Day 2
7:00 am - 8:00 am Breakfast
8:00 am - 8:05 am Chairperson Remarks
8:05 am - 8:35 am Information Security for a Fully Interconnected World
In this presentation see a real world example of how to maintain a security programme in a world where users expect full access to data, the cloud, BYOD and a perimeter-less network
8:40 am - 9:10 am Business Meetings
9:10 am - 9:40 am Business Meetings
9:40 am - 10:30 am End User Panel: Privacy, Security and Compliance with General Data Protection Regulation
As organizations continue to leverage analytics to make critical business decisions, managing data throughout its lifecycle becomes more important. Data needs to be protected from initial creation through archiving the information. Privacy and security are headlines- executive leadership, including the C-Suite and Board of Directors are asking about especially with the new data privacy regulation going into effect by 2018. How does the cyber security executive ensure privacy, security and business requirements are aligned?
This session will cover some thoughts, possible approaches, lessons learned and a discussion what has worked and not worked for session participants.
Join this discussion:
•Where data is and who owns it throughout the life cycle
•Understanding common data practices to ensure compliance
•Reviewing key components of the new regulation and avoiding potential pitfalls
•Mastering data masking, encryption and other security controls
•Understanding requirements with the GDPR
Panelist: Bjorn Watne, Group CISO, Storebrand
Panelist: John Popolizio, CSO, New York Life
Panelist: Daniel Cisowski, CISO, Vorwerk & Co. KG
Panelist: Simon Legg, Executive Director Information Technology, PRA Health Sciences
Moderator: Adrian Davis, Managing Director EMEA, (ISC)2
10:30 am - 10:45 am Mid-Morning Tea
10:45 am - 11:30 am Brainweave: Empowering Organisations to Proactively Leverage the Dark Web & P2P Intelligence
Cyber exploitations are undermining the very integrity of our global markets, damaging brands, Intellectual Property, Privacy, and Financial transactions. Current risk mitigation efforts fall woefully short in addressing the origination of these incidents. In this session, we'll explore how to empower organizations with actionable Threat Intelligence that truly enables decision-makers to become proactive by leveraging the Dark Web and Peer-2-Peer domains. Sovereign will define these notorious domains and demonstrate why bad actors are also using Encrypted Messaging.
10:45 am - 11:30 am Master Class: Bridging the gap between Security and DevOps
Join John Smith, Senior Security Architect at Veracode where he explores the key pain points that are often felt between the security and DevOps teams which inevitably leads to a slower remediation time and potentially a less secure application.
• How to automate your DevOps pipeline
• How to get to remediation quicker (whilst still keeping security high)
• How to improve the people and processes of a DevOps programme
11:30 am - 12:00 pm Business Meetings
12:00 pm - 12:30 pm Business Meetings
12:35 pm - 1:40 pm Networking Lunch
1:35 pm - 2:20 pm Track: Empowering Unified IT/OT Systems to Secure the Enterprise
Explore common issues existing in many industrial control systems including the apparent disconnect between existing control and communication systems and classical corporate IT. As control systems continue to change away from proprietary systems, look at common challenges and incompatibilities between contemporary IT and OT systems. Explore the best methods for successful integration to ensure enhanced cyber security. Look at ways the Internet of Things is affecting critical infrastructure
In this discussion:
• Analysing security gaps across IT/OT
• Navigating threat intelligence, network security monitoring, and malware analysis
• Improving incident response and disaster recovery
In this discussion:
• Analysing security gaps across IT/OT
• Navigating threat intelligence, network security monitoring, and malware analysis
• Improving incident response and disaster recovery
1:35 pm - 2:20 pm Track: Optimizing Global Security in an Inter-Connected World
The world is becoming more and more inter-connected. Many US-based financial institutions are global enterprises with presence all around the world, either through expansion into other countries or via service agreements with third-party providers offshore. The approach to Security in different regions of the world can vary widely or even slightly, but important, ways. It is imperative to take a holistic view of security across all assets and sites globally in order to effectively manage it.
Topics to be discussed:
•Regulatory drivers for Banking and Financial Service Industry
•How to manage and measure risk with foreign third parties and subsidiaries
•Offshore protection of Intellectual Property and personally identifiable information
•Business continuity and disaster recovery
2:25 pm - 2:55 pm Business Meetings
2:55 pm - 3:25 pm Business Meetings
3:25 pm - 4:10 pm Master Class: Balancing Risk- Tackling Security Challenges with AI
Modern enterprises inevitably increase their attack surface area as they adopt new and different work practices in order to better compete. In order to support this reality requires a technologically sophisticated security solution. The need for endpoint protection is really nothing new, although most organizations don’t spend a lot of time thinking about it. Traditional security suites can only protect against threats that have been previously identified. These legacy solutions sort through signatures stored in their database to determine whether an application meets their profile of a threat; once detected, the malicious program is neutralized. But this all depends on the program already existing within the database. Not only are there millions of new threats released each month, but there are new threats that are able to hide their presence and mimic other types of file. Through artificial intelligence, enterprises can secure a system against previously unknown threats, in addition to threats that may hide their malicious behaviour while under scrutiny.
3:25 pm - 4:10 pm Think Tank: Live Hacking Presentation: Where Does Your Vulnerability Lie?
•Understanding a cyber attack from the perspective of the hacker: What are your vulnerabilities?
•Witnessing in real time how a hacker infiltrates your company’s network in order to gain access to your customer data
•Understanding the steps needed to be taken to ensure that your network and customer data remain secure on all touch points
4:10 pm - 4:30 pm Afternoon Tea
4:30 pm - 5:00 pm Business Meetings
5:00 pm - 5:30 pm Business Meetings
5:30 pm - 6:00 pm The Swiss Perspective of Data Regulations in the Financial Sector
In this session discuss the impact of data security regulations. Hear the Main differences and approaches in a country with strong compliance regulation and high level of confidentiality for customer’s data: cyber threats, risks and countermeasures in banking companies. This discussion will offer a glimpse at what Swiss corporations are doing and how EU regulations affect them.