home Subscribe | About Us | Contact Us  
CU InforSecurity Conference
Speaking Engagements
Vendor Case Studies
CU Orginizations
Newsletters
DP Vendors
Consulting
Webinars
Get Our Free Email Newsletter



 





Credit Union tech-talk InfoSecurity Conference

Many thanks to everyone who supported the 2007 conference at the fabulous Red Rock Resort in Las Vegas and made it successful and we look forward to seeing you again in 2008 at Las Vegas' premiere desert resort -  JW Marriott Resort & Spa!

 
The only security conference:
By, For and About Credit Unions!


YES - I want to attend the 2008 CU InfoSecurity Conference

June 5 - 6, 2008 at the JW Marriott Resort & Spa

(Please Click Here for the complete conference brochure in PDF format, or just scroll down to see the complete schedule below)

 

Name:
Position:
Institution:
Address:
City/State/Zip:
Phone/Ext:
Email:

 

YES, I want to attend the Conference - $495 - Sorry but the 2 nights free lodging at the JW Marriott are SOLD OUT & unavailable!

   

YES, I want to bring my spouse - $99 includes Reception, Continental Breakfasts, Lunch and Refreshment Breaks

 

Invoice me -  

Credit Card Billing Information (SSL Encrypted)
Name on Card:
Card Type:
Card Number:
Expiration: (mm/yyyy)
CCV Number: last three digits found on back of card
Billing Address:
City/State/Zip:
Cardholder agrees to perform the obligations set forth in the Cardholder's agreement with the issuer.

(Please note ALL fields are REQUIRED to register)

Pre-conference - Wednesday June 4th



1:00PM - 2:00PM - Registration

2:00PM - 3:00PM 

Online Banking Transaction Monitoring Panel Discussion 

Arcot, Digital Resolve and Iovation 

Some security experts are convinced that credit unions are spending too much money on 
front-end authentication and not enough on transaction monitoring after the logon. They 
argue that if one of your member's identity is compromised, security layers beyond 
authentication should be in place to limit the damage cybercrooks can do. In this 
session, our experts will cover ways to actively monitor all activity online and 
proactively address those risks.

3:00PM - 4:00PM 

Email Privacy - Protecting Your Members

Dena Bauckman, Director of Product Management for ZixCorp

Email is one of the easiest and most effective ways for credit unions to communicate 
with members, and yet many credit unions are reluctant to fully leverage its benefits. 
Why - because email is inherently unsecure. Sending an email is analogous to sending a 
postcard, with the contents of the message clearly visible to all. With identity theft 
at an all time high, it is critical to protect members by securing emails that contains 
personal information. But how do you do this? Join this session and learn more about the 
issues credit unions face and the different approaches available to secure email 
communication. 

4:00PM - 5:00PM Breakout Session 1

Mobile Phones for Two-Factor Authentication 

Steve Smith, Director of Product Marketing at Clareity Security

Credit unions seeking to expand their online and mobile banking offerings to their 
member base face the age-old challenge of balancing security with usability. Mobile 
authentication can be the linchpin that holds together online banking and mobile banking 
in a way that marries security with convenience. This session will cover how mobile 
authentication can help protect members from various hacker methods including 
"man-in-the-middle” attacks, and will demonstrate how a system works in the real world.

4:00PM - 5:00PM Breakout Session 2

Spreadsheet Security 

Tony Prylowski, CEO of ExSafe

Spreadsheets are often the most common method used to analyze credit union data and are increasingly used as a front-end to more advanced BI (business intelligence) systems. 
All kinds of sensitive data are often stored in spreadsheets. This hands-on session will 
cover the handful of security features built into Microsoft Excel and how you can 
utilize them. It will also go a step beyond and demonstrate advanced third party 
solutions that deliver security features such as role-based security, support for 
electronic signatures and locking down to the cell level.

5:00PM - 7:00PM

Credit Union Security Tour 

Ensign Federal Credit Union may be a fairly small credit union - $135M in assets - but 
they are powerhouse when it comes to security, back office technology and high-tech 
branches. Come join us for a tour of their branch and main office where they will 
demonstrate some interesting features such as: a secure Internet cafe; digital 
merchandising; teller cash dispensers; a CyberKey/CyberLock system, a low cost but 
powerful Digital Video Recording system; drive-thru video teller system; a sophisticated 
UPS/power backup system; a 100MB WAN with a double encrypted 3MB wireless WAN backup connection; and offsite data mirroring capabilities.

Please Note: This tour is reserved specifically for attendees who grace us with their 
presence at all of the Pre-Conference presentations on Wednesday, June 4th from 2pm - 
5pm.



Thursday June 5th



8:00AM - 9:00AM - Registration 

9:00AM - 10:00AM 

Security Program Management 

Stephen Goldsby, President and CEO of Integrated Computer Solutions

Information security should be managed as any other business activity -methodically, 
objectively and with an eye toward metrics. This presentation will discuss risk, risk 
assessment, risk management and most importantly, how to integrate security risk 
management into business risk management at your credit union. It will demonstrate that 
not all risk is bad, and security risk management is a key enabler in today's business 
landscape. A framework for security risk management will be presented and standards for 
implementation will be discussed.

10:15AM - 11:15AM

Log File Management - Real World Examples

Chris Petersen, CTO and Founder of LogRhythm & A. N. Ananth, CEO of Prism Microsystems 

Everyone knows that it is extremely time-consuming - but necessary - to perform a daily 
review of the log files on all of your file, print and e-mail servers. Log file 
management systems can provide visibilty into these files in a centralized location and 
generate in-depth reports on the performance, availability, and reliability of your 
servers and many differnet facets of your network infrastructure. This session will 
provide a hands-on look into how two different systems handle log file management.

11:30AM - 12:30PM

HIPS — Protecting the Weakest Link at a Credit Union

Dan Holt, CEO of HEIT

This session will demonstrate and discuss methods Credit Unions are using to protect the 
weakest link in the security chain: the end point (PCs & Servers). The FFIEC 
specifically states the need for multi-layered security, malicious code prevention, OS 
lockdown, and Host-based Intrusion Detection/Prevention. Zero-Day attacks continue to 
increase, and HIPS adds another valuable layer to any credit union's defense in depth 
strategy. This demonstration will cover preventing data loss, preventing zero-day 
attacks, meeting FFIEC requirements, and reporting on the end point.

1:30PM - 2:30PM

Malware in Action - a Live Demo

Jerry Piatkiewicz, Senior Security Consultant at Perimeter eSecurity

Malicious code such as viruses and worms was once the sole province of hobbyist hackers 
– this is no longer the case. Today malicious code is produced by professional criminals 
working for groups like the Russian Mafia. Spyware, Trojans, and Rootkits are now being 
used to gain control of your systems in such a way that your computers can be used to 
generate revenue for these criminals, all without being detected. In this session we 
will use tools to infect a computer live to see how the malcode works. You will come 
away from this session having a unique understanding of how modern malware threatens you 
and what you can do to prevent it.

2:45PM - 3:45PM

Credit Union Peer Discussions

All Attendees

Here is your chance to network with your peers on top security topics. No moderators - just conference attendees breaking out in small groups to talk among themselves on topics such as:

• Phishing

• Online Forensics

• Regulatory Compliance

• Member Education & Loyalty

• Fraud Detection & Prevention

• Stronger Authentication (FFIEC Guidance) 

4:00PM - 6:00PM 

Vendors’ Reception and Exhibits 

Come join us for cocktails and hor deurves and meet with some of the world’s top 
security vendors in an intimate and friendly setting. Exchange notes with these security 
experts and learn more about their solutions.



Friday June 6th



9:00AM - 10:00AM 

New Trends in Social Engineering

Jim Stickley, CTO & Vice President of Engineering for TraceSecurity

With the increase of stronger network security, and identity theft at an all-time high, 
hackers are deploying creative new social engineering techniques as a means to gain your 
members' confidential information. Jim will discuss various attack techniques designed 
specifically for credit unions, and how to defend against them. Topics include remote 
attacks, such as the latest in e-mail and phone scams, as well as numerous on-site 
attacks. Both physical security and network security are at risk to social engineering 
attacks. By demonstrating examples of these malicious techniques throughout the 
presentation, individuals in all job capacities will gain valuable information that can 
be applied to daily business operations.

10:15AM - 11:15AM

Stand Up to Network Bullies - How to Build a Network that Defends Itself

Jeff Simpler, CEO of Simpler-Webb

Credit Unions have traditionally set the pace when it comes to spending on technology 
and security initiatives, but progress has slowed while successful attacks on networks 
are more disruptive and expensive than ever. As a result, the concept pro-active network 
defense has emerged suggesting integrated security on all devices and applications with 
centralized monitoring, management, and control. Jeff will demonstrate the components of 
the “superhero network” and how they work together to meet GLBA requirements. 

11:30AM - 12:30PM

Managing Networks & Endpoints: The Big Picture

Jim Shaeffer, CEO of JCS & Associates

It can be difficult for CU IT Departments to have end-to-end visibility across their 
network and endpoints. The majority of Security Information Management solutions are 
unaffordable for most credit unions, but this hands-on session will demonstrate how you 
can affordably obtain a device-independent view of your entire network and ensure that 
your security devices and applications – firewall, IDS, IPS, AV, URL filtering, etc – 
are properly configured and working correctly. It will also cover ways to deploy 
effective data protection solutions at every endpoint in your credit union from an 
easily managed central location.

Post-Conference

12:45PM - 1:30

Maintaining Telecommunications & Meeting Auditor Requirements

Tim Ruff, President of Telecom Recovery 

Maintaining telecommunications with your staff and members after a disaster is 
challenging at best. This point is evidenced by the fact that the Post-Katrina reports 
from all of the governmental agencies regulating financial institutions placed restoring 
communications quickly at the top of their lists. This hands-on demonstration will show 
you how to 1) inexpensively satisfy telecom disaster requirements; 2) show auditors that 
you can provide a backup telecom system with just 1 phone call; and 3) successfully 
answer every telecom disaster preparedness questionnaire on the NCUA forms.

Post-Conference Pool Party

Come join us in our poolside cabana for drinks and refreshments. A perfect way to wrap-up 
the conference by networking and relaxing next to a beautiful waterfall!