California Cybersecurity Education Summit 2022 Banner

Overview

View photo highlights of the California Cybersecurity Education Summit 2022 event here.

CA Cyber 2022 photo 1 CA Cyber 2022 photo 2 CA Cyber 2022 photo 3

The COVID-19 pandemic dramatically increased the State of California’s reliance on virtual tools for meetings, shopping, education, healthcare and government services. Moving quickly to virtual environments also opened the door for a greater number of cyberattack attempts on information technology assets in California, across the country and throughout the world. Organized cybercriminal groups have increased phishing, ransomware and other cybercrimes against government entities, healthcare organizations, public utilities, education facilities and corporations. The 2022 State of California Cybersecurity Education Summit, hosted by the California Department of Technology (CDT), the Governor’s Office of Emergency Services (CalOES), California Highway Patrol (CHP) and the California Department of Military (CalGuard), will include cybersecurity leaders from state and local government throughout California.

 

A message from our Keynote Speaker

The Cybersecurity Education Summit is a can’t-miss event for security professionals and educators from every sector. It’s an annual highlight in the daily effort to protect Californians from cyber risks that can upend daily life and sideline businesses. I look forward to attending in-person in 2022, engaging with cyber professionals and educators from the public and private sector, and learning about the latest products, training and strategies to protect our state. Please join CDT, CalOES, CHP and the CA Dept of Military at the Cybersecurity Education Summit this October.

Vitaliy Panych, California State Chief Information Security Officer

Speakers

Adele Burnes

Adele Burnes

Deputy Chief, CA Division of Apprenticeship Standards

Adele Burnes has spent her career in workforce development and economic empowerment. She has worked at this important issue from many angles including government policy work, tech startups to develop startup ecosystems, and leading strategy and operations for Year Up Bay Area, the most effective workforce development program ever measured in the US, and as the first ever Regional Director of Apprenticeship for the Bay Area Community College Consortium. Today as Deputy Chief at DAS, Adele’s work is focused on policy and strategy to expand apprenticeships in CA to create a more equitable and accessible on ramp into a wide variety of careers from the building trades to healthcare, tech, education, public service and every sector of our economy.

More
John Cleveland

John Cleveland

Deputy State Chief Information Officer, Department of Technology, State of California

John Cleveland is California’s Deputy State Chief Information Security Officer with the California Department of Technology (CDT). 
Prior to his current position, John was manager of CDT’s Statewide Security Operations Center. His other positions included security operations chief at the Employment Development Department, chief information security officer at the Department of Child Support Services, and chief technology officer at the Contractors State License Board. He has been instrumental in his previous roles devising and implementing security operations strategies and has built security controls for some of the state’s largest benefit-based systems.
John brings over 20 years of private sector information security and technology management experience, including roles as service delivery manager for Banyan Systems, consulting manager and security practice manager at Lucent Worldwide Services, and principal consultant and owner of his own security consulting business. 
He is an Iraq war veteran with over 10 years of military service.

More
Kathy Cruz

Kathy Cruz

Director, Advisory Services, Government Cybersecurity, KPMG LLP

Kathy Cruz is a Director in KPMG’s Advisory Services, helping government clients build digital trust through cybersecurity strategies, risk mitigation practices, and strengthened operational controls. Focusing on integrating cybersecurity initiatives throughout the enterprise, she helps clients mature their cybersecurity programs and create the needed flexibility to address the changing cyber landscape. Kathy helps government clients focus on building cyber security resilience for their organizations, supporting business objectives and services to the public.
Previously, Kathy was Senior Advisor to California’s State Chief Information Security Officer providing leadership in cybersecurity strategy and major initiatives. With over thirty years of experience in both the private and public sector, Kathy is a recognized innovator and leader. A five-time Chief Information Officer with a customer-centric mindset, she has been instrumental in implementing complex and innovative technical solutions to solve business problems, advance operational efficiency, improve the delivery of products and services and advance business opportunities. Kathy’s broad background includes working globally with executives, clients, investors, Board of Directors, and leaders in California state government.
Kathy is the recipient of CIO Magazine 100 Award, recognizing the top 100 CIOs in the U.S. She is also recipient of the Silicon Valley YWCA Tribute to Women in Industry (TWIN) Award. Kathy is a past Board member of the Gentle Barn Foundation headquartered in Santa Clarita, CA, a past Board Member of the Career Action Center in San Jose, CA, and a former member of Golden Gate University School of Technology and Industry Executive Advisory Board. Kathy previously served as an Ensign in the California State Guard, Cyber Operations Detachment.

More
Dustin DeBrum

Dustin DeBrum

Operations Director, California Cybersecurity Institute, New Programs & Digital Transformation Hub (DxHub) Cal Poly

Dustin DeBrum is Operations Director for the California Cybersecurity Institute, New Programs, and Digital Transformation Hub (DxHub) at Cal Poly, where he supports cyber education initiatives and outreach to build a skilled cyber workforce capable of navigating today’s complex threat landscape. His higher-education career spans over 21 years at Cal Poly supporting university commercial operations and enterprise technology services. Before Cal Poly, DeBrum worked for multiple dot-com companies in Silicon Valley. In addition to his experience, DeBrum has presented and hosted workshops, conferences, and online webinars on space cybersecurity, technology disability policy, credit card security, and cloud deployment strategy. DeBrum holds a Bachelor’s degree in Twentieth-Century Science & Technology History from San Jose State University and a Master’s degree in Educational Leadership and Administration from Cal Poly.

More
Eric Escobar

Eric Escobar

Principal Consultant / Wireless Lead, Adversary Group Company, Secureworks

Eric is a seasoned pentester and a Principal Security Consultant at Secureworks. On a daily basis he attempts to compromise large enterprise networks to test their physical, human, network and wireless security. He has successfully compromised companies from all sectors of business including: Healthcare, Pharmaceutical, Entertainment, Amusement Parks, Banking, Finance, Technology, Insurance, Military, Retail, Food Distribution, Government, Education, Transportation, Energy and Industrial Manufacturing. Before entering the cyber security arena, Eric attained both a BS and MS in Civil Engineering along with his Professional Engineering license.

More
John Evans

John Evans

Chief Technology Advisor, Cybersecurity, World Wide Technology

John Evans serves as a Chief Technology Advisor (CTA) at World Wide Technology (WWT). In this role, Evans engages with clients on strategy, innovation and transformation to develop and deliver solutions that are tailor-made for business in government and education. He is a highly consultative and knowledgeable technology advisor focused on achieving tangible operational and business outcomes for WWT’s customers at enterprise scale. Prior to joining WWT, Evans served as Chief Information Security Officer (CISO) and Deputy Chief Technology Officer (CTO) for the State of Maryland, where he helped lead statewide technology and security initiatives. Evans brings over 15 years of technology expertise with extensive experience with security, cloud, and mission critical applications with a primary focus on the SLED market. Prior to his role within the State of Maryland, Evans worked in various executive-level, program management and network operation positions for organizations such as ManTech, Northrop Grumman Corporation, Secure Network Systems and Vigilant Watch Integration. Evans is also an Adjunct Professor – Graduate School, Cybersecurity for University of Maryland University College.

More
Adam German

Adam German

Chief Information Security Officer, Office of State Controller, State of California

Adam German is the Chief Information Security Officer for the California State Controller’s Office (SCO), where he has close to two decades of experience working for the world’s fifth largest economy’s Chief Fiscal Officer. SCO ensures the state government’s monetary resources are independently accounted for and disbursed according to law in a timely manner. As the CISO, Adam works towards securely deploying robust security protections, and developing strong guiding principles to ensure the long-term successful protection of government resources.
Adam has extensive knowledge in the field of Information Security, and his record of achievements demonstrate his success at leading, managing, and delivering security solutions. He is the current President of the ISACA-Sacramento Chapter. He also teaches ISACA certification courses, participates in multiple local and national security forums, and volunteers his time serving with information security think tank groups.

More
Jose Jaramillo

Jose Jaramillo

Agency IT Risk Officer, Labor and Workforce Development Agency, State of California

Jose A. Jaramillo, LWDA Agency IT Risk Officer, has been serving Californians as a risk, governance, and compliance professional for over ten years. Jose previously served as the Information Security Officer at the California Department of Real Estate (DRE). Jose was DRE’s first Information Security Officer (ISO), responsible for securing the personal information of over 430,000 real estate licensees. In his role as ISO, he worked diligently to build an Information Security Program from the ground up. Jose has over two decades of IT experience working in state government and the private sector. Some of his experience includes: managing enterprise risk, IT governance, implementing enterprise security policy and procedure suite, compliance, incident response and technology recovery. Jose holds a Master in Public Administration, from the McGeorge School of Law; a B.S. in Management Information Systems and Accounting, from the University of the Pacific.

More
Jeff Jennings

Jeff Jennings

SLED Practice Director, Fortinet

Jennings has over 23 years of experience in the K-20 sector, as well as 21 years of experience in the FCC E-rate program. He is an accomplished leader of sales, marketing & compliance/support teams. He brings to Fortinet extensive expertise in SLED, EDU, K-12, Education technology, funding, purchasing practices, e-rate federal funding consulting/compliance and strategic planning. He has proven to be successful in providing consultative services to local government & local education agencies (LEA’s) as well as school districts and state agencies.

More
Moinul Khan

Moinul Khan

Vice President, Product Management, Zscaler

Moinul Khan is the VP and GM of the data protection business at Zscaler. Moinul brings 20+ years of experience in enterprise security. Before joining Zscaler, he led product and strategy in Palo Alto Networks, Netskope, Juniper, and other companies and built market-leading products in many security domains.

More
Douglas Leone

Douglas Leone

Agency Information Security Officer (AISO),, Labor and Workforce Development Agency, State of California

Douglas Leone, is the Agency Information Security Officer (AISO) at the Labor and Workforce Development Agency. He has been at the front lines of building secure systems for Californians moving from practitioner to an Information Security Officer in 2013 when he obtained his CISSP. Doug grew up in Virginia, coming west after his six-year enlistment in the United States Navy where he began his information technology career. After serving in the military, Doug has architected and built secure systems for over 50 Sacramento businesses in the private sector before joining California state service. He has earned over 30 information technology certifications for Microsoft, Cisco, Novell, and other industry-leading companies and has obtained his Certified Information Systems Security Professional certification. Doug’s philosophy is ensuring trust and enabling business by building security and privacy by design into systems from concept throughout operations and maintenance.

More
Peter Liebert

Peter Liebert

Former State Chief Information Security Officer, State of California

Joseph Maio

Joseph Maio

Information Security Officer/Security Operations Center Manager, California Natural Resources Agency

Joe Maio is an Information Security Officer and the Security Operations Center Manager for the California Natural Resources Agency (CNRA). In this capacity, Joe works towards implementing security technologies, policies, and procedures to ensure the long-term successful protection of California's natural resources and the CNRA's 32,000+ member workforce and technologies. Joe's knowledge and skills span a broad array of information technology practices, including information security, privacy, database administration, eDiscovery, cyber forensics and investigations, server administration, application development, and project management. He has an aptitude for developing custom security solutions that are used for proactive cyber defense and incident response, and aspires to protect the State of California from the cyberthreats of today.

More
Mike Marshall

Mike Marshall

Agency Information Security Officer, Environmental Protection Agency, State of California

Michael Melore

Michael Melore

Senior Cyber Security Advisor, IBM Security

Michael is a Senior Cyber Security Advisor for IBM Security and a Certified Information Systems Security Professional. He is the founder for “SecRT” which is are regional CISO/Security Leader Round Table groups across the US (1,300+ Security Executive Members). Michael is a frequent national public speaker and moderator, FBI InfraGard committeeman, NASCIO committee member, and recognized subject matter expert in Security and Threat Intelligence, Identity Access Governance, and Authorization. His prior roles iclude: Lead architect for many of the world’s largest authentication and authorization infrastructures, including two of the 1st billion user authentication infrastructures. Michael is a champion of regularly scheduled cybersecurity threat simulation exercises, training and education.

More
Michele Myauo

Michele Myauo

Managing Director – NA Public Service Security Lead, Accenture

Michele Myauo, Ph.D., is a cybersecurity and IT executive, author, speaker, and professor. Myauo has over 20 yrs. experience leading cybersecurity, IT systems engineering, services sales and business execution globally across academia, industry, and government, including the U.S. Intelligence Community and departments such as Commerce, Defense, Energy, Homeland Security, and State. At Accenture Myauo is a Managing Director leading the North America Public Service Security Industry focused on empowering state and local governments, educational institutions and non-profits in rapidly adopting secure and resilient cybersecurity solutions to innovate and achieve more sustainably.
Prior to Accenture, Myauo held leadership positions in cybersecurity and IT at Microsoft and IBM. Myauo was also a professor at The George Washington University. Myauo holds a Doctorate in systems engineering from The George Washington University, a M.S. in industrial and organization psychology from University of Baltimore, and a B.S. in psychology from Bethany College.

More
Zach Nandapurkar

Zach Nandapurkar

Technical Account Manager, Tanium

Zach Nandapurkar is a Technical Account Manager at Tanium based in San Francisco, California. Zach is passionate about digital transformation at the State of California, focusing on the execution of the Cal-Secure Plan and reducing cyber risk statewide. Zach is responsible for designing Tanium's response to Cal-Secure with mentorship from Chris Cruz, Tanium's SLED CIO. Zach is a graduate of the University of Southern California ('18) with a B.S. in Computer Science and Business Administration and in his free time enjoys skiing, traveling to new destinations in California, learning about California History and Politics, and watching USC Trojan Football.

More
Tom Osborne

Tom Osborne

Deputy Director, Homeland Security, California Governor’s Office of Emergency Services

Deputy Director Osborne was appointed by Governor Newsom and joined the California Governor’s Office of Emergency Services (Cal OES) in November 2019. Deputy Director Osborne provides direction and oversight to the newly formed Cal OES Homeland Security Division. In this role, Deputy Director Osborne is responsible for the State Threat Assessment System (STAS), the California Cyber Security Integration Center (Cal-CSIC), and the following homeland security programs: the Governor’s Homeland Security Advisory Committee; the Governor’s Creating Safer Communities Task Force; the Governor’s Cybersecurity Task Force; Port and Maritime Security; Chemical Biological, Radiological, Nuclear and Explosive material (CBRNE) Protection and Preparedness; Event Planning Security; Critical Infrastructure Protection; Statewide School Safety; and the BioWatch System. Moreover, Deputy Director Osborne provides administrative oversight to the application of California’s homeland security grants, known as the Homeland Security Grant Program (HSGP) and Urban Area Security Initiative (UASI) — funding that totaled $197,911,000 in FY2019 and received from the U.S. Department of Homeland Security (DHS).
Prior to joining Cal OES, Deputy Director Osborne spent nearly 24 years with the Federal Bureau of Investigation (FBI) as a Special Agent, specializing in national security threat issues. Assigned to the Sacramento Field Office, his final assignment at the FBI was an executive management role as the Assistant Special Agent in Charge (ASAC) overseeing the National Security and Administrative Branches, where his responsibilities included International and Domestic Terrorism, Counterintelligence, Cyber, Critical Incident Response, Surveillance, Training, FBI National Academy, security, facilities, and oversight of all professional staff employees. Deputy Director Osborne also spent over a year in Washington, D.C. as Unit Chief of the FBI’s Counterterrorism Internet Targeting Unit.

More
Joe Panora

Joe Panora

Senior Fellow, Center for Digital Government

Joe Panora has over 34 years of state public service with 14 years serving in correctional safety/public safety law enforcement as IT director/chief information officer (CIO).
Joe Panora was appointed by California Gov. Schwarzenegger and later Gov. Brown to serve as director of Enterprise Information Services (EIS) for the Department of Corrections and Rehabilitation (CDCR) since January 2008. During his career, Joe has also served for the following departments: Caltrans, Franchise Tax Board, Employment Development Department, State Controller’s Office and California Youth Authority. Joe retired from state service as the director of EIS for CDCR in December 2014.
As the EIS director, Joe was responsible for leading an organization with over 650 IT professionals. His team worked to deliver and improve statewide processes for education, rehabilitation, board hearings, health care, and offender/parole/juvenile operations. Also, this included the department’s IT strategic plan, policies, standards, enterprise architecture, procurement, customer service/field operations, and automation efforts. Over his tenure, Joe implemented an IT project portfolio worth over $800 million, which resulted in both a business and IT transformation for CDCR. Significant program and cost efficiencies were achieved as well as enhanced delivery of services.
Joe has received the following awards: 2014: Cybersecurity Leadership Innovation Award – Leadership Innovators Category (Center for Digital Government); 2013: Named one of Government Technology’s Top 25 Doers, Dreamers and Drivers for his contribution to public-sector innovation; and 2010: Outstanding Technology Leadership Award at the California CIO Academy Awards, a program hosted by Public CIO magazine.
Joe holds a master's degree in Business Administration and Telecommunications, a Bachelor of Arts degree in Accounting, and is a certified Project Management Professional (PMP).

More
Vitaliy Panych

Vitaliy Panych

Chief Information Security Officer, Department of Technology, State of California

Vitaliy Panych is the Chief Information Security Officer for the State of California at the California Department of Technology. He was appointed by Gov. Gavin Newsom in February 2021 after serving in an acting roll for nearly two years.
Before landing at CDT in 2019 as the deputy state chief information officer, he was the agency information security officer for the California Department of Corrections and Rehabilitation from 2016 through 2019. He joined the Employment Development Department in 2009 serving as its security and compliance manager. Prior to that, he was at the Franchise Tax Board in 2007, where he became a system software specialist and was later named Information security vulnerability management lead, a role he held until moving to the EDD. A veteran of government service, Vitaliy began his state career as a network engineer at the state’s Teale Data Center in 2003.
He earned bachelors’ degrees in computer science and political science from California State University at Sacramento. His professional portfolio is full of accreditations and distinctions, including several Global Information Assurance Certification (GIAC) credentials.

More
Andy Piazza

Andy Piazza

Global Leader of Threat Intelligence, IBM Security

Andy Piazza is an accomplished security professional with 20 years of experience in security operations, threat intelligence, and incident response. Andy has developed multiple cyber threat intelligence programs for clients and is a frequent contributor to the CTI community through his personal blog and talks at industry conferences. He has worked alongside clients and stakeholders in multiple critical infrastructure sectors to improve their incident response capabilities, security operations integrations and processes, and threat management programs.
Andy is a US Army combat veteran with multiple deployments to Iraq, Central America, and Haiti. He has earned a Master's in Intelligence Studies from American Military University and a Master's in Information Security Engineering from SANS. He enjoys writing, mentoring, and project development in support of threat intelligence and cybersecurity operations. He’s also the Director of Operations for BSidesNOVA and the Global Head of Threat Intelligence at IBM X-Force. Andy can be found on Twitter as @klrgrz, on Medium at https://klrgrz.medium.com, and his personal site klrgrz.com.

More
David Rosado

David Rosado

Director, Region 9, US Department of Homeland Security

David Rosado serves as the Regional Director for Region 9 at the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), where he leads the effort to protect and advance the resilience of the nation’s physical and cyber infrastructure in the states of Arizona, California, Hawaii, Nevada, the territories of American Samoa and Guam, and the Commonwealth of the Northern Mariana Islands.
Prior to joining CISA, Mr. Rosado had a distinguished career in public service and security management. Mr. Rosado served as Chief of Police in the City of Hartford, Connecticut where he oversaw a department with over 400 police officers and a budget of approximately $46 million.
Mr. Rosado also served for 20 years with the Connecticut State Police, where he achieved the second-highest rank in the agency as Lieutenant Colonel. In this role, he oversaw more than 800 sworn and civilian employees and was responsible for all operational components of the agency, including patrol, investigations, specialized units, and protection of critical infrastructure statewide.
After Mr. Rosado’s law enforcement career, he worked for Major League Baseball in New York City, serving on a national level as MLB’s Chief Security Liaison to all of Minor League Baseball. Mr. Rosado also served as Chief Operations and Chief Security Officer of a logistics and technology firm in Connecticut. Most recently, Mr. Rosado, also an attorney, worked in private practice at a litigation firm in Hartford, Connecticut.
Mr. Rosado is fluent in Spanish and received a Bachelor of Arts degree in sociology from the University of Connecticut, and a Juris Doctor degree from the University of Connecticut School of Law. He is also a graduate of the FBI National Academy, Session 249, in Quantico, Virginia.

More
Mike Spanbauer

Mike Spanbauer

Field Chief Technology Officer and Architect, Security, Juniper Networks

Mike Spanbauer is a Technology Evangelist for Juniper Security. Mike’s work and expertise in network and security advisory, consulting, and product strategy over the last 25 years provides a breadth of perspective across network and security execution, as well as approaches to solve for operational and governance needs that organizations face. He most recently served as Vice President of Research Strategy for NSS Labs, driving the enterprise research and consulting practice for NSS’ global clients. Prior to that, Mike held leadership roles at Current Analysis and HP in research, strategy, and competitive intelligence. Throughout his career, Mike has possessed a passion to help guide organizations to make well-informed decisions that ensure delivery on their intended technical outcomes. He brings this passion to Juniper’s customers, partners, and prospects, listening to their needs and challenges ensuring Connected Security continues to solve for them, day in and day out.

More
Maria Thompson

Maria Thompson

State and Local Government Cyber Security Leader, Amazon Web Services

Maria S. Thompson is the State and Local Government Cybersecurity Lead for Amazon Web Services (AWS). In this role, she brings over 20 years of experience in information technology, strategic planning, computer network defense and risk management. Prior to her role with AWS, Maria served as North Carolina’s first State Chief Risk and Security Officer. There she was instrumental in establishing the Whole of State Approach to Cyber. This included the development and implementation of the state’s first Cyber Disruption Plan, and the Joint Cyber Task Force (JCTF). Maria also served 20 years in the United States Marine Corps and retired as the cybersecurity chief/information assurance chief for the Marine Corps. Other security roles held includes certification and accreditation (C&A) lead for the Multi-National Forces – Iraq and senior security engineer in a joint military organization and Security Operations Center lead for a federal agency.

More
Matthew Thompson

Matthew Thompson

Senior Vice President & General Manager, Public Sector Solutions, Socure

Matthew Thompson, CISSP, is an industry-recognized thought leader in the area of Identity and Security Management and currently leads Socure's Public Sector business while also serving as the President of the Board for the Kantara Initiative, the leading global community commons improving trustworthy use of identity and personal data through innovation, standardization and good practice. Matt is an innovator in the digital identity space with several patents having co-founded ID.me, which was named to the “100 Brilliant Companies” list in 2014 by Entrepreneur Magazine. Matt has spent more than a decade working in the public and private sectors to promote privacy-enhancing, secure, interoperable, and user-friendly ways to give individuals and organizations confidence in their online interactions, which garnered him recognition by One World Identity as one of the “Top 100 Leaders in Identity” in 2017 and 2018.
Graduating as the Top Cadet from the Virginia Military Institute, Honor Graduate from Army Ranger School and with an MBA from Harvard Business School, Matt is a proven business leader, successful entrepreneur, Ironman triathlete, and decorated combat veteran. He served as an Army Special Operations Officer, completing four deployments to Iraq and Afghanistan with multiple awards for his service in combat. Matt’s civilian experience includes positions at McKinsey & Company, Goldman Sachs, Capital One and IDEMIA.

More
Steve Towns

Steve Towns

Deputy Chief Content Officer, Content Studio, e.Republic

As Executive Editor at e.Republic, Steve is responsible for the coordination of editorial strategies and standards across all the firm’s media platforms. He directs the editorial teams that produce Government Technology, Emergency Management and Digital Communities and their respective Websites, in addition to developing and maintaining corporate policies and standards for editorial. Steve has over 20 years of writing and editing experience including more than 17 years covering technology in the state and local government market.
Steve joined e.Republic in 1996. During his tenure, e.Republic’s print and electronic media have received many awards for editorial excellence, including “Magazine of the Year” from ASBPE for Emergency Management in 2013, “Best New Web Site” from ASBPE for emergencymgmt.com in 2009, ”Best Overall Publication” at the Maggie awards for Government Technology in 2008 and “Magazine of the Year” from ASBPE for Public CIO in 2007.

More
Mark Weatherford

Mark Weatherford

Senior Fellow, Center for Digital Government

Mark Weatherford is a globally recognized information security professional with experience at some of the world’s largest public- and private-sector organizations. He was appointed as the first deputy undersecretary for cybersecurity at DHS in the Obama administration and was chief information security officer for the state of Colorado and for the state of California under Gov. Arnold Schwarzenegger. In the energy industry, he was VP and chief security officer at the North American Electric Reliability Corporation, where he worked daily with Congress and electric utilities across North America on cybersecurity standards, regulations, and policy issues. He also served as a principal at The Chertoff Group and was VP and chief cybersecurity strategist at vArmour. Most recently, he was the VP and global information security strategist at Booking Holdings, the world’s largest online travel business with offices and employees in almost every country in the world and whose major companies include Booking, Priceline, Kayak, OpenTable and Agoda.

More
Chris Wysopal

Chris Wysopal

Co-Founder and Chief Technology Officer, Veracode

Chris Wysopal is Chief Technology Officer at Veracode. He oversees technology strategy and information security. Prior to co-founding Veracode in 2006, Chris was vice president of research and development at security consultancy @stake, which was acquired by Symantec.
In the 1990’s, Chris was one of the original vulnerability researchers at The L0pht, an ethical hacker think tank, where he was one of the first to publicize the risks of insecure software. He has testified to the US Congress on the subject of government security and how vulnerabilities are discovered and remediated in software.
Chris received a BS in computer and systems engineering from Rensselaer Polytechnic Institute. He is the author of The Art of Software Security Testing.

More

Agenda

Thursday, October 20

8:00 am Pacific

Registration and Morning Refreshments

Magnolia Room and Grand Nave Lobby

9:00 am Pacific

Opening Remarks

Camellia/Gardenia Room

Liana Bailey-Crimmins, State Chief Information Officer, Department of Technology, State of California

Miriam Ingenito, Undersecretary, Government Operations Agency, State of California

Tom Osborne, Deputy Director, Homeland Security, California Governor’s Office of Emergency Services

Vitaliy Panych, State Chief Information Security Officer, Department of Technology, Office of Information Security, State of California

Major General Matthew Beevers, Adjutant General, California Military Department

9:20 am Pacific

General Session – A National Focus on Cybersecurity

Camellia/Gardenia Room

The Cybersecurity and Infrastructure Security Agency (CISA) works with partners to defend against today’s threats and collaborating to build more secure and resilient infrastructure for the future. In this session, Region 9 Director, David Rosado, will provide an update on key focus areas for CISA including their 2023-2025 strategic plan and training resources and opportunities.

David Rosado, Director, Region 9, US Department of Homeland Security

9:45 am Pacific

General Session - The Hacker Mindset - A Spotlight on Global Government

Camellia/Gardenia Room

Moderator: Mike Driessen, Vice President, Government Technology

Chris Wysopal, Co-Founder and Chief Technology Officer, Veracode

10:15 am Pacific

Networking Break

Magnolia Room and Grand Nave Lobby

10:45 am Pacific

Concurrent Sessions

Cal-Secure Roadmap – What it Contains and What Organizations Should be Doing

Tofanelli

Cal-Secure is the State of California Executive Branch’s five-year information security roadmap. The roadmap was created through a collaborative process with the California Cybersecurity Integration Center (Cal-CSIC) and its four critical partners: the California Governor’s Office of Emergency Services (Cal OES), California Highway Patrol (CHP), California Department of Technology (CDT), and California Military Department (CMD) and the state government security community. This session will provide an overview of the roadmap and what State of California technology and business leaders should be doing to support this effort in their own organization.

Moderator: Vitaliy Panych, State Chief Information Security Officer, Department of Technology, Office of Information Security, State of California

John Cleveland, Deputy State Chief Information Security Officer, Department of Technology, State of California

Kathy Cruz, Director, Advisory Services, Government Cybersecurity, KPMG LLP

Zach Nandapurkar, Technical Account Manager, Tanium

Securing the Modern Workplace from a Multitude of Threats

Carr

The pandemic may be waning but the requests for full-time and hybrid remote work schedules have not let up. What does this mean for maintaining a secure environment? How do you maintain a secure hoteling environment? Does BYOD become a permanent part of your plans? How do you handle facial recognition and other security log-in systems that protect your environment regardless of user location? This session will discuss options that many organizations are currently implementing.

Moderator: Mike Driessen, Vice President, Government Technology

Baird Cowan, Chief Technology Officer, Department of Consumer Affairs, State of California

Jose Jaramillo, Agency IT Risk Officer, Labor and Workforce Development Agency, State of California

Mike Spanbauer, Field Chief Technology Officer and Architect, Security, Juniper Networks

Working with Business Leaders as an ISO

Bataglieri

The security team for any organization, be it a one-person shop or a larger team, has the role of enabling and protecting the mission of the organization. A key relationship will be needed with business leaders at the top and middle level of the organization. What do you need from them? How should you communicate with them? What is their language and how do you translate yours to better match theirs? This session will focus on why, how and when to create that relationship so the role of the ISO becomes more strategic in all business plans moving forward.

Moderator: Lloyd Indig, Agency Information Security Officer, Health and Human Services Agency, State of California

Russell Fong, Chief Administrative Officer, Office of State Controller, State of California

Adam German, Chief Information Security Officer, Office of State Controller, State of California

Jeff Jennings, National SLED Practice Director, Fortinet

Douglas Leone, Agency Information Security Officer (AISO), Labor and Workforce Development Agency, State of California

The CISA Zero Trust Network Architecture (ZTNA) Maturity Model Explained

Beavis

Post Covid, many organizations are now struggling with a more distributed network footprint, new SAAS applications, and some employees on permanent work from home status. Organizations are turning to Zero Trust architectures to adapt their IT services to manage these new realities. This talk will walk through the CISA ZTNA Maturity Model and how it can be used to help organizations define a rational and prioritized multi-year ZTNA strategy.

Trevor Hogan, Director of Strategy and Risk, e360

Data Loss Prevention – Best Practices and Planning

Bondi

At its heart, data loss prevention (DLP) gives an organization control over what employees can share and prevents unintended exposure of sensitive information. What is the minimum bar for implementing a DLP system? How can you classify and track data as part of your efforts? Is an encryption system an important tool to deploy and when would it make sense? And lastly, how do you handle data at rest versus data “in flight?” This session will provide an overview of DLP and a myriad of points that should or could be in your short term and long term plans.

Moderator: Joe Panora, Senior Fellow, Center for Digital Government

Ken Kojima, Chief Information Security Officer, Department of Corrections and Rehabilitation, State of California

Ron Mendoza, Principal Security Architect, Franchise Tax Board, State of California

Moinul Khan, Vice President, Product Management, Zscaler

2022 Status of California Cybersecurity Education and Workforce Development

Compagno

This presentation will highlight the current state of California Cybersecurity Education and Workforce Development. This will include a broad overview and discussion of key facets and recent developments in cybersecurity education (K-12 and Higher Education) statewide. The group will focus on growing collaborations among major stakeholders and key partners; career education pipelines; degree, certificate, and digital badging; and recent innovations in state/regional utilization of effective cybersecurity workforce development models including apprenticeships.

Moderator: Keith Clement, Professor, California State University, Fresno

Erle Hall, Education Programs Consultant, Department of Education, State of California

Markus Geissler, Ph.D., Professor, Cosumnes River College

11:45 am Pacific

Lunch

Camellia/Gardenia Room

12:30 pm Pacific

General Session – Cybersecurity in Today’s Threat Landscape

Camellia/Gardenia Room

This panel of government leaders and industry experts will address key areas of focus for the coming year. While every organization has its own unique set of challenges, there is a baseline and a set of long-term goals all should be working towards. What support can you expect from State of California executives? What industry coalitions exist and what should government technology professionals do as a result? This session will strive to provide basic answers but to also provide a roadmap for government organizations to follow.

Moderator: Jennifer Axt, Vice President, SLED, Tanium

Peter Liebert, Former State Chief Information Security Officer, State of California

Vitaliy Panych, State Chief Information Security Officer, State of California

Mark Weatherford, Former State Chief Information Security Officer, State of California and State of Colorado

1:15 pm Pacific

Networking Break

Magnolia Room and Grand Nave Lobby

1:30 pm Pacific

Concurrent Sessions

Security and Privacy Risk Management

Tofanelli

Large, medium and small organizations have the same challenges but have different resources available to them. What does a cybersecurity risk management approach look like to all of them? What are the basics? Where and when do you need partners? What resources are available to you so you don’t have to go it alone? This session will include takeaways on security and privacy risk management regardless of how large or small your organization is. The challenges are the same, the solutions may be different.

Moderator: Lloyd Indig, Agency Information Security Officer, Health and Human Services Agency, State of California

Tim Boswell, Outbound Product Manager, ServiceNow

Vivian Yan, Assistant Chief Security Officer, Security Operations Section Manager, Privacy, Security and Disclosure Bureau, Franchise Tax Board, State of California

Applying the National Institute of Standards and Technology (NIST) Cybersecurity Framework

Carr

Many organizations are implementing an adaptive, cyber-resilient digital strategy by using the cybersecurity framework outlined by NIST. The framework covers the areas of protection, detection, response, recovery and identity with the goal to foster risk and cybersecurity management communications amongst both internal and external organizational stakeholders.

Michael Melore, Senior Cyber Security Advisor, IBM Security

Today’s Adversary – Who are they and What are they Doing?

Bataglieri

As cybersecurity professionals, today’s adversary is seemingly everywhere. From the untrained employee or resident to the nation state, the adversaries are numerous and have their own characteristics and goals. What exactly are the adversaries doing today? What is their motivation? How do we defend against them, or at least the most common of them? How are they getting access today and how can we best detect and/or prevent them from doing damage or stealing information? This session will be an update on the current state of the adversary with practical advice to thwart their efforts.

Moderator: Mike Driessen, Vice President, Government Technology

Andy Piazza, Global Leader of Threat Intelligence, IBM Security

Michael Aguilar, Principal Consultant, SecureWorks Adversary Group

Joseph Maio, Information Security Officer/Security Operations Center Manager, California Natural Resources Agency

Making Security Everyone’s Job

Beavis

It may be trite to say that security is everyone’s job but it is also quite true! So how does one accomplish this? What role does organization management and leadership play? How can cybersecurity teams and technology teams ensure that this is known and being done? This session will provide practical ideas on education, testing, the role of organizational leadership, practical consequences for failing tests and other practices to help you improve security awareness throughout your organization.

Moderator: Joe Panora, Senior Fellow, Center for Digital Government

Teri Bennett, Consultant Partner, Pinnacle Advocacy

Michele Myauo, Managing Director – NA Public Service Security Lead, Accenture

Lessons from Gamification and Cybersecurity: The Space Grand Challenge 2022

Bondi

Over the past five years, Cal Poly's California Cybersecurity Institute (CCI) has grown its cyber Capture the Flag (CTF) competition, designed for middle and high school students, into an immersive space-focused cybersecurity challenge. This session will discuss lessons from gamifying cyber education, incorporating Cal Poly's Learn By Doing philosophy and recruiting prospective students towards STEM degrees at Cal Poly, and cybersecurity training/credentials.

Dustin DeBrum, Operations Director, California Cybersecurity Institute, New Programs & Digital Transformation Hub (DxHub) Cal Poly

2:30 pm Pacific

Networking Break

Magnolia Room and Grand Nave Lobby

2:45 pm Pacific

Concurrent Sessions

Security Architecture – Design and Implementation

Tofanelli

The purpose of a security architecture is to reduce cyber security threats and the expenses that might result from them. A security architecture is a set of models, methods, and security principles that align with organizational objectives, keeping your organization safe from cyber threats. Through security architecture, business requirements are translated to executable security requirements. The State of California SIMMs covers some of this but there are many nuances based on the size and maturity of your organization. In this session, a mix of speakers will provide guidance on implementing and improving your security architecture.

Moderator: Mike Driessen, Vice President, Government Technology

Dustin Grimmeissen, Senior Director, Specialty Sales, AHEAD, Inc.

Maria Thompson, Executive Government Advisor, AWS

Identity Proofing from A to Z

Carr

Identity proofing is the process of verifying a user's identity: confirming that they are who they say they are. This may sound like ordinary authentication, the kind based on a username/password combination, but identity proofing actually comes into play before users get their credentials to access an application or alongside the traditional authentication process. That brings up the question of how to balance service friction with identity proofing. In this session, presenters will discuss concepts, tools and methods to help organizations better understand and plan for identity proofing as they modernize internal and external systems.

Moderator: Steve Towns, Deputy Chief Content Officer, Content Studio, Government Technology

John Evans, Chief Technology Advisor, Cybersecurity, World Wide Technology

Greg Fair, Digital Identity Chief and Acting Chief Product Officer, Department of Technology, State of California

Todd Ibbotson, Information Security Officer, Employee Development Department, State of California

Matt Thompson, SVP & General Manager, Public Sector Solutions, Socure

Third-Party Risk Management Planning and Implementation

Bataglieri

What steps do you need to take to ensure that third parties do not compromise your security posture? What are some best practices for ensuring security while using third-party hosted solutions? What rules are currently in place that can guide my decisions in this area? How should incident response be updated to reflect my use of third-party hosted solutions? These questions and more will be addressed in this session as the ever-changing landscape of technology continues to embrace more solutions that are outside the organizational firewalls.

Moderator: Robert Mayorga, Chief Security Officer, Franchise Tax Board, State of California

Albert Arboleda, Chief Information Security Officer, Information Security, CalPERS

Kasia Killgore, Program Manager, Data Oversight Program, Franchise Tax Board, State of California

Recruiting, Retaining and Building Your Cybersecurity Team

Bondi

Pay and telework will get you started but those are not the only tools you can employ as you recruit and work to retain your cybersecurity team. As the cybersecurity threat landscape has grown, the pipeline has become increasingly too small to fill the vacuum of organizational needs in both the public and private sectors. What are some other tactics you can employ given the constraints of public service organizations? How can you become an employer of choice? This panel will discuss things an organization can do to narrow the gap between private sector opportunities, and the perks they offer, and the long-term stability of the public sector as well as the importance of the mission – serving the residents of our state.

Moderator: Joe Panora, Senior Fellow, Center for Digital Government

Kenneth Anyanwu, Success Coordinator, SEIU Local 1000

Adele Burnes, Deputy Chief, CA Division of Apprenticeship Standards

Mike Marshall, Agency Information Security Officer, Environmental Protection Agency, State of California

3:45 pm Pacific

Networking Break

Magnolia Room and Grand Nave Lobby

4:00 pm Pacific

Awards Program

Camellia/Gardenia Room

4:30 pm Pacific

Awards Program Networking Reception

Magnolia Room and Grand Nave Lobby

Network with your colleagues and discuss technology solutions with the event exhibitors.

Conference times, agenda, and speakers are subject to change.

Sheraton Grand Sacramento

1230 J Street
Sacramento, CA 95814
(916) 447-1700

Get Directions To
Sheraton Grand Sacramento

Advisory Board

Government Representatives

Liana Bailey-Crimmins
State Chief Information Officer and Director
Department of Technology
State of California

Andrew Bell
Information Security Officer
Military Department
State of California

Brenda Bridges Cruz
Deputy Director, Office of Professional Development
Department of Technology
State of California

Jennifer Chan
Chief Information Officer
State Lottery
State of California

Keith Clement
Professor
California State University, Fresno

John Cleveland
Deputy State Chief Information Security Officer
Department of Technology
State of California

Brian Colt
Information Security Officer
Department of Corrections and Rehabilitation
State of California

Michael Crews
Chief Information Officer (Acting)
Governor's Office of Emergency Services
State of California

Jun Dai
Associate Professor
California State University, Sacramento

Faith DeuPree
Information Security Officer
Department of Finance
State of California

Ray Diggins
Chief Information Officer
Highway Patrol
State of California

Pam Greeley
Information Security Officer
Highway Patrol
State of California

Eric Harrald
Chief Information Security Officer
Department of Motor Vehicles
State of California

Glenn Herdrich
Information Security Manager
County of Sacramento

Lloyd Indig
Agency Information Security Officer
Health and Human Services Agency
State of California

Karl Kopper
Chief Information Security Officer
Department of Transportation
State of California

David Lane
Acting Commander, CalSIC
Offices of Emergency Services
State of California

Douglas Leone
Agency Information Security Officer
Labor and Workforce Development Agency
State of California

Mark Lourenco
IT Security Director
Department of Education
State of California

Joseph Maio
Information Security Officer
Natural Resources Agency
State of California

Mike Marshall
Chief Information Security Officer
Environmental Protection Agency
State of California

Robert Mayorga
Chief Security Officer
Franchise Tax Board
State of California

Kristin Montgomery
Chief Information Officer
Department of Corrections and Rehabilitation
State of California

Eric Nehls
Cyber Policy and Strategy Planner
Office of Emergency Services
State of California

Rosanna Nguyen
Chief, Information Technology Consulting Unit
Department of Finance
State of California

Russ Nichols
Deputy State Chief Information Officer and Chief Deputy Director
Department of Technology
State of California

Harry O'Laughlin
Enterprise Security Architect
Judicial Council of California

George Okamoto
Agency Information Officer
Labor and Workforce Development Agency
State of California

Beverly Page
Information Security Officer
Department of Transportation, Information Technology, Security Services Division
State of California

Vitaliy Panych
State Chief Information Security Officer
Department of Technology
State of California

Jason Piccione
Agency Information Officer
Business, Consumer Services and Housing Agency
State of California

Ty Shepard
LT COL, Cyber Network Defense
Military Department
State of California

Darice Trafton
Agency Information Security Officer
Business, Consumer Services and Housing Agency
State of California

Cesar Vigil Fuentes
Chief Information Security Officer
Department of Insurance
State of California

Industry Representatives

Kathy Cruz
Director, Advisory Cyber Security Services
KPMG

Chris Cruz
Chief Information Officer, SLED
Tanium

Erik Ellner
Sr. Account Manager
Juniper

Cheryl Gardner
Account Executive
Dell Technologies

Ron Hamilton
Chief Information Security Officer
e360

Ewa Hoyt
Principal, Technology Sales Representative, Public Sector Security
IBM

Jeff Longo
Major Account Manager
Fortinet

Don Michie
Managing Client Solution Architect
AHEAD

Vaishali Patel
Regional Sales Manager
Zscaler

Adam Petrovsky
Regional Manager
World Wide Technology

Nick Saavedra
Regional Sales Director
ServiceNow

Benjamin Troglia
Associate Director
Accenture

Cindy Weltzin
Account Executive
Veracode

Amanda Zvolanek
Account Manager
Amazon Web Services

Registration Information / Contact Us

Contact Information

2023 Sponsorship opportunities are available. For more information, contact:

Heather Earney
Government Technology
Phone: (916) 932-1339
E-mail: heather.earney@erepublic.com

Venue

Sheraton Grand Sacramento

1230 J Street
Sacramento, CA 95814
(916) 447-1700