NYC CxO Security Forum

Quarterly Executive Briefing

Tuesday 29 September 2026

Days
Hours
Minutes
Seconds

A Private, Peer-Led Forum for Cybersecurity Leaders

CxO Security Forum brings together senior executives in cybersecurity, risk, and compliance to engage in peer-driven dialogue — not one-way presentations or vendor pitches. Our curated discussions are designed to elevate strategic decision-making, sharpen leadership perspective, and support both professional growth and personal mastery in today’s complex threat landscape.

Each Executive Briefing has a unique agenda, which follows our engaging format with Discussion Leaders and thoughtful “TED Talk” presentations followed by moderated conversations where the assembled executives from the Community share their best practices, experiences, lessons learned, etc. 

Participants gain: 

  • Trusted peer insight: candid discussion with leaders facing the same strategic challenges
  • Personal & professional growth: sharpen leadership and strategic judgment through real executive exchange
  • Actionable dialogue: moderated, high-impact conversations focused on what matters now
  • No noise, no pitches: gatherings where peers drive the agenda and learning
  • Stronger decision confidence: discussions that help you avoid costly missteps and evaluate solutions with clarity

Next Forum Agenda

As with past NYC CxO Security Forum briefings, the February gathering will feature a tightly curated agenda built around real-world insight, peer experience, and practical guidance — not theory or sales pitches.

Planned discussions and briefings will include:

 

  • Agentic AI in the Enterprise
    A practitioner-focused discussion on where agentic AI is already being deployed, where it’s creating new risk, and how leading organizations are thinking about governance, controls, and accountability.

  • Learning from High-Profile Breaches (TBC)
    Candid perspectives from nationally recognized CISO peers, examining recent, well-publicized breaches — what actually happened, what was missed, and what leaders would do differently with the benefit of hindsight.

 

  • Workforce, Talent, and the Security Organization
    Insight from one of the world’s largest staffing firms on how cybersecurity, risk, and compliance teams are evolving — including hiring trends, organizational design, and where leaders are struggling to find (and retain) critical skills.

  • New Thinking from Leading Authors
    Select authors will share ideas from their latest work, offering fresh perspectives on leadership, risk, security, and the changing role of the CxO — with time reserved for discussion and audience engagement.

  • Legal, Regulatory, and Liability Realities
    A partner from a major law firm will share insights drawn from real client cases and advisory work, covering today’s most pressing issues around regulation, security, privacy, liability, and the use of AI in business applications — with a focus on practical guidance leaders can apply immediately.

As always, each session will be succinct, moderated, and discussion-driven, building toward a cohesive set of takeaways rather than disconnected presentations.

Thank You to Our Partners

Agenda

Our community-led gatherings ALWAYS have an amazing agenda filled with thoughtful Discussion Leaders and security, risk, & compliance influencers – including nationally-recognized authors and cyber-celebrities! 

June 2026 Agenda & Summary

LOOK BACK:  You can review the agenda, as well as a summary with detailed notes from our last New York City CxO Security Forum. 

(click the document icon above)

Registration & Networking

3:00 PM

Welcome/Introductions

3:15 PM

Agentic AI Meets Zero Trust: What Actually Breaks—and How to Fix It
[Discussion Pod #1]

Josh Woodruff is the Author of "Agentic AI + Zero Trust," a former CISO, and a long-time advisor in the industry. He will talk more about the years of research that went into the book. 

In the rush to deploy autonomous/semi-autonomous AI, Community Members have shared their doubts that existing identity, data, and control frameworks are ready. Drawing from years of research for his book and field experience, Josh will share:

  • Why most agentic AI initiatives fail operationally, not technically
  • How Zero Trust principles must evolve for AI agents, workflows, and non-human identities
  • Where security teams need to rethink identity, authorization, and monitoring
  • What CISOs and CIOs can do now to avoid costly architectural mistakes

This session blends short-form insights with moderated group discussion, focused on immediately actionable takeaways for enterprise leaders.

3:20 PM

Start-Up Showcase #1: OT Security's Missing Control Layer?

Josh Ross – Founder & CEO, IronLoop

Josh will introduce a hypothesis that OT security may be missing a dedicated configuration control layer—one designed to validate design intent, understand the impact of change, and provide greater confidence in operational resilience and compliance.

This brief session is intended as a conversation starter, inviting executive feedback on how this emerging approach addresses a meaningful gap in today's OT security stack.

3:50 PM

The Missing Metric in Third-Party Risk Management?
[Discussion Pod #2]

Jeremy Huval
Chief Innovation Officer, HITRUST

What level of risk are we actually accepting?

Jeremy will provide an early look at a new approach designed to help organizations translate disparate assurance artifacts into a more consistent and actionable measure of cyber risk. Drawing on emerging work currently being evaluated by leading enterprises, this discussion explores whether the industry may finally be moving toward a common language for understanding and comparing third-party risk.

This session will include an opportunity for interested organizations to learn more about a limited pilot program currently being evaluated by select enterprise teams.

Read More3:55 PM

Beyond the Headlines: Executive Accountability, Regulatory Pressure, and the Reality of CISO Risk
[Discussion Pod #3]

Tim Brown - Chief Information Security Officer & VP at SolarWinds is one of the most nationally recognized CISOs in the industry (perhaps in history?)

He was previously the subject of the first U.S. SEC enforcement action brought personally against a sitting CISO—a case that was ultimately dropped. In this candid, practitioner-to-practitioner discussion, Tim will go beyond public reporting to explore:

  • What the SEC action actually felt like from inside the role
  • How regulatory scrutiny is changing executive decision-making
  • Where CISOs should draw sharper lines between accountability, authority, and governance
  • Practical lessons for security leaders navigating board relationships, disclosure, and personal risk

This talk and our subsequent moderated discussion is a rare opportunity to hear directly from an executive who has lived through a defining moment for the profession—and emerged with a clear, actionable perspective. 

4:25 PM

Networking & Organized Interaction Break

5:00 PM

AI-Native Identity: Why IAM Is Being Rewritten
[Discussion Pod #4]

Barak Perelman is a industry veteran and the Founder & CEO of Opti.ai.  Fresh from a well-received presentation at the Gartner IAM Summit, Barak will reprise and expand on his research gathering input from dozens of your peers around identity.

To move identity from the current hodge-podge of big vendor solutions with “2025 AI-washed” marketing to real “baked in” AI is hindered by structural issues related to governance and accountability. Barak looked in detail at this from a risk-based approach and will share actionable insights for participants they can readily apply with their teams.

5:30 PM

Start-Up Showcase #2: The Insider Threat Problem We Still Haven't Solved

Casper Neo - Founder & CEO, Palace Cybersecurity  (nee Google) 

Identifying when legitimate access is being used in ways that were never intended remains a challenge. 

Drawing on research developed and deployed at Google and recently presented at Black Hat, Casper Neo will provide a brief look at a new approach that applies modern recommendation-system techniques to insider threat detection and access governance. The concept is simple but provocative: can security teams learn what access should look like well enough to recognize what does not belong?

6:00 PM

Reception & Networking

Cyber author book signing!

Refreshments, food, cocktails & discussions till 8pm

**Meet the Author: Josh Woodruff**

One of the industry's leading voices on the intersection of AI, identity, and Zero Trust, Josh Woodruff will share insights from his latest research on how Agentic AI is reshaping security architectures, trust models, and access governance.

Forum Participants will receive the opportunity to meet Josh personally and obtain a FREE signed copy of his new book, *Agentic AI + Zero Trust*—a practical executive guide to understanding the opportunities, risks, and security implications of autonomous AI systems as they rapidly enter the enterprise. This is a rare opportunity to engage directly with the author and discuss one of the most important emerging topics in cybersecurity today.

6:05 PM

Request an Invitation

**Request an Invitation**

Registration is open only to qualified senior executives. (Sorry, this excludes Sales/Marketing/Business Development!)

Forum Discussion Leaders

(Past, Present & Future)

Josh Woodruff speaking in the Northeast

Tim Brown

CISO & VP, SolarWinds

Tim Brown joined SolarWinds in 2017 as vice president of security and is now the CISO for SolarWinds, overseeing internal IT security, product security, and security strategy. After the SUNBURST attack in December 2020, Tim Brown led the response and remediation efforts. Tim has spoken to thousands of customers and has been instrumental in all customer remediation support and services.

He has worked closely with the SolarWinds® CEO in designing the future state of security and their “Secure by Design” philosophy. This new philosophy on software design will not only benefit SolarWinds but the industry as a whole, and it sets a precedent for responses to future cyberattacks.

As a former Dell Fellow and CTO, Tim deeply understands the challenges and aspirations of the person responsible for driving digital innovation and change. Tim has over 25 years of experience, and his trusted advisor status has taken him from meeting with members of Congress and the Senate to the Situation Room in the White House. He’s also an avid inventor and holds 18 issued patents on security-related topics.

Agentic AI + Zero Trust

Josh Woodruff

Author, Agentic AI + Zero Trust: A Guide for Business Leaders
IANS Faculty | CSA Zero Trust Working Groups

Josh Woodruff is the author of Agentic AI + Zero Trust: A Guide for Business Leaders, a practical framework for safely operationalizing autonomous AI using Zero Trust principles. Drawing on nearly 30 years of experience as both a CIO and CISO, Josh translates real-world enterprise deployments into clear executive guidance on trust, governance, and risk in agentic systems.

The book—co-authored with Michelle Savage and featuring a foreword by Zero Trust pioneer John Kindervag—cuts through AI hype to explain why most AI initiatives stall in pilot mode, and what successful organizations do differently. Josh is also the Founder and CEO of Massive Scale Consulting, co-leads the Cloud Security Alliance Zero Trust Working Group, and serves as IANS Faculty, advising enterprises across regulated and high-risk industries.

Known for his ability to frame complex AI and security challenges in plain executive language, Josh focuses on helping leaders design guardrails that accelerate innovation without sacrificing control, accountability, or resilience.

Jeremy Huval

Jeremy Huval

Chief Innovation Officer
HITRUST

With roughly two decades of experience in performing cybersecurity and compliance assessments, Jeremy is the Chief Innovation Officer at HITRUST, helping unlock the value of the most widely adopted security framework in the healthcare industry. He oversees the development and implementation of innovative solutions that enhance the privacy and security of health information, while ensuring compliance with regulatory and industry standards. Jeremy is passionate about driving innovation and excellence in the healthcare sector, and is committed to advancing the mission and vision of HITRUST. He brings diverse perspectives and experiences to the team, and values collaboration, creativity, and integrity.

Myrna Soto

Myrna Soto

Chief Trust Officer
HITRUST

Myrna Soto is the Chief Trust Officer at HITRUST. As the Founder and CEO of Apogee Executive Advisors LLC since May 2021, she has been dedicated to delivering tailored executive advisory and consulting services in Technology Risk Management, Artificial Intelligence, Cybersecurity, Mergers and Acquisitions, Corporate governance, Corporate development, and Capital investments. Her work supports a diverse range of clients in navigating complex challenges and achieving strategic objectives.

With over four years leading Apogee, Myrna combines her expertise in cybersecurity, mergers and acquisitions, and corporate development with roles on the boards of prominent organizations, including Consumers Energy, TriNet, Popular Inc., Delineated Vectra.ai. She is committed to empowering organizations through effective governance, risk management, and strategic decision-making.

Gregory Webb

Gregory Webb

Chief Executive Officer
HITRUST

Gregory Webb is the Chief Executive Officer at HITRUST. He is an accomplished global technology leader and software executive with experience running high-growth go-to-market, customer success, and engineering teams in enterprise software startups including Venafi, Bromium and AppViewX. Gregory is an industry veteran with a proven track record leading organizations to market leadership and revenue growth backed by top-tier venture capital and private equity firms including Andreessen Horowitz, Meritech Capital, Foundation Capital, Highland Capital and Brighten Park Capital. He received his PhD from UCLA and a Fulbright scholar at Stockholm University.

Barak Perelman speaking in the Northeast

Barak Perelman

CEO & Co-Founder, Opti

Barak Perelman is the CEO & Co-founder of Opti, where he is focused on addressing structural challenges in identity, governance, and accountability as AI becomes embedded into enterprise systems. A seasoned cybersecurity operator and founder, Barak brings more than two decades of hands-on experience building products, leading strategy, and protecting critical infrastructure in highly complex environments.

Previously, Barak was the Co-founder and CEO of Indegy, an industrial cybersecurity company that built a comprehensive security and governance platform for industrial networks. Indegy was acquired by Tenable in 2019, where Barak went on to serve as VP OT Security, helping integrate industrial and enterprise security perspectives. Earlier in his career, he led product design at Stratoscale, where he managed large-scale cybersecurity projects.

Barak holds degrees in computer science, mathematics, and physics, as well as an MBA. He is known for his ability to connect deep technical systems thinking with executive-level governance concerns, particularly around identity, accountability, and the unintended consequences of AI-driven automation inside large enterprises.

John Kindervag 2025 - Chief Evangelist

John Kindervag

Creator of Zero Trust
Chief Evangelist at Illumio

John Kindervag is considered one of the world’s foremost cybersecurity experts. With over 25 years of experience as a practitioner and industry analyst, he is best known for creating the revolutionary Zero Trust Model of Cybersecurity. As Chief Evangelist at Illumio, John Kindervag is responsible for accelerating awareness and adoption of Zero Trust Segmentation.

Most recently, John led cybersecurity strategy as a Senior Vice President at On2IT. He previously served as Field CTO at Palo Alto Networks and, before that, spent over eight years as a Vice President and Principal Analyst on the security and risk team at Forrester Research.

In 2021, John was named to the President’s National Security Telecommunications Advisory Committee (NSTAC) Zero Trust Sub-Committee and was a primary author of the NSATC Zero Trust report that was delivered to the President. That same year, he was also named CISO Magazine’s Cybersecurity Person of the Year. John serves as an advisor to several organizations, including the Cloud Security Alliance and venture capital firm NightDragon.

Richard Stiennon

Richard Stiennon

Chief Research Analyst - IT Harvest
frmr. VP of Research - Gartner

Richard founded IT-Harvest in 2005 to cover the 4,550+ vendors that make up the IT security industry. He has presented on the topic of cybersecurity in 32 countries on six continents. He was a lecturer at Charles Sturt University in Australia. He is the author of Surviving Cyberwar (Government Institutes, 2010) and Washington Post Best Seller, There Will Be Cyberwar, as well as the annual Security Yearbook, published by Wiley for 2025. He was the VP of Research at Gartner. He has a B.S. in Aerospace Engineering from the University of Michigan, and his MA in War in the Modern World from King’s College, London.

Kurtus Minder

Kurtis Minder

CEO & Co-Founder, GroupSense
Author, Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation


Kurtis Minder is one of the world’s foremost experts in ransomware response and cyber threat intelligence. As CEO and co-founder of GroupSense, he has led negotiations in some of the largest ransomware and data extortion cases globally, engaging directly with threat actors and nation-state affiliates. With over 25 years in cybersecurity—including roles at Fortinet, AT&T, and Citrix-acquired Caymus Systems—Kurtis has combined operational security, cyber reconnaissance, and real-world intelligence tradecraft into a uniquely effective digital risk strategy. His pioneering work and insights have been featured in The New Yorker, BBC, The Wall Street Journal, and Fortune.

At ACCSFF 2025, Kurtis will deliver a TED-style keynote and participate in a moderated discussion on themes from his acclaimed new book, Cyber Recon, offering a rare behind-the-scenes look at the people, tools, and tactics behind today’s cyber espionage and ransomware ecosystem.

Tim Rohrbaugh

Tim Rohrbaugh

Founder - RadicalNotion.AI, 3x Public Co. CISO

Tim Rohrbaugh brings 20+ years of C-level cybersecurity leadership to the frontier of AI for security and applied engineering. As founder of RadicalNotion.AI and former CISO of JetBlue Airways, he has built and operated enterprise programs that protect high-value, regulated data— including responsibility for safeguarding more than 40 million consumer records at a public financial services company.

A career security architect and systems engineer, Tim advances a practical view of GenAI as “augmented intelligence”: trustworthy, domain-tuned reasoning agents that reduce noise, challenge bias, and accelerate evidence-backed decisions without exposing IP. He has served as Vice Chair of the Airlines for America Cyber Security Council and as a board member of the Online Trust Alliance, where he contributed to national privacy and security policy. His work has been recognized with multiple awards, including Top Global CISO by Cyber Defense Magazine. Tim holds two joint patents in identity verification and authentication and is a frequent speaker and advisor to boards and engineering teams alike.

Chase Arms Folded

Dr. Chase Cunningham, PhD.

“Dr. Zero Trust” - Author, Speaker and Industry Thought-Leader

Dr. Chase Cunningham is a globally recognized cybersecurity strategist, bestselling author, and trusted advisor to both the public and private sectors. Widely known as “Dr. Zero Trust,” Chase pioneered the Zero Trust security framework during his time as a Senior Analyst at Forrester Research—an approach now adopted as a standard across government and Fortune 500 enterprises alike.

Over a 20+ year career that spans the U.S. Navy, Department of Defense, and senior industry roles, Chase has led initiatives in cryptographic systems, threat intelligence, cyber forensics, and national cyber defense strategy. He holds a PhD in Computer Science and Cybersecurity, with research centered on insider threats and advanced detection algorithms. He also maintains CISSP and CEH certifications.

An engaging keynote speaker and regular contributor to leading cybersecurity forums, Chase is the author of several acclaimed books including Cyber Warfare: Truth, Tactics, and Strategies and his latest, Buy the Breach: Hacking Failure for Market Success. In Buy the Breach, he unveils a contrarian but data-backed strategy for turning corporate cyber failures into personal financial gains—arming cyber professionals with the tools to outperform hedge funds by investing in the inevitable post-breach market rebound.

Chase is a rare voice who blends deep technical expertise with sharp financial insight. Whether briefing the Executive Branch or advising the boardroom, his mission is clear: empower defenders, demystify complexity, and challenge the status quo.

Michael Hiskey

Michael Hiskey

[Moderator] Founder, CxO Security Forum | Author | Speaker | Executive Strategist

Michael Hiskey is an author, blogger, and speaker with more than 20 years of experience in enterprise B2B strategy across cybersecurity, fintech, data, and AI. His work has appeared in Forbes, InformationWeek, WSJ.com, ITProPortal, and he has been featured on CNBC and C|Net.

A seasoned executive, Michael has held Chief Marketing Officer and Chief Strategy Officer roles at companies including Avanan, Socure, Semarchy, Trifacta, and Data Connectors, as well as leadership positions at IBM and MicroStrategy. He has lived and worked on three continents, managing global teams and driving measurable ROI for complex organizations.

Michael is the founder of the CxO Security Forum, a community-led network reinventing how executives connect for education, mentoring, and peer exchange. Having moderated and organized hundreds of cybersecurity conferences, roundtables, and executive forums, he is dedicated to creating practitioner-first environments that foster collaboration between industry, government, and academia.

He holds an MBA from Columbia Business School, and lives on Long Island with his wife and two daughters. More at linkedin.com/in/mphnyc.

June 2026 Agenda & Summary

LOOK BACK:  You can review the agenda, as well as a summary with detailed notes from our last New York City CxO Security Forum. 

(click the document icon above)

About CxO Forum

CxO Security Forum began as a response to a common frustration among senior cybersecurity leaders: the way enterprise solutions are marketed, sold, and evaluated is fundamentally broken. What started as a call for change has grown into a trusted community that puts executive practitioners at the center of the conversation.

 

We bring together CISOs, CIOs, and senior decision-makers who are responsible for protecting their organizations, guiding strategic risk, and navigating the evolving role of AI in security. Every forum, gathering, and conversation is designed to foster education, mentoring, and authentic peer connection.

 

 

What makes us different is our focus on relationships. Our events are intentionally small, curated, and built for real dialogue. Sponsors are carefully selected, and there are no product pitches. Participants come for thoughtful, actionable conversations that support both professional development and practical decision-making.

 

At CxO Security Forum, the goal is simple. Give experienced leaders a space to learn from one another, to share insight, and to build meaningful connections that last beyond the event itself.

Participation is free for qualified senior executives

Location

DLA Piper LLP

1251 Avenue of the Americas, New York, NY  10020

1251 Avenue of the Americas,  New York City

© 2026 CxO Security Forum. All rights reserved