Loading…
RVAsec 2019 has ended
101 [clear filter]
Wednesday, May 22
 

11:00am EDT

Intro to Infosec and Overview of the 101 Track
Information Security is constantly in the news and making headlines. Which companies are breached? What are the impacts? How will the government respond to adversarial nations? The Internet still behaves much like the wild west – policy decisions are consistently being made and changed based on the structure and sustainability of the web. Organizations large and small are feeling the impacts of having a poor cyber security posture. This talk is perfect for those who are beginners, career changers, or anyone who needs a refresh on the building blocks of  information security. It will discuss how data can be compromised, what those impacts are, and some suggestions of first steps. We will then dive into what vulnerabilities are and what to do about it. Finally, we will go over the things the rest of the 101 track will cover.

Speakers
avatar for Deana Shick

Deana Shick

Member of the Technical Staff, CERT/CC
Deana Shick has been a Member of the Technical Staff at the Software Engineering Institute's CERT Coordination Center (CERT/CC) for 5 years. Deana works on the Threat Ecosystem Analysis team where she researches and analyzes current and emerging threats and vulnerabilities. Prior... Read More →


Wednesday May 22, 2019 11:00am - 11:50am EDT
Senate Chambers, 1st Floor

1:00pm EDT

What is Cyber Insurance? Are you covered?
Attendees of this session will gain a clear perspective of what benefits Cyber Insurance can provide to their existing Cyber Security Program.  Today, Cyber Insurance is no longer a “nice to have” but is a “must have” for every company doing business in a digital world.  But how much coverage do you need and what’s really involved in getting cyber insurance?  People who attend this session will gain a clear perspective on what Cyber Insurance can and can’t provide and where traditional insurance policies fall short.

Speakers
avatar for Lou Botticelli

Lou Botticelli

Director, Markel Corporation
Lou Botticelli serves as Executive Underwriter, Professional Liability for Markel Assurance Risk Management.  Prior to his employment at Markel in 2015 he worked for insurance broker Marsh & McLennan on the Private Equity & Mergers and Acquisitions team performing both advisory and... Read More →
avatar for Kara Owens

Kara Owens

Global Cyber Underwriting Executive, Markel Corporation
Kara Owens is Managing Director, Global Cyber Underwriting Executive at Markel Corporation.  In this role, Kara is responsible for establishing and leading Markel’s cyber market strategy and working with cyber underwriters across the Company to achieve growth and profit initiatives... Read More →


Wednesday May 22, 2019 1:00pm - 1:50pm EDT
Senate Chambers, 1st Floor

2:00pm EDT

Vulnerability Assessments and Penetration Tests
A quick look at the marketing FUD of 'Automated Pentests' and a high level look at the various technical pieces that delineate the difference between scanning and the real-world attacks used in pentesting. Touches on technical and business processes to ensure that your organization is spending its resources in the right places.

Speakers
avatar for David Sullivan

David Sullivan

Penetration Tester, CampusGuard
Offensive Security Services at CampusGuard. Star Wars, Hockey, Emo Music, Mental Health Awareness and Swahili enthusiast.



Wednesday May 22, 2019 2:00pm - 2:50pm EDT
Senate Chambers, 1st Floor

3:00pm EDT

Social Engineering, Physical Security & USB Attacks
You may think that USB drops are a thing of the past but that’s certainly not the case. Sometimes breaching a target with a massive defense budget is as simple as a $10 USB dropped at the right location. In this talk I’ll share how an organization could start their own USB drop assessment by detailing the history, common research, tools of the trade, tactics, and mindset of a potential attacker. 

Speakers
avatar for Brad Thornton

Brad Thornton

Senior Penetration Tester, ICSynergy
I’m currently a Senior Penetration Tester with a consultant firm. I participate in multiple CTF events, belong to several security focused organizations, and attend numerous conferences on the subject. Historically, I’ve served in various roles in relation to privilege identity... Read More →


Wednesday May 22, 2019 3:00pm - 3:50pm EDT
Senate Chambers, 1st Floor
 
Thursday, May 23
 

10:10am EDT

Risk Assessment - The Heart of Risk-based Security
Everywhere you look today you see “risk-based security” being touted as the next big thing. Knowing your assets, understanding the threats and vulnerabilities that may impact those assets, and calculating a risk score in order to prioritize mitigation actions, should be every organization’s goal. Risk-based security is not accomplished by performing a risk assessment exercise once a year. It requires a continuous assessment of your organization’s risk posture. Too many businesses think that completing a risk assessment is a difficult and complicated process that requires expensive software and can only be done by third party consultants. As a result, risk assessments are not conducted or conducted once and stored away to show the auditors. Risk assessments are essential in order to assure that the expenditures involved in mitigating vulnerabilities and the implementation of security controls are commensurate with the risks facing the organization. Attend this interactive session to explore the definitions, methodologies, structure and the expected results of a proper risk assessment that can be produced by your organization.


Speakers
avatar for Barry Kouns

Barry Kouns

Chairman & CFO, Risk Based Security Inc.
Barry Kouns is CEO at Risk Based Security, a vulnerability intelligence, organizational ratings,and on-demand security solutions firm. Barry's experience includes information security consulting, risk assessment and quality management. Barry has full knowledge of GLBA, FFIEC, HIPAA... Read More →


Thursday May 23, 2019 10:10am - 11:00am EDT
Senate Chambers, 1st Floor

11:10am EDT

Network Security 101
Think the network is a black box that magically gets your cat videos to you? This talk explains how it works at the fundamental levels.

Speakers
avatar for Rick Lull

Rick Lull

Sr Security Solution Architect, InterVision Systems
Lifelong geek turned security consultant after stops as a desktop tech, server bubba, and network jockey. Rick is a healthcare IT survivor, and is now playing Horatio on the bridge for hire with a national technology consulting company, advising clients on security strategy and operations... Read More →


Thursday May 23, 2019 11:10am - 12:00pm EDT
Senate Chambers, 1st Floor

1:00pm EDT

Being Secure Doesn’t Mean You Are Managing Risk
Charles will explain the beginner concepts of identifying, quantifying, qualifying, and decisioning risks with a focus on how this differs from the practice of cybersecurity.

Speakers
avatar for Charles Tango

Charles Tango

CISO, Altria
Charles is the Chief Information Security Officer at Altria, the parent company of producers of superior branded tobacco and wine products such as Philip Morris USA and Ste. Michelle Wine Estates.Charles also represents Altria on the board of the Richmond Technology Council, which... Read More →


Thursday May 23, 2019 1:00pm - 1:50pm EDT
Senate Chambers, 1st Floor

2:00pm EDT

101 Panel
A recap of the 101 track and Q&A with some of our speakers and RVAsec experts.
Moderated by Deana Shick.

Speakers
avatar for Deana Shick

Deana Shick

Member of the Technical Staff, CERT/CC
Deana Shick has been a Member of the Technical Staff at the Software Engineering Institute's CERT Coordination Center (CERT/CC) for 5 years. Deana works on the Threat Ecosystem Analysis team where she researches and analyzes current and emerging threats and vulnerabilities. Prior... Read More →


Thursday May 23, 2019 2:00pm - 2:50pm EDT
Senate Chambers, 1st Floor
 
Filter sessions
Apply filters to sessions.