Nordics-The Greatest Fears?

CISO Council

May 27, 2021

CISOs know that time does not stand still and need to exhibit adaptability and resilience, especially during times of disruption. Being forced to make extremely fast decisions with high levels of uncertainty requires the latest knowledge within the industry’s latest technologies. The CISO Vision Council is a virtual gathering for CISOs to connect with peers and discuss challenges and solutions that will help their organizations to stay ahead of technology innovations, regulations and an ever-changing risk landscape.

Speakers

Bjørn Watne

SVP & CISO

Storebrand

CISO Council Speaker

Bjørn R. Watne has been working with Information Security for two decades, and is currently CISO for the Storebrand Group – the largest private asset manager in the Nordics. Previous to joining the financial sector, Watne spent many years within Telecoms as well as working as a consultant with different industries.

He has his BSc in Computer Science from Agder University in Norway, and an MBA from ESCP in Paris, France. Professional certifications include CISSP and ISSMP from (ISC)2, and CISA, CISM, CRISC, CGEIT and CDPSA from ISACA. Over the years he's held numerous board positions with professional associations and is a regular speaker at industry events.

Tor Stale Hansen

Itera

CISO Council Speaker

Tor-Ståle Hansen is Itera Group's Chief Information Security Officer (CISO). ITERA 'security' embraces the disciplines of cybersecurity, information security, data protection and privacy, and is governed through all three perspectives; governance, risk management and compliance. As Group CISO, he reports to the board and is a member of Group management.

 

Tor-Ståle came from the positions Global CISO in Capgemini Global Business Line Insights & Data, and a commercial role as Head of Global Portfolio Data Protection & Privacy. He led a commercial portfolio in privacy and he has negotiated and provided services with many F500 companies. In addition, Tor-Ståle led Capgemini's internal work with Ethics & Trust in relation to AI, ML, and Cloud & Platforms and was also co-editor of ‘Capgemini Technology & Offerings Playbook’ together with Global CTO.

 

Tor-Ståle has experience with known security frameworks; NIST, CIS, SCF, ISO27k, various laws and regulations within security, intelligence activities, the financial industry's ICT regulations, the health service's norm for information security, cyber and information security in petroleum activities, aviation, etc. His dataprotection and privacy expertise cover both the European GDPR, the US CCPA and the Brazilian LGPD and other state regulation. Tor-Ståle has led Capgemini Research Institute's publication "Championing Data Protection and Privacy - a source of competition advantage in the digital age" and has developed new methods and technology within GRC, (recognized and award as new technology).

 

Tor-Ståle has studied ‘Cybersecurity Risk Management’ at Harvard Kennedy School (HKS) Harvard University, mathematics, chemistry, micro biology at the University of Tromsø, (and he is a former commercial pilot). Tor-Ståle is a guest lecturer for the Master students in Strategic Security magament at the University of Agder, and he is a cybersecurity newtwork leader at JUC, a nordic professional network for lawyers.

Mads Syska Hasling

CISO

Saxo Bank

CISO Council Speaker

Global Information and Cyber Security/Risk executive with 15+ years’ work experience. Leading through leaders, building and maintaining talents. Holding a Master of Science in Software Engineering and multiple security certifications (CISSP, CISM, CSSLP and CRISC).

Jesper Olsen

CISO

Palo Alto Networks

CISO Council Speaker

Personally, Jesper is Married to Rikke going on 15 years, has two teenage daughters, Josefine aged 17 and Lilliane aged 13. In a work perspective, Jesper is a military police veteran and has worked with security in all aspects; Physical security, security in software development and Communications security as Security Officer. In his latest position as Senior Information Security Officer at Maersk Drilling, Jesper was responsible for the Strategic and tactical Cyber & Information Security Programs for offices and offshore drilling units, as well as responsible for the SOC and external security providers. In his spare time Jesper plays around with various technology projects and hacking techniques and works out at home. In addition, Jesper educates young people, their parents and their teachers in online ethics and the risks of overexposing and oversharing on Social Media platforms.

Chris Roberts

vCISO

Hillbilly Hit Squad

CISO Council Speaker

Hacker, InfoSec, Safety, CyberStuff Researcher, Advisor, @Hacknotcrime henchman, and various other names on the technical side of the world Chris is currently serving as a vCISO or advisor for a number of entities and organizations around the globe. His most recent projects are focused within the threat intelligence, identity, cryptography, Artificial Intelligence, and services space. I’ve been fortunate to be elbow deep in technology for more years than I care to remember, and these days am involved in both tactical and strategic discussions with clients across the spectrum of industries talking maturity, risk, and how to effect change. Oh, and I just got called a Scottish Security Warlock....I’m kinda digging it. Happy to connect, to talk and discuss what we can ALL do to effect change in this world, to collaborate and to communicate in a way that benefits all….I’d prefer folks didn’t use this forum to sell me certs, software or anything that has a hooded matrix theme (I DO come with a warning label...)

Igor Volovich

Security Strategist

Cyber Strategy Partners

CISO Council Speaker

Igor Volovich is the founder and chief strategist at Cyber Strategy Partners, a Washington, DC‐area cybersecurity leadership and strategy advisory practice focusing on enterprise risk management, cyber defense, governance, and compliance, and national critical infrastructure protection, serving large-scale multinationals, public sector agencies, and emerging segments such as Smart Cities, Internet‐of‐Things (IoT), Industrial-Internet-of-Things (IIoT), and Smart Grid.

Mr. Volovich has recently served as Senior Advisor, Enterprise Security Architecture and Strategy, Office of the CISO at the United States Postal Service, advising senior executive leadership on cyber risk management strategies, program development, capability maturity improvements, and governance and compliance for the Postal enterprise including IT and OT environments, creating and guiding transformative initiatives across the cybersecurity program.

Previously, Mr. Volovich served as the Chief Strategy Officer at Romad Cyber, an emerging-stage endpoint security startup, where he led product and market strategy efforts leading to two consecutive Security Shark Tank® wins for innovation and product strategy, and development of $30M in net-new enterprise business.

Mr. Volovich served as the Chief Information Security Officer (CISO) and Vice President of Global Information Security at Schneider Electric, a $32‐billion 185,000‐staff industrial automation and energy management multinational, leading the firm’s information security functions in the Americas region. Prior to joining Schneider through a merger, Mr. Volovich served as the Chief Information Security Officer (CISO) and Vice President of Information Security and Cyber Risk Management of Invensys plc, a global $5B market leader in the fields of industrial process control, automation, and safety systems (ICS/DCS/SCADA).

Before entering private practice, Mr. Volovich served as a senior member of the Corporate Incident Response and Intrusion Detection Team at Microsoft’s Trustworthy Computing (TwC) organization, where he was responsible for the architecture and management of security controls deployed in protection of Microsoft’s global information assets, as well as internal investigations and incident response functions.

 

Additionally, Igor has volunteered as a STARS Mentor at MACH37 (mach37.com), the nation’s first cyber-focused startup accelerator operated in partnership with Virginia’s Center for Innovative Technology (cit.org) and CIT GAP Funds, advising founders and leaders of emerging cyber technology firms on product development, market positioning, and business strategy.

 

Mr. Volovich has worked with and advised some of the world’s leading firms including United States Postal Service, Schneider Electric, Invensys, Microsoft, MSN, IBM, Altria/Philip Morris, Standard & Poors, AT&T Wireless, Freddie Mac, FINRA, Estée Lauder, US Department of Defense, US Department of Labor, British Telecom, Pep Boys, Toyota Financial, Aviva, Asurion, as well as tech startups such as Romad Cyber, TeraBeam Networks, eCharge, and LivingSocial.

 

Mr. Volovich holds the CISSP designation from ISC², Certified in Risk Controls (CRISC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) designations from the Information systems Audit and Control Association (ISACA), and the Certified Information Privacy Professional (CIPP) certification from the International Association of Privacy Professionals (IAPP).

 

Mr. Volovich is a member of ISC², ISACA, InfraGard, NIST Cloud Forensics Working Group, US DHS ICS‐CERT, Alliance for Gray Market and Counterfeit Abatement (AGMA Global), and the Airborne Law Enforcement Association (ALEA). In addition to his professional work, Mr. Volovich volunteered as a Flight Officer with Virginia Airborne Search and Rescue Squad, serving the Northern Virginia and DC area communities, attaining the rank of Lieutenant, and serving as Chair of the Membership Committee and a Fundraising Committee member.

May 27, 2021
Council
Navigating 3rd Party Risk
Filling the Talent Void
The Greatest Fears?
Technology Supply Chain
Being Effective…. Securely
AI and ML: Using Emerging Technologies to Reinforce Security Defense Efforts
Patch Management and Endpoint Protection
Data Security: Cloud Computing, Mobility and Regulations

Agenda

All times Central European Time (CET)

3:00 PM-4:15 PM

The Greatest Fears?

The biggest fear is not the technology, it is the mistakes made by the people using the technology that could potentially lead to a cyberattack. The majority of CISOs agree that an employee carelessly falling victim to a phishing scam is the most likely cause of a security breach. Most also agree that they will not be able to reduce the level of employee disregard for information security. How do we guard against human error without limiting employee efficiency and productivity?