Guarding the Doors: Navigating Risk From Third-Party Code

CISO Council

September 9, 2021

Speakers

Larry Whiteside

Co-Founder & President

Cyversity

CISO Council Speaker

Larry Whiteside Jr. is a veteran CISO, former USAF Officer, and thought leader in the Cybersecurity field. He has 25+ years’ experience in building and running cybersecurity programs, holding C Level Security executive roles in multiple industries including DoD, Federal Government, Financial Services, Healthcare, and Critical Infrastructure.

Larry currently serves as the Chief Technology Officer and Chief Security Officer at CyberClan, a full service Global Incident Response and Managed Security Services Provider for the small to medium sized business.

Larry is also the Co-Founder, President, and on the Board of Directors at the International Consortium of Minority Cybersecurity Professionals (ICMCP), a 501(c)3 non-profit association that is dedicated to increase the number of minorities and women in the cybersecurity career field through providing workforce development that includes skills assessment, training, education, mentorship, and opportunity.

Since 2009, via Whiteside Security, which he founded, Larry has advised several corporate security executives and companies across the cybersecurity industry on how to make Cyber Security a number one objective to their business. He has helped CEOs and board members of private cybersecurity companies achieve their goals in sales, marketing, and customer retention.

Larry has spoken in front of C Level leadership and Board of Directors of some of the largest private and public sector organizations in America. A thought leader in the industry with extensive experience presenting at conferences such as the Gartner Security Summit, RSA Conference, and SC World Congress, Larry has been featured in many articles relating to information security and risk management.

Larry received his Bachelor of Science degree in computer science at Huston-Tillotson University.

Paige Adams

Group CISO

Zurich Insurance Group

CISO Council Speaker

Paige Adams has been a member of the Zurich executive team since 2014 and served as the Global Head of Cyber Response, Chief Information Security Officer for Zurich North America, and VP for Cyber Security before assuming his current role as Group Chief Information Security Officer in February 2018. Prior to joining Zurich, Paige spent a 26-year career in the United States Navy serving in a variety of intelligence and cyber roles. Paige has a Bachelor of Science in Business Administration (Computer Information Systems) from Hawaii Pacific University and a Masters in Computer Science from the US Naval Postgraduate School..

Dan Manley

Managing Director - CISO

CME Group

CISO Council Speaker

Managing Director and CISO with 30 years of professional experience related to cyber security, technology, risk management, audit and control with leadership roles at CME Group, Allstate and KPMG. Broad technology background, with specialization in – Cyber Security - Information Technology – Business Resiliency (continuity, availability and recovery) – Global Risk and Compliance – Large-scale program delivery

Mohammad Rupom

VP, Cyber Risk Intelligence

BNP Paribas Canada

CISO Council Speaker

Experienced leader, manager, coach and developer of talent with a proven ability to lead through influence. Mentoring the team members to help them grow by innovating new ideas solving problems by negotiating the roadblock. Work as a seasoned technical leader to grow the team from the start up level to a competitive state by taking proactive actions such as, supervising the projects through the agility, being the subject matter expert to provide high quality cyber security and intelligence through prioritizing the business need while keeping an eye on the analytic details, initiate the threat hunting capabilities. Develop relationships across the company with security leads/leaders in a cross-functional and collaborative environment to advance the classified work, develop transparency and trust, and make recommendations to advance the company's cyber security posture. Identifies new opportunities that can showcase the capabilities of the team to the audience and make the team champion organization wide as well as to the clients.

Tom Mustac

Senior Director Cybersecurity

Mount Sinai Health System

CISO Council Speaker

Dr Mustac is responsible for the cybersecurity of connected devices across The Mount Sinai Health System's internationally acclaimed facilities including the Icahn School of Medicine at Mount Sinai, eight hospital campuses, and more than 400 ambulatory practices with revenues exceeding $8B. Active management and remediation of known vulnerabilities across all platforms and technologies and incident response activites. Collaborate with device manufacturers, leading medical institutions, and government agencies to promote the adoption of standards, industry best practices, and building consensus to promote patient safety across all audiences. Education of stakeholders regarding the cyber risks of connected medical devices, IoT devices, and the mitigation of risk and best practices to protect the infrastructure of their facilities.

Igor Volovich

Security Strategist

Cyber Strategy Partners

CISO Council Speaker

Igor Volovich is the founder and chief strategist at Cyber Strategy Partners, a Washington, DC‐area cybersecurity leadership and strategy advisory practice focusing on enterprise risk management, cyber defense, governance, and compliance, and national critical infrastructure protection, serving large-scale multinationals, public sector agencies, and emerging segments such as Smart Cities, Internet‐of‐Things (IoT), Industrial-Internet-of-Things (IIoT), and Smart Grid.

Mr. Volovich has recently served as Senior Advisor, Enterprise Security Architecture and Strategy, Office of the CISO at the United States Postal Service, advising senior executive leadership on cyber risk management strategies, program development, capability maturity improvements, and governance and compliance for the Postal enterprise including IT and OT environments, creating and guiding transformative initiatives across the cybersecurity program.

Previously, Mr. Volovich served as the Chief Strategy Officer at Romad Cyber, an emerging-stage endpoint security startup, where he led product and market strategy efforts leading to two consecutive Security Shark Tank® wins for innovation and product strategy, and development of $30M in net-new enterprise business.

Mr. Volovich served as the Chief Information Security Officer (CISO) and Vice President of Global Information Security at Schneider Electric, a $32‐billion 185,000‐staff industrial automation and energy management multinational, leading the firm’s information security functions in the Americas region. Prior to joining Schneider through a merger, Mr. Volovich served as the Chief Information Security Officer (CISO) and Vice President of Information Security and Cyber Risk Management of Invensys plc, a global $5B market leader in the fields of industrial process control, automation, and safety systems (ICS/DCS/SCADA).

Before entering private practice, Mr. Volovich served as a senior member of the Corporate Incident Response and Intrusion Detection Team at Microsoft’s Trustworthy Computing (TwC) organization, where he was responsible for the architecture and management of security controls deployed in protection of Microsoft’s global information assets, as well as internal investigations and incident response functions.

 

Additionally, Igor has volunteered as a STARS Mentor at MACH37 (mach37.com), the nation’s first cyber-focused startup accelerator operated in partnership with Virginia’s Center for Innovative Technology (cit.org) and CIT GAP Funds, advising founders and leaders of emerging cyber technology firms on product development, market positioning, and business strategy.

 

Mr. Volovich has worked with and advised some of the world’s leading firms including United States Postal Service, Schneider Electric, Invensys, Microsoft, MSN, IBM, Altria/Philip Morris, Standard & Poors, AT&T Wireless, Freddie Mac, FINRA, Estée Lauder, US Department of Defense, US Department of Labor, British Telecom, Pep Boys, Toyota Financial, Aviva, Asurion, as well as tech startups such as Romad Cyber, TeraBeam Networks, eCharge, and LivingSocial.

 

Mr. Volovich holds the CISSP designation from ISC², Certified in Risk Controls (CRISC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) designations from the Information systems Audit and Control Association (ISACA), and the Certified Information Privacy Professional (CIPP) certification from the International Association of Privacy Professionals (IAPP).

 

Mr. Volovich is a member of ISC², ISACA, InfraGard, NIST Cloud Forensics Working Group, US DHS ICS‐CERT, Alliance for Gray Market and Counterfeit Abatement (AGMA Global), and the Airborne Law Enforcement Association (ALEA). In addition to his professional work, Mr. Volovich volunteered as a Flight Officer with Virginia Airborne Search and Rescue Squad, serving the Northern Virginia and DC area communities, attaining the rank of Lieutenant, and serving as Chair of the Membership Committee and a Fundraising Committee member.

September 9, 2021
Council
Navigating 3rd Party Risk
Filling the Talent Void
The Greatest Fears?
Technology Supply Chain
Being Effective…. Securely
AI and ML: Using Emerging Technologies to Reinforce Security Defense Efforts
Patch Management and Endpoint Protection
Data Security: Cloud Computing, Mobility and Regulations

Attend this event

Not available on September 9, 2021?

View other dates for the CISO Council

Agenda

All times Pacific Standard Time (PST)

3:00 PM-4:15 PM

Guarding the Doors: Navigating Risk From Third-Party Code

Open source libraries are widely leveraged by developers. In fact, 97 percent of the typical Java application is made up of open source libraries. But nearly 80 percent of developers never update third-party libraries after including them in codebase.

What does this mean for your applications? There is a good chance that your third-party libraries have undetected vulnerabilities. Scary, right?

The good news is that when alerted to vulnerabilities in open source libraries, developers tend to act quickly. This is especially true when developers understand how the vulnerability could impact their application.

Join us as we review our annual study on open source libraries, State of Software Security (SOSS) v11: Open Source Edition. We will explore the most popular open source libraries, how libraries are evaluated and selected, and how to eliminate risk by fixing vulnerabilities.


In Partnership With