Guarding the Doors: Navigating Risk From Third-Party Code

CISO Council

August 18, 2021

Speakers

Larry Whiteside

Co-Founder & President

Cyversity

CISO Council Speaker

Larry Whiteside Jr. is a veteran CISO, former USAF Officer, and thought leader in the Cybersecurity field. He has 25+ years’ experience in building and running cybersecurity programs, holding C Level Security executive roles in multiple industries including DoD, Federal Government, Financial Services, Healthcare, and Critical Infrastructure.

Larry currently serves as the Chief Technology Officer and Chief Security Officer at CyberClan, a full service Global Incident Response and Managed Security Services Provider for the small to medium sized business.

Larry is also the Co-Founder, President, and on the Board of Directors at the International Consortium of Minority Cybersecurity Professionals (ICMCP), a 501(c)3 non-profit association that is dedicated to increase the number of minorities and women in the cybersecurity career field through providing workforce development that includes skills assessment, training, education, mentorship, and opportunity.

Since 2009, via Whiteside Security, which he founded, Larry has advised several corporate security executives and companies across the cybersecurity industry on how to make Cyber Security a number one objective to their business. He has helped CEOs and board members of private cybersecurity companies achieve their goals in sales, marketing, and customer retention.

Larry has spoken in front of C Level leadership and Board of Directors of some of the largest private and public sector organizations in America. A thought leader in the industry with extensive experience presenting at conferences such as the Gartner Security Summit, RSA Conference, and SC World Congress, Larry has been featured in many articles relating to information security and risk management.

Larry received his Bachelor of Science degree in computer science at Huston-Tillotson University.

Anthony Gonzalez

VP & CISO

QBE North America

CISO Council Speaker

Visionary, results and solutions-driven professional with 20+ years of experience in progressively responsible Cyber Security and IT leadership roles in the financial services, insurance, pharmaceutical, biotechnology, consumer goods,and chemical manufacturing industries. Adept in building and leading global Cyber Security, IT technical and support functions. Creative, resourceful problem solver with a track record of success in delivering cost-effective and value-added services to his customers. Additional experience in industrial engineering and process improvement. Specialties: Areas of expertise include: Cyber Security, Network Security,Application Security, Infrastructure Management and Security Incident Management, Disaster Recovery, Forensic Investigations, Operations Management, Financial Management, Project/Portfolio Management, Policy/Procedure Development, Budget Preparation, Strategic Planning, Process Design/Implementation, Risk Mitigation, Enterprise Architecture, IT Governance, Manufacturing/Laboratory Automation, Organizational Design, Vendor Audits, System, Start-Up Operations, Sarbanes-Oxley (SOX), Talent Development/Mentoring, International Team Management, and Regulatory Compliance

Kelvin Arcelay

SVP Information Security & IT Risk Management

EVO Payments International

CISO Council Speaker

Published industry expert with solid technical background, domestic and international successes delivering strategic solutions, global and culturally diverse teams, Cyber-security and process optimization. Specialties: - Customer-focused, revenue-optimization opportunities - Repeated successes optimizing service delivery strategies in multiple industries - Information Governance, Risk Management and Internal Controls - M&A Due Diligence and Integrations - Cyber-security and Internal Controls Risk ManagementPublished industry expert with solid technical background, domestic and international successes delivering strategic solutions, global and culturally diverse teams, Cyber-security and process optimization. Specialties: - Customer-focused, revenue-optimization opportunities - Repeated successes optimizing service delivery strategies in multiple industries - Information Governance, Risk Management and Internal Controls - M&A Due Diligence and Integrations - Cyber-security and Internal Controls Risk Management

Aditya PS

Chief Information Security Officer - CSU Program

Unisys

CISO Council Speaker

Aditya PS has over 18+ years of experience in increasingly responsible positions in Program Management, Cyber Security, Consulting and Cross Border Transaction. He has excellent technical and organizational skills enabling him to go both wide as well as deep at the same time. He poses excellent ability to persuade and influence both internal and external audiences through highly effective communication and presentation skills.

Expert business strategist; expertise in analyzing markets, developing innovative business strategies and overseeing company-wide implementation. Strong global experience across leading companies in healthcare, energy, technology, and capital investments. In-depth expertise in product development and strategic management. Facilitated international expansion of operations that brought new products to market. Able to manage large project teams and known for the high-quality deliverable that meets or exceed timeline and budgetary targets. Managed project delivery portfolio of over $100mn USD including several MAD (Mergers, Acquisitions and Divestiture). He has helped clients enter new markets swiftly and achieve their business objectives in emerging markets.

A High-energy leader who thrives on leading the impossible and having track record of motivating staff to achieve exceptional business performance. He has a proven ability to work within highly dynamic environments with unstructured situations requiring vision, leadership, and resourcefulness to successfully translate an opportunity into a significant enterprise initiative and executing it.

Managed successful delivery of multi-$M worth of Projects to align business goals with solutions to drive competitive advantage and bottom-line gains. Expert aptitude for project planning, financial controls, change management, legal & regulatory compliance, strategic introductions, advisory services, and disciplined meeting facilitation.

Experience in managing multi-million dollar investments.

August 18, 2021
Council
Navigating 3rd Party Risk
Filling the Talent Void
The Greatest Fears?
Technology Supply Chain
Being Effective…. Securely
AI and ML: Using Emerging Technologies to Reinforce Security Defense Efforts
Patch Management and Endpoint Protection
Data Security: Cloud Computing, Mobility and Regulations

Agenda

All times Eastern Standard Time (EST)

3:00 PM-4:15 PM

Guarding the Doors: Navigating Risk From Third-Party Code

Open source libraries are widely leveraged by developers. In fact, 97 percent of the typical Java application is made up of open source libraries. But nearly 80 percent of developers never update third-party libraries after including them in codebase.

What does this mean for your applications? There is a good chance that your third-party libraries have undetected vulnerabilities. Scary, right?

The good news is that when alerted to vulnerabilities in open source libraries, developers tend to act quickly. This is especially true when developers understand how the vulnerability could impact their application.

Join us as we review our annual study on open source libraries, State of Software Security (SOSS) v11: Open Source Edition. We will explore the most popular open source libraries, how libraries are evaluated and selected, and how to eliminate risk by fixing vulnerabilities.

In partnership with:

In Partnership With