The NorthEast Annual Cybersecurity Summit (NEACS) has a wonderful history in the New England area, with ten years of community-focused gatherings, generally in/around Trumbull, CT. After a brief hiatus, the CxO Security Forum has picked up the effort from the ISC2 Connecticut Chapter and expanded it to include virtually all of the local information security-oriented professional associations, who are generally nonprofit, member-driven organizations with a national or international affiliation.
Moreover, following the CxO Security Forum format, the Summit has a deeper and more expansive focus to feature relevant state and federal government agencies that have a focus on cybersecurity and fraud prevention.
(includes Breakfast, lunch, full conference pass & CPEs!)
Supporters:
Only 10 non-competitive Solution providers will be invited to sponsor, and must be vetted by the Community.
📊 Cyber Industry Outlook 2026 — Solution Providers, investment trends, and product sprawl: what’s coming next
🤖 Securing AI — defending against AI-driven attacks and building safe, trustworthy models
🕵️ Law Enforcement Case Studies — fresh insights from FBI, HSI, IRS-CI, USSS, and state partners
💳 Fraud + Cyber Convergence — where financial crimes meet cybersecurity, and how leaders can respond
🔐 Zero Trust in Practice — reframing as risk strategy vs. products & services
🧑💼 CISO Leadership Challenges — hiring, budgeting, and governance in an era of AI disruption
🏥 Cybersecurity in Regulated Sectors — lessons from healthcare, financial services, and critical infrastructure
🌐 Public–Private Partnerships — improving collaboration between agencies and enterprises
⚡ Emerging Threats Roundtable — interactive discussion on AI-powered intrusions, ransomware, and supply chain attacks
🎤 Keynotes from industry authors, analysts, and global experts
🔄 Moderated discussion pods — real-time audience-driven dialogue
🤝 2+ hours of curated networking with peers and vetted Solution Providers in the Solutions Showcase
You can review the agenda, as well as a summary with detailed notes from last year's NEACS
(click the document icon above)
Stay informed about the upcoming CxO Security Forum. Subscribers receive early access to the full agenda, speaker lineup, and venue details, along with reminders about key dates and networking opportunities.
Event communications are concise, relevant, and tailored to support your planning. Signing up ensures you have the information you need to make the most of your forum experience from the moment the doors open.
The Forum is a collaboration point for the many member-driven professional associations across the region. Hear a brief introduction from Board Members of each of those InfoSec & Fraud Associations as we open the agenda
9:20 AMRichard Stiennon, veteran analyst and industry provocateur will kick off the Forum, taking us on a data-rich tour of the entire cybersecurity industry—all 4,550 vendors, 660 subcategories, and $12 billion in recent funding. Drawing from his forthcoming book Security Yearbook 2025, Stiennon will share insights derived from two decades of studying cyber trends at Gartner and now IT-Harvest—the only firm systematically cataloging the global cyber vendor ecosystem.
This talk is not just about the numbers. Richard will break down the practical implications for executives:
He’ll also spotlight key global dynamics, such as Israel’s IDF-fueled innovation engine, Germany’s vendor loyalty culture, and the emergence of AI Security as a distinct and fast-growing segment.
If you’ve ever asked “What should I actually be paying attention to in cybersecurity right now?”—this is your answer. This session will set the tone and context for the day, offering a strategic foundation for every discussion that follows.
9:45 AMChase Cunningham, Ph.D. the Author of “Buy the Breach: Hacking Failure for Market Success,” is also known to cyber leaders as “Dr. Zero Trust.” He will lead a fun, informative, and thought-provoking talk which will lead into what should be an eye-opening discussion!
In this talk, he shines a spotlight on one of cybersecurity’s most under-explored truths: the market *rewards* failure. Drawing from his groundbreaking book, Chase walks through how cybersecurity professionals—yes, you—can outperform hedge funds without ever learning complex finance. Just by applying the same analytical skills you use to track vulnerabilities and threat actors, you can spot profitable market patterns tied to breaches, outages, and incidents.
This isn’t theoretical: Chase will share real-world portfolio results, case studies from Marriott, Equifax, CrowdStrike, and others, and the exact strategy he uses to buy low during breach-triggered panic and ride the inevitable recovery wave.
Participants will learn:
Then stay for the live *Buy the Breach* discussion with Chase, where he’ll answer tough questions, unpack recent breach-related trades, and offer practical guidance on turning your cybersecurity expertise into a market edge.
Bottom line: If you're already protecting companies from failure, why not learn to profit when others don’t? The game is rigged—this session shows you how to beat it.
10:15 AMIn this talk, government agency leaders will share how they approach coordinated threat disruption, interagency collaboration, and executive-level response to cyber-enabled crimes.
When cybercrime intersects with national security, terrorism, cross-boarder issues, or financial stability, the US Secret Service, Department of Homeland Security, FBI and state fusion center (NJCCIC) step in—not just with investigations, but with leadership. Drawing from real-world cases—ranging from cryptocurrency scams to insider threats—RAIC Cerra will outline lessons learned for private-sector leaders.
What does it take to lead under pressure, across jurisdictions, and in defense of critical assets? In this fast-moving session, participants will get practical takeaways on how to elevate their cyber leadership posture—and why the most effective defenders think like protectors, not just responders.
10:45 AMExecutive Panel - In this candid, discussion-driven session, three leading CISOs from major healthcare systems will share how their teams are balancing governance, compliance, data integrity, data governance and security while embracing AI.
Healthcare is one of the most highly regulated, risk-sensitive industries—and yet it’s also at the forefront of adopting AI and advanced cybersecurity practices. Hospital CISOs don’t have the luxury of waiting; they are already governing and securing generative AI platforms that enable improved outcomes and enable innovation.
Topics will include:
You’ll hear what’s working in practice, how healthcare CISOs prioritize risk when stakes include both lives and liabilities, and why enterprise leaders across finance, manufacturing, retail, and government should be watching this space closely.
If you want to understand where AI and cybersecurity are really converging, this is the session to attend. Healthcare may be the proving ground—but the implications are universal.
Panelists
Kurtis Minder has spent the last decade doing what most cybersecurity professionals only read about—negotiating directly with cybercriminals, including ransomware gangs, nation-state affiliates, and digital extortionists. As the founder and CEO of GroupSense, Minder built a world-class cyber espionage team, managing over 4,000 personas in multiple languages. He helped victims navigate headline-making ransomware attacks, and briefed everyone-from Congress to the Intelligence Community.
In this gripping, TED-style keynote, Kurtis draws from his new book, Cyber Recon, and his real-world experience leading some of the largest ransomware response efforts globally. He’ll walk attendees through the tradecraft of cyber reconnaissance, the nuances of engaging threat actors using mindful negotiation, and what it really takes to protect your organization in today’s hostile digital landscape.
Blending operational insights with personal stories—from fake identities like “Vinny,” to briefing Congressional subcommittees—Kurtis offers a rare, behind-the-scenes look at the human element of cyber conflict. Whether you lead security for a Fortune 500 or a regional bank, you’ll leave with concrete lessons on digital risk, negotiation, and resilience in the age of cybercrime.
Participants will enjoy a lovely full hot lunch while connecting with the thoughtful Solution Providers who are supporting the community at the Atlantic City CyberSecurity & Fraud Forum
12:15 PMMark Sangster goes beyond the headlines and surface-level frameworks to expose the invisible forces that shape today’s most devastating breaches. Drawing from his books “Cyber-Conscious Leadership” and “No Safe Harbor,” Mark unpacks real-world case studies—ransomware attacks that began as innocent supplier emails, regulatory landmines triggered by seemingly minor missteps, and grey zone attacks that blur the lines between criminal and nation-state actors.
As cybersecurity is recognized as a board-level issue, what is less clear is how to lead effectively in a world where the threat landscape is shaped by geopolitics, systemic business vulnerabilities, and adversaries who don’t play by rules.
Leaders at the Forum will walk away with:
Not just about protecting your company—it’s about sharpening your strategic edge as an executive.
1:00 PMSupervisory Special Agent Michelle Liu will share 2024 threat intelligence from the FBI’s national cyber program, including updates on ransomware recovery efforts, business email compromise, AI-enabled criminal tools, and the FBI’s role in supporting victims across industries. She’ll highlight real-world examples and underscore how early reporting and collaboration can lead to faster response and even cryptocurrency recovery.
As cyber threats evolve—from AI-powered voice cloning to digital currency-based ransomware—so too must the partnerships built to defend against them. In this joint session, attendees will hear directly from the FBI Newark Field Office’s Cyber Division and leaders from the New Jersey InfraGard Members Alliance, a critical public-private partnership for protecting U.S. infrastructure.
Joining the session are representatives from InfraGard NJ, who will explain how their organization connects cybersecurity professionals with government experts to strengthen community resilience and critical infrastructure protection. Attendees will learn how to get involved, what data can be safely shared, and why InfraGard’s model of trusted collaboration is more relevant than ever.
Whether you're in finance, healthcare, energy, or education, this session offers practical insights and concrete steps to deepen your engagement with law enforcement, reduce response times, and build a safer digital ecosystem.
1:30 PMWhat the Largest Bank Fine in U.S. History Means for Cybersecurity Leaders
IRS-Criminal Investigations will talk us through what started as a routine money laundering investigation and then became the largest criminal BSA case in U.S. history: TD Bank pled guilty and paid a record-breaking $3 billion fine for failing to detect and report financial crimes between 2018 and 2024. But this wasn’t just a banking compliance failure—it was a breakdown of fundamental controls that cybersecurity teams should recognize as eerily familiar: weak identity verification, outdated monitoring tools, no internal escalation, and massive blind spots in onboarding.
With the passage of the AI Clarity Act and GENIUS Act, any company involved in digital asset transactions—especially fintechs and crypto-related entities—will now fall under the Bank Secrecy Act (BSA). That means cybersecurity functions may be criminally liable if they fail to detect malicious or illicit behavior.
This session reframes cybersecurity risk from “fear of breach” to fear of prosecution. If your organization touches crypto, stablecoins, or manages digital financial flows, this talk is your wake-up call. Learn what went wrong at TD, how BSA violations can stem from cyber failings, and what proactive cyber leaders should do now to protect not just their companies—but themselves.
1:45 PMFraud is no longer just a cost of doing business—it’s a security issue. More organizations are merging fraud prevention and cybersecurity into unified teams and frameworks to confront shared threats more effectively. This session explores the rise of Cyber-Fraud Fusion, where cyber threat intel, identity protection, and fraud operations are integrated to create a layered defense.
We’ll highlight how enterprises across industries are shifting from reactive fraud tools to proactive, intelligence-driven strategies—using concepts like the Cyber-Fraud Kill Chain to identify and disrupt attacks earlier. Attendees will gain a practical understanding of how convergence improves detection, response, and cross-functional coordination.
2:00 PMThis panel discussion features a real-world exchange between cyber educators and industry leaders. Professors will share how they’re designing programs with hands-on labs, industry-funded projects, and even high school hackathons. CISOs and CTOs will weigh in on the “last-mile” problem: grads with zero experience, mismatched expectations, and a professionalism gap that’s hard to ignore.
With over 700,000 unfilled cybersecurity jobs in the U.S., you’d think the hiring problem would solve itself. But here’s the rub: cybersecurity programs are churning out grads, and CISOs still ask, “What can they actually do on day one?” Are they SOC-ready? Do they understand fraud prevention, governance, compliance—or even what cybersecurity is?
We’ll dig into big questions:
Come for the honest dialogue, stay for the practical takeaways—and leave with a few ideas for fixing a system that isn’t working for educators, employers, or students.
2:30 PM
Dr. Robert Riegle—former DHS Director and national intelligence expert—will challenge participants to rethink how authenticity, attribution, and assurance must be redefined at the device and data layer. In today’s environment of AI-driven disinformation, autonomous systems, and rising threats to critical infrastructure, the old model of “trust but verify” no longer cuts it. We must now verify before we trust—especially when it comes to operational technology, hardware identity, and machine-level decision-making.
In this provocative talk, he will be drawing on his national security background and work with emerging identity technologies, Dr. Riegle will explore how edge devices, autonomous systems, and even supply chains must be provably trustworthy to support U.S. counter-terrorism, counter-intelligence, and cybersecurity goals.
Following the talk, a moderated discussion will open the floor for participants to explore practical implications—how to support policy shifts, certify device lineage, and adopt technologies that “burn in” authenticity at the point of creation.
3:00 PMIn Closing - We’ve heard from the spies and the scientists. The agents and the analysts. The CEOs, strategists, and storytellers. Now, as we close the 2nd Annual Atlantic City CyberSecurity & Fraud Forum, we return to the reason we came together in the first place: to make a difference.
In this final session, we’ll recap the boldest ideas, sharpest warnings, and most actionable takeaways shared throughout the day—from ransomware negotiation tradecraft to the market forces behind cyber failures, from AI-fueled attacks to law enforcement collaboration models that actually work.
But more than a summary, this is a call to action. Whether you’re protecting a regional bank, a global enterprise, or your local community college’s network, the mission is the same: build trust, verify identity, out-think the adversary—and never go it alone.
Join us to reflect, reconnect, and recharge for what comes next. Because the future of cybersecurity and fraud prevention isn’t just about staying ahead of threats—it’s about leading with purpose, and leaving with a plan.
3:30 PMStay & Connect: Informal Networking + Solution Showcase
Before hitting the road, grab a coffee and take time to connect. Trade insights with peers, chat with Solution Providers, and follow up on the ideas sparked throughout the day.
No panels, no pitches—just real conversations to wrap things up right.
4:00 PMStay informed about the upcoming CxO Security Forums.
Subscribers receive early access to the full agenda, speaker lineup, and venue details, along with reminders about key dates and networking opportunities.
Event communications are concise, relevant, and tailored to support your planning. Signing up ensures you have the information you need to make the most of your forum experience from the moment the doors open.
Chief Research Analyst - IT Harvest
frmr. VP of Research - Gartner
Richard founded IT-Harvest in 2005 to cover the 4,550+ vendors that make up the IT security industry. He has presented on the topic of cybersecurity in 32 countries on six continents. He was a lecturer at Charles Sturt University in Australia. He is the author of Surviving Cyberwar (Government Institutes, 2010) and Washington Post Best Seller, There Will Be Cyberwar, as well as the annual Security Yearbook, published by Wiley for 2025. He was the VP of Research at Gartner. He has a B.S. in Aerospace Engineering from the University of Michigan, and his MA in War in the Modern World from King’s College, London.
Quinnipiac University - Program Director Cyber & Associate Teaching Professor
Postulating a better connection for industry and academic in cybersecurity, with specific focus on regulated industries lie financial services and healthcare
Dr. Zero Trust
Dr. Chase Cunningham, “Dr. Zero Trust,” is an internationally recognized cybersecurity expert and has been a key strategist in a variety of corporate endeavors as well as a valuable consultant to the US DoD and the Executive Branch. With over two decades of experience in cybersecurity, Dr. Cunningham has earned a reputation as a thought leader and visionary in the field, specializing in Zero Trust security architecture, threat intelligence, and advanced cyber defense strategies.
His career has been marked by a series of influential roles in both the public and private sectors. He served as a Senior Analyst at Forrester Research, where he developed the firm’s highly regarded Zero Trust framework, which has become the industry standard for cybersecurity strategy. Prior to that, he held pivotal roles in the U.S. Navy, where he worked on advanced cryptographic systems and cybersecurity operations, contributing to national defense efforts.
A frequent keynote speaker at major cybersecurity conferences, he is known for his ability to distill complex security challenges into actionable insights. He has authored numerous white papers, articles, and books on cybersecurity, and his work is regularly cited by industry leaders, government agencies, and academic institutions. His most recent book, Cyber Warfare: Truth, Tactics, and Strategies, has been added to the national cybersecurity canon hall of fame and has been praised as essential reading for cybersecurity professionals and strategists.
Chase holds a PhD in Computer Science and Cybersecurity from Colorado Technical University, where his research focused on advanced threat detection and algorithmic detection of insider threat tactics. He is also a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker (CEH).
Principal, LLM Strategic Solutions & CISOonCall, 3x Public Co. CISO
Applied GenAI for Cybersecurity, a discussion of in-house LLMs - focus on using the strengths of AI to positively affect security operations
Cybersecurity Author, Strategic Advisor, and Storyteller of the Unseen
Mark Sangster (mbsangster.com/) is a recognized authority on cybersecurity risk and a compelling voice in the fight against digital crime. A celebrated author and award-winning speaker, Mark brings a unique ability to distill complex cyber threats into practical, boardroom-ready insights. His books, No Safe Harbor and Cyber-Conscious Leadership, challenge conventional thinking by exposing the stories that don’t make headlines—highlighting the human and systemic failures behind major breaches.
Mark’s thought leadership spans industries and continents, with appearances on major stages including Harvard Law School and RSAConference, and contributions to The Wall Street Journal, CSO Magazine, and other leading media. He’s an advocate for shifting the cybersecurity conversation away from technical jargon and toward real business risk—translating the language of threat intelligence into the language of leadership.
With deep insight into emerging threats, geopolitical risks, and the psychology of cybercrime, Mark arms executives with the frameworks they need to lead resilient organizations. Whether drawing parallels between cyberattacks and aviation disasters or unraveling the hidden mechanics of “grey crime,” Mark’s work is as thought-provoking as it is actionable.
At the Forum, expect a conversation that’s more than informative—it’s transformative.
FBI New Haven
SSA Michelle Liu is a 14-year veteran of the FBI and currently serves as a Supervisory Special Agent in the Cyber Division of the FBI’s Newark Field Office. With deep expertise in national security, counterintelligence, and cybercrime, SSA Liu leads efforts to investigate and disrupt advanced threat actors targeting U.S. infrastructure and private sector organizations. She also serves as the Program Manager for Midnight Blizzard, one of the FBI’s highest-priority cyber initiatives. Known for her strong partnerships with industry, SSA Liu works closely with companies across New Jersey to share threat intelligence and support victims of ransomware, business email compromise, and emerging AI-driven threats.
CEO & Co-Founder, GroupSense
Author, Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation
Kurtis Minder is one of the world’s foremost experts in ransomware response and cyber threat intelligence. As CEO and co-founder of GroupSense, he has led negotiations in some of the largest ransomware and data extortion cases globally, engaging directly with threat actors and nation-state affiliates.
With over 25 years in cybersecurity—including roles at Fortinet, AT&T, and Citrix-acquired Caymus Systems—Kurtis has combined operational security, cyber reconnaissance, and real-world intelligence tradecraft into a uniquely effective digital risk strategy. His pioneering work and insights have been featured in The New Yorker, BBC, The Wall Street Journal, and Fortune.
At ACCSFF 2025, Kurtis will deliver a TED-style keynote and participate in a moderated discussion on themes from his acclaimed new book, Cyber Recon, offering a rare behind-the-scenes look at the people, tools, and tactics behind today’s cyber espionage and ransomware ecosystem.
CEO, TripleID | Former Director, U.S. Department of Homeland Security
Dr. Robert Riegle is a nationally recognized authority on intelligence sharing, critical infrastructure protection, and national security policy. He currently serves as CEO of TripleID, a company pioneering next-generation identity and authenticity solutions for operational technology, edge devices, and autonomous systems.
Previously, Dr. Riegle served as Director of the State and Local Program Office within the Office of Intelligence & Analysis at the U.S. Department of Homeland Security (DHS), where he was instrumental in shaping the national intelligence-sharing framework between federal agencies and state and local Fusion Centers. As a senior executive and intelligence officer, he co-led DHS-wide efforts to formalize policy for interagency collaboration and helped align intelligence coordination across multiple domains, including counterterrorism, cyber, and counterintelligence.
His earlier roles include serving with the Defense Intelligence Agency in support of Operations Iraqi Freedom and Enduring Freedom, and in leadership positions at Booz Allen Hamilton, Chevy Chase Bank, and Indeck Power. A veteran with multiple commendations, Dr. Riegle holds a J.D. from The Catholic University of America and a B.S. in Government from the University of Maryland.
Dr. Riegle brings a unique lens to today’s challenges at the intersection of national security, technology, and trust—championing the need for verifiable authenticity in the systems we rely on most.
Award winning CISO, top-rated keynote speaker & bestselling author
A frank disucssion on the mistakes most CISOs are making when it comes to the cybersecurity budget, planning, hiring, and purchasing processes
Artificial intelligence (AI) is reshaping the landscape of cybersecurity governance, risk, and compliance (GRC), presenting both transformative opportunities and complex challenges. This session addresses the critical question facing executives: how can we harness the innovative potential of AI while managing its inherent risks and meeting regulatory demands?
CxO Security Forum began as a response to a common frustration among senior cybersecurity leaders: the way enterprise solutions are marketed, sold, and evaluated is fundamentally broken. What started as a call for change has grown into a trusted community that puts executive practitioners at the center of the conversation.
We bring together CISOs, CIOs, and senior decision-makers who are responsible for protecting their organizations, guiding strategic risk, and navigating the evolving role of AI in security. Every forum, gathering, and conversation is designed to foster education, mentoring, and authentic peer connection.
What makes us different is our focus on relationships. Our events are intentionally small, curated, and built for real dialogue. Sponsors are carefully selected, and there are no product pitches. Participants come for thoughtful, actionable conversations that support both professional development and practical decision-making.
At CxO Security Forum, the goal is simple. Give experienced leaders a space to learn from one another, to share insight, and to build meaningful connections that last beyond the event itself.
370 Bassett Road
North Haven, Connecticut 06473
Registration is open only to qualified executives (excluding Sales, Marketing, and Business Development!)
© 2025 CxO Security Forum. All rights reserved