The COVID-19 pandemic dramatically increased the State of California’s reliance on virtual tools for meetings, shopping, education, healthcare and government services. Moving quickly to virtual environments also opened the door for a greater number of cyberattack attempts on information technology assets in California, across the country and throughout the world. Organized cybercriminal groups have increased phishing, ransomware and other cybercrimes against government entities, healthcare organizations, public utilities, education facilities and corporations. The 2022 State of California Cybersecurity Education Summit, hosted by the California Department of Technology (CDT), the Governor’s Office of Emergency Services (CalOES), California Highway Patrol (CHP) and the California Department of Military (CalGuard), will include cybersecurity leaders from state and local government throughout California.
The Cybersecurity Education Summit is a can’t-miss event for security professionals and educators from every sector. It’s an annual highlight in the daily effort to protect Californians from cyber risks that can upend daily life and sideline businesses. I look forward to attending in-person in 2022, engaging with cyber professionals and educators from the public and private sector, and learning about the latest products, training and strategies to protect our state. Please join CDT, CalOES, CHP and the CA Dept of Military at the Cybersecurity Education Summit this October.
Vitaliy Panych, California State Chief Information Security Officer
Thursday, October 20 |
|
8:00 am Pacific |
Registration and Morning RefreshmentsMagnolia Room and Grand Nave Lobby |
9:00 am Pacific |
Opening RemarksCamellia/Gardenia RoomLiana Bailey-Crimmins, State Chief Information Officer, Department of Technology, State of California Miriam Ingenito, Undersecretary, Government Operations Agency, State of California Tom Osborne, Deputy Director, Homeland Security, California Governor’s Office of Emergency Services Vitaliy Panych, State Chief Information Security Officer, Department of Technology, Office of Information Security, State of California Major General Matthew Beevers, Adjutant General, California Military Department |
9:20 am Pacific |
General Session – A National Focus on CybersecurityCamellia/Gardenia RoomThe Cybersecurity and Infrastructure Security Agency (CISA) works with partners to defend against today’s threats and collaborating to build more secure and resilient infrastructure for the future. In this session, Region 9 Director, David Rosado, will provide an update on key focus areas for CISA including their 2023-2025 strategic plan and training resources and opportunities. David Rosado, Director, Region 9, US Department of Homeland Security |
9:45 am Pacific |
General Session - The Hacker Mindset - A Spotlight on Global GovernmentCamellia/Gardenia RoomModerator: Mike Driessen, Vice President, Government Technology Chris Wysopal, Co-Founder and Chief Technology Officer, Veracode |
10:15 am Pacific |
Networking BreakMagnolia Room and Grand Nave Lobby |
10:45 am Pacific |
Concurrent SessionsCal-Secure Roadmap – What it Contains and What Organizations Should be DoingTofanelliCal-Secure is the State of California Executive Branch’s five-year information security roadmap. The roadmap was created through a collaborative process with the California Cybersecurity Integration Center (Cal-CSIC) and its four critical partners: the California Governor’s Office of Emergency Services (Cal OES), California Highway Patrol (CHP), California Department of Technology (CDT), and California Military Department (CMD) and the state government security community. This session will provide an overview of the roadmap and what State of California technology and business leaders should be doing to support this effort in their own organization. Moderator: Vitaliy Panych, State Chief Information Security Officer, Department of Technology, Office of Information Security, State of California John Cleveland, Deputy State Chief Information Security Officer, Department of Technology, State of California Kathy Cruz, Director, Advisory Services, Government Cybersecurity, KPMG LLP Zach Nandapurkar, Technical Account Manager, Tanium Securing the Modern Workplace from a Multitude of ThreatsCarrThe pandemic may be waning but the requests for full-time and hybrid remote work schedules have not let up. What does this mean for maintaining a secure environment? How do you maintain a secure hoteling environment? Does BYOD become a permanent part of your plans? How do you handle facial recognition and other security log-in systems that protect your environment regardless of user location? This session will discuss options that many organizations are currently implementing. Moderator: Mike Driessen, Vice President, Government Technology Baird Cowan, Chief Technology Officer, Department of Consumer Affairs, State of California Jose Jaramillo, Agency IT Risk Officer, Labor and Workforce Development Agency, State of California Mike Spanbauer, Field Chief Technology Officer and Architect, Security, Juniper Networks Working with Business Leaders as an ISOBataglieriThe security team for any organization, be it a one-person shop or a larger team, has the role of enabling and protecting the mission of the organization. A key relationship will be needed with business leaders at the top and middle level of the organization. What do you need from them? How should you communicate with them? What is their language and how do you translate yours to better match theirs? This session will focus on why, how and when to create that relationship so the role of the ISO becomes more strategic in all business plans moving forward. Moderator: Lloyd Indig, Agency Information Security Officer, Health and Human Services Agency, State of California Russell Fong, Chief Administrative Officer, Office of State Controller, State of California Adam German, Chief Information Security Officer, Office of State Controller, State of California Jeff Jennings, National SLED Practice Director, Fortinet Douglas Leone, Agency Information Security Officer (AISO), Labor and Workforce Development Agency, State of California The CISA Zero Trust Network Architecture (ZTNA) Maturity Model ExplainedBeavisPost Covid, many organizations are now struggling with a more distributed network footprint, new SAAS applications, and some employees on permanent work from home status. Organizations are turning to Zero Trust architectures to adapt their IT services to manage these new realities. This talk will walk through the CISA ZTNA Maturity Model and how it can be used to help organizations define a rational and prioritized multi-year ZTNA strategy. Trevor Hogan, Director of Strategy and Risk, e360 Data Loss Prevention – Best Practices and PlanningBondiAt its heart, data loss prevention (DLP) gives an organization control over what employees can share and prevents unintended exposure of sensitive information. What is the minimum bar for implementing a DLP system? How can you classify and track data as part of your efforts? Is an encryption system an important tool to deploy and when would it make sense? And lastly, how do you handle data at rest versus data “in flight?” This session will provide an overview of DLP and a myriad of points that should or could be in your short term and long term plans. Moderator: Joe Panora, Senior Fellow, Center for Digital Government Ken Kojima, Chief Information Security Officer, Department of Corrections and Rehabilitation, State of California Ron Mendoza, Principal Security Architect, Franchise Tax Board, State of California Moinul Khan, Vice President, Product Management, Zscaler 2022 Status of California Cybersecurity Education and Workforce DevelopmentCompagnoThis presentation will highlight the current state of California Cybersecurity Education and Workforce Development. This will include a broad overview and discussion of key facets and recent developments in cybersecurity education (K-12 and Higher Education) statewide. The group will focus on growing collaborations among major stakeholders and key partners; career education pipelines; degree, certificate, and digital badging; and recent innovations in state/regional utilization of effective cybersecurity workforce development models including apprenticeships. Moderator: Keith Clement, Professor, California State University, Fresno Erle Hall, Education Programs Consultant, Department of Education, State of California Markus Geissler, Ph.D., Professor, Cosumnes River College |
11:45 am Pacific |
LunchCamellia/Gardenia Room |
12:30 pm Pacific |
General Session – Cybersecurity in Today’s Threat LandscapeCamellia/Gardenia RoomThis panel of government leaders and industry experts will address key areas of focus for the coming year. While every organization has its own unique set of challenges, there is a baseline and a set of long-term goals all should be working towards. What support can you expect from State of California executives? What industry coalitions exist and what should government technology professionals do as a result? This session will strive to provide basic answers but to also provide a roadmap for government organizations to follow. Moderator: Jennifer Axt, Vice President, SLED, Tanium Peter Liebert, Former State Chief Information Security Officer, State of California Vitaliy Panych, State Chief Information Security Officer, State of California Mark Weatherford, Former State Chief Information Security Officer, State of California and State of Colorado |
1:15 pm Pacific |
Networking BreakMagnolia Room and Grand Nave Lobby |
1:30 pm Pacific |
Concurrent SessionsSecurity and Privacy Risk ManagementTofanelliLarge, medium and small organizations have the same challenges but have different resources available to them. What does a cybersecurity risk management approach look like to all of them? What are the basics? Where and when do you need partners? What resources are available to you so you don’t have to go it alone? This session will include takeaways on security and privacy risk management regardless of how large or small your organization is. The challenges are the same, the solutions may be different. Moderator: Lloyd Indig, Agency Information Security Officer, Health and Human Services Agency, State of California Tim Boswell, Outbound Product Manager, ServiceNow Vivian Yan, Assistant Chief Security Officer, Security Operations Section Manager, Privacy, Security and Disclosure Bureau, Franchise Tax Board, State of California Applying the National Institute of Standards and Technology (NIST) Cybersecurity FrameworkCarrMany organizations are implementing an adaptive, cyber-resilient digital strategy by using the cybersecurity framework outlined by NIST. The framework covers the areas of protection, detection, response, recovery and identity with the goal to foster risk and cybersecurity management communications amongst both internal and external organizational stakeholders. Michael Melore, Senior Cyber Security Advisor, IBM Security Today’s Adversary – Who are they and What are they Doing?BataglieriAs cybersecurity professionals, today’s adversary is seemingly everywhere. From the untrained employee or resident to the nation state, the adversaries are numerous and have their own characteristics and goals. What exactly are the adversaries doing today? What is their motivation? How do we defend against them, or at least the most common of them? How are they getting access today and how can we best detect and/or prevent them from doing damage or stealing information? This session will be an update on the current state of the adversary with practical advice to thwart their efforts. Moderator: Mike Driessen, Vice President, Government Technology Andy Piazza, Global Leader of Threat Intelligence, IBM Security Michael Aguilar, Principal Consultant, SecureWorks Adversary Group Joseph Maio, Information Security Officer/Security Operations Center Manager, California Natural Resources Agency Making Security Everyone’s JobBeavisIt may be trite to say that security is everyone’s job but it is also quite true! So how does one accomplish this? What role does organization management and leadership play? How can cybersecurity teams and technology teams ensure that this is known and being done? This session will provide practical ideas on education, testing, the role of organizational leadership, practical consequences for failing tests and other practices to help you improve security awareness throughout your organization. Moderator: Joe Panora, Senior Fellow, Center for Digital Government Teri Bennett, Consultant Partner, Pinnacle Advocacy Michele Myauo, Managing Director – NA Public Service Security Lead, Accenture Lessons from Gamification and Cybersecurity: The Space Grand Challenge 2022BondiOver the past five years, Cal Poly's California Cybersecurity Institute (CCI) has grown its cyber Capture the Flag (CTF) competition, designed for middle and high school students, into an immersive space-focused cybersecurity challenge. This session will discuss lessons from gamifying cyber education, incorporating Cal Poly's Learn By Doing philosophy and recruiting prospective students towards STEM degrees at Cal Poly, and cybersecurity training/credentials. Dustin DeBrum, Operations Director, California Cybersecurity Institute, New Programs & Digital Transformation Hub (DxHub) Cal Poly |
2:30 pm Pacific |
Networking BreakMagnolia Room and Grand Nave Lobby |
2:45 pm Pacific |
Concurrent SessionsSecurity Architecture – Design and ImplementationTofanelliThe purpose of a security architecture is to reduce cyber security threats and the expenses that might result from them. A security architecture is a set of models, methods, and security principles that align with organizational objectives, keeping your organization safe from cyber threats. Through security architecture, business requirements are translated to executable security requirements. The State of California SIMMs covers some of this but there are many nuances based on the size and maturity of your organization. In this session, a mix of speakers will provide guidance on implementing and improving your security architecture. Moderator: Mike Driessen, Vice President, Government Technology Dustin Grimmeissen, Senior Director, Specialty Sales, AHEAD, Inc. Maria Thompson, Executive Government Advisor, AWS Identity Proofing from A to ZCarrIdentity proofing is the process of verifying a user's identity: confirming that they are who they say they are. This may sound like ordinary authentication, the kind based on a username/password combination, but identity proofing actually comes into play before users get their credentials to access an application or alongside the traditional authentication process. That brings up the question of how to balance service friction with identity proofing. In this session, presenters will discuss concepts, tools and methods to help organizations better understand and plan for identity proofing as they modernize internal and external systems. Moderator: Steve Towns, Deputy Chief Content Officer, Content Studio, Government Technology John Evans, Chief Technology Advisor, Cybersecurity, World Wide Technology Greg Fair, Digital Identity Chief and Acting Chief Product Officer, Department of Technology, State of California Todd Ibbotson, Information Security Officer, Employee Development Department, State of California Matt Thompson, SVP & General Manager, Public Sector Solutions, Socure Third-Party Risk Management Planning and ImplementationBataglieriWhat steps do you need to take to ensure that third parties do not compromise your security posture? What are some best practices for ensuring security while using third-party hosted solutions? What rules are currently in place that can guide my decisions in this area? How should incident response be updated to reflect my use of third-party hosted solutions? These questions and more will be addressed in this session as the ever-changing landscape of technology continues to embrace more solutions that are outside the organizational firewalls. Moderator: Robert Mayorga, Chief Security Officer, Franchise Tax Board, State of California Albert Arboleda, Chief Information Security Officer, Information Security, CalPERS Kasia Killgore, Program Manager, Data Oversight Program, Franchise Tax Board, State of California Recruiting, Retaining and Building Your Cybersecurity TeamBondiPay and telework will get you started but those are not the only tools you can employ as you recruit and work to retain your cybersecurity team. As the cybersecurity threat landscape has grown, the pipeline has become increasingly too small to fill the vacuum of organizational needs in both the public and private sectors. What are some other tactics you can employ given the constraints of public service organizations? How can you become an employer of choice? This panel will discuss things an organization can do to narrow the gap between private sector opportunities, and the perks they offer, and the long-term stability of the public sector as well as the importance of the mission – serving the residents of our state. Moderator: Joe Panora, Senior Fellow, Center for Digital Government Kenneth Anyanwu, Success Coordinator, SEIU Local 1000 Adele Burnes, Deputy Chief, CA Division of Apprenticeship Standards Mike Marshall, Agency Information Security Officer, Environmental Protection Agency, State of California |
3:45 pm Pacific |
Networking BreakMagnolia Room and Grand Nave Lobby |
4:00 pm Pacific |
Awards ProgramCamellia/Gardenia Room |
4:30 pm Pacific |
Awards Program Networking ReceptionMagnolia Room and Grand Nave LobbyNetwork with your colleagues and discuss technology solutions with the event exhibitors. Conference times, agenda, and speakers are subject to change. |
1230 J Street
Sacramento, CA 95814
(916) 447-1700
Liana Bailey-Crimmins
State Chief Information Officer and Director
Department of Technology
State of California
Andrew Bell
Information Security Officer
Military Department
State of California
Brenda Bridges Cruz
Deputy Director, Office of Professional Development
Department of Technology
State of California
Jennifer Chan
Chief Information Officer
State Lottery
State of California
Keith Clement
Professor
California State University, Fresno
John Cleveland
Deputy State Chief Information Security Officer
Department of Technology
State of California
Brian Colt
Information Security Officer
Department of Corrections and Rehabilitation
State of California
Michael Crews
Chief Information Officer (Acting)
Governor's Office of Emergency Services
State of California
Jun Dai
Associate Professor
California State University, Sacramento
Faith DeuPree
Information Security Officer
Department of Finance
State of California
Ray Diggins
Chief Information Officer
Highway Patrol
State of California
Pam Greeley
Information Security Officer
Highway Patrol
State of California
Eric Harrald
Chief Information Security Officer
Department of Motor Vehicles
State of California
Glenn Herdrich
Information Security Manager
County of Sacramento
Lloyd Indig
Agency Information Security Officer
Health and Human Services Agency
State of California
Karl Kopper
Chief Information Security Officer
Department of Transportation
State of California
David Lane
Acting Commander, CalSIC
Offices of Emergency Services
State of California
Douglas Leone
Agency Information Security Officer
Labor and Workforce Development Agency
State of California
Mark Lourenco
IT Security Director
Department of Education
State of California
Joseph Maio
Information Security Officer
Natural Resources Agency
State of California
Mike Marshall
Chief Information Security Officer
Environmental Protection Agency
State of California
Robert Mayorga
Chief Security Officer
Franchise Tax Board
State of California
Kristin Montgomery
Chief Information Officer
Department of Corrections and Rehabilitation
State of California
Eric Nehls
Cyber Policy and Strategy Planner
Office of Emergency Services
State of California
Rosanna Nguyen
Chief, Information Technology Consulting Unit
Department of Finance
State of California
Russ Nichols
Deputy State Chief Information Officer and Chief Deputy Director
Department of Technology
State of California
Harry O'Laughlin
Enterprise Security Architect
Judicial Council of California
George Okamoto
Agency Information Officer
Labor and Workforce Development Agency
State of California
Beverly Page
Information Security Officer
Department of Transportation, Information Technology, Security Services Division
State of California
Vitaliy Panych
State Chief Information Security Officer
Department of Technology
State of California
Jason Piccione
Agency Information Officer
Business, Consumer Services and Housing Agency
State of California
Ty Shepard
LT COL, Cyber Network Defense
Military Department
State of California
Darice Trafton
Agency Information Security Officer
Business, Consumer Services and Housing Agency
State of California
Cesar Vigil Fuentes
Chief Information Security Officer
Department of Insurance
State of California
Kathy Cruz
Director, Advisory Cyber Security Services
KPMG
Chris Cruz
Chief Information Officer, SLED
Tanium
Erik Ellner
Sr. Account Manager
Juniper
Cheryl Gardner
Account Executive
Dell Technologies
Ron Hamilton
Chief Information Security Officer
e360
Ewa Hoyt
Principal, Technology Sales Representative, Public Sector Security
IBM
Jeff Longo
Major Account Manager
Fortinet
Don Michie
Managing Client Solution Architect
AHEAD
Vaishali Patel
Regional Sales Manager
Zscaler
Adam Petrovsky
Regional Manager
World Wide Technology
Nick Saavedra
Regional Sales Director
ServiceNow
Benjamin Troglia
Associate Director
Accenture
Cindy Weltzin
Account Executive
Veracode
Amanda Zvolanek
Account Manager
Amazon Web Services
2023 Sponsorship opportunities are available. For more information, contact:
Heather Earney
Government Technology
Phone: (916) 932-1339
E-mail: heather.earney@erepublic.com