The Big Bad Hack: Why Attackers Are Winning and How to Fight Back
    • session level icon
    speaker photo
    Global VP, Defense.com
    Registration Level:
    • session level iconOpen Sessions
    10:15 am - 11:00 am

    Despite businesses investing more in security than ever, cyber attackers continue to outsmart defenses—just like the cunning villains of classic tales. So, where is it all going wrong? In this session, we’ll reveal why attackers are thriving and why traditional security strategies just aren’t strong enough to keep modern threats out.

    Through real-world case studies, we’ll explore how attackers wield AI and automation like magic, breaking into systems faster than ever before. You’ll discover how your team can overcome resource constraints by implementing practical, cost-effective strategies—no enchanted swords or armies required. By the end of the session, you’ll leave with the confidence and tools needed to ensure your business lives happily ever after in cybersecurity.

    10:15 am
    Tabletop Exercises: The Fun Kind
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    10:15 am - 11:00 am

    Tabletops are not new in incident response training. But oftentimes, they’re pretty dull or ridden with anxiety. But, what if we applied gamification and game-based learning techniques? By transforming tabletop exercises into interactive, engaging scenarios, with Dungeons & Dragons-style play, we can make them more memorable and effective!

    This approach allows participants to practice critical skills, with a structure that encourages more balanced team involvement and participation, and dice-rolling to determine success and failure (that does a remarkable job in simulating a real-world experience). Enter HackBack Gaming! Why not build incident response “muscle” memory in a fun way? This session provides a foundation for you to start conducting exercises like this yourself right away.

    11:00 am
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    11:00 am - 11:10 am
    Location / Room: Exhibitor Hall

    Visit the Exhibitor Hall to network with attendees and connect with our vendor sponsors and association partners.

    11:10 am
    AI and Security Awareness: Building a Future-Ready Culture
    • session level icon
    speaker photo
    Security Behavior and Culture Lead
    Registration Level:
    • session level iconConference Pass
    11:10 am - 11:55 am

    In the era of rapid technological change, the intersection of artificial intelligence (AI) and cybersecurity presents both tremendous opportunities and complex challenges. This presentation will explore how AI is transforming security awareness programs and shaping security culture within organizations. Attendees will learn how to leverage AI to build a more resilient and proactive security culture that empowers individuals to become active participants in the fight against cyber threats. We’ll discuss the importance of human behavior in security, practical tools for implementing AI-driven training, and how to create a dynamic culture where employees continuously adapt to emerging threats.

     

    11:10 am
    Building Trusted Partnerships to Enable Secure Products
    • session level icon
    Registration Level:
    • session level iconConference Pass
    11:10 am - 11:55 am

    In today’s interconnected digital ecosystem, the security of any product is only as strong as its weakest link. This panel session explores the critical role of trusted partnerships in developing and maintaining secure products throughout their lifecycle.

    Our distinguished panel delves into the challenges and opportunities of fostering collaborative relationships between vendors, suppliers, and customers to enhance product security. They examine how these partnerships can lead to more robust security measures, improved threat intelligence sharing, and faster response times to emerging vulnerabilities. Key topics include:

    • Establishing trust in the supply chain
    • Collaborative approaches to secure software development
    • The role of transparency in building and maintaining trust
    • Balancing intellectual property concerns with security needs
    • Leveraging partnerships for more effective incident response
    • Case studies of successful security-focused partnerships
    11:10 am
    Cyber Risk by the Numbers from a Cyber Insurance Perspective
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    11:10 am - 11:55 am

    You’ve experienced a cyber incident. Does cyber insurance really pay? What’s actually a recoverable expense? How can insurance help? And when the insurance does pay, how do you balance the amount of insurance with cybersecurity priorities? In this session, we’ll evaluate the data and dig into recent real-world examples of how cyber insurance pays claims, what’s covered, the role of insurance in incident preparation and response, and how organizations are using analytics in decision-making.

    11:10 am
    [Panel] The Evolving Cyber Threat Landscape: Tales of Villains, Heroes, and Resilience
    • session level icon
    speaker photo
    Sr. Solutions Architect, US, Bitdefender
    speaker photo
    Team Lead – IRSM – Cybersecurity Engineering & Innovation, Chevron
    Registration Level:
    • session level iconOpen Sessions
    11:10 am - 11:55 am
    Location / Room: Pecan

    Today’s professionals face challenges reminiscent of classic fairy tales: shadowy villains, unexpected allies, and battles for safety and survival. This panel will delve into the current threat landscape, from ransomware dragons to insider trolls. It will offer insights into the strategies and tools organizations need to craft their own happily ever after in cybersecurity.

    12:00 pm
    [Lunch Keynote] Cyber World on Fire: A Look at Internet Security in Today’s Age of Conflict
    • session level icon
    speaker photo
    CNN Military Analyst; U.S. Air Force (Ret.); Chairman, Cedric Leighton Associates, LLC
    Registration Level:
    • session level iconOpen Sessions
    12:00 pm - 12:45 pm
    Location / Room: Keynote Theater

    This informative session analyses the growing threat of cyberattacks and risks to internet security in today’s world. Col. Leighton explores the various types of attacks and vectors, including how bad actors can impact businesses and individuals. The session also examines the role of governments and international organizations—partnering with public and private businesses—in protecting against cyber threats.

    Col. Leighton describes how nefarious actions are becoming increasingly more sophisticated and widespread, with hackers targeting not just large corporations but also smaller businesses and even individuals. He emphasizes the need for organizations to take proactive measures to protect their networks and data, including investing in advanced security technologies and providing regular training to employees.

    He shares examples of cyber activity—good and bad; offensive and defensive—from Ukraine, China, and around the globe.

    12:00 pm
    Advisory Council Roundtable Lunch (VIP / Invite Only)
    • session level icon
    Registration Level:
    • session level iconVIP / Exclusive
    12:00 pm - 12:45 pm

    Moderated discussion for SecureWorld Advisory Council members. By invite only.

    12:45 pm
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    12:45 pm - 1:15 pm
    Location / Room: Exhibitor Hall

    Visit the Exhibitor Hall to network with attendees and connect with our vendor sponsors and association partners.

    1:15 pm
    Cybersecurity Challenges for Small and Medium Businesses
    • session level icon
    Registration Level:
    • session level iconConference Pass
    1:15 pm - 2:00 pm

    Small and medium businesses (SMBs) are the backbone of the U.S. economy, generating over half of the annual GDP and employing millions of Americans. But they also face unique cybersecurity challenges that can threaten their survival and growth. In this talk, learn how to assess and mitigate the cyber risks that SMBs face, and how to implement a robust cybersecurity program with limited resources and expertise.

    We cover the following topics:

    • The state of SMB cybersecurity in the U.S.
    • The cost and impact of cyber breaches on SMBs
    • The main cyber threats and vulnerabilities that SMBs face
    • The best practices and frameworks for SMB cybersecurity
    • The steps to build or improve your cybersecurity program

    Whether you are an IT manager, a cybersecurity professional, or a business owner, this talk is informative and practical. Walk away with a better understanding of the cyber landscape and the tools and techniques to protect your SMB from cyberattacks.

    1:15 pm
    How to Write Your Own Security Happily Ever After
    • session level icon
    speaker photo
    Information Security Awareness Lead, Brown & Brown Insurance
    Registration Level:
    • session level iconConference Pass
    1:15 pm - 2:00 pm

    Attackers try to exploit our technologies, processes, and people to breach our systems and steal data. We educate our technology teams, train elevated access teams in secure processes, and keep users informed on emerging threats. That’s easier said than done. Most security teams do not include professional educators or communication specialists. We tend to sprinkle bits of information, or we push everything to everyone all at once leaving it to the user to decide what to view. 

    How do we know when we’ve said enough? Is it possible to share too much? (Psst, yes, it is.) Experts recommend using stories, but what makes a good story and what’s the best way to deliver it so the message sticks? How do we balance customization with available resources? Attendees will learn a new framework to create and structure content for each of your audiences so security awareness and training will have the greatest impact with the least amount of security team time. This framework will ensure all areas you need to educate are covered and the right amount of information is shared.

    1:15 pm
    Addressing the Cybersecurity Skill Shortage Internally and Externally
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    1:15 pm - 2:00 pm

    This presentation will cover accelerating skill development and cross-department collaboration efficiently and economically. Key takeaway: How to build a cyber guild and utilize it for expanded upskilling and role development.

    1:15 pm
    [Panel] The Sorcerer's Apprentice: Taming AI in Cybersecurity
    • session level icon
    speaker photo
    Executive Cybersecurity Strategist, Global Security Strategy Office, CDW
    speaker photo
    VP, Field Engineering, Cyberhaven
    Registration Level:
    • session level iconOpen Sessions
    1:15 pm - 2:00 pm

    AI can be both a powerful ally and a mischievous force if left unchecked. This panel will explore how organizations can harness the magic of AI for cybersecurity—automating defenses, detecting threats, and enhancing decision-making—while addressing the risks of bias, over-reliance, and adversarial AI. Use this transformative technology wisely to write your cybersecurity success story.

    2:00 pm
    Networking Break
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    2:00 pm - 2:10 pm
    Location / Room: Exhibitor Hall

    Visit the Exhibitor Hall to network with attendees and connect with our vendor sponsors and association partners.

    2:10 pm
    The World's First AI Certification, ISO 42001: What We've Learned After One Year
    • session level icon
    speaker photo
    Senior Manager, Schellman
    speaker photo
    Principal | ISO Practice Director | AI Assessment Leader, Schellman
    Registration Level:
    • session level iconConference Pass
    2:10 pm - 2:55 pm

    In 2024, Schellman became one of the first accredited certification bodies for ISO 42001, providing invaluable insights into AI governance. Our experience revealed that ISO 42001 equips organizations with a robust framework to navigate the complex landscape of AI regulation. By establishing clear guidelines for ethical AI practices, organizations can enhance transparency, accountability, and compliance. This standard not only helps mitigate risks associated with AI deployment but also fosters trust among stakeholders. We believe that ISO 42001 is essential for organizations striving to balance innovation with regulatory demands, ultimately paving the way for responsible AI adoption in diverse sectors.

    2:10 pm
    Integrating Transformative OT Cybersecurity Programs
    • session level icon
    Registration Level:
    • session level iconConference Pass
    2:10 pm - 2:55 pm

    Session description to come.

    2:10 pm
    Social Engineering: Training the Human Firewall
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    2:10 pm - 2:55 pm

    Phishing is one of the leading cyberattacks worldwide, resulting in numerous social engineering training exercises to train average users to defend against these attacks. This discussion focuses on research that took a pool of users with three different phishing campaigns. Each campaign progressively has a phish that should be more advanced to spot than the previous phish presented. The research shows the psychological reasoning behind why a user will interact with a phish, regardless of educational awareness. Results include why a 0% or 100% report rate is unrealistic and how to use phishing metrics to quantify risk in a business.

    2:10 pm
    Navigating Third-Party Risk and Vendor Resilience
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    2:10 pm - 2:55 pm

    In today’s dynamic cyber risk landscape, risk managers must stay informed and adapt their strategies accordingly. Recent global cyber events have had a profound impact on critical functions across multiple sectors, underscoring the gravity of cyber events. Risk managers also face complexities from trends like reliance on third parties and evolving data protection laws.

    To successfully navigate these challenges, risk managers are tasked with learning from significant cyber events, implementing best practices for managing third-party cyber risk, and staying updated on privacy regulations. This session assists risk managers in effectively mitigating cyber risks and safeguarding their organizations by discussing strategies for managing third-party cyber risk and providing updates on privacy regulations.

    3:00 pm
    Networking Break and Dash for Prizes
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    3:00 pm - 3:30 pm
    Location / Room: Exhibitor Hall

    Visit the solution sponsor booths in the Exhibitor Hall and connect with other attendees.

    Participating sponsors will announce their Dash for Prizes winners. Must be present to win.

    3:00 pm
    Happy Hour
    • session level icon
    Registration Level:
    • session level iconOpen Sessions
    3:00 pm - 4:00 pm
    Location / Room: Exhibitor Hall

    Join your peers for conversation and complimentary beverages. This is a great opportunity to network with other security professionals from the area and discuss the hot topics from the day.

     

    3:30 pm
    [Closing Keynote] Ask a CISO: Navigating Career Progression and Leadership in Cybersecurity
    • session level icon
    speaker photo
    Deputy CISO, ENGIE North America
    speaker photo
    CISO & Director, Healthcare Technology Management, Texas Children's Hospital
    speaker photo
    VP, Global Information & Product Security, Pindrop
    Registration Level:
    • session level iconOpen Sessions
    3:30 pm - 4:15 pm
    Location / Room: Keynote Theater

    As the cybersecurity landscape evolves, so too do the careers of those who defend our digital environments. In this interactive closing keynote session, a panel of local Chief Information Security Officers (CISOs) will provide valuable insights into the critical journey from cybersecurity practitioner to strategic leader.

    Attendees will have the unique opportunity to engage with these seasoned professionals, asking questions about career progression, succession planning, and how to successfully transition from technical roles to leadership positions. Whether you’re looking to move up the ranks, build your leadership skills, or understand what it takes to step into the CISO role, this session will offer practical advice, real-world experiences, and actionable strategies to guide your professional growth. Join us for a dynamic discussion that explores the intersection of technical expertise and leadership in today’s cybersecurity world.

Exhibitors
  • Bitdefender
    Booth: 320

    Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumer, business, and government environments, Bitdefender is the industry’s trusted expert* for eliminating threats, protecting privacy and data, and enabling cyber resiliency. With deep investments in research and development, Bitdefender Labs discovers 400 new threats each minute and validates 30 billion threat queries daily. The company has pioneered breakthrough innovations in antimalware, IoT security, behavioral analytics, and artificial intelligence and its technology is licensed by more than 150 of the world’s most recognized technology brands. Founded in 2001, Bitdefender has customers in 170 countries with offices around the world. For more information, visit https://www.bitdefender.com.  ​

  • CDW
    Booth: 100

    CDW Corporation is a leading multi-brand provider of information technology solutions to business, government, education and healthcare customers in the United States, the United Kingdom and Canada. A Fortune 500 company and member of the S&P 500 Index, CDW helps its customers to navigate an increasingly complex IT market and maximize return on their technology investments. For more information about CDW, please visit  www.CDW.com.

    Our broad array of products and services range from hardware and software to integrated IT solutions such as security, cloud, hybrid infrastructure and digital experience.

  • Cyberhaven
    Booth: 300

    When the DLP market first emerged 20 years ago, the goal was to protect confidential information in on-premises databases, file servers, application servers, other data repositories, and endpoints. Today millions of sensitive documents, files, and other data are being exfiltrated in violation of corporate data policies every day because DLP is completely ineffective in the era of cloud-first applications and Zero Trust security. These data breaches result in stolen IP, damaged brands, and significant financial penalties. Let’s face it, DLP in its current form is nothing more than a compliance checkbox. Cyberhaven is transforming the DLP market and helping organizations secure all of the high-value data they must protect in order to compete and thrive in the digital economy. It’s a big hairy problem, and we are up to the challenge.

  • Defense.com
    Booth: 260

    Defense.com is transforming the way businesses manage cyber security by allowing them to easily identify, prioritise and remediate threats.

    We help to simplify and solve the cyber security challenges facing organisations, allowing teams to protect their brand and assets against today’s evolving threat landscape. Businesses of all sizes rely on our solutions to protect, detect and respond to cyber threats.

  • Digital Hands
    Booth: 210

    Digital Hands is how you finally get MDR with the flexibility, fine-tuning, and support needed to make it work in your specific environment. We call it Real-World MDR.

    Too many companies get excited about the promise of MDR, only to be disappointed by MDR’s missing pieces. Where are the custom playbooks? The expert guidance? Firewall management? How do you handle the sheer volume of alerts? Why won’t this play nice with your tech stack? And on and on it goes. Meanwhile, the bad actors are becoming more and more sophisticated with AI and automation. So, you’ve got to think fast, act fast, and flex fast. That’s why organizations with some of the most sensitive data of all – such as hospitals, financial institutions, law firms, and government agencies – continue to give us industry-leading satisfaction sentiments year after year after year.

  • InfraGard Houston
    Booth: TBD

    The Houston Chapter of InfraGard provides members of the Critical Infrastructure community a means to share information to prevent, protect, and defend against hostile acts against Critical Infrastructure and Key Resources (CIKR). InfraGard is designed to address the need for private and public-sector information-sharing mechanisms at both the national and local levels. It is our goal to improve and extend information sharing between private industry and the government, particularly the FBI, when it comes to critical national infrastructures.

  • ISACA Houston
    Booth: TBD

    Our aim is to sponsor local educational seminars and workshops, conduct regular chapter meetings, and help to further promote and elevate the visibility of the IS audit, control and security profession throughout the area. We conduct chapter meetings the third Thursday of the month that typically includes a morning or afternoon training along with a luncheon meeting/training. We also sponsor SIG group meetings on the same day. Local seminars are held in the spring and fall that include topics of high relevance to our membership community. Certification training is scheduled before each ISACA exam date based on interest level.

  • Houston ISC2 Chapter
    Booth: TBD

    Houston ISC2 is a dedicated non-profit chapter of ISC2, the world’s leading cybersecurity professional association. We strive to create a safe and secure cyber world by supporting our members through valuable networking opportunities, educational resources, and career advancements. Based in Houston, we actively promote cybersecurity awareness within the community and empower individuals to enhance their skills and knowledge in this critical field.

  • ISSA South Texas
    Booth: TBD

    The South Texas Chapter of the Information Systems Security Association (ISSA) is a non-profit organization of information security professionals and practitioners. South Texas ISSA provides education forums, publications and peer interaction opportunities which enhance the knowledge, skill and professional growth of its members. This Chapter is affiliated with the international ISSA organization, conforms to its professional and organizational guidelines, and supports the ISSA Code of Ethics. We encourage our members to pursue and maintain formal security certifications in their chosen fields and offer training opportunities to help members meet requirements for continuing education.

  • NetAlly, LLC
    Booth: 110

    Since 1993, we have been the #1 ally of network professionals worldwide. We began by making the world’s first handheld network analyzer, and have continued as industry pacesetters ever since, first as Fluke Networks® then NetScout®. Now, as an independent company, NetAlly continues to set the standard for portable network testing. We are a company founded by engineers, passionate about innovation, and motivated by one purpose: to create the best test equipment possible, designed with your success in mind. Period.

    Our leading edge tools work hard to get the job done fast by…
    • Simplifying the complexities of networks
    • Providing instant visibility for efficient problem solving
    • Enabling seamless collaboration between site personnel and remote experts.

    Your organization relies on you to keep their networks running. And just like you, we are reliable, practical, no-nonsense experts. We are your behind the scenes partner.

    We are NetAlly.

  • Oil and Natural Energy Information Sharing and Analysis Center (ONE-ISAC)
    Booth:

    ONE-ISAC is dedicated to supporting cybersecurity intelligence and collaboration in the oil and natural gas sectors. Since 2014, we’ve worked to protect critical infrastructure by sharing timely threat intelligence and best practices.

  • Ping Identity
    Booth: 240

    Ping Identity delivers intelligent identity solutions for the enterprise. We enable companies to achieve Zero Trust identity-defined security and more personalized, streamlined user experiences.

  • Silverfort
    Booth: 220

    Silverfort protects enterprises from data breaches, cyber attacks and insider threats, by preventing credential compromise and misuse across the entire corporate network and cloud infrastructure. Silverfort leverages patent-pending technology to seamlessly harden the basic authentication and access mechanisms used by all client devices and services, instantly equipping them with the latest authentication and access protection technology without any change or integration.

  • Tevora + ProcessUnity
    Booth: 120

    Tevora is an enterprise consulting firm specializing in information assurance, governance and compliance services and solutions. We work with some of the world’s leading companies, institutions and governments to ensure the safety of their information and their compliance with applicable regulations. With a distinctive combination of proven products and services, Tevora aids enterprises in protecting their most important assets from external and internal threats. For more information visit https://www.tevora.com.

    ProcessUnity’s cloud-based solutions help organizations of all sizes automate their risk and compliance programs. Our highly configurable, easy-to-use tools significantly reduce manual administrative tasks, allowing customers to spend more time on strategic risk mitigation. As a software-as-a-service technology, ProcessUnity deploys quickly with minimal effort from customers and their IT resources. For more information, visit https://www.processunity.com.

  • ThreatLocker
    Booth: 250

    ThreatLocker® is a global cybersecurity leader, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. ThreatLocker’s combined Application Whitelisting, Ringfencing™, Storage Control, and Privileged Access Management solutions are leading the cybersecurity market towards a more secure approach of blocking unknown application vulnerabilities. To learn more about ThreatLocker visit: www.threatlocker.com

  • Trustmi
    Booth: 310

    Trustmi is a leading fintech cybersecurity solution designed to prevent financial losses from fraud and errors, 24/7. Our AI-driven platform instantly detects suspicious activity and human errors by continuously analyzing millions of data points, including vendor actions, emails, files, and payment details. Trustmi helps you accelerate digital transformation by reducing manual verification efforts and enhancing the efficiency and security of your payment processes, ensuring a smarter, faster approach to fraud prevention.

  • WiCyS Houston Affiliate
    Booth: TBD

    Women in CyberSecurity (WiCyS) is a global community that is dedicated to bringing talented women together to celebrate and foster their passion and drive for cybersecurity. WiCyS Houston Affiliate was formed to empower women in cyber and create a safe community for women to flourish, explore, and learn. We unite local, national, and international communities across academia, research, and industry to empower women through knowledge, experience, networking, and mentorship.

Return to Agenda
Keynote Speakers
Speakers
  • speaker photo
    Larry Wilson, CISSP, CISA, Instructor
    Sr. Cybersecurity Consultant, Wilson Cyber

    Larry Wilson was formerly the Chief Information Security Officer for Sumitomo Pharma Americas, Inc., Worcester Polytechnic Institute, and the University of Massachusetts (UMass) President's Office. In the CISO role, Larry was responsible for developing, implementing, and overseeing compliance with the SMPA / WPI / UMass Information Security Policy and Written Information Security Plan (WISP). In addition to designing and deploying the respective cybersecurity programs, Larry has developed and delivered cybersecurity training at multiple industry events, workshops, training venues, etc. Courses include Designing and Building a Cybersecurity Program, Designing and Building a Ransomware Program, and Designing and Building a Third-Party Risk Program. Larry has also worked with multiple companies in multiple industries to help design, build, and maintain their Cybersecurity Programs, Ransomware Program, and Third-Party Risk Programs.

  • speaker photo
    Rob Finch, Instructor
    Cyber Risk Analyst, Cyber Risk Opportunities LLC
  • speaker photo
    Manoj Tripathi, Moderator
    VP, Global Information & Product Security, Pindrop

    Manoj Tripathi is a seasoned CISO and has decades of experience in security, technology and leadership, across SaaS, Products and Consulting companies. Manoj is passionate about security and technology topics and has presented on security program management strategy and secure development topics at various security conferences. He holds the C|CISO and the CISSP certifications.

  • speaker photo
    Panel Discussion
  • speaker photo
    Al Lindseth, Moderator
    Principal, CI5O Advisory Services LLC

    Highly effective and successful senior executive with 25 years in the energy industry. Experience and knowledge spans different markets, products, business models and disciplines.
    Proven track record of:
    • Driving resolution of the top challenges facing different groups, companies or individuals, whether as a member of its management team or as an outside expert
    • Acting as change agent to effect turnaround situations and solve critical problems
    • Balancing between an entrepreneurial culture and the discipline to achieve the high standards and controls of a large public company
    • Doing more with less (PAALP ranked #5 in Forbes 500 in revenues/employee in 2009)

  • speaker photo
    Octavio Herrera
    Chairman of the Board, Oil and Natural Energy Information Sharing and Analysis Center (ONE-ISAC)

    Octavio Herrera, a cum laude graduate from Norwich’s University MSIA program, has held a number of information security positions within Fortune 500 companies. During his 25+ years career he has led the regulatory compliance program at Alcoa’s largest business unit, managed the IT Security program for American Family Life Assurance Company of Columbus (AFLAC), served as Information Security Officer for the Houston Independent School district – the seventh largest district in the nation and the largest in Texas - an since 2013, he leads the cyber security practice for Occidental Petroleum Corporation (OXY).

    Mr. Herrera has been honored as one of the “Top 40 Hispanics under 40” by Hispanic Engineer & Information Technology magazine and featured in Fortune Magazine’s March 2009 article, “How to Get a Job”.

    Mr. Herrera is one of the original founding members of the Oil and Natural Energy Information Sharing and Analysis Center (ONE-ISAC) where he currently serves as a chairman of the board and has been honored as a finalist for the 2024 Houston CISO ORBIE Award, a program that recognizes excellence in technology leadership for Cyber Security leaders nationwide.

  • speaker photo
    Monica Taylor Boggan
    Head of the Business Information Security Office (BISO), WM

    Monica Taylor Boggan is the Head of the Business Information Security Office (BISO) at WM, where she drives the alignment of cybersecurity with core business priorities across WM’s Digital, Corporate, Customer, Operations & Sustainability, and Healthcare Solutions divisions. Her work centers on building stronger third-party risk capabilities, leading AI security oversight, and bringing greater clarity and transparency to cyber risk.

    With over 25 years in technology and deep expertise in cybersecurity, Monica has led transformative efforts in enterprise risk management, security strategy, and cyber governance. She has implemented third-party risk management systems, managed AI governance assessment programs, and designed executive-level reporting to better inform risk-based decisions.

    A native Texan, Monica holds an MBA from Lamar University and maintains certifications as a CISSP, CISA, and CRISC, reflecting her commitment to both strategic leadership and technical excellence. Monica is recognized for her ability to translate complex security issues into actionable guidance for business leaders, enabling informed decision-making at every level. Her work spans the intersection of cybersecurity, innovation, and risk, with a strong focus on empowering organizations to build secure, resilient digital environments.

  • speaker photo
    Romen Brewer
    BISO, Humana

    Romen Brewer is an accomplished Business Information Security Officer (BISO) with a track record of driving security and technology efforts to meet business demand across various industries (Oil & Gas, Software/Gaming, Financial services, and Healthcare).

    As a BISO at Humana, he serves a as trusted advisor ensuring security is a business enabler while reducing risk and delivering on evolving AI/ML governance. Passionate about translating security challenges into business-enabling solutions, Romen has leveraged his unique perspective to several large-scale enterprises impacting with multiple levels of stakeholders.

    ‘What excites me most about cybersecurity is the constant evolution—staying ahead means continuously learning how technology innovation, business strategy, and security risk intersect in new and unexpected ways.” - Romen

  • speaker photo
    Jo Justice
    Director, BISO, Leidos
  • speaker photo
    Brittany Opeloye
    Director, IT/OT Security, ConocoPhillips
  • speaker photo
    Robert McKee
    Global VP, Defense.com

    Robert is passionate about transforming how businesses approach their cybersecurity challenges. His customer-centric approach has helped hundreds of organizations strengthen their security posture while maintaining operational efficiency. Throughout his career, he has been particularly passionate about democratizing enterprise-grade security solutions for smaller businesses.
    Known for his dynamic speaking style and practical insights, Robert regularly shares his expertise on topics including sales leadership, channel strategy, and the evolving cyber security landscape. His hands-on experience working with both technical and non-technical stakeholders makes him a valuable voice in bridging the gap between security requirements and business objectives.

  • speaker photo
    Melecia McLean
    Security Behavior and Culture Lead

    Melecia McLean is a Security Behavior and Culture Lead at a leading tech organization, where she applies her expertise in human risk management, social engineering, and AI to develop and enhance a proactive security culture. She leads dynamic cybersecurity awareness programs that equip individuals to protect their data, fostering a culture of vigilance, adaptability, and resilience. Melecia focuses on bridging human behavior with technology to strengthen organizational security. A passionate advocate for diversity, she served as Managing Director of Girls in Tech - Houston, championing women’s leadership in cybersecurity and STEM. Melecia is also dedicated to empowering the next generation of kids to explore cybersecurity, ensuring a future of inclusive and accessible technology.

  • speaker photo
    Andrei Ionescu
    Sr. Solutions Architect, US, Bitdefender

    Andrei has been in cybersecurity for 20 years; the last 13 he has been working for Bitdefender. In his day to day role, he helps enterprises to adopt Bitdefender inside their security stack while ensuring a smooth transition to our tools and services.

  • speaker photo
    Ashish Shah, Moderator
    Team Lead – IRSM – Cybersecurity Engineering & Innovation, Chevron
  • speaker photo
    Panel Discussion
  • speaker photo
    Col. Cedric Leighton
    CNN Military Analyst; U.S. Air Force (Ret.); Chairman, Cedric Leighton Associates, LLC

    Cedric Leighton is a CNN Military Analyst and a retired United States Air Force Colonel. On CNN, he has provided incisive commentaries on the Israel-Hamas War, the War in Ukraine, the U.S. withdrawal from Afghanistan, and numerous other conflicts around the world. His analysis has been seen by millions of viewers around the world and provided much needed context to some of the most pressing national security issues of our time. As a U.S. Air Force officer, Colonel Leighton served at U.S. Special Operations Command, the Joint Staff, and the National Security Agency, where he helped train the nation's cyber warriors. A Middle East combat veteran, he is the recipient of numerous military awards, including the Defense Superior Service Medal and the Bronze Star. After serving 26 years as a U.S. Air Force Intelligence Officer, Col. Leighton founded a strategic risk consultancy and became the co-founder of CYFORIX, where he advises multinational businesses on developing better cyber strategies designed to reduce risk and unpredictability.

  • speaker photo
    Dr. Paul Berryman
    Information Security Awareness Lead, Brown & Brown Insurance

    Paul has a passion for security, education, and bad puns, bringing them together whenever possible. He has spent the last 2 decades protecting people from the usual suspects of hackers, criminals, and bored teenagers and is focused on teaching how to connect with people through storytelling and energizing presentations to change behaviors. He enables organizations to train their users and reduce the element of human risk.

    Prior to working in security and education, Paul had 6 years of swashbuckling adventures with the US Navy. He’s a big fan of colleges, having attended 7 different ones. He most recently earned a doctorate in education and teaches technology content to high schoolers, college students, and adults. He's figured out that strong security starts with teaching how to behave online. It isn’t rocket science, but just in case he has a degree in that, too.

  • speaker photo
    Paul Kinder
    Executive Cybersecurity Strategist, Global Security Strategy Office, CDW

    Paul Kinder is a distinguished member of CDW’s Global Security Strategy Office (GSSO), where he provides advanced security consulting and enhances the solutions portfolio for CDW’s cybersecurity, data privacy, and Artificial Intelligence (AI) services. As a recognized speaker on topics ranging from AI to cybersecurity maturity, Paul has delivered impactful presentations within CDW, to customers, and to government organizations. He collaborates closely with customers and internal stakeholders to develop and deliver effective solutions and exceptional value.
    With experience in building and supporting data privacy and cybersecurity teams and developing and expanding cybersecurity and risk management programs for diverse clients, Paul has successfully led and executed multi-year cybersecurity projects across various industries.

    Paul's expertise spans across cybersecurity program development, cloud computing, artificial intelligence governance, risk assessment and gap analysis, risk management, PMO management, process development and improvement, and the security development lifecycle (SDLC). He has developed and implemented comprehensive cybersecurity programs in the medical, legal services, and financial services industries, spearheaded complex risk assessments and cybersecurity programs, and supported a cybersecurity services delivery framework for a premier consulting organization.
    He holds a B.S. in Business Administration from Kansas State University, an M.B.A. from Texas Christian University, and is currently earning an M.A. in International Security Studies from the University of Arizona. With over thirty years of industry experience, Paul possesses twenty active credentials in cybersecurity, data privacy, service management, and project management.

  • speaker photo
    John Loya
    VP, Field Engineering, Cyberhaven

    John Loya is the Vice President of Field Engineering at Cyberhaven. He has previously held roles at Microsoft, McAfee, and Digital Guardian. In his current role he assists customers and prospects globally with their data protection needs in terms of compliance, governance, privacy, classification, and security. He has worked previously as a developer, quality assurance engineer, and an automation engineer. He has been in the security space for the past 19 years with a strong focus on Data Loss Prevention and Insider Risk Management.

  • speaker photo
    Jason Lam
    Senior Manager, Schellman

    Jason Lam is a Senior Manager with Schellman based in Austin, TX. Prior to joining Schellman in 2015, Jason worked as an Enterprise Risk Management Associate at a regional audit firm, specializing in Sarbanes-Oxley (SOX) audits and System and Organization Controls (SOC) examinations. Jason is now primarily focused on ISO certifications for organizations across various industries as well as oversight and development of Schellman's ISO practice. Jason has achieved the following certifications relevant to the fields of accounting, auditing, and information systems security: Certified Public Accountant (CPA), Certified Information Systems Security Professional (CISSP), and Certified Information Systems Auditor (CISA).

  • speaker photo
    Danny Manimbo
    Principal | ISO Practice Director | AI Assessment Leader, Schellman

    Danny Manimbo is a Principal with Schellman based in Denver, Colorado. As a member of Schellman’s West Coast / Mountain region management team, Danny is primarily responsible for leading Schellman's AI and ISO practices as well as the development and oversight of Schellman's attestation services. Danny has been with Schellman for 10 years and has over 13 years of experience in providing information security and data privacy audit and compliance services. Danny has achieved the following certifications relevant to the fields of accounting, auditing, and information systems security and privacy: • Certified Public Accountant (CPA) • Certified Information Systems Security Professional (CISSP) • Certified Information Systems Auditor (CISA) • Certified Internal Auditor (CIA) • Certificate of Cloud Security Knowledge (CCSK) • Certified Information Privacy Professional – United States (CIPP/US)

  • speaker photo
    Happy Hour
  • speaker photo
    Panel Discussion
  • speaker photo
    Roya Gordon
    Deputy CISO, ENGIE North America

    Roya Gordon is the Deputy Chief Information Security Officer (CISO) of ENGIE North America, where she is responsible for the cybersecurity of renewable assets, including solar, wind, battery storage, and power plants. With a 20-year career spanning military intelligence, control systems cybersecurity at Idaho National Laboratory, cyber threat intelligence (CTI) in the energy sector, and Operational Technology (OT) expert in the tech startup space, Roya brings a wealth of expertise to her role. She oversees three dedicated teams focused on IT security, OT security, and IT/OT GRC, ensuring comprehensive protection and compliance. She holds a Master's degree in Global Affairs with a focus on Cyber Warfare from Florida International University (FIU) and served six years in the US Navy as an intelligence specialist.

  • speaker photo
    Gordon Groschl
    CISO & Director, Healthcare Technology Management, Texas Children's Hospital

    Gordon Groschl serves as the Chief Information Security Officer and Director of Healthcare Technology Management at Texas Children's Hospital. He is responsible for protecting the largest and number #1 ranked pediatric health system in the US. With over 25 years of comprehensive experience in telecommunication, healthcare cybersecurity, and technology management, Gordon brings dedication and passion for providing transformational cybersecurity change and organizational change management. He oversees 4 teams covering all aspects of cybersecurity and maintains CISSP, CCSP, HCISPP, and CHCIO certifications. Gordon is focused on transforming cybersecurity programs utilizing innovation in a business-centric approach.

  • speaker photo
    Manoj Tripathi, Moderator
    VP, Global Information & Product Security, Pindrop

    Manoj Tripathi is a seasoned CISO and has decades of experience in security, technology and leadership, across SaaS, Products and Consulting companies. Manoj is passionate about security and technology topics and has presented on security program management strategy and secure development topics at various security conferences. He holds the C|CISO and the CISSP certifications.

Conference Microsite!
Registration is quick and easy. Once you get started, use a browser on your phone or tablet to:

• Create a personalized agenda
• View maps of the venue and Exhibit Hall
• Use secure messaging to network with attendees
• View speaker slides after the conference
• Play CyberHunt, the app game, and compete for prizes
Propel your cyber career at SecureWorld!

Hone your skills and connect with your regional peers in InfoSec.