ISAC Annual Summit 2026 Banner

Overview

Three Days of Collaboration, Learning, and Cybersecurity Insights

This gathering marks the 19th ISAC Annual Summit—celebrating nearly two decades of State, Local, Tribal, and Territorial (SLTT) collaboration and community defense. Government Technology is proud to partner with the MS-ISAC® in advancing an ongoing initiative that has been shaping how the public sector confronts its most urgent cybersecurity challenges.

Join us on June 21-24, 2026 at the Caribe Royale in Orlando, Florida. Engage with peers, gain insights from shared SLTT best practices, and enhance your security, resilience, and continuity strategies to better protect U.S. government networks and systems.

The event begins with a welcome reception on June 21, but the room block has some guest rooms available a few days prior to the event start.

Learn more about the Partnership between the Center for Internet Security and Government Technology HERE

Hear from ISAC members on the value of attending the ISAC Annual Summit

 

 

A message from our Keynote Speaker

Speakers

Carlos Kizzee

Carlos Kizzee

Senior Vice President, CIS Stakeholder Engagement, Center for Internet Security

Carlos P. Kizzee is the SVP, CIS Stakeholder Engagement with the Center for Internet Security. Previously, Carlos served with the Retail & Hospitality ISAC as VP, Intelligence; building and supporting retail and hospitality industry security collaboration; and with Defense Security Information Exchange as Executive Director, promoting threat intelligence sharing and collaboration within the defense industrial base and actively supporting the development and establishment of the National Defense ISAC.
Prior to those roles, Carlos served with the Center for Internet Security as the Vice‐President for Multi‐Sector Initiatives, and within the Department of Homeland Security as the Deputy Director, Stakeholder Engagement and Cyber Infrastructure Resilience Division, and the Program Manager for a Joint Program Office implementing key operational information sharing and information sharing support program activities associated with Public‐Private threat information sharing, collaboration, and automation. Carlos also served within DHS as the Director of Strategic Cyber Initiatives for the Critical Infrastructure and Cyber Protection Branch of the National Cyber Security Division, Counsel for the National Operations Center, Senior Counsel for Infrastructure Protection, and as a Senior Attorney‐Advisor for the DHS Office of General Counsel, General Law Division.
Carlos is a graduate of the United States Naval Academy and served as a career Marine Corps Officer. He received a Juris Doctorate from the Georgetown University Law Center, and a Master of Laws from the Judge Advocate General’s School of the Army at the University of Virginia’s School of Law.

More
Hector Monsegur

Hector Monsegur

Cyber Security Expert and Co-founder, SafeHill 

Hector Monsegur is an internationally-recognized expert on global cyber security issues and a leading voice on cyber attacks and cyber warfare. As Director of Research at Alacrinet and Co-host of Hacker and the Fed, Monsegur works to secure clients in technology, healthcare, finance, government, and other industries. In his leadership role, his unmatched technical experience is shared to both educate other operators and guide technical research. Formerly known by his online alias “Sabu,” Monsegur was once the technical expert behind the Anonymous/LulzSec hacker collectives. As a "black hat hacker", he highlighted critical vulnerabilities in numerous organizations, including governments, military organizations, and cyber security firms. Later, in working with the US Government, Monsegur identified key vulnerabilities—and potential attacks—against major federal infrastructure, including the US military and NASA. Since working with US government and commercial security executives around the world, he has helped prevent upwards of 350 cyber attacks against US government computer systems.  

More
Theresa Payton

Theresa Payton

First Female White House Chief Information Officer; AI Strategist; Business and Personal Security Expert; Privacy Visionary

As a visionary in the digital world, who famously made history as the first female to serve as White House Chief Information Officer and is widely recognized as one of the nation’s most respected authorities on cybersecurity, Theresa Payton is a highly sought-after keynote speaker. She captivates audiences by drawing from her experience as a veteran cybercrime fighter and entrepreneur, masterfully blending memorable anecdotes with cutting-edge insights.
A celebrated, patented inventor of new security designs, Payton identifies emerging trends and techniques to help businesses – and audiences – combat cyber threats, from the impact of the Internet of Things to securing Big Data. She’s the cybersecurity expert organizations in both the public and private sectors turn to protect their most valuable resources, improve their IT systems and strategies and to discreetly guide them through data breaches.
Managing cybersecurity risk is what Payton knows and does best. Before overseeing IT operations as CIO for President George W. Bush and his administration, she held executive roles in banking technology for two of the country’s top financial institutions. After serving in the White House, she went on to co-found Dark3, a cybersecurity product company, and Fortalice Solutions, a world-class cybersecurity consulting firm ranked a “Top 5 Most Innovative Cybersecurity Company” in Northern Virginia, Maryland, and DC.
Because of her ability to explain complex security issues and help non-tech-savvy people understand how to protect their privacy, Payton has been a frequent guest on The Today Show, Good Morning America, Fox Business, and Fox News and has been featured on CBS News, CNN, NBC News, and MSNBC, as well as Canadian and Irish news outlets. She also starred on the reality TV series “Hunted”, where highly trained investigators (including Payton) “hunted” to catch people attempting to hide throughout the world.
She is the author of multiple industry-leading books on IT strategy and cyber security, including “Manipulated: Inside the Cyberwar to Hijack Elections and Distort the Truth,” which The Guardian included on their list of the “Top 10 Books About Cybercrime.”

More
Chris Tarbell

Chris Tarbell

Director, Cyber Security and Investigations, Berkley Research Group and Former FBI Special Agent

Chris Tarbell is a former FBI special agent and current Director of Cyber Security and Investigations at Berkeley Research Group. Tarbell has been called one of the most successful cyber security law enforcement officials of all time. He is the man responsible for infiltrating the hacker group Anonymous and taking down the notorious dark web drug trafficking site Silk Road, called “the most sophisticated and extensive criminal marketplace on the Internet.” He led the tracking and arrest of two of the most infamous figures in cyber space: Sabu, who was at one point the most influential hacker in the world, and Dread Pirate Roberts, who was later convicted for his involvement with Silk Road. With 17 years in law enforcement–including time in the FBI’s preeminent cyber crime squad–and extremely rare insight into the minds of the hacker community, Tarbell is one of the nation’s preeminent voices on cyber security, and the man that gives even the most notorious cyber criminals nightmares.

More
Emmanuel Adinkra

Emmanuel Adinkra LinkedIn

Senior IT Administrator, Santa Clarita Water Agency

Emmanuel Adinkra is a Network and Systems Administrator at Santa Clarita Valley Water Agency and a certified cybersecurity engineer specializing in critical infrastructure security, cyberpsychology, and trust and safety. His work focuses on strengthening cybersecurity resilience within public utilities while addressing the human factors that influence cyber risk, organizational culture, and digital behavior. Emmanuel is also a final-year Doctoral Candidate in Cybersecurity at Marymount University.
He has spoken at global forums including TrustCon and the Stanford Trust & Safety Research Conference, and collaborates with governments, law enforcement, academia, and industry on combating online harms such as financial sextortion, CSAM, and cyberbullying. Emmanuel also serves in advisory and collaborative capacities across digital safety, cybersecurity, and AI governance initiatives, contributing to conversations on responsible technology, online trust, and public policy. His work bridges cybersecurity operations, public policy, and digital safety advocacy, with a strong focus on protecting vulnerable communities online.

More
Jonathan Alonzo

Jonathan Alonzo

Cybersecurity Manager, San Bernardino County Sheriff Department, State of California

[LinkedIn:https://www.linkedin.com/in/jonathan-alonzo-754405ab

Jonathan Alonzo is the Cybersecurity Manager for the San Bernardino County Sheriff’s Department. He obtained a Bachelor’s of Arts in Criminal Justice from California University, Fullerton in 2008 and a Bachelor’s of Science in Information Security from Azusa Pacific University in 2015. Jonathan started his career with the Sheriff’s department in 2015 as a Technician in the Technical Service department. He advanced his career over the last eight years and is now overing seeing Cybersecurity in now overing seeing Cybersecurity Operations for the Sheriff’s department. With his education and experience in Law Enforcement and Cybersecurity, Jonathan has become a valuable member of the Technical Service Department and Sheriff’s office.

More
Enrique Alvarez

Enrique Alvarez LinkedIn

Public Sector Advisor, Google Cloud

Enrique Alvarez serves as a Public Sector Advisor within the Office of the Chief Information Security Officer (OCISO) at Google Cloud. In this capacity, he facilitates the achievement of cloud and AI-driven transformational objectives for international, federal, state, local, and educational partners. Before his tenure at Google, Enrique retired from a distinguished career with the Federal Bureau of Investigation (FBI) as a special agent and supervisor, where he directed a cyber investigative unit focused on state-sponsored threats.
Leveraging extensive experience in both law enforcement and the military, Enrique possesses comprehensive insight into the sophisticated threats encountered by public sector entities. He applies this proficiency to demonstrate how Google Cloud's security protocols meet or exceed security requirements of public sector clientele.
Enrique also served as a commissioned officer in the United States Navy, retiring from the reserve component in 2013. Enrique holds degrees from Stanford University and the Navy Postgraduate School.

More
Rob Beach

Rob Beach

Director of Information Technology, City of Palm Bay, State of Florida

Robert "Rob" Beach is the Director of Information Technology for the City of Palm Bay, Florida, with over 30 years of public sector technology leadership. His career includes CTO of the City of Cocoa, IT Director for Seminole County, and IT Director for the City of Oviedo. A Computerworld Premier 100 IT Leader (2010), Rob holds degrees from the University of Central Florida and Florida Institute of Technology. He currently serves as President of FLGISA and has been an active MS-ISAC member, including previous service on its Executive Committee and as a Leadership Mentor.

More
Dave Beller

Dave Beller LinkedIn

Quantum Resiliency in Cryptography for SLTT Security, San Diego Unified School District

Dave Beller has been the Cybersecurity Architect for San Diego Unified School District since 2022, specializing in secure automation, identity governance, and compliance for California’s second largest school district. He leads district level initiatives to strengthen operational security, modernize authentication, and improve incident response readiness. He holds a BS in Cybersecurity and Information Assurance from WGU, many IT and Security industry certifications, and is currently working on a MS in Cybersecurity.

More
Phil Bertolini

Phil Bertolini

Chief Delivery Officer, Government Technology

Phil Bertolini is a Chief Delivery Officer for Government Technology, the premiere event and thought leadership content provider for state and local government technology professionals. Previously, he served as deputy county executive and CIO for Oakland County, Michigan. During his 31-year tenure, Phil built a world-class IT organization in the second-largest county in Michigan, just north of Detroit. As Oakland County CIO, he oversaw more than 150 employees serving over 1.2 million residents. In 2005, he was also promoted to deputy county executive, holding dual positions until his retirement. Phil’s efforts earned the county national attention, winning numerous awards for technology innovation and excellence. He was named Governing Magazine’s Public Official of the Year and Government Technology Magazine’s Top 25 Doers, Dreamers & Drivers. He was also honored by the President Obama White House as a Champion of Change.

More
Charles Burton

Charles Burton

Director of Information Technology, Calcasieu Parrish, State of Louisiana

Charles Burton has led technology teams in Louisiana local government for 20 years and is currently the Calcasieu Parish Technology Director. He is passionate about utilizing technology to create efficient and effective organizational operations. He is a McNeese State University alumnus as well as receiving a bachelors in computer science from University of Phoenix and a Masters in Computer Science from the University of South Florida. He holds several industry certifications including ITIL, PMP, CGCIO, CISSP, CompTIA as well as Microsoft certificates.
Mr. Burton serves on several boards and committees including Louisiana Digital Government Advisory Board, McNeese State University and SOWELA technical Community College Computer Science Advisory Board, NACo Information Technology Standing Committee, Economic Development Alliance Technology Council chair. Regional lead member of the Louisiana Cyber Guard. He has spoken on the topic of Cybersecurity at events including BSides, CyberNow, Texas Cyber Summit, Louisiana Digital Government Summit and the Calcasieu Cybersecurity Summit.
Mr. Burton is involved in community organizations where he resides in Lake Charles, LA with his wife and family. He enjoys spending time outdoors, golfing and tinkering with his jeep.

More
Brian Cohen

Brian Cohen

Vice President, Center for Digital Education

Brian Cohen is the vice president of the Center for Digital Government and Center for Digital Education, a national research and advisory institute on information technology policies and best practices in state and local government and education. Prior to joining the Center, Brian was vice chancellor and University CIO for the City University of New York (CUNY).
As the vice chancellor and University CIO at CUNY, Brian directed the Office of Computing and Information Services (CIS), developed and managed the enterprise IT vision, strategy and day-to-day technology operations of the University. His areas of focus included academic and business systems, cloud strategies, IT policies and procedures, cybersecurity, project management, IT resiliency and disaster recovery and network and telecommunications.
Brian also served in leadership roles with the City of New York. Among his many accomplishments, Brian developed the City of New York’s e-Government strategy, implemented the City’s award-winning nyc.gov website and managed the City’s effort to address the Y2K technology challenge.

More
Meghan Cook

Meghan Cook

Director, Cyber Incident Response Team, Division of Homeland Security & Emergency Services, State of New York

Meghan Cook is Director of the Cyber Incident Response Team (CIRT) and Assistant Director of the Office of Counter Terrorism (OCT) at the NYS Division of Homeland Security and Emergency Services (NYS DHSES).
Meghan leads a team of cyber and homeland security professionals providing proactive cyber services and incident response for NYS local governments, non-executive state agencies and schools. She also leads multi state and local agency teams to address statewide cyber challenges.
For 25 years, Meghan was the Program Director for the Center for Technology in Government (CTG), a globally renowned research institute at University at Albany/SUNY as well as Adjunct Professor at Nelson A. Rockefeller College, and Advisor to the NYS Local Government Information Technology Directors Association (NYSLGITDA).
She has published numerous research and practice articles, book chapters, and reports on digital transformation and cybersecurity in local government, including the Cybersecurity Primer for Local Government Leaders and Artificial Intelligence (AI) and Public Managers: Key Questions and Recommended Actions.
She is a highly sought speaker and facilitator, having delivered over 400 thought-leadership and strategy development sessions for government leaders all over the world. Meghan has won several awards including SUNY Adirondack’s Trailblazer Award, Excelsior College’s Alumni Achievement Award, and the SUNY Excellence and Chancellor Awards. She holds a BS from Excelsior University and MPA and MS from the University at Albany, State University of New York.
@megcook

More
Mikel Costello

Mikel Costello LinkedIn

Enterprise Architect / Strategic Planning and Design Manager, WaTech, State of Washington

Costello is an enterprise architect and former IT executive with 25+ years of experience in digital transformation, cybersecurity, and cloud strategy across government and military sectors. At Washington Technology Solutions, he leads statewide IT strategy, designs secure multi-cloud environments, and develops governance frameworks to enhance cybersecurity and reduce technical debt. A Zero Trust and SASE thought leader, he authored Washington’s Zero Trust White Paper. His career includes managing large technology portfolios, modernizing infrastructure, and delivering cost-efficient, resilient, and mission-aligned IT solutions across multi-agency environments.

More
Gary Coverdale

Gary Coverdale

Chief Information Security Officer, Santa Barbara County, State of California

Gary Coverdale is the acting CISO for Santa Barbara County and advisor to other Public Sector Agencies.
Previously serving on MS-ISAC’s Executive Committee for over 11 years, Mr. Coverdale has been Co-chair of both the Metrics and Mentoring Work Groups.
Mr. Coverdale has been awarded the Lifetime Achievement Award from MS-ISAC, the Security Leadership Award of Excellence for the California Cyber Security Symposium and nominated for the ISE Information Security Executive of the Year-West Region.
He is listed by The Cyber Express as one of the Top 50 CISOs to Watch 2023 State Tech as well Magazine’s 2025 list of 25 IT Influencers Worth Following.
He is the Past Chair of the California Counties Information Services Directors Association – Information Security Council.

More
Ben Edelen

Ben Edelen

Chief Information Security Officer, Boulder County, State of Colorado

Benjamin Edelen, CISO at Boulder County, Colorado, protects his community by making government awesome, helping people stand together, and by getting the basics right. Benjamin holds a bunch of professional certifications, participates in government and cyber security communities of practice, and is grateful for the opportunity to make a difference.

More
Harold Garron

Harold Garron LinkedIn

Disaster Recovery Manager, Cooper University Healthcare

Harold Garron is a seasoned cybersecurity and network professional specializing in disaster recovery, centralized log aggregation, and security operations in complex healthcare environments. He serves as Disaster Recovery Manager at Cooper University Health Care and as an adjunct professor at Rowan University teaching computer science and cybersecurity, bridging enterprise practice with academic rigor. Harold holds Master of Science degrees in Information Assurance and Computer Science and brings extensive hands-on expertise with Cisco, Aruba, and security infrastructure to strengthen organizational resilience and incident response programs.    

More
Kateri Gill

Kateri Gill

Director of Strategic Partnerships, Center for Internet Security (CIS)

Kateri Gill is the Director of Strategic Partnerships at the Center for Internet Security (CIS). Since joining CIS in 2016, she has worn many hats, all while supporting government entities in their cyber maturity journey. With a passion for leadership and program development, Kateri played a pivotal role in standing up the EI-ISAC, and is currently focused on large-scale service deployments, including multi-tenancy solutions and managing trade association relationships.
Kateri has earned numerous industry and professional certifications in her time at CIS. However, prior to CIS, she employed her degrees in Geology and Physics to the field of Semiconductor Engineering. Outside of work, Kateri is an adventurer who enjoys visiting new places and sampling the most unique item on every food menu.

More
Daniel Gohl

Daniel Gohl LinkedIn

Chief Technology and Strategy Officer, U.S. SLED, HP Inc.

Daniel Gohl joined HP Inc. as head of U.S. Education Strategy in September 2022. He brings three decades of partnering for success through innovation with students and educators from pre-kindergarten through post-graduate studies. Daniel has deep knowledge and extensive experience in teaching, education management and educational policy at the local, state and national level. He is committed to helping communities, and the institutions serving them, ensure that education is contemporary, challenging and continuous. Dan was raised in the Mid-Hudson Valley region of New York and currently lives in Fort Lauderdale, Florida with his wife and three children.

More
John Israel

John Israel LinkedIn

Chief Information Security Officer, State of Minnesota

Israel serves as the State of Minnesota's chief information security officer and the assistant commissioner of Minnesota IT Services (MNIT). At MNIT, he leads the state’s executive branch cybersecurity teams, chairs the Minnesota Cybersecurity Task Force, and fosters collaborative efforts to develop effective cybersecurity strategies across all levels of government.
John has over 25 years of IT experience leading, building, and growing cybersecurity and IT functions in municipal, county, and state entities. He also oversees cybersecurity operations for the state and multiple grant-funded outreach programs that provide cybersecurity support and resources to counties, port cities, and tribal nations throughout Minnesota.
At MNIT, John has played a key role in strengthening the state's cybersecurity capabilities, including serving as deputy CISO and leading the Security Operations Center (SOC). He was instrumental in establishing the state's first SOC and developing cybersecurity threat intelligence sharing through the Minnesota Fusion Center, hosted by the Minnesota Bureau of Criminal Apprehension.
Before joining MNIT in 2008, John led IT operations for the Washington County Sheriff's Office. John holds a Bachelor of Arts degree from Concordia University in Saint Paul, a Master of Science degree from Norwich University in Vermont, and a Certified Information Systems Security Professional (CISSP) certification from ISC(2).

More
Dan Lohrmann

Dan Lohrmann

Senior Fellow, Center for Digital Government 

Daniel J. Lohrmann is an internationally recognized cybersecurity leader, technologist, keynote speaker and author.
During his distinguished career, Dan has served global organizations in the public and private sectors in a variety of executive leadership capacities, receiving numerous national awards including: CSO of the Year, Public Official of the Year and Computerworld Premier 100 IT Leader.
Lohrmann led Michigan government’s cybersecurity and technology infrastructure teams from May 2002 – August 2014, including enterprise-wide Chief Security Officer (CSO), Chief Technology Officer (CTO) and Chief Information Security Officer (CISO) roles in Michigan. He works with cybersecurity technology companies to provide insights and long-term strategic support. Dan is a Senior Fellow with the Center for Digital Government and a contributor to Government Technology magazine. He has advised senior leaders at the White House, National Governors Association (NGA), National Association of State CIOs (NASCIO), U.S. Department of Homeland Security (DHS), federal, state and local government agencies, Fortune 500 companies, small businesses and non-profit institutions.
Dan has more than 30 years of experience in the computer industry, beginning his career with the National Security Agency. He worked for three years in England as a senior network engineer for Lockheed Martin (formerly Loral Aerospace) and for four years as a technical director for ManTech International in a U.S./UK military facility. He has been a keynote speaker at global security and technology conferences from South Africa to Dubai and from Washington D.C. to Moscow.
Dan currently serves as Field CISO for the public sector at Presidio. He is the co-author of Cyber Mayday and the Day After: A Leader's Guide to Preparing, Managing, and Recovering from Inevitable Business Disruptions, published by Wiley in November, 2021. He is also the author of two earlier books: Virtual Integrity: Faithfully Navigating the Brave New Web and BYOD For You: The Guide to Bring Your Own Device to Work.
Lohrmann holds a Master's Degree in Computer Science (CS) from Johns Hopkins University in Baltimore, Maryland, and a Bachelor's Degree in CS from Valparaiso University in Indiana.
Follow Dan on Twitter at: @govcso
Dan’s award-winning blog: http://www.govtech.com/blogs/lohrmann-on-cybersecurity/

More
James Longhurst

James Longhurst LinkedIn

Information Systems Associate Director, Utah County

James Longhurst is the Information Systems Associate Director for Utah County Government, where he leads technology strategy, cybersecurity, and operations for an organization serving more than 700,000 residents. With more than 19 years of experience in IT leadership, enterprise infrastructure, and public sector technology, James has led initiatives across both government and healthcare environments. Prior to joining Utah County, he served as an Information Systems Director for Universal Health Services, where he led recovery and rebuilding efforts for several hospitals following a major ransomware attack impacting healthcare facilities across multiple states. James holds a master’s degree in Computer Information Systems from Colorado State University.

More
Lauren McFayden

Lauren McFayden

Threat Intelligence Analyst, Center for Internet Security

Aimé Nsengiyumva

Aimé Nsengiyumva LinkedIn

Deputy Chief Information Security Officer, State of Tennessee

Aimé Nsengiyumva, Deputy Chief Information Security Officer, has been working for the State of Tennessee for the past 11 years. Before that, he worked for the United Nations Organization for more than 15 years in various Information Technology leadership roles.
In the past 3 years, he has been actively involved in the State of Tennessee’s “Whole-of-State” program initiatives.
He holds a Master of Science degree in Information Technology (Project Management and Leadership) and a Bachelor of Science in Information Technology (Network Technologies). He has earned various industry standard certifications, including the CISSP, PMP, ITIL, and TOGAF.

More
Major General (ret.) Rich Neely

Major General (ret.) Rich Neely

Executive Vice President & General Manager for Operations, Intelligence and Services (OIS) at the Center for Internet Security (CIS)

Major General (ret.) Rich Neely is the Executive Vice President & General Manager for Operations, Intelligence and Services (OIS) at the Center for Internet Security (CIS). Reporting to the President and CEO, he directs the strategy, performance, and financial stewardship of CIS’s operational portfolio, delivering critical cybersecurity services to U.S. state, local, tribal, and territorial (SLTT) governments. In this role, he oversees the organizations that operate the MS-ISAC and EIISAC, directing a diverse suite of products and services designed to harden nationwide cyber resilience through strategic technology partnerships and member-focused initiatives.
Neely concluded his distinguished military career as the 40th Adjutant General of Illinois, serving on the Governor's cabinet and commanding both the Illinois Army and Air National Guard with a formation exceeding 13,000 Soldiers and Airmen. As an Air Force Master Cyber Officer, he holds the distinction of being the first Adjutant General in the nation with cyber expertise. During his tenure at the Pentagon, Neely served as the Air National Guard's Chief Information Officer (CIO), overseeing enterprise network operations across 90 Wings, and responsible for all deployable communications units, Cyber and Space Operational units bringing deep operational experience across the Air, Intelligence, Space, Communications, and Cyber domains. He also served as the National Guard's Chief of Current Operations (J33), functioning as the principal point of contact for all National Guard Domestic Operations, Defense Support to Civil Authorities, and crisis management coordination with federal interagency partners across all 54 states and territories.
His career reflects a consistent record of leadership in high-stakes environments. Neely established the first Illinois National Guard Election Protection team in 2018 to support local election authorities and directed military planning for the 2012 NATO Summit in Chicago — one of the largest National Special Security Events conducted outside the National Capital Region. These efforts underscore his enduring commitment to both national security and the protection of democratic institutions.
Following his military retirement and prior to joining CIS, Neely served as a program advisor at George Mason University, focusing on cybersecurity, Position, Navigation and Timing (PNT), and disruptive technologies, while concurrently serving on the boards of several organizations. He is widely recognized as a national leader at the intersection of cybersecurity, critical infrastructure, emergency management, and national security, and is a sought-after speaker before prominent audiences including U.S. Northern Command, the National Governors Association, the Armed Forces Policy Board and has delivered international keynote addresses before the Association of Business Service Leaders in Poland.
Neely holds a Bachelor of Science in Finance and a Master of Science in Information Leadership/CIO and holds several professional certifications. His highest military decoration includes the Air Force Distinguished Service Medal. He also received the Polish Commander's Cross with Silver Star Order of Merit awarded from the President of Poland, and the Distinguished Service Medal (Illinois) awarded by the Governor of Illinois.

More
Allen Ohanian

Allen Ohanian LinkedIn

Chief Information Officer, Los Angeles County Department of Children and Family Services

Allen Ohanian is a cybersecurity executive, public-sector technology leader, international speaker, and scholar-practitioner with more than 20 years of experience in cybersecurity, privacy, risk management, incident response, and technology governance. He is the Chief Information Security Officer for the Los Angeles County Department of Children and Family Services, where he led enterprise cybersecurity strategy, risk reduction, security awareness, incident response, privacy coordination, and compliance initiatives supporting one of the nation’s largest child welfare agencies. His work integrates artificial intelligence, cyber psychology, human behavior, organizational trust, and cyber resilience. Allen is also a Ph.D. candidate in Industrial/Organizational Psychology and has contributed to cybersecurity education, workforce development, and public-sector innovation through academic programs and national and international forums.

More
Garrett Ragland-Helf

Garrett Ragland-Helf LinkedIn

Group Facilitator, MS-ISAC Leadership Mentoring Program

Garrett Ragland-Helf is a CISO Advisory Analyst at Apollo Information Systems and a founding contributor to the company's Texas Cybersecurity Framework assessment program. Since the program's launch, he has served as the lead advisor on engagements across a wide range of Texas SLED entities, from large state agencies to small, resource-constrained local governments, translating complex technical risk into actionable strategy for C-suite and executive leadership. Rooted in hands-on GRC program design and executive advisory work, Garrett brings a practitioner's perspective to the challenge of helping government organizations build assessment programs that move beyond one-time compliance exercises toward scalable, defensible foundations for long-term security maturity.

More
Rob Reese

Rob Reese

Cyber Incident Response Team (CIRT) Manager, MS-ISAC

Rob Reese is currently the Cyber Incident Response Team (CIRT) Manager for the MS-ISAC, where he has served in this position for over five years. Prior to joining Center for Internet Security (CIS) and the MS-ISAC, Rob spent 10 years at the Virginia State Police (VSP) in the Virginia Fusion Center (VFC) as an analyst and analyst team lead/manager rotating between the Terrorism Unit, the Critical Infrastructure Protection Unit, and the Cyber Intelligence Unit. Rob was involved in conducting behavioral threat assessments on potential predatory/targeted violence. Rob has also previously served as a police officer and detective with the UNC-Chapel Hill Department of Public Safety as well as completed a short stint at Capital One working in identity fraud prior to joining VSP. Rob thanks God for the opportunity he has had to serve both in law enforcement and at the MS-ISAC, where with his team of passionate and knowledgeable incident responders, gets to continue to help people in need.

More
Randy Rose

Randy Rose LinkedIn

Vice President of Security Operations and Intelligence, CIS Security Ops & Intelligence

Randy has over two decades of experience across state, local, and federal government. He currently leads Security Operations at the Center for Internet Security, overseeing the Intelligence, Real-Time Monitoring, Incident Response, and Red Team missions supporting the Multi-State ISAC. Previously, he led the largest Joint Military Security Operations Center in Europe and the Intelligence Department for the Navy's Global Cyber Command.
He previously served in the U.S. Air Force and as New York State’s first local government-focused penetration tester. He moonlights as an adjunct instructor at multiple universities and sits on the Board for two local nonprofit organizations.

More
Theodore Sayers

Theodore Sayers

Senior Director of Threat Intelligence, CIS Security Ops & Intelligence

Theodore (TJ) Sayers is the Senior Director of Threat Intelligence at the Center for Internet Security (CIS), where he leads the Cyber Threat Intelligence, Multidimensional Threats, and Red Team missions. He previously oversaw the Digital Forensic & Incident Response team, led CIS liaison efforts at the U.S. Department of Homeland Security's Cybersecurity and Infrastructure Security Agency, and operated in various analyst capacities.
He has appeared in Forbes, The Washington Post, NPR, The Associated Press, and other media outlets covering cybersecurity topics and policies, with a focus on emerging technology and geopolitical threats impacting U.S. domestic security.
TJ is an adjunct instructor at Siena University developing and teaching graduate curriculum on cybersecurity, forensics, and information technology. He holds a Master of Public Administration from the Rockefeller College of Public Affairs at the University at Albany and numerous industry certifications. He also serves as an Intelligence Officer in the U.S. Navy Reserve, including time overseas as the Director of Intelligence for a U.S. SOCOM Joint Task Force mission.
CIS is home to the Multi-State Information Sharing and Analysis Center (MS-ISAC) and the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC), which serve thousands of U.S. State, Local, Tribal, and Territorial (SLTT) governments and election offices.

More
Kyle Smith

Kyle Smith LinkedIn

Vice President, GTM Strategy, NuHarbor Security

Kyle (he/him) is the Vice President of GTM Strategy at NuHarbor Security. He leads the development and execution of strategic product initiatives, ensuring that NuHarbor’s solutions are aligned with the evolving needs of both public and private sector organizations. His expertise in driving data-driven techniques enables clients to stay ahead of emerging cybersecurity threats. With over two decades in the cybersecurity industry, Kyle has held leadership roles across multiple domains, including security operations, network architecture, and product innovation. Prior to joining NuHarbor, he led cross-domain technology teams, spearheading security and systems initiatives to protect organizations from advanced threats. His work has helped safeguard hundreds of organizations with a combination of innovative approaches and operational excellence.
Kyle’s practical approach to technology and deep understanding of client challenges make him a trusted leader at NuHarbor. His passion for developing tailored security solutions ensures that clients receive expert guidance that drives meaningful outcomes.

More
Biplav Srivastava

Biplav Srivastava LinkedIn

Professor, AI Institute, University of South Carolina

Biplav Srivastava is an experienced researcher and technologist with expertise in Artificial Intelligence (AI), Sustainability and Services, and proven track record of many science firsts and high-impact innovation ($B+) in a global business environment. He has received major recognitions for technical work (two books, 250+ papers), patents (75+ issued) and prototypes (20+) from peers, interacted with commercial customers as well as universities and governments, represented at standard bodies (World Wide Web Consortium, Partnership on AI), and assisted business leaders at highest levels with technical issues. Biplav sees AI as enabling people to make rational decisions despite real world complexities of poor data, changing goals and limited resources by augmenting their cognitive limitations with technology. Trustworthy AI, aligned to human values and sustainable development, is the need of the hour. His group is working on promoting goal-oriented, ethical, human-machine collaboration using learning and reasoning. See details at: https://ai4society.github.io/

More
Teri Takai

Teri Takai

Chief Programs Officer, Center for Digital Government

Teri Takai is the Chief Programs Officer for the Center for Digital Government, a national research and advisory institute on information technology policies and best practices in state and local government. Teri worked for Ford Motor Company for 30 years in global application development and information technology strategic planning. From Ford, she moved to EDS in support of General Motors. A long-time interest in public service led her to the government sector, first as CIO of the State of Michigan, then as CIO of the State of California and, subsequently, the CIO of the U.S. Department of Defense, the first woman appointed to this role. She then served as the CIO for Meridian Health Plan.
Teri is a member of several industry advisory boards. She has won numerous awards including Governing magazine’s Public Official of the Year, CIO Magazine’s CIO Hall of Fame, Government Technology magazine’s Top 25 Doers, Dreamers & Drivers, the Women in Defense Excellence in Leadership Award and the Department of Defense Medal for Distinguished Public Service.

More
Soledad Antelada Toledano

Soledad Antelada Toledano

Security Advisor, Google Cloud

Soledad Antelada Toledano is a Security Advisor within the Google Cloud Office of the CISO, Public Sector, where she provides expert advisory and advocacy to public sector customers on critical security matters through leadership engagement, executive sponsorship, thought leadership, and customer advocacy. Her extensive cybersecurity background includes serving as Deputy CISO for the Harris for President campaign, where she provided national-level security leadership.
Prior to joining Google, Soledad spent several years at the Department of Energy’s Lawrence Berkeley National Lab, a prestigious scientific institution, where she made history as the first woman in the Cybersecurity department in a Security Engineering role.
Notably, she served as Head of Security for the ACM/IEEE Supercomputing Conference, overseeing the security and network architecture (SCinet) of the world's fastest network for research purposes.
Soledad is the founder of GirlsCanHack, an organization dedicated to empowering women in cybersecurity, and was recognized as one of the 20 Most Influential Latinos in Technology in America in 2016. She enjoys discussing the evolution of cybersecurity and the future of AI within security, and brings unique experience from working with the world's fastest networks and large-scale event security, as well as a deep understanding of research and SecOps needs
Soledad is also a published author, with her book, Critical Infrastructure Security: Cybersecurity lessons learned from real-world breaches, released in 2024.

More
Saby Waraich

Saby Waraich

Former Public Sector CIO & Cybersecurity Executive | Keynote Speaker | Author, SCARE to CARES

Saby Waraich is a former public sector CIO, cybersecurity executive, international keynote speaker, and international bestselling author of SCARE to CARES: Leading Digital Transformation without Chaos. With more than 25 years of leadership experience, he helps senior leaders lead through digital transformation, organizational change, and cybersecurity challenges with clarity, calm, and trust.
Ranked as a Top 10 Global Thought Leader in IT Leadership, Saby has led multimillion-dollar technology and security initiatives across government, higher education, and global organizations. He has spoken in more than 20 countries across five continents, sharing practical strategies that help leaders move from stress, chaos, anxiety, resistance, and ego to communication, adaptation, relationships, empowerment, and staying calm. His work has been featured through Forbes Technology Council, Thinkers360, and national media outlets.

More
Kim Watson

Kim Watson LinkedIn

Retired Senior Program Advisor, Operations and Intelligence Services at the Center for Internet Security (CIS)

Kim Watson recently retired as the Senior Program Advisor, Operations and Intelligence Services at the Center for Internet Security (CIS) and has almost 40 years’ experience in information assurance, cybersecurity, and defensive cyber operations. Prior to joining CIS, they were the Technical Director for the Integrated Adaptive Cyber Defense (IACD) portfolio at the Johns Hopkins Applied Physics Laboratory. Ms. Watson was a technical leader at the Department of Homeland Security (DHS) and the National Security Agency (NSA). During their time at NSA, Ms. Watson specialized in vulnerability discovery, technology evaluation, and operational risk management.

More
Nathan Willigar

Nathan Willigar LinkedIn

Chief Security Advisor, Microsoft

Mr. Willigar serves as Microsoft’s Customer Security Advisor for the State, Local, and Education sector, where he advises CISOs, CIOs, and executive leaders on security strategy, helping align Microsoft’s vision and solutions to customer needs while building trusted relationships.
Previously, he was the Chief Information Security Officer for the State of Maine, overseeing the security of the State’s IT infrastructure. Over more than six years, he strengthened Maine’s cybersecurity posture by maturing its security program, protecting citizen data, and supporting agency missions through tailored IT solutions. He collaborated closely with state and federal partners to identify threats, mitigate risk, and enhance enterprise-wide security capabilities.
Mr. Willigar served on the Maine Cyber Security Advisory Council and MS-ISAC. He holds a CISM, an MBA from Thomas College, a BA from Husson College, and completed the FBI CISO Academy.

More
Al Yu

Al Yu LinkedIn

Information Technology Director, Blackhawk County, State of Iowa

Al serves as the Information Technology Director for Black Hawk County, Iowa, where he leads a dedicated team responsible for managing enterprise technology operations, cybersecurity, and digital transformation initiatives. With over 25 years in the IT industry, including two decades in the K-12 sector, he brings a unique perspective on the challenges faced by state, local, tribal, and territorial (SLTT) entities.

He is passionate about cybersecurity, operational efficiency, and public service. Known for his people-first leadership approach, he champions a culture of continuous learning and collaboration. Al is also committed to supporting underserved and underrepresented communities by promoting equitable access to technology and digital resources, both within his organization and through broader engagement efforts. In his role, Al focuses on fostering a secure environment that supports both government operations and public service delivery. He is honored to serve on the MS-ISAC Executive Committee, where he brings a practical, service-oriented perspective to advancing cybersecurity initiatives nationwide.

More
View Speakers

Agenda

Sunday, June 21

4:00 pm Eastern

Registration / Help Desk

Palms Atrium

4:00 pm Eastern

Exhibit Hall

Grand Sierra D/E

5:30 pm Eastern

Welcome Reception

Palms 3

7:00 pm Eastern

End of Reception

Monday, June 22

7:30 am Eastern

Registration / Help Desk

Palms Atrium

7:30 am Eastern

Continental Breakfast / Exhibit Hall

Grand Sierra D/E

8:45 am Eastern

Welcome Remarks

Palms 1/2

Featured Vocalist: Valecia Stochetti, Cybersecurity Engineer, Center for Internet Security

9:00 am Eastern

Color Guard and National Anthem

Palms 1/2

9:10 am Eastern

Keynote Introduction

Palms 1/2

9:15 am Eastern

Keynote Presentation –How to Work Better Together –Through Collaboration in Tech, Security and AI

Palms 1/2

As the first female White House Chief Information Officer, Theresa Payton led national cybersecurity and digital transformation efforts that demanded unprecedented collaboration across fragmented agencies and stakeholders, proving that breaking silos and building shared situational awareness are essential for success in complex, high-stakes environments.

Drawing from her White House experience and current advisory work with Fortune 500 boards at Fortalice Solutions, Theresa shows how adaptive, cross-functional teams—much like the Team of Teams model, enable organizations to respond faster and smarter to AI-amplified threats, evolving cyber risks, and digital transformation challenges.

In today's landscape, true collaboration in tech and security means aligning people, processes, and technology: fostering transparency, ethical governance, and inclusive decision-making so that AI becomes a unifying force rather than a divider.

Theresa’s AI TRUST Framework and real-world lessons, from defending national networks to securing AI-driven operations, offer practical strategies for leaders to build resilient partnerships that protect systems and data while accelerating innovation.

Her keynote delivers an optimistic, actionable message:

"Collaboration isn't just nice to do, it's the competitive edge that turns fragmented threats into unified strength," empowering attendees to lead stronger, more connected teams in the age of AI, cybersecurity, and digital trust.

Theresa Payton, First Female White House Chief Information Officer; AI Strategist; Business and Personal Security Expert; Privacy Visionary

10:15 am Eastern

Transition Remarks

Palms 1/2

10:20 am Eastern

Networking Break in the Exhibit Hall

Network with your colleagues and discuss technology solutions with the event sponsors.

10:50 am Eastern

Concurrent Sessions I

Executive Security Exchange: CISO Roundtable Discussions

Grand Sierra F

This breakout session is designed to foster dynamic peer exchange among Chief Information Security Officers (CISOs) and senior security leaders, focusing on practical strategies to strengthen enterprise security posture. Participants will be organized into small roundtable groups, each assigned a topic such as Defense in Depth, Continuous Monitoring, Security Validation, AI Security Strategy, Security Culture, or Data Loss Prevention. Groups will designate a facilitator and scribe to capture insights, challenges, and leading practices, encouraging open dialogue, real-world storytelling, and collaborative ideation grounded in state and local environments.

Microsoft will actively support the session by rotating between tables, providing perspective, challenging assumptions, and deepening discussion.

All inputs will be consolidated into a structured summary and distributed post-session, serving as a shared knowledge asset to enable continued collaboration and capture actionable insights, trends, and opportunities.

Nathan Willigar, Chief Security Advisor, SLED Microsoft

* * * * * * * * * * * * * * * * * * * * * * * * * *

Sponsored Session

Grand Sierra G

Session title and description forthcoming.

* * * * * * * * * * * * * * * * * * * * * * * * * *

Ransomware Ready (1 of 4): Been There, Done That

Coral B

(Ransomware Prevention/Resilience)

This panel of SLTT leaders talks about the value of a cybersecurity program, what they have tried and lessons learned. The topics address high priority, low level of entry capabilities for small under-resourced organizations to mitigate ransomware impacts. They include training, patching, endpoint protection, and phishing prevention.

Moderator: Carlos Kizzee, Senior Vice President, CIS Stakeholder Engagement, Center for Internet Security

Rob Beach, Chief Technology Officer, City of Palm Beach, State of Florida

Gary Coverdale, Chief Information Security Officer, Santa Barbara County, State of California

Ben Edelen, Chief Information Security Officer, Boulder County, State of Colorado

* * * * * * * * * * * * * * * * * * * * * * * * * *

Elections in the Age of AI

Bonaire 1/2

(Elections Security)

AI technologies are transforming modern election campaigns, voter behavior, and election processes. This presentation will highlight applications of AI in elections, such as enhancing voter accessibility, improving election administration, creating campaign materials, and enabling civic engagement. The talk will also address risk and challenges that AI presents, as well as governance considerations to address these challenges.

Dr. Thomas P. Scanlon, Senior Research Scientist and Technical Manager, CERT Division, Software Engineering Institute, Carnegie Mellon University

* * * * * * * * * * * * * * * * * * * * * * * * * *

Building Trustworthy AI: A Practical Roadmap for Responsible AI Adoption Across SLTT Government

Coral C

(AI, GenAI, Machine Learning)

Generative AI is moving rapidly from experimentation to everyday use across state, local, tribal, and territorial (SLTT) governments—but readiness, governance maturity, and risk management approaches vary widely. This session brings together practical guidance and peer insights to help SLTT leaders move from intent to execution. Attendees will learn how jurisdictions are establishing clear expectations for responsible AI use through transparency statements, tailored Responsible AI guidance, and operational playbooks for AI readiness, governance, risk review, and procurement.

Subject matter experts directly involved in shaping emerging AI Governance, Risk, and Procurement Playbooks will discuss where SLTTs truly stand today, what challenges persist, and what’s coming next—including the safe integration of tools like copilots, agentic systems, and AI-enabled SaaS platforms. Participants will walk away with actionable templates, real-world examples, and best practices to support secure prompting, protect sensitive data, reinforce human-in-the-loop review, and confidently scale AI adoption across enterprise workflows—while balancing innovation with accountability.

Stephanie Gass, Sr. Director of Information Security, Center for Internet Security

James Globe, VP of Strategic Cybersecurity Capabilities, Technology & Innovation

Jason Skeen, Information Technology Security Manager, Mecklenburg County, State of North Carolina

Al Yu, Information Technology Director, Blackhawk County, State of Iowa

* * * * * * * * * * * * * * * * * * * * * * * * * *

Whole-of-State in Action, Part I: Confronting Challenges in State–Local Partnership

Grand Sierra H/I

(Whole-of-State)

Whole-of-State in Action: This panel dives deeply into the realities and friction points of operationalizing whole-of-state cybersecurity. Panelists—representing states at different maturity levels and using different models of MS ISAC participation—will discuss the nuanced challenges that arise when aligning state strategies with the needs, capabilities, and constraints of local jurisdictions. The facilitator will press into real-world issues such as sustaining local engagement, addressing unfunded mandates, balancing compliance and flexibility, strengthening local cyber hygiene, and building long term resilience beyond grant cycles. Panelists will emphasize how they are confronting these challenges through governance models, shared services, capacity building strategies, cross jurisdictional trust structures, and continuous improvement cycles. This candid, practitioner focused discussion will resonate strongly with SLTT attendees seeking relatable experiences, tangible tactics, and evidence of progress happening across the nation. Each state's story will highlight that while no two whole of state approaches are the same, shared learning accelerates success for all. The session concludes with actionable next steps and invitations to deepen engagement with MS ISAC and other relevant resources and peer networks.

Moderator: Karen Sorady, VP of MS-ISAC Member Engagement, Center for Internet Security

Meghan Cook, Director, Cyber Incident Response Team, Division of Homeland Security & Emergency Services, State of New York

John Israel, Chief Information Security Officer, State of Minnesota

Aime Msengiyumva, Deputy Chief Information Security Officer, State of Tennessee

* * * * * * * * * * * * * * * * * * * * * * * * * *

GovRAMP 101: Strengthening Third-Party Cybersecurity Risk Management for Public Sector Agencies

Bonaire 5/6

(GovRamp)

As state and local governments increasingly rely on cloud services and third-party vendors, managing cybersecurity risk across the digital supply chain has become a mission-critical responsibility. This foundational session introduces GovRAMP and demonstrates how agencies can leverage it to build a scalable, repeatable, and defensible third-party cybersecurity risk management program.

Designed for both technical and non-technical stakeholders, GovRAMP 101 provides practical guidance for integrating GovRAMP into procurement, IT, security, and compliance workflows—reducing risk while accelerating secure technology adoption.

Participants will explore:

•GovRAMP Overview: Understanding what GovRAMP is, how it aligns with NIST standards, and how it supports consistent, risk-based security assurance across vendors.

•Getting Started with GovRAMP: Step-by-step guidance for agencies beginning their GovRAMP journey, including assessing current practices and defining roles and responsibilities.

•Sample Security Policies & Procurement Language: How to use GovRAMP-aligned policy templates and procurement language to clearly communicate security expectations to vendors from the outset.

•Internal Stakeholder Education: Strategies for educating leadership, procurement, legal, IT, and program teams on shared responsibility and the value of standardized security reviews.

•Vendor Education & Engagement: Helping vendors understand GovRAMP requirements, pathways, and benefits to foster transparency and collaboration.

•Leveraging Continuous Monitoring: Using GovRAMP’s continuous monitoring approach to maintain ongoing visibility into vendor risk, reduce reassessment fatigue, and respond to changes over time.

Attendees will leave with a clear understanding of how GovRAMP can serve as the backbone of an agency’s third-party cybersecurity risk management program—enabling more secure, efficient, and confident technology decisions.

Leah McGrath, Executive Director and Board Ex-Officio, GovRAMP

* * * * * * * * * * * * * * * * * * * * * * * * * *

11:50 am Eastern

Short Break

12:10 pm Eastern

Concurrent Sessions II

Public Sector CISO Roundtable

Antigua 1/2

Join leading public sector security executives at the Public Sector CISO Roundtable. This interactive session moves beyond high-level discussions to address the most pressing, real-world priorities, challenges, and specific agency needs facing modern cybersecurity leaders.

Participants will explore how to successfully navigate the complex convergence of sophisticated threat actors, legacy system modernization, and strict regulatory mandates. A core focus will be placed on the dual nature of artificial intelligence: analyzing how AI amplifies threat actor tactics while strategically leveraging it as a workforce force multiplier to enhance threat detection and SOC operations.

Finally, the roundtable will dive into practical strategies for building long-term cyber resilience. Attendees will collaborate on architectural best practices, SOC modernization, and the evolving future of public-private information sharing in an AI-driven landscape.

IMPORTANT NOTE: Email confirmation of Invite required to attend.

Enrique Alvarez, Public Sector Advisor, Google Cloud

Soledad Antelada Toledano, Security Advisor, Google Google Cloud

* * * * * * * * * * * * * * * * * * * * * * * * * *

Modernizing Vulnerability Operations at State Scale: Virginia's Journey to Unified Risk Management in a Decentralized Environment

Grand Sierra F

(Vulnerability Management/Risk Management)

In this case study, the Virginia Information Technologies Agency (VITA) shares its multi-year effort to modernize statewide vulnerability and exposure management across 68 independent executive branch agencies. Session attendees will learn how VITA reduced manual triage effort by 80%, cut high-risk vulnerabilities by 50% in three months, and established a scalable, intelligence-driven model for remediation across a decentralized enterprise.

Moderator: Phil Bertolini, Chief Delivery Officer, Government Technology

Richard White, Director, Security. Products & Services, Virginia IT Agency, Commonwealth of Virginia

* * * * * * * * * * * * * * * * * * * * * * * * * *

Ransomware Ready (2 of 4): Foundations First — Access Control & Backups That Protect What Matters

Coral B

(Ransomware Prevention/Resilience)

Small jurisdictions often face the perfect storm of limited staff, aging technology, and increasing ransomware pressure. This session focuses on two of the most powerful and achievable starter controls: Access Control and Data Backup. Participants will learn how these foundational policies prevent unauthorized access, limit lateral movement, and enable reliable recovery, even in environments with minimal resources. Using policy templates, this session will walk through essential access management steps to establish unique user accounts, timely remove old accounts, handle role changes, manage privileged access hygiene, and the introduction of multi-factor authentication as a critical added safeguard that significantly decreases the risk of compromised credentials in small, resource constrained environments. The session will also overview building a sustainable data backup policy, discussing how offline and off-network backups, monthly restore testing, and clear ownership roles directly support ransomware resilience. Attendees will leave this session with sample policies and a checklist for validating backups. This session is ideal for teams needing "where do we start?" guidance, setting the stage for continued skill‑building across the full four‑session series and joining a broader year‑long effort to refine and exercise these policies with MS‑ISAC collaboration and TTX exercise support.

Moderator: Carlos Kizzee, Senior Vice President, CIS Stakeholder Engagement, Center for Internet Security

Gary Coverdale, Chief Information Security Officer, Santa Barbara County, State of California

Ben Edelen, Chief Information Security Officer, Boulder County, State of Colorado

* * * * * * * * * * * * * * * * * * * * * * * * * *

Ongoing Election Threats, Information Sharing and What's Left at the Federal Level

Grand Sierra G

(Elections Security)

As election officials continue to navigate an increasingly complex threat environment, the intersection of cybersecurity, physical security, geopolitical tensions, and malign information operations has elevated the importance of timely and actionable threat intelligence. This session will examine the evolving landscape of threats facing election infrastructure, including the influence of global conflicts, nation-state activity, domestic extremism, and emerging cyber tactics targeting public trust and election operations.

Participants will gain insight into how threat intelligence is gathered, analyzed, and shared to support election security and resilience. The discussion will highlight the critical role of information sharing in helping election officials identify risks, prepare for incidents, and strengthen coordinated response efforts across jurisdictions.

The session will also explore the current role of federal agencies in protecting elections.

Randy Rose, Vice President of Security Operations and Intelligence, CIS Security Ops & Intelligence

* * * * * * * * * * * * * * * * * * * * * * * * * *

AI, Human Behavior, and Cyber Resilience in Government: Building a Practical AI Enterprise Strategy for SLTTs

Bonaire 3/4

(AI, GenAI, Machine Learning)

As artificial intelligence reshapes the cyber threat landscape, government organizations must prepare for more than technical attacks alone. This session presents a practical case study from a large local government environment and introduces a multidisciplinary approach integrating cybersecurity leadership, AI risk, cyber psychology, and Organizational Psychology. Attendees will learn how modern threats increasingly exploit cognitive overload, trust gaps, and behavioral predictability, and how leaders can respond by building resilience in people, systems, and institutions.

Moderator: Phil Bertolini, Chief Delivery Officer, Government Technology

Allen Ohanian, Chief Information Officer, Los Angeles County Department of Children and Family Services, State of California

* * * * * * * * * * * * * * * * * * * * * * * * * *

MS-ISAC Higher Ed Member Connect and Fraudulent Student Applications

Bonaire 7/8

(Higher Education)

This session focuses on the value of MS-ISAC's Member Connect platform for higher education and the importance of expanding participation across institutions. The session then transitions to a discussion on ghost student accounts—fraudulent enrollment records—and their significant impact on federal funding for higher-education organizations.

Moderator: Brian Cohen, Vice President, Center for Digital Education

Fred Rankin, IT Director of Cyber Security/Infrastructure/End User Services, Lane Community College

* * * * * * * * * * * * * * * * * * * * * * * * * *

Secure by Design: Embedding Enterprise Cyber Resilience into Local Government Software

Bonaire 5/6

(Local Government)

This session explores how organizations can make security a foundational characteristic across the entire system lifecycle, from concept and design to deployment, operation, and decommissioning. Drawing on enterprise cyber strategies, real-world case studies, and practical frameworks, attendees will learn how to embed security into culture, governance, and supply chains to create infrastructure that is inherently robust, resistant to attack, and capable of rapid recovery.

Charles Burton, Director of Information Technology, Calcasieu Parrish, State of Louisiana

* * * * * * * * * * * * * * * * * * * * * * * * * *

1:10 pm Eastern

Working Lunch

Palms 1/2

1:40 pm Eastern

General Session – Joint Threat Brief: Center for Internet Security and Center for Digital Government

Palms 1/2

Moderator: Dan Lohrmann, Senior Fellow, Center for Digital Government

Lauren McFayden, Threat Intelligence Analyst, Center for Internet Security

Randy Rose, Vice President of Security Operations and Intelligence, CIS Security Ops & Intelligence

Theodore Sayers, Senior Director of Threat Intelligence, CIS Security Ops & Intelligence

2:10 pm Eastern

Networking Break in the Exhibit Hall

Grand Sierra D/E

Network with your colleagues and discuss technology solutions with the event sponsors.

2:40 pm Eastern

Concurrent Sessions III

Own the Intelligence: Where Should Your AI Live?

Grand Sierra F

Daniel Gohl, Chief Technology and Strategy Officer for US SLED, HP

* * * * * * * * * * * * * * * * * * * * * * * * * *

Vulnerability Management Best Practices

Grand Sierra G

(Vulnerability Management/Risk Management)

Effective vulnerability management requires clear articulation of value, urgency, and business impact. This session facilitates a conversation on practical strategies to strengthen vulnerability management programs and secure the budgets needed to sustain them—covering how to speak the language of the business, frame risk effectively, and position security investments as essential enablers rather than cost centers.

Anthony Coronas, Director of Information Technology, Yocha Dehe Wintun Nation, State of California

* * * * * * * * * * * * * * * * * * * * * * * * * *

Ransomware Ready (3 of 4): Detect, Contain, Recover — Endpoint Protection and Incident Response for Lean Teams

Coral B

(Ransomware Prevention/Resilience)

Even with preventative controls in place, small jurisdictions must be ready to act fast when ransomware indicators appear. This session helps participants implement both Incident Response and Incident Handling—and be able to quickly identify which is needed. Attendees will work through how to make sure their IT and business continuity plans share the same priorities. Those joint priorities are the basis for quick assessment of an incident to determine what should happen next, to include communications and escalation requirements. Session will include Incident Handling workflows and checklists for environments where the first responder may also be the system administrator, communications lead, and recovery coordinator and escalation may include coordination with the MS-ISAC SOC or support designated by an insurance provider. This session will provide attendees with actionable draft policies, role checklists, and a simple "first 30 minutes" response guidance, plus opportunities to test these policies in real‑world scenarios.

Rob Reese, Cyber Incident Response Team (CIRT) Manager, MS-ISAC

Kim Watson, Senior Program Advisory, Center for Internet Security (former)

* * * * * * * * * * * * * * * * * * * * * * * * * *

Promoting AI's Safe Usage for Elections

Bonaire 5/6

(Elections Security)

This session explores the evolving role of artificial intelligence in electoral processes, focusing on its potential to improve data-driven decision-making amid the growing challenges of misinformation, manipulation, and voter suppression. It examines how AI tools could address information gaps for voters, candidates, and election commissions while acknowledging the skepticism and concerns that surround the use of AI in critical civic functions.

Biplav Srivastava, Professor, AI Institute, University of South Carolina

* * * * * * * * * * * * * * * * * * * * * * * * * *

Cyber Risk in the Public Sector: Managing Shared Responsibilities, AI Tools, and Secure Digital Supply Chains

Grand Sierra H/I

(GovRamp)

In today’s rapidly evolving digital landscape, state agencies and local governments face increasing cyber risks—especially when adopting third-party tools and cloud-based solutions. This hands-on workshop equips public sector professionals with practical strategies to assess and manage cyber risks across their digital ecosystems.

Participants will explore:

•Shared Responsibility Models: Clarifying “what’s yours, what’s mine, and what’s ours” when implementing third-party platforms and cloud services.

•Tracking Generative & Agentic AI: Understanding how AI is embedded in cloud products and how to monitor its use for compliance and risk.

•Efficient Security Reviews: Conducting apples-to-apples evaluations of vendors and digital supply chain components to streamline security assessments.

•GovRAMP Implementation: Step-by-step guidance on how to apply GovRAMP principles to your agency’s procurement and IT processes.

Through real-world scenarios, attendees will leave with actionable tools to strengthen their cyber posture and make informed decisions about technology adoption.

Leah McGrath, Executive Director and Board Ex-Officio, GovRAMP

* * * * * * * * * * * * * * * * * * * * * * * * * *

Small Government, Big Problems: Utilizing Open-Source Software to Support Citizens

Coral C

(Local Government)

Small and local governments face an outsized challenge: rising expectations from citizens paired with shrinking budgets, limited staff, and a complex technology landscape. This session explores how open-source software can help governments break out of that cycle—providing flexibility, transparency, and long-term sustainability while reducing vendor lock-in and enabling collaboration across agencies. The session addresses common concerns around support, security, and staffing, and separates myth from reality around open source in government.

Moderator: Deb Snyder, Senior Fellow, Center for Digital Government

Bob Henderson, Director of Information Technology, Cass County, State of North Dakota

* * * * * * * * * * * * * * * * * * * * * * * * * *

Log Aggregation and SIEM Overview

Bonaire 7/8

(Threat Intel/SecOps/IR)

This technical presentation provides a practical overview of log aggregation and its evolution into full Security Information and Event Management (SIEM) capabilities. The session covers centralized log aggregation, real-world methods for collecting logs from diverse sources (Linux, Windows, network devices, cloud/container environments), prevalent log formats and parsing techniques, and the distinction between basic aggregation platforms and mature SIEM solutions. Attendees will leave with actionable insights to design scalable logging pipelines.

Moderator: Phil Bertolini, Chief Delivery Officer, Government Technology

Harold Garron, Disaster Recovery Manager, Cooper University Healthcare

Kyle Smith, Vice President, GTM Strategy, NuHarbor Security

* * * * * * * * * * * * * * * * * * * * * * * * * *

3:40 pm Eastern

Short Break / Transition to the General Session

4:00 pm Eastern

Sponsored Session

Palms 1/2

Title and Description Forthcoming

5:00 pm Eastern

General Session – Strengthening the Nation Together: The New MS-ISAC Charter and Governance Model for the Future of SLTT Cybersecurity

Palms 1/2

In this end-of-day plenary keynote, a member of the Interim Member Governance Board (IMGB) will unveil the newly revised MS-ISAC Charter and Governance Model, developed through rigorous engagement with the SLTT community. This session explores how the revised governance structure strengthens MS-ISAC's value proposition, reinforces transparency and member influence, and creates a more unified, collaborative environment among the MS-ISAC and the state, local, tribal, and territorial government ecosystem. The session concludes with a first-of-its-kind MS-ISAC Champagne Toast.

Moderator: Teri Takai, Chief Programs Officer, Center for Digital Government

Carlos Kizzee, Senior Vice President, CIS Stakeholder Engagement, Center for Internet Security

Major General (ret.) Rich Neely, Executive Vice President & General Manager for Operations, Intelligence and Services (OIS) at the Center for Internet Security (CIS)

5:30 pm Eastern

ISAC Awards Ceremony

Palms 1/2

Presented by: Center for Internet Security Volunteer Committee

6:15 pm Eastern

Closing Reception

Grand Sierra D/E

7:00 pm Eastern

Adjourn Day 1

Tuesday, June 23

7:30 am Eastern

Registration / Help Desk

Palms Atrium

7:30 am Eastern

Continental Breakfast / Exhibit Hall

Grand Sierra D/E

8:45 am Eastern

Opening Remarks and Day 1 Recap

Palms 1/2

9:00 am Eastern

Keynote Presentation – Cyberchat Q and A: Insights for Elevating Cyber Resilience in Your Organization

Palms 1/2

Once adversaries in the cybersphere, Hector Monsegur and Chris Tarbell have joined forces to help organizations confront today’s most pressing cyber threats. Drawing on their extraordinary experiences - one as a former black-hat hacker, the other as an FBI special agent - their conversation offers a rare, dual-lens view of the modern threat landscape. In a dynamic, audience-driven discussion, Monsegur and Tarbell break down the most significant risks facing organizations today, how real-world attacks unfold, and where defenses most often fail. Together, they share practical insights and actionable frameworks that leaders can apply to strengthen security, reduce risk, and protect operations from disruptions that can cripple organizations and erode trust.

Chris Tarbell, Director, Cyber Security and Investigations, Berkley Research Group and Former FBI Special Agent

Hector Monsegur, Cyber Security Expert and Co-founder, SafeHill

10:00 am Eastern

Transition Remarks

Palms 1/2

10:20 am Eastern

Networking Break in the Exhibit Hall

Grand Sierra D/E

Network with your colleagues and discuss technology solutions with the event sponsors.

10:50 am Eastern

Concurrent Sessions I

Zero Trust: Good not Good Enough

* * * * * * * * * * * * * * * * * * * * * * * * * *

Ransomware Ready (4 of 4): Test, Test, Test

Coral B

(Ransomware Prevention/Resilience)

The most effective ransomware defense combines technical controls with an informed, confident workforce. This capstone session of the Ransomware Ready series focuses on establishing a test and exercise program that not just drives improvements, but also empowers staff across departments to respond efficiently and effectively to cyber impacts. The session will focus on simple strategies to make time spent 'practicing' provide significant return on investment. The session will capstone the series with a Call to Action and next steps; launching a year long MS ISAC collaborative initiative where participants will exercise their new policies in virtual training and workshop settings, collaborate to share improvements and lessons learned, and contribute to periodic updates of the Ransomware Prevention Toolkit as threats and operational environments evolve. Attendees of this session series will leave with both the tools and the community needed to keep their policies living, relevant, and resilient.

Rob Reese, Cyber Incident Response Team (CIRT) Manager, MS-ISAC

Kim Watson, Senior Program Advisory, Center for Internet Security

* * * * * * * * * * * * * * * * * * * * * * * * * *

Managing Election Supply Chain Security Through Procurement

Grand Sierra F

(Elections Security)

Election infrastructure relies on complex supply chains spanning technology, services, and physical materials, making procurement a critical control point for managing security risk. This session explores how election officials can integrate supply chain security into procurement practices to safeguard the integrity, availability, and trustworthiness of election systems and technology providers.

Grace Mozingo, Senior Program Support Specialist, MS-ISAC PMO, Center for Internet Security, Inc.

* * * * * * * * * * * * * * * * * * * * * * * * * *

Shadow AI in the C-Suite: What You Don't Know About

Grand Sierra H/I

(AI, GenAI, Machine Learning)

Right now, someone in your organization is pasting sensitive data into an AI tool you didn't approve, don't monitor, and can't audit. This session demystifies AI for executive leaders, cutting through the hype to show that AI runs on the same infrastructure you already secure. The session walks through four critical privacy risk categories—including data exposure, shadow AI adoption, and vendor liability, then delivers a practical decision framework for accepting or mitigating each one.

Moderator: Deb Snyder, Senior Fellow, Center for Digital Government

Chase Fopiano, CISSP, CCSP, CIPM, Executive Director, National Privacy Council

Stephanie Gass, Senior Director of Information Security

* * * * * * * * * * * * * * * * * * * * * * * * * *

Whole-of-State Part II: State Playbooks for Advancing Local Cyber Resilience

Coral C

(Whole-of-State)

Whole-of-State in Action: States across the country are evolving rapidly in how they support local governments on cybersecurity—yet no two models look alike. Building on the first session in the Whole-of-State in Action series, panelists will provide an unfiltered look into how their government structures, funding strategies, SLCGP implementations, and intergovernmental partnerships are shaping cyber resilience for municipalities, counties, school districts, and tribes. Through a facilitated dialogue, state leaders will share their practical playbooks: what's working, what they would do differently, and how they are building trust while navigating political, financial, and operational realities. Attendees will gain insight into diverse state models, from states offering comprehensive statewide MS ISAC membership to those developing bespoke state only services or locally driven programs. This session prioritizes transparency, lessons learned, and peer-to-peer value. Local attendees will leave with a clearer picture of the services and support emerging across states, while state officials will gain cross-state inspiration to mature their programs.

Moderator: Netta Squires, President Government Affairs, Cybersecurity & Resilience, Open District Solutions

John Godfrey, Chief Information Security Officer, State of Kansas

John Israel, Chief Information Security Officer, State of Minnesota

Aime Msengiyumva, Deputy Chief Information Security Officer, State of Tennessee

* * * * * * * * * * * * * * * * * * * * * * * * * *

Protecting PLC/SCADA Labs in Higher Education

Grand Sierra G

(Higher Education)

In higher-education institutions that collaborate with local industry partners to support workplace-learning programs, securing environments that rely on PLC/SCADA hardware is essential. This discussion outlines how one institution protected its operational environment, given the software's limitations and its challenges operating within modern network architectures.

Moderator: Brian Cohen, Vice President, Center for Digital Education

Fred Rankin, IT Director of Cyber Security/Infrastructure/End User Services, Lane Community College

* * * * * * * * * * * * * * * * * * * * * * * * * *

From Reactive to Resilient: Securing Executive Buy-In to Scale Local Government Cybersecurity

Bonaire 1/2

(Local Government)

This case study explores the journey of transforming a reactive security posture into a fully funded, proactive program within a county government. The session pulls back the curtain on specific strategies used to secure executive buy-in for a 300% increase in staffing and the budget for a modernized security stack—covering how to speak the language of elected officials, leverage strategic partnerships, and navigate the local government budget cycle.

Moderator: Phil Bertolini, Chief Delivery Officer, Government Technology

James Longhurst, Information Systems Associate Director, Utah County

Brandon Wong, Information Security Manager, Utah County

* * * * * * * * * * * * * * * * * * * * * * * * * *

11:50 am Eastern

Short Break

12:10 pm Eastern

Concurrent Sessions II

Why Do Security Pros and Teams Fail, and What Can You Do About It?

Grand Sierra H/I

(Professional Development)

Why do cybersecurity and technology professionals and their teams fail? Drawing on years of experience as Michigan’s former CISO and enterprise-level CIO, CTO, and CSO, Dan Lohrmann explores this question through surprising real-world stories and insights from leading award-winning government teams. While many believe the solution lies in more training, certifications, higher salaries, bigger budgets, better leadership skills, or stronger executive buy-in, Lohrmann reveals why even well-resourced teams can still fall short and what truly drives success. This keynote outlines seven ways to revitalize your role, your team, and your professional outlook, offering practical, actionable guidance along with interactive table discussions designed to help attendees personally apply the lessons learned.

Dan Lohrmann, Senior Fellow, Center for Digital Government

* * * * * * * * * * * * * * * * * * * * * * * * * *

Secure Elections: Working with Emergency Managers

Grand Sierra F

(Elections Security)

Secure elections require more than cybersecurity; they demand close coordination between election officials and emergency managers. As elections are designated critical infrastructure, election officials must integrate emergency planning, incident command, risk assessment, and crisis communication into election operations. This session explores how emergency management expertise in preparedness, response coordination, and recovery helps ensure continuity of voting during natural disasters, cyber incidents, and physical threats.

Paul Lux, Supervisor of Elections, Okaloosa County, State of Florida

Mark Peck, Senior Network Engineer, Greene County, State of Missouri

Netta Squires, President Government Affairs, Cybersecurity & Resilience, Open District Solutions

* * * * * * * * * * * * * * * * * * * * * * * * * *

Building Defensible Cyber Maturity in Resource-Constrained Governments

Bonaire 5/6

(Local Government)

Many state and local government entities approach cybersecurity maturity assessments as compliance exercises—something to complete, file, and forget. This session challenges that model. Drawing from hands-on experience designing and delivering Texas Cybersecurity Framework (TCF) assessments across a wide range of SLED entities, this session walks through how to build assessment methodology that is consistent, repeatable, and genuinely defensible. Attendees will leave with a clearer framework for thinking about maturity assessment not as a snapshot, but as a foundation for long-term program development.

Moderator: Deb Snyder, Senior Fellow, Center for Digital Government

Garrett Ragland-Helf, Group Facilitator, MS-ISAC Leadership Mentoring Program

* * * * * * * * * * * * * * * * * * * * * * * * * *

Operationalizing Zero Trust: Advancing Maturity Through SASE and SSE

Coral B

(Security Best Practice)

This session provides a practical framework for operationalizing Zero Trust using Secure Access Service Edge (SASE) and Security Service Edge (SSE) capabilities aligned to CISA's Zero Trust Maturity Model (ZTMM). The discussion focuses on how SLTT entities can move from "Initial" to "Advanced" maturity by integrating identity, device posture, network segmentation, application access, and data protection into a cohesive enforcement fabric.

Mikel Costello, Enterprise Architect / Strategic Planning and Design Manager, WaTech, State of Washington

* * * * * * * * * * * * * * * * * * * * * * * * * *

IT Budgets: From Cost Centers to Business Enablers

Bonaire 3/4

(Budget/Leadership)

Cybersecurity remains one of the toughest investments to justify because its ROI is largely invisible. When security works, nothing happens, and "nothing" is a hard sell. This session is a facilitated conversation focused on practical strategies to increase your chances of getting IT and cybersecurity budgets approved—by speaking the language of the business, framing risk effectively, and positioning security as a business enabler rather than a cost center.

Moderator: Teri Takai, Chief Programs Officer, Center for Digital Government

Anthony Coronas, Director of Information Technology, Yocha Dehe Wintun Nation, State of California

* * * * * * * * * * * * * * * * * * * * * * * * * *

1:10 pm Eastern

Working Lunch

Palms 1/2

1:35 pm Eastern

General Session

Palms 1/2

2:20 pm Eastern

Networking Break in the Exhibit Hall

Grand Sierra D/E

Network with your colleagues and discuss technology solutions with the event sponsors.

2:45 pm Eastern

Concurrent Sessions III

SCARE to CARES: Navigating Ransomware Incidents without Chaos

Grand Sierra F

(Ransomware Prevention/Incident Response)

Ransomware attacks rarely fail because of technology alone. Organizations struggle when stress rises, communication breaks down, and teams lose clarity during fast-moving incidents. This session introduces the SCARE to CARES leadership framework—developed from real-world experience leading through a major ransomware incident—helping leaders guide teams from fear and chaos toward calm, coordination, and decisive action through: Communicate, Adapt, Relationships, Empower, and Stay Calm.

Saby Waraich, Former Public Sector CIO & Cybersecurity Executive, Keynote Speaker, Author, SCARE to CARES

* * * * * * * * * * * * * * * * * * * * * * * * * *

Understanding the Perpetrators Who Threaten Election Workers: Behavioral Insights from DOJ Election Threat Cases

Grand Sierra G

(Elections Security)

This session presents a case-study analysis of twenty-one criminal cases prosecuted by the Department of Justice's Election Threats Task Force, analyzed through the lens of behavioral threat assessment frameworks. The discussion connects research findings to the current election threat environment and presents ten actionable recommendations that election officials and security partners can implement to strengthen prevention, detection, and response efforts.

Nikki Fisher, Chief Election Security Officer, Oregon Secretary of State

* * * * * * * * * * * * * * * * * * * * * * * * * *

Beyond Mythos and GPT 5.5-Cyber Models: Imagineering a Future State Cybersecurity Program 2028 (Public Sector)

Bonaire 1/2

(AI, GenAI, Machine Learning)

Public sector cybersecurity programs are trying to fight today's attacks with yesterday's organizational operating models. This session outlines a near-term, achievable future state model for public sector cybersecurity that fully leverages data science and generative AI technologies, backed by strong governance and leadership—connecting emerging technology with frameworks like NIST NICE, CSF, and ISO 27001 to present a notional Future State Program for 2028.

Moderator: Phil Bertolini, Chief Delivery Officer, Government Technology

James Globe, VP of Strategic Cybersecurity Capabilities, Technology & Innovation

Paul Grabow, Principal Researcher, Cybersecurity CMMC Practitioner

* * * * * * * * * * * * * * * * * * * * * * * * * *

Quantum Resiliency in Cryptography for SLTT Security

Grand Sierra H/I

(Emerging Technology)

Cryptographically-relevant quantum computers will arrive any time now, and as long-lived institutions, SLTTs are uniquely valuable targets for "harvest now, decrypt later" strategies. This session covers why quantum matters for SLTTs, a plain-English overview of quantum computing, which classical cryptographic algorithms are at risk (including RSA and Elliptic Curve Cryptography), what quantum-resilient cryptography looks like, and a practical roadmap for cryptographic inventory, prioritization, and pilot PQC deployment.

Dave Beller, Quantum Resiliency in Cryptography for SLTT Security, San Diego Unified School District

* * * * * * * * * * * * * * * * * * * * * * * * * *

Visualizing Security Posture by Mapping Tools to the CIS Framework

Bonaire 7/8

(Security Best Practice)

This case study explores a practical, visual approach to Governance, Risk, and Compliance (GRC) designed to solve the challenges of assessment fatigue, redundant toolsets, and resource drain. Attendees will walk through a complete use case of mapping an organization's security stack directly to CIS Control Safeguards, highlighting rapid identification of coverage gaps, elimination of overlapping vendor solutions, and the ability to clearly communicate compliance posture to both technical teams and executive leadership.

Andy Boell, Owner/Cybersecurity Specialist, Midwest Cyber

Valecia Stochetti, Cybersecurity Engineer, Center for Internet Security

* * * * * * * * * * * * * * * * * * * * * * * * * *

San Bernardino County Sheriff's Department — Royal Ransomware Recovery I Right of Boom Realities: Leadership Lessons on Key Activities That Enhance Preparedness

Coral B

(Ransomware Prevention/Incident Response)

This session presents an in-depth overview of the Royal Ransomware attack that struck the San Bernardino County Sheriff's Department on 4/7/2023, one of the largest law-enforcement agencies in the nation. The attack prompted immediate coordination with Cyber Insurance, County IT, the FBI, DHS, CalOES, JRIC, and Microsoft, and disrupted multiple mission-critical systems including CAD, CLETS, report writing, jail and patrol systems, and more. Attendees will gain firsthand insight into the response timeline, key decisions, and lessons learned. In this candid panel discussion, leaders who have navigated real-world cyber crises share the essential lessons they learned "right of boom," providing insights on best practices that should be contemplated and operationalized long before an incident occurs. Panelists explore the practical value of pre-event planning, including establishing and exercising response policies, validating communication chains, pre-authorizing decision pathways, and conducting meaningful tabletop exercises that truly stress-test assumptions.

Moderator: Dan Lohrmann, Senior Fellow, Center for Digital Government

Jonathan Alonzo, Cybersecurity Manager, San Bernardino County Sheriff Department, State of California

* * * * * * * * * * * * * * * * * * * * * * * * * *

Why Should I Be Bothered? OT Teams and the Cybersecurity Hassle

Bonaire 5/6

(Operational Technology (OT) Security)

This session examines the unique challenges faced by Operational Technology (OT) teams when confronted with cybersecurity requirements, exploring why OT professionals often view security mandates as a "hassle" and how to bridge the gap between IT security practices and OT operational realities.

Emmanuel Adinkra, Senior IT Administrator, Santa Clarita Water Agency

* * * * * * * * * * * * * * * * * * * * * * * * * *

3:45 pm Eastern

Short Break / Transition to the General Session

4:05 pm Eastern

General Session - Preparing for the Unknown: Physical & Cyber Threats on Election Day

Palms1/2

Moderator: Phil Bertolini, Chief Delivery Officer, Government Technology

5:05 pm Eastern

Fireside Chat – MYTHOS Retold: Combatting the Artificially Enhanced Threat Actor

Palms 1/2

Artificial intelligence is reshaping the threat landscape but not always in the ways headlines suggest. In this fireside chat, experts will unpack the reality behind AI-driven capabilities like Mythos and what they truly mean for state, local, tribal, and territorial (SLTT) defenders. While AI can dramatically accelerate vulnerability discovery and compress the timeline from detection to exploitation, most weaknesses and the defenses that mitigate them remain familiar. Panelists will translate emerging risks into actionable strategy, focusing on how SLTT organizations can strengthen resilience through security fundamentals, faster decision-making, and collective defense. Attendees will leave with a clearer understanding of where AI meaningfully changes the game and where it doesn’t, along with practical steps to stay ahead of increasingly automated adversaries without being overwhelmed by the hype.

Moderator: Dan Lohrmann, Senior Fellow, Center for Digital Government

Tony Sager, Senior Vice President and Chief Evangelist, Center for Internet Security

Trent Shoultz, Senior Director, Solutions Consulting, State & Local Government and Education, Palo Alto Networks

5:35 pm Eastern

Adjourn Day 2

Wednesday, June 24

7:30 am Eastern

Registration / Help Desk

Palms Atrium

7:30 am Eastern

Continental Breakfast / Exhibit Hall

Grand Sierra D/E

8:45 am Eastern

Opening Remarks and Day 2 Recap

Palms 1/2

9:00 am Eastern

General Session – State Key Perspectives on the Future of SLTT Cybersecurity – NASCIO Survey Results Briefing

Palms 1/2

9:30 am Eastern

Transition Remarks

Palms 1/2

9:35 am Eastern

General Session – Local Perspectives: How Florida is Ensuring Stable State-Funding for Local Government Cybersecurity Programs

Palms 1/2

Across the nation, local governments face increasingly sophisticated cybersecurity threats without the corresponding resources to defend against them. The State of Florida is breaking new ground by advancing landmark legislation establishing a dedicated statewide appropriation to strengthen cybersecurity programs, tools, and services specifically for counties, cities, school districts, and special districts. This session brings together local government leadership who championed the effort and state legislators who sponsored and shaped the bill; offering attendees rare insights into how policy, advocacy, and operational needs can converge to produce a transformative funding model for local governments.

Moderator: Carlos Kizzee, Senior Vice President, CIS Stakeholder Engagement, Center for Internet Security

The Honorable Rep. Monique Miller, State Representative, Florida House of Representatives

Rob Beach, Director of Information Technology, City of Palm Bay, Florida/President FLGISA

Todd Bayley, Chief Information Officer, Pasco County, State of Florida

10:05 am Eastern

Transition Remarks

Palms 1/2

10:10 am Eastern

General Session – Territorial Perspectives: How Puerto Rico Secures a Multi-Agency Government in a Territorial Operating Model

Palms 1/2

Puerto Rico operates one of the most complex government IT and cybersecurity environments in the United States, serving 3.2 million residents across 120+ agencies, all within the constraints and opportunities of an unincorporated territorial governance model. This session provides a rare, inside look at how the Puerto Rico Office of Management and Budget (OGP) and Puerto Rico Innovation & Technology Service (PRITS) are modernizing cybersecurity, centralizing services, and strengthening resilience across a highly distributed, resource variable government enterprise. Attendees will hear firsthand how Puerto Rico is tackling challenges familiar across the SLTT community: fragmented legacy systems, uneven cybersecurity maturity, procurement hurdles, workforce shortages, and the operational realities of natural disasters. The Commonwealth will share their lessons learned in building shared services, implementing enterprise-level identity and network security programs, driving agency alignment, and maturing governance in a decentralized environment. Participants will leave with actionable practices that any SLTT can adapt regardless of size, geography, or political structure; and a renewed understanding of how unified cybersecurity strategy can thrive even in the most complex environments.

Kateri Gill, Director of Strategic Partnerships, Center for Internet Security (CIS).

10:40 am Eastern

Transition Remarks

Palms 1/2

10:45 am Eastern

General Session – Tribal Perspectives: Securing Sovereign Nations in a Shared Threat Landscape

Palms 1/2

Join the Tribal ISAC for a dynamic panel discussion featuring Tribal Nations professionals as they share firsthand perspectives on navigating cybersecurity and IT management within sovereign jurisdictions. Their perspectives will highlight how tribal governments balance self-determination with the demands of an increasingly complex threat environment while addressing challenges familiar across the SLTT community, including constrained funding, workforce shortages, and rapidly evolving cyber risks. Through a conversation facilitated by the Tribal ISAC, panelists will offer practical insights into how tribes are building resilience, sustaining critical services, and attracting and retaining skilled IT and cybersecurity professionals in support of their nation’s security and resilience. Attendees will gain a deeper understanding of the unique legal, cultural, and operational considerations shaping tribal cybersecurity strategies, alongside actionable ideas that resonate across all sectors. Whether you serve tribal communities or broader SLTT organizations, this session will provide valuable perspectives and peer-driven solutions you can apply immediately.

11:15 am Eastern

Closing Remarks: Next Steps in Our SLTT Cybersecurity Call to Action

Palms 1/2

Carlos Kizzee, Senior Vice President, CIS Stakeholder Engagement, Center for Internet Security

Teri Takai, Chief Programs Officer, Center for Digital Government

11:30 am Eastern

End of Summit

Conference times, agenda, and speakers are subject to change.

Caribe Royale Orlando

8101 World Center Drive
Orlando, FL 32821
(407) 238-8000

Get Directions To
Caribe Royale Orlando

Registration Information / Contact Us

Event Date: June 21 - 24, 2026

Registration is FREE for State, Local, Tribal, and Territorial (SLTT) government organizations.

2026 ISAC Annual Summit - Justification for Attendance

If you represent a Private Sector organization and are interested in Sponsorship Opportunities, please contact Heather Earney.

This event is open to all individuals who meet the eligibility criteria, without regard to race, color, religion, gender, gender identity, age, disability, or any other protected class. We are committed to fostering an inclusive and welcoming environment for all participants.

Contact Information

Need help registering, or have general event questions? Contact:

Brad Loebs
Government Technology
A division of e.Republic
Phone:  (916) 932-1409
E-mail:  bloebs@erepublic.com

Already a sponsor, but need a hand? Reach out to:

Mireya Gaton
Government Technology
A division of e.Republic
Phone: (916) 296-2617
E-Mail: mgaton@erepublic.com

Want to sponsor and stand out? Reach out to explore opportunities!

Heather Earney
Government Technology
A division of e.Republic
Phone: (916) 365-2308
E-mail: heather.earney@erepublic.com

Venue

Caribe Royale Orlando

8101 World Center Drive
Orlando, FL 32821
(407) 238-8000

Show More

Room Block

Standard Room Rate: $229 per night, single or double
   All reservations are subject to a $100 per night incidentals hold at check-in.
Rate Cut-Off Date: Thursday, June  4, 2026
To Make a Reservation:
   Phone: (800) 823-8300 and or (407) 238-8000
   Online: Group Reservation Link (Standard)

Government Room Rate: $140 per night, single or double
   A limited number of rooms are available at this rate.
   All reservations are subject to a $100 per night incidentals hold at check-in.
  In addition to showing photo ID at check-in (i.e., driver’s license, passport), you must provide proof of government employment (i.e., government agency ID badge with photo). 

Rate Cut-Off Date: Thursday, June  4, 2026
To Make a Reservation:
   Phone: (800) 823-8300 and or (407) 238-8000
   Online: Group Reservation Link (Government)

If you experience issues booking online, call the hotel directly for assistance.

Rooms are on a first-come, first-served basis. Please note, once the room block is full, you will need to make other arrangements for your accommodations with the hotel directly or at a nearby hotel.

Map and Directions 

https://www.cariberoyale.com/luxury-resorts-orlando-fl

Event Parking

Complimentary self-parking available around property in front of Convention Center and in front of all towers.

Parking fees subject to change without notice.