Main menu
Virtual Problems - Real Answers: June 1, 2011
Working alone or small groups, attackers from all over the world come with numerous agendas to take on the largest organizations and cause severe economic damage. Every attempt to secure our systems makes them harder to use, yet they remain vulnerable. There is a better way: stop chasing after virtual problems and start focusing on real answers.
The San Francisco and Silicon Valley chapters of the Information Systems Security Association (ISSA), in partnership with the San Francisco Bay Area InfraGard invite members of the local security community to attend Cornerstones of Trust at the Crowne Plaza Hotel in Foster City, California. Cornerstones of Trust (#cot11) is the Bay Area's premier, community-driven conference to help security practitioners and leaders address Virtual Problems with Real Answers. Attendees return year after year to stay abreast of an evolving security landscape, network with experts and peers, and earn continuing professional education credits (CPEs) for a price that is "the most security conference for your dollar."
Register now to experience a conference that is strategically planned to maximize actionable value for real-world practitioners, featuring:
- Distinguished, contrasting Keynote Speakers who critically examine Virtual Problems and Real Answers with talks that are custom tailored for our advanced, local audience
- Four parallel session tracks with carefully selected session speakers who offer unique, timely expertise and the ability to both educate and inspire their audience
- A Chief Information Security Officer (CISO) panel session of ground-breaking industry leaders
- Opportunities to network and enjoy the included Breakfast, Lunch, and Afternoon Reception
Track Information
The Virtual Business
- The 2011 Verizon Business Data Breach Investigation Report
- Christopher Porter, Principal on the RISK Intelligence team for Verizon
- Smartphone App Liabilities and how Cloud Security Can Help
- Dr. Amit Sinha, Chief Technology Officer, Zscaler
- Cyber Security Paradigm Shift Needed: Focus on Solving Problems Instead of "Something Else"
- Dr. Ulrich Lang, CEO and co-founder of ObjectSecurity
- To Russia with Love
- Ken Baylor, Ph.D., CISSP, CISM, President of Gladius Consulting
Technology in Motion
- The Web Application Security Crisis
- John Weinschenk, CEO of Cenzic
- Data under Attack: Securing Data Today and in the Future
- Ulf Mattsson is the CTO of Protegrity
- Mistakes to Avoid in Cloud Security
- E. Eugene Schultz, Ph.D., CISSP, CISM, is the CTO of Emagined Security
- Locking Doors, but Opening Windows: Authenticate Your Open Enterprise
- Slawek Ligier, Senior Director of User Authentication Product Development at Symantec
Legal Dynamics
- Records Information Management and Litigation Readiness: Real-World Strategies that Work
- Mark Diamond, founder, President & CEO of Contoural, Inc.
- Being an Expert Witness: Preparing for Trial, Depositions, and Testifying at Trial,
whether You're an Expert Witness or a Fact Witness-
Panelists:
- Stephen Wu
- Hoyt L. Kesterson II
- Glenn S. Tenney
- Computer Incident Response Planning
- Neal McCarthy
- Hacking Back in Self-Defense: Is it Legal, Should it Be?
- David Willson, JD, LLM, CISSP, Security+, is with Titan Info Security Group
Compliance and Beyond
- Rethinking Risk: Black Swans, Tsunamis, and Planning for the Unknown
- Bill Sewall, JD, CISSP
- Selling Security: Strategies for Securing Executive Approval
- Justin Drain, Information Security Officer / Data Security Manager for Fremont Bank
- Gone in 60 Keystrokes
- Mike Lloyd, Ph.D., is the Chief Scientist of RedSeal Systems
- Information Security Across the Generations
- Amy Hirsh Robinson is Principal of the Interchange Group.
Keynote - Asymmetric Warfare, The Rise of Cyber Terrorism
Greg Hoglund - Chief Executive Officer and Co-Founder HBGary
Greg Hoglund is the CEO and Cofounder of HBGary, Inc. A pioneer in software security and a successful entrepreneur, Greg also co-founded two other network security companies including Cenzic, Inc. and Bugscan, Inc., which was acquired by LogicLibrary, Inc. in 2004. He holds two patents and has numerous patents pending. Greg is frequently invited to speak at top international security and technology conferences. Most recently, Greg delivered a keynote presentation on Attribution at SecTor 2010. He has delivered presentations and training at other events including the Northern California Hospital Cyberterrorism Seminar and Black Hat USA 2010. Greg is co-author of several books including Exploiting Online Games (Addison Wesley, 2007) and Rootkits: Subverting the Windows Kernel (Addison Wesley, 2005) and Exploiting Software: How to Break Code (Addison Wesley, 2004).
Asymmetric Warfare, The Rise of Cyber Terrorism
As events have recently shown, hackers working alone or small groups can take on the largest of corporations and cause severe economic damage. These cyber attacks are designed to do harm and loudly disrupt operations, as opposed to quietly stealing intellectual property or identity theft. The attacks are coupled with a political agenda or ideology and have set the stage for a new type of warfare – one in which a single hacker can wield tremendous power over those who depend on information technology.
These attackers come from all over the world with numerous agendas, but the end result is the same, loss due to downtime, brand damage, and leaked proprietary information. The attacks are usually coupled with fear tactics, intimidation, threats and demands, as well as propaganda. Targets are not only corporations and government, but also individuals. Traditional methods of security aren’t enough to deal with crimeware and APT, much less this new form of cyber terrorist attack.
Organizations need to prepare for the possibility of insider threats, sabotage, leaked internal documents, and the possibility of a highly public propaganda campaign. In the new social media, every blogger is a journalist and people read their news in 140 characters or less. Even the perception that a corporation may have been hacked, even if untrue, is enough to damage a brand. This is an environment ripe for propaganda campaigns leveraged by the few and fed to the masses.
Afternoon Keynote - Virtual Problems, Real Solutions

Alan H. Karp - Principal Scientist, Hewlett-Packard Laboratories
Dr. Karp is a Principal Scientist in the Intelligent Infrastructure Laboratory, where he is conducting research on parallel programming at scale. He also heads the Virus Safe Computing Group at HP Labs, which implements usable security. He was Senior Technical Contributor and Chief Scientist at Hewlett-Packard's E-speak Operation and was one of the architects of the chips in Intel's Itanium processor line. Dr. Karp has served on the editorial boards of the Journal of Quantitative Spectroscopy and Radiative Transfer, the Journal of Transport Theory and Statistical Physics, and the editorial advisory board of the journal Scientific Programming. He holds 56 patents.
Virtual Problems, Real Solutions
It seems that every attempt to secure our systems makes them harder to use, yet they remain vulnerable. There is a better way, but it means we have to stop chasing after virtual problems and start focusing on real solutions. Virtual problems are those that are hard to solve, and having solved them, we find that they don't tell us what we need to know. Real solutions go to the heart of the matter and allow us to build systems that are easier to use because they are more secure.
Chief Security Officer Panel Session
This interactive panel of ground-breaking Chief Information Security Officers will examine recent trends in data breaches, virtualization, mobile data, social media, and content aggregation. Note that attendees will have an opportunity to submit advance questions for these CISOs. Panelists include:
Patrick Heim, former CISO, Kaiser Permanente and McKesson Corp.
Mr. Heim has been working in the field of Information Security for over 15 years in a diversity of roles. He has been a CISO, CTO of a security technology firm, security consultant, penetration tester, IT auditor, and has held numerous IT related roles.
Mr. Heim's most recent position was CISO of Kaiser Permanente. Prior to this he was the CISO of McKesson Corporation. He has also held roles with nCircle, eNetSecure / Applied Signal Technologies, and Ernst & Young LLP.
Leslie Lambert, Vice President and CISO, Juniper Networks
Leslie Lambert is Vice President of Information Technology and Chief Information Security Officer (CISO) at Juniper Networks; a leading security vendor serving thousands of enterprise customers worldwide. Ms. Lambert is responsible for overall IT Security Management, including intrusion detection, threat vulnerability assessments, incident management, security awareness, prevention and protection against SPAM and malware attacks, policies/standards/procedures development and deployment. Ms. Lambert has 30 years of experience in Information Technology and technical/business infrastructure.
Prior to joining Juniper Networks, Ms. Lambert was with Sun Microsystems, Inc. and held several critical IT roles: Chief Information Security Officer, Vice President of IT Strategy and Architecture, Vice President of Service Management and Systems Engineering Practices, Vice President of Demand Creation Systems IT, as well as Vice President of both the iPlanet and Software Systems Group divisions.
Ms. Lambert’s experiences range from Control Systems Design to the delivery, implementation and management of IT systems and infrastructure. Her experience covers the industries of oil and gas, engineering and construction, evaluation research, customer training, CAD/CAE, and information Technology, where she gained significant hands-on operational, architectural, and management experience.
Ms. Lambert holds an MBA with an emphasis in Finance and Marketing, as well as an MA and BA in Experimental Psychology (measurement, evaluation, statistics, and techniques of experimental research). She also has degrees in Mathematics and Engineering Technology, and has completed graduate-Level study in Computer Science.
Industry Awards
- 2010 CSO Magazine Compass Award
- 2009 Computerworld Magazine “Computerworld's Premier 100 IT Leaders
- 2006 Selected and continues to serve as an Anita Borg Institute (ABI) Ambassador; helping the advancement of technical professional women within corporations
- 2005 CIO Magazine “Ones to Watch”.
- 2005 YWCA of Silicon Valley winner of” Tribute to Women and Industry TWIN”
Gary Terrell, CISO, Adobe Systems
Gary Terrell, Information Security Officer, CIPP, Adobe, has global responsibility for Adobe’s security program including governance, risk and compliance. Terrell works closely with Adobe's product engineers to ensure that Adobe software will be protected from external threats when deployed in computing clouds such as Amazon, and plays an integral role in the development of the company's enterprise products, including Adobe LiveCycle Document Security and Adobe LiveCycle Policy Server.
Moderated by:
Jeff Klaben, Industry Maven
As a four-time CISO, Mr. Klaben has traversed the breadth of the information security landscape. Most recently, he served as Group Director of Technology Risk Management and IT Security at SanDisk and previously as Chief Information Security Officer for Applied Biosystems (now Life Technologies). He was Engineering Group Director with Cadence Design Systems’ Products and Technology Organization and previously led enterprise architecture, global security, and IT regulatory compliance at Applied Materials. At Accenture, Jeff led professional services delivery, product management, training, and alliances strategy for the firm’s technology and security consulting service lines. He also partnered with the firm to co-found two startups. Jeff has also held positions in technology marketing and as a system software engineer.
Jeff is founder and co-chair of the Cornerstones of Trust Conference and continues to serve on the board of the San Francisco Bay Area InfraGard, where he served for eight years as President of this 501 (c)(3) non-profit dedicated to public/private information sharing. Jeff regularly teaches and speaks. He assisted the White House as town hall moderator for the rollout of the National Strategy to Secure Cyberspace. Recent speaking engagement include Knowledge Synergized, DAC, CDN Live, IIA, InfraGard, RSA, Disaster Resistant California, ISACA Bangalore India, ISSA CISO Forum, and Secure World Expo. Mr. Klaben was recently recognized with a Dedicated Service Award from the United States Department of Justice, the Belotti Award from Santa Clara University’s Leavey School of Business, and “Cardio King” status by the YMCA of Silicon Valley.

































