Michigan Cyber Summit 2026 Banner

Overview

Leading the charge in cybersecurity resilience.

The Michigan Cyber Summit returns as a premier gathering of 600+ cybersecurity leaders and innovators from across the public and private sectors. Hosted in partnership with the Michigan Department of Technology, Management and Budget (DTMB), this summit explores the strategies, technologies, and partnerships that are keeping Michigan at the forefront of cyber defense. From leveraging federal resources to navigating emerging threats, attendees gain practical insights to strengthen preparedness, accelerate response, and protect what matters most.

 

A message from our Keynote Speaker

We are excited to host yet another Michigan Cyber Summit. This event brings technology leaders and professionals across public and private sectors, offering a chance to build connections and explore how we can collaborate to protect the people of our state. The event will cover a wide range of topics and include opportunities to network, ensuring that we do our part to make cybersecurity easier for users and harder for hackers. 

 Rex Menold, Chief Security Officer, Michigan Department of Technology, Management & Budget

The 2026 Michigan Cyber Summit brings the opportunity for us to connect with cybersecurity professionals on a variety of key topics, including new technologies, emerging threats, and ways to better secure the entire digital ecosystem. Cybersecurity is constantly evolving, and we need to make sure we continue keeping Michigan’s residents and data secure. 

 Eric Swanson, Acting Chief Information Officer, Michigan Department of Technology, Management & Budget

This is DTMB’s 15th year hosting the Michigan Cyber Summit, and this year’s event promises to be a great one. Michigan has long been a leader in cybersecurity, and this event brings professionals across the globe together to ensure Michigan’s cyber posture remains strong. Experience a full day of learning, collaboration, and conversation while diving into cybersecurity discussions designed to find ways to better secure our great state.

Kyle Guerrant, DTMB acting director

Speakers

Rachel Wilson

Rachel Wilson

Managing Director and Chief Data Officer, Morgan Stanley Wealth Management and Former NSA Senior Executive

Rachel Wilson is a Managing Director of Morgan Stanley Wealth Management and Chief Data Officer. Her team of security professionals is responsible for protecting all sensitive client data from any type of theft, loss or compromise. She also oversees the resilience of Wealth Management’s critical infrastructure and the continuity of core business processes at times of turbulence. Additionally, Rachel supervises the client fraud risk program, which institutes technical and business controls to help prevent unauthorized access to or misuse of client funds. As a senior subject matter expert, Rachel regularly advises Wealth Management leadership and clients on the cyber threat landscape and mitigation strategies.
From 2017-2020, Rachel served as the first-ever Head of Wealth Management Cybersecurity. In this role, Rachel advised senior business and technology leaders on a range of cybersecurity issues, including secure code development standards, secure network architecture, vendor relationships, advanced persistent threat (APT) detection and mobile security. Her team drove innovation for new cybersecurity and authentication technology in the pursuit of protecting the integrity and confidentiality of firm and client data. In 2019, Rachel was recognized by Morgan Stanley Wealth Management as part of the MAKERS Class, a program that honors women who serve as groundbreakers, innovators and advocates. She was also named one of the Top Women in WealthTech 2020 by ThinkAdvisor.
Prior to joining the firm in 2017, Rachel spent 15 years at the National Security Agency (NSA), where she held several key senior executive-level leadership positions. Between 2008 and 2010, she ran NSA’s counterterrorism operations and led a global enterprise in detecting and disrupting terrorist plotting against the U.S. and its allies. Between 2010 and 2012, Rachel served as NSA’s Chief of Operations in the U.K., working out of the U.S. Embassy in London. In this role, she worked with U.K. intelligence services to counter terrorist and cyber threats to the 2012 Olympics. Returning to the U.S. in 2012, Rachel spent nearly five years leading NSA’s cyber exploitation operations as the Deputy and then Chief of the Remote Operations Center within NSA’s Tailored Access Operations. In this capacity, she led the planning and execution of thousands of cyber exploitation operations against a wide array of foreign intelligence, military and cyber targets, and served as the committing official for many of NSA’s highest risk and most important intelligence gathering activities.
More

Agenda

Thursday, October 15

8:00 am Eastern

Registration and Morning Refreshments in the Exhibit Area

9:00 am Eastern

Welcome and Opening Remarks

Rex Menold, Chief Security Officer, Michigan Department of Technology, Management & Budget, State of Michigan

9:15 am Eastern

Keynote – Strengthening the Shield: Insights from the Trenches of National Security

There’s no question - public-sector leaders must continue to strengthen their cyber hygiene, foster cross-sector partnerships, and adapt to the evolving threat landscape. Join Rachel Wilson, former NSA cyber operations leader, for an engaging and action-driven keynote that bridges real-world cybersecurity expertise with the challenges of emerging technologies. Drawing on her experience safeguarding critical systems, Rachel explores the heightened risks posed by AI-enabled threats like ransomware, insider attacks, and credential exploitation. This session is a call to action for everyone, from CIOs to frontline technologists, to embrace a proactive and resilient approach to protecting critical assets in the age of AI.

Rachel Wilson, Managing Director and Chief Data Officer, Morgan Stanley Wealth Management and Former NSA Senior Executive

10:15 am Eastern

Networking Break in the Exhibit Area

10:45 am Eastern

Concurrent Sessions

When Machines Get Credentials: Securing Agents and Non-Human Identities

Artificial intelligence agents, automated services, application programming interfaces, bots, and service accounts are quickly becoming active participants in everyday operations. Unlike traditional users, these identities can act continuously, move at machine speed, and sometimes make decisions without waiting for direct human approval. This session examines how organizations of all sizes can authenticate, authorize, monitor, and contain non-human identities before automation expands beyond their control. Speakers will explore practical safeguards, ownership expectations, access limits, infrastructure requirements, and the warning signs that an agent may be behaving in an unexpected or unsafe way.

The Art of the Cyber Story: Making Incidents Understandable

Every cyber incident has a technical story, but the details alone do not always help leaders, employees, customers, or the public understand what happened. This session will examine how organizations can clearly explain the attack path, the technology involved, the decisions made, and the lessons learned without creating unnecessary fear or confusion. Speakers will use real or anonymized examples to show how a strong incident narrative can support leadership decisions, insurance conversations, employee awareness, public communication, and future preparedness. The session will also explore how storytelling can help people recognize that they are part of the security process, not simply the audience for another annual training.

Cybercrime Meets Automation: Responding When Attackers Move Faster

Attackers are using automation, synthetic content, scalable phishing, and artificial intelligence-assisted techniques to reach more targets with less effort. For smaller governments, schools, nonprofit organizations, healthcare providers, and businesses, this creates a difficult reality: the threat may be highly automated even when the defense is handled by one person wearing several hats. This session brings together cybersecurity and law enforcement perspectives to examine emerging criminal tactics, practical defensive uses of artificial intelligence, evidence preservation, escalation paths, and when to call for outside assistance. It will also highlight resources available to Michigan organizations when their internal capacity is limited.

Privacy and Security at the Same Table

Security teams need access to information to identify risk, investigate activity, and protect services. Privacy teams must ensure that information is collected, retained, shared, and used responsibly. Those goals do not have to conflict. This session explores how privacy and security professionals can make decisions together, particularly when evaluating artificial intelligence tools, reviewing retention policies, monitoring activity, conducting investigations, or introducing new data-driven services. The conversation will focus on finding responsible paths forward instead of defaulting to either unrestricted access or an automatic no.

From Alert to Playbook: Practical Artificial Intelligence for Cyber Defenders

Artificial intelligence can support cyber operations without replacing human judgment. This practical discussion will look at realistic ways defenders can use it to organize incident information, draft response playbooks, improve documentation, summarize technical findings, accelerate handoffs, and identify gaps in existing procedures. Speakers will also address where human review remains essential, what information should not be entered into external tools, and how to test outputs before they become part of an operational process.

Building a Security Function When Resources Are Limited

A mature cybersecurity program rarely appears all at once. It is built one decision, one relationship, and one control at a time. Designed for small businesses, nonprofit organizations, local governments, schools, and other organizations with limited staff, this session will explain how to establish a practical security function from the ground up. Topics will include identifying the most important services, setting achievable priorities, using shared resources and available contracts, documenting responsibilities, creating a basic incident process, and improving protection without requiring a large security department.

11:45 am Eastern

Lunch

12:45 pm Eastern

General Session

1:45 pm Eastern

Networking Break in the Exhibit Area

2:15 pm Eastern

Concurrent Sessions

The Quantum Deadline: Preparing Your Organization for Post-Quantum Security

Quantum computing may still feel distant, but the transition to post-quantum cryptography cannot wait until a cryptographically relevant machine arrives. Organizations must first locate where encryption is used, understand which systems and contracts will be affected, and prepare for changes that may increase processing requirements, complexity, and cost. This session will examine how businesses, public agencies, schools, healthcare organizations, and nonprofit organizations can begin building a cryptographic inventory, evaluate vendor readiness, introduce post-quantum requirements into purchasing decisions, and plan around federal transition timelines. The goal is not to predict the exact arrival of quantum computing, but to ensure today’s technology decisions do not become tomorrow’s emergency.

Moderator Dan Lohrmann, Senior Fellow, Government Technology

Beyond the Patch Cycle: Reducing Risk Across the Technology Supply Chain

Patching is essential, but it is not as simple as applying every update the moment it appears. Organizations must weigh urgency, testing, system availability, vendor trust, operational impact, and the possibility that a compromised update could introduce new risk. This session explores how to build a more disciplined vulnerability and patch management process that works across organizations of different sizes and industries. Speakers will discuss asset visibility, prioritization, exception handling, third-party dependencies, and how to avoid the slow accumulation of unresolved weaknesses that can eventually lead to a major incident.

Ready for Disruption: Building a Resilient Organization

Cyber resilience begins with accepting that even well-protected organizations may experience disruption. The real question is whether critical services can continue, teams can adapt, and recovery can begin without creating additional harm. This session will focus on the operational effects of an incident, including unavailable systems, disrupted communications, vendor dependencies, delayed services, and difficult decisions about what must be restored first. Speakers will share practical lessons from real situations, explain how organizations can develop a resilient mindset, and discuss how exercises, clear responsibilities, and realistic recovery plans help teams respond when conditions do not match the original playbook.

The Cyber Workforce Pivot: Skills That Will Matter Next

Automation and artificial intelligence are changing how cybersecurity work is performed, but they are not eliminating the need for skilled people. Tomorrow’s professionals will need to interpret machine-generated findings, challenge automated recommendations, communicate risk, understand operations, and make sound decisions when technology cannot provide a complete answer. This session will explore how cyber roles are evolving, which skills are gaining importance, and how Michigan employers can continue developing entry-level talent even as routine tasks become automated. The discussion will also address certifications, continuous learning, college recruitment, career transitions, and the shared responsibility to build a workforce prepared for the next generation of security work.

Buying Securely: Funding, Contracts, and the Questions That Matter

Cybersecurity decisions are often shaped by funding rules, contract language, legal requirements, grant restrictions, and purchasing timelines long before a tool is implemented. This session brings together security, finance, procurement, legal, and grants perspectives to explain how organizations can make stronger purchasing decisions. Panelists will discuss how to define security expectations, evaluate ongoing costs, confirm allowable uses of funding, assess cooperative purchasing options, and require vendors to provide meaningful evidence rather than general assurances. The session will help technical and business teams understand what each side needs to move a secure investment forward.

Government Risk and Authorization Management Program Without the Guesswork

Cloud security assurance programs can help organizations evaluate risk, but only when leaders understand what a certification or authorization actually covers. This session will provide a practical introduction to the Government Risk and Authorization Management Program, formerly the State Risk and Authorization Management Program. Speakers will explain how the verification model works, what different statuses indicate, and how those designations can support vendor evaluation. The discussion will also examine Michigan’s position, the questions buyers should still ask, and why participation in an assurance program should inform due diligence rather than replace it.

3:15 pm Eastern

Networking Break in the Exhibit Area

3:45 pm Eastern

General Session

4:45 pm Eastern

Closing Remarks

5:00 pm Eastern

Networking Reception in the Exhibit Area

Network with your colleagues and discuss technology solutions with the event exhibitors.

5:30 pm Eastern

End of Conference

Conference times, agenda, and speakers are subject to change.

Vibe Credit Union Showplace

46100 Grand River Ave
Novi, MI 48374
(248) 348-5600

Get Directions To
Vibe Credit Union Showplace

Advisory Board

Government Representatives

Daniel Ayala
Managing Partner
Secratic LLC

Jamie Bennett
Deputy Chief Security Officer
Department of Technology, Management & Budget
State of Michigan

Caleb Buhs
Chief Deputy Director
Department of Technology, Management & Budget
State of Michigan

Nicole Bushong
Senior Executive Management Assistant
Department of Technology, Management & Budget
State of Michigan

Donna Davis
Chief of Staff
CyberPatriot Program
CyberPatriot

Danielle Davis
Senior Executive Management Assistant
Department of Technology, Management & Budget
State of Michigan

Jack Drew
Director
Michigan State Police, Michigan Cyber Command Center
State of Michigan

Tiziana Galezzi
General Manager
Department of Technology, Management & Budget
State of Michigan

Shelley Jeltema
Assistant Professor CIT / Ceospatial Sciences
Lansing Community College
Lansing Community College

Stephanie Jeppesen
State Administrative Manager, Business Services Unit, Cybersecurity and Infrastructure Protection
Department of Technology, Management & Budget
State of Michigan

Michelle McClish
State Assistant Administrator and CIP External Engagement Lead
Department of Technology, Management & Budget
State of Michigan

Rex Menold
Chief Security Officer
Department of Technology, Management & Budget
State of Michigan

Brian Pillar
General Manager
Department of Technology, Management & Budget
State of Michigan

Manny Rosales
Chief Technology Officer
Department of Technology, Management & Budget
State of Michigan

Michael Sauer
Director
Northern Michigan Universiy - UP Cybersecurity Institute
Northern Michigan University - UP

Megan Schrauben
MiSTEM Executive Director
Law Enforcement
State of Michigan

Andrew Sczgielski
Supervisory Special Agent
Cyber Criminal Squad, CY-16
FBI Detroit Cyber Task Force

Eric Swanson
Chief Information Officer (Acting)
Department of Technology, Management & Budget
State of Michigan

Cheryl Wilson
Computer Science Consultant
Department of Education
State of Michigan

Ulrika Zay
State of Michigan
State of Michigan
State of Michigan

Industry Representatives

Tammie Buehler
Client Director
Trace3

Hugh Carroll
VP, Corporate Affairs
Fortinet

Kerry DeBano
Client Relationship Executive
Deloitte

Miguel Mickey
Account Executive
Microsoft

Registration Information / Contact Us

Event Date: October 15, 2026

Registration is open to professionals from the public, private and nonprofit sectors.

Registration Fees:

State of Michigan Employees: Free
Local Government & Non-Profit: $80.00
College Students: $50*

*Students must register with school issued email for verification.

Industry Registration Fee: $95.00**

**Companies providing IT or cybersecurity services in the government technology space are only eligible to attend under an event sponsorship. Private sector attendees must register using their company-issued email for verification. 

If you represent a Private Sector organization and are interested in Sponsorship Opportunities, please contact Heather Earney.

This event is open to all individuals who meet the eligibility criteria, without regard to race, color, religion, gender, gender identity, age, disability, or any other protected class. We are committed to fostering an inclusive and welcoming environment for all participants.

Contact Information

Need help registering, or have general event questions? Contact:

Sherri Tidwell
Government Technology
A division of e.Republic
Phone: (916) 932-1382
E-mail: stidwell@erepublic.com

Already a sponsor, but need a hand? Reach out to:

Mireya Gaton
Government Technology
A division of e.Republic
Phone:(916) 296-2617
E-Mail: mgaton@erepublic.com

Want to sponsor and stand out? Reach out to explore opportunities!

Heather Earney
Government Technology
A division of e.Republic
Phone: (916) 365-2308
E-mail: heather.earney@erepublic.com

Venue

Vibe Credit Union Showplace

46100 Grand River Ave
Novi, MI 48374
(248) 348-5600

Show Hotel & Parking

Room Block 

There is no room block established for this event. 

Map and Directions 

https://www.suburbancollectionshowplace.com/directions-parking

Event Parking 

Self-parking: Free self-parking available. 
Instructions: To park, enter at the traffic light off Grand River Ave and stay to the left at the fork in the road and follow past the Diamond circle driveway and the parking lot is on the left. Enter the building through the “Diamond Entrance”.