-
08:00 – 08:45
Registration & Coffee in the Exhibition Area
-
8:45 - 8:55
Chair’s Opening Remarks
Johanthan Sander - Field CTO - Astrix Security
-
8:55- 9:00
Speed Networking – Making new connections at CISO Financial Services NY!
During this 5-minute networking session, the aim of the game is to go and meet two people you don't already know.
-
09:00 - 09:30
Opening Panel: Confessions of CISOs: What They Don’t Tell You About the Job
- How can sleepless nights, board politics, and regulator heat be managed without burnout?
- Which AI-driven threats and hybrid risks are keeping CISOs awake in 2026?
- When speed clashes with security and compliance with agility, how can the trade-offs be survived?
- What do CISOs wish had been known before stepping into the role?
Moderator: Mo Jamous, EX Chief Information Officer, Consumer & Business Banking – U.S. Bank
Matthew Presson, CISO for the Americas – Bullish
Paul Pak, Chief Information Security Officer, Head of Information Governance - Jennison Associates
Scot Miller, SVP, Information Security - Rocket (Advisory board member)
Christopher Russell, CISO & Head of Tokenization – TZERO GROUP
-
09:30 - 10:00
Presentation: Did you know your firm has crypto trading platform?
Paul Pak - Chief Information Security Officer, Head of Information Governance - Jennison Associates
From ramp and dump schemes (pig butchering) to executive assassinations/executive cyber stalking, why you need to have a Brand and Executive Protection Program in the world of AI and why you need one now.
-
10:00 - 10:30
Expert Ask-Me-Anything: AI, Risk & Regulation
An informal, interactive session where the audience will ask questions live, on the spot.
Speakers respond in real time to questions on AI risk and security, regulatory challenges (SEC, NYDFS, DORA), board-level communication, and building resilient cyber teams.
Moderator: Alexander Abramov, Head of Information Risk -Financial Services
Jessica Wilson, Business Information Security Officer – Bank of America
Mo Jamous, EX Chief Information Officer, Consumer & Business Banking – U.S. Bank
Robert LaRosa, Information Security Engineer – GELLER
Johanthan Sander, Field CTO- Astrix Security
-
10:30-10:45
Spotlight session
-
10:45-11:00
Fireside chat with Fastly
Speaker and topic to be announced
-
11:00-11:30
Mid-Morning Coffee & Networking in the Exhibition Area
-
The CISO Boardroom
-
11:30-12:00
Who Takes the Fall When AI Fails in Financial Services?
- How can deepfake fraud, model poisoning, AI-powered phishing, and AI in credit or lending decisions be stopped?
- Who owns AI risk, and which frameworks or guardrails keep innovation safe?
- Who carries the liability when AI fails in FS?
- How is AI risk best reported in board language?
- What playbooks work for AI-specific incidents like data leakage or model poisoning?
-
12:00-12:15
Yes, No, Maybe? A Reality Check for FS Cyber Leaders
The moderator throws out a statement, and you raise your hand: yes, no, or maybe.
Topics include third-party risk, overlapping compliance, board metrics that miss the point, and whether resilience plans would hold up.
Julia Cherashore, Senior Fellow- DATA Foundation
-
12:15-13:00
Discussion group A: What Happens When Agentic AI Runs Your Security Ops Before You Do?
What risks come with AI-on-AI escalation between defenders and adversaries?
- How can effective oversight frameworks be built for AI-augmented SOCs?
- What early wins, and early fails are showing up in adopting agentic AI for security?
- How can human analysts stay in the loop when machines move first?
Ellis Wong, Chief Information Security Officer - JST Capital
-
Cloud & DevSecOps Lab
-
11:30-12:00
DevSecOps in Financial Services: Automate, Delegate, or Burn Out?
- Which pipeline controls are best enforced through policy-as-code?
- How can security checks be safely delegated to dev teams in regulated contexts?
- What metrics demonstrate DevSecOps reducing audit findings?
- Where does human review still outperform automated tools in Financial Services?
Ellis Wong, Chief Information Security Officer - JST Capital
-
12:00-12:15
Quick Wins or Just Noise? Cutting Through the Cloud & DevSecOps Hype
Every week there’s another “must-have” tool. In this session we run through common practices — IaC scanning, SAST/DAST, secrets management, SBOMs, automated checks, and more. For each one, you vote: real value or just noise. A few volunteers share why.
Jessica Wilson, Business Information Security Officer – Bank of America
-
12:15-13:00
Discussion group B: What’s Your First Move When Your Multi-Cloud Setup Gets Hit at 2am?
- How do you embed post-quantum readiness into cloud strategy?
- How can you secure serverless and containers without slowing delivery?
- What AI analytics improve cloud threat detection accuracy?
- Which cloud security capabilities will be baseline by 2028?
Manoju Thalari, GCP Data Engineer – UBS
-
13:00 – 14:00
Lunch & Networking in the Exhibition Area
-
14:00-14:30
Presentation : Beyond the Breach: What Diplomatic Targets Reveal About Financial Sector Risks
Gharun Lacy - Deputy Assistant Secretary of State for Cyber and Technology Security Bureau of Diplomatic Security - U.S. Department of State
-
14:30-15:00
Presentation: The Five Habits of Highly Secure Organizations
Ben Rothke - Senior Information Security Manager - Experian
-
15:00-15:30
Panel Discussion: Who Owns the Fallout around when GenAI use misfires — Security, Risk, or the Board?
- Who owns AI risk when models impact lending, underwriting, or fraud detection?
- How do organisations embed AI monitoring into existing cyber and risk management frameworks?
- What guardrails help prevent AI misuse without stifling innovation?
- How should firms prepare for AI-specific incidents such as data leakage or model poisoning?
Moderator: Neil Cohen, Head of Marketing - Portal26
Robert LaRosa, Information Security Engineer - GELLER
-
15:30-16:00
Panel Discussion: How to Stop Compliance Spend Becoming a Black Hole?
- Where do compliance frameworks overlap across borders, and how can the duplication be cut?
- What makes a compliance budget credible as resilience spending?
- When does compliance move from obligation to competitive advantage?
- Which signals of audit readiness build market trust?
Moderator: Alexander Abramov, Head of Information Risk -Financial Services
Nishit Mehta, Vice President, Analytics Solutions Manager – JPMorganChase
Robert LaRosa, Information Security Engineer - GELLER
-
16:00-16:30
Afternoon Break & Networking in the Exhibition Area
-
16:30-17:00
Presentation: Insider Risk 2.0: When AI Changes the Threat Landscape
Hasan Dimdik - Senior Workplace Security Engineer - ING
AI is changing the nature of insider risk, amplifying the impact of trusted users and blurring the boundary between productivity and threat. As identities gain more power and controls struggle to keep pace, organisations must rethink insider risk through behaviour, context, and AI-driven defence. -
17:00-17:30
Presentation: When Banks Hold the Keys: The New CISO Reality Post-SAB 122
Christopher Russell - CISO & Head of Tokenization - TZERO GROUP
-
17:30-18:00
Live Poll Debate: Would You Trust AI to Act Before Your Team Can?
Experts go head-to-head, using real incidents and risks from the field. We’ll start with a live poll to see where the room stands, then run it again at the end to track if minds have shifted.
The debate centers on one tough question: should we ever let technology act on its own during a live cyber incident in financial services?
The audience is part of it too so ask your questions, share your views, and see how your take stacks up against your peers.
Jessica Wilson, Business Information Security Officer – Bank of America
John Decker, Chief Technology Officer -Trian Partners
Mo Jamous, EX Chief Information Officer, Consumer & Business Banking – U.S. Bank
-
18:00-18:05
Chair’s Closing Remarks
Johanthan Sander - Field CTO - Astrix Security
-
18:05-19:00
Networking drinks and Prize Draw
Not Found