Leading the charge in cybersecurity resilience.
The Michigan Cyber Summit returns as a premier gathering of 600+ cybersecurity leaders and innovators from across the public and private sectors. Hosted in partnership with the Michigan Department of Technology, Management and Budget (DTMB), this summit explores the strategies, technologies, and partnerships that are keeping Michigan at the forefront of cyber defense. From leveraging federal resources to navigating emerging threats, attendees gain practical insights to strengthen preparedness, accelerate response, and protect what matters most.
We are excited to host yet another Michigan Cyber Summit. This event brings technology leaders and professionals across public and private sectors, offering a chance to build connections and explore how we can collaborate to protect the people of our state. The event will cover a wide range of topics and include opportunities to network, ensuring that we do our part to make cybersecurity easier for users and harder for hackers.
– Rex Menold, Chief Security Officer, Michigan Department of Technology, Management & Budget
The 2026 Michigan Cyber Summit brings the opportunity for us to connect with cybersecurity professionals on a variety of key topics, including new technologies, emerging threats, and ways to better secure the entire digital ecosystem. Cybersecurity is constantly evolving, and we need to make sure we continue keeping Michigan’s residents and data secure.
– Eric Swanson, Acting Chief Information Officer, Michigan Department of Technology, Management & Budget
This is DTMB’s 15th year hosting the Michigan Cyber Summit, and this year’s event promises to be a great one. Michigan has long been a leader in cybersecurity, and this event brings professionals across the globe together to ensure Michigan’s cyber posture remains strong. Experience a full day of learning, collaboration, and conversation while diving into cybersecurity discussions designed to find ways to better secure our great state.
- Kyle Guerrant, DTMB acting director
Thursday, October 15 |
|
8:00 am Eastern |
Registration and Morning Refreshments in the Exhibit Area |
9:00 am Eastern |
Welcome and Opening RemarksRex Menold, Chief Security Officer, Michigan Department of Technology, Management & Budget, State of Michigan |
9:15 am Eastern |
Keynote – Strengthening the Shield: Insights from the Trenches of National SecurityThere’s no question - public-sector leaders must continue to strengthen their cyber hygiene, foster cross-sector partnerships, and adapt to the evolving threat landscape. Join Rachel Wilson, former NSA cyber operations leader, for an engaging and action-driven keynote that bridges real-world cybersecurity expertise with the challenges of emerging technologies. Drawing on her experience safeguarding critical systems, Rachel explores the heightened risks posed by AI-enabled threats like ransomware, insider attacks, and credential exploitation. This session is a call to action for everyone, from CIOs to frontline technologists, to embrace a proactive and resilient approach to protecting critical assets in the age of AI.
Rachel Wilson, Managing Director and Chief Data Officer, Morgan Stanley Wealth Management and Former NSA Senior Executive |
10:15 am Eastern |
Networking Break in the Exhibit Area |
10:45 am Eastern |
Concurrent SessionsWhen Machines Get Credentials: Securing Agents and Non-Human IdentitiesArtificial intelligence agents, automated services, application programming interfaces, bots, and service accounts are quickly becoming active participants in everyday operations. Unlike traditional users, these identities can act continuously, move at machine speed, and sometimes make decisions without waiting for direct human approval. This session examines how organizations of all sizes can authenticate, authorize, monitor, and contain non-human identities before automation expands beyond their control. Speakers will explore practical safeguards, ownership expectations, access limits, infrastructure requirements, and the warning signs that an agent may be behaving in an unexpected or unsafe way.
The Art of the Cyber Story: Making Incidents UnderstandableEvery cyber incident has a technical story, but the details alone do not always help leaders, employees, customers, or the public understand what happened. This session will examine how organizations can clearly explain the attack path, the technology involved, the decisions made, and the lessons learned without creating unnecessary fear or confusion. Speakers will use real or anonymized examples to show how a strong incident narrative can support leadership decisions, insurance conversations, employee awareness, public communication, and future preparedness. The session will also explore how storytelling can help people recognize that they are part of the security process, not simply the audience for another annual training.
Cybercrime Meets Automation: Responding When Attackers Move FasterAttackers are using automation, synthetic content, scalable phishing, and artificial intelligence-assisted techniques to reach more targets with less effort. For smaller governments, schools, nonprofit organizations, healthcare providers, and businesses, this creates a difficult reality: the threat may be highly automated even when the defense is handled by one person wearing several hats. This session brings together cybersecurity and law enforcement perspectives to examine emerging criminal tactics, practical defensive uses of artificial intelligence, evidence preservation, escalation paths, and when to call for outside assistance. It will also highlight resources available to Michigan organizations when their internal capacity is limited.
Privacy and Security at the Same TableSecurity teams need access to information to identify risk, investigate activity, and protect services. Privacy teams must ensure that information is collected, retained, shared, and used responsibly. Those goals do not have to conflict. This session explores how privacy and security professionals can make decisions together, particularly when evaluating artificial intelligence tools, reviewing retention policies, monitoring activity, conducting investigations, or introducing new data-driven services. The conversation will focus on finding responsible paths forward instead of defaulting to either unrestricted access or an automatic no.
From Alert to Playbook: Practical Artificial Intelligence for Cyber DefendersArtificial intelligence can support cyber operations without replacing human judgment. This practical discussion will look at realistic ways defenders can use it to organize incident information, draft response playbooks, improve documentation, summarize technical findings, accelerate handoffs, and identify gaps in existing procedures. Speakers will also address where human review remains essential, what information should not be entered into external tools, and how to test outputs before they become part of an operational process.
Building a Security Function When Resources Are LimitedA mature cybersecurity program rarely appears all at once. It is built one decision, one relationship, and one control at a time. Designed for small businesses, nonprofit organizations, local governments, schools, and other organizations with limited staff, this session will explain how to establish a practical security function from the ground up. Topics will include identifying the most important services, setting achievable priorities, using shared resources and available contracts, documenting responsibilities, creating a basic incident process, and improving protection without requiring a large security department.
|
11:45 am Eastern |
Lunch |
12:45 pm Eastern |
General Session |
1:45 pm Eastern |
Networking Break in the Exhibit Area |
2:15 pm Eastern |
Concurrent SessionsThe Quantum Deadline: Preparing Your Organization for Post-Quantum SecurityQuantum computing may still feel distant, but the transition to post-quantum cryptography cannot wait until a cryptographically relevant machine arrives. Organizations must first locate where encryption is used, understand which systems and contracts will be affected, and prepare for changes that may increase processing requirements, complexity, and cost. This session will examine how businesses, public agencies, schools, healthcare organizations, and nonprofit organizations can begin building a cryptographic inventory, evaluate vendor readiness, introduce post-quantum requirements into purchasing decisions, and plan around federal transition timelines. The goal is not to predict the exact arrival of quantum computing, but to ensure today’s technology decisions do not become tomorrow’s emergency.
Moderator Dan Lohrmann, Senior Fellow, Government Technology Beyond the Patch Cycle: Reducing Risk Across the Technology Supply ChainPatching is essential, but it is not as simple as applying every update the moment it appears. Organizations must weigh urgency, testing, system availability, vendor trust, operational impact, and the possibility that a compromised update could introduce new risk. This session explores how to build a more disciplined vulnerability and patch management process that works across organizations of different sizes and industries. Speakers will discuss asset visibility, prioritization, exception handling, third-party dependencies, and how to avoid the slow accumulation of unresolved weaknesses that can eventually lead to a major incident.
Ready for Disruption: Building a Resilient OrganizationCyber resilience begins with accepting that even well-protected organizations may experience disruption. The real question is whether critical services can continue, teams can adapt, and recovery can begin without creating additional harm. This session will focus on the operational effects of an incident, including unavailable systems, disrupted communications, vendor dependencies, delayed services, and difficult decisions about what must be restored first. Speakers will share practical lessons from real situations, explain how organizations can develop a resilient mindset, and discuss how exercises, clear responsibilities, and realistic recovery plans help teams respond when conditions do not match the original playbook.
The Cyber Workforce Pivot: Skills That Will Matter NextAutomation and artificial intelligence are changing how cybersecurity work is performed, but they are not eliminating the need for skilled people. Tomorrow’s professionals will need to interpret machine-generated findings, challenge automated recommendations, communicate risk, understand operations, and make sound decisions when technology cannot provide a complete answer. This session will explore how cyber roles are evolving, which skills are gaining importance, and how Michigan employers can continue developing entry-level talent even as routine tasks become automated. The discussion will also address certifications, continuous learning, college recruitment, career transitions, and the shared responsibility to build a workforce prepared for the next generation of security work.
Buying Securely: Funding, Contracts, and the Questions That MatterCybersecurity decisions are often shaped by funding rules, contract language, legal requirements, grant restrictions, and purchasing timelines long before a tool is implemented. This session brings together security, finance, procurement, legal, and grants perspectives to explain how organizations can make stronger purchasing decisions. Panelists will discuss how to define security expectations, evaluate ongoing costs, confirm allowable uses of funding, assess cooperative purchasing options, and require vendors to provide meaningful evidence rather than general assurances. The session will help technical and business teams understand what each side needs to move a secure investment forward.
Government Risk and Authorization Management Program Without the GuessworkCloud security assurance programs can help organizations evaluate risk, but only when leaders understand what a certification or authorization actually covers. This session will provide a practical introduction to the Government Risk and Authorization Management Program, formerly the State Risk and Authorization Management Program. Speakers will explain how the verification model works, what different statuses indicate, and how those designations can support vendor evaluation. The discussion will also examine Michigan’s position, the questions buyers should still ask, and why participation in an assurance program should inform due diligence rather than replace it.
|
3:15 pm Eastern |
Networking Break in the Exhibit Area |
3:45 pm Eastern |
General Session |
4:45 pm Eastern |
Closing Remarks |
5:00 pm Eastern |
Networking Reception in the Exhibit AreaNetwork with your colleagues and discuss technology solutions with the event exhibitors.
|
5:30 pm Eastern |
End of ConferenceConference times, agenda, and speakers are subject to change.
|
46100 Grand River Ave
Novi, MI 48374
(248) 348-5600
Daniel Ayala
Managing Partner
Secratic LLC
Jamie Bennett
Deputy Chief Security Officer
Department of Technology, Management & Budget
State of Michigan
Caleb Buhs
Chief Deputy Director
Department of Technology, Management & Budget
State of Michigan
Nicole Bushong
Senior Executive Management Assistant
Department of Technology, Management & Budget
State of Michigan
Donna Davis
Chief of Staff
CyberPatriot Program
CyberPatriot
Danielle Davis
Senior Executive Management Assistant
Department of Technology, Management & Budget
State of Michigan
Jack Drew
Director
Michigan State Police, Michigan Cyber Command Center
State of Michigan
Tiziana Galezzi
General Manager
Department of Technology, Management & Budget
State of Michigan
Shelley Jeltema
Assistant Professor CIT / Ceospatial Sciences
Lansing Community College
Lansing Community College
Stephanie Jeppesen
State Administrative Manager, Business Services Unit, Cybersecurity and Infrastructure Protection
Department of Technology, Management & Budget
State of Michigan
Michelle McClish
State Assistant Administrator and CIP External Engagement Lead
Department of Technology, Management & Budget
State of Michigan
Rex Menold
Chief Security Officer
Department of Technology, Management & Budget
State of Michigan
Brian Pillar
General Manager
Department of Technology, Management & Budget
State of Michigan
Manny Rosales
Chief Technology Officer
Department of Technology, Management & Budget
State of Michigan
Michael Sauer
Director
Northern Michigan Universiy - UP Cybersecurity Institute
Northern Michigan University - UP
Megan Schrauben
MiSTEM Executive Director
Law Enforcement
State of Michigan
Andrew Sczgielski
Supervisory Special Agent
Cyber Criminal Squad, CY-16
FBI Detroit Cyber Task Force
Eric Swanson
Chief Information Officer (Acting)
Department of Technology, Management & Budget
State of Michigan
Cheryl Wilson
Computer Science Consultant
Department of Education
State of Michigan
Ulrika Zay
State of Michigan
State of Michigan
State of Michigan
Tammie Buehler
Client Director
Trace3
Hugh Carroll
VP, Corporate Affairs
Fortinet
Kerry DeBano
Client Relationship Executive
Deloitte
Miguel Mickey
Account Executive
Microsoft
Registration is open to professionals from the public, private and nonprofit sectors.
Registration Fees:
State of Michigan Employees: Free
Local Government & Non-Profit: $80.00
College Students: $50*
*Students must register with school issued email for verification.
Industry Registration Fee: $95.00**
**Companies providing IT or cybersecurity services in the government technology space are only eligible to attend under an event sponsorship. Private sector attendees must register using their company-issued email for verification.
If you represent a Private Sector organization and are interested in Sponsorship Opportunities, please contact Heather Earney.
This event is open to all individuals who meet the eligibility criteria, without regard to race, color, religion, gender, gender identity, age, disability, or any other protected class. We are committed to fostering an inclusive and welcoming environment for all participants.
Need help registering, or have general event questions? Contact:
Sherri Tidwell
Government Technology
A division of e.Republic
Phone: (916) 932-1382
E-mail: stidwell@erepublic.com
Already a sponsor, but need a hand? Reach out to:
Mireya Gaton
Government Technology
A division of e.Republic
Phone:(916) 296-2617
E-Mail: mgaton@erepublic.com
Want to sponsor and stand out? Reach out to explore opportunities!
Heather Earney
Government Technology
A division of e.Republic
Phone: (916) 365-2308
E-mail: heather.earney@erepublic.com