Loading…
Type: Track 3 clear filter
arrow_back View All Dates
Thursday, April 10
 

11:00am ADT

Psychology of Cyber: The Driving Force Behind Social Engineering Attacks
Thursday April 10, 2025 11:00am - 11:45am ADT
In the cybersecurity industry, people are described as a weak link leading to cyber-attacks, and the most effective way to reduce risk is to implement the latest and greatest technology. But on average, more than 1 in 5, or 20%, malicious phishing emails leak through filters and into people’s inboxes. Coupling this with Verizon’s Data Breach Report findings that 82% of all cyber breaches involve the human element led by social engineered attacks, focusing on motivating people to spot and stop these attacks has never been more relevant.  


It’s time to change the narrative that people are the problem – they’re your organizations’ best asset to spotting and stopping cyber-attacks that evade technology controls.  


To effectively manage risk, you must understand further than the technology implemented when creating successful cybersecurity programs. If humans are the target of attacks, then the best way to stay ahead of social engineering antics is to know how humans are programmed to think.  


Our brains are wired with mental shortcuts that have, over the millennia, helped us conserve resources and implement survival strategies. However, leaning too heavily on these shortcuts creates biases that can lead to flawed decision-making – particularly when it comes to cyber risk. One of the riskiest groups of employees is new hires. They possess preconceived notions like "Beginner's Bubble" (the Dunning-Kruger Effect), anchoring or optimism bias. The solution to lowering that risk is to apply a motivation-based approach supported by proven frameworks in neuroscience, biology, psychology, and behavioral economics. 


This presentation will provide security professionals, leaders, and program administrators with proven frameworks and methodologies like SCARF that they can integrate into awareness programs without additional tools or solutions. We will share what we’ve uncovered in our work with independent cybersecurity researchers and organizations worldwide, provide actionable insights for attendees to bring back to their programs, and challenge ideas to help drive the next evolution of cybersecurity awareness. 
Speakers
avatar for David Shipley

David Shipley

CEO & Co-Founder, Beauceron Security
David Shipley is an award-winning entrepreneur and a recognized global expert in cybersecurity. He regularly speaks at public and private events around the world and appears in national and regional media to address cybersecurity issues.In 2016, David co-founded Beauceron Security... Read More →
Thursday April 10, 2025 11:00am - 11:45am ADT
Argyle Suite 2

1:00pm ADT

What Cyber Teams Can Learn from an NFL Lockeroom
Thursday April 10, 2025 1:00pm - 1:45pm ADT
Teamwork makes the dream work. Unfortunately, for cyber teams, we prioritize technical skill over all else.

As expectations and stakes have grown, we need technical experts to function in a team more then ever. In this session, a cyber leader and former NFL Linebacker, will discuss:
  1. The details of great teamwork and how this could apply to our current cyber culture. 
  2. A poll of 1,500 cyber consultants were polled to get a "current" state of our teams.
  3. Advice for how to build culture in a positive manner.
Speakers
avatar for Sean Tufts

Sean Tufts

Managing Partner, Optiv
Sean Tufts' focus on Critical Infrastructure is born from deep industry experience having spent most of his career in Oil & Gas and Electric utility operations.  He's a former NFL Linebacker for the Carolina Panthers turned Critical Infrastructure security leader.  Post NFL, he... Read More →
Thursday April 10, 2025 1:00pm - 1:45pm ADT
Argyle Suite 2

2:00pm ADT

Shifting Left Sooner: Building Cyber Resilience with the Allies You Didn’t Know You Needed
Thursday April 10, 2025 2:00pm - 2:45pm ADT
Through the journey of a Cyber Curious Business Analyst (BA), you’ll have an introduction to some of the tools, techniques and approaches that can be used to bring visibility to and acceptance of, security & privacy needs, controls and requirements starting at the discovery stage and onward throughout the lifecycle of a project. This talk will discuss some of the benefits of building an alliance with a Cyber Curious BA who already speaks the language of the business and who can help build a security and privacy aware culture from the middle outward in ways you may not have seen before. This presentation will be of interest to C-Suite, Project / Program Leadership, Security & Privacy Leads and their team, students looking to break into the industry, professionals wanting to pivot into the industry from other roles and of course, other Cyber Curious Business Analysts!
Speakers
avatar for Deborah Turner-Chappell

Deborah Turner-Chappell

Senior Cyber Security Business Analyst, C3SA Cyber Security and Audit Corp
As a Cyber Curious Senior Business Analyst (BA) with over 15 yrs of experience on large IT transformation initiatives, Deborah Turner-Chappell attended her first B-Sides conference in 2023 and within six months, she had obtained her CISSP certification and landed a role as a Cyber... Read More →
Thursday April 10, 2025 2:00pm - 2:45pm ADT
Argyle Suite 2

3:00pm ADT

Bake it in, don't bolt it on: Making the case for System Security Engineering (SSE) in the modern Security Context
Thursday April 10, 2025 3:00pm - 3:45pm ADT
Modern project management and delivery practices struggle to find value when it comes to security's role in delivering initiatives for clients and organizations. Too often, we are added too late in the project and design lifecycle where any controls become too costly, or drive schedules too far right, to implement. So how can we fix this?

System Security Engineering (SSE)! By using a system engineering based methodology, and applying sound engineering principles, there is a more effective, cost efficient and schedule friendly approach we can apply that provides better security assurance to our clients and employers.

This presentation will look at the fundamental, guiding principles of the SSE in engineering trustworthy and secure systems. Pulling from the principles of NIST SP 800-160 rev.2, vol.1, this presentation will look at how integration of security within the different lifecycle phases of a design or project can help remedy this age old question plaguing security professionals.

Speakers
avatar for Sean Scrivener

Sean Scrivener

Senior Manager, Security Consultant - IT Risk Advisory Services, Royal Bank of Canada (RBC)
With over 14 years experience in security, Sean has worked across multiple domains within several critical infrastructure sectors. This has included military-industrial, banking and manufacturing; as well as multiple federal, provincial and municipal government departments. These... Read More →
Thursday April 10, 2025 3:00pm - 3:45pm ADT
Argyle Suite 2

4:00pm ADT

No One Pings Alone
Thursday April 10, 2025 4:00pm - 4:45pm ADT
In cybersecurity, we often focus on tools, tactics, and technical skills, but the heart of our field lies in its people. Community and culture are the often-overlooked forces driving innovation, resilience, and collaboration. In this talk,I’ll share how, in my experience, community is key to helping individuals grow and groups thrive, and how cybersecurity’s unique culture of support can help you grow both personally and professionally. Drawing from years of experience in community building, I’ll share lessons learned, practical strategies, and real-world examples to highlight why investing in relationships—both within and beyond the workplace—is an investment in the future of cybersecurity.
Speakers
avatar for Julien Richard

Julien Richard

VP - InfoSec, Lastwall
Julien has been battling cyber threats for over 20 years, currently serving as the VP of InfoSec at Lastwall. He works with a talented team to implement security measures that keep them ready for any challenge.With more certifications than a high-tech Swiss Army knife (OSCP, CISSP... Read More →
Thursday April 10, 2025 4:00pm - 4:45pm ADT
Argyle Suite 2
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -