PEER 150 New York Cyber Attic
Co-Hosted By: New York Institute of Technology
Tuesday, October 15th, 2019
8:30am - 9:15am - Hacking Social: The State of Social Media Security
James C. Foster
Founder & CEO
ZeroFox
Last year there were numerous stories of targeted attacks and compromise via social media. Protecting our brands, people, and organization in the context of new business communications platforms – social media and digital platforms – is more important than ever. With more Facebook business pages than .coms today, every brand is more susceptible to targeted attacks and exploitation via social media than ever before. With social media being the latest tool in the evolution of your brand growth and engagement programs, safeguarding it should be the cornerstone of a brand protection program as well. Brand protection in the social media age means grappling with the speed, volume and diversity of risks associated with social media. Marketers are expected to find and eliminate malicious content, brand impersonations and fake accounts, hacked accounts, and customer scams, all while succeeding in their day jobs of growing engagement and driving revenue. The ZeroFOX Platform helps marketing teams through accuracy and automation by protecting accounts from hijacking, taking down fake accounts impersonating your brand or key executives, stopping scams that exploit customer engagement and automatically remediating offensive content posted to your own page across all channels. With robust protection for all a marketing team’s social assets, marketers can focus their resources on creating value on social media, not fixing issues that arise.
9:30am - 10:15am - Imitation Attacks: Attackers' Tools, Motivations & Monetization Schemes
Dan Woods
Vice President, Shape Intelligence Center
Shape Security
During this session, former FBI agent and CIA cyber operations officer, Dan Woods, will explain attackers' tools, motivations and monetization schemes associated with actual imitation attacks against the Global 2000. He'll provide examples of human click-farm attacks, malware (such as Magecart), and digital fingerprint marketplaces (such as Genesis). He'll also explain several steps you can take to protect your brand and your customers
10:30am - 11:30am - Cybersecurity Strategies for Critical Infrastructure and Systems
Moderator:
Michael Nizich, Ph.D., Director, Entrepreneurship & Technology Innovation Center (ETIC), New York Institute of Technology
Panelists:
Amy Batallones, Cyber Security Operations Center (CSOC) Lead, Con Edison
Cedric Curry, CISO, NYC Citywide Administrative Services
Tariq Habib, CISO, State of NY Metropolitan Transportation Authority
Timothy Swope, CISO, Catholic Health Services
Amy Batallones is Manager of the Cyber Security Operations Center (CSOC) at Con Edison Company of New York, one of the largest investor-owned energy companies in the United States. Her team is responsible for 24/7 monitoring, analysis, and response to cybersecurity threats to the company. She previously worked in information security risk management designing secure architectures for IT and OT systems, conducting vulnerability and risk assessments, and drafting cyber security policies.
Batallones is part of several industry working groups leading the improvement of critical infrastructure cyber security on a national level. She is a frequent speaker at security conferences, including the International Conference for Cyber Security (ICCS) and NERC’s Grid Security Conference (GridSecCon). Batallones routinely works with NYC schools and organizations to support, mentor, and encourage women, youth, and minorities in STEM.
Batallones received her B.S. in Computer Science from Fordham University and M.S. in Management of Technology from New York University. Batallones previously served on the Executive Committee for IEEE’s New York Section and currently is an adjunct professor at Fordham University.
Cedric Curry is Chief information Security Officer (CISO) for NYC Department of Citywide Administrative Services, has 30 years’ experience in Information technology, holds a Bachelor’s Degree of Science in Management, as well as diverse studies in Intellectual Property Law, Psychology, and Business Administration. His IT related credentials includes a Certified Information Systems Security Professional (CISSP), Certified Project Manager (PMP), and Microsoft Certified Solutions Developer. Aside from his professional skillsets, Cedric is a Lifelong Martial Artist, a Sensei. Holding multiple Black Belts; in Chinese Goju System, Kyokushin Karate, and Krav Maga Martial Arts. This self-defense mental framework is especially applied in Cybersecurity as he protects and defends the information assets of the City of New York.
Cedric is a Husband of 22+ years, Father to a young son who is an avid Gamer and a Martial Artist. He enjoys teaching children and adult self-defense classes during off work hours; providing instruction on practical self-defense, leadership skills, and a working knowledge of mandarin language.
Cedric’s Motto is “Work Hard Train Hard and Never Give Up!”
Tariq Habib is the Chief Information Security Officer at the New York Metropolitan Transportation Authority (MTA), where he is responsible for all aspects of the MTA information security strategy and operations. He brings a unique perspective of someone who is experienced in Intelligent Transportation Systems programs as well as broad experience in IT and OT security strategy and operations. With many years of information technology and operational technology experience, Tariq is promoting an evolution of the security and risk management models. He has strong understandings of threat landscape, public policy, and critical infrastructure systems security. Prior to his role as the CISO of MTA, he worked as the Chief Technology Officer for the MTA Bridges & Tunnels. He has also worked at the Bronx District Attorney’s Office and held positions at various private sector companies.
Timothy Swope is currently the CISO of Catholic Health Services, an 18,000 employee hospital group in Long Island, NY. He is an Information Security and IT Risk Management professional who partners with Chief Information Security Officers and IT Governance, Risk and Compliance executives to assess and deliver IT Security and Risk Management programs to Health Care and Insurance, Pharmaceutical and government agencies. After spending over 2 decades assisting clients implement secure enterprise BI, EHR, Meaningful Use and other data science systems, Tim knows and understands the requirements and components that create a secure information security posture. A key area of his expertise centers around interpreting and applying Federal, State and Industry regulations such as: DSRIP, HITRUST, HIPAA, NIST SP 800-53, 21 CFR Part 11, Health Insurance Reform: Security Standards, FISMA (Federal Information Security Management Act) and locally the Zadroga Act to name a few. He also supported cyber security requirements for Medicaid’s Delivery System Reform Incentive Payment (DSRIP) Program at two of New York’s largest PPS’s (Performing Provider Systems) Northwell Health and NYC Health and Hospitals.
He has supported the IT Risk Management and IS Security initiatives of organizations that include Excellus BCBS, Medimmune/Astra Zeneca, MERCK, ENDO Pharmaceuticals, Novo Nordisk, Daiichi-Sankyo Solutions, Johnson and Johnson, District of Columbia Government office of the Chief Financial Officer, District of Columbia Water and Sewer Authority, City of Richmond, Virginia Department of Public Utilities, Virginia State Department of Health, and the Kentucky Department of Health Services, State of Oregon Department of Health Services as well as the U.S. Department of Labor and the Center for Medicare and Medicaid Services.
Tim holds a B.S. in Interdepartmental Mathematics and Economics from Indiana University along with certifications in Master Data Management, AI and Business Intelligence applications.
Michael Nizich, Ph.D., is the Director of the Entrepreneurship and Technology Innovation Center (ETIC) and an adjunct assistant professor of computer science at New York Institute of Technology. He also directs NYIT’s Center of Academic Excellence for Cybersecurity Education, designated by the U.S. Department of Homeland Security and the National Security Agency.
Through ETIC programs, Nizich regularly connects both domestic and international students with internships and full-time positions in cybersecurity, and serves as a member of the CTEA committee for cybersecurity for Suffolk County Community College.
Nizich has more than 25 years of professional experience in information technology in a variety of industries, including aviation, education, law enforcement, biotechnology, and cybersecurity. Nizich has held IT leadership positions in both private and publicly held companies.
With more than 10 years of college-level teaching experience, Nizich holds a Ph.D. in Information Studies from Long Island University, a master’s degree in Technology Systems Management from Stony Brook University, and a bachelor’s degree in Computer Information Systems from Dowling College.
11:45am - 12:30pm - Security: The New Business Priority Facing Management
Dr. Arthur Langer
Executive Director, Center for Technology Management
Columbia University
Rosa Mexicano
61 Columbus Ave at 62nd St
New York, NY 10023
1:45pm - 2:45pm - Crisis Management
Dana Deasy
CIO
Department of Defense
Crisis can happen at any time, typically when you least expect it. Technology leaders prepare for crisis by creating disaster recovery plans, contingency plans and role playing scenarios, but are they really ready? The complexity of a crisis and the unknown are just a few of the challenges that face IT leaders in today's complex environment. Whether it be social, economic, geo-political or cyber, crisis management can be overwhelming. As the CIO of many large organizations including BP, JPMorgan Chase, Seimens and currently the Department of Defense, Dana Deasy has been at the forefront of many different types of crisis challenges. Join Dana as he discusses each crisis and goes through the thought process and outcomes of crisis management.
3:00pm - 3:45pm - Cyber Risk Remediation Techniques
Raj Badhwar
SVP, Chief Information Security Officer
Voya Financial
The cyber risk and threat landscape has changed rapidly and dramatically over the last 5-10 years primarily due to the evolution of sophisticated malware, data exfiltration and breach tools, publicly known and high profile exploits of internet facing business applications containing sensitive customer or business data, monetization of the breached or exfiltrated data, the emergence of insider threat, the entry of nation states into Data and IP theft, and stricter regulatory guidelines at the local, state or federal level and enforcement of the same through censure, suspension and massive fines. It would thus not be a far-fetched assertion to make today that the cyber and reputational risk that a given business entity carries these days is equal to or greater than other more traditional Systematic/Market risks (e.g. Inflation, reinvestment, interest rate risks etc.) and Non-systematic risks (e.g. Capital, business, financial, currency, liquidity, regulatory and legislative risks), making Cyber Security very much an important Business issue that needs to be remediated. The presentation will focus on providing some common sense and fundamental best practices to help secure the Information Technology eco system for a Business Entity.
Raj Badhwar
Raj Badhwar is SVP, Chief information security officer for Voya Financial, Inc. (NYSE: VOYA), which helps Americans plan, invest and protect their savings — to get ready to retire better. Serving the financial needs of approximately 13.8 million individual and institutional customers in the United States, Voya is a Fortune 500 company that had $8.5 billion in revenue in 2018. The company had $560 billion in total assets under management and administration as of June 30, 2019.
Badhwar is responsible for leading the security engineering, architecture and operational functions for all domains (cloud security, data security, network security, application and system security, monitoring and response, vulnerability management, and identity and access management); setting the overall security strategy and direction; enhancing security standards and policies, risk and quality control assessments; and establishing compliance with required government, financial and privacy regulations, and also help Voya win in the market place.
Badhwar has more than 25 years of experience within the IT industry, with proven management, analytical and organizational skills, as well as expertise involving requirement analysis, architecture, design, development and management of technical resources for cybersecurity engineering and operations, and incident response. He has a mix of security, application development, and network management experience and possesses a strategic and tactical skill set for analytical and technical workloads. He also held a top-secret (SSBI) clearance from the U.S. Department of Defense.
Prior to joining Voya, Badhwar was the global head of information security for American International Group, Inc. (AIG), where he led global cyber security engineering and operations, aided by a strategy centered on the protection and preservation of IT systems, infrastructure and other computing assets. Prior to his role at AIG, he held senior Cyber Security and IT leadership roles at BAE Systems Inc., Bank of America, Time Warner Cable and AOL Time Warner.
Badhwar graduated from George Washington University (GWU) with a Master of Science (MS) in information systems technology and also holds a Bachelor of Science (BS) in electrical and electronics engineering from Karnatak University. He is a certified information systems security professional (CISSP), a certified ethical hacker (CEH), and also a Finra licensed securities professional (Series 99) among many other certifications. He has also co-authored 13 security patents, and has conducted extensive research in the areas of cryptography, zero trust networks, artificial intelligence (AI) code of ethics for cybersecurity, and AI-based pattern matching and reactive-response for cyber incident response and fraud mitigation.
Amy Batallones
Amy Batallones is Manager of the Cyber Security Operations Center (CSOC) at Con Edison Company of New York, one of the largest investor-owned energy companies in the United States. Her team is responsible for 24/7 monitoring, analysis, and response to cybersecurity threats to the company. She previously worked in information security risk management designing secure architectures for IT and OT systems, conducting vulnerability and risk assessments, and drafting cyber security policies.
Batallones is part of several industry working groups leading the improvement of critical infrastructure cyber security on a national level. She is a frequent speaker at security conferences, including the International Conference for Cyber Security (ICCS) and NERC’s Grid Security Conference (GridSecCon). Batallones routinely works with NYC schools and organizations to support, mentor, and encourage women, youth, and minorities in STEM.
Batallones received her B.S. in Computer Science from Fordham University and M.S. in Management of Technology from New York University. Batallones previously served on the Executive Committee for IEEE’s New York Section and currently is an adjunct professor at Fordham University.
Cedric Curry
Cedric Curry is Chief information Security Officer (CISO) for NYC Department of Citywide Administrative Services, has 30 years’ experience in Information technology, holds a Bachelor’s Degree of Science in Management, as well as diverse studies in Intellectual Property Law, Psychology, and Business Administration. His IT related credentials includes a Certified Information Systems Security Professional (CISSP), Certified Project Manager (PMP), and Microsoft Certified Solutions Developer. Aside from his professional skillsets, Cedric is a Lifelong Martial Artist, a Sensei. Holding multiple Black Belts; in Chinese Goju System, Kyokushin Karate, and Krav Maga Martial Arts. This self-defense mental framework is especially applied in Cybersecurity as he protects and defends the information assets of the City of New York.
Cedric is a Husband of 22+ years, Father to a young son who is an avid Gamer and a Martial Artist. He enjoys teaching children and adult self-defense classes during off work hours; providing instruction on practical self-defense, leadership skills, and a working knowledge of mandarin language.
Cedric’s Motto is “Work Hard Train Hard and Never Give Up!”
Dana Deasy
Mr. Dana Deasy is the Department of Defense Chief Information Officer (DoD CIO). He is the primary advisor to the Secretary of Defense for matters of information management, information technology, and information assurance, as well as non-intelligence space systems, critical satellite communications, navigation and timing programs, spectrum, and telecommunications.
Mr. Deasy has more than 38 years of experience leading and delivering large scale IT strategies in projects. He previously held several private sector senior leadership positions, most recently as Global Chief Information Officer (CIO) of JPMorgan Chase. There, he was responsible for the firm’s technology systems and managed a budget of more than $9 billion and over 40,000 technologists supporting JPMorgan Chase’s Retail, Wholesale, and Asset Management businesses.
Earlier in his career, Mr. Deasy served as the Chief Information Officer and Group Vice President at BP and as CIO for General Motors North America, Tyco International, and Siemens Americas. He also held several senior leadership positions at Rockwell Space Systems Division, including as Director of Information Management for Rockwell’s space shuttle program.
He was inducted into the CIO Hall of Fame in 2012 and the International Association of Outsourcing Professionals Hall of Fame in 2013, named Transformational CIO in 2017, and inducted into the 2019 Wash100 leaders.
James Foster
James C. Foster is the Founder and CEO of ZeroFOX. Foster is an industry veteran and a world-renowned thought leader. He’s published over a dozen books, holds patents, has spoken on Capitol Hill, and is a recognized keynote speaker. Foster started his career as a civilian in the United States Navy in Annapolis, Maryland. In 2005, Foster became a Fellow from the Wharton School of Business at the University of Pennsylvania and received his Bachelor of Science in Software Engineering from Capitol College.
Tariq Habib
Tariq Habib is the Chief Information Security Officer at the New York Metropolitan Transportation Authority (MTA), where he is responsible for all aspects of the MTA information security strategy and operations. He brings a unique perspective of someone who is experienced in Intelligent Transportation Systems programs as well as broad experience in IT and OT security strategy and operations. With many years of information technology and operational technology experience, Tariq is promoting an evolution of the security and risk management models. He has strong understandings of threat landscape, public policy, and critical infrastructure systems security. Prior to his role as the CISO of MTA, he worked as the Chief Technology Officer for the MTA Bridges & Tunnels. He has also worked at the Bronx District Attorney’s Office and held positions at various private sector companies.
Dr. Art Langer
Dr. Arthur Langer is the Academic Director of the Executive Masters of Science in Technology Management programs at Columbia University. He serves on multiple faculties at Columbia University, including the Graduate School of Business, the Department of Organization and Leadership at the Graduate School of Education (Teachers College) and the School of Continuing Education. Arthur is also the Senior Director of the Center for Technology, Innovation, and Community Engagement at Columbia University’s Fu Foundation School of Engineering and Applied Science. Art’s practice and research involves technology leadership, workforce development, adult mentoring programs, workplace learning, adult education, intellectual development and transformative learning. Art is also the Chairman and Founder of Workforce Opportunity Services (www.wforce.org), a nonprofit social venture that provides scholarships and careers to underserved populations around the world. Arthur holds a B.S. in Computer Science, an M.B.A. in Accounting/Finance, and a Doctorate of Education from Columbia University.
Michael Nizich, Ph.D.
Michael Nizich, Ph.D., is the Director of the Entrepreneurship and Technology Innovation Center (ETIC) and an adjunct assistant professor of computer science at New York Institute of Technology. He also directs NYIT’s Center of Academic Excellence for Cybersecurity Education, designated by the U.S. Department of Homeland Security and the National Security Agency.
Through ETIC programs, Nizich regularly connects both domestic and international students with internships and full-time positions in cybersecurity, and serves as a member of the CTEA committee for cybersecurity for Suffolk County Community College.
Nizich has more than 25 years of professional experience in information technology in a variety of industries, including aviation, education, law enforcement, biotechnology, and cybersecurity. Nizich has held IT leadership positions in both private and publicly held companies.
With more than 10 years of college-level teaching experience, Nizich holds a Ph.D. in Information Studies from Long Island University, a master’s degree in Technology Systems Management from Stony Brook University, and a bachelor’s degree in Computer Information Systems from Dowling College.
Timothy Swope
Timothy Swope is currently the CISO of Catholic Health Services, an 18,000 employee hospital group in Long Island, NY. He is an Information Security and IT Risk Management professional who partners with Chief Information Security Officers and IT Governance, Risk and Compliance executives to assess and deliver IT Security and Risk Management programs to Health Care and Insurance, Pharmaceutical and government agencies. After spending over 2 decades assisting clients implement secure enterprise BI, EHR, Meaningful Use and other data science systems, Tim knows and understands the requirements and components that create a secure information security posture. A key area of his expertise centers around interpreting and applying Federal, State and Industry regulations such as: DSRIP, HITRUST, HIPAA, NIST SP 800-53, 21 CFR Part 11, Health Insurance Reform: Security Standards, FISMA (Federal Information Security Management Act) and locally the Zadroga Act to name a few. He also supported cyber security requirements for Medicaid’s Delivery System Reform Incentive Payment (DSRIP) Program at two of New York’s largest PPS’s (Performing Provider Systems) Northwell Health and NYC Health and Hospitals.
He has supported the IT Risk Management and IS Security initiatives of organizations that include Excellus BCBS, Medimmune/Astra Zeneca, MERCK, ENDO Pharmaceuticals, Novo Nordisk, Daiichi-Sankyo Solutions, Johnson and Johnson, District of Columbia Government office of the Chief Financial Officer, District of Columbia Water and Sewer Authority, City of Richmond, Virginia Department of Public Utilities, Virginia State Department of Health, and the Kentucky Department of Health Services, State of Oregon Department of Health Services as well as the U.S. Department of Labor and the Center for Medicare and Medicaid Services.
Tim holds a B.S. in Interdepartmental Mathematics and Economics from Indiana University along with certifications in Master Data Management, AI and Business Intelligence applications.
Dan Woods
Dan Woods is the Vice President of the Shape Intelligence Center at Shape Security, a startup based in Silicon Valley. Shape protects over 1.6 billion internet users for the world’s largest retailers, banks, airlines and government agencies. Shape has created a unique and effective platform to defend websites against new forms of attack that use AI at massive scales. Prior to joining Shape, Woods served as Assistant Chief Special Agent of Special Investigations at the Arizona Attorney General’s Office where he investigated computer crimes and complex fraud. Prior to that, he spent 20 years with local, state, and federal law enforcement and intelligence organizations, including the FBI as a special agent where he investigated cyber terrorism; and the CIA as a technical operations officer where he specialized in cyber operations. Woods holds a Bachelor of Science in Computer Systems Engineering from Arizona State University (1998), and was an Honorary Commander, United States Air Force, 56th Security Forces Squadron, at Luke Air Force Base west of Phoenix (2014-2016).
For more information about sponsorship, please contact [email protected].
Shape Security is defining a new future in which excellent cybersecurity not only stops attackers, but also welcomes good users. Shape disrupts the economics of cybercrime, making it too expensive for attackers to commit online fraud, while enabling enterprises to more easily identify and transact with genuine customers on their websites and mobile apps. The world’s leading organizations rely on Shape as their primary line of defense against attacks on their web and mobile applications, including five of the Top 10 global banks, four of the Top 10 global airlines, two of the Top 5 global hotel chains and two of the Top 5 US government agencies. The Shape platform, covered by 55 patents, was designed to stop the most dangerous application attacks enabled by cybercriminal fraud tools, including credential stuffing (account takeover), fake account creation, and unauthorized aggregation. Today, the Shape Network defends 1.7 billion user accounts from account takeover and protects 30% of all US savings. The company is headquartered in Mountain View, California, and also has offices in London and Sydney.
enSilo protects businesses around the world from data breaches and disruption caused by cyber attacks. The enSilo Endpoint Security Platform comprehensively secures endpoints in real-time pre- and post-infection without alert fatigue, excessive dwell time or breach anxiety while also containing incident response costs by orchestrating automated detection, prevention and incident response actions against advanced malware. enSilo’s patented approach stops advanced malware with a high degree of precision, provides full system visibility and an intuitive user interface and combines next-generation antivirus (NGAV), application communication control, automated endpoint detection and response (EDR) with real-time blocking, threat hunting, incident response, and virtual patching capabilities in a single agent. The platform can be deployed either in the cloud or on-premises and supports multi-tenancy. To learn more visit http://www.ensilo.com.
ZeroFOX, the innovator of social media & digital security, protects modern organizations from dynamic security, brand and physical risks across social, mobile, web and collaboration platforms. Using targeted data collection and artificial intelligence-based analysis, ZeroFOX protects modern organizations from targeted phishing attacks, credential compromise, data exfiltration, brand hijacking, executive and location threats and more. Recognized as a Leader in Digital Risk Monitoring by Forrester, the patented ZeroFOX SaaS platform processes and protects millions of posts, messages and accounts daily across the social and digital landscape, spanning LinkedIn, Facebook, Slack, Twitter, HipChat, Instagram, Reddit, Pastebin, Tumblr, YouTube, VK, mobile app stores, the deep & dark web, domains and more.
New York Institute of Technology Auditorium
1871 Broadway
New York, NY 10023
New York Institute of Technology (NYIT) offers 90 degree programs, including undergraduate, graduate, and professional degrees, in more than 50 fields of study, including architecture and design; arts and sciences; education; engineering and computing sciences; health professions; management; and medicine. A non-profit, independent, private, and nonsectarian institution of higher education, NYIT has more than 9,000 students worldwide.