Early Registration $50 just $25

Atlantic City CyberSecurity & Fraud Forum

Leadership Discussions on Emerging
Cyber, Risk & Fraud Challenges

Friday | 25 September 2026 | 9:00am - 3:30pm

Days
Hours
Minutes
Seconds

A Collaborative, Peer-Led Forum for
Cybersecurity & Compliance Leaders

The Atlantic City CyberSecurity & Fraud Forum brings together senior cybersecurity, fraud, risk, compliance, privacy, and technology leaders alongside law enforcement professionals dedicated to cyber defense, investigation, and fraud prevention. Designed as a collaborative, practitioner-led event, the forum provides a trusted environment where executives can openly discuss today’s most pressing cyber risks, share real-world experiences, and learn from peers facing similar challenges.

 

Rather than focusing on vendor presentations, the forum emphasizes meaningful conversations, practical strategies, and actionable insights on topics including AI-driven threats, ransomware, identity security, fraud prevention, third-party risk, incident response, regulatory compliance, and cyber resilience. Attendees benefit from engaging discussions with industry experts and public-sector partners while building valuable relationships that strengthen collaboration across both the private and public sectors.

 

Whether you are responsible for protecting people, data, financial assets, or critical infrastructure, the Atlantic City CyberSecurity & Fraud Forum offers an opportunity to gain fresh perspectives, exchange ideas with fellow leaders, and leave with practical knowledge that can be applied immediately within your organization.

 

$50 Participant registration includes CPEs, the full agenda, as well as hot breakfast & lunch buffets!

Agenda Summary

🧭 Cybersecurity First Principles: Simplifying Strategy in a Noisy World

 

Cybersecurity leaders have more tools, frameworks and data than ever—but not necessarily better outcomes. We’ll examine how resilience, Zero Trust, intelligence and risk forecasting can work together as part of one coherent strategy, helping leaders focus limited resources on the things that actually reduce risk.

 

🤖 The AI Security Industry: What’s Real, What’s Noise & What Comes Next

 

AI is reshaping both the threat landscape and the cybersecurity industry itself. We’ll look beyond the marketing claims at the explosion of new AI-security vendors, where genuinely new capabilities are emerging, how automation may change security operations, and what executives should actually be paying attention to.

 

🤖 Agentic AI + Zero Trust: Getting Beyond “Pilot Purgatory”

 

Enterprises are moving from copilots toward autonomous agents that can make decisions and take action. We’ll explore why so many AI initiatives stall, what changes when machines become actors inside the enterprise, and how Zero Trust, identity, governance and accountability can help organizations operationalize AI safely.

 

🧠 When AI “Alignment” Isn’t a Security Control

 

Organizations are increasingly relying on built-in model safeguards without fully understanding how fragile they may be. Through real-world demonstration and discussion, we’ll examine risks in the LLM supply chain, how post-training alignment can be weakened or removed, and what security leaders should be doing differently as AI becomes embedded throughout the enterprise.

 

🔗 Third-Party Cyber Risk Management (TPCRM): Beyond the Vendor Questionnaire

 

Third-party cyber risk is emerging as a distinct discipline within traditional TPRM. Organizations increasingly inherit cyber risk from their vendors—including AI capabilities quietly embedded inside third-party products. We’ll examine why point-in-time assessments are no longer enough and how leaders can move toward more continuous, measurable assurance, visibility and resilience across their extended enterprise.

 

💰 Inside the “Biggest Heist Ever”: Cybercrime, Crypto & Financial Investigation

 

A firsthand look inside the historic Bitfinex investigation and the effort to trace and recover billions in stolen bitcoin. Beyond the extraordinary case itself, the discussion will explore what it teaches us about attribution, cryptocurrency, money laundering and the increasingly blurred lines between cybersecurity and financial crime.

💰 Inside the “Biggest Heist Ever”: Cybercrime, Crypto & Financial Investigation

 

A firsthand look inside the historic Bitfinex investigation and the effort to trace and recover billions in stolen bitcoin. Beyond the extraordinary case itself, the discussion will explore what it teaches us about attribution, cryptocurrency, money laundering and the increasingly blurred lines between cybersecurity and financial crime.

 

💳 Cyber + Fraud Convergence: Two Problems Becoming One

 

Account takeover, synthetic identity, business email compromise, deepfakes and AI-assisted fraud increasingly cross the traditional boundaries between security and financial-crime teams. We’ll explore where those functions need to collaborate more closely—and how shared intelligence, identity controls and investigations can help disrupt attacks earlier.

 

⚖️ Risk, Regulation & Executive Accountability

 

Cybersecurity is no longer simply an IT problem. Boards, regulators and business leaders increasingly expect security executives to quantify risk, understand dependencies, govern AI and demonstrate that controls actually work. Discussions throughout the day will examine how those expectations are changing—and what they mean for security, risk and compliance leaders.

 

🕵️ Real-World Investigations, Threats & Lessons Learned

 

Practitioners, investigators and public-sector partners will take participants behind incidents and investigations where the details matter: what attackers actually did, how investigators connected the dots, where existing controls failed, and what leaders can apply inside their own organizations.

 

🧑‍💼 Leading Through Constant Disruption

 

Vendor sprawl. AI accountability. Third-party exposure. Board pressure. Fraud. Talent constraints. The modern cyber leader has to make consequential decisions with incomplete information and finite resources. Throughout the Forum, we’ll focus on practical approaches that help executives prioritize, communicate risk and make better decisions.

 

Emerging Threats & Executive Discussion

 

The agenda will leave room for the issues that may not even be obvious today. Moderated, audience-driven discussions will surface what leaders are seeing inside their own organizations—and allow peers to compare approaches to the threats, technologies and risks changing fastest.

Plus

 

🎤 Nationally Recognized Authors, Investigators & Industry Experts

TED-style talks designed to introduce a strong point of view, followed by moderated executive discussion—not canned presentations.

 

🔄 Moderated Discussion Pods

Peer-driven conversations that bring the audience into the discussion, challenge assumptions and turn presentations into practical exchanges.

 

🤝 2+ Hours of Curated Networking

Meaningful time to connect with fellow cybersecurity, fraud, risk and compliance leaders—as well as a small group of vetted, non-competing Solution Providers supporting the Forum.

 

detailed Agenda

Registration & Networking

8:30 AM

Welcome/Introductions

The Forum is a collaboration point for the many member-driven professional associations across the region. Hear a brief introduction from Board Members of each of those InfoSec & Fraud Associations as we open the agenda

9:00 AM

AI Is the New Threat Actor. AI Is the New Defender [Discussion Pod #1]

Cybersecurity in the Machine Age

AI is no longer simply another technology that cybersecurity teams need to secure. It is beginning to change who attacks us, how attacks unfold, how quickly vulnerabilities can be exploited—and how we defend ourselves.

Richard Stiennon, has spent decades mapping the cybersecurity industry. In researching his latest book, Guardians of the Machine Age, he has watched an entirely new AI-security ecosystem emerge at extraordinary speed, with hundreds of companies attacking problems ranging from autonomous security operations and agent security to model protection, identity, vulnerability management, deepfake defense and AI governance. His conclusion: we are not looking at another cybersecurity product cycle. We are watching the structure of the industry change.

But that does not mean ripping out everything that came before.

In this provocative, forward-looking discussion, Richard will separate the durable fundamentals from the genuinely new. What happens when attackers can discover vulnerabilities, develop exploits and persist against a target at machine speed? What changes when defenders can deploy autonomous agents of their own? Which existing security investments become more important—not less? Where is today’s AI-security market producing real innovation, and where are we simply attaching “AI” to familiar products? And what emerging capabilities should security leaders be watching now, before they become mainstream?

9:45 AM

Reduce the Probability of Material Impact [Discussion Pod #2]

Using Cybersecurity First Principles to Make Better Risk Decisions

Rick Howard argues that cybersecurity strategy should begin with one irreducible first principle: Reduce the probability of material impact due to a cyber event over a defined period of time.

Cybersecurity leaders are surrounded by frameworks, controls, tools, threat intelligence and an endless stream of urgent priorities. Rick will lead a discussion on using that principle as a practical decision-making filter—not simply as a statement of strategy. Drawing from Cybersecurity First Principles, major cyber incidents and three decades of leadership across military, intelligence, technology and industry, he will challenge several commonly accepted assumptions about how security programs are built and measured.

Participants will explore how to:

  • Distinguish meaningful risk reduction from activity that merely creates the appearance of progress
  • Connect cybersecurity and fraud decisions to the potential material impact on the organization
  • Prioritize limited people, time and budget against the actions most likely to reduce risk
  • Use resilience, zero trust, intelligence and risk forecasting as components of one coherent strategy
  • Explain cybersecurity priorities to boards and business leaders in language grounded in probability, impact and time

In this talk and the moderated discussion that follows, Rick will leave participants with a practical question they can take back to their organizations: Does this action measurably reduce the probability of material impact—and, if not, why are we doing it?

10:15 AM

IAM/reinvited [Discussion Pod #3]

Ravi Khatod has spent decades building and leading cybersecurity companies through successive waves of change. His question for us is deceptively simple: If IAM is a mature market dominated by some of cybersecurity’s biggest companies, why are so many smart people starting new identity companies?

In this fast-paced TED-style talk, Ravi will separate what is genuinely changing from what is simply being renamed. We’ll look at the evolution from human access to non-human identities and now AI agents that can act, transact and make decisions at machine speed—and why that may force us to rethink some very basic assumptions about authentication, authorization, privilege and control.

What does a CISO actually need to understand about NHI? What parts of today's identity architecture will survive the agentic era? What isn't quite here yet—but soon will be? And how much control can we realistically maintain as machines increasingly act on behalf of people and other machines?

Ravi’s goal is to leave leaders with a practical Identity Scorecard: what should already be possible today, where existing approaches are beginning to age out, what deserves a place on the next several years of the roadmap—and the questions CISOs should be asking their teams and vendors now, before agent-centric processes scale faster than their controls.

A moderated discussion will follow to pressure-test that scorecard against the realities in the room—and explore which identity assumptions we may need to unlearn next.

11:00 AM

Leading the Fight: Cybersecurity & Government Agencies [Panel]

Executive Panel -

In this talk, government agency leaders will share how they approach coordinated threat disruption, interagency collaboration, and executive-level response to cyber-enabled crimes. 

When cybercrime intersects with national security, terrorism, cross-boarder issues, or financial stability, the US Secret Service, Department of Homeland Security, FBI and state fusion center (NJCCIC) step in—not just with investigations, but with leadership. Drawing from real-world cases—ranging from cryptocurrency scams to insider threats—our panelists will outline lessons learned for private-sector leaders.

What does it take to lead under pressure, across jurisdictions, and in defense of critical assets? In this fast-moving session, participants will get practical takeaways on how to elevate their cyber leadership posture—and why the most effective defenders think like protectors, not just responders.

Panelists: 

  • Krista Valenzuela, Bureau Chief - Cyber Threat Outreach & Partnerships - NJ Cybersecurity and Communications Integration Cell (NJCCIC)
  • Supervisory Special Agent Michelle Liu, FBI Newark – Cyber Division
  • Carlo Nastasi, Special Agent, IRS Criminal Investigation
  • Stan Field, Cybersecurity Advisor, CISA Region 2
  • Jesse Imbergamo, Supervisory Special Agent, HSI
11:20 AM

Biggest Heist Ever: Inside the Hunt for Billions in Stolen Bitcoin [Discussion Pod #4]

What the Bitfinex investigation reveals about the convergence of cybercrime, fraud and financial intelligence

Special Keynote Discussion Leader: Chris Janczewski, Head of Global Investigations, TRM Labs; former IRS-CI Special Agent

Chris Janczewski was the lead investigator at IRS Criminal Investigations, and got a lead he just could not give up.  He went deep on the research… and cracked the “Biggest Heist Ever,” what would eventually be valued at $15 Billion. 

The Netflix documentary Biggest Heist Ever tells the remarkable story of the 2016 Bitfinex hack, an eccentric aspiring rapper known as “Razzlekhan,” and billions of dollars in stolen bitcoin hidden and laundered across the digital economy. Chris Janczewski was the IRS Criminal Investigation special agent who led the landmark investigation—and the man behind much of the story portrayed on screen.

In a focused keynote talk, Chris will take participants inside the investigation, showing how blockchain intelligence, cyber forensics, financial records and traditional investigative techniques were combined to follow the money and recover the stolen assets. He will also explain why the case offers an important lesson for today’s leaders: criminals move seamlessly across the boundaries separating cybercrime, fraud, cryptocurrency, money laundering and traditional finance.

A moderated discussion will follow, exploring what cybersecurity, fraud, AML, risk and compliance leaders can learn from the case—and why closer cooperation between these communities has become an operational imperative.

11:45 AM

Lunch & Solution Showcase Networking Discussions

Participants will enjoy a lovely full hot lunch while connecting with the thoughtful Solution Providers who are supporting the community at the Atlantic City CyberSecurity & Fraud Forum

12:15 PM

Agentic AI Meets Zero Trust: What Actually Breaks—and How to Fix It [Discussion Pod #5]

Josh Woodruff is the Author of "Agentic AI + Zero Trust," a former CISO, and a long-time advisor in the industry. He will talk more about the years of research that went into the book. 

In the rush to deploy autonomous/semi-autonomous AI, Community Members have shared their doubts that existing identity, data, and control frameworks are ready. Drawing from years of research for his book and field experience, Josh will share:

  • Why most agentic AI initiatives fail operationally, not technically
  • How Zero Trust principles must evolve for AI agents, workflows, and non-human identities
  • Where security teams need to rethink identity, authorization, and monitoring
  • What CISOs and CIOs can do now to avoid costly architectural mistakes

This session blends short-form insights with moderated group discussion, focused on immediately actionable takeaways for enterprise leaders.

1:10 AM

Whose Definition of "Safe" Is Running in Your Environment? [Discussion Pod #6]

Model Integrity, Inherited Policy, and the New AI Supply Chain

Every open-weight model you deploy arrives with a safety policy already baked into it. Someone decided what that model will refuse to do. That someone worked at a different company, under a different regulator, possibly in a different country, with a different risk appetite and a different definition of acceptable speech than yours. You inherited their judgment the moment you pulled the weights, and you have no practical way to read it, audit it, or prove what it says.

Tim Rohrbaughhas spent the last year researching model alignment at the weight level and has published roughly 60 modified models. His work shows that refusal and safety behaviors can be surgically altered while the model continues to pass the benchmarks and acceptance tests most organizations rely on. The uncomfortable conclusion: adding a safety behavior and removing one are the same technical operation abet a different cost. Nothing in the artifact distinguishes alignment from tampering, which means your current controls cannot either.

That gap widens across today's AI supply chain. At native precision a model is genuinely inspectable: you can diff the tensors, read the config, and localize exactly what changed. But almost nobody runs models at native precision. You approve a published model and deploy a quantized build produced by a third party you never vetted, through a transformation that buries the signal you would have been looking for. The artifact you can inspect is not the artifact you run, and the handoff between them is currently owned by no one.

Tim will cover what he has actually done and what it means for defenders: open-weight provenance, the AI Bill of Materials as declared provenance, behavioral screening as measured provenance, and practical approaches via modeldna.ai.

You'll leave able to answer, or at least able to ask: If a major model registry like Huggingface hosts a tampered model tomorrow, how long would it take you to determine whether you are running it, including the quantized derivative your vendor shipped or was using?

1:45 PM

Degrees, Certs & Entry-Level Grit: What Cyber Grads Can (& Can’t) Do For You
[Panel]

This panel discussion features a real-world exchange between cyber educators and industry leaders. Professors will share how they’re designing programs with hands-on labs, industry-funded projects, and even high school hackathons. CISOs and CTOs will weigh in on the “last-mile” problem: grads with zero experience, mismatched expectations, and a professionalism gap that’s hard to ignore.

With over 700,000 unfilled cybersecurity jobs in the U.S., you’d think the hiring problem would solve itself. But here’s the rub: cybersecurity programs are churning out grads, and CISOs still ask, “What can they actually do on day one?” Are they SOC-ready? Do they understand fraud prevention, governance, compliance—or even what cybersecurity is?

We’ll dig into big questions:

  • Are four-year degrees still the gold standard—or are certs and bootcamps the smarter play for mid-career upskilling?
  • How do you hire interns and set expectations when “everyone is busy”?
  • What can companies do (without breaking budgets) to actually shape the talent pipeline?
  • And how can we close the generation gap without lowering the bar?

Come for the honest dialogue, stay for the practical takeaways—and leave with a few ideas for fixing a system that isn’t working for educators, employers, or students.

Panelists:

  • Dr. Otto Hernandez,  Vice President - Academic Affairs, Atlantic Cape Community College
  • Michael Zambotti, Professor, Saint Francis University
  • Sharon Kelley, Executive Director for Information Security & CISO, New Jersey Institute of Technology
  • Aakash Taneja, Professor of Computer Information Systems, Stockton University
  • Mark Eggleston, CISO, confidential
  • Brian Callahan, Director of Cybersecurity Research, Monmouth University 
  • Dalal Samaan, CISO, Keenova
  • Danny Zakharia, CISO, Children's Hospital of Philadelphia 
2:30 PM

The Next Breach Won’t Look Like the Last One: Preparing for What You’re Not Measuring [Discussion Pod #7]

Every security program today is optimized to prevent the last breach.

The controls, dashboards, budgets, and board conversations are all shaped by yesterday’s incidents—ransomware, phishing, endpoint compromise. But the next wave of risk is already forming outside those models: non-human identities, AI-driven decisioning, supply chain entanglement, and silent data manipulation that doesn’t trigger alerts.

In this closing session, we’ll challenge a dangerous assumption: that improving today’s controls will protect you from tomorrow’s threats.

This discussion will explore:

  • Why most enterprise security programs are overfit to known attack patterns
  • Where visibility is breaking down (AI agents, APIs, third-party logic, machine-to-machine trust)
  • How attackers are shifting from disruption to subtle manipulation and persistence
  • Why traditional metrics (MTTR, patch SLAs, alert volume) may be giving false confidence
  • What leading organizations are doing to rethink detection, trust, and resilience before the next wave hits

This is not a prediction talk. It’s a reality check. Expect a fast-paced, candid discussion that forces a simple but uncomfortable question:  What risks are we blind to—because we’re not even looking for them?

3:05 PM

Closing Discussion & Networking

Stay & Connect: Informal Networking + Solution Showcase
Before hitting the road, grab a coffee and take time to connect. Trade insights with peers, chat with Solution Providers, and follow up on the ideas sparked throughout the day.

No panels, no pitches—just real conversations to wrap things up right.

3:30 PM

Partners

Each CxO Security Forum is built in collaboration with respected government agencies and professional associations. These partners help shape the agenda, contribute expert speakers, and invite their networks to participate. Their involvement ensures every gathering delivers relevant, high-value content tailored to senior cybersecurity and risk professionals.

Registration - Request an Invite

**Request an invitation below**

(After your request is approved, look out for a confirmation email & calendar invite shortly) 

Forum Discussion Leaders

(Past, Present & Future - Agenda still being confirmed!)

Rick Howard

Rick Howard

Author, Cybersecurity First Principles
Co-Founder and CEO, Cybercanon Project

Rick Howard is a cybersecurity executive, author, educator and strategist whose career spans more than three decades across military service, intelligence, technology, media and executive leadership.

He is the co-founder and CEO of the Cybercanon Project, an all-volunteer nonprofit dedicated to identifying, preserving and promoting the essential books and ideas that have shaped the cybersecurity profession. Through the work of its volunteer community, the project seeks to become the industry’s trusted source for curated, enduring cybersecurity knowledge.

Rick is the author of Cybersecurity First Principles: A Reboot of Strategy and Tactics, which challenges security leaders to move beyond disconnected tools, trends and conventional “best practices” and instead build their programs around a clearly defined set of foundational principles. Drawing on cybersecurity history, major incidents and practical risk analysis, Rick offers a strategic framework for determining which security actions will have the greatest impact.

Over the course of his career, Rick has served as Chief Security Officer of Palo Alto Networks, Chief Security Officer and podcast host at The CyberWire, CISO of TASC, General Manager of VeriSign’s iDefense intelligence service and Global SOC Director at Counterpane. Earlier in his career, he served as Chief of the U.S. Army Computer Emergency Response Team, coordinating defensive operations, intelligence and response activities across the Army’s global network.

He was also among the founding organizers of the Cyber Threat Alliance and currently advises organizations including Tidal Cyber, the Center for Internet Security and Resilience.

Rick holds a Master of Computer Science from the Naval Postgraduate School and an engineering degree from the United States Military Academy. He taught computer science at West Point and currently serves as a seminar instructor in Carnegie Mellon University’s CISO Executive Program, where he teaches cybersecurity first principles.

As a CxO Security Forum Special Keynote Discussion Leader, Rick will challenge participants to reconsider some of the profession’s most widely accepted assumptions—and explore how first-principles thinking can help leaders simplify strategy, forecast risk and focus limited resources on the actions that matter most.

Richard Stiennon

Richard Stiennon

Chief Research Analyst - IT Harvest
frmr. VP of Research - Gartner

Richard Stiennon is one of the most respected and provocative voices in the cybersecurity industry. As Chief Research Analyst at IT-Harvest—the firm he founded in 2005—he leads the only comprehensive effort to map, track, and analyze the entire global cybersecurity vendor landscape. His research underpins the Security Yearbook series, offering deep data and sharp insight into the trends shaping the industry.

A former VP of Research at Gartner, Richard has held senior roles at Fortinet, Webroot, and Blancco Technology Group, and has advised government agencies and Fortune 500 companies alike. His past publications include There Will Be Cyberwar, a Washington Post bestseller, and Surviving Cyberwar. His thought leadership spans over three decades and 32 countries, blending strategic analysis with operational depth.

Richard holds a B.S. in Aerospace Engineering from the University of Michigan and an M.A. in War in the Modern World from King’s College London. He is also an active commentator on LinkedIn, Substack, and X (formerly Twitter), where he regularly challenges assumptions and surfaces the next wave of cybersecurity innovation.

Ravi Khatod

Ravi Khatod

Founder & CEO, Ambient Security

Ravi Khatod is a veteran cybersecurity executive, entrepreneur, and company builder who has spent more than two decades at the forefront of major shifts in enterprise security. Across leadership roles at companies including IronPort, PacketMotion, Bromium, Agari, CloudVector, and SecureAuth, Ravi has helped build and scale businesses spanning email security, endpoint protection, API security, and identity.

Today, as Founder and CEO of Ambient Security, Ravi is focused on one of the industry’s next major challenges: how identity, access, and privilege must evolve as AI agents, machines, and other non-human identities become active participants in the enterprise. His perspective combines decades of operating experience with a forward-looking view of where cybersecurity architecture—and the role of identity within it—is headed next.

Agentic AI + Zero Trust

Josh Woodruff

Author, Agentic AI + Zero Trust: A Guide for Business Leaders
IANS Faculty | CSA Zero Trust Working Groups

Josh Woodruff is the author of Agentic AI + Zero Trust: A Guide for Business Leaders, a practical framework for safely operationalizing autonomous AI using Zero Trust principles. Drawing on nearly 30 years of experience as both a CIO and CISO, Josh translates real-world enterprise deployments into clear executive guidance on trust, governance, and risk in agentic systems.

The book—co-authored with Michelle Savage and featuring a foreword by Zero Trust pioneer John Kindervag—cuts through AI hype to explain why most AI initiatives stall in pilot mode, and what successful organizations do differently. Josh is also the Founder and CEO of Massive Scale Consulting, co-leads the Cloud Security Alliance Zero Trust Working Group, and serves as IANS Faculty, advising enterprises across regulated and high-risk industries.

Known for his ability to frame complex AI and security challenges in plain executive language, Josh focuses on helping leaders design guardrails that accelerate innovation without sacrificing control, accountability, or resilience.

6862e72ec198885a1ad9f30d_Chris Janczewski

Chris Janczewski

Head of Global Investigations
TRM Labs

Chris Janczewski is the Head of Global Investigations at TRM Labs, where he leads an elite team of investigators from major law enforcement and private sector organizations, including the U.S. Secret Service, FBI, Homeland Security Investigations (HSI), UK's National Crime Agency, and Federal Police of Brazil.

Prior to joining TRM, Chris had a distinguished 13-year career as a Special Agent with IRS Criminal Investigations (IRS-CI), where he led some of the most significant cryptocurrency investigations in history. His notable achievements include leading the investigation that resulted in the largest seizure in U.S. government history and spearheading the "Welcome to Video" takedown..

Chris was instrumental in establishing an inter-agency cryptocurrency strike force with the Washington, D.C. United States Attorney's Office and has advised policymakers at the highest levels of government on cryptocurrency and cyber issues. His investigative methodologies have been extensively cited in the Department of Justice's "Cryptocurrency Enforcement Framework."

His exceptional work has earned him numerous accolades, including: Secretary's Honor Award from the Secretary of the Treasury (2020) Chief's Investigative Excellence from IRS-CI (2020) Meritorious Service Award from the Secretary of the Treasury (2019)

Chris's expertise is frequently sought after, and he has been featured in various media, including Netflix's documentary "Biggest Heist Ever" about the Bitfinex hack.

Tim Rohrbaugh

Tim Rohrbaugh

Founder/Principal
RadicalNotion.AI, 3x Public Co. CISO

Tim Rohrbaugh brings 20+ years of C-level cybersecurity leadership to the frontier of AI for security and applied engineering. As founder of RadicalNotion.AI and former CISO of JetBlue Airways, he has built and operated enterprise programs that protect high-value, regulated data— including responsibility for safeguarding more than 40 million consumer records at a public financial services company.

A career security architect and systems engineer, Tim advances a practical view of GenAI as “augmented intelligence”: trustworthy, domain-tuned reasoning agents that reduce noise, challenge bias, and accelerate evidence-backed decisions without exposing IP. He has served as Vice Chair of the Airlines for America Cyber Security Council and as a board member of the Online Trust Alliance, where he contributed to national privacy and security policy. His work has been recognized with multiple awards, including Top Global CISO by Cyber Defense Magazine. Tim holds two joint patents in identity verification and authentication and is a frequent speaker and advisor to boards and engineering teams alike.

Carlo Nastasi

Special Agent Carlo Nastasi

Lead Agent – SAR Review Team & Liaison to the Private Banking Industry
IRS Criminal Investigation (IRS-CI)


Carlo Nastasi is a senior Special Agent with the Internal Revenue Service Criminal Investigation (IRS-CI), where he has led high-profile financial crime investigations for over 16 years. Specializing in money laundering, cyber-enabled financial crimes, and Bank Secrecy Act (BSA) violations, he currently serves as the lead agent on the Suspicious Activity Report (SAR) Review Team and as a key liaison to the private banking industry.

Agent Nastasi was instrumental in the groundbreaking $3 billion TD Bank case—the largest BSA-related fine and first major criminal plea of its kind—where his team uncovered systemic failures in onboarding, transaction monitoring, and compliance reporting. His insights into how traditional financial blind spots intersect with modern cyber threats have made him a sought-after speaker for both regulatory and cybersecurity audiences.

Before joining IRS-CI in 2008, Carlo was an Audit Senior at Deloitte & Touche and holds a degree in finance and accounting from Pace University. Over the course of his career, he has investigated international tax fraud, Ponzi schemes, political corruption, and cybercrime across fiat and cryptocurrency domains. He also previously served on an FBI task force supporting white-collar and political corruption investigations.

Carlo brings a unique perspective at the intersection of cyber risk, financial regulation, and criminal enforcement—and helps organizations understand the real-world consequences of getting it wrong.

Krista Valenzuela

Krista Valenzuela

Bureau Chief
Cyber Threat Outreach & Partnerships (CTOP) at the NJCCIC


Krista Valenzuela serves as the Bureau Chief of Cyber Threat Outreach & Partnerships (CTOP) at the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC). In this role, she leads statewide efforts to strengthen cyber resilience by raising awareness of emerging cyber threats, tactics, and techniques, promoting cybersecurity best practices, and fostering strategic partnerships with critical infrastructure, businesses, government agencies, organizations, and individuals throughout New Jersey and beyond.

An experienced cybersecurity leader and senior cyber threat intelligence professional, Krista has a proven track record in threat intelligence, intelligence analysis, team leadership, data analysis, report development, and public presentations. Her work focuses on translating complex cyber threats into actionable intelligence that helps organizations better defend against today's evolving threat landscape.

Prior to joining the NJCCIC, Krista supported the U.S. Department of Defense's information assurance mission, where she contributed to protecting critical systems and advancing national cybersecurity objectives.

Krista holds a Bachelor of Arts in International Studies from The College of New Jersey and is passionate about building collaborative partnerships that enhance cybersecurity awareness, preparedness, and resilience across both the public and private sectors.

FBI_Cyber_Division

Michelle Liu

Supervisory Special Agent, FBI Newark – Cyber Division

SSA Michelle Liu is a 14-year veteran of the FBI and currently serves as a Supervisory Special Agent in the Cyber Division of the FBI’s Newark Field Office. With deep expertise in national security, counterintelligence, and cybercrime, SSA Liu leads efforts to investigate and disrupt advanced threat actors targeting U.S. infrastructure and private sector organizations. She also serves as the Program Manager for Midnight Blizzard, one of the FBI’s highest-priority cyber initiatives. Known for her strong partnerships with industry, SSA Liu works closely with companies across New Jersey to share threat intelligence and support victims of ransomware, business email compromise, and emerging AI-driven threats.

Stan Field

Stan Field

Cybersecurity Advisor, CISA Region 2

Stan Field is a Cybersecurity Advisor with the Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), Integrated Operations Division (IOD), located within Region 2. Stan priorly served as the Chief Information Security Officer (CISO) for the County of Cumberland, New Jersey, from 2019 to 2025. Prior to his role in Cumberland County, he served 25 years with the New Jersey State Police as a Captain.

Stan is a graduate of Rutgers University and holds a Bachelor of Arts Degree in Pure Mathematics. He is also a graduate of Seton Hall University, where he holds a Master of Arts degree in Administration. Stan is certified as a Certified Fraud Examiner (CFE), a Universal Forensic Extraction Device (UFED) Mobile and Physical Examiner, and a Certified Electronic Evidence Collection Specialist. He also holds a prior certification by the International Association of Computer Investigative Specialists (IACIS) and a Certified Forensic Computer Examiner (CFCE).

HSI Badge

Jesse Imbergamo

Supervisory Special Agent , Homeland Security Investigations (HSI) in the Office of the Special Agent in Charge, New Jersey

Jesse Imbergamo is a Supervisory Special Agent with Homeland Security Investigations (HSI) in the Office of the Special Agent in Charge, New Jersey. He currently serves as the Group Supervisor of the Financial Fraud Group, which specializes in complex fraud and financial crimes investigations including elder fraud and exploitation, investment fraud, and money laundering. SSA Imbergamo began his career with HSI in 2018 in the New York City office. During his time in New York, he served on the El Dorado Task Force in the Undercover Operations Group, where he specialized in infiltrating and dismantling international drug trafficking and money laundering organizations. He began his role as Group Supervisor in the New Jersey office in 2025. >

Prior to his position with HSI, SSA Imbergamo was a detective with the New Orleans Police Department (NOPD) where he worked on an interagency task force responsible for investigating serial armed robberies and gang related shootings. He also served on the NOPD’s Special Weapons and Tactics (SWAT) Team and the Dive Team.

Otto Hernandez

Dr. Otto Hernandez

Vice President - Academic Affairs, Atlantic Cape Community College

During his 40+ years at Atlantic Cape, Dr. Otto Hernandez has served as Department Chair multiple times, Dean of STEM, and Vice President of Academic Affairs (CAO). Currently, he is serving as Department Chair for Aviation, Business and Technology programs. During his tenure at ACCC, he has participated in the creation of multiple courses and degree programs focusing on both AS and AAS degrees in aviation and computing. Additionally, Otto has participated in the creation of multiple articulation agreements with four-year colleges and universities. Currently, Otto is part of the research team on a three-year grant from the National Science Foundation to create Industry-Linked AI and Machine Learning Pathways for Computer Programmers.

michael zambotti

Michael Zambotti

Professor, Saint Francis University

Mr. Michael Zambotti joined the faculty at Saint Francis in 2021. He is passionate about cybersecurity and has a specific interest in Open Source Intelligence (OSINIT) as well as cyber incident response and management. Michael is devoted to his students and promotes student success and growth through a combination of engagement and responsiveness. In addition to teaching at Saint Francis, Michael is an Adjunct Lecturer in the Graduate Cybersecurity program at Utica University. He also works as a Client CIO at Miles Technologies in Lumberton, NJ.

Sharon Kelley

Sharon Kelley

Executive Director for Information Security & CISO, New Jersey Institute of Technology

Sharon Kelley, CISSP, CCSP is the Executive Director of Information Security and Chief Information Security Officer at the New Jersey Institute of Technology. A cybersecurity executive with more than two decades of experience, she specializes in building security programs, strengthening cyber resilience, and translating complex risks into practical strategies that support education, research, and innovation. Sharon is a Board Member of the ISC2 New Jersey Chapter and is a frequent speaker on cybersecurity leadership, research security, workforce development, and emerging technologies, with a passion for building the next generation of cybersecurity professionals.

Aakash Taneja

Aakash Taneja

Professor of Computer Information Systems, Stockton University

Aakash Taneja, Ph.D., PMP, is a Professor of Computer Science and Information Systems at Stockton University, where he brings together academic research, cybersecurity expertise, and practical experience in information technology. He has served in leadership roles within Stockton’s computer science and information systems programs, including as CSIS Program Coordinator.

Dr. Taneja’s research and professional interests include cybersecurity, critical infrastructure security, human factors in cybersecurity, social engineering, and the intersection of technology and organizational risk. His research has examined cybersecurity challenges associated with the modernization of critical infrastructure and the human and behavioral factors that influence susceptibility to cyber threats.

He is also actively engaged in cybersecurity research and education, contributing to research on topics including AI trust dynamics, phishing victimization, and emerging cybersecurity risks. His work reflects a multidisciplinary approach that connects technical cybersecurity issues with human behavior and organizational decision-making.

Dr. Taneja holds a Ph.D. in Computer Science and is a Project Management Professional (PMP). Through his teaching, research, and program leadership, he works to prepare students and professionals to address the increasingly complex cybersecurity challenges facing organizations and critical infrastructure.

Mark Eggleston

Mark Eggleston, CISSP, GSEC

CISO, confidential

Mark Eggleston is the SVP and chief information security officer (CISO) at a yet to be disclosed global company within the Vista Equity Partners portfolio, responsible for the global security program design, operations and continual maturation. As a senior executive specializing in security and privacy program development and management, Mark’s unique background and expertise in information technology, program, and people management have positioned him as a thought leader and frequent industry speaker.

Mark started his career as a program manager and psychotherapist at a hospital serving children and adolescents. Later, Mr. Eggleston helped develop an internal compliance approach—complete with policies and tools—ensuring a geographically dispersed health care provider organization (across 19 states) complied with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Mr. Eggleston then transitioned to applying his HIPAA expertise at an HMO where he has implemented many successful security controls and technologies, including single sign-on (SSO), Identity and Access Management (IAM), Cloud Access security broker (CASB), and a vulnerability assessment program. Thereafter he led the global security program at CSC, a large business services company.

Mark received his Bachelor of Science in psychology from Radford University. Later, Mark received both his Master of social work and his post-baccalaureate certificate in management information systems from Virginia Commonwealth University. In addition, Mark holds GSEC and CISSP certifications.

Brian Callahan

Dr. Brian Callahan

Director of Cybersecurity Research and Specialist Professor of Computer Science and Software Engineering, Monmouth University

Dr. Brian Robert Callahan is Director of the Cybersecurity Research Center and a Specialist Professor of Computer Science and Software Engineering at Monmouth University, where his work explores the intersection of cybersecurity with emerging technologies including generative AI and quantum computing.

Previously, Brian founded and led the Rensselaer Cybersecurity Collaboratory at Rensselaer Polytechnic Institute, directing applied research spanning quantum security, AI/ML, blockchain, software security, and cyber defense. His student teams have earned national recognition, including a #1 national Cyber Power Ranking, while his research has received support from IBM and other organizations.

A cybersecurity practitioner, researcher, educator, and OpenBSD developer, Brian holds credentials including CISSP, ISSMP, CCSP, CISM, and CCSK. He brings a rare ability to connect deeply technical developments with the strategic, business, and societal questions cybersecurity leaders increasingly need to understand.

Dalal Samaan

Dalal Samaan

Chief Information Security Officer, Keenova

Dalal Samaan serves as the Chief Information Security Officer at Keenova Therapeutics. In her previous role at Organon, she was the Executive Director of the Healthcare Compliance Monitoring and Analytics program and served as the Interim Chief Privacy Officer.

Before joining Organon, Dalal built an extensive career in Information Risk Management and Network Services at Merck & Co., Inc.

Dalal Samaan holds a Bachelor of Science degree in Electrical Engineering and Computer Science from NYU-Polytechnic School of Engineering. She also earned a Master of Science degree in Telecommunications Management from Stevens Institute of Technology. In addition, she currently maintains CISSP and CIPT certifications.

Danny Zakharia

Danny Zakharia

Chief Information Security Officer, Children's Hospital of Philadelphia

Danny Zakharia, CISSP is an enterprise Cybersecurity leader with over 30+ years of experience building resilient, business-aligned security programs for global organizations such as Comcast, CVS, and SEPTA.

Danny has built a reputation for designing cloud security strategies that reduce enterprise incidents and risks while actively supporting high velocity corporate growth.

Currently leading a major security reboot at CHOP, Danny's team is tasked with safeguarding critical infrastructure ensuring regulatory compliance (such as SOC2, ISO 27001, HIPAA/HiTrust) and managing corporate incident response.

A frequent speaker on board-level risk communication and cyber security resilience/governance, Danny holds multiple industry credentials as well as a bachelor of science in Electrical Engineering from Drexel U. and Master of engineering in computer engineering from Widener U.

Michael Hiskey

Michael Hiskey

[Moderator] Founder, CxO Security Forum | Author | Speaker | Executive Strategist

Michael Hiskey is an author, blogger, and speaker with more than 20 years of experience in enterprise B2B strategy across cybersecurity, fintech, data, and AI. His work has appeared in Forbes, InformationWeek, WSJ.com, ITProPortal, and he has been featured on CNBC and C|Net.

A seasoned executive, Michael has held Chief Marketing Officer and Chief Strategy Officer roles at companies including Avanan, Socure, Semarchy, Trifacta, and Data Connectors, as well as leadership positions at IBM and MicroStrategy. He has lived and worked on three continents, managing global teams and driving measurable ROI for complex organizations.

Michael is the founder of the CxO Security Forum, a community-led network reinventing how executives connect for education, mentoring, and peer exchange. Having moderated and organized hundreds of cybersecurity conferences, roundtables, and executive forums, he is dedicated to creating practitioner-first environments that foster collaboration between industry, government, and academia.

He holds an MBA from Columbia Business School, and lives on Long Island with his wife and two daughters. More at linkedin.com/in/mphnyc.

About CxO Forum

CxO Security Forum began as a response to a common frustration among senior cybersecurity leaders: the way enterprise solutions are marketed, sold, and evaluated is fundamentally broken. What started as a call for change has grown into a trusted community that puts executive practitioners at the center of the conversation.

We bring together CISOs, CIOs, and senior decision-makers who are responsible for protecting their organizations, guiding strategic risk, and navigating the evolving role of AI in security. Every forum, gathering, and conversation is designed to foster education, mentoring, and authentic peer connection.

What makes us different is our focus on relationships. Our events are intentionally small, curated, and built for real dialogue. Sponsors are carefully selected, and there are no product pitches. Participants come for thoughtful, actionable conversations that support both professional development and practical decision-making.

At CxO Security Forum, the goal is simple. Give experienced leaders a space to learn from one another, to share insight, and to build meaningful connections that last beyond the event itself.

Add Your Heading Text Here

Participation is free for qualified senior executives  

Location

Stay tuned, location forthcoming

Atlantic Cape Community College

5100 Black Horse Pike, Mays Landing, NJ 08330

Registration

Registration is open only to qualified executives (excluding Sales, Marketing, and Business Development!)

Early Registration is just $25

© 2025 CxO Security Forum. All rights reserved