Home » Smart Webinars » CIO & CISO NORDICS SMART WEBINAR

CIO & CISO NORDICS SMART WEBINAR

Date: 22nd April, 2021 2 PM

Event Overview

A Holistic Approach to Cybersecurity

In the age of digital transformation, businesses are evolving faster than ever. An  ever-growing list of applications are being deployed that may run on any number of clouds, while nascent technologies such as the Internet of Things and artificial intelligence are becoming important aspects of many business’s competitive strategies. CISOs must take lead in this transformation process to help balance the risks of new digital technologies with their potential benefits.

Agenda

14:00 - WELCOME REMARKS & INTRODUCTION

14:10 - 14:25 - SESSION 1 - DELEGATE PRESENTATION

I Hacked a Bank and How to Deal With it

 

Speaker:

  • Per Thorsheim, Information Security Officer at Vipps

14:30 - 14:45 - SESSION 2 - PARTNER PRESENTATION

Why static analysis won’t protect from cloud native supply chain attacks

 

See how attackers are using the development and build supply chain to inject malicious images into pipelines, and eventually into production. Static scanning techniques are unable to detect packers (including encrypters) and downloaders that encrypt binary code which is then only executed in memory. This means malware will only download during runtime, and can only be detected when images are run in production. The key is to run an image in a pre-production sandbox to see runtime behavior without running the image in production. A further benefit of running an image in a pre-production sandbox is figuring out issues that are guaranteed to turn into real threats, versus the list of potential threats that come with static scanning.

Aqua Security is the largest pure-play cloud native security company, providing customers the freedom to innovate and run their businesses with minimal friction. The Aqua Cloud Native Security Platform provides prevention, detection, and response automation across the entire application lifecycle to secure the build, secure cloud infrastructure and secure running workloads wherever they are deployed. Aqua customers are among the world’s largest enterprises in financial services, software, media, manufacturing and retail, with implementations across a broad range of cloud providers and modern technology stacks spanning containers, serverless functions, and cloud VMs.

 

Speaker:

  • Benjy Portnoy (CISSP, CISA), Director Solution Architects at Aqua Security

 

Benjy is a cyber security professional with over 15 years experience in consulting, designing, and implementing strategic cybersecurity projects for organizations across EMEA. He is currently Senior Director of Solution Architecture at Aqua Security where he works with Aqua’s customers to foster a devsecops culture while streamlining security into their DevOps processes to secure their cloud native applications. Prior to joining Aqua Security, Benjy held senior security architect roles at BlueCoat and Symantec where he worked closely with CISO’s and security operations teams developing strategies for vulnerability management, datacenter security, and incident response. Benjy holds both CISA (Certified Information Systems Auditor) and CISSP (Certified Information System

14:45 -15:15 - SESSION 3 - OPEN DISCUSSIONS AND Q&A

A Holistic Approach to Cybersecurity

In the age of digital transformation, businesses are evolving faster than ever. An  ever-growing list of applications are being deployed that may run on any number of clouds, while nascent technologies such as the Internet of Things and artificial intelligence are becoming important aspects of many business’s competitive strategies. CISOs must take lead in this transformation process to help balance the risks of new digital technologies with their potential benefits.

In the past, effective cybersecurity strategies primarily relied on defensive processes and technologies. But as the boundaries of the network have become blurred with the proliferation of mobile devices and connectivity virtually everywhere, cybersecurity has become far too complex to rely on defensive solutions alone. Instead of the traditional firewall, what may be required is more of an immune system that responds to threats as they emerge and addresses any ill effects before they severely weaken the business as a whole.

Since attacks are inevitable, CISOs must be proactive to ensure their organizations are prepared. By focusing on alignment throughout the organization to build an understanding of how the whole system is connected, weak points can be addressed and processes improved before serious threats do long-term damage.

 

MODERATOR:

  • Hanne Hansen, Former CISO at Orsted

Q&A:

  • Hernan Huwyler, Director Governance Risk Management at Danske Bank
  • Surinder S. Rait, Head of IT Security Assurance at Ericsson
  • Benjy Portnoy (CISSP, CISA), Director Solution Architects at Aqua Security

Panel Questions:

  1. Do you have any tips on how organizations can  empower developers  from a security perspective and foster a shared responsibility model?
  2. Why is there a growing trend on attacks specifically against cloud native infrastructure?
  3. What are some of the risks around leveraging opensource components in cloud native applications?
  4. Can you give some examples of what evasion techniques bad actors are using to avoid detection when attacking cloud native applications?
  5. How are organizations helping foster a devsecops culture?
  6. How can security leaders effectively collaborate with operational leaders to create better outcomes for the organization?
  7. How can security leaders enable innovation without creating new security vulnerabilities?
  8. What are the best practices and tools to assess your organization’s overall risk profile?