|
Credit Union tech-talk InfoSecurity Conference
Many thanks to everyone who supported the
2007 conference at the fabulous Red Rock Resort in Las Vegas and made it
successful and we look forward to seeing you again in 2008 at Las Vegas' premiere desert resort
- JW Marriott Resort & Spa!
 
The only security conference:
By, For and About Credit Unions!
YES - I want to attend the
2008 CU InfoSecurity Conference June
5 - 6, 2008 at the JW Marriott Resort & Spa (Please
Click Here
for the complete conference brochure in PDF format, or just scroll down
to see the complete schedule below)
Pre-conference - Wednesday June 4th
1:00PM - 2:00PM - Registration
2:00PM - 3:00PM
Online Banking Transaction Monitoring Panel Discussion
Arcot, Digital Resolve and Iovation
Some security experts are convinced that credit unions are spending too much money on
front-end authentication and not enough on transaction monitoring after the logon. They
argue that if one of your member's identity is compromised, security layers beyond
authentication should be in place to limit the damage cybercrooks can do. In this
session, our experts will cover ways to actively monitor all activity online and
proactively address those risks.
3:00PM - 4:00PM
Email Privacy - Protecting Your Members
Dena Bauckman, Director of Product Management for ZixCorp
Email is one of the easiest and most effective ways for credit unions to communicate
with members, and yet many credit unions are reluctant to fully leverage its benefits.
Why - because email is inherently unsecure. Sending an email is analogous to sending a
postcard, with the contents of the message clearly visible to all. With identity theft
at an all time high, it is critical to protect members by securing emails that contains
personal information. But how do you do this? Join this session and learn more about the
issues credit unions face and the different approaches available to secure email
communication.
4:00PM - 5:00PM Breakout Session 1
Mobile Phones for Two-Factor Authentication
Steve Smith, Director of Product Marketing at Clareity Security
Credit unions seeking to expand their online and mobile banking offerings to their
member base face the age-old challenge of balancing security with usability. Mobile
authentication can be the linchpin that holds together online banking and mobile banking
in a way that marries security with convenience. This session will cover how mobile
authentication can help protect members from various hacker methods including
"man-in-the-middle” attacks, and will demonstrate how a system works in the real world.
4:00PM - 5:00PM Breakout Session 2
Spreadsheet Security
Tony Prylowski, CEO of ExSafe
Spreadsheets are often the most common method used to analyze credit union data and are
increasingly used as a front-end to more advanced BI (business intelligence) systems.
All kinds of sensitive data are often stored in spreadsheets. This hands-on session will
cover the handful of security features built into Microsoft Excel and how you can
utilize them. It will also go a step beyond and demonstrate advanced third party
solutions that deliver security features such as role-based security, support for
electronic signatures and locking down to the cell level.
5:00PM - 7:00PM
Credit Union Security Tour
Ensign Federal Credit Union may be a fairly small credit union - $135M in assets - but
they are powerhouse when it comes to security, back office technology and high-tech
branches. Come join us for a tour of their branch and main office where they will
demonstrate some interesting features such as: a secure Internet cafe; digital
merchandising; teller cash dispensers; a CyberKey/CyberLock system, a low cost but
powerful Digital Video Recording system; drive-thru video teller system; a sophisticated
UPS/power backup system; a 100MB WAN with a double encrypted 3MB wireless WAN backup
connection; and offsite data mirroring capabilities.
Please Note: This tour is reserved specifically for attendees who grace us with their
presence at all of the Pre-Conference presentations on Wednesday, June 4th from 2pm -
5pm.
Thursday June 5th
8:00AM - 9:00AM - Registration
9:00AM - 10:00AM
Security Program Management
Stephen Goldsby, President and CEO of Integrated Computer Solutions
Information security should be managed as any other business activity -methodically,
objectively and with an eye toward metrics. This presentation will discuss risk, risk
assessment, risk management and most importantly, how to integrate security risk
management into business risk management at your credit union. It will demonstrate that
not all risk is bad, and security risk management is a key enabler in today's business
landscape. A framework for security risk management will be presented and standards for
implementation will be discussed.
10:15AM - 11:15AM
Log File Management - Real World Examples
Chris Petersen, CTO and Founder of LogRhythm & A. N. Ananth, CEO of Prism Microsystems
Everyone knows that it is extremely time-consuming - but necessary - to perform a daily
review of the log files on all of your file, print and e-mail servers. Log file
management systems can provide visibilty into these files in a centralized location and
generate in-depth reports on the performance, availability, and reliability of your
servers and many differnet facets of your network infrastructure. This session will
provide a hands-on look into how two different systems handle log file management.
11:30AM - 12:30PM
HIPS — Protecting the Weakest Link at a Credit Union
Dan Holt, CEO of HEIT
This session will demonstrate and discuss methods Credit Unions are using to protect the
weakest link in the security chain: the end point (PCs & Servers). The FFIEC
specifically states the need for multi-layered security, malicious code prevention, OS
lockdown, and Host-based Intrusion Detection/Prevention. Zero-Day attacks continue to
increase, and HIPS adds another valuable layer to any credit union's defense in depth
strategy. This demonstration will cover preventing data loss, preventing zero-day
attacks, meeting FFIEC requirements, and reporting on the end point.
1:30PM - 2:30PM
Malware in Action - a Live Demo
Jerry Piatkiewicz, Senior Security Consultant at Perimeter eSecurity
Malicious code such as viruses and worms was once the sole province of hobbyist hackers
– this is no longer the case. Today malicious code is produced by professional criminals
working for groups like the Russian Mafia. Spyware, Trojans, and Rootkits are now being
used to gain control of your systems in such a way that your computers can be used to
generate revenue for these criminals, all without being detected. In this session we
will use tools to infect a computer live to see how the malcode works. You will come
away from this session having a unique understanding of how modern malware threatens you
and what you can do to prevent it.
2:45PM - 3:45PM
Credit Union Peer Discussions
All Attendees
Here is your chance to network with your peers on top security topics. No moderators - just conference attendees breaking out in small groups to talk among themselves on topics such
as:
• Phishing
• Online Forensics
• Regulatory Compliance
• Member Education & Loyalty
• Fraud Detection & Prevention
• Stronger Authentication (FFIEC Guidance)
4:00PM - 6:00PM
Vendors’ Reception and Exhibits
Come join us for cocktails and hor deurves and meet with some of the world’s top
security vendors in an intimate and friendly setting. Exchange notes with these security
experts and learn more about their solutions.
Friday June 6th
9:00AM - 10:00AM
New Trends in Social Engineering
Jim Stickley, CTO & Vice President of Engineering for TraceSecurity
With the increase of stronger network security, and identity theft at an all-time high,
hackers are deploying creative new social engineering techniques as a means to gain your
members' confidential information. Jim will discuss various attack techniques designed
specifically for credit unions, and how to defend against them. Topics include remote
attacks, such as the latest in e-mail and phone scams, as well as numerous on-site
attacks. Both physical security and network security are at risk to social engineering
attacks. By demonstrating examples of these malicious techniques throughout the
presentation, individuals in all job capacities will gain valuable information that can
be applied to daily business operations.
10:15AM - 11:15AM
Stand Up to Network Bullies - How to Build a Network that Defends Itself
Jeff Simpler, CEO of Simpler-Webb
Credit Unions have traditionally set the pace when it comes to spending on technology
and security initiatives, but progress has slowed while successful attacks on networks
are more disruptive and expensive than ever. As a result, the concept pro-active network
defense has emerged suggesting integrated security on all devices and applications with
centralized monitoring, management, and control. Jeff will demonstrate the components of
the “superhero network” and how they work together to meet GLBA requirements.
11:30AM - 12:30PM
Managing Networks & Endpoints: The Big Picture
Jim Shaeffer, CEO of JCS & Associates
It can be difficult for CU IT Departments to have end-to-end visibility across their
network and endpoints. The majority of Security Information Management solutions are
unaffordable for most credit unions, but this hands-on session will demonstrate how you
can affordably obtain a device-independent view of your entire network and ensure that
your security devices and applications – firewall, IDS, IPS, AV, URL filtering, etc –
are properly configured and working correctly. It will also cover ways to deploy
effective data protection solutions at every endpoint in your credit union from an
easily managed central location.
Post-Conference
12:45PM - 1:30
Maintaining Telecommunications & Meeting Auditor Requirements
Tim Ruff, President of Telecom Recovery
Maintaining telecommunications with your staff and members after a disaster is
challenging at best. This point is evidenced by the fact that the Post-Katrina reports
from all of the governmental agencies regulating financial institutions placed restoring
communications quickly at the top of their lists. This hands-on demonstration will show
you how to 1) inexpensively satisfy telecom disaster requirements; 2) show auditors that
you can provide a backup telecom system with just 1 phone call; and 3) successfully
answer every telecom disaster preparedness questionnaire on the NCUA forms.
Post-Conference Pool Party
Come join us in our poolside cabana for drinks and refreshments. A perfect way to
wrap-up
the conference by networking and relaxing next to a beautiful waterfall!
|