RSS:2024 Sponsor Education and Engineering (SEE) Track 2 (Day 1) :: Rochester Security Summit

RSS:2024 Sponsor Education and Engineering (SEE) Track 2 (Day 1)

Navigating the Path to Compliance: CMMC, NIST, HIPAA, and Other Industry-Specific Standards

David Wolf, Just Solutions
10:00 am - 10:50 am

David Wolf, Vice President, CISO, CISSP

As the Vice President, David Wolf is a technology visionary and serial entrepreneur with over 30 years of experience in the IT industry. David attended Rochester Institute of Technology and has a Master of Science from Roberts Wesleyan College. David has achieved the highest industry security certifications of CISSP (Certified Information Systems Security Professional), CEH (Certified Ethical Hacker), and CCISO (Certified Chief Information Security Officer). He enjoys using his technical expertise to help fellow business owners get the most out of their IT, making him both the business and technology expert Just Solutions’ loyal clients rely on.

Navigating SEC Disclosure Rules: Building Defensible SOC & IR Processes

Jason Hicks, Kudelski Security
11:00 am - 11:50 am

Delve into the latest SEC disclosure regulations and other critical rules impacting your organization’s cybersecurity strategy. Learn how to fine-tune your SOC and incident response (IR) processes to meet these new requirements, explore the steps for determining materiality in collaboration with key business units and the Board, and address crucial CYA (cover your assets) considerations. This session will equip attendees with strategies to build a defensible, compliant approach that ensures your organization is fully prepared and protected.

Jason Hicks

Jason Hicks is a veteran information security and risk management executive with CISO experience in the finance, retail, information security service provider, entertainment, manufacturing, and logistics verticals. Currently Mr. Hicks is responsible for Kudelski Security’s incident response consulting services. Prior to Kudelski Security, Mr. Hicks was President of Mountain Cyber LLC, and provided virtual CIO & CISO services to a variety of clients. Mr. Hicks also advised various private equity & venture capital organizations on technology and security investments. Prior to Mountain Cyber LLC, Mr. Hicks served as field chief information security officer at Coalfire Systems. Prior to Coalfire Systems, Mr. Hicks was the Global CISO for the Kudelski Group (SWX: KUD) and was responsible for the global security programs at five member companies. Mr. Hicks also provided Virtual CISO services to multiple, multi-billion-dollar organizations. Prior to Kudelski Group, Mr. Hicks served as global chief information security officer (CISO) at Ares Management LLP (NYSE: ARES), a multi-national alternative asset manager, with more than $370 billion in assets under management.

Mr. Hicks has extensive experience managing response activities for major cyber security incidents including data breach and ransomware/malware, including the initial response, public notification and remediation. He has extensive experience working with regulators and law enforcement on breach response.

TBSecurity Frameworks and CyberSecurity Mesh ArchitectureA

Mark Rosenecker, Fortinet
1:00 pm - 1:50 pm

Security Frameworks, such as NIST CSF, CIS CSC, and ISO 27001, can provide a pathway to better cybersecurity posture, but often times the myriad solutions implemented to fulfill security controls leave the SecOps team overwhelmed. CyberSecurity Mesh Architectures, like the Fortinet Security Fabric, can help to solve this problem by providing out-of-box integration across solutions and a consistency of experience across products' GUI and CLI management interfaces. Learn how an integrated approach, with the operations team in mind at the forefront, can help your organization achieve your compliance goals while keeping your SecOps team happy at the same time.

Mark Rosenecker, Systems Engineer

Mark Rosenecker/Fortinet Systems Engineer, has spent the past 30 years working in IT in a variety of roles and the last 10 years in CyberSecurity. He holds certifications from several manufacturers, including HPE, Dell, VMware, F5, Aruba, McAfee, Cisco, Palo Alto Networks, and of course, Fortinet. His broad experience with servers, storage, virtualization, networking, and security brings a unique perspective to his approach to CyberSecurity. Mark’s over-arching philosophy with regards to design and architecture of any solution (but especially CyberSecurity) is KISS – Keep It Simple, Stupid!

A Guide to Identifying the Cybersecurity Metrics that Actually Matter

Jordan Farkas, Axonius
2:00 pm - 2:50 pm

When it comes to cybersecurity metrics, there’s a lot of elements to consider. What risks are most critical to your organization? Which business units are the most likely targets? Where does security sit in the list of business priorities? The real question is - where do you start? It all comes down to business context. Join Axonius for a roadmap on how to determine which cybersecurity metrics actually matter for your organization. We’ll cover:

Jordan Farkas, Senior Systems Engineer

Jordan Farkas is a Senior Systems Engineer for Strategic Accounts at Axonius. Jordan has a vulnerability management background and is coming up on 4 years at Axonius, where he leads the Field Technical Advisory Group for the Axonius Platform. He is based out of New York City, eats too much sushi, and is a fan of the Mets, Knicks, and unfortunately the Giants.