CISO Canada Summit | February 26-28, 2017 | The Ritz-Carlton, Montreal - Montreal, QC, Canada

↓ Agenda Key

Keynote Presentation

Visionary speaker presents to entire audience on key issues, challenges and business opportunities

Keynote Presentations give attending delegates the opportunity to hear from leading voices in the industry. These presentations feature relevant topics and issues aligned with the speaker's experience and expertise, selected by the speaker in concert with the summit's Content Committee." title="Keynote Presentations give attending delegates the opportunity to hear from leading voices in the industry. These presentations feature relevant topics and issues aligned with the speaker's experience and expertise, selected by the speaker in concert with the summit's Content Committee.

Executive Visions

Panel moderated by Master of Ceremonies and headed by four executives discussing critical business topics

Executive Visions sessions are panel discussions that enable in-depth exchanges on critical business topics. Led by a moderator, these sessions encourage attending executives to address industry challenges and gain insight through interaction with expert panel members." title="Executive Visions sessions are panel discussions that enable in-depth exchanges on critical business topics. Led by a moderator, these sessions encourage attending executives to address industry challenges and gain insight through interaction with expert panel members.

Thought Leadership

Solution provider-led session giving high-level overview of opportunities

Led by an executive from the vendor community, Thought Leadership sessions provide comprehensive overviews of current business concerns, offering strategies and solutions for success. This is a unique opportunity to access the perspective of a leading member of the vendor community." title="Led by an executive from the vendor community, Thought Leadership sessions provide comprehensive overviews of current business concerns, offering strategies and solutions for success. This is a unique opportunity to access the perspective of a leading member of the vendor community.

Think Tank

End user-led session in boardroom style, focusing on best practices

Think Tanks are interactive sessions that place delegates in lively discussion and debate. Sessions admit only 15-20 participants at a time to ensure an intimate environment in which delegates can engage each other and have their voices heard." title="Think Tanks are interactive sessions that place delegates in lively discussion and debate. Sessions admit only 15-20 participants at a time to ensure an intimate environment in which delegates can engage each other and have their voices heard.

Roundtable

Interactive session led by a moderator, focused on industry issue

Led by an industry analyst, expert or a member of the vendor community, Roundtables are open-forum sessions with strategic guidance. Attending delegates gather to collaborate on common issues and challenges within a format that allows them to get things done." title="Led by an industry analyst, expert or a member of the vendor community, Roundtables are open-forum sessions with strategic guidance. Attending delegates gather to collaborate on common issues and challenges within a format that allows them to get things done.

Case Study

Overview of recent project successes and failures

Case Studies allow attending executives to hear compelling stories about implementations and projects, emphasizing best practices and lessons learned. Presentations are immediately followed by Q&A sessions." title="Case Studies allow attending executives to hear compelling stories about implementations and projects, emphasizing best practices and lessons learned. Presentations are immediately followed by Q&A sessions.

Focus Group

Discussion of business drivers within a particular industry area

Focus Groups allow executives to discuss business drivers within particular industry areas. These sessions allow attendees to isolate specific issues and work through them. Presentations last 15-20 minutes and are followed by Q&A sessions." title="Focus Groups allow executives to discuss business drivers within particular industry areas. These sessions allow attendees to isolate specific issues and work through them. Presentations last 15-20 minutes and are followed by Q&A sessions.

Analyst Q&A Session

Moderator-led coverage of the latest industry research

Q&A sessions cover the latest industry research, allowing attendees to gain insight on topics of interest through questions directed to a leading industry analyst." title="Q&A sessions cover the latest industry research, allowing attendees to gain insight on topics of interest through questions directed to a leading industry analyst.

Vendor Showcase

Several brief, pointed overviews of the newest solutions and services

Taking the form of three 10-minute elevator pitches by attending vendors, these sessions provide a concise and pointed overview of the latest solutions and services aligned with attendee needs and preferences." title="Taking the form of three 10-minute elevator pitches by attending vendors, these sessions provide a concise and pointed overview of the latest solutions and services aligned with attendee needs and preferences.

Executive Exchange

Pre-determined, one-on-one interaction revolving around solutions of interest

Executive Exchanges offer one-on-one interaction between executives and vendors. This is an opportunity for both parties to make key business contacts, ask direct questions and get the answers they need. Session content is prearranged and based on mutual interest." title="Executive Exchanges offer one-on-one interaction between executives and vendors. This is an opportunity for both parties to make key business contacts, ask direct questions and get the answers they need. Session content is prearranged and based on mutual interest.

Open Forum Luncheon

Informal discussions on pre-determined topics

Led by a moderator, Open Forum Luncheons offer attendees informal, yet focused discussions on current industry topics and trends over lunch." title="Led by a moderator, Open Forum Luncheons offer attendees informal, yet focused discussions on current industry topics and trends over lunch.

Networking Session

Unique activities at once relaxing, enjoyable and productive

Networking opportunities take various unique forms, merging enjoyable and relaxing activities with an environment conducive to in-depth conversation. These gatherings allow attendees to wind down between sessions and one-on-one meetings, while still furthering discussions and being productive." title="Networking opportunities take various unique forms, merging enjoyable and relaxing activities with an environment conducive to in-depth conversation. These gatherings allow attendees to wind down between sessions and one-on-one meetings, while still furthering discussions and being productive.

 

Sunday, February 26, 2017 - CISO Canada Summit

3:00 pm - 4:30 pm

Registration & Greeting

 

4:30 pm - 6:00 pm

Exclusive CXO Think Tank

 

6:00 pm - 7:00 pm

Networking Cocktail Reception

 

7:00 pm - 8:30 pm

Networking Dinner

 

8:30 pm - 10:00 pm

After Dinner Networking

 

Monday, February 27, 2017 - CISO Canada Summit

7:00 am - 7:55 am

Registration and Networking Breakfast

 

8:00 am - 8:10 am

Welcome Address and Opening Remarks

 

8:10 am - 8:40 am

Keynote Presentation

The Future of the CIO in the Coming Digital Economy

As more businesses undergo a digital transformation, and as those digital transformations become more ingrained into organizational culture, Digital becomes not something unique and different from the business, but a core component of every aspect of the business. As this shift occurs, IT itself faces the very real possibility of no longer being something unique from the business, but instead a component of every aspect of the business. In this world, what role then exists for the CIO? Two clear paths are presenting themselves " one leads to a focus on infrastructure and integration, to keeping the lights on for the digital innovators, while the other leads to information and innovation itself. Knowing what path to choose, how to choose it, and how to see it through will be one of the greatest challenges CIOs of this era will face.

Takeaways:

  • Change is, if not already hear, certainly coming and CIOs that don't prepare for the change may not like the results when it arrives
  • Digital transformation is all about connecting enterprise system to information technology to drive productivity and performance improvements
  • Be prepared to tackle the tasks that no-one wants to do, but everyone needs done; establish relevance to cultivate importance
 

8:45 am - 9:15 am

Keynote Presentation

Security's Place in Enterprise Risk Management

While Information Security has existed for decades, Enterprise Risk Management (ERM), as a formal and holistic practice, is much newer yet already has taken pre-eminence over its forebear. What is the CISO, who in many ways has toiled in invisibility, infamy, or ignominy to do when faced with the issue of being supplanted by the Chief Risk Officer, just as enterprise demand for and focus on security has reached all-time heights? Savvy CISOs will recognize this new, broader need for holistic visibility into, and management of, overall enterprise risk and will position themselves for success by looking beyond traditional information security boundaries and engaging business partners around all enterprise risk.

Takeaways:

  • Just because information security is an aspect of enterprise risk doesn't mean that the CISO needs to take a back seat position
  • Enterprise risk is defined by the business but needs to be quantified by an expert; CISOs bring risk quantification expertise to the table
  • The end goal is not about fiefdoms and ownership, it is about improving enterprise value and success; maintaining focus is essential
 

9:20 am - 9:45 am

Executive Exchange

 

Thought Leadership

HP Presents: The Mindset of Hacker

As Sun Tzu famously said, to know your enemy, you must become your enemy. This session is a unique opportunity to do just that. Join Canada's most infamous reformed hacker, Michael MafiaBoy Calce, as he sheds light on the biggest threat to today's CISO. Michael's presentation will provide a unique perspective on hackers' motives and tactics by highlighting the more unique methods and entry points targeted by today's cyber criminals.

Sponsored by:

HP Inc. View details

 
 
 

9:50 am - 10:15 am

Executive Exchange

 

Roundtable

Capacity Management in a non-Physical World

Whether it is from server virtualization, or private cloud delivery, everyone thinks that non-physical infrastructure delivery eliminates the needs for capacity planning, rendering the practice obsolete and irrelevant. The fact of the matter is that nothing could be further from the truth for multiple reasons. Firstly the needs of the physical infrastructure that hosts the virtual/cloud deployment still needs to be carefully managed, and secondly the risks of virtual server sprawl / cloud infrastructure over-provisioning are all too real and more likely than equivalent issues in the physical world. Join our panel of experts as we investigate the implications of capacity planning for non-physical infrastructure, explore collective experiences, and dive into lessons learned to determine best practices.

Takeaways:

  • Just because you use infrastructure in a non-physical way doesn't mean it only exists in that format; physical infrastructure still exists
  • Capacity planning of the underlying physical infrastructure is perhaps even more important in a virtual/cloud world because one misstep can now affect significantly more applications and end users
  • Virtual/cloud capacity isn't endless and so capacity planning of the physical layer is equally as important as capacity planning of the physical layer

Roundtable

Best-of-Breed or Consolidated: Principles in Security Architecture Design

When it comes to implementing network security infrastructure there are two schools of thought: use best-of-breed point solutions, or go with all round consolidated platforms. Pros and cons abound for either approach revolving around varying levels of protection, integration, and administrative overhead but the increasing complexity of current security infrastructure is showing a winning approach. Even though consolidated solutions may offer greater benefits in the long run, no one exists in a green-field situation when it comes to network and infrastructure security so careful planning is required to ensure the necessary protection.

Takeaways:

  • The management burden of best-of-breed outweighs performance benefits
  • Consolidated platforms can lead to feature overlap and unnecessary cost
  • Planning is required to maximize coverage but minimize effort and spend

Roundtable

Big Data Analytics - A Fundamental Shift

We have moved from an information-poor to an information-rich society. Practically unlimited availability of data, computing, networking, and socio-mobile connectivity are fundamentally altering our world. In particular, they are enabling businesses to become more effective and efficient by using big data analytics - collecting all relevant data and automating their processing to drive decision-making. This represents a fundamental shift from traditional business analytics where limited amount of structured data is batch-processed to produce standard Business Intelligence reports. We will assess the current state of big data analytics, technology and business trends, and their enormous implications to the future of all businesses.

Takeaways:

  • How Big Data analytics is different from traditional business analytics
  • What businesses are getting out of big data analytics
  • Why Big Data analytics will become critical to every business
 

10:20 am - 10:30 am

Morning Networking Coffee Break

 

10:35 am - 11:00 am

Executive Exchange

 

Think Tank

Bridging the Talent Gap: Building the Team of Tomorrow

There is no escaping the fact that the demands on the IT department are changing. Those changes are necessitating changes in the IT department itself and nowhere is this being felt more than in the roles and responsibilities of the IT staff themselves. Complicating this transition is the fact that every IT department is undergoing to change at roughly the same time making the personnel with the requisite skillsets extremely hard to find, and perhaps even harder to retain. Savvy CIOs need to quickly identify which are the hot skills they most urgently require and then build a strategy that allows them to build (train), borrow (outsource), or buy (hire) the right people with the right capability at the right time.

Takeaways:

  • Commit to a talent-first organization which recognizes and rewards the most important asset you have " your people
  • Identify the skills most urgently in need and prioritize their acquisition
  • Determine which acquisition methods needs to be used for which skill to maximize impact and return on investment

Think Tank

Building Dynamic Security Teams

There's no other way to say it than bluntly; Information Security is a white-hot field within Information Technology as a whole " over the last dozen years it has gone from after-thought, to scapegoat, to critical enterprise success factor. As a result, the need for capable and qualified Information Security specialists, whether front-line Analysts, mid-level Managers, or top level CISOs is at an all time high, but personnel and skills availability is sinking to an all-time (at least in terms of supply and demand ratio) low. There simply isn't enough expertise in existence to go around, or enough education occurring to create it. In this environment, senior Information Security leaders have to get creative in their pursuit of the people, performance, and passion necessary to address this capability shortfall.

Takeaways:

  • Learn how to build grass-roots programs that cultivate a farm full of potential security experts through internal and collaborative programs
  • Find out how to leverage key organizational traits to generate buzz and interest where none existed before
  • Understand the relevance of certs vs. experience and how to evaluate and validate the value of candidates

Think Tank

Defining Data Governance

Data volume, data variety, and data velocity have all grown exponentially over the last few years, the so-called Big Data explosion. And while this increased organizational focus on data, the information it contains, and the insights that can be gleaned from it promises tremendous opportunity, that opportunity isn't achieved without overcoming significant challenges. Whether it be the increased need for better data quality (an issue unresolved from the small data days), more efficient and effective data management, answering questions around data ownership vs. stewardship, or even increased regulatory pressure as a result of data security and data privacy, this increased focus on data has created an increased need for Data Governance. Join our panelists as we discuss the thorny issue of Data Governance: what it is, how it works, why you need it, and who should be responsible for it.

Takeaways:

  • Data management issues have existed as long as data has existed but the Big Data boom has increased these challenges exponentially
  • Resolving data management issues requires a strong data governance program to make rules, resolve issues, and enforce compliance
  • Determining what to about data governance is the easy part, determining how and by whom it should be done will be the real challenge facing IT
 

11:05 am - 11:30 am

Executive Exchange

 

Thought Leadership

Identity and the New Age of Enterprise Security

From a technology standpoint, as a society the world of business has gone through two distinct stages in the evolution of its information security focus. The first addressed network based protection and preventative controls such as firewalls and anti-malware. The second looked at data-centric and detective controls such as encryption and intrusion/extrusion monitoring. Since breaches continue to occur at a record pace, what is need new is clearly a new evolution, one that pushes towards individual focused security through granular user monitoring and management as provided by solutions such as Identity and Access Management. While IAM isn't a new technology field, it is one whose time has come and CISO need to begin investing in modern-day, light-weight, easy to implement IAM solutions now to stay ahead of the curve, and reduce enterprise threats. 

Takeaways: 

  • The breach onslaught demonstrates that existing security solutions are incapable of defending current threats 
  • Enterprises need to begin looking at security from an activity perspective rather than an artifact perspective 
  • IAM provides activity insight, and therefore threat awareness, no other platform can equal

Sponsored by:

RSA View details

 
 
 

11:35 am - 12:00 pm

Executive Exchange

 

Roundtable

Planning for a MultiCloud Future

The promise of the cloud is almost beyond compare; infinite computing resources, unmatched reliability and uptime, instantaneous service availability, simplistic self-service and provisioning, and the low-low prices of a buy by the drink model. These are the reasons behind the rush to the cloud that we are currently experiencing, but the wholesale adoption does bring a downside " as more and more capability is moved to the cloud, more and more cloud providers are utilized since, for the most part, each provider offers only a limited suite of services. The MultiCloud environment that creates a new set of challenges that IT leaders need to overcome, notably resiliency, interoperability/integration, and security and compliance through careful planning and the lessons learned from building complex on premise distributed systems.

Takeaways:

  • As enterprises move to the cloud, MultiCloud environments will increasingly become the norm, not the exception
  • Consistent planning and thoughtful architecture will be essential to efficient and effective cloud deployments
  • IT leaders do not need to be alarmed, they've been down the complex environment path before, but they do need to be careful

Roundtable

Identity and the New Age of Enterprise Security

From a technology standpoint, as a society the world of business has gone through two distinct stages in the evolution of its information security focus. The first addressed network based protection and preventative controls such as firewalls and anti-malware. The second looked at data-centric and detective controls such as encryption and intrusion/extrusion monitoring. Since breaches continue to occur at a record pace, what is need new is clearly a new evolution, one that pushes towards individual focused security through granular user monitoring and management as provided by solutions such as Identity and Access Management. While IAM isn't a new technology field, it is one whose time has come and CISO need to begin investing in modern-day, light-weight, easy to implement IAM solutions now to stay ahead of the curve, and reduce enterprise threats. 

Takeaways: 

The breach onslaught demonstrates that existing security solutions are incapable of defending current threats 

Enterprises need to begin looking at security from an activity perspective rather than an artifact perspective 

IAM provides activity insight, and therefore threat awareness, no other platform can equal

Roundtable

Big Data and Analytics at the Next Level

The explosive growth of data volume and data variety that have characterized this new big data era are set to head in a steeper upward trajectory as IoT moves from being a fringe technology, to a mainstream capability. When a single Boeing 787 is able to capture 70Tb of data per flight from thousands of individual sensors throughout the vehicle, just imagine the data volume that can be captured when not just every plane, or even every vehicle, but every device and every individual is streaming a constant set of status information. Data growth by itself however is only a small portion of the story, as to have value this data must be analysed in essentially real-time in order to create actionable outcomes.

Takeaways:

  • Big data today may be big, but every single one of the v's that compose it (Volume, Variety, Velocity, Veracity and Value) is set to increase exponentially as a result of IoT
  • The ability to analyse, interpret, and find meaning in this vast sea of data will be single biggest differentiator in enterprise success
  • Enterprises will have to walk a fine line when it comes to privacy of the information they collect to ensure the continued ability to do so
 

12:05 pm - 12:30 pm

Executive Exchange

 

Think Tank

Moving from Operations to Transformations

The accepted number for the amount of the IT budget that is tied up in operational spend, in paying to maintain technology that has already been purchased, is 80% leaving only 20% for the IT department to use to drive new projects. Because this level of funding is so low, as much as 70% of IT sponsored projects fail. Yet IT departments are being constantly pushed to be innovative, to find a way to embrace new technologies and leverage them to drive business change. How can you do that when your time, money, and effort goes to just keeping the lights on? Join us as we collectively explore this issue and examine some of the successful strategies that are being leveraged by top IT leaders.

Takeaways:

  • The pressure on CIO's to drive change has never been higher, but fortunately neither has the opportunity to do so
  • Disruptive technologies don't just have the power to disrupt IT for the worse, they have the power to disrupt the business for the better
  • Fortune favors the bold; now is the time to take a leap into new modes of business to break the operational spend stranglehold

Think Tank

Disaster Recovery and Preparing for the Inevitable

Like death and taxes, IT outages are an inevitability whether as the result of power loss, telecommunications outage, or any one of a myriad other potential technical and non-technical issues. In this environment, the savvy CIO knows that what matters most is preparation " being ready for that next outage with an IT infrastructure that is both resilient and flexible and Disaster Recovery procedures that allow for efficient and effective recovery, balancing Recovery Time and Recovery Point objectives with appropriate cost. Disasters happen but with proper planning they don't have to be disastrous to your business.

Takeaways:

  • In the event of a severe outage, businesses without a Disaster Recovery plan are at a significant disadvantage when it comes to recoverability and viability
  • DR planning cannot be an at all costs proposition and appropriate planning must take into account reasonable Recovery Time and Recovery Point objectives
  • Catastrophic outages get the press but are the thin end of the wedge " minor service interruptions are far more common and must be planned for as well

Think Tank

The Power of Big Data: Energizing the Customer Experience

Customer intimacy is an imperative for companies who are struggling with increasing commoditization of goods and services and an explosive growth in the channels of engagement. Digital organizations have a head start and have disrupted traditional customer interfaces to gain competitive advantage. As a result, organizations across industries are now exploring ways to energize the customer experience and fill the digital gap. This session will present practical ways in which leaders in digital customer experience are leveraging Big Data to harvest customer insights, create new business applications and enable digital transformation within sales and marketing.

Takeaways:

  • Discover how new data ingestion techniques and Big Data Lake are used to drive customer intimacy
  • Learn how digital customer transactions and social media can successfully integrate with enterprise data such as inventory and order management
  • Discuss how CIOs and CMOs need to interact to enable effective operating models to monetize on Big Data

Presented by:

Della Shea, Chief Privacy Officer and Vice President of Data Governance, Symcor View details

 
 
 

12:35 pm - 1:20 pm

Networking Luncheon


 

1:25 pm - 1:50 pm

Executive Exchange

 

Think Tank

Cloud SLAs: Making, Measuring, and Managing

The lifeblood of any cloud relationship is the Service Level Agreement (SLA) upon which it is based " the SLA sets the expectations of both parties and acts as the roadmap for change, whether planned or unplanned. Each SLA has a complex lifecycle that includes three distinct phases " negotiation where the original terms of the agreement are established, measurement where service is actively monitored to ensure agreed upon levels are achieved, and management where deficiencies from and adjustments to initial agreements are acted upon. IT Leaders must take an active role in all phases of the SLA lifecycle to ensure optimal protection for their enterprise.

Takeaways:

  • Without strong SLAs, cloud service level agreements aren't worth the paper they are written on
  • While many cloud vendors offer only a standard SLA, effort should always be invested in attempting to negotiate an appropriate set of terms
  • SLA work does not end with the negotiation of acceptable terms, in fact that is when the real work begins of ensuring SLA compliance

Think Tank

Building a Collaborative and Social IT Security Program

In todays environment there can be no arguing that a comprehensive IT Security program is a de facto requirement for every organization. Such a program needs to address the full range of security threats that can be leveraged against an organization, needs to be integrated into whatever regulatory and governance requirements exist, but beyond that it needs to be accessible, consumable, and actionable by everyone that is influenced by it, or interacts with it. Building a program that is shared through social channels and relies on the collaborative input of employees and constituents for not only creation but enforcement will drive higher levels of adoption, responsiveness and, ultimately, protection.

Takeaways:

  • A security program, that is the stated intentions of the organization combined with the policies and tools to back those intentions up is essential
  • The program needs to be easily communicated, easily consumed, and easily complied with
  • Using an open social and collaborative approach to creation, distribution, and enforcement ensure greater adoption and ultimately greater security

Think Tank

Ensuring Data Quality

Data quality is one of the most critical issues facing every enterprise and whether data be duplicate, stale, incomplete, invalid, conflicting or just plain incorrect the impact of enterprise decision making and ultimately enterprise success and be significant and severe. As the number of data sources grows, as the speed with which data is collected and utilized increases, and as the raw volume expands almost exponentially, the impacts of poor data quality becomes more significant than ever before. IT executives must build strong data governance capabilities to ensure that enterprise data is kept unique, timely, complete, valid, consistent, and accurate.

Takeaways:

  • Data quality is not a new problem but the advent of the IoT age means that it will be a problem of greater relevance than ever before
  • The process by which data quality can be addressed isn't fun or sexy but where enterprises have often ignored it to date they can no longer do so
  • Enterprises that do not proactively address data quality now may find that IoT is their downfall rather than their savior
 

1:55 pm - 2:20 pm

Executive Exchange

 

Fireside Chat

Shadow IT - To Embrace or Eliminate?

Best practice in most enterprises, at least as far as the CIO and CISO goes, is to squash Shadow IT wherever it is encountered. Shadow IT, the argument goes, leads to a world of data and integration problems for the IT department, and significant amounts of unknown and unquantifiable risk for the information security group. A small but vocal minority however is beginning to advocate for Shadow IT as a catalyst of innovation, citing the increases in productivity and creativity by allowing enterprise staff to find their own out of the box solutions to organizational problems. CISOs can allow their organizations to have their cake (Shadow IT) and eat it too (still be secure) by following a few simple steps that allow them to build in security regardless of user activity.

Takeaways:

  • Shadow IT is not malicious activity; it is simply the Line of Business user community looking to be efficient and effective
  • A well-developed security program can take Shadow IT into account and incorporate protection mechanisms that allow end user flexibility
  • Embracing Shadow IT does not mean no holds barred and end users need to understand the limit of the boundaries and the reason for their existence
 

2:25 pm - 2:50 pm

Executive Exchange

 

Roundtable

Sourcing Enabled Business Transformation

Innovation is more than just a buzzword; it's fast becoming the mantra by which successful companies live. As enterprises strive to become ever more agile, offloading mundane responsibilities to sourcing partners can free the resources to become innovative. While beneficial, this really only scratches the surface as it still requires and relies on your resources to undertake that innovation journey. Partners that can bring innovation wherewithal to the table however, that can bake it directly into the service offering provide a greater opportunity to innovate. Understanding how such services can be integrated into your day to day operations, how they can spring board your innovation efforts, and how they can allow you to become truly transformational is essential to innovation success.

Takeaways:

  • Transformational innovation often requires knowledge, insight, and data that you simply don't have the access to yourself
  • A strong partner not only provides the opportunity to innovate, it also provides the resources to help make it happen
  • By leveraging a single for both operational and transformational initiatives, significant economies of scale can be leveraged making innovation easier

Roundtable

Increase Your Security Intelligence and Enterprise Compliance

The breadth and depth of security threats that are targeting the modern enterprise are bordering on overwhelming, but they're not alone as the breadth and depth of security solutions are also bordering on overwhelming. When security managers have to respond to alerts and warnings from dozens of security systems, and CISOs have to make strategic decisions based on fragmented data, it's hard to argue that security is improving. Security Information and Event Management (SIEM) platforms that aggregate the vast quantities of data, correlate diverse events, and filter the signal from the noise are allowing enterprises to get back ahead of the curve and make appropriate tactical and strategic decisions.

Takeaways:

  • The life of enterprise security staff is being complicated not just by the threats they face, but the tools they use
  • Abandoning tools isn't an option and CISOs need to help themselves and their staff get ahead of the curve
  • SIEM offers significant benefits in separating the wheat from the chaff and letting the business actually become secure

Roundtable

Turning Big Data into Big Opportunity

It has been said that leveraging Big Data is like looking for a needle in a haystack; that the challenge is finding the one piece of insight in the sea of irrelevant data. The truth is there is no irrelevant data just data without initial context or meaning, suggesting the problem in actuality is one of looking for a needle in a needle stack. Compounding this problem is that, to offer maximum value, these insights need to found as quickly as possible lest someone else find the relevance first and exploits the opportunity that goes along with it. IT Leaders need to focus not just on building the toolset that allow the business to find insights, but on building an insight pipeline that finds the relevance and feeds it to business peers.

Takeaways:

  • See that Big Data is an opportunity engine waiting to be exploited
  • Learn to identify the insights the business needs to succeed
  • Understand how to build the capability to find and deliver those insights
 

2:55 pm - 3:20 pm

Executive Exchange

 

Think Tank

Leadership Considerations in a Multi-Generational World

Executives are currently facing a difficult challenge in terms of personnel management because they are dealing with three very different generational groups of workers " Baby Boomers, Gen Xers, and Millennials. These three groups all have very different outlooks on the world and on work, and all have very different work styles and capabilities. These differences lead to lack of understanding and conflict in a lot of cases, conflict that leaders must learn how to overcome. Smart leaders know that they need to leverage the differences between generations rather than expecting, and trying to force, everyone to be the same, and that building an integrated workforce, with complimentary skills and abilities, is the key to long-term workforce stability.

Takeaways:

  • Boomers (1946 to 1964), Gen Xers (1965 to 1980), and Millennials (1981-2000) have had different life experiences which has given them different outlooks
  • Each group has specific and unique strengths that can and should be brought to bear to improve the enterprise
  • Building an integrated team that recognizes and rewards differences yields greater success than trying to homogenize everyone to the same standard

Think Tank

Speaking the Language of the Business

For many years the CIO, has struggled with the concept of IT-Business alignment and finding ways to ensure that the IT department and the Lines of Business with which it integrates have a common understanding and ability to communicate. Now, as the CISO and the information security department grow out of the IT shadow, they increasingly find themselves in the same position. Their challenge however is greater in that the concepts of IT security are in many ways more abstract than those of generalist IT, and their activities often run counter to the goals of the rest of the organization. CISOs must learn for the trials and tribulations of the CIO and the IT department, and find common ground with the business, to ensure they can hear what their partners are saying, while communicating their own points in understandable terms.

Takeaways:

  • IT-Business communications have long been strained and only now are improving across most organizations through concerted effort
  • IT has had to find ways to speak the language of the business " it was not the business that learned to speak IT
  • The CISO must adopt and emulate the successful communications practices and strategies of the IT department or risk serious relationship issues

Think Tank

Big Data Analytics and the Impact on Fraud
Financial fraud is, unfortunately a huge business, with annual losses so massive that were Fraud a country, it would have the fifth highest global GDP. While enterprises in the financial services sector have always used analytical processes to detect and limit those losses, as technology moves forward the analytical capabilities that can be brought to bear increase in exponentially in capability and those on the leading edge are able to see, and stop, more fraud in less time. Just as Big Data capabilities are bringing significant business benefit to other aspects of the business, they can to fraud mitigation but several challenges need to be overcome for maximum efficiency. Only by addressing quality, volume, security, and integration challenges and by further ensuring the right staff with the right skills are in place can benefits actually be realized. Takeaways:
  • The increased use of unmanned technology combined with ever quicker financial transaction processing has created a world ripe for the proliferation of fraud
  • In a fight fire with fire approach, those same machine learning approaches can be repurposed to analyze transactions looking for the needle in the needlestack that is the illicit one
  • A Big Data approach only works with the right foundation; garbage in garbage out has never been more true and data and process rigor is essential to success
 

3:25 pm - 3:35 pm

Afternoon Networking Coffee Break

 

3:40 pm - 4:05 pm

Executive Exchange

 

Innovation Showcase

An exclusive opportunity to be exposed to the hottest new solutions providers in a quick-hit format designed to whet the appetite and spark immediate interest.
 

4:10 pm - 4:35 pm

Executive Exchange

 

Think Tank

To Android or Not to Android, THAT, is the Question

Android represents the most common and most popular mobile device operating system and any businesses developing for an external audience absolutely must ensure that Android is a supported platform in the capabilities it offers. However, Android is also the most unsecure platform with as much as 95% of all mobile malware inexistence targeting that platform and so businesses that allow mobility within their organization must very carefully consider that threat before they allow Android devices to connect. Rationalizing that dichotomy of a device that will be common and popular amongst the workforce yet at the same time represents a dire threat to enterprise security is an issue that every CIO and CISO must address.

Takeaways:

  • Android isn't adoption isn't going anywhere but up and enterprise mobility programs must be prepared for almost omnipresent Android devices
  • Android's security issues are legendary however, and in an era of heightened scrutiny on and need for enterprise security, how can IT leaders allow such unsecure devices
  • Balancing user satisfaction and organizational protection is a fine line that IT leaders must constantly walk

Think Tank

Physical and Digital Convergence

The discussion around the convergence of physical security and information security dates back over a decade, but though much was made of the concept in the early 2000's little was actually done and the buzz faded. Flash-forward to today however and the buzz is back because of the increased focus on holistic risk management, the increased pressure of greater compliance requirements, and the increased demand for every aspect of the business to be a value generator. CISOs and CIROs need to evaluate the opportunities for both technology convergence (streamlining platforms) and organizational convergence (streamlining roles) to meet new threat protections mandates.

Takeaways:

  • As enterprise security matures and morphs or integrates into enterprise risk management, converged security becomes a must have
  • Convergence allows for far greater levels of visibility and control of threats and threat actors
  • Convergence enhances not just base security but also top-level risk management, enterprise compliance, and even operational value

Think Tank

Big Data, Small Data, and all the Data in Between

Increasingly over the last several years the term Big Data has become prevalent, to the point that it is invariably all anyone thinks of when data is mentioned at all. Often what we think of when we use the term Big Data is actually unstructured data " all the new data forms that enterprises have never collected before and are being overwhelmed by the possibilities of. But big/unstructured data is by no means the only data enterprises have and core structured or small data is often still the most relevant and valuable data an enterprise owns. As we collectively push forward into a more analytics-centric and therefore data-centric world what we need is a considered all-data strategy, one that incorporates big data, small data, master data, and meta data.

Takeaways:

  • While Big Data is valuable, so is the rest of the data that an enterprise owns and consistent focus must be applied to all data forms and types
  • A holistic data strategy that considers and the balances the needs of all data structures, types, needs, uses, and owners is essential for efficient and effective data operations
  • For business that have not yet invested in Master Data Management, such a program is the ideal foundation for building a comprehensive data program
 

4:40 pm - 5:20 pm

Executive Visions

Facilitating Technology-Enabled Business Transformation

The role of the modern IT Executive is more complex than it has ever been before, not just because the technology landscape has become more complex, but also because increasingly IT execs have had to become a business-focused executive, not just a technologist. Long have we talked about the CIO and CISO getting a seat at the table but modern businesses are now demanding that their technology impresario join them and leverage his deep and rich technical acumen to allow the organization as a whole to better position itself for market-place success. To be successful, CxOs need to invest in themselves, in their personnel, and in the right technologies to allow them to position the IT department to proactively address business needs as an innovator and driver, rather than order-taker and enabler.

Takeaways:

  • IT leadership can no longer be simply technology focused, but must instead take their visibility into business process and become business focused
  • A broader business-focus does not preclude maintaining technology excellence however and indeed may demand more of it than ever before
  • Success for CxOs will be measured not in how they can enable enterprise decisions, but in how they can drive growth
 

5:20 pm - 6:30 pm

Cocktail Reception

 

6:30 pm - 8:00 pm

Networking Dinner

 

8:00 pm - 10:00 pm

After Dinner Networking

 

Tuesday, February 28, 2017 - CISO Canada Summit

7:00 am - 8:00 am

Networking Breakfast

 

8:10 am - 8:40 am

Keynote Presentation

IT Integration in a Distributed IT World

It's no secret - the integration of disparate systems, disparate applications, and disparate data stores has long been one of the biggest challenges faced by the IT department. Simply put, getting everything to talk to everything is no easy task. The rapid adoption of cloud delivered services has compounded this problem almost exponentially - if it was hard to integrate when you controlled the whole stack it has become nearly impossible when you control very little of it. To be efficient and effective IT departments need to adopt a new model of system, application, and data integration. Endless webs of one-off point-to-point integrations simply won't cut it anymore and a purposeful, structured approach is required.

Takeaways:

  • Learn how to build a holistic strategy to integrate systems, applications, and data
  • Understand how to leverage SOA and ESB to streamline app to app communications
  • Discover the power and impact of holistic Master Data Management and other data integration processes
 

8:45 am - 9:15 am

Keynote Presentation

Addressing Privacy on a Global Scale

Of all the risk management issues that present themselves to the modern-day CISO, perhaps the most difficult to address is that of privacy. In and of itself, privacy is no different a challenge than protecting any other sensitive information, however the multi-jurisdictional impacts of the issue due to wildly differing laws between the US and European countries (as well as Canada, another country with strong privacy laws) make this an issue that is often times overwhelming to address. CISOs must work diligently to ensure that their privacy efforts conform with the standards of any jurisdiction with which they might work, where their data might be held and this is an almost overwhelming task.

Takeaways:

  • Privacy is one of the most challenging issues for any business and CISO to address
  • The difference in regulations between and among European countries (both those in and out of the EU itself) and North American ones means traversing a fraught landscape
  • A strong approach to privacy that addresses global differences is essential to being a stable and viable global business
 

9:20 am - 9:45 am

Executive Exchange

 

Thought Leadership

Applying Big Data Principles to Security Paradigms

Volume, variety, velocity, veracity; all four of the hallmarks of Big Data have a clear fit in the world of security as the number of threats grows, their natures diverge, the speed with they are encountered (and subsequently have to be dealt with) accelerates, and the need to be ever more accurate enhances. As enterprises have made significant investments in Big Data programs and analytics platforms, they are beginning to reap real benefits in terms of business efficiency and innovation. The time then has come to begin applying those same principles and platforms to the security challenges facing enterprises to allow for faster, more effective overall security.

Takeaways:

  • The nature of the enterprise security challenge closely mimics many of the Big Data challenges business are beginning to learn how to solve
  • Just as Big Data challenges required different tools to address for Line of Business and general IT issues, so they will for information security challenges
  • Security must become the next focus for analytics capabilities, and analytics the next focus for security professionals
 

9:50 am - 10:15 am

Executive Exchange

 

Roundtable

Cloud Adoption Challenges on a Macro Level

The hype around the cloud is pervasive and can be potentially overwhelming but numerous studies have shown that tangible benefits can be had, whether in cost savings, efficiency improvements, or flexibility enhancements. That said numerous impediments exist to not just realizing that value, but even considering adoption; regulatory issues, integration challenges, business process revamp, and a dozen other challenges can halt cloud projects in their tracks before they get off the ground. In this group discussion we'll explore those inhibitors, understanding which challenges prevent adoption and what can be done to overcome them.

Takeaways:

  • The cloud presents a significant opportunity to organizations and while most have adopted in some form or other, wholesale adoption still lags
  • To realize benefits enterprises must deal with a variety of challenges each one requiring different solutions
  • Industry by industry adoption is constrained for different reasons but do common solutions exist that can resolve issues across the board?

Roundtable

Security in an Outsourced World

Building security into your enterprise processes, and integrating it with your existing technology investments has never been more critical or complicated than it is in this era of decentralized computing, and ever-tightening compliance requirements. Furthering this complication is the impact that partnering deals can have since infrastructure, applications, and even data may now longer be under your direct control. To be able to ensure efficient and effective security capabilities you need to understand the nature of the threats that exist today, the impact a sourcing relationship can have on these threats, and the mitigation strategies and tools key industry leaders are using to address the challenge.

Takeaways:

  • Social, Mobile, Cloud, and Analytics is already having a significant impact on enterprise security, sourcing potentially adds another layer of complexity
  • Beyond simple security however there are also issues such as privacy and compliance that also need to be considered
  • Investing in the right tools and practices is essential to weather the storm without breaking the bank

Roundtable

Mobile Data Quality

Data quality has long been one of the most challenging issues that IT organizations and the enterprises that are hoe to them have had to deal with. Everyone knows that these data quality issues exist, but the cost and complication of addressing them has pushed them to the back burner. We stand however at a precipice, one that has been brought on us by mobile computing " as more devices enter the hands of more users, more data is being created and consumed, making the data quality issue more pressing, more relevant, and more urgent to solve. IT leaders can no longer ignore data quality issues for the good of their companies and the good of their careers and need to bring this issue to the fore and get it resolved before the avalanche sweeps them under.

Takeaways:

  • Data quality is hard and unappealing and so in many case it is simply not done, or not done effectively
  • Enterprises have been scuffling by with poor data quality capabilities and may be convinced that the situation is manageable
  • Even though data volumes have grown quickly over the last few years, mobility is set to give data volume a near vertical growth curve which will compound and highlight this fundamental issue
 

10:20 am - 10:30 am

Morning Networking Coffee Break

 

10:35 am - 11:00 am

Executive Exchange

 

Roundtable

Proving the ROI of IoT

We all know that ROI calculations, on the surface, are simple mathematical formulas: compare the cost of investment against the value of the return over a given and agreed upon period. But determining exactly what each side of the equation entails and totals is the challenging part, and nowhere moreso than in burgeoning areas such as IoT adoption where use cases are still not clearly understood, and technology costs are highly variable, and all the components related to cost may not yet be quantifiable. The benefits are there, as a number of enterprises are discovering with early pilot programs, but CIOs must enter this area with their eyes wide open to ensure that early IoT implementations have the ROI necessary to keep more complex projects moving forward.

Takeaways:

  • Costs must be carefully quantified for any IoT project " it's not just the sensors, but networking, data, security, etc. spend must be taken into account
  • Similarly, value must be clearly established both in isolation and in comparison to any more traditional methods that could be used
  • Successful IoT projects will be those that can initially leverage existing spend to mitigate costs with successive project piggybacking on earlier investments

Roundtable

Balancing Reactivity and Proactivity in Enterprise Security

As with all things in life, the focus on how to conduct enterprise security ebbs and flows between varying degrees of reactivity and proactivity. In the old school Security 1.0 world, where the focus was almost completely on network security, efforts were in general proactive in nature with firewalls and anti-malware seeking to prevent threats before they even occurred. This didn't work so well and so Security 2.0 focused on reactivity, wrapping things like encryption around the data so that even if a breach occurred, the loss would be mitigated. Yet breaches, and losses, continue to occur. So if primarily proactive security doesn't work, and if primarily reactive security also doesn't work, how then do we find the right balance between the two to find a security posture that does work?

Takeaways:

  • Proactive security measures, those that prevent a threat from occurring are valuable and necessary but haven't proven effective
  • Reactive security measures, those that mitigate a threat that has occurred are also valuable but complicated a limit enterprise efficiency and efficacy
  • A new approach is needed, but is that one that blends techniques or one that finds new approaches (whether they be reactive, proactive, or both)?

Roundtable

Big Data and Analytics at the Scale of Mobility

The explosive growth of data volume and data variety that have characterized this new Big Data era are set to head in a steeper upward trajectory as enterprises collectively begin to exploit the massive data flows that are coming out of mobile devices. As the volume of mobile devices eclipses that of human beings on the planet, just imagine the data volume that can be captured when every device and every individual is streaming a constant set of contextual status information. Data growth by itself however is only a small portion of the story, as to have value this data must be analysed in essentially real-time in order to create actionable outcomes.

Takeaways:

  • Big Data today may be big, but every single one of the v's that compose it (Volume, Variety, Velocity, Veracity and Value) is set to increase exponentially as a result of wholesale mobility adoption
  • The ability to analyse, interpret, and find meaning in this vast sea of data will be single biggest differentiator in enterprise success
  • Enterprises will have to walk a fine line when it comes to privacy of the information they collect to ensure the continued ability to do so.
 

11:05 am - 11:30 am

Executive Exchange

 

Think Tank

Disrupting Markets with Disruptive Technologies

While the combination of Social, Mobile, Analytics, and Cloud have been present and disrupting IT departments and enterprises as a whole for over two years now, in many ways organizations have still not fully embraced them, have still not fully leveraged them. These new platforms allow organizations radically new ways to go to market, allowing for broad scale deployment of systems of engagement that create dynamic relationships with clients and prospects. Finding the resources, wherewithal, and ability to fully commit to these technologies and the capabilities they create has proven to be a struggle for many, but a struggle that can be overcome by leveraging the right partners that bring the right skills and experiences to bear.

Takeaways:

  • Social, Mobile, Analytics, and Cloud are all here to stay; each one adds value to enterprises but collectively that value increases exponentially
  • The manner in which these technologies are implemented, operated, and utilized is different than the foregoing systems of record we are used to
  • Unique skills and capabilities are required to leverage the power and value of these platforms, skills and capabilities that can be in short supply

Think Tank

Security and Compliance; Chicken and Egg or Chalk and Cheese?

Since regulatory (and industry) compliance became a notable thing in the early-mid 2000's it has been intimately linked with information security and often times has been the lever (or hammer) by which enterprises made necessary investments in security. But being compliant and being secure aren't the same thing, and in too many cases enterprises that were perfectly compliant have been perfectly breached. A new focus is needed; one that respects that while security and compliance are not the same thing, they are working towards the same goal (a reduction in overall enterprise risk exposure) and sees that compliance flows from security.

Takeaways:

  • While a secure company is likely a compliant company, the same cannot be said of the reverse situation
  • Just because compliance has loosened the purse strings doesn't mean it takes a pre-eminent position on security investments
  • Reducing enterprise risk is the goal of both practices but without appropriate focus on both is a goal that will never be achieved

Think Tank

Using Data & Analytics to Drive Business Transformation

Big Data initiatives have become a reality among almost every company today, however, what we have seen is lots of initiatives have become just science projects and did not deliver on early expectations. This situation needs to reversed quickly because those organizations that are being successful with Big Data and analytics programs are rapidly leaving those that are unsuccessful in their wake. Big Data and analytics has the potential to be transformational for the enterprise, but IT leaders need to be making the right investments, in the right areas, to ensure optimal success. This panel discussion will focus on how to use data and analytics to drive true business success and show some real examples of companies and individuals who made a difference.

Takeaways:

  • Analytics is not a new capability and has always been aligned with the most successful companies
  • The roles of IT and the lines of business are changing when it comes to data and analytics programs
  • The business benefits of analytics programs can be huge but efforts need to be constrained so that they don't turn into flights of fancy, yet set free enough that they find the unknown unknowns that truly drive transformation
 

11:35 am - 12:15 pm

Executive Visions

Diversity in IT

The importance technology plays within an enterprise will only continue to gain momentum as more developers, engineers, and programmers enter the workforce. As these segments continue to grow, so does the diversity of the workforce within the technology field. For a field that is severely constrained by a talent and skills gap, this influx of bodies can only be a good thing. Beyond the basic ability to deliver of identified capabilities a diverse workforce, whether cultural or gender influenced offers a whole that is more than the sum of the parts. Finding ways to drive and increase diversity in IT then should be a key focus for every IT executive.

Takeaways:

  • Identify the importance behind diversity in technology, opportunities, and capabilities
  • Discuss the importance of cultivating diversity at the grass-roots level and building post-secondary programs that drive awareness of and interest in IT
  • Understand the hurdles that exist that limit the prevalence of diversity in IT, and what steps must be taken to lower, if not eliminate, them
 

12:15 pm - 12:25 pm

Thank You Address and Closing Remarks

 

12:30 pm - 1:20 pm

Grab and Go Luncheon